File _patchinfo of Package patchinfo.38056
<patchinfo incident="38056">
<issue tracker="bnc" id="1239322">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
<issue tracker="bnc" id="1239185">VUL-0: CVE-2025-22868: TRACKERBUG: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2</issue>
<issue tracker="bnc" id="1237367">docker pulls in container-selinux unconditionally</issue>
<issue tracker="cve" id="2025-22869"/>
<issue tracker="cve" id="2024-2365"/>
<issue tracker="cve" id="2024-29018"/>
<issue tracker="cve" id="2025-22868"/>
<issue tracker="cve" id="2024-41110"/>
<packager>cyphar</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for docker, docker-stable</summary>
<description>This update for docker, docker-stable fixes the following issues:
- CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185).
- CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322).
Other fixes:
- Make container-selinux requirement conditional on selinux-policy (bsc#1237367)
</description>
</patchinfo>