containernetworking-plugins (1.9.1-ubuntu24.04u28) noble; urgency=low

  * [HIGH] CVE-2024-1394 in containernetworking-plugins (1.9.1-1.el9) - golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA paylo...
  * [HIGH] CVE-2024-34156 in containernetworking-plugins (1.9.1-1.el9) - encoding/gob: golang: Calling Decoder.Decode on a message which contains deep...
  * [HIGH] CVE-2025-61726 in containernetworking-plugins (1.9.1-1.el9) - golang: net/url: Memory exhaustion in query parameter parsing in net/url
  * [HIGH] CVE-2025-61729 in containernetworking-plugins (1.9.1-1.el9) - crypto/x509: golang: Denial of Service due to excessive resource consumption...
  * [HIGH] CVE-2025-68121 in containernetworking-plugins (1.9.1-1.el9) - crypto/tls: crypto/tls: Incorrect certificate validation during TLS session r...
  * [HIGH] CVE-2026-25679 in containernetworking-plugins (1.9.1-1.el9) - net/url: Incorrect parsing of IPv6 host literals in net/url
  * [HIGH] CVE-2026-32280 in containernetworking-plugins (1.9.1-1.el9) - crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certi...
  * [HIGH] CVE-2026-32281 in containernetworking-plugins (1.9.1-1.el9) - crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certif...
  * [HIGH] CVE-2026-32283 in containernetworking-plugins (1.9.1-1.el9) - crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key...
  * [MEDIUM] CVE-2022-30629 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: session tickets lack random ticket_age_add
  * [MEDIUM] CVE-2022-41717 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http: excessive memory growth in a Go server accepting HTTP/2 req...
  * [MEDIUM] CVE-2022-41723 in containernetworking-plugins (1.9.1-1.el9) - golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
  * [MEDIUM] CVE-2022-41724 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: large handshake records may cause panics
  * [MEDIUM] CVE-2022-41725 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http, mime/multipart: denial of service from excessive resource c...
  * [MEDIUM] CVE-2023-24534 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http, net/textproto: denial of service from excessive memory allo...
  * [MEDIUM] CVE-2023-24536 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http, net/textproto, mime/multipart: denial of service from exces...
  * [MEDIUM] CVE-2023-24538 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: backticks not treated as string delimiters
  * [MEDIUM] CVE-2023-24539 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: improper sanitization of CSS values
  * [MEDIUM] CVE-2023-24540 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: improper handling of JavaScript whitespace
  * [MEDIUM] CVE-2023-29400 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: improper handling of empty HTML attributes
  * [MEDIUM] CVE-2023-29406 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http: insufficient sanitization of Host header
  * [MEDIUM] CVE-2023-29409 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: slow verification of certificate chains containing large...
  * [MEDIUM] CVE-2023-39318 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: improper handling of HTML-like comments within script...
  * [MEDIUM] CVE-2023-39319 in containernetworking-plugins (1.9.1-1.el9) - golang: html/template: improper handling of special tags within script contex...
  * [MEDIUM] CVE-2023-39321 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: panic when processing post-handshake message on QUIC conn...
  * [MEDIUM] CVE-2023-39322 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: lack of a limit on buffered post-handshake
  * [MEDIUM] CVE-2023-39326 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http/internal: Denial of Service (DoS) via Resource Consumption v...
  * [MEDIUM] CVE-2023-45287 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges...
  * [MEDIUM] CVE-2023-45290 in containernetworking-plugins (1.9.1-1.el9) - golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhau...
  * [MEDIUM] CVE-2024-24783 in containernetworking-plugins (1.9.1-1.el9) - golang: crypto/x509: Verify panics on certificates with an unknown public key...
  * [MEDIUM] CVE-2024-24788 in containernetworking-plugins (1.9.1-1.el9) - golang: net: malformed DNS message can cause infinite loop
  * [MEDIUM] CVE-2024-24791 in containernetworking-plugins (1.9.1-1.el9) - net/http: Denial of service due to improper 100-continue handling in net/http
  * [MEDIUM] CVE-2025-22871 in containernetworking-plugins (1.9.1-1.el9) - net/http: Request smuggling due to acceptance of invalid chunked data in net/...
 -- azcu-bot <azcu-publishing@microsoft.com>  Fri, 24 Jul 2026 00:00:00 +0000

