[CLSA-2026:1778661840] skopeo: Fix of CVE-2024-24786
Type:
security
Severity:
Moderate
Release date:
2026-05-13 08:44:04 UTC
Description:
- CVE-2024-24786: fix infinite loop in vendored google.golang.org/protobuf protojson.Unmarshal on malformed JSON by handling EOF in skipJSONValue and rejecting ObjectClose after a Name token in Decoder.Read
Updated packages:
  • skopeo-1.11.2-0.1.el9.tuxcare.els5.x86_64.rpm
    sha:f52edc49556c9d4715c66383d89b4b2677838ec09826d72f85ab0eadcb286837
  • skopeo-tests-1.11.2-0.1.el9.tuxcare.els5.x86_64.rpm
    sha:00af9d09192b3c755cd36f3894e61e8b594ddfe45c7d5a6eec815acc28a34fbd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.