Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6939

Опубликовано: 18 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-6939: container-tools:ol8 security and bug fix update (MODERATE)

aardvark-dns [2:1.7.0-1]

[2:1.6.0-1]

buildah [1:1.31.3-1]

[1:1.31.2-1]

[1:1.31.1-2]

  • build buildah off main branch for early testing of zstd compression
  • Related: #2176055

[1:1.31.1-1]

[1:1.31.0-1]

[1:1.30.0-2]

  • rebuild for following CVEs: CVE-2023-25173 CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2175070
  • Resolves: #2179948
  • Resolves: #2187317
  • Resolves: #2187364
  • Resolves: #2203680
  • Resolves: #2207510

[1:1.30.0-1]

[1:1.29.1-4]

[1:1.29.1-3]

cockpit-podman [75-1]

[74-1]

[73-1]

[72-1]

[71-1]

[70-1]

[69-1]

[68-1]

[67-1]

[66-1]

[65-1]

[64-1]

[63.1-2]

[59-1]

[58-1]

[57-1]

[56-1]

[55-1]

[54-1]

[53-1]

[52-1]

[51.1-1]

[50-1]

[49.1-1]

[48-1]

[47-1]

[46-1]

[44-2]

  • use spec file from the upstream source
  • Related: #2061390

[44-1]

[43-1]

[42-1]

[41-1]

[40-1]

[39-1]

[38-1]

[37-1]

[36-2]

  • revert the ansible change to fix gating tests
  • Related: #2001445

[36-1]

[35-1]

[34-1]

[33-1]

[32-2]

  • attempt to fix gating tests - thanks for Matej Marusak
  • Related: #1934415

[32-1]

[31-1]

[30-1]

  • fix gating test failure for cockpit-podman
  • Related: #1934415

[29-3]

  • fix gating test failure for cockpit-podman
  • Related: #1934415

[29-2]

  • gating test fix - properly install browser
  • Related: #1934415

[29-1]

[28.1-1]

[28-4]

  • readd cockpit-system Related: #1914884

[28-3]

  • fix gating tests for cockpit-podman - thanks for Matej Marusak
  • Related: #1883490

[28-2]

  • remove applied patch and cockpit-shell dependency
  • Related: #1883490

[28-1]

[27.1-4]

  • fix 'Fix gating tests of container-tools for 8.4.0'
  • Related: #1883490

[27.1-3]

  • another gating test fix - don't remove all containers but only admin ones thanks to Matej Marusak
  • Related: #1883490

[27.1-2]

  • gating tests - always set VM password
  • Related: #1883490

[27.1-1]

[27-1]

[26-1]

[25-4]

  • replace docker.io with quay.io for gating tests due do docker.io new pull rate limit requirements
  • Related: #1883490

[25-3]

  • test: Cleanup images before pulling the ones we need - thanks to Matej Marusak
  • Related: #1883490

[25-2]

  • remove hack in tests
  • Related: #1883490

[25-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[18.1-2]

  • revert back to 18.1 as this version is aimed at 8.3.0
  • Related: #1821193

[19-1]

[18.1-1]

  • Fix AppStream metainfo (rhbz#1854673)

[18-1]

[17-1]

[16-1]

  • synchronize containter-tools 8.3.0 with 8.2.1
  • Related: #1821193

[15-1]

  • Drop obsolete functionality for Fedora Atomic
  • Localize dates and times
  • Make tests non-destructive, to support gating
  • Fix crash on filtering anonymous images
  • Translation updates
  • Show historical logs

[12-1]

  • Configure CPU share for system containers
  • Translation updates

[11-1]

  • Fix Alert notification in Image Search Modal
  • Allow more than a single Error Notification for Container action errors
  • Various Alert cleanups
  • Translation updates

[10-1]

  • Support for user containers
  • Show list of containers that use given image
  • Show placeholder while loading containers and images
  • Fix setting memory limit rhbz#1732713
  • Add container Terminal rhbz#1703245

[4-1]

  • Fix regression in container commit
  • Fix AppStream ID rhbz#1734809

[3-1]

  • Enable Commit button for running containers
  • Fix race condition with container deletion
  • Stop fetching all containers/images for each container/image event

[2-2]

  • Fix podman dependency

[2-1]

  • Update to upstream 2 release
  • Support podman API 1.3
  • Support running commands with arguments
  • Show the default command coming from image
  • Implement filtering of images and containers

[1-2]

  • Update to upstream 1 release

conmon [3:2.1.8-1]

[3:2.1.7-1]

containernetworking-plugins [1:1.3.0-4]

  • add Epoch in Provides
  • Related: #2176055

[1:1.3.0-3]

  • remove no_openssl for FIPS compliance
  • Related: #2176055

[1:1.3.0-2]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179944
  • Resolves: #2187342
  • Resolves: #2187360
  • Resolves: #2203693
  • Resolves: #2207506

[1:1.3.0-1]

containers-common [2:1-54.0.1]

  • Updated removed references [Orabug: 33473101] (Alex Burmashev)
  • Adjust registries.conf (Nikita Gerasimov)
  • remove references to RedHat registry (Nikita Gerasimov)

[2:1-54]

  • update vendored components and shortnames
  • Related: #2176055

[2:1-53]

  • update vendored components
  • Related: #2176055

[2:1-52]

  • update vendored components
  • Related: #2176055

[2:1-51]

  • be sure default_capabilities contain SYS_CHROOT
  • Resolves: #2166195

[2:1-50]

  • improve shortnames generation
  • Related: #2176055

[2:1-49]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-48]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-47]

  • enable NET_RAW capability for RHEL8 only
  • Related: #2123641

[2:1-46]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-45]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-44]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-43]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-42]

  • update vendored components and configuration files
  • Related: #2123641

[2:1-41]

  • add beta GPG key
  • Related: #2123641

[2:1-40]

  • add beta keys to default-policy.json
  • Related: #2061390

[2:1-39]

  • update shortnames
  • Related: #2061390

[2:1-38]

  • arch limitation because of go-md2man (missing on i686)
  • Related: #2061390

[2:1-37]

  • add install section
  • update vendored components
  • Related: #2061390

[2:1-36]

  • remove aardvark-dns and netavark - packaged separately
  • update vendored components and configuration files
  • Related: #2061390

[2:1-35]

  • update vendored components and configuration files
  • Related: #2061390

[2:1-34]

  • remove rhel-els and update shortnames
  • Related: #2061390

[2:1-33]

  • update shortnames
  • Related: #2061390

[2:1-32]

  • additional fix for unqualified registries
  • Related: #2061390

[2:1-31]

  • fix unqualified registries
  • Related: #2061390

[2:1-30]

  • update vendored components and configuration files
  • Related: #2061390

[2:1-29]

  • update unqualified registries list
  • Related: #2061390

[2:1-28]

  • update aardvark-dns and netavark to 1.0.3
  • update vendored components
  • Related: #2061390

[2:1-27]

  • add man page sources too
  • Related: #2061390

[2:1-26]

  • add missing man pages from Fedora
  • Related: #2061390

[2:1-25]

  • allow consuming aardvark-dns and netavark from upstream branch
  • Related: #2061390

[2:1-24]

  • update to netavark and aardvark-dns 1.0.2
  • update vendored components
  • Related: #2061390

[2:1-23]

  • update to netavark and aardvark-dns 1.0.1
  • Related: #2001445

[2:1-22]

  • build rust packages with RUSTFLAGS set to make ExecShield happy
  • Related: #2001445

[2:1-21]

  • do not specify infra_image in containers.conf
  • needed to resolve gating test failures
  • Related: #2001445

[2:1-20]

  • update to netavark-1.0.0 and aardvark-dns-1.0.0
  • Related: #2001445

[2:1-19]

  • package aarvark-dns and netavark as part of the containers-common
  • Related: #2001445

[2:1-18]

  • update shortnames and vendored components
  • Related: #2001445

[2:1-17]

  • containers.conf should contain network_backend = 'cni' in RHEL8.6
  • Related: #2001445

[2:1-16]

  • update vendored components and configuration files
  • Related: #2001445

[2:1-15]

  • sync vendored components
  • Related: #2001445

[2:1-14]

  • sync vendored components
  • Related: #2001445

[2:1-13]

  • update shortnames from Pyxis
  • Related: #2001445

[2:1-12]

  • do not allow broken content from Pyxis to land in shortnames.conf
  • Related: #2001445

[2:1-11]

  • sync vendored components
  • update shortnames from Pyxis
  • Related: #2001445

[2:1-10]

  • use log_driver = 'journald' and events_logger = 'journald' for RHEL9
  • Related: #2001445

[2:1-9]

  • consume seccomp.json from the oldest vendored version of c/common, not main branch
  • Related: #2001445

[2:1-8]

  • update vendored components
  • Related: #2001445

[2:1-7]

  • make log_driver = 'k8s-file' default in containers.conf
  • Related: #2001445

[2:1-6]

  • sync vendored components
  • Related: #2001445

[2:1-5]

  • update to the new vendored components
  • Related: #2001445

[2:1-4]

  • update to the new vendored components
  • Related: #2001445

[2:1-3]

  • update to the new vendored components
  • Related: #2001445

[2:1-2]

  • synchronize config files for RHEL-8.5
  • Related: #1934415

[2:1-1]

  • initial import
  • Related: #1934415

container-selinux [2:2.221.0-1]

[2:2.219.0-1]

[2:2.218.0-1]

[2:2.215.0-1]

[2:2.213.0-2]

  • add watch statement removal from container.te
  • Related: #2176055

[2:2.213.0-1]

[2:2.211.1-1]

criu [3.18-4]

  • switch to egg-info on 8.9
  • Related: #2176055

[3.18-3]

  • remove --progress-bar option
  • Related: #2176055

[3.18-2]

  • update to 3.18
  • Related: #2176055

[3.17-1]

  • update to 3.17
  • Resolves: #2175794

[3.15-2]

  • add gating tests
  • Related: #1971718

[3.15-1]

  • add -devel and -libs subpackages
  • Resolves: #1971718

[3.12-9]

  • Added additional fixup patches for the socket labelling

[3.12-8]

  • Patch for socket labelling has changed upstream

[3.12-4]

  • Applied patch to correctly restore socket()s

[3.12-3]

  • Correctly exclude libs and devel for RHEL

[3.12-2]

  • Updated to official 3.12

[3.12-0.1]

  • Updated to 3.12 (pre-release)
  • Create libs subpackage
  • Build against SELinux (Fedora and RHEL8)
  • Build against libbsd (Fedora)

[ 3.11-2]

  • Updated to 3.11
  • Removed upstreamed patches
  • Added patch for gcc-9

[3.10-7]

  • Fix 'criu check --feature link_nsid' with more than 10 interfaces (#1652442)

[3.10-6]

  • Make sure no iptables rules are left after restore (#1652471)

[3.10-5]

  • Added Recommends: tar It is necessary when checkpointing containers with a tmpfs

[3.10-4]

  • Add patch to fix errors with read-only runc

[3.10-3]

[3.10-2]

  • Disable annobin as it seems to break CRIU

[3.10-1]

  • Update to 3.10 (#1599710)
  • Switch to python3

[3.9-2]

  • Simplify ExclusiveArch now that there is no more F26

[3.9-1]

  • Update to 3.9

[3.8.1-1]

  • Update to 3.8.1

[3.8-2]

  • Bump release for COPR

[3.8-1]

  • Update to 3.8

[3.7-5]

[3.7-4]

  • Switch to %ldconfig_scriptlets

[3.7-3]

  • Fix python/python2 dependencies accross all branches

[3.7-2]

  • Cleanup spec file conditionals

[3.7-1]

  • Update to 3.7

[3.6-2]

[3.6-1]

  • Update to 3.6

[3.5-5]

  • Added patch to fix build on Fedora rawhide aarch64

[3.5-4]

  • Upgrade imported manpages to 3.5

[3.5-3]

  • Fix ExclusiveArch on RHEL

[3.5-2]

  • Merge RHEL and Fedora spec file

[3.5-1]

  • Update to 3.5 (#1496614)

[3.4-1]

  • Update to 3.4 (#1483774)
  • Removed upstreamed patches
  • Added s390x (#1475719)

[3.3-5]

[3.3-4]

[3.3-3]

[3.3-2]

  • Added patches to handle changes in glibc

[3.3-1]

  • Update to 3.3

[3.2.1-2]

  • Added patches to handle unified hierarchy and new glibc

[3.2.1-1]

  • Update to 3.2.1-1

[3.1-2]

  • Rebuild for protobuf 3.3.1

[3.1-1]

  • Update to 3.1

[3.0-1]

  • Update to 3.0

[2.12-1]

  • Update to 2.12

[2.11.1-1]

  • Update to 2.11.1

[2.11-1]

  • Update to 2.11

[2.10-4]

  • Added patch to fix build on ppc64le

[2.10-3]

[2.10-2]

  • Rebuild for protobuf 3.2.0

[2.10-1]

  • Update to 2.10

[2.9-1]

  • Update to 2.9
  • Added crit manpage to crit subpackage

[2.8-2]

  • Rebuild for protobuf 3.1.0

[2.8-1]

  • Update to 2.8
  • Dropped 'mount_resolve_path()' patch

[2.7-2]

  • Added upstream patch to fix #1381351 ('criu: mount_resolve_path(): criu killed by SIGSEGV')

[2.7-1]

  • Update to 2.7

[2.6-1]

  • Update to 2.6

[2.5-1]

  • Update to 2.5

[2.4-2]

[2.4-1]

  • Update to 2.4

[2.3-1]

  • Update to 2.3
  • Copy man-page from Fedora 24 for RHEL

[2.2-1]

  • Update to 2.2

[2.1-2]

  • Remove crtools symbolic link

[2.1-1]

  • Update to 2.1

[2.0-2]

  • Merge changes from Fedora

[2.0-1]

  • Update to 2.0

[1.8-2]

[1.8-1]

  • Update to 1.8

[1.7.2-1]

  • Update to 1.7.2

[1.7-1]

  • Update to 1.7

[1.6.1-3]

  • Build only for power64le

[1.6.1-2]

  • Build for aarch64 and power64

[1.6.1-1]

  • Update to 1.6.1
  • Merge changes for RHEL packaging

[1.6-2]

[1.6-1.1]

  • adapt to RHEL7

[1.6-1]

  • Update to 1.6

[1.5.2-2]

  • Require protobuf-python and python-ipaddr for python-criu

[1.5.2]

  • Update to 1.5.2

[1.5.1-2]

  • Create python-criu and crit subpackages

[1.5.1]

  • Update to 1.5.1

[1.4-1]

  • Update to 1.4

[1.3.1-1]

  • Update to 1.3.1 (#1142896)

[1.3-1]

  • Update to 1.3
  • Dropped all upstreamed patches
  • included pkgconfig file in -devel

[1.2-5]

[1.2-4]

  • Include inttypes.h for PRI helpers

[1.2-3]

[1.2-2]

[1.2-1]

  • Update to 1.2
  • Dropped all upstreamed patches

[1.1-4]

  • Create -devel subpackage

[1.0-3]

  • Fix the epoch of crtools

[1.0-2]

  • Rename crtools to criu #1034677

[1.0-1]

  • Update to 1.0

[0.8-1]

  • Update to 0.8

[0.7-1]

  • Update to 0.7

[0.6-5]

[0.6-3]

  • Delete all kind of -fstack-protector gcc options

[0.6-3]

  • Added arm macro to ExclusiveArch

[0.6-2]

  • fix building on ARM
  • fix null pointer dereference

[0.6-1]

  • updated to 0.6
  • upstream moved binaries to sbin
  • using upstream's make install

[0.5-1]

  • updated to 0.5

[0.4-1]

  • updated to 0.4

[0.3-4]

[0.3-3]

  • added ExclusiveArch blocker bug

[0.3-2]

  • improved Summary and Description

[0.3-1]

  • updated to 0.3
  • fix building Documentation/

[0.2-2]

  • remove macros like %{__mkdir_p} and %{__install}
  • add comment why it is only x86_64

[0.2-1]

  • initial release

crun [1.8.7-1]

[1.8.6-1]

[1.8.5-1]

[1.8.4-1]

[1.8.3-2]

  • fix could not find symbol criu_set_lsm_mount_context in libcriu.so
  • Resolves: #2183041

[1.8.3-1]

[1.8.2-1]

[1.8.1-2]

  • add BR: criu-devel
  • Related: #2176055

[1.8.1-1]

[1.7.2-1]

[1.7.1-1]

[1.7-1]

[1.6-1]

[1.5-1]

[1.4.5-2]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2061390

[1.4.5-1]

[1.4.4-1]

[1.4.3-1]

[1.4.2-1]

[1.4.1-1]

[1.4-1]

[1.3-1]

[1.2-1]

[1.1-1]

[1.0-1]

[0.21-3]

  • remove BR: criu-devel and leave it just for RHEL9
  • Related: #1934415

[0.21-2]

  • do not use versioned provide
  • BR: criu-devel
  • Related: #1934415

[0.21-1]

[0.20.1-1]

[0.20-1]

[0.19.1-1]

[0.19-2]

  • remove unused patch reference from spec
  • Related: #1934415

[0.19-1]

[0.18-1]

  • allow to build without glibc-static (thanks to Giuseppe Scrivano)
  • Related: #1883490

[0.17-2]

  • reverting back to 0.17 as there's no glibc-static in RHEL
  • Related: #1883490

[0.18-1]

[0.17-1]

[0.16-2]

  • exclude i686 because of build failures
  • Related: #1883490

[0.16-1]

[0.15.1-1]

[0.15-2]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[0.15-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[0.14.1-2]

  • use proper CFLAGS
  • Related: #1821193

[0.14.1-1]

[0.14-1]

[0.13-1]

  • initial import

fuse-overlayfs [1.12-1]

libslirp netavark [2:1.7.0-1]

[2:1.6.0-1]

[2:1.5.0-5]

  • fix --dns-add command is not functioning
  • Resolves: #2182897

[2:1.5.0-4]

  • exclude i686
  • Related: #2123641

[2:1.5.0-3]

  • update build parameters
  • Related: #2123641

[2:1.5.0-2]

  • always stay offline during build
  • Related: #2123641

[2:1.5.0-1]

[2:1.4.0-1]

[2:1.3.0-1]

[2:1.2.0-1]

[2:1.1.0-6]

  • bump Epoch to preserve upgrade path
  • Related: #2061390

[1.1.0-5]

  • remove dependency on md2man
  • Related: #2061390

[1.1.0-4]

  • fix arches
  • Related: #2061390

[1.1.0-3]

  • add gating.yaml
  • Related: #2061390

[1.1.0-2]

  • require /usr/bin/go-md2man directly

[1.1.0-1]

  • initial import
  • Related: #2061390

oci-seccomp-bpf-hook [1.2.9-1]

[1.2.8-2]

podman [3:4.6.1-4]

[3:4.6.1-3]

  • add podmansh provides
  • Related: #2176055

[3:4.6.1-2]

[3:4.6.1-1]

[3:4.6.0-3]

  • build podman 4.6.0 off main branch for early testing of zstd compression
  • Related: #2176055

[3:4.6.0-2]

  • update license token to be SPDX compatible
  • Related: #2176055

[3:4.6.0-1]

[3:4.6.0-0.3]

  • update to 4.6.0-rc2
  • Related: #2176055

[3:4.6.0-0.2]

  • add missing Requires on podman-plugins
  • Resolves: #2220931

[3:4.6.0-0.1]

  • update to 4.6.0-rc1
  • Related: #2176055

[3:4.5.1-5]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179945
  • Resolves: #2187315
  • Resolves: #2187361
  • Resolves: #2203678
  • Resolves: #2207507

[3:4.5.1-4]

  • rebuild for following CVEs: CVE-2023-25173 CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2175071
  • Resolves: #2179950
  • Resolves: #2187318
  • Resolves: #2187366
  • Resolves: #2203681
  • Resolves: #2207512

[3:4.5.1-3]

[3:4.5.1-2]

  • add missing BuildRequires
  • Related: #2176055

[3:4.5.1-1]

[3:4.4.1-19]

[3:4.4.1-18]

  • _user_tmpfilesdir definition is not part of systemd in 8.9
  • Related: #2176055

[3:4.4.1-17]

  • add missing BR: systemd-rpm-macros
  • Related: #2176055

python-podman [4.6.0-1]

[4.5.1-1]

[4.5.0-1]

runc [1:1.1.9-1]

[1:1.1.8-1]

[1:1.1.7-2]

  • rebuild for following CVEs: CVE-2022-41724
  • Resolves: #2179972

[1:1.1.7-1]

[1:1.1.6-1]

[1:1.1.5-1]

[1:1.1.4-2]

skopeo [2:1.13.3-1]

[2:1.13.2-1]

[2:1.13.1-1]

[2:1.13.0-1]

[2:1.12.0-2]

  • rebuild for following CVEs: CVE-2022-41724 CVE-2022-41725 CVE-2023-24537 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
  • Resolves: #2179951
  • Resolves: #2187319
  • Resolves: #2187367
  • Resolves: #2203682
  • Resolves: #2207513

[2:1.12.0-1]

[2:1.11.3-0.2]

[2:1.11.3-0.1]

[2:1.11.2-0.4]

[2:1.11.2-0.3]

  • fix build
  • Related: #2176055

[2:1.10.0-1]

[2:1.9.2-1]

[2:1.9.1-1]

[2:1.9.0-2]

  • update to skopeo-1.9.0 - thanks to Lokesh Mandvekar for fixing build issues
  • Related: #2061390

[2:1.8.0-2]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2061390

[2:1.8.0-1]

[2:1.7.0-2]

  • Related: #2061390

[2:1.7.0-1]

[2:1.6.1-1]

[2:1.6.0-1]

[2:1.5.2-1]

[2:1.5.1-1]

[2:1.5.0-2]

  • bump Epoch to preserve upgrade path
  • Related: #2001445

[1:1.5.0-1]

[1:1.5.1-0.3]

[1:1.5.1-0.2]

[1:1.5.1-0.1]

[1:1.4.1-0.12]

[1:1.4.1-0.11]

[1:1.4.1-0.10]

[1:1.4.1-0.9]

[1:1.4.1-0.8]

[1:1.4.1-0.7]

[1:1.4.1-0.6]

[1:1.4.1-0.5]

[1:1.4.1-0.4]

[1:1.4.1-0.3]

[1:1.4.1-0.2]

[1:1.4.2-0.1]

[1:1.4.1-2]

[1:1.4.1-1]

  • update to v1.4.1
  • Related: #1934415

[1:1.4.0-7]

[1:1.4.0-6]

  • carve away containers-common - it's now a separate package
  • Related: #1934415

[1:1.4.0-5]

  • be sure short-name-mode is permissive in RHEL8
  • Related: #1934415

[1:1.4.0-4]

  • don't define short-name-mode in RHEL8
  • Related: #1934415

[1:1.4.0-3]

  • re-add Requires: runc
  • Related: #1934415

[1:1.4.0-2]

  • update to 1.4.0 release and switch to the release-1.4 maint branch
  • Related: #1934415

[1:1.4.0-1]

  • update vendored components
  • ship /etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release only on non-RHEL and CentOS distros
  • Related: #1934415

[1:1.3.1-7]

  • switch to 'main' branch of podman
  • Related: #1934415

[1:1.3.1-6]

  • move unqualified-search-registries to [registries.search]
  • Resolves: #1977280

[1:1.3.1-5]

  • update shortnames from Pyxis
  • Related: #1934415

[1:1.3.1-4]

  • add direct runc dependency to avoid situation when runc is listed as default runtime but only crun is present in RHEL8
  • Related: #1934415

[1:1.3.1-3]

[1:1.3.1-2]

  • use v3.2 branch for podman and update vendored branches
  • Related: #1934415

[1:1.3.1-1]

[1:1.3.0-5]

  • update shortname overrides
  • Related: #1952204

[1:1.3.0-4]

  • sync with Pyxis
  • use containers-mounts.conf.5.md from containers/common
  • Related: #1934415

[1:1.3.0-3]

  • update to new versions of vendored components
  • fail is there is an issue in communication with Pyxis API
  • understand devel branch in update.sh script
  • Related: #1934415

[1:1.3.0-2]

  • fix filelist with the new upstream release
  • Related: #1934415

[1:1.3.0-1]

[1:1.2.3-3]

  • update vendored components versions
  • sync shortnames with pyxis
  • Related: #1934415

[1:1.2.3-2]

  • assure runc is set as default runtime in RHEL8
  • update shortnames from upstream
  • sync vendored component versions with upstream
  • Related: #1934415

[1:1.2.3-1]

  • update to skopeo-1.2.3
  • sync with Fedora deps
  • fix typo in upstream Makefile
  • Related: #1934415

[1:1.2.2-6]

  • add update-vendored.sh, pyxis.sh and amend the shortname generation
  • Related: #1934415

[1:1.2.2-5]

  • require crun >= 0.19 and set it as default OCI runtime
  • add ensure() function to update.sh so that configuration statements can be easily amended/reviewed
  • Related: #1934415

[1:1.2.2-4]

  • use infra_image = 'registry.redhat.io/ubi8/pause' in containers.conf (unlike previous one ubi8/pause doesn't require authentication)
  • Related: #1934415

[1:1.2.2-3]

  • use infra_image = 'registry.redhat.io/rhel8/pause' in contiainers.conf
  • add update-vendored.sh script which will always assure we ship documentation/configs for versions vendored in podman, buildah and skopeo
  • Related: #1934415

[1:1.2.2-2]

  • use rhel-shortnames only from trusted registries
  • sync with config files from current versions of vendored projects
  • Resolves: #1933775
  • Resolves: #1933776

[1:1.2.2-1]

[1:1.2.1-14]

  • rename shortnames.conf to 000-shortnames.conf to assure evaluation order
  • Related: #1883490

[1:1.2.1-13]

[1:1.2.1-12]

[1:1.2.1-11]

[1:1.2.1-10]

[1:1.2.1-9]

  • define 8.4.0 branch for podman (v3.0)
  • remove redundant source file
  • Related: #1883490

[1:1.2.1-8]

[1:1.2.1-7]

  • convert subscription-manager from weak dep to a hint
  • Related: #1883490

[1:1.2.1-6]

  • fix rhel-shortnames.conf generation (avoid duplicates and records with invalid URL)
  • Related: #1883490

[1:1.2.1-5]

  • assure 'NET_RAW' is always defined
  • support rhel-shortnames.conf with generated shortname/registry aliases
  • Related: #1883490

[1:1.2.1-4]

  • add 'NET_RAW' default capability
  • Related: #1883490

[1:1.2.1-3]

  • ship preconfigured /etc/containers/registries.d/ files with containers-common
  • Related: #1883490

[1:1.2.1-2]

[1:1.2.1-1]

[1:1.2.0-6]

  • gating tests fixes and bump podman branch
  • Related: #1883490

[1:1.2.0-5]

  • still use arch exclude as the go_arches macro is broken for 8.4
  • Related: #1883490

[1:1.2.0-4]

  • unify vendored branches
  • add validation script
  • Related: #1883490

[1:1.2.0-3]

  • simplify spec file
  • use short commit ID in tarball name
  • Related: #1883490

[1:1.2.0-2]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[1:1.2.0-1]

  • synchronize with stream-container-tools-rhel8
  • Related: #1883490

[1:1.1.1-3]

  • propagate proper CFLAGS to CGO_CFLAGS to assure code hardening and optimization
  • Related: #1821193

[1:1.1.1-2]

  • drop applied patches
  • Related: #1821193

[1:1.1.1-1]

[1:1.1.0-3]

  • fix broken gating tests: docker unexpectedly removed htpasswd from their 'registry:2' image, so we now use htpasswd from httpd-tools on host.

[1:1.1.0-2]

  • fix 'CVE-2020-14040 skopeo: golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash [rhel-8]'
  • Resolves: #1854719

[1:1.1.0-1]

[1:1.0.0-2]

  • exclude i686 arch
  • Related: #1821193

[1:1.0.0-1]

[1:0.2.0-6]

  • synchronize containter-tools 8.3.0 with 8.2.1
  • Related: #1821193

[1:0.1.41-1]

  • update to 0.1.41
  • Related: #1821193

[1:0.1.40-10]

  • modify registries.conf default configuration to be more secure by default
  • Resolves: #1810053

[1:0.1.40-9]

  • Fix CVE-2020-1702.
  • Resolves: #1801922

[1:0.1.40-8]

  • change the search order of registries and remove quay.io (#1784267)

[1:0.1.40-7]

  • compile in FIPS mode
  • Related: RHELPLAN-25139

[1:0.1.40-6]

  • be sure to use golang >= 1.12.12-4
  • Related: RHELPLAN-25139

[1:0.1.40-5]

  • fix file list
  • Related: RHELPLAN-25139

[1:0.1.40-4]

  • fix symlinks in /usr/share/rhel/secrets and make subscription-manager soft dependency to make them work
  • Related: RHELPLAN-25139

[1:0.1.40-3]

  • rebuild because of CVE-2019-9512 and CVE-2019-9514
  • Resolves: #1772132, #1772137

[1:0.1.40-2]

  • comment out mountopt option in order to fix gating tests see bug 1769769
  • Related: RHELPLAN-25139

[1:0.1.40-1]

  • update to 0.1.40
  • Related: RHELPLAN-25139

[1:0.1.37-5]

  • Fix CVE-2019-10214 (#1734651).

[1:0.1.37-4]

  • fix permissions of rhel/secrets Resolves: #1691543

[1:0.1.37-3]

  • Resolves: #1719994 - add registry.access.redhat.com to registries.conf

[1:0.1.37-2]

  • Resolves: #1721247 - enable fips mode

[1:0.1.37-1]

  • Resolves: #1720654 - rebase to v0.1.37

[1:0.1.36-1.git6307635]

  • built upstream tag v0.1.36, including system tests

[1:0.1.32-4.git1715c90]

  • Fixes @openshift/machine-config-operator#669
  • install /etc/containers/oci/hooks.d and /etc/containers/certs.d

[1:0.1.32-3.git1715c90]

  • rebase

[1:0.1.32-2.git1715c90]

  • re-enable debuginfo

[1:0.1.31-12.gitb0b750d]

  • go tools not in scl anymore

[1:0.1.31-11.gitb0b750d]

  • Resolves: #1615609
  • built upstream tag v0.1.31

[1:0.1.31-10.git0144aa8]

  • Resolves: #1616069 - correct order of registries

[1:0.1.31-9.git0144aa8]

  • Resolves: #1615609 - rebuild with gobuild tag 'no_openssl'

[1:0.1.31-8.git0144aa8]

  • Resolves: #1614934 - containers-common soft dep on slirp4netns and fuse-overlayfs

[1:0.1.31-7.git0144aa8]

  • build with %gobuild
  • use scl-ized go-toolset as dep
  • disable i686 builds temporarily because of go-toolset issues

[1:0.1.31-6.git0144aa8]

  • add statx to seccomp.json to containers-config
  • add seccomp.json to containers-config

[1:0.1.31-4.git0144aa8]

  • Resolves: #1597629 - handle dependency issue for skopeo-containers
  • rename skopeo-containers to containers-common as in Fedora

[1:0.1.31-3.git0144aa8]

  • Resolves: #1583762 - btrfs dep removal needs exclude_graphdriver_btrfs buildtag

[1:0.1.31-2.git0144aa8]

  • correct bz in previous changelog

[1:0.1.31-1.git0144aa8]

  • Resolves: #1580938 - resolve FTBFS
  • Resolves: #1583762 - remove dependency on btrfs-progs-devel
  • bump to v0.1.31 (from master)
  • built commit ca3bff6
  • use go-toolset deps for rhel8

[0.1.29-5.git7add6fc]

  • Fix small typo in registries.conf

[0.1.29-4.git]

  • Add policy.json.5

[0.1.29-3.git]

  • Add registries.conf

[0.1.29-2.git]

  • Add registries.conf man page

[0.1.29-1.git]

  • bump to 0.1.29-1
  • Updated containers/image docker-archive generates docker legacy compatible images Do not create subdirectories for layers with no configs Ensure the layer IDs in legacy docker/tarfile metadata are unique docker-archive: repeated layers are symlinked in the tar file sysregistries: remove all trailing slashes Improve docker/* error messages Fix failure to make auth directory Create a new slice in Schema1.UpdateLayerInfos Drop unused storageImageDestination.{image,systemContext} Load a *storage.Image only once in storageImageSource Support gzip for docker-archive files Remove .tar extension from blob and config file names ostree, src: support copy of compressed layers ostree: re-pull layer if it misses uncompressed_digest|uncompressed_size image: fix docker schema v1 -> OCI conversion Add /etc/containers/certs.d as default certs directory

[0.1.28-2.git0270e56]

[0.1.28-1.git]

  • Vendor in fixed libraries in containers/image and containers/storage

[0.1.27-1.git]

  • Fix Conflicts to Obsoletes
  • Add better docs to man pages.
  • Use credentials from authfile for skopeo commands
  • Support storage='' in /etc/containers/storage.conf
  • Add global --override-arch and --override-os options

[0.1.25-2.git2e8377a7]

  • Add manifest type conversion to skopeo copy
  • User can select from 3 manifest types: oci, v2s1, or v2s2
  • e.g skopeo copy --format v2s1 --compress-blobs docker-archive:alp.tar dir:my-directory

[0.1.25-2.git7fd6f66b]

  • Force storage.conf to default to overlay

[0.1.25-1.git7fd6f66b]

  • Fix CVE in tar-split
  • copy: add shared blob directory support for OCI sources/destinations
  • Aligning Docker version between containers/image and skopeo
  • Update image-tools, and remove the duplicate Sirupsen/logrus vendor
  • makefile: use -buildmode=pie

[0.1.24-8.git28d4e08a]

  • Add /usr/share/containers/mounts.conf

[0.1.24-7.git28d4e08a]

  • Bug fixes
  • Update to release

[0.1.24-6.dev.git28d4e08]

  • skopeo-containers conflicts with docker-rhsubscription <= 2:1.13.1-31

[0.1.24-5.dev.git28d4e08]

  • Add rhel subscription secrets data to skopeo-containers

[0.1.24-4.dev.git28d4e08]

  • Update container/storage.conf and containers-storage.conf man page
  • Default override to true so it is consistent with RHEL.

[0.1.24-3.dev.git28d4e08]

  • built commit 28d4e08

[0.1.24-2.dev.git875dd2e]

  • built commit 875dd2e
  • Resolves: gh#416

[0.1.24-1.dev.gita41cd0]

  • bump to 0.1.24-dev
  • correct a prior bogus date
  • fix macro in comment warning

[0.1.23-6.dev.git1bbd87]

  • Change name of storage.conf.5 man page to containers-storage.conf.5, since it conflicts with inn package
  • Also remove default to 'overalay' in the configuration, since we should
  • allow containers storage to pick the best default for the platform.

[0.1.23-5.git1bbd87f]

[0.1.23-4.git1bbd87f]

  • Rebuild with binutils fix for ppc64le (#1475636)

[0.1.23-3.git1bbd87f]

[0.1.23-2.dev.git1bbd87]

  • Fix storage.conf man page to be storage.conf.5.gz so that it works.

[0.1.23-1.dev.git1bbd87]

  • Support for OCI V1.0 Images
  • Update to image-spec v1.0.0 and revendor
  • Fixes for authentication

[0.1.22-2.dev.git5d24b67]

  • Epoch: 1 for CentOS as CentOS Extras' build already has epoch set to 1

[0.1.22-1.dev.git5d24b67]

  • Give more useful help when explaining usage
  • Also specify container-storage as a valid transport
  • Remove docker reference wherever possible
  • vendor in ostree fixes

[0.1.21-1.dev.git0b73154]

  • Add support for storage.conf and storage-config.5.md from github container storage package
  • Bump to the latest version of skopeo
  • vendor.conf: add ostree-go
  • it is used by containers/image for pulling images to the OSTree storage.
  • fail early when image os does not match host os
  • Improve documentation on what to do with containers/image failures in test-skopeo
  • We now have the docker-archive: transport
  • Integration tests with built registries also exist
  • Support /etc/docker/certs.d
  • update image-spec to v1.0.0-rc6

[0.1.20-1.dev.git0224d8c]

  • BZ #1380078 - New release

[0.1.19-2.dev.git0224d8c]

  • No golang support for ppc64. Adding exclude arch. BZ #1445490

[0.1.19-1.dev.git0224d8c]

  • bump to v0.1.19-dev
  • built commit 0224d8c

[0.1.17-3.dev.git2b3af4a]

[0.1.17-2.dev.git2b3af4a]

  • Rebuild for gpgme 1.18

[0.1.17-1.dev.git2b3af4a]

  • bump to 0.1.17-dev

[0.1.14-6.git550a480]

  • Fix BZ#1391932

[0.1.14-5.git550a480]

  • Conflicts with atomic in skopeo-containers

[0.1.14-4.git550a480]

  • built skopeo-containers

[0.1.14-3.gitd830391]

  • built mtrmac/integrate-all-the-things commit d830391

[0.1.14-2.git362bfc5]

  • built commit 362bfc5

[0.1.14-1.gitffe92ed]

  • build origin/master commit ffe92ed

[0.1.13-6]

[0.1.13-5]

  • include go-srpm-macros and compiler(go-compiler) in fedora conditionals
  • define %gobuild if not already
  • add patch to build with older version of golang

[0.1.13-4]

  • update to v0.1.12

[0.1.12-3]

  • fix go build source path

[0.1.12-2]

  • update to v0.1.12

[0.1.11-1]

  • update to v0.1.11

[0.1.10-1]

  • update to v0.1.10
  • change runcom -> projectatomic

[0.1.9-1]

  • update to v0.1.9

[0.1.8-1]

  • update to v0.1.8

[0.1.4-2]

[0.1.4]

  • First package for Fedora

slirp4netns [1.2.1-1]

[1.2.0-3]

  • BuildRequires: /usr/bin/go-md2man
  • Related: #2176055

udica

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module container-tools:ol8 is enabled

aardvark-dns

1.7.0-1.module+el8.9.0+90021+ce997450

buildah

1.31.3-1.module+el8.9.0+90021+ce997450

buildah-tests

1.31.3-1.module+el8.9.0+90021+ce997450

cockpit-podman

75-1.module+el8.9.0+90021+ce997450

conmon

2.1.8-1.module+el8.9.0+90021+ce997450

container-selinux

2.221.0-1.module+el8.9.0+90021+ce997450

containernetworking-plugins

1.3.0-4.module+el8.9.0+90021+ce997450

containers-common

1-54.0.1.module+el8.9.0+90021+ce997450

crit

3.18-4.module+el8.9.0+90021+ce997450

criu

3.18-4.module+el8.9.0+90021+ce997450

criu-devel

3.18-4.module+el8.9.0+90021+ce997450

criu-libs

3.18-4.module+el8.9.0+90021+ce997450

crun

1.8.7-1.module+el8.9.0+90021+ce997450

fuse-overlayfs

1.12-1.module+el8.9.0+90021+ce997450

libslirp

4.4.0-1.module+el8.9.0+90021+ce997450

libslirp-devel

4.4.0-1.module+el8.9.0+90021+ce997450

netavark

1.7.0-1.module+el8.9.0+90021+ce997450

oci-seccomp-bpf-hook

1.2.9-1.module+el8.9.0+90021+ce997450

podman

4.6.1-4.module+el8.9.0+90021+ce997450

podman-catatonit

4.6.1-4.module+el8.9.0+90021+ce997450

podman-docker

4.6.1-4.module+el8.9.0+90021+ce997450

podman-gvproxy

4.6.1-4.module+el8.9.0+90021+ce997450

podman-plugins

4.6.1-4.module+el8.9.0+90021+ce997450

podman-remote

4.6.1-4.module+el8.9.0+90021+ce997450

podman-tests

4.6.1-4.module+el8.9.0+90021+ce997450

python3-criu

3.18-4.module+el8.9.0+90021+ce997450

python3-podman

4.6.0-1.module+el8.9.0+90021+ce997450

runc

1.1.9-1.module+el8.9.0+90021+ce997450

skopeo

1.13.3-1.module+el8.9.0+90021+ce997450

skopeo-tests

1.13.3-1.module+el8.9.0+90021+ce997450

slirp4netns

1.2.1-1.module+el8.9.0+90021+ce997450

udica

0.2.6-20.module+el8.9.0+90021+ce997450

Oracle Linux x86_64

Module container-tools:ol8 is enabled

aardvark-dns

1.7.0-1.module+el8.9.0+90021+ce997450

buildah

1.31.3-1.module+el8.9.0+90021+ce997450

buildah-tests

1.31.3-1.module+el8.9.0+90021+ce997450

cockpit-podman

75-1.module+el8.9.0+90021+ce997450

conmon

2.1.8-1.module+el8.9.0+90021+ce997450

container-selinux

2.221.0-1.module+el8.9.0+90021+ce997450

containernetworking-plugins

1.3.0-4.module+el8.9.0+90021+ce997450

containers-common

1-54.0.1.module+el8.9.0+90021+ce997450

crit

3.18-4.module+el8.9.0+90021+ce997450

criu

3.18-4.module+el8.9.0+90021+ce997450

criu-devel

3.18-4.module+el8.9.0+90021+ce997450

criu-libs

3.18-4.module+el8.9.0+90021+ce997450

crun

1.8.7-1.module+el8.9.0+90021+ce997450

fuse-overlayfs

1.12-1.module+el8.9.0+90021+ce997450

libslirp

4.4.0-1.module+el8.9.0+90021+ce997450

libslirp-devel

4.4.0-1.module+el8.9.0+90021+ce997450

netavark

1.7.0-1.module+el8.9.0+90021+ce997450

oci-seccomp-bpf-hook

1.2.9-1.module+el8.9.0+90021+ce997450

podman

4.6.1-4.module+el8.9.0+90021+ce997450

podman-catatonit

4.6.1-4.module+el8.9.0+90021+ce997450

podman-docker

4.6.1-4.module+el8.9.0+90021+ce997450

podman-gvproxy

4.6.1-4.module+el8.9.0+90021+ce997450

podman-plugins

4.6.1-4.module+el8.9.0+90021+ce997450

podman-remote

4.6.1-4.module+el8.9.0+90021+ce997450

podman-tests

4.6.1-4.module+el8.9.0+90021+ce997450

python3-criu

3.18-4.module+el8.9.0+90021+ce997450

python3-podman

4.6.0-1.module+el8.9.0+90021+ce997450

runc

1.1.9-1.module+el8.9.0+90021+ce997450

skopeo

1.13.3-1.module+el8.9.0+90021+ce997450

skopeo-tests

1.13.3-1.module+el8.9.0+90021+ce997450

slirp4netns

1.2.1-1.module+el8.9.0+90021+ce997450

udica

0.2.6-20.module+el8.9.0+90021+ce997450

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2023-6938: container-tools:4.0 security and bug fix update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2023-6474: podman security, bug fix, and enhancement update (MODERATE)

oracle-oval
больше 1 года назад

ELSA-2023-6473: buildah security update (MODERATE)

CVSS3: 6.1
ubuntu
около 2 лет назад

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

CVSS3: 6.1
redhat
около 2 лет назад

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.