Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:4154

Опубликовано: 09 нояб. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • buildah: Host environment variables leaked in build container when using chroot isolation (CVE-2021-3602)

  • containers/storage: DoS via malicious image (CVE-2021-20291)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
buildahaarch642.module+el8.5.0+710+4c471e88buildah-1.22.3-2.module+el8.5.0+710+4c471e88.aarch64.rpm
buildah-testsaarch642.module+el8.5.0+710+4c471e88buildah-tests-1.22.3-2.module+el8.5.0+710+4c471e88.aarch64.rpm
cockpit-podmannoarch1.module+el8.5.0+710+4c471e88cockpit-podman-33-1.module+el8.5.0+710+4c471e88.noarch.rpm
conmonaarch641.module+el8.4.0+643+525e162aconmon-2.0.29-1.module+el8.4.0+643+525e162a.aarch64.rpm
conmonaarch641.module+el8.5.0+710+4c471e88conmon-2.0.29-1.module+el8.5.0+710+4c471e88.aarch64.rpm
containernetworking-pluginsaarch641.module+el8.5.0+710+4c471e88containernetworking-plugins-1.0.0-1.module+el8.5.0+710+4c471e88.aarch64.rpm
containers-commonnoarch2.module+el8.5.0+710+4c471e88containers-common-1-2.module+el8.5.0+710+4c471e88.noarch.rpm
container-selinuxnoarch1.module+el8.4.0+653+ad26b47dcontainer-selinux-2.167.0-1.module+el8.4.0+653+ad26b47d.noarch.rpm
container-selinuxnoarch1.module+el8.5.0+709+440d5e7econtainer-selinux-2.167.0-1.module+el8.5.0+709+440d5e7e.noarch.rpm
critaarch643.module+el8.7.0+1077+0e4f03d4crit-3.15-3.module+el8.7.0+1077+0e4f03d4.aarch64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
почти 5 лет назад

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

suse-cvrf
около 4 лет назад

Security update for libcontainers-common

suse-cvrf
больше 4 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

suse-cvrf
больше 4 лет назад

Security update for conmon, libcontainers-common, libseccomp, podman

CVSS3: 6.5
ubuntu
больше 5 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).