Resolve CVE-2025-47910. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e36ffc5112 2025-10-05 00:48:00.108269+00:00 -------------------------------------------------------------------------------- Name : containernetworking-plugins Product : Fedora 42 Version : 1.8.0 Release : 2.fc42 URL : https://github.com/containernetworking/plugins Summary : Reference and example networking plugins, maintained by the CNI team Description : Reference and example networking plugins, maintained by the CNI team. The CNI (Container Network Interface) project consists of a specification and libraries for writing plugins to configure network interfaces in Linux containers, along with a number of supported plugins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. -------------------------------------------------------------------------------- Update Information: Resolve CVE-2025-47910 -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 26 2025 Bradley G Smith - 1.8.0-2 - Resolve CVE-2025-47910 - Resolves: rhbz#2398656, rhbz#2398402 - Rebuild with go 1.25.1 (fc44, fc43) or 1.24.7 (fc42, fc41) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398402 - CVE-2025-47910 containernetworking-plugins: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398402 [ 2 ] Bug #2398656 - CVE-2025-47910 containernetworking-plugins: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398656 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e36ffc5112' at the command line.For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.