Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12579

Опубликовано: 19 июл. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-12579: aardvark-dns security update (IMPORTANT)

runc [1:1.1.4-1.0.1]

  • rootless: fix /sys/fs/cgroup mounts to prevent CVE-2023-25809
  • rootfs: prohibit symlinks that conflicts with readonlyPaths and/or maskedPaths to prevent CVE-2023-27561
  • Prohibit /proc and /sys to be symlinks to prevent CVE-2023-28642
  • JIRA: OLDIS-25589

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module container-tools:ol8 is enabled

aardvark-dns

1.5.0-2.module+el8.8.0+21045+adcb6a64

buildah

1.29.1-2.module+el8.8.0+21056+d98a0860

buildah-tests

1.29.1-2.module+el8.8.0+21056+d98a0860

cockpit-podman

63.1-1.module+el8.8.0+21045+adcb6a64

conmon

2.1.6-1.module+el8.8.0+21045+adcb6a64

container-selinux

2.205.0-2.module+el8.8.0+21045+adcb6a64

containernetworking-plugins

1.2.0-1.module+el8.8.0+21045+adcb6a64

containers-common

1-64.0.1.module+el8.8.0+21056+d98a0860

crit

3.15-3.module+el8.8.0+21045+adcb6a64

criu

3.15-3.module+el8.8.0+21045+adcb6a64

criu-devel

3.15-3.module+el8.8.0+21045+adcb6a64

criu-libs

3.15-3.module+el8.8.0+21045+adcb6a64

crun

1.8.4-2.module+el8.8.0+21056+d98a0860

fuse-overlayfs

1.11-1.module+el8.8.0+21056+d98a0860

libslirp

4.4.0-1.module+el8.8.0+21045+adcb6a64

libslirp-devel

4.4.0-1.module+el8.8.0+21045+adcb6a64

netavark

1.5.0-5.module+el8.8.0+21056+d98a0860

oci-seccomp-bpf-hook

1.2.8-1.module+el8.8.0+21045+adcb6a64

podman

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-catatonit

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-docker

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-gvproxy

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-plugins

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-remote

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-tests

4.4.1-12.module+el8.8.0+21056+d98a0860

python3-criu

3.15-3.module+el8.8.0+21045+adcb6a64

python3-podman

4.4.1-1.module+el8.8.0+21045+adcb6a64

runc

1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8

skopeo

1.11.2-0.2.module+el8.8.0+21045+adcb6a64

skopeo-tests

1.11.2-0.2.module+el8.8.0+21045+adcb6a64

slirp4netns

1.2.0-2.module+el8.8.0+21045+adcb6a64

udica

0.2.6-20.module+el8.8.0+21045+adcb6a64

Oracle Linux x86_64

Module container-tools:ol8 is enabled

aardvark-dns

1.5.0-2.module+el8.8.0+21045+adcb6a64

buildah

1.29.1-2.module+el8.8.0+21056+d98a0860

buildah-tests

1.29.1-2.module+el8.8.0+21056+d98a0860

cockpit-podman

63.1-1.module+el8.8.0+21045+adcb6a64

conmon

2.1.6-1.module+el8.8.0+21045+adcb6a64

container-selinux

2.205.0-2.module+el8.8.0+21045+adcb6a64

containernetworking-plugins

1.2.0-1.module+el8.8.0+21045+adcb6a64

containers-common

1-64.0.1.module+el8.8.0+21056+d98a0860

crit

3.15-3.module+el8.8.0+21045+adcb6a64

criu

3.15-3.module+el8.8.0+21045+adcb6a64

criu-devel

3.15-3.module+el8.8.0+21045+adcb6a64

criu-libs

3.15-3.module+el8.8.0+21045+adcb6a64

crun

1.8.4-2.module+el8.8.0+21056+d98a0860

fuse-overlayfs

1.11-1.module+el8.8.0+21056+d98a0860

libslirp

4.4.0-1.module+el8.8.0+21045+adcb6a64

libslirp-devel

4.4.0-1.module+el8.8.0+21045+adcb6a64

netavark

1.5.0-5.module+el8.8.0+21056+d98a0860

oci-seccomp-bpf-hook

1.2.8-1.module+el8.8.0+21045+adcb6a64

podman

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-catatonit

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-docker

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-gvproxy

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-plugins

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-remote

4.4.1-12.module+el8.8.0+21056+d98a0860

podman-tests

4.4.1-12.module+el8.8.0+21056+d98a0860

python3-criu

3.15-3.module+el8.8.0+21045+adcb6a64

python3-podman

4.4.1-1.module+el8.8.0+21045+adcb6a64

runc

1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8

skopeo

1.11.2-0.2.module+el8.8.0+21045+adcb6a64

skopeo-tests

1.11.2-0.2.module+el8.8.0+21045+adcb6a64

slirp4netns

1.2.0-2.module+el8.8.0+21045+adcb6a64

udica

0.2.6-20.module+el8.8.0+21045+adcb6a64

Связанные уязвимости

suse-cvrf
больше 2 лет назад

Security update for runc

suse-cvrf
больше 2 лет назад

Security update for runc

oracle-oval
около 2 лет назад

ELSA-2023-12578: buildah security update (IMPORTANT)

oracle-oval
больше 1 года назад

ELSA-2023-6380: runc security update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2023-6938: container-tools:4.0 security and bug fix update (MODERATE)