[CLSA-2025:1763489872] runc: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2025-11-18 18:17:56 UTC
Description:
- rebuild with newer golang to fix security vulnerabilities: - CVE-2023-45287: fix RSA-based TLS key exchange timing attack vulnerability - CVE-2024-24788: fix DNS resolver infinite loop causing denial of service - CVE-2023-39321: fix QUIC post-handshake message processing causing panic and denial of service
Updated packages:
  • runc-1.1.4-1.el9_1.tuxcare.els2.x86_64.rpm
    sha:585bc408c5f3a936b5459d7013b4e63ab76aa3c92f1a30e4233cdcb072698d0b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.