Lucene search

K
oraclelinuxOracleLinuxELSA-2023-12578
HistoryJul 19, 2023 - 12:00 a.m.

buildah security update

2023-07-1900:00:00
linux.oracle.com
14
buildah
runc
security vulnerabilities
rootless
symlinks
/sys
/proc
cve-2023-25809
cve-2023-27561
cve-2023-28642
jira
oldis-25589
unix

0.001 Low

EPSS

Percentile

19.2%

runc
[1:1.1.4-1.0.1]

  • rootless: fix /sys/fs/cgroup mounts to prevent CVE-2023-25809
  • rootfs: prohibit symlinks that conflicts with readonlyPaths
    and/or maskedPaths to prevent CVE-2023-27561
  • Prohibit /proc and /sys to be symlinks to prevent CVE-2023-28642
  • JIRA: OLDIS-25589