Synopsis
Important: containernetworking-plugins security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.
Security Fix(es):
- crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
- golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)
- crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)
- net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.6 x86_64
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x
Fixes
-
BZ - 2418462
- CVE-2025-61729 crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
-
BZ - 2434432
- CVE-2025-61726 golang: net/url: Memory exhaustion in query parameter parsing in net/url
-
BZ - 2437111
- CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
-
BZ - 2445356
- CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| x86_64 |
|
containernetworking-plugins-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e6ffe73407c29521c79902e94c32576296dd96b4af83e2af3db483e3a4ecbf07 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e33768f01e16f45af73f15645d486723838c694780742cf36da9b2788a54a90b |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: 3cf33595d609b354e7f4d626c50bd33b70f43e1e29eec1f5df82e82c5a9f25b2 |
Red Hat Enterprise Linux Server - AUS 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| x86_64 |
|
containernetworking-plugins-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e6ffe73407c29521c79902e94c32576296dd96b4af83e2af3db483e3a4ecbf07 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e33768f01e16f45af73f15645d486723838c694780742cf36da9b2788a54a90b |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: 3cf33595d609b354e7f4d626c50bd33b70f43e1e29eec1f5df82e82c5a9f25b2 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| s390x |
|
containernetworking-plugins-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a3dd62da4d96fd2a5da87a113dca1659c97b1efa6d83477d42e9d6cb952e13c3 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a55663e798104b5e0a83977e6927b62ce1d48a1ffe01636924d41e21d274b586 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: 750382a55240c5efd10951a64f1e183b0d86d481133951d047aa61166c5b6fb4 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| ppc64le |
|
containernetworking-plugins-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: bf22e22e4597aa761efbf24cc4de562bb9a127d874023f35492ca3bb85700a29 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: a2c063eac1512b339433f56c5264078464f5bc19021025c7fdd7f703b40b7d33 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: ce25c98e5f9918d046112fbd0847fa5884dbe6c6e5c11973e514ff678a0d54a7 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| aarch64 |
|
containernetworking-plugins-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 4661ab5dad67645af20872ea7c658705c1afd94d70e04a53de62565ea8a79440 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 940da286d81485eda5df2b118ee799f0ceef81c2b0bf28808f10fe232409fa6c |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 95e69e168b6511802a773fcd843be7fc68644b1a124b03b4708debeb4c1754bc |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| ppc64le |
|
containernetworking-plugins-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: bf22e22e4597aa761efbf24cc4de562bb9a127d874023f35492ca3bb85700a29 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: a2c063eac1512b339433f56c5264078464f5bc19021025c7fdd7f703b40b7d33 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: ce25c98e5f9918d046112fbd0847fa5884dbe6c6e5c11973e514ff678a0d54a7 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| x86_64 |
|
containernetworking-plugins-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e6ffe73407c29521c79902e94c32576296dd96b4af83e2af3db483e3a4ecbf07 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e33768f01e16f45af73f15645d486723838c694780742cf36da9b2788a54a90b |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: 3cf33595d609b354e7f4d626c50bd33b70f43e1e29eec1f5df82e82c5a9f25b2 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| aarch64 |
|
containernetworking-plugins-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 4661ab5dad67645af20872ea7c658705c1afd94d70e04a53de62565ea8a79440 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 940da286d81485eda5df2b118ee799f0ceef81c2b0bf28808f10fe232409fa6c |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 95e69e168b6511802a773fcd843be7fc68644b1a124b03b4708debeb4c1754bc |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| s390x |
|
containernetworking-plugins-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a3dd62da4d96fd2a5da87a113dca1659c97b1efa6d83477d42e9d6cb952e13c3 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a55663e798104b5e0a83977e6927b62ce1d48a1ffe01636924d41e21d274b586 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: 750382a55240c5efd10951a64f1e183b0d86d481133951d047aa61166c5b6fb4 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| x86_64 |
|
containernetworking-plugins-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e6ffe73407c29521c79902e94c32576296dd96b4af83e2af3db483e3a4ecbf07 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: e33768f01e16f45af73f15645d486723838c694780742cf36da9b2788a54a90b |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.x86_64.rpm
|
SHA-256: 3cf33595d609b354e7f4d626c50bd33b70f43e1e29eec1f5df82e82c5a9f25b2 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| aarch64 |
|
containernetworking-plugins-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 4661ab5dad67645af20872ea7c658705c1afd94d70e04a53de62565ea8a79440 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 940da286d81485eda5df2b118ee799f0ceef81c2b0bf28808f10fe232409fa6c |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.aarch64.rpm
|
SHA-256: 95e69e168b6511802a773fcd843be7fc68644b1a124b03b4708debeb4c1754bc |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| ppc64le |
|
containernetworking-plugins-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: bf22e22e4597aa761efbf24cc4de562bb9a127d874023f35492ca3bb85700a29 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: a2c063eac1512b339433f56c5264078464f5bc19021025c7fdd7f703b40b7d33 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.ppc64le.rpm
|
SHA-256: ce25c98e5f9918d046112fbd0847fa5884dbe6c6e5c11973e514ff678a0d54a7 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6
| SRPM |
|
containernetworking-plugins-1.6.2-3.el9_6.src.rpm
|
SHA-256: f4f0f74d1d7ee9d4b64ffe751961e7824c064a294d034aa9f1212d39966f5a4a |
| s390x |
|
containernetworking-plugins-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a3dd62da4d96fd2a5da87a113dca1659c97b1efa6d83477d42e9d6cb952e13c3 |
|
containernetworking-plugins-debuginfo-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: a55663e798104b5e0a83977e6927b62ce1d48a1ffe01636924d41e21d274b586 |
|
containernetworking-plugins-debugsource-1.6.2-3.el9_6.s390x.rpm
|
SHA-256: 750382a55240c5efd10951a64f1e183b0d86d481133951d047aa61166c5b6fb4 |