{"id":"CLSA-2025-1763489872","summary":"runc: Fix of 3 CVEs","details":"- rebuild with newer golang to fix security vulnerabilities:\n- CVE-2023-45287: fix RSA-based TLS key exchange timing attack vulnerability\n- CVE-2024-24788: fix DNS resolver infinite loop causing denial of service\n- CVE-2023-39321: fix QUIC post-handshake message processing causing panic\n  and denial of service","modified":"2026-05-27T11:34:56.900423128Z","published":"2025-11-18T18:17:56Z","upstream":["CVE-2023-39321","CVE-2023-45287","CVE-2024-24788"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1763489872.html"}],"affected":[{"package":{"name":"runc","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/runc?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4:1.1.4-1.el9_1.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1763489872.json"}}],"schema_version":"1.7.5"}