--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2026-82f07c2a59
2026-02-26 00:57:00.907714+00:00
--------------------------------------------------------------------------------

Name        : apptainer
Product     : Fedora EPEL 8
Version     : 1.4.5
Release     : 3.el8
URL         : https://apptainer.org
Summary     : Application and environment virtualization formerly known as 
Singularity
Description :
Apptainer provides functionality to make portable
containers that can be used across host environments.

--------------------------------------------------------------------------------
Update Information:

Enable FIPS support.  This was built with golang-1.25.7 so it also fixes these
CVE's based on older golang versions: CVE-2025-61723, CVE-2025-61725,
CVE-2025-58183, CVE-2025-58185, CVE-2025-58188, and CVE-2025-58189.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb 17 2026 Dave Dykstra <[email protected]> - 1.4.5-3
- Enable FIPS support.  Fixes BZ#2437258.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2407504 - CVE-2025-58189 apptainer: go crypto/tls ALPN negotiation 
error contains attacker controlled information [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407504
  [ 2 ] Bug #2408539 - CVE-2025-61725 apptainer: Excessive CPU consumption in 
ParseAddress in net/mail [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408539
  [ 3 ] Bug #2408956 - CVE-2025-61723 apptainer: Quadratic complexity when 
parsing some invalid inputs in encoding/pem [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408956
  [ 4 ] Bug #2409898 - CVE-2025-58185 apptainer: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409898
  [ 5 ] Bug #2410838 - CVE-2025-58188 apptainer: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-8]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410838
  [ 6 ] Bug #2412476 - CVE-2025-58183 apptainer: Unbounded allocation when 
parsing GNU sparse map [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2412476
  [ 7 ] Bug #2437258 - Apptainer is compiled without FIPS support
        https://bugzilla.redhat.com/show_bug.cgi?id=2437258
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update apptainer' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to