RLSA-2020:1379

See a problem?
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2020:1379.json
JSON Data
https://api.osv.dev/v1/vulns/RLSA-2020:1379
Related
Published
2020-04-07T09:15:36Z
Modified
2023-02-02T13:02:04.334443Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Important: container-tools:rhel8 security and bug fix update
Details

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • QEMU: Slirp: potential OOB access due to unsafe snprintf() usages (CVE-2020-8608)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • useradd and groupadd fail under rootless Buildah and podman [stream-container-tools-Rocky Linux8-Rocky Linux-8.1.1] (BZ#1803495)

  • Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-Rocky Linux8-Rocky Linux-8.1.1/buildah] (BZ#1804188)

  • Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-Rocky Linux8-Rocky Linux-8.1.1/podman] (BZ#1804194)

  • fuse-overlayfs segfault [stream-container-tools-Rocky Linux8-Rocky Linux-8.1.1/fuse-overlayfs] (BZ#1805016)

  • buildah COPY command is slow when .dockerignore file is not present [stream-container-tools-Rocky Linux8-Rocky Linux-8.1.1/buildah] (BZ#1806119)

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / cockpit-podman

Package

Name
cockpit-podman
Purl
pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:11-1.module+el8.5.0+770+e2f49861

Rocky Linux:8 / cockpit-podman

Package

Name
cockpit-podman
Purl
pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8-4-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:11-1.module+el8.4.0+559+c02fa3b2

Rocky Linux:8 / cockpit-podman

Package

Name
cockpit-podman
Purl
pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8-5-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:11-1.module+el8.5.0+708+6758137d

Rocky Linux:8 / containernetworking-plugins

Package

Name
containernetworking-plugins
Purl
pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.8.3-4.module+el8.5.0+770+e2f49861

Rocky Linux:8 / containernetworking-plugins

Package

Name
containernetworking-plugins
Purl
pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8-4-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.8.3-4.module+el8.4.0+559+c02fa3b2

Rocky Linux:8 / containernetworking-plugins

Package

Name
containernetworking-plugins
Purl
pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8-5-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.8.3-4.module+el8.5.0+708+6758137d

Rocky Linux:8 / python-podman-api

Package

Name
python-podman-api
Purl
pkg:rpm/rocky-linux/python-podman-api?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-0.2.gitd0a45fe.module+el8.5.0+770+e2f49861

Rocky Linux:8 / python-podman-api

Package

Name
python-podman-api
Purl
pkg:rpm/rocky-linux/python-podman-api?distro=rocky-linux-8-4-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-0.2.gitd0a45fe.module+el8.4.0+559+c02fa3b2

Rocky Linux:8 / python-podman-api

Package

Name
python-podman-api
Purl
pkg:rpm/rocky-linux/python-podman-api?distro=rocky-linux-8-5-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.2.0-0.2.gitd0a45fe.module+el8.5.0+708+6758137d

Rocky Linux:8 / slirp4netns

Package

Name
slirp4netns
Purl
pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.4.2-3.git21fdece.module+el8.5.0+770+e2f49861

Rocky Linux:8 / slirp4netns

Package

Name
slirp4netns
Purl
pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8-4-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.4.2-3.git21fdece.module+el8.4.0+536+994a2182

Rocky Linux:8 / slirp4netns

Package

Name
slirp4netns
Purl
pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8-5-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.4.2-3.git21fdece.module+el8.5.0+708+6758137d

Rocky Linux:8 / udica

Package

Name
udica
Purl
pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.2.1-2.module+el8.5.0+770+e2f49861

Rocky Linux:8 / udica

Package

Name
udica
Purl
pkg:rpm/rocky-linux/udica?distro=rocky-linux-8-4-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.2.1-2.module+el8.4.0+559+c02fa3b2

Rocky Linux:8 / udica

Package

Name
udica
Purl
pkg:rpm/rocky-linux/udica?distro=rocky-linux-8-5-legacy&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:0.2.1-2.module+el8.5.0+708+6758137d

Rocky Linux:8 / container-selinux

Package

Name
container-selinux
Purl
pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:2.124.0-1.gitf958d0c.module+el8.5.0+681+c9a1951f