|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2026-8729dce4b8 (pack)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 44 Update: pack-0.40.8-1.fc44
Date:  Fri, 31 Jul 2026 00:59:24 +0000
Message-ID:  <20260731005924.705E8793B1@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8729dce4b8 2026-07-31 00:54:29.804794+00:00 -------------------------------------------------------------------------------- Name : pack Product : Fedora 44 Version : 0.40.8 Release : 1.fc44 URL : https://github.com/buildpacks/pack Summary : Convert code into runnable images Description : pack is a CLI implementation of the Platform Interface Specification for Cloud Native Buildpacks. -------------------------------------------------------------------------------- Update Information: Security update to pack 0.40.8 Fixes CVE-2024-25621: containerd - local privilege escalation Fixes CVE-2025-47913: golang.org/x/crypto/ssh/agent - SSH client panic Fixes CVE-2025-47914: golang.org/x/crypto/ssh/agent - SSH Agent server DoS Fixes CVE-2025-52881: container escape and denial of service Fixes CVE-2026-27145: crypto/x509 - DoS via excessive DNS SAN processing Fixes CVE-2026-33762: go-git - DoS via crafted Git index file Fixes CVE-2026-34165: go-git - DoS via crafted .idx file Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution Fixes CVE-2026-39829: golang.org/x/crypto/ssh - DoS via crafted public key Fixes CVE-2026-39830: golang.org/x/crypto/ssh - Resource leak DoS Fixes CVE-2026-39832: golang.org/x/crypto/ssh/agent - Key restrictions bypass Fixes CVE-2026-39833: golang.org/x/crypto/ssh/agent - Key confirmation bypass Fixes CVE-2026-39835: golang.org/x/crypto/ssh - Certificate DoS Fixes CVE-2026-44740: go-billy - DoS via symlink cycle Fixes GO-2026-4970: Root escape via symlink plus trailing slash Fixes GO-2026-5856: Encrypted Client Hello privacy leak -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 22 2026 Lokesh Mandvekar <lsm5@redhat.com> - 0.40.8-1 - Update to 0.40.8 * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.40.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419047 - CVE-2024-25621 pack: containerd local privilege escalation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419047 [ 2 ] Bug #2420625 - CVE-2025-47913 pack: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2420625 [ 3 ] Bug #2424069 - [Minor Incident] CVE-2025-52881 pack: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424069 [ 4 ] Bug #2454569 - CVE-2026-34165 pack: go-git: Denial of Service via crafted .idx file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454569 [ 5 ] Bug #2454570 - CVE-2026-33762 pack: go-git: Denial of Service via crafted Git index file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454570 [ 6 ] Bug #2478228 - pack-0.40.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2478228 [ 7 ] Bug #2489893 - CVE-2026-39828 pack: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2489893 [ 8 ] Bug #2490092 - CVE-2026-39829 pack: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490092 [ 9 ] Bug #2490496 - CVE-2026-39830 pack: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2490496 [ 10 ] Bug #2493089 - CVE-2026-39832 pack: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493089 [ 11 ] Bug #2493535 - CVE-2026-39835 pack: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2493535 [ 12 ] Bug #2494334 - CVE-2026-27145 pack: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494334 [ 13 ] Bug #2494451 - CVE-2026-39833 pack: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494451 [ 14 ] Bug #2496516 - CVE-2026-44740 pack: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2496516 [ 15 ] Bug #2503325 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2503325 [ 16 ] Bug #2503623 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2503623 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8729dce4b8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds