Описание
Moderate: container-tools:3.0 security update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.
Security Fix(es):
-
golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
-
cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708)
-
golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
-
prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
-
golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
-
golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
-
golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
-
golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
-
golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
-
golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.
Затронутые продукты
Rocky Linux 8
Ссылки на источники
Исправления
- Red Hat - 2045880
- Red Hat - 2085361
- Red Hat - 2107342
- Red Hat - 2107371
- Red Hat - 2107374
- Red Hat - 2107376
- Red Hat - 2107383
- Red Hat - 2107386
- Red Hat - 2107390
- Red Hat - 2107392
Связанные уязвимости
ELSA-2022-7529: container-tools:3.0 security update (MODERATE)
ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)
ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)