RHSA-2026:61907: Important: runc security update
Important: runc security update
Other sources
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.Security Fix(es): crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2 - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.9-1.el9_4.2.aa - Upgrade
Upgrade
runcto a version that resolves this vulnerability.Patch CVE-2026-32281 - Upgrade
Upgrade
Go crypto/x509to a version that resolves this vulnerability.Patch CVE-2026-32280 - Upgrade
Upgrade
Go crypto/x509to a version that resolves this vulnerability.Patch CVE-2026-33810
Event History
Frequently Asked Questions
Which runc-related packages are included in this update?
The advisory lists redhat/runc, redhat/runc-debuginfo, and redhat/runc-debugsource.
What types of security issues are addressed?
The update addresses two denial-of-service issues in Go certificate chain validation and building, CVE-2026-32281 and CVE-2026-32280. It also addresses a certificate-validation bypass involving incorrect DNS constraint application, CVE-2026-33810.
Which Red Hat Enterprise Linux offerings are listed as affected?
The advisory lists Update Services for SAP Solutions on x86_64 and Power LE, Extended Life Cycle offerings on x86_64 and Power little endian, and the ARM 64 four-year updates offering.