Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:9018 - Security Advisory
Issued:
2025-06-12
Updated:
2025-06-12

RHSA-2025:9018 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: skopeo security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for skopeo is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.

Security Fix(es):

  • net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2358493 - CVE-2025-22871 net/http: Request smuggling due to acceptance of invalid chunked data in net/http

CVEs

  • CVE-2025-22871

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
skopeo-1.11.2-0.1.el9_2.3.src.rpm SHA-256: 96f8a4fa2026a6dced30e8f1278f6e51b47ac1915f8025808ad6eb51a8698c69
x86_64
skopeo-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: dbeadbef94fc6236a6abd2e030d83958e13e0142642e8c1a844fc21434dd2d71
skopeo-debuginfo-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: 3749c694f872236f49552ea99974e63bcfaf94070c4bd8b593b31a0a9e0d1c0f
skopeo-debugsource-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: a7df69a86fa7508c9ecce63cfddd83728e988b0ce1f25b1fc6e3b08ddb37646a
skopeo-tests-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: 29314f85bfcb1e1ce5bac214e24d3e13bbd9583bf1b49259c05ac79fcf4acb62

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
skopeo-1.11.2-0.1.el9_2.3.src.rpm SHA-256: 96f8a4fa2026a6dced30e8f1278f6e51b47ac1915f8025808ad6eb51a8698c69
ppc64le
skopeo-1.11.2-0.1.el9_2.3.ppc64le.rpm SHA-256: acd41409f9a512111789c88914943082a944fc97f48156f480e61401fea9e7de
skopeo-debuginfo-1.11.2-0.1.el9_2.3.ppc64le.rpm SHA-256: a9090adf2c16eca05347788662f81b116f1fdee3f7feef176594b687e03d3bee
skopeo-debugsource-1.11.2-0.1.el9_2.3.ppc64le.rpm SHA-256: 4b8b211fa517fc6d1c2d858a8d06e92f8e000846866bb4f4eb44bfc96dc3874e
skopeo-tests-1.11.2-0.1.el9_2.3.ppc64le.rpm SHA-256: d20151a0dd5aaa181f4d652233810e9574c39e5424c922b2568d1b33d8e9e4fc

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
skopeo-1.11.2-0.1.el9_2.3.src.rpm SHA-256: 96f8a4fa2026a6dced30e8f1278f6e51b47ac1915f8025808ad6eb51a8698c69
x86_64
skopeo-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: dbeadbef94fc6236a6abd2e030d83958e13e0142642e8c1a844fc21434dd2d71
skopeo-debuginfo-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: 3749c694f872236f49552ea99974e63bcfaf94070c4bd8b593b31a0a9e0d1c0f
skopeo-debugsource-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: a7df69a86fa7508c9ecce63cfddd83728e988b0ce1f25b1fc6e3b08ddb37646a
skopeo-tests-1.11.2-0.1.el9_2.3.x86_64.rpm SHA-256: 29314f85bfcb1e1ce5bac214e24d3e13bbd9583bf1b49259c05ac79fcf4acb62

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
skopeo-1.11.2-0.1.el9_2.3.src.rpm SHA-256: 96f8a4fa2026a6dced30e8f1278f6e51b47ac1915f8025808ad6eb51a8698c69
aarch64
skopeo-1.11.2-0.1.el9_2.3.aarch64.rpm SHA-256: 43fa2d9e1fa38e2a39fd7894bdb1f6f385862b95377bbca66c448aa0868c7a7e
skopeo-debuginfo-1.11.2-0.1.el9_2.3.aarch64.rpm SHA-256: 33cf02b0156a1938daaaeaba7ae885a1432f51c57c387fb61d327adf4dead43e
skopeo-debugsource-1.11.2-0.1.el9_2.3.aarch64.rpm SHA-256: d3d5f0c89d9b51e3ef3beb8c068a867dd5fd98266d8177e5f361eeb5c1621d60
skopeo-tests-1.11.2-0.1.el9_2.3.aarch64.rpm SHA-256: 497f9f4174e84102571fcdb785e7ae3e941a63855e0f38ff326550a68f5bde54

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
skopeo-1.11.2-0.1.el9_2.3.src.rpm SHA-256: 96f8a4fa2026a6dced30e8f1278f6e51b47ac1915f8025808ad6eb51a8698c69
s390x
skopeo-1.11.2-0.1.el9_2.3.s390x.rpm SHA-256: 5e4ab757c7a1ff7585c2d898ffb7562998af5483f425fd01e35c14a7d5afe823
skopeo-debuginfo-1.11.2-0.1.el9_2.3.s390x.rpm SHA-256: a23fe5d54fc44738f37ba6f27bf8e67d7d37160cec375e6501b47fca54b5e6f0
skopeo-debugsource-1.11.2-0.1.el9_2.3.s390x.rpm SHA-256: 77c9ab0f79494f0a4227613049b6dea10ecaed21fc56a1d35f49672dc22e4612
skopeo-tests-1.11.2-0.1.el9_2.3.s390x.rpm SHA-256: 21568858a37ee25507bf16181495f5d64914a1229c615505192ce400c367d8c4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility