Lucene search

K
osvGoogleOSV:RLSA-2024:2098
HistoryMay 06, 2024 - 1:04 p.m.

Important: container-tools:rhel8 security and bug fix update

2024-05-0613:04:21
Google
osv.dev
5
container-tools module
podman
buildah
skopeo
runc
security fix
bug fix
ptrace process context
cve-2024-1753

8.6 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Bug Fix(es):

  • container_init_t does not possess ptrace process context [rhel-8.9.0.z] (JIRA:Rocky Linux-28923)

Security Fix(es):

  • podman: full container escape at build time (CVE-2024-1753)

8.6 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%