[CLSA-2025:1747251120] buildah: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-05-14 19:32:04 UTC
Description:
- Rebuild with new golang version to address the following CVEs: - CVE-2023-45287: Timing Side Channel attack in RSA based TLS key exchanges - CVE-2024-34156: panic due to stack exhaustion for Decoder.Decode
Updated packages:
  • buildah-1.29.5-1.el9_2.tuxcare.els2.x86_64.rpm
    sha:c6158a6a247d8614f31658da57b4d0e763f68f21d2467ff7a20133204fa6816f
  • buildah-tests-1.29.5-1.el9_2.tuxcare.els2.x86_64.rpm
    sha:f1ccca4be6e89521ed562476dd318894379fe745350a8c78a4ea188e22daba19
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.