RHSA-2026:49944: Important: container-tools:rhel8 security, bug fix, and enhancement update
Important: container-tools:rhel8 security, bug fix, and enhancement update
Other sources
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip (CVE-2025-61728) golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) Bug Fix(es) and Enhancement(s): [RHEL 8.8] Buildah specfile missing dumpspec test binary (JIRA:RHEL-170411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.29.8-1.module+el8.8.0+24545+b713e821 - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 63.1-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.229.0-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1-67.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 1.14.3-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.11-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/netavarkto a version that resolves this vulnerability.Fixed in 1.5.1-3.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.10-1.module+el8.8.0+24130+2fde7a57 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/python-podmanto a version that resolves this vulnerability.Fixed in 4.4.1-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.2.9-1.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.11.6-1.module+el8.8.0+24525+a924b82f - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.6-20.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.8-1.module+el8.8.0+24545+b713e821 - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.29.8-1.module+el8.8.0+24545+b713e821 - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.29.8-1.module+el8.8.0+24545+b713e821 - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.8-1.module+el8.8.0+24545+b713e821 - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criu-develto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criu-libsto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/criu-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.3-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.3-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.11-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.11-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.10-1.module+el8.8.0+24130+2fde7a57 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.10-1.module+el8.8.0+24130+2fde7a57 - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-gvproxyto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-gvproxy-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 4.4.1-27.module+el8.8.0+24545+b713e821.8 - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-4.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/python3-podmanto a version that resolves this vulnerability.Fixed in 4.4.1-1.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.9-1.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.9-1.module+el8.8.0+24525+a924b82f.1 - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.11.6-1.module+el8.8.0+24525+a924b82f - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+23884+2031fc78 - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+23884+2031fc78
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49944?
The severity of RHSA-2026:49944 is high with a score of 7.
What components are affected by RHSA-2026:49944?
Affected components include redhat/aardvark-dns, redhat/buildah, redhat/conmon, redhat/containernetworking-plugins, redhat/containers-common, redhat/criu, redhat/crun, and redhat/fuse-overlayfs.
How do I fix RHSA-2026:49944?
To fix RHSA-2026:49944, update the relevant container-tools packages through your package manager.
What is the main security issue addressed by RHSA-2026:49944?
The main security issue addressed by RHSA-2026:49944 is a Denial of Service vulnerability due to excessive resource consumption via crafted certificates.
When was RHSA-2026:49944 published?
RHSA-2026:49944 was published on August 4, 2026.