[CLSA-2026:1772576264] containernetworking-plugins: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-03-03 22:17:49 UTC
Description:
- rebuild with newer golang version 1.25.7-1.el9_6.tuxcare.els1 to fix the following CVEs - CVE-2025-68121: fix TLS session resumption bypass by preventing shared auto-rotated ticket keys in Config and validating full certificate chain expiry - CVE-2025-61726: limit parsed URL query parameters to mitigate excessive memory consumption during form parsing - CVE-2025-61729: fix excessive resource consumption when constructing hostname error messages for certificates with many SANs
Updated packages:
  • containernetworking-plugins-1.6.2-2.el9_6.tuxcare.els1.x86_64.rpm
    sha:f3e7a627586076fd71642cc34cd54985be3727f3dcac6dfa6d11a6761d91648c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.