stable

pack-0.40.8-1.fc43

FEDORA-2026-e6e0368149 created by lsm5 a month ago for Fedora 43

Security update to pack 0.40.8

Fixes CVE-2024-25621: containerd - local privilege escalation Fixes CVE-2025-47913: golang.org/x/crypto/ssh/agent - SSH client panic Fixes CVE-2025-47914: golang.org/x/crypto/ssh/agent - SSH Agent server DoS Fixes CVE-2025-52881: container escape and denial of service Fixes CVE-2026-27145: crypto/x509 - DoS via excessive DNS SAN processing Fixes CVE-2026-33762: go-git - DoS via crafted Git index file Fixes CVE-2026-34165: go-git - DoS via crafted .idx file Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution Fixes CVE-2026-39829: golang.org/x/crypto/ssh - DoS via crafted public key Fixes CVE-2026-39830: golang.org/x/crypto/ssh - Resource leak DoS Fixes CVE-2026-39832: golang.org/x/crypto/ssh/agent - Key restrictions bypass Fixes CVE-2026-39833: golang.org/x/crypto/ssh/agent - Key confirmation bypass Fixes CVE-2026-39835: golang.org/x/crypto/ssh - Certificate DoS Fixes CVE-2026-44740: go-billy - DoS via symlink cycle Fixes GO-2026-4970: Root escape via symlink plus trailing slash Fixes GO-2026-5856: Encrypted Client Hello privacy leak

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-e6e0368149

This update has been submitted for testing by lsm5.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

lsm5 edited this update.

a month ago

This update's test gating status has been changed to 'passed'.

a month ago

This update has been submitted for stable by bodhi.

a month ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
modified
a month ago
approved
a month ago
BZ#2419047 CVE-2024-25621 pack: containerd local privilege escalation [fedora-43]
0
0
BZ#2420625 CVE-2025-47913 pack: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43]
0
0
BZ#2424069 [Minor Incident] CVE-2025-52881 pack: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [fedora-43]
0
0
BZ#2454569 CVE-2026-34165 pack: go-git: Denial of Service via crafted .idx file [fedora-all]
0
0
BZ#2454570 CVE-2026-33762 pack: go-git: Denial of Service via crafted Git index file [fedora-all]
0
0
BZ#2478228 pack-0.40.8 is available
0
0
BZ#2490496 CVE-2026-39830 pack: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
0
0
BZ#2493089 CVE-2026-39832 pack: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
0
0
BZ#2493535 CVE-2026-39835 pack: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
0
0
BZ#2494334 CVE-2026-27145 pack: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
0
0
BZ#2494451 CVE-2026-39833 pack: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
0
0
BZ#2496516 CVE-2026-44740 pack: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
0
0
BZ#2503325 CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
0
0
BZ#2503623 CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
0
0

Automated Test Results