Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8633 - Security Advisory
Issued:
2025-06-09
Updated:
2025-06-09

RHSA-2025:8633 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: skopeo security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for skopeo is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

  • net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2358493 - CVE-2025-22871 net/http: Request smuggling due to acceptance of invalid chunked data in net/http

CVEs

  • CVE-2025-22871

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
x86_64
skopeo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: d3f723328d879b3d39d12584bb18b74ed4c61708128afce44bba72160fca5ded
skopeo-debuginfo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: 1c8873fc2073f9337f642324534bc64004e70e954669a66928a9b682a1f9b2d3
skopeo-debugsource-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: b3367c4fd93620b66aaad6a1d07a3f8df189ffe2231ec575aa4a06ec0c07a022
skopeo-tests-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: c9face4aeed5ef9dbe73eea58a867e1359e3edcbbf97cabc1850628d80b2163c

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
x86_64
skopeo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: d3f723328d879b3d39d12584bb18b74ed4c61708128afce44bba72160fca5ded
skopeo-debuginfo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: 1c8873fc2073f9337f642324534bc64004e70e954669a66928a9b682a1f9b2d3
skopeo-debugsource-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: b3367c4fd93620b66aaad6a1d07a3f8df189ffe2231ec575aa4a06ec0c07a022
skopeo-tests-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: c9face4aeed5ef9dbe73eea58a867e1359e3edcbbf97cabc1850628d80b2163c

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
s390x
skopeo-1.14.5-2.el9_4.1.s390x.rpm SHA-256: f0b46544f41dcbea5d1fb86a8abae0b29ffff0805de7941fa0755f414173a052
skopeo-debuginfo-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 2ea7842027b61bfc6d821bebaf2252cc0111d16d34238607adcb2a88aac101f9
skopeo-debugsource-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 39822373791d80ae9dad3468b644bd72c807e5a1af53bbdabb7834aa8a37e8f7
skopeo-tests-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 4b22176b5e6fd54581ee3a56c417e59dcd6ce6bf3b3f87ecb4b9ae28d0b0074b

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
ppc64le
skopeo-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: aa53135df0a382d2043f6c48edba0eb224190f4aef5f9a9333b43ee6efa51cc7
skopeo-debuginfo-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: ab4bf2847ca2eca8f9bfaa0baf3ac3cff525c708cff653967acb340a07a8ffbe
skopeo-debugsource-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: c78c1f59109e0c6c0ab1d8e97b413b52f93df4167859e64f475d34868d33fbe9
skopeo-tests-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: 4be57ed0e8329546d8b0dd24d94203dbfc74948c29bf49eb705c1eb30e21e6e9

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
aarch64
skopeo-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 481704da3aba0027594c58c799f778e2a8d86d530282f0b95b5b5ceeac45c4d0
skopeo-debuginfo-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: c4cb414ff21df8a112d2d77d99d68965d50b146b854f6d62ceff184dd9db7595
skopeo-debugsource-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 2ea73a79349b550afb4b7c4d156685802a6905df2c2a019547a5a2af82fa8477
skopeo-tests-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 7fea1d597a2acce062c9ffa1ab1670bc1239b6d7f3404d1b5c6c75e42bd07548

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
ppc64le
skopeo-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: aa53135df0a382d2043f6c48edba0eb224190f4aef5f9a9333b43ee6efa51cc7
skopeo-debuginfo-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: ab4bf2847ca2eca8f9bfaa0baf3ac3cff525c708cff653967acb340a07a8ffbe
skopeo-debugsource-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: c78c1f59109e0c6c0ab1d8e97b413b52f93df4167859e64f475d34868d33fbe9
skopeo-tests-1.14.5-2.el9_4.1.ppc64le.rpm SHA-256: 4be57ed0e8329546d8b0dd24d94203dbfc74948c29bf49eb705c1eb30e21e6e9

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
x86_64
skopeo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: d3f723328d879b3d39d12584bb18b74ed4c61708128afce44bba72160fca5ded
skopeo-debuginfo-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: 1c8873fc2073f9337f642324534bc64004e70e954669a66928a9b682a1f9b2d3
skopeo-debugsource-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: b3367c4fd93620b66aaad6a1d07a3f8df189ffe2231ec575aa4a06ec0c07a022
skopeo-tests-1.14.5-2.el9_4.1.x86_64.rpm SHA-256: c9face4aeed5ef9dbe73eea58a867e1359e3edcbbf97cabc1850628d80b2163c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
aarch64
skopeo-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 481704da3aba0027594c58c799f778e2a8d86d530282f0b95b5b5ceeac45c4d0
skopeo-debuginfo-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: c4cb414ff21df8a112d2d77d99d68965d50b146b854f6d62ceff184dd9db7595
skopeo-debugsource-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 2ea73a79349b550afb4b7c4d156685802a6905df2c2a019547a5a2af82fa8477
skopeo-tests-1.14.5-2.el9_4.1.aarch64.rpm SHA-256: 7fea1d597a2acce062c9ffa1ab1670bc1239b6d7f3404d1b5c6c75e42bd07548

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
skopeo-1.14.5-2.el9_4.1.src.rpm SHA-256: d9e6cb9b173c31ab90ce722c6ca8a5fb8a4d39f8999fa7ff09e9ec8140ec4031
s390x
skopeo-1.14.5-2.el9_4.1.s390x.rpm SHA-256: f0b46544f41dcbea5d1fb86a8abae0b29ffff0805de7941fa0755f414173a052
skopeo-debuginfo-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 2ea7842027b61bfc6d821bebaf2252cc0111d16d34238607adcb2a88aac101f9
skopeo-debugsource-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 39822373791d80ae9dad3468b644bd72c807e5a1af53bbdabb7834aa8a37e8f7
skopeo-tests-1.14.5-2.el9_4.1.s390x.rpm SHA-256: 4b22176b5e6fd54581ee3a56c417e59dcd6ce6bf3b3f87ecb4b9ae28d0b0074b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility