Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:35833: Important: container-tools:rhel8 security update

  • What: Security update for container-tools in Red Hat
  • Impact: Addresses vulnerabilities in container tools
Read Full Article →

Red Hat Product Errata RHSA-2026:35833 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35833 - Security Advisory Overview Updated Packages Synopsis Important: container-tools:rhel8 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2455470 - CVE-2026-34986 github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions BZ - 2480688 - CVE-2026-42508 golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVEs CVE-2026-34986 CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-42508 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM aardvark-dns-1.10.1-2.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 647e0a1e8698849a3249df0f0a66ea9ebdd99d691f7c703319ad4dc0248af438 buildah-1.33.14-4.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 41d199746e906a4bd72a86aecf6576fbb3ebfa9ff35f849d822580cf4a0803b4 cockpit-podman-84.1-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: ed9243004da9218d9734da1a848f36477b9106bc30e0ce589881a4380e7cbcd7 conmon-2.1.10-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: bc05b003c2cec5d26e6e3e43fdcbbe84ef218a8567acd2a846bf6d7267819cb8 container-selinux-2.229.0-3.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 91663e42a5f97dfdc3f00485d39353f1a49e1a7e1af3ac03c9693b3e5cff8bd6 containernetworking-plugins-1.4.0-8.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: c3b01d1376ff31c32dd81b73a26bdecac155a4aa64c3ba5088c86acbf0be1717 containers-common-1-82.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: a2f91b6b4cd6d6e67aa9d749700053dcad62adc5b97f9cb13945020e9a7eca85 criu-3.18-5.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: db6d99a5a6edfdf333606948967c9be8f327600ec958dc7947ecbce32fa20016 crun-1.14.3-2.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 6dedab74b576d1657e18098c55f8dbc85ff3ff31d1c78df3667e2bb33e9790c1 fuse-overlayfs-1.13-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 02adb1f1e1734157ddb26a359582f1bd40c0428e9c639a4112afdbcb00b779c3 libslirp-4.4.0-2.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 2de93ac316ce2ba6d95a39bf2e7006e2f0ad2d0438c7bbb49f4e06541d899e78 netavark-1.10.3-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 258bcd530dccdab057d6f3b58ea3cae3b1b43f8321910ae84bcf88bf56c5cae7 oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: dccd271c697975ff7493848de4570fcbd377d8626a2b771b622b6c1ceeea5817 podman-4.9.4-32.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 14714072cb6d75cba0d642ebcbd64edcf49d51975cb395d62d7d551583bb762f python-podman-4.9.0-3.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: e23d6ae8ac12cc0b1720b8938bff2cd967f4b8cb75361709c1dc06babfd8a55a runc-1.2.9-4.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 6e3d1391bf0640bca4f79632de96ffcb8804e966c889c3d46c3d26b0a92d7b4d skopeo-1.14.6-2.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 4336dd5157b07079c0581d0bdf6103d36c010bb373f9b8273d09639a84f59548 slirp4netns-1.2.3-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: 49d359766bed9b0cdc7a924c19b938b9c09ffc7cd7bd53964f1e7917c58e6ad1 toolbox-0.0.99.5.1-1.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: dee026bac9b490c0f7a83f89df1ead020b44120a974c6fab4c73d722de9ba711 udica-0.2.6-21.module+el8.10.0+24482+e50f4e4f.src.rpm SHA-256: ac58201f5ccc42a4c0ec33d552a35b8539cae297a9d2592cc52830d5dd84e222 x86_64 cockpit-podman-84.1-1.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: ce5178c6720cc8bb40eae48454ca518d643b78962b666a5b2da14e79a6db9c4a container-selinux-2.229.0-3.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 22d6bc11f08b92483278f16d554dd50c4171aeb417a00f46db4ab05486dee25c podman-docker-4.9.4-32.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 5d8b66ccb4ffb25531ca1da6d0271c41f2f5e9a85a1696f30268678db893a0f1 python3-podman-4.9.0-3.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 2473a65aa8373cef8754f04a2da63da6ddd4a75f5bf720da41889977e4139ead udica-0.2.6-21.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 30b04ab6ac7532a6926d774f19666dddd8389f08863e0d9160756146d59b4009 cockpit-podman-84.1-1.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: ce5178c6720cc8bb40eae48454ca518d643b78962b666a5b2da14e79a6db9c4a container-selinux-2.229.0-3.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 22d6bc11f08b92483278f16d554dd50c4171aeb417a00f46db4ab05486dee25c podman-docker-4.9.4-32.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 5d8b66ccb4ffb25531ca1da6d0271c41f2f5e9a85a1696f30268678db893a0f1 python3-podman-4.9.0-3.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 2473a65aa8373cef8754f04a2da63da6ddd4a75f5bf720da41889977e4139ead udica-0.2.6-21.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 30b04ab6ac7532a6926d774f19666dddd8389f08863e0d9160756146d59b4009 aardvark-dns-1.10.1-2.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: cd6a275eade2a63492c4c12ecf127798bc1fc265663cc5cf23d951db123e66e1 buildah-1.33.14-4.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 3e7b04768915ba208c58a71c2f4f397a7b0bad8b374d44cb712bdf052df5e36e buildah-debuginfo-1.33.14-4.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 4a0f480521257d28ffd55deb6ebd7269e4fda5a6edc49330b4c25be3852e400e buildah-debugsource-1.33.14-4.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 21e2ffcf03e306c4e880ddbb8395b6cff56d461d37d64b74131d95c5fc2f0f4c buildah-tests-1.33.14-4.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 9fc79d13afe8d7f94f66c0e31daf8f026f6b09c123b28c612f360e636d84443e buildah-tests-debuginfo-1.33.14-4.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 201008ecf71d8f6afb4a2ef4c9fab3a2eb6498d301223b8692a471f6b67df5f5 cockpit-podman-84.1-1.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: ce5178c6720cc8bb40eae48454ca518d643b78962b666a5b2da14e79a6db9c4a conmon-2.1.10-1.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 6c08cfdda08ba8971886fcfecb2783863cf894250efa95f56133db8a04c814a0 conmon-debuginfo-2.1.10-1.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 57e24d6d54dc42895f5f05710bec161977bcb3162a2ebca8cc483a9fc4b163cf conmon-debugsource-2.1.10-1.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: afe466f2fb7348e43a27607525fd3995c496d8c94d87dfdf7d2980c9d6cec74e container-selinux-2.229.0-3.module+el8.10.0+24482+e50f4e4f.noarch.rpm SHA-256: 22d6bc11f08b92483278f16d554dd50c4171aeb417a00f46db4ab05486dee25c containernetworking-plugins-1.4.0-8.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: b3eea6bb5f0135272cb14b3a42eb0f2f803aa71e0f107b715312f9d5aa145e67 containernetworking-plugins-debuginfo-1.4.0-8.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 3a0493be1bf33277996186e4dd595b41dc61634ed75d849fcb89407c46cfa75e containernetworking-plugins-debugsource-1.4.0-8.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 6df43fb1c9b10c5110c936072444425b15b5f06db7a6ecba46451007caf02f76 containers-common-1-82.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 753604b72010470e0b1dfe963b27cb801a1c170b3789291d8aeefab239e82ecd crit-3.18-5.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 49c939d6c0949b5e2e4795858e90adf2ba0bdf6a1024451534361b736e4f0f39 criu-3.18-5.module+el8.10.0+24482+e50f4e4f.x86_64.rpm SHA-256: 029df1af7a45ff5390a41c5d7ee82555b49c3ff887f24ddf497f80

Share this article