File _patchinfo of Package patchinfo.38011
<patchinfo incident="38011">
<issue tracker="cve" id="2025-22870"/>
<issue tracker="cve" id="2024-45338"/>
<issue tracker="cve" id="2024-41110"/>
<issue tracker="cve" id="2024-45337"/>
<issue tracker="cve" id="2025-27144"/>
<issue tracker="cve" id="2025-22869"/>
<issue tracker="bnc" id="1237679">VUL-0: CVE-2025-27144: apptainer: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service</issue>
<issue tracker="bnc" id="1234794">VUL-0: CVE-2024-45338: TRACKERBUG: golang.org/x/net/html: denial of service due to non-linear parsing of case-insensitive content</issue>
<issue tracker="bnc" id="1234595">VUL-0: CVE-2024-45337: apptainer: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto</issue>
<issue tracker="bnc" id="1238611">VUL-0: CVE-2025-22870: TRACKERBUG: golang.org/net/http, golang.org/x/net/proxy, golang.org/x/net/http/httpproxy: proxy bypass using IPv6 zone IDs</issue>
<issue tracker="bnc" id="1239341">VUL-0: CVE-2025-22869: apptainer: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
<issue tracker="bnc" id="1228324">VUL-0: CVE-2024-41110: docker: Authz zero length regression</issue>
<packager>eeich</packager>
<rating>critical</rating>
<category>security</category>
<summary>Security update for apptainer</summary>
<description>This update for apptainer fixes the following issues:
- CVE-2025-27144: Fixed Denial of Service in Go JOSE's Parsing (bsc#1237679).
- CVE-2024-45338: Fixed denial of service due to non-linear parsing of case-insensitive content (bsc#1234794).
- CVE-2024-45337: Fixed Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234595).
- CVE-2025-22870: Fixed proxy bypass using IPv6 zone IDs (bsc#1238611).
- CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239341).
- CVE-2024-41110: Fixed Authz zero length regression (bsc#1228324).
</description>
</patchinfo>