Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:1762

Опубликовано: 10 мая 2022
Источник: rocky
Оценка: Important

Описание

Important: container-tools:rhel8 security, bug fix, and enhancement update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • psgo: Privilege escalation in 'podman top' (CVE-2022-1227)

  • prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)

  • podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)

  • crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)

  • buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
aardvark-dnsaarch6427.module+el8.6.0+785+d1251653aardvark-dns-1.0.1-27.module+el8.6.0+785+d1251653.aarch64.rpm
buildahaarch644.module+el8.6.0+785+d1251653buildah-1.24.2-4.module+el8.6.0+785+d1251653.aarch64.rpm
buildah-testsaarch644.module+el8.6.0+785+d1251653buildah-tests-1.24.2-4.module+el8.6.0+785+d1251653.aarch64.rpm
cockpit-podmannoarch1.module+el8.6.0+784+32aef5decockpit-podman-43-1.module+el8.6.0+784+32aef5de.noarch.rpm
conmonaarch641.module+el8.6.0+784+32aef5deconmon-2.1.0-1.module+el8.6.0+784+32aef5de.aarch64.rpm
containernetworking-pluginsaarch642.module+el8.6.0+785+d1251653containernetworking-plugins-1.0.1-2.module+el8.6.0+785+d1251653.aarch64.rpm
containers-commonaarch6427.module+el8.6.0+785+d1251653containers-common-1-27.module+el8.6.0+785+d1251653.aarch64.rpm
container-selinuxnoarch1.module+el8.6.0+785+d1251653container-selinux-2.179.1-1.module+el8.6.0+785+d1251653.noarch.rpm
critaarch643.module+el8.7.0+1077+0e4f03d4crit-3.15-3.module+el8.7.0+1077+0e4f03d4.aarch64.rpm
critaarch643.module+el8.5.0+710+4c471e88crit-3.15-3.module+el8.5.0+710+4c471e88.aarch64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 4 лет назад

ELSA-2022-1762: container-tools:ol8 security, bug fix, and enhancement update (IMPORTANT)

suse-cvrf
почти 4 года назад

Security update for podman

suse-cvrf
почти 4 года назад

Security update for podman

CVSS3: 8.8
ubuntu
больше 4 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

CVSS3: 8
redhat
около 5 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.