1
0

Update submodules from pool/ctop#2 and create patchinfo.20260716103918513562.93181000773252/_patchinfo

This commit is contained in:
2026-07-16 12:39:18 +02:00
parent 36014d8696
commit 00faed4a91
2 changed files with 28 additions and 1 deletions
+1 -1
Submodule ctop updated: e73e88ec78...6f9aa5d5ed
@@ -0,0 +1,27 @@
<patchinfo>
<issue tracker="bnc" id="1248710">VUL-0: CVE-2022-21698: ctop: github.com/prometheus/client_golang/prometheus/promhttp: Denial of service using InstrumentHandlerCounter</issue>
<issue tracker="cve" id="2024-45310"/>
<issue tracker="cve" id="2026-10722"/>
<issue tracker="cve" id="2026-39821"/>
<issue tracker="bnc" id="1265800">VUL-0: CVE-2026-33814: ctop: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE</issue>
<issue tracker="bnc" id="1266632">VUL-0: CVE-2026-39821: ctop: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation</issue>
<issue tracker="cve" id="2022-21698"/>
<issue tracker="cve" id="2026-33814"/>
<issue tracker="bnc" id="1257431">VUL-0: CVE-2024-45310: ctop: github.com/opencontainers/runc/libcontainer/utils: runc can be tricked into creating empty files/directories on host</issue>
<issue tracker="bnc" id="1267805">VUL-0: CVE-2026-10722: ctop: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input</issue>
<packager>jubalh</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for ctop</summary>
<description>This update for ctop fixes the following issues:
Changes in ctop embedded dependencies:
- CVE-2022-21698: client_golang: Denial of service using InstrumentHandlerCounter (bsc#1248710)
- CVE-2024-45310: runc: runc can be tricked into creating empty files (bsc#1257431)
- CVE-2026-10722: ebpf: Crash when parsing malformed ELF/BTF input (bsc#1267805)
- CVE-2026-33814: net: Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265800)
- CVE-2026-39821: net: Failure to reject ASCII-only Punycode-encoded labels (bsc#1266632)
</description>
<package>ctop</package>
</patchinfo>