Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 42 CRI-O 1.31.13 Critical Cross-Origin Vulnerability Resolution

fedora
Calendar Grey October 11, 2025
Dist Fedora Esm H88
Fedora 42 has released an important update for cri-o1.31 resolving multiple security issues and enhancing stability.
Update to release v1.31.13 Resolves: rhbz#2333357, rhbz#2398406, rhbz#2398661, rhbz#2399063, rhbz#2399337 Upstream fix

Summary

Open Container Initiative-based implementation of Kubernetes Container Runtime

Interface.

Update Information:

Update to release v1.31.13 Resolves: rhbz#2333357, rhbz#2398406, rhbz#2398661, rhbz#2399063, rhbz#2399337 Upstream fix

Change Log

* Thu Oct 2 2025 Bradley G Smith - 1.31.13-1 - Update to release v1.31.13 - Resolves: rhbz#2333357, rhbz#2398406, rhbz#2398661, rhbz#2399063, rhbz#2399337 - Upstream fix

References


[ 1 ] Bug #2333357 - cri-o-1.34.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2333357 [ 2 ] Bug #2398406 - CVE-2025-47910 cri-o1.31: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398406 [ 3 ] Bug #2398661 - CVE-2025-47910 cri-o1.31: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398661 [ 4 ] Bug #2399063 - CVE-2025-47906 cri-o1.31: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399063 [ 5 ] Bug #2399337 - CVE-2025-47906 cri-o1.31: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399337

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-51d26ffda5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: cri-o1.31
Product: Fedora 42
Version: 1.31.13
Release: 1.fc42
Summary: Open Container Initiative-based implementation of Kubernetes Container Runtime Interface

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here