[ALSA-2023:2283] Moderate: skopeo security and bug fix update
Type:
security
Severity:
moderate
Release date:
2023-05-12
Description:
The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files. Security Fix(es): * golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) * golang: crypto/tls: session tickets lack random ticket_age_add (CVE-2022-30629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 skopeo-1.11.2-0.1.el9.aarch64.rpm 191fb1513339ab60ed821d51354e51c3ae4ed69fb52cc7de8ee0b1d5eab0b0df
aarch64 skopeo-tests-1.11.2-0.1.el9.aarch64.rpm 7c8dce7aa6578256c90f5f45f808d63b4ecdf511d2ab84f215dfa704962e96f5
ppc64le skopeo-1.11.2-0.1.el9.ppc64le.rpm 3df8b09494ed0b186308ad9490d02c15fe16a6d9d2e1f9f9fbaea5111f6e936d
ppc64le skopeo-tests-1.11.2-0.1.el9.ppc64le.rpm 851a21bf2fbd0d1fa47908ac482eaa3f03aaf71f8bccbcffc60f2e21cfae2abd
s390x skopeo-1.11.2-0.1.el9.s390x.rpm 91bb9b7bc7a6f9a0200a7a0dd9fd833f11c955584db6d26ec9a30048a7045dba
s390x skopeo-tests-1.11.2-0.1.el9.s390x.rpm e38efdc7abc3a47e40102d42c0fb7cac86008fcf7b7eae215f68664d68b8ba22
x86_64 skopeo-tests-1.11.2-0.1.el9.x86_64.rpm 836ae8578d5a93c18f7aa2bae383270264912ca9deb9178bcccd6894a9398c47
x86_64 skopeo-1.11.2-0.1.el9.x86_64.rpm 903687d6856e66f4c6783db831bef213171f6af945f7f0e06450f954eba652ff
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.