CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
17.1%
An update is available for podman.
This update affects Rocky Linux 9.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.
Security Fixes:
podman: jose-go: improper handling of highly compressed data (CVE-2024-28180)
podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
podman: jose: resource exhaustion (CVE-2024-28176)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
rocky | 9 | aarch64 | podman | < 4.9.4-4.el9_4 | podman-4:4.9.4-4.el9_4.aarch64.rpm |
rocky | 9 | ppc64le | podman | < 4.9.4-4.el9_4 | podman-4:4.9.4-4.el9_4.ppc64le.rpm |
rocky | 9 | s390x | podman | < 4.9.4-4.el9_4 | podman-4:4.9.4-4.el9_4.s390x.rpm |
rocky | 9 | x86_64 | podman | < 4.9.4-4.el9_4 | podman-4:4.9.4-4.el9_4.x86_64.rpm |
rocky | 9 | aarch64 | podman-debuginfo | < 4.9.4-4.el9_4 | podman-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm |
rocky | 9 | ppc64le | podman-debuginfo | < 4.9.4-4.el9_4 | podman-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm |
rocky | 9 | s390x | podman-debuginfo | < 4.9.4-4.el9_4 | podman-debuginfo-4:4.9.4-4.el9_4.s390x.rpm |
rocky | 9 | x86_64 | podman-debuginfo | < 4.9.4-4.el9_4 | podman-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm |
rocky | 9 | aarch64 | podman-debugsource | < 4.9.4-4.el9_4 | podman-debugsource-4:4.9.4-4.el9_4.aarch64.rpm |
rocky | 9 | ppc64le | podman-debugsource | < 4.9.4-4.el9_4 | podman-debugsource-4:4.9.4-4.el9_4.ppc64le.rpm |