Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6939

Опубликовано: 18 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-6939: container-tools:ol8 security and bug fix update (MODERATE)

aardvark-dns [2:1.7.0-1]

[2:1.6.0-1]

buildah [1:1.31.3-1]

[1:1.31.2-1]

[1:1.31.1-2]

  • build buildah off main branch for early testing of zstd compression
  • Related: #2176055

[1:1.31.1-1]

[1:1.31.0-1]

[1:1.30.0-2]

  • rebuild for following CVEs: CVE-2023-25173 CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2175070
  • Resolves: #2179948
  • Resolves: #2187317
  • Resolves: #2187364
  • Resolves: #2203680
  • Resolves: #2207510

[1:1.30.0-1]

[1:1.29.1-4]

[1:1.29.1-3]

cockpit-podman [75-1]

[74-1]

[73-1]

[72-1]

[71-1]

[70-1]

[69-1]

[68-1]

[67-1]

[66-1]

[65-1]

[64-1]

[63.1-2]

[59-1]

[58-1]

[57-1]

[56-1]

[55-1]

[54-1]

[53-1]

[52-1]

[51.1-1]

[50-1]

[49.1-1]

[48-1]

[47-1]

[46-1]

[44-2]

  • use spec file from the upstream source
  • Related: #2061390

[44-1]

[43-1]

[42-1]

[41-1]

[40-1]

[39-1]

[38-1]

[37-1]

[36-2]

  • revert the ansible change to fix gating tests
  • Related: #2001445

[36-1]

[35-1]

[34-1]

[33-1]

[32-2]

  • attempt to fix gating tests - thanks for Matej Marusak
  • Related: #1934415

[32-1]

[31-1]

[30-1]

  • fix gating test failure for cockpit-podman
  • Related: #1934415

[29-3]

  • fix gating test failure for cockpit-podman
  • Related: #1934415

[29-2]

  • gating test fix - properly install browser
  • Related: #1934415

[29-1]

[28.1-1]

[28-4]

  • readd cockpit-system Related: #1914884

[28-3]

  • fix gating tests for cockpit-podman - thanks for Matej Marusak
  • Related: #1883490

[28-2]

  • remove applied patch and cockpit-shell dependency
  • Related: #1883490

[28-1]

[27.1-4]

  • fix 'Fix gating tests of container-tools for 8.4.0'
  • Related: #1883490

[27.1-3]

  • another gating test fix - don't remove all containers but only admin ones thanks to Matej Marusak
  • Related: #1883490

[27.1-2]

  • gating tests - always set VM password
  • Related: #1883490

[27.1-1]

[27-1]

[26-1]

[25-4]

  • replace docker.io with quay.io for gating tests due do docker.io new pull rate limit requirements
  • Related: #1883490

[25-3]

  • test: Cleanup images before pulling the ones we need - thanks to Matej Marusak
  • Related: #1883490

[25-2]

  • remove hack in tests
  • Related: #1883490

[25-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[18.1-2]

  • revert back to 18.1 as this version is aimed at 8.3.0
  • Related: #1821193

[19-1]

[18.1-1]

  • Fix AppStream metainfo (rhbz#1854673)

[18-1]

[17-1]

[16-1]

  • synchronize containter-tools 8.3.0 with 8.2.1
  • Related: #1821193

[15-1]

  • Drop obsolete functionality for Fedora Atomic
  • Localize dates and times
  • Make tests non-destructive, to support gating
  • Fix crash on filtering anonymous images
  • Translation updates
  • Show historical logs

[12-1]

  • Configure CPU share for system containers
  • Translation updates

[11-1]

  • Fix Alert notification in Image Search Modal
  • Allow more than a single Error Notification for Container action errors
  • Various Alert cleanups
  • Translation updates

[10-1]

  • Support for user containers
  • Show list of containers that use given image
  • Show placeholder while loading containers and images
  • Fix setting memory limit rhbz#1732713
  • Add container Terminal rhbz#1703245

[4-1]

  • Fix regression in container commit
  • Fix AppStream ID rhbz#1734809

[3-1]

  • Enable Commit button for running containers
  • Fix race condition with container deletion
  • Stop fetching all containers/images for each container/image event

[2-2]

  • Fix podman dependency

[2-1]

  • Update to upstream 2 release
  • Support podman API 1.3
  • Support running commands with arguments
  • Show the default command coming from image
  • Implement filtering of images and containers

[1-2]

  • Update to upstream 1 release

conmon [3:2.1.8-1]

[3:2.1.7-1]

containernetworking-plugins [1:1.3.0-4]

  • add Epoch in Provides
  • Related: #2176055

[1:1.3.0-3]

  • remove no_openssl for FIPS compliance
  • Related: #2176055

[1:1.3.0-2]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179944
  • Resolves: #2187342
  • Resolves: #2187360
  • Resolves: #2203693
  • Resolves: #2207506

[1:1.3.0-1]

containers-common [2:1-54.0.1]

  • Updated removed references [Orabug: 33473101] (Alex Burmashev)
  • Adjust registries.conf (Nikita Gerasimov)
  • remove references to RedHat registry (Nikita Gerasimov)

[2:1-54]

  • update vendored components and shortnames
  • Related: #2176055

[2:1-53]

  • update vendored components
  • Related: #2176055

[2:1-52]

  • update vendored components
  • Related: #2176055

[2:1-51]

  • be sure default_capabilities contain SYS_CHROOT
  • Resolves: #2166195

[2:1-50]

  • improve shortnames generation
  • Related: #2176055

[2:1-49]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-48]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-47]

  • enable NET_RAW capability for RHEL8 only
  • Related: #2123641

[2:1-46]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-45]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-44]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-43]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-42]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-41]

  • add beta GPG key
  • Related: #2123641

[2:1-40]

  • add beta keys to default-policy.json
  • Related: #2061390

[2:1-39]

  • update shortnames
  • Related: #2061390

[2:1-38]

  • arch limitation because of go-md2man (missing on i686)
  • Related: #2061390

[2:1-37]

  • add install section
  • update vendored components
  • Related: #2061390

[2:1-36]

  • remove aardvark-dns and netavark - packaged separately
  • update vendored components and configuration files
  • Related: #2061390

[2:1-35]

  • update vendored components and configuration files
  • Related: #2061390

[2:1-34]

  • remove rhel-els and update shortnames
  • Related: #2061390

[2:1-33]

  • update shortnames
  • Related: #2061390

[2:1-32]

  • additional fix for unqualified registries
  • Related: #2061390

[2:1-31]

  • fix unqualified registries
  • Related: #2061390

[2:1-30]

  • update vendored components and configuration files
  • Related: #2061390

[2:1-29]

  • update unqualified registries list
  • Related: #2061390

[2:1-28]

  • update aardvark-dns and netavark to 1.0.3
  • update vendored components
  • Related: #2061390

[2:1-27]

  • add man page sources too
  • Related: #2061390

[2:1-26]

  • add missing man pages from Fedora
  • Related: #2061390

[2:1-25]

  • allow consuming aardvark-dns and netavark from upstream branch
  • Related: #2061390

[2:1-24]

  • update to netavark and aardvark-dns 1.0.2
  • update vendored components
  • Related: #2061390

[2:1-23]

  • update to netavark and aardvark-dns 1.0.1
  • Related: #2001445

[2:1-22]

  • build rust packages with RUSTFLAGS set to make ExecShield happy
  • Related: #2001445

[2:1-21]

  • do not specify infra_image in containers.conf
  • needed to resolve gating test failures
  • Related: #2001445

[2:1-20]

  • update to netavark-1.0.0 and aardvark-dns-1.0.0
  • Related: #2001445

[2:1-19]

  • package aarvark-dns and netavark as part of the containers-common
  • Related: #2001445

[2:1-18]

  • update shortnames and vendored components
  • Related: #2001445

[2:1-17]

  • containers.conf should contain network_backend = 'cni' in RHEL8.6
  • Related: #2001445

[2:1-16]

  • update vendored components and configuration files
  • Related: #2001445

[2:1-15]

  • sync vendored components
  • Related: #2001445

[2:1-14]

  • sync vendored components
  • Related: #2001445

[2:1-13]

  • update shortnames from Pyxis
  • Related: #2001445

[2:1-12]

  • do not allow broken content from Pyxis to land in shortnames.conf
  • Related: #2001445

[2:1-11]

  • sync vendored components
  • update shortnames from Pyxis
  • Related: #2001445

[2:1-10]

  • use log_driver = 'journald' and events_logger = 'journald' for RHEL9
  • Related: #2001445

[2:1-9]

  • consume seccomp.json from the oldest vendored version of c/common, not main branch
  • Related: #2001445

[2:1-8]

  • update vendored components
  • Related: #2001445

[2:1-7]

  • make log_driver = 'k8s-file' default in containers.conf
  • Related: #2001445

[2:1-6]

  • sync vendored components
  • Related: #2001445

[2:1-5]

  • update to the new vendored components
  • Related: #2001445

[2:1-4]

  • update to the new vendored components
  • Related: #2001445

[2:1-3]

  • update to the new vendored components
  • Related: #2001445

[2:1-2]

  • synchronize config files for RHEL-8.5
  • Related: #1934415

[2:1-1]

  • initial import
  • Related: #1934415

container-selinux [2:2.221.0-1]

[2:2.219.0-1]

[2:2.218.0-1]

[2:2.215.0-1]

[2:2.213.0-2]

  • add watch statement removal from container.te
  • Related: #2176055

[2:2.213.0-1]

[2:2.211.1-1]

criu [3.18-4]

  • switch to egg-info on 8.9
  • Related: #2176055

[3.18-3]

  • remove --progress-bar option
  • Related: #2176055

[3.18-2]

  • update to 3.18
  • Related: #2176055

[3.17-1]

  • update to 3.17
  • Resolves: #2175794

[3.15-2]

  • add gating tests
  • Related: #1971718

[3.15-1]

  • add -devel and -libs subpackages
  • Resolves: #1971718

[3.12-9]

  • Added additional fixup patches for the socket labelling

[3.12-8]

  • Patch for socket labelling has changed upstream

[3.12-4]

  • Applied patch to correctly restore socket()s

[3.12-3]

  • Correctly exclude libs and devel for RHEL

[3.12-2]

  • Updated to official 3.12

[3.12-0.1]

  • Updated to 3.12 (pre-release)
  • Create libs subpackage
  • Build against SELinux (Fedora and RHEL8)
  • Build against libbsd (Fedora)

[ 3.11-2]

  • Updated to 3.11
  • Removed upstreamed patches
  • Added patch for gcc-9

[3.10-7]

  • Fix 'criu check --feature link_nsid' with more than 10 interfaces (#1652442)

[3.10-6]

  • Make sure no iptables rules are left after restore (#1652471)

[3.10-5]

  • Added Recommends: tar It is necessary when checkpointing containers with a tmpfs

[3.10-4]

  • Add patch to fix errors with read-only runc

[3.10-3]

[3.10-2]

  • Disable annobin as it seems to break CRIU

[3.10-1]

  • Update to 3.10 (#1599710)
  • Switch to python3

[3.9-2]

  • Simplify ExclusiveArch now that there is no more F26

[3.9-1]

  • Update to 3.9

[3.8.1-1]

  • Update to 3.8.1

[3.8-2]

  • Bump release for COPR

[3.8-1]

  • Update to 3.8

[3.7-5]

[3.7-4]

  • Switch to %ldconfig_scriptlets

[3.7-3]

  • Fix python/python2 dependencies accross all branches

[3.7-2]

  • Cleanup spec file conditionals

[3.7-1]

  • Update to 3.7

[3.6-2]

[3.6-1]

  • Update to 3.6

[3.5-5]

  • Added patch to fix build on Fedora rawhide aarch64

[3.5-4]

  • Upgrade imported manpages to 3.5

[3.5-3]

  • Fix ExclusiveArch on RHEL

[3.5-2]

  • Merge RHEL and Fedora spec file

[3.5-1]

  • Update to 3.5 (#1496614)

[3.4-1]

  • Update to 3.4 (#1483774)
  • Removed upstreamed patches
  • Added s390x (#1475719)

[3.3-5]

[3.3-4]

[3.3-3]

[3.3-2]

  • Added patches to handle changes in glibc

[3.3-1]

  • Update to 3.3

[3.2.1-2]

  • Added patches to handle unified hierarchy and new glibc

[3.2.1-1]

  • Update to 3.2.1-1

[3.1-2]

  • Rebuild for protobuf 3.3.1

[3.1-1]

  • Update to 3.1

[3.0-1]

  • Update to 3.0

[2.12-1]

  • Update to 2.12

[2.11.1-1]

  • Update to 2.11.1

[2.11-1]

  • Update to 2.11

[2.10-4]

  • Added patch to fix build on ppc64le

[2.10-3]

[2.10-2]

  • Rebuild for protobuf 3.2.0

[2.10-1]

  • Update to 2.10

[2.9-1]

  • Update to 2.9
  • Added crit manpage to crit subpackage

[2.8-2]

  • Rebuild for protobuf 3.1.0

[2.8-1]

  • Update to 2.8
  • Dropped 'mount_resolve_path()' patch

[2.7-2]

  • Added upstream patch to fix #1381351 ('criu: mount_resolve_path(): criu killed by SIGSEGV')

[2.7-1]

  • Update to 2.7

[2.6-1]

  • Update to 2.6

[2.5-1]

  • Update to 2.5

[2.4-2]

[2.4-1]

  • Update to 2.4

[2.3-1]

  • Update to 2.3
  • Copy man-page from Fedora 24 for RHEL

[2.2-1]

  • Update to 2.2

[2.1-2]

  • Remove crtools symbolic link

[2.1-1]

  • Update to 2.1

[2.0-2]

  • Merge changes from Fedora

[2.0-1]

  • Update to 2.0

[1.8-2]

[1.8-1]

  • Update to 1.8

[1.7.2-1]

  • Update to 1.7.2

[1.7-1]

  • Update to 1.7

[1.6.1-3]

  • Build only for power64le

[1.6.1-2]

  • Build for aarch64 and power64

[1.6.1-1]

  • Update to 1.6.1
  • Merge changes for RHEL packaging

[1.6-2]

[1.6-1.1]

  • adapt to RHEL7

[1.6-1]

  • Update to 1.6

[1.5.2-2]

  • Require protobuf-python and python-ipaddr for python-criu

[1.5.2]

  • Update to 1.5.2

[1.5.1-2]

  • Create python-criu and crit subpackages

[1.5.1]

  • Update to 1.5.1

[1.4-1]

  • Update to 1.4

[1.3.1-1]

  • Update to 1.3.1 (#1142896)

[1.3-1]

  • Update to 1.3
  • Dropped all upstreamed patches
  • included pkgconfig file in -devel

[1.2-5]

[1.2-4]

  • Include inttypes.h for PRI helpers

[1.2-3]

[1.2-2]

[1.2-1]

  • Update to 1.2
  • Dropped all upstreamed patches

[1.1-4]

  • Create -devel subpackage

[1.0-3]

  • Fix the epoch of crtools

[1.0-2]

  • Rename crtools to criu #1034677

[1.0-1]

  • Update to 1.0

[0.8-1]

  • Update to 0.8

[0.7-1]

  • Update to 0.7

[0.6-5]

[0.6-3]

  • Delete all kind of -fstack-protector gcc options

[0.6-3]

  • Added arm macro to ExclusiveArch

[0.6-2]

  • fix building on ARM
  • fix null pointer dereference

[0.6-1]

  • updated to 0.6
  • upstream moved binaries to sbin
  • using upstream's make install

[0.5-1]

  • updated to 0.5

[0.4-1]

  • updated to 0.4

[0.3-4]

[0.3-3]

  • added ExclusiveArch blocker bug

[0.3-2]

  • improved Summary and Description

[0.3-1]

  • updated to 0.3
  • fix building Documentation/

[0.2-2]

  • remove macros like %{__mkdir_p} and %{__install}
  • add comment why it is only x86_64

[0.2-1]

  • initial release

crun [1.8.7-1]

[1.8.6-1]

[1.8.5-1]

[1.8.4-1]

[1.8.3-2]

  • fix could not find symbol criu_set_lsm_mount_context in libcriu.so
  • Resolves: #2183041

[1.8.3-1]

[1.8.2-1]

[1.8.1-2]

  • add BR: criu-devel
  • Related: #2176055

[1.8.1-1]

[1.7.2-1]

[1.7.1-1]

[1.7-1]

[1.6-1]

[1.5-1]

[1.4.5-2]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2061390

[1.4.5-1]

[1.4.4-1]

[1.4.3-1]

[1.4.2-1]

[1.4.1-1]

[1.4-1]

[1.3-1]

[1.2-1]

[1.1-1]

[1.0-1]

[0.21-3]

  • remove BR: criu-devel and leave it just for RHEL9
  • Related: #1934415

[0.21-2]

  • do not use versioned provide
  • BR: criu-devel
  • Related: #1934415

[0.21-1]

[0.20.1-1]

[0.20-1]

[0.19.1-1]

[0.19-2]

  • remove unused patch reference from spec
  • Related: #1934415

[0.19-1]

[0.18-1]

  • allow to build without glibc-static (thanks to Giuseppe Scrivano)
  • Related: #1883490

[0.17-2]

  • reverting back to 0.17 as there's no glibc-static in RHEL
  • Related: #1883490

[0.18-1]

[0.17-1]

[0.16-2]

  • exclude i686 because of build failures
  • Related: #1883490

[0.16-1]

[0.15.1-1]

[0.15-2]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[0.15-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[0.14.1-2]

  • use proper CFLAGS
  • Related: #1821193

[0.14.1-1]

[0.14-1]

[0.13-1]

  • initial import

fuse-overlayfs [1.12-1]

libslirp netavark [2:1.7.0-1]

[2:1.6.0-1]

[2:1.5.0-5]

  • fix --dns-add command is not functioning
  • Resolves: #2182897

[2:1.5.0-4]

  • exclude i686
  • Related: #2123641

[2:1.5.0-3]

  • update build parameters
  • Related: #2123641

[2:1.5.0-2]

  • always stay offline during build
  • Related: #2123641

[2:1.5.0-1]

[2:1.4.0-1]

[2:1.3.0-1]

[2:1.2.0-1]

[2:1.1.0-6]

  • bump Epoch to preserve upgrade path
  • Related: #2061390

[1.1.0-5]

  • remove dependency on md2man
  • Related: #2061390

[1.1.0-4]

  • fix arches
  • Related: #2061390

[1.1.0-3]

  • add gating.yaml
  • Related: #2061390

[1.1.0-2]

  • require /usr/bin/go-md2man directly

[1.1.0-1]

  • initial import
  • Related: #2061390

oci-seccomp-bpf-hook [1.2.9-1]

[1.2.8-2]

podman [3:4.6.1-4]

[3:4.6.1-3]

  • add podmansh provides
  • Related: #2176055

[3:4.6.1-2]

[3:4.6.1-1]

[3:4.6.0-3]

  • build podman 4.6.0 off main branch for early testing of zstd compression
  • Related: #2176055

[3:4.6.0-2]

  • update license token to be SPDX compatible
  • Related: #2176055

[3:4.6.0-1]

[3:4.6.0-0.3]

  • update to 4.6.0-rc2
  • Related: #2176055

[3:4.6.0-0.2]

  • add missing Requires on podman-plugins
  • Resolves: #2220931

[3:4.6.0-0.1]

  • update to 4.6.0-rc1
  • Related: #2176055

[3:4.5.1-5]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179945
  • Resolves: #2187315
  • Resolves: #2187361
  • Resolves: #2203678
  • Resolves: #2207507

[3:4.5.1-4]

  • rebuild for following CVEs: CVE-2023-25173 CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2175071
  • Resolves: #2179950
  • Resolves: #2187318
  • Resolves: #2187366
  • Resolves: #2203681
  • Resolves: #2207512

[3:4.5.1-3]

[3:4.5.1-2]

  • add missing BuildRequires
  • Related: #2176055

[3:4.5.1-1]

[3:4.4.1-19]

[3:4.4.1-18]

  • _user_tmpfilesdir definition is not part of systemd in 8.9
  • Related: #2176055

[3:4.4.1-17]

  • add missing BR: systemd-rpm-macros
  • Related: #2176055

python-podman [4.6.0-1]

[4.5.1-1]

[4.5.0-1]

runc [1:1.1.9-1]

[1:1.1.8-1]

[1:1.1.7-2]

  • rebuild for following CVEs: CVE-2022-41724
  • Resolves: #2179972

[1:1.1.7-1]

[1:1.1.6-1]

[1:1.1.5-1]

[1:1.1.4-2]

skopeo [2:1.13.3-1]

[2:1.13.2-1]

[2:1.13.1-1]

[2:1.13.0-1]

[2:1.12.0-2]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179951
  • Resolves: #2187319
  • Resolves: #2187367
  • Resolves: #2203682
  • Resolves: #2207513

[2:1.12.0-1]

[2:1.11.3-0.2]

[2:1.11.3-0.1]

[2:1.11.2-0.4]

[2:1.11.2-0.3]

  • fix build
  • Related: #2176055

[2:1.10.0-1]

[2:1.9.2-1]

[2:1.9.1-1]

[2:1.9.0-2]

  • update to skopeo-1.9.0 - thanks to Lokesh Mandvekar for fixing build issues
  • Related: #2061390

[2:1.8.0-2]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2061390

[2:1.8.0-1]

[2:1.7.0-2]

  • Related: #2061390

[2:1.7.0-1]

[2:1.6.1-1]

[2:1.6.0-1]

[2:1.5.2-1]

[2:1.5.1-1]

[2:1.5.0-2]

  • bump Epoch to preserve upgrade path
  • Related: #2001445

[1:1.5.0-1]

[1:1.5.1-0.3]

[1:1.5.1-0.2]

[1:1.5.1-0.1]

[1:1.4.1-0.12]

[1:1.4.1-0.11]

[1:1.4.1-0.10]

[1:1.4.1-0.9]

[1:1.4.1-0.8]

[1:1.4.1-0.7]

[1:1.4.1-0.6]

[1:1.4.1-0.5]

[1:1.4.1-0.4]

[1:1.4.1-0.3]

[1:1.4.1-0.2]

[1:1.4.2-0.1]

[1:1.4.1-2]

[1:1.4.1-1]

  • update to v1.4.1
  • Related: #1934415

[1:1.4.0-7]

[1:1.4.0-6]

  • carve away containers-common - it's now a separate package
  • Related: #1934415

[1:1.4.0-5]

  • be sure short-name-mode is permissive in RHEL8
  • Related: #1934415

[1:1.4.0-4]

  • don't define short-name-mode in RHEL8
  • Related: #1934415

[1:1.4.0-3]

  • re-add Requires: runc
  • Related: #1934415

[1:1.4.0-2]

  • update to 1.4.0 release and switch to the release-1.4 maint branch
  • Related: #1934415

[1:1.4.0-1]

  • update vendored components
  • ship /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release only on non-RHEL and CentOS distros
  • Related: #1934415

[1:1.3.1-7]

  • switch to 'main' branch of podman
  • Related: #1934415

[1:1.3.1-6]

  • move unqualified-search-registries to [registries.search]
  • Resolves: #1977280

[1:1.3.1-5]

  • update shortnames from Pyxis
  • Related: #1934415

[1:1.3.1-4]

  • add direct runc dependency to avoid situation when runc is listed as default runtime but only crun is present in RHEL8
  • Related: #1934415

[1:1.3.1-3]

[1:1.3.1-2]

  • use v3.2 branch for podman and update vendored branches
  • Related: #1934415

[1:1.3.1-1]

[1:1.3.0-5]

  • update shortname overrides
  • Related: #1952204

[1:1.3.0-4]

  • sync with Pyxis
  • use containers-mounts.conf.5.md from containers/common
  • Related: #1934415

[1:1.3.0-3]

  • update to new versions of vendored components
  • fail is there is an issue in communication with Pyxis API
  • understand devel branch in update.sh script
  • Related: #1934415

[1:1.3.0-2]

  • fix filelist with the new upstream release
  • Related: #1934415

[1:1.3.0-1]

[1:1.2.3-3]

  • update vendored components versions
  • sync shortnames with pyxis
  • Related: #1934415

[1:1.2.3-2]

  • assure runc is set as default runtime in RHEL8
  • update shortnames from upstream
  • sync vendored component versions with upstream
  • Related: #1934415

[1:1.2.3-1]

  • update to skopeo-1.2.3
  • sync with Fedora deps
  • fix typo in upstream Makefile
  • Related: #1934415

[1:1.2.2-6]

  • add update-vendored.sh, pyxis.sh and amend the shortname generation
  • Related: #1934415

[1:1.2.2-5]

  • require crun >= 0.19 and set it as default OCI runtime
  • add ensure() function to update.sh so that configuration statements can be easily amended/reviewed
  • Related: #1934415

[1:1.2.2-4]

  • use infra_image = 'registry.redhat.io/ubi8/pause' in containers.conf (unlike previous one ubi8/pause doesn't require authentication)
  • Related: #1934415

[1:1.2.2-3]

  • use infra_image = 'registry.redhat.io/rhel8/pause' in contiainers.conf
  • add update-vendored.sh script which will always assure we ship documentation/configs for versions vendored in podman, buildah and skopeo
  • Related: #1934415

[1:1.2.2-2]

  • use rhel-shortnames only from trusted registries
  • sync with config files from current versions of vendored projects
  • Resolves: #1933775
  • Resolves: #1933776

[1:1.2.2-1]

[1:1.2.1-14]

  • rename shortnames.conf to 000-shortnames.conf to assure evaluation order
  • Related: #1883490

[1:1.2.1-13]

[1:1.2.1-12]

[1:1.2.1-11]

[1:1.2.1-10]

[1:1.2.1-9]

  • define 8.4.0 branch for podman (v3.0)
  • remove redundant source file
  • Related: #1883490

[1:1.2.1-8]

[1:1.2.1-7]

  • convert subscription-manager from weak dep to a hint
  • Related: #1883490

[1:1.2.1-6]

  • fix rhel-shortnames.conf generation (avoid duplicates and records with invalid URL)
  • Related: #1883490

[1:1.2.1-5]

  • assure 'NET_RAW' is always defined
  • support rhel-shortnames.conf with generated shortname/registry aliases
  • Related: #1883490

[1:1.2.1-4]

  • add 'NET_RAW' default capability
  • Related: #1883490

[1:1.2.1-3]

  • ship preconfigured /etc/containers/registries.d/ files with containers-common
  • Related: #1883490

[1:1.2.1-2]

[1:1.2.1-1]

[1:1.2.0-6]

  • gating tests fixes and bump podman branch
  • Related: #1883490

[1:1.2.0-5]

  • still use arch exclude as the go_arches macro is broken for 8.4
  • Related: #1883490

[1:1.2.0-4]

  • unify vendored branches
  • add validation script
  • Related: #1883490

[1:1.2.0-3]

  • simplify spec file
  • use short commit ID in tarball name
  • Related: #1883490

[1:1.2.0-2]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[1:1.2.0-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[1:1.1.1-3]

  • propagate proper CFLAGS to CGO_CFLAGS to assure code hardening and optimization
  • Related: #1821193

[1:1.1.1-2]

  • drop applied patches
  • Related: #1821193

[1:1.1.1-1]

[1:1.1.0-3]

  • fix broken gating tests: docker unexpectedly removed htpasswd from their 'registry:2' image, so we now use htpasswd from httpd-tools on host.

[1:1.1.0-2]

  • fix 'CVE-2020-14040 skopeo: golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash [rhel-8]'
  • Resolves: #1854719

[1:1.1.0-1]

[1:1.0.0-2]

  • exclude i686 arch
  • Related: #1821193

[1:1.0.0-1]

[1:0.2.0-6]

  • synchronize containter-tools 8.3.0 with 8.2.1
  • Related: #1821193

[1:0.1.41-1]

  • update to 0.1.41
  • Related: #1821193

[1:0.1.40-10]

  • modify registries.conf default configuration to be more secure by default
  • Resolves: #1810053

[1:0.1.40-9]

  • Fix CVE-2020-1702.
  • Resolves: #1801922

[1:0.1.40-8]

  • change the search order of registries and remove quay.io (#1784267)

[1:0.1.40-7]

  • compile in FIPS mode
  • Related: RHELPLAN-25139

[1:0.1.40-6]

  • be sure to use golang >= 1.12.12-4
  • Related: RHELPLAN-25139

[1:0.1.40-5]

  • fix file list
  • Related: RHELPLAN-25139

[1:0.1.40-4]

  • fix symlinks in /usr/share/rhel/secrets and make subscription-manager soft dependency to make them work
  • Related: RHELPLAN-25139

[1:0.1.40-3]

  • rebuild because of CVE-2019-9512 and CVE-2019-9514
  • Resolves: #1772132, #1772137

[1:0.1.40-2]

  • comment out mountopt option in order to fix gating tests see bug 1769769
  • Related: RHELPLAN-25139

[1:0.1.40-1]

  • update to 0.1.40
  • Related: RHELPLAN-25139

[1:0.1.37-5]

  • Fix CVE-2019-10214 (#1734651).

[1:0.1.37-4]

  • fix permissions of rhel/secrets Resolves: #1691543

[1:0.1.37-3]

  • Resolves: #1719994 - add registry.access.redhat.com to registries.conf

[1:0.1.37-2]

  • Resolves: #1721247 - enable fips mode

[1:0.1.37-1]

  • Resolves: #1720654 - rebase to v0.1.37

[1:0.1.36-1.git6307635]

  • built upstream tag v0.1.36, including system tests

[1:0.1.32-4.git1715c90]

  • Fixes @openshift/machine-config-operator#669
  • install /etc/containers/oci/hooks.d and /etc/containers/certs.d

[1:0.1.32-3.git1715c90]

  • rebase

[1:0.1.32-2.git1715c90]

  • re-enable debuginfo

[1:0.1.31-12.gitb0b750d]

  • go tools not in scl anymore

[1:0.1.31-11.gitb0b750d]

  • Resolves: #1615609
  • built upstream tag v0.1.31

[1:0.1.31-10.git0144aa8]

  • Resolves: #1616069 - correct order of registries

[1:0.1.31-9.git0144aa8]

  • Resolves: #1615609 - rebuild with gobuild tag 'no_openssl'

[1:0.1.31-8.git0144aa8]

  • Resolves: #1614934 - containers-common soft dep on slirp4netns and fuse-overlayfs

[1:0.1.31-7.git0144aa8]

  • build with %gobuild
  • use scl-ized go-toolset as dep
  • disable i686 builds temporarily because of go-toolset issues

[1:0.1.31-6.git0144aa8]

  • add statx to seccomp.json to containers-config
  • add seccomp.json to containers-config

[1:0.1.31-4.git0144aa8]

  • Resolves: #1597629 - handle dependency issue for skopeo-containers
  • rename skopeo-containers to containers-common as in Fedora

[1:0.1.31-3.git0144aa8]

  • Resolves: #1583762 - btrfs dep removal needs exclude_graphdriver_btrfs buildtag

[1:0.1.31-2.git0144aa8]

  • correct bz in previous changelog

[1:0.1.31-1.git0144aa8]

  • Resolves: #1580938 - resolve FTBFS
  • Resolves: #1583762 - remove dependency on btrfs-progs-devel
  • bump to v0.1.31 (from master)
  • built commit ca3bff6
  • use go-toolset deps for rhel8

[0.1.29-5.git7add6fc]

  • Fix small typo in registries.conf

[0.1.29-4.git]

  • Add policy.json.5

[0.1.29-3.git]

  • Add registries.conf

[0.1.29-2.git]

  • Add registries.conf man page

[0.1.29-1.git]

  • bump to 0.1.29-1
  • Updated containers/image docker-archive generates docker legacy compatible images Do not create subdirectories for layers with no configs Ensure the layer IDs in legacy docker/tarfile metadata are unique docker-archive: repeated layers are symlinked in the tar file sysregistries: remove all trailing slashes Improve docker/* error messages Fix failure to make auth directory Create a new slice in Schema1.UpdateLayerInfos Drop unused storageImageDestination.{image,systemContext} Load a *storage.Image only once in storageImageSource Support gzip for docker-archive files Remove .tar extension from blob and config file names ostree, src: support copy of compressed layers ostree: re-pull layer if it misses uncompressed_digest|uncompressed_size image: fix docker schema v1 -> OCI conversion Add /etc/containers/certs.d as default certs directory

[0.1.28-2.git0270e56]

[0.1.28-1.git]

  • Vendor in fixed libraries in containers/image and containers/storage

[0.1.27-1.git]

  • Fix Conflicts to Obsoletes
  • Add better docs to man pages.
  • Use credentials from authfile for skopeo commands
  • Support storage='' in /etc/containers/storage.conf
  • Add global --override-arch and --override-os options

[0.1.25-2.git2e8377a7]

  • Add manifest type conversion to skopeo copy
  • User can select from 3 manifest types: oci, v2s1, or v2s2
  • e.g skopeo copy --format v2s1 --compress-blobs docker-archive:alp.tar dir:my-directory

[0.1.25-2.git7fd6f66b]

  • Force storage.conf to default to overlay

[0.1.25-1.git7fd6f66b]

  • Fix CVE in tar-split
  • copy: add shared blob directory support for OCI sources/destinations
  • Aligning Docker version between containers/image and skopeo
  • Update image-tools, and remove the duplicate Sirupsen/logrus vendor
  • makefile: use -buildmode=pie

[0.1.24-8.git28d4e08a]

  • Add /usr/share/containers/mounts.conf

[0.1.24-7.git28d4e08a]

  • Bug fixes
  • Update to release

[0.1.24-6.dev.git28d4e08]

  • skopeo-containers conflicts with docker-rhsubscription <= 2:1.13.1-31

[0.1.24-5.dev.git28d4e08]

  • Add rhel subscription secrets data to skopeo-containers

[0.1.24-4.dev.git28d4e08]

  • Update container/storage.conf and containers-storage.conf man page
  • Default override to true so it is consistent with RHEL.

[0.1.24-3.dev.git28d4e08]

  • built commit 28d4e08

[0.1.24-2.dev.git875dd2e]

  • built commit 875dd2e
  • Resolves: gh#416

[0.1.24-1.dev.gita41cd0]

  • bump to 0.1.24-dev
  • correct a prior bogus date
  • fix macro in comment warning

[0.1.23-6.dev.git1bbd87]

  • Change name of storage.conf.5 man page to containers-storage.conf.5, since it conflicts with inn package
  • Also remove default to 'overalay' in the configuration, since we should
  • allow containers storage to pick the best default for the platform.

[0.1.23-5.git1bbd87f]

[0.1.23-4.git1bbd87f]

  • Rebuild with binutils fix for ppc64le (#1475636)

[0.1.23-3.git1bbd87f]

[0.1.23-2.dev.git1bbd87]

  • Fix storage.conf man page to be storage.conf.5.gz so that it works.

[0.1.23-1.dev.git1bbd87]

  • Support for OCI V1.0 Images
  • Update to image-spec v1.0.0 and revendor
  • Fixes for authentication

[0.1.22-2.dev.git5d24b67]

  • Epoch: 1 for CentOS as CentOS Extras' build already has epoch set to 1

[0.1.22-1.dev.git5d24b67]

  • Give more useful help when explaining usage
  • Also specify container-storage as a valid transport
  • Remove docker reference wherever possible
  • vendor in ostree fixes

[0.1.21-1.dev.git0b73154]

  • Add support for storage.conf and storage-config.5.md from github container storage package
  • Bump to the latest version of skopeo
  • vendor.conf: add ostree-go
  • it is used by containers/image for pulling images to the OSTree storage.
  • fail early when image os does not match host os
  • Improve documentation on what to do with containers/image failures in test-skopeo
  • We now have the docker-archive: transport
  • Integration tests with built registries also exist
  • Support /etc/docker/certs.d
  • update image-spec to v1.0.0-rc6

[0.1.20-1.dev.git0224d8c]

  • BZ #1380078 - New release

[0.1.19-2.dev.git0224d8c]

  • No golang support for ppc64. Adding exclude arch. BZ #1445490

[0.1.19-1.dev.git0224d8c]

  • bump to v0.1.19-dev
  • built commit 0224d8c

[0.1.17-3.dev.git2b3af4a]

[0.1.17-2.dev.git2b3af4a]

  • Rebuild for gpgme 1.18

[0.1.17-1.dev.git2b3af4a]

  • bump to 0.1.17-dev

[0.1.14-6.git550a480]

  • Fix BZ#1391932

[0.1.14-5.git550a480]

  • Conflicts with atomic in skopeo-containers

[0.1.14-4.git550a480]

  • built skopeo-containers

[0.1.14-3.gitd830391]

  • built mtrmac/integrate-all-the-things commit d830391

[0.1.14-2.git362bfc5]

  • built commit 362bfc5

[0.1.14-1.gitffe92ed]

  • build origin/master commit ffe92ed

[0.1.13-6]

[0.1.13-5]

  • include go-srpm-macros and compiler(go-compiler) in fedora conditionals
  • define %gobuild if not already
  • add patch to build with older version of golang

[0.1.13-4]

  • update to v0.1.12

[0.1.12-3]

  • fix go build source path

[0.1.12-2]

  • update to v0.1.12

[0.1.11-1]

  • update to v0.1.11

[0.1.10-1]

  • update to v0.1.10
  • change runcom -> projectatomic

[0.1.9-1]

  • update to v0.1.9

[0.1.8-1]

  • update to v0.1.8

[0.1.4-2]

[0.1.4]

  • First package for Fedora

slirp4netns [1.2.1-1]

[1.2.0-3]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2176055

udica

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module container-tools:ol8 is enabled

aardvark-dns

1.7.0-1.module+el8.9.0+90021+ce997450

buildah

1.31.3-1.module+el8.9.0+90021+ce997450

buildah-tests

1.31.3-1.module+el8.9.0+90021+ce997450

cockpit-podman

75-1.module+el8.9.0+90021+ce997450

conmon

2.1.8-1.module+el8.9.0+90021+ce997450

container-selinux

2.221.0-1.module+el8.9.0+90021+ce997450

containernetworking-plugins

1.3.0-4.module+el8.9.0+90021+ce997450

containers-common

1-54.0.1.module+el8.9.0+90021+ce997450

crit

3.18-4.module+el8.9.0+90021+ce997450

criu

3.18-4.module+el8.9.0+90021+ce997450

criu-devel

3.18-4.module+el8.9.0+90021+ce997450

criu-libs

3.18-4.module+el8.9.0+90021+ce997450

crun

1.8.7-1.module+el8.9.0+90021+ce997450

fuse-overlayfs

1.12-1.module+el8.9.0+90021+ce997450

libslirp

4.4.0-1.module+el8.9.0+90021+ce997450

libslirp-devel

4.4.0-1.module+el8.9.0+90021+ce997450

netavark

1.7.0-1.module+el8.9.0+90021+ce997450

oci-seccomp-bpf-hook

1.2.9-1.module+el8.9.0+90021+ce997450

podman

4.6.1-4.module+el8.9.0+90021+ce997450

podman-catatonit

4.6.1-4.module+el8.9.0+90021+ce997450

podman-docker

4.6.1-4.module+el8.9.0+90021+ce997450

podman-gvproxy

4.6.1-4.module+el8.9.0+90021+ce997450

podman-plugins

4.6.1-4.module+el8.9.0+90021+ce997450

podman-remote

4.6.1-4.module+el8.9.0+90021+ce997450

podman-tests

4.6.1-4.module+el8.9.0+90021+ce997450

python3-criu

3.18-4.module+el8.9.0+90021+ce997450

python3-podman

4.6.0-1.module+el8.9.0+90021+ce997450

runc

1.1.9-1.module+el8.9.0+90021+ce997450

skopeo

1.13.3-1.module+el8.9.0+90021+ce997450

skopeo-tests

1.13.3-1.module+el8.9.0+90021+ce997450

slirp4netns

1.2.1-1.module+el8.9.0+90021+ce997450

udica

0.2.6-20.module+el8.9.0+90021+ce997450

Oracle Linux x86_64

Module container-tools:ol8 is enabled

aardvark-dns

1.7.0-1.module+el8.9.0+90021+ce997450

buildah

1.31.3-1.module+el8.9.0+90021+ce997450

buildah-tests

1.31.3-1.module+el8.9.0+90021+ce997450

cockpit-podman

75-1.module+el8.9.0+90021+ce997450

conmon

2.1.8-1.module+el8.9.0+90021+ce997450

container-selinux

2.221.0-1.module+el8.9.0+90021+ce997450

containernetworking-plugins

1.3.0-4.module+el8.9.0+90021+ce997450

containers-common

1-54.0.1.module+el8.9.0+90021+ce997450

crit

3.18-4.module+el8.9.0+90021+ce997450

criu

3.18-4.module+el8.9.0+90021+ce997450

criu-devel

3.18-4.module+el8.9.0+90021+ce997450

criu-libs

3.18-4.module+el8.9.0+90021+ce997450

crun

1.8.7-1.module+el8.9.0+90021+ce997450

fuse-overlayfs

1.12-1.module+el8.9.0+90021+ce997450

libslirp

4.4.0-1.module+el8.9.0+90021+ce997450

libslirp-devel

4.4.0-1.module+el8.9.0+90021+ce997450

netavark

1.7.0-1.module+el8.9.0+90021+ce997450

oci-seccomp-bpf-hook

1.2.9-1.module+el8.9.0+90021+ce997450

podman

4.6.1-4.module+el8.9.0+90021+ce997450

podman-catatonit

4.6.1-4.module+el8.9.0+90021+ce997450

podman-docker

4.6.1-4.module+el8.9.0+90021+ce997450

podman-gvproxy

4.6.1-4.module+el8.9.0+90021+ce997450

podman-plugins

4.6.1-4.module+el8.9.0+90021+ce997450

podman-remote

4.6.1-4.module+el8.9.0+90021+ce997450

podman-tests

4.6.1-4.module+el8.9.0+90021+ce997450

python3-criu

3.18-4.module+el8.9.0+90021+ce997450

python3-podman

4.6.0-1.module+el8.9.0+90021+ce997450

runc

1.1.9-1.module+el8.9.0+90021+ce997450

skopeo

1.13.3-1.module+el8.9.0+90021+ce997450

skopeo-tests

1.13.3-1.module+el8.9.0+90021+ce997450

slirp4netns

1.2.1-1.module+el8.9.0+90021+ce997450

udica

0.2.6-20.module+el8.9.0+90021+ce997450

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2023-6938: container-tools:4.0 security and bug fix update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2023-6474: podman security, bug fix, and enhancement update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2023-6473: buildah security update (MODERATE)

CVSS3: 6.1
ubuntu
почти 2 года назад

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

CVSS3: 6.1
redhat
почти 2 года назад

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

Уязвимость ELSA-2023-6939