[ALSA-2025:9143] Moderate: containernetworking-plugins security update
Type:
security
Severity:
moderate
Release date:
2025-06-17
Description:
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * net/[http:](http:) Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 containernetworking-plugins-1.6.2-2.el9_6.aarch64.rpm 1a8b27c0c9276895303fb334b09197b331df3c80c8e0df3de63c692aadb5981c
ppc64le containernetworking-plugins-1.6.2-2.el9_6.ppc64le.rpm c4857b2aaa9367f571117613e93d4ced4a007dc972e6a3014dc1b5297f898719
s390x containernetworking-plugins-1.6.2-2.el9_6.s390x.rpm 9d398e432a8b99e3a0c5d6e1c06efeedcbeb2118611dda9a72dbfa1be2ff4d20
x86_64 containernetworking-plugins-1.6.2-2.el9_6.x86_64.rpm b725688fc0a180919f580f563b2d308aa41536f02bb577d7de9096bb3fc65a74
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.