Описание
Moderate: container-tools:rhel8 security, bug fix, and enhancement update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
-
golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221)
-
cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708)
-
golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)
-
opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190)
-
buildah: possible information disclosure and modification (CVE-2022-2990)
-
runc: incorrect handling of inheritable capabilities (CVE-2022-29162)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Затронутые продукты
Rocky Linux 8
Ссылки на источники
Исправления
- Red Hat - 1820551
- Red Hat - 1941727
- Red Hat - 1945929
- Red Hat - 1974423
- Red Hat - 1995656
- Red Hat - 1996050
- Red Hat - 2005866
- Red Hat - 2009264
- Red Hat - 2009346
- Red Hat - 2024938
- Red Hat - 2027662
- Red Hat - 2028408
- Red Hat - 2030195
- Red Hat - 2039045
- Red Hat - 2052697
- Red Hat - 2053990
- Red Hat - 2055313
- Red Hat - 2059666
- Red Hat - 2062697
- Red Hat - 2064702
Связанные уязвимости
ELSA-2022-7457: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.