Red Hat Security Advisory: container-tools:rhel8 security update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
The vulnerability CVE-2026-34986 affects the buildah package, which facilitates building OCI container images on Red Hat Enterprise Linux 9 and related platforms. The issue is a denial of service vulnerability in the Go JOSE library (versions 3 and 4) triggered by crafted JSON Web Encryption (JWE) objects. Red Hat has issued security advisories (RHSA-2026:10135 and RHSA-2026:17458) and released patched versions of buildah (1.41.8-3.el9_7) to remediate this vulnerability. The affected products include multiple Red Hat Enterprise Linux 9 variants and related container and Kubernetes management components. No active exploitation has been reported.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition in the buildah tool by processing specially crafted JWE objects. This may disrupt container image building processes on affected systems. There are no reports of active exploitation in the wild. The vulnerability is rated as high severity by Red Hat Product Security.
Mitigation Recommendations
An official patch is available and has been released by Red Hat in buildah version 1.41.8-3.el9_7 and related packages. Users and administrators should apply the security updates provided by Red Hat as detailed in the advisories RHSA-2026:10135 and RHSA-2026:17458. No additional mitigation actions are specified or required beyond applying the official updates.
Red Hat Security Advisory: container-tools:rhel8 security update
Description
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) * golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) * golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey (CVE-2026-42508) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-34986 affects the buildah package, which facilitates building OCI container images on Red Hat Enterprise Linux 9 and related platforms. The issue is a denial of service vulnerability in the Go JOSE library (versions 3 and 4) triggered by crafted JSON Web Encryption (JWE) objects. Red Hat has issued security advisories (RHSA-2026:10135 and RHSA-2026:17458) and released patched versions of buildah (1.41.8-3.el9_7) to remediate this vulnerability. The affected products include multiple Red Hat Enterprise Linux 9 variants and related container and Kubernetes management components. No active exploitation has been reported.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition in the buildah tool by processing specially crafted JWE objects. This may disrupt container image building processes on affected systems. There are no reports of active exploitation in the wild. The vulnerability is rated as high severity by Red Hat Product Security.
Mitigation Recommendations
An official patch is available and has been released by Red Hat in buildah version 1.41.8-3.el9_7 and related packages. Users and administrators should apply the security updates provided by Red Hat as detailed in the advisories RHSA-2026:10135 and RHSA-2026:17458. No additional mitigation actions are specified or required beyond applying the official updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:10135
- Cve Count
- 1
Threat ID: 6a16095ce29bf47b506253b8
Added to database: 05/26/2026, 20:58:04 UTC
Last enriched: 08/15/2026, 00:27:52 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.