[ALSA-2026:70641] Important: skopeo security update
Type:
security
Severity:
important
Release date:
2026-09-24
Description:
Command line utility to inspect images and repositories directly on Docker registries without the need to pull them. Security Fix(es): * skopeo: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * skopeo: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * skopeo: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * skopeo: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * skopeo: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 skopeo-tests-1.22.2-8.el9_8.aarch64.rpm 1554698050b151117f15047c6cbdd3fef1364597a4fc2e282179ac13311f68b5
aarch64 skopeo-1.22.2-8.el9_8.aarch64.rpm e33722915f3ba923040b9b7eafafcbcd92cb7b51943b966db7c43a1164e1944e
ppc64le skopeo-tests-1.22.2-8.el9_8.ppc64le.rpm 4f6b898f7ca69667d59a15c9dbcc5c6cd4822a8f45889e8500106a2aadbd0b88
ppc64le skopeo-1.22.2-8.el9_8.ppc64le.rpm eace9a171b99870ac813a46eb276cfcc0ec62a506b12a5719d630a246a337ee7
s390x skopeo-1.22.2-8.el9_8.s390x.rpm 72b0c16e4db9660ac5fc9a1b70737a9c7491b307e23f61c1e4c75daa5b443d16
s390x skopeo-tests-1.22.2-8.el9_8.s390x.rpm cfe4e1efe1bb66dc5b2a59b17d16657c15a5035d3ed549873ba66eae7223ae7f
x86_64 skopeo-1.22.2-8.el9_8.x86_64.rpm 5416749829136b84767130452ef629abdb13e24c2ceed6292db022bb206bc9c2
x86_64 skopeo-tests-1.22.2-8.el9_8.x86_64.rpm 99dfb50a5e71139715533e893460bbe6d93a842d639e0e2591ffee19d46189f6
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.