Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-0923

Опубликовано: 04 фев. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-0923: buildah security update (IMPORTANT)

[1.37.6-1.0.1]

  • Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[2:1.37.6-1]

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

buildah

1.37.6-1.0.1.el9_5

buildah-tests

1.37.6-1.0.1.el9_5

Oracle Linux x86_64

buildah

1.37.6-1.0.1.el9_5

buildah-tests

1.37.6-1.0.1.el9_5

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
7 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

CVSS3: 8.6
redhat
7 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

CVSS3: 8.6
nvd
7 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

CVSS3: 8.6
debian
7 месяцев назад

A vulnerability was found in `podman build` and `buildah.` This issue ...

suse-cvrf
6 месяцев назад

Security update for podman