Lucene search

K
redhatRedHatRHSA-2019:0975
HistoryMay 07, 2019 - 3:39 a.m.

(RHSA-2019:0975) Important: container-tools:rhel8 security and bug fix update

2019-05-0703:39:11
access.redhat.com
62

0.004 Low

EPSS

Percentile

73.6%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • A flaw was found in the way runc handled system file descriptors when running containers. A malicious container could use this flaw to overwrite contents of the runc binary and consequently run arbitrary commands on the container host system. (CVE-2019-5736)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • [stream rhel8] rebase container-selinux to 2.94 (BZ#1693675)

  • [stream rhel8] unable to mount disk at /var/lib/containers via systemd unit when container-selinux policy installed (BZ#1695669)

  • [stream rhel8] don’t allow a container to connect to random services (BZ#1695689)

OSVersionArchitecturePackageVersionFilename
RedHatanyppc64lebuildah-debuginfo< 1.5-3.gite94b4f9.module+el8.0.0+2958+4e823551buildah-debuginfo-1.5-3.gite94b4f9.module+el8.0.0+2958+4e823551.ppc64le.rpm
RedHatanys390xcontainers-common< 0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551containers-common-0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551.s390x.rpm
RedHatanyaarch64oci-systemd-hook< 0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551oci-systemd-hook-0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551.aarch64.rpm
RedHatanys390xfuse-overlayfs-debuginfo< 0.3-2.module+el8.0.0+2958+4e823551fuse-overlayfs-debuginfo-0.3-2.module+el8.0.0+2958+4e823551.s390x.rpm
RedHatanyaarch64oci-systemd-hook-debugsource< 0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551oci-systemd-hook-debugsource-0.1.15-2.git2d0b8a3.module+el8.0.0+2958+4e823551.aarch64.rpm
RedHatanyaarch64skopeo< 0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551skopeo-0.1.32-3.git1715c90.module+el8.0.0+2958+4e823551.aarch64.rpm
RedHatanys390xoci-umount-debuginfo< 2.3.4-2.git87f9237.module+el8.0.0+2958+4e823551oci-umount-debuginfo-2.3.4-2.git87f9237.module+el8.0.0+2958+4e823551.s390x.rpm
RedHatanyaarch64containernetworking-plugins-debuginfo< 0.7.4-3.git9ebe139.module+el8.0.0+2958+4e823551containernetworking-plugins-debuginfo-0.7.4-3.git9ebe139.module+el8.0.0+2958+4e823551.aarch64.rpm
RedHatanyaarch64podman< 1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551podman-1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551.aarch64.rpm
RedHatanyx86_64podman-debuginfo< 1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551podman-debuginfo-1.0.0-2.git921f98f.module+el8.0.0+2958+4e823551.x86_64.rpm
Rows per page:
1-10 of 1141