public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/buildah] update-buildah-cve-2026-46597: rebuild for CVE-2026-39822
@ 2026-08-05 18:47 Jindrich Novy
0 siblings, 0 replies; only message in thread
From: Jindrich Novy @ 2026-08-05 18:47 UTC (permalink / raw)
To: git-commits
A new commit has been pushed.
Repo : rpms/buildah
Branch : update-buildah-cve-2026-46597
Commit : cad0ec1eedb0c63e983678710278718fd67f6f2b
Author : Jindrich Novy <jnovy@redhat.com>
Date : 2026-07-10T07:49:34+02:00
Stats : +5/-1 in 1 file(s)
URL : https://src.fedoraproject.org/rpms/buildah/c/cad0ec1eedb0c63e983678710278718fd67f6f2b?branch=update-buildah-cve-2026-46597
Log:
rebuild for CVE-2026-39822
Rebuild buildah against golang-1.26.5 which fixes
CVE-2026-39822 (Go os.Root symlink following vulnerability).
Resolves: RHEL-193645
Signed-off-by: Jindrich Novy <jnovy@redhat.com>
---
diff --git a/buildah.spec b/buildah.spec
index e264377..38153fd 100644
--- a/buildah.spec
+++ b/buildah.spec
@@ -40,7 +40,7 @@ Epoch: 2
Version: 1.43.1
# The `AND` needs to be uppercase in the License for SPDX compatibility
License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0
-Release: 3%{?dist}
+Release: 4%{?dist}
%if %{defined golang_arches_future}
ExclusiveArch: %{golang_arches_future}
%else
@@ -206,6 +206,10 @@ rm %{buildroot}%{_datadir}/%{name}/test/system/tools/build/*
%{_datadir}/%{name}/test
%changelog
+* Fri Jul 10 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.43.1-4
+- rebuild for CVE-2026-39822
+- Resolves: RHEL-193645
+
* Wed Jul 08 2026 Jindrich Novy <jnovy@redhat.com> - 2:1.43.1-3
- bump golang.org/x/crypto to v0.53.0 to fix CVE-2026-39832 and CVE-2026-39835
- Resolves: RHEL-188733 RHEL-190066
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-05 18:47 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-05 18:47 [rpms/buildah] update-buildah-cve-2026-46597: rebuild for CVE-2026-39822 Jindrich Novy
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox