[ALSA-2026:70191] Important: runc security update
Type:
security
Severity:
important
Release date:
2026-09-23
Description:
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 runc-1.4.2-3.el9_8.aarch64.rpm c5faa67457ad15bdf70d8658f29932c79e6845469864ffd9d1fd04b584df6b43
ppc64le runc-1.4.2-3.el9_8.ppc64le.rpm f96a0872b13b01ca7b614c49298ce55de389992e944a16e911e58731a31e6dbd
s390x runc-1.4.2-3.el9_8.s390x.rpm a4741838992a21e1a71968a109180da62e80b94d2385c49d1bb0773cc7b72b11
x86_64 runc-1.4.2-3.el9_8.x86_64.rpm 707a46b77f5976de53f96ab2b46294af8db165cfd5c616346eb23c08d4d1ccc4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.