Lucene search

K
redhatRedHatRHSA-2024:3254
HistoryMay 22, 2024 - 10:41 a.m.

(RHSA-2024:3254) Important: container-tools:rhel8 security update

2024-05-2210:41:20
access.redhat.com
8
container-tools
rhel8
security update
podman
buildah
skopeo
runc
cve-2024-1753
cve-2022-2880
cve-2022-41715
cve-2024-24786
cve-2024-28180

8.6 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

7.3 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.1%

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • buildah: full container escape at build time (CVE-2024-1753)

  • golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)

  • golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)

  • golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)

  • jose-go: improper handling of highly compressed data (CVE-2024-28180)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanys390xcontainernetworking-plugins-debuginfo< 1.4.0-2.module+el8.10.0+21366+f9cb49f8containernetworking-plugins-debuginfo-1.4.0-2.module+el8.10.0+21366+f9cb49f8.s390x.rpm
RedHatanyx86_64libslirp-debugsource< 4.4.0-2.module+el8.10.0+21672+01ba06aelibslirp-debugsource-4.4.0-2.module+el8.10.0+21672+01ba06ae.x86_64.rpm
RedHatanyaarch64podman-plugins< 4.9.4-1.module+el8.10.0+21632+761e0d34podman-plugins-4.9.4-1.module+el8.10.0+21632+761e0d34.aarch64.rpm
RedHatanyaarch64containernetworking-plugins< 1.4.0-2.module+el8.10.0+21366+f9cb49f8containernetworking-plugins-1.4.0-2.module+el8.10.0+21366+f9cb49f8.aarch64.rpm
RedHatanyaarch64toolbox-debugsource< 0.0.99.5-2.module+el8.10.0+21341+ff0b5f89toolbox-debugsource-0.0.99.5-2.module+el8.10.0+21341+ff0b5f89.aarch64.rpm
RedHatanyaarch64buildah-debuginfo< 1.33.7-1.module+el8.10.0+21590+d7d75709buildah-debuginfo-1.33.7-1.module+el8.10.0+21590+d7d75709.aarch64.rpm
RedHatanyaarch64oci-seccomp-bpf-hook< 1.2.10-1.module+el8.10.0+20565+a40ba0e5oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+20565+a40ba0e5.aarch64.rpm
RedHatanyppc64lecontainernetworking-plugins-debuginfo< 1.4.0-2.module+el8.10.0+21366+f9cb49f8containernetworking-plugins-debuginfo-1.4.0-2.module+el8.10.0+21366+f9cb49f8.ppc64le.rpm
RedHatanyx86_64criu-libs< 3.18-5.module+el8.10.0+21672+01ba06aecriu-libs-3.18-5.module+el8.10.0+21672+01ba06ae.x86_64.rpm
RedHatanyppc64leslirp4netns-debugsource< 1.2.3-1.module+el8.10.0+21306+6be40ce7slirp4netns-debugsource-1.2.3-1.module+el8.10.0+21306+6be40ce7.ppc64le.rpm
Rows per page:
1-10 of 2411

8.6 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

7.3 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.1%