[ALSA-2024:8110] Important: containernetworking-plugins security update
Type:
security
Severity:
important
Release date:
2024-10-15
Description:
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 containernetworking-plugins-1.4.0-6.el9_4.aarch64.rpm 8254dbefb2f49369f6b0276e1b73050adcab6528b16525f151ee4e3a464001e8
ppc64le containernetworking-plugins-1.4.0-6.el9_4.ppc64le.rpm bf8d0e4e5f2aad94bf704cc3d6facd9d199f1fe1ab3a592a95c643cd00114002
s390x containernetworking-plugins-1.4.0-6.el9_4.s390x.rpm ba787fc67eb3c5024799cdc36db907c78bb95371ab1e7c80a6719fae6e93aead
x86_64 containernetworking-plugins-1.4.0-6.el9_4.x86_64.rpm 05cd7d098ff1b2b6b2bf07d0ef8d218754663569ae2e09cff7144cdeb1c362ab
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.