Security update for skopeo
This update for skopeo fixes the following issues: - CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238685) - CVE-2025-27144: gopkg.in/square/go-jose.v2,gopkg.in/go-jose/go-jose.v2,github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237613) - CVE-2024-6104: hashicorp/go-retryablehttp: url might write sensitive information to log file (bsc#1227056) - CVE-2023-45288: golang.org/x/net/http2: close connections when receiving too many headers (bsc#1236483)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for skopeo fixes the following issues: - CVE-2025-22870: golang.org/x/net/proxy: proxy bypass using IPv6 zone IDs (bsc#1238685) - CVE-2025-27144: gopkg.in/square/go-jose.v2,gopkg.in/go-jose/go-jose.v2,github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237613) - CVE-2024-6104: hashicorp/go-retryablehttp: url might write sensitive information to log file (bsc#1227056) - CVE-2023-45288: golang.org/x/net/http2: close connections when receiving too many headers (bsc#1236483)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1227056
- https://bugzilla.suse.com/1236483
- https://bugzilla.suse.com/1237613
- https://bugzilla.suse.com/1238685
- https://www.suse.com/security/cve/CVE-2023-45288
- https://www.suse.com/security/cve/CVE-2024-6104
- https://www.suse.com/security/cve/CVE-2025-22870
- https://www.suse.com/security/cve/CVE-2025-27144
- https://www.suse.com/support/update/announcement/2025/suse-su-202520179-1/