Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 43 Chunkah Important Update Arbitrary Permissions Fix March 2026

fedora
Calendar Grey April 1, 2026
Dist Fedora Esm H88
Chunkah update for Fedora 43 addresses important permission modifications via crafted tar archive vulnerabilities.
Automatic update for chunkah-0.3.2-1.fc43

Summary

chunkah is an OCI building tool that takes a flat rootfs and outputs a

layered OCI image with content-based layers. It optimizes container image

layer reuse by grouping files based on their content (e.g., by RPM package)

rather than by Dockerfile instruction order.

It is a generalized successor to rpm-ostree's build-chunked-oci command.

Update Information:

Automatic update for chunkah-0.3.2-1.fc43. Changelog for chunkah * Mon Mar 23 2026 Packit - 0.3.2-1 - Update to 0.3.2 upstream release * Fri Mar 20 2026 Packit - 0.3.1-1 - Update to 0.3.1 upstream release Automatic update for chunkah-0.3.1-1.fc43. Changelog for chunkah * Fri Mar 20 2026 Packit - 0.3.1-1 - Update to 0.3.1 upstream release

Change Log

* Mon Mar 23 2026 Packit - 0.3.2-1 - Update to 0.3.2 upstream release * Fri Mar 20 2026 Packit - 0.3.1-1 - Update to 0.3.1 upstream release

References


[ 1 ] Bug #2449673 - CVE-2026-33056 chunkah: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449673

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1269948465' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: chunkah
Product: Fedora 43
Version: 0.3.2
Release: 1.fc43
Summary: OCI building tool for content-based container image layers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here