[CLSA-2026:1786706622] podman: Fix of CVE-2026-39829
Type:
security
Severity:
Important
Release date:
2026-08-14 11:23:52 UTC
Description:
- CVE-2026-39829: reject oversized RSA moduli (>8192 bits) and enforce strict DSA parameter limits (Q exactly 160 bits, in-range G and Y) in the vendored golang.org/x/crypto/ssh key parsers, preventing a CPU-exhaustion denial of service during signature verification
CVEs fixed:
Updated packages:
  • podman-4.4.1-13.el9_2.tuxcare.els15.x86_64.rpm
    sha:4b22634ebd515f7bd09d82b4419054ddc9165b31e2216350be315067584f3075
  • podman-docker-4.4.1-13.el9_2.tuxcare.els15.noarch.rpm
    sha:92332888f603a5e5efcd609a9e6858bb3a14d45d97811bcdd57f36f237bac578
  • podman-gvproxy-4.4.1-13.el9_2.tuxcare.els15.x86_64.rpm
    sha:a1c82ac36bcf11b7883d781c3c7c70f4ac3c8ec5ef66aab5f43abf7598c02807
  • podman-plugins-4.4.1-13.el9_2.tuxcare.els15.x86_64.rpm
    sha:eb2aac3d33728b325ae02f3cc5223c5836fa270355efa3be652af025d57b2577
  • podman-remote-4.4.1-13.el9_2.tuxcare.els15.x86_64.rpm
    sha:bd372319c40759e798deea9c02c2a0c08fde6ca35ebb84d90eecd6f17e105f16
  • podman-tests-4.4.1-13.el9_2.tuxcare.els15.x86_64.rpm
    sha:4fe84f24d861a4624e3a1951ceb3f77079190cd429110a2d8644a0ebe9c0c03f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.