[CLSA-2025:1762421840] skopeo: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-11-06 09:37:26 UTC
Description:
- CVE-2024-3727: fix path traversal vulnerability with full digest validation in all containers/image transports - CVE-2025-27144: fix excessive memory consumption vulnerability in github.com/go-jose/go-jose/v3 library
Updated packages:
  • skopeo-1.11.2-0.1.el9.tuxcare.els1.x86_64.rpm
    sha:6e134f321cd0690494d87533d6ad835e4564d38a5ac32fe347fe3afb80051fc8
  • skopeo-tests-1.11.2-0.1.el9.tuxcare.els1.x86_64.rpm
    sha:1736bf0f53d7ce092af6468ce256a4d152d83cfbcbfff543a680ed3f34166031
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.