Lucene search

K
redhatRedHatRHSA-2021:4222
HistoryNov 09, 2021 - 8:46 a.m.

(RHSA-2021:4222) Moderate: container-tools:3.0 security and bug fix update

2021-11-0908:46:34
access.redhat.com
89

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

15.5%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • buildah: Host environment variables leaked in build container when using chroot isolation (CVE-2021-3602)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanyx86_64buildah-tests< 1.19.9-1.module+el8.5.0+12236+c988d830buildah-tests-1.19.9-1.module+el8.5.0+12236+c988d830.x86_64.rpm
RedHatanyppc64lebuildah-debuginfo< 1.19.9-1.module+el8.5.0+12236+c988d830buildah-debuginfo-1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le.rpm
RedHatanyppc64leoci-seccomp-bpf-hook-debugsource< 1.2.0-3.module+el8.5.0+11073+ba5c6d09oci-seccomp-bpf-hook-debugsource-1.2.0-3.module+el8.5.0+11073+ba5c6d09.ppc64le.rpm
RedHatanyx86_64skopeo-debuginfo< 1.2.2-10.module+el8.5.0+11808+4e1db630skopeo-debuginfo-1.2.2-10.module+el8.5.0+11808+4e1db630.x86_64.rpm
RedHatanyx86_64fuse-overlayfs-debuginfo< 1.4.0-2.module+el8.5.0+10306+3f72d66dfuse-overlayfs-debuginfo-1.4.0-2.module+el8.5.0+10306+3f72d66d.x86_64.rpm
RedHatanyaarch64toolbox-tests< 0.0.99-1.module+el8.5.0+10306+3f72d66dtoolbox-tests-0.0.99-1.module+el8.5.0+10306+3f72d66d.aarch64.rpm
RedHatanyppc64lepodman-remote-debuginfo< 3.0.1-6.module+el8.5.0+12609+beaa716dpodman-remote-debuginfo-3.0.1-6.module+el8.5.0+12609+beaa716d.ppc64le.rpm
RedHatanys390xcontainernetworking-plugins< 0.9.1-1.module+el8.5.0+10306+3f72d66dcontainernetworking-plugins-0.9.1-1.module+el8.5.0+10306+3f72d66d.s390x.rpm
RedHatanyppc64lefuse-overlayfs-debugsource< 1.4.0-2.module+el8.5.0+10306+3f72d66dfuse-overlayfs-debugsource-1.4.0-2.module+el8.5.0+10306+3f72d66d.ppc64le.rpm
RedHatanyx86_64skopeo-debugsource< 1.2.2-10.module+el8.5.0+11808+4e1db630skopeo-debugsource-1.2.2-10.module+el8.5.0+11808+4e1db630.x86_64.rpm
Rows per page:
1-10 of 2201

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

15.5%