RHSA-2026:61906: Important: runc security update
Important: runc security update
Other sources
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.Security Fix(es): crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1 - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.9-3.el9_6.1.aa - Upgrade
Upgrade
runcto a version that resolves this vulnerability.Patch CVE-2026-32281 - Upgrade
Upgrade
crypto/x509 (Go)to a version that resolves this vulnerability.Patch CVE-2026-32280
Event History
Frequently Asked Questions
Which systems are covered by this advisory?
The advisory lists Red Hat runc, runc-debuginfo, and runc-debugsource packages for specified Red Hat Enterprise Linux offerings on x86_64, IBM z Systems, and Power little-endian platforms, including certain Extended Update Support, Extended Life Cycle, and SAP Update Services channels.
What type of impact do the addressed issues have?
Both listed CVEs concern denial of service in Go certificate chain processing: CVE-2026-32281 involves inefficient certificate chain validation, and CVE-2026-32280 affects certificate chain building.