Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:1762

Опубликовано: 10 мая 2022
Источник: rocky
Оценка: Important

Описание

Important: container-tools:rhel8 security, bug fix, and enhancement update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • psgo: Privilege escalation in 'podman top' (CVE-2022-1227)

  • prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)

  • podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)

  • crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)

  • buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
critx86_643.module+el8.7.0+1077+0e4f03d4crit-3.15-3.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
criux86_643.module+el8.7.0+1077+0e4f03d4criu-3.15-3.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
criu-develx86_643.module+el8.7.0+1077+0e4f03d4criu-devel-3.15-3.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
criu-libsx86_643.module+el8.7.0+1077+0e4f03d4criu-libs-3.15-3.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
libslirpx86_641.module+el8.7.0+1077+0e4f03d4libslirp-4.4.0-1.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
libslirp-develx86_641.module+el8.7.0+1077+0e4f03d4libslirp-devel-4.4.0-1.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
python3-criux86_643.module+el8.7.0+1077+0e4f03d4python3-criu-3.15-3.module+el8.7.0+1077+0e4f03d4.x86_64.rpm
python3-podmannoarch1.module+el8.7.0+1077+0e4f03d4python3-podman-4.0.0-1.module+el8.7.0+1077+0e4f03d4.noarch.rpm
slirp4netnsx86_642.module+el8.7.0+1077+0e4f03d4slirp4netns-1.1.8-2.module+el8.7.0+1077+0e4f03d4.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 3 лет назад

ELSA-2022-1762: container-tools:ol8 security, bug fix, and enhancement update (IMPORTANT)

suse-cvrf
почти 3 года назад

Security update for podman

suse-cvrf
почти 3 года назад

Security update for podman

CVSS3: 8.8
redos
почти 2 года назад

Множественные уязвимости podman

CVSS3: 8.8
ubuntu
около 3 лет назад

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.