Details:
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829)
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830)
golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832)
golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
2:1.10.1-2.module+el8.10.0+24482+e50f4e4f2:1.33.14-4.module+el8.10.0+24482+e50f4e4f2:1.33.14-4.module+el8.10.0+24482+e50f4e4f2:1.33.14-4.module+el8.10.0+24482+e50f4e4f2:1.33.14-4.module+el8.10.0+24482+e50f4e4f2:1.33.14-4.module+el8.10.0+24482+e50f4e4f0:84.1-1.module+el8.10.0+24482+e50f4e4f3:2.1.10-1.module+el8.10.0+24482+e50f4e4f3:2.1.10-1.module+el8.10.0+24482+e50f4e4f3:2.1.10-1.module+el8.10.0+24482+e50f4e4fExploitability
AV:NAC:LPR:LUI:RScope
S:CImpact
C:HI:HA:N8.7/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N