[ALSA-2020:1379] Important: container-tools:rhel8 security and bug fix update
Type:
security
Severity:
important
Release date:
2020-04-07
Description:
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * QEMU: Slirp: potential OOB access due to unsafe snprintf() usages (CVE-2020-8608) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * useradd and groupadd fail under rootless Buildah and podman [stream-container-tools-rhel8-rhel-8.1.1] (BZ#1803495) * Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1804188) * Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/podman] (BZ#1804194) * fuse-overlayfs segfault [stream-container-tools-rhel8-rhel-8.1.1/fuse-overlayfs] (BZ#1805016) * buildah COPY command is slow when .dockerignore file is not present [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1806119)
Updated packages:
  • containernetworking-plugins-0.8.3-4.module_el8.5.0+2635+e4386a39.x86_64.rpm
  • python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+2635+e4386a39.noarch.rpm
  • cockpit-podman-11-1.module_el8.5.0+2635+e4386a39.noarch.rpm
  • slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39.x86_64.rpm
  • udica-0.2.1-2.module_el8.5.0+2635+e4386a39.noarch.rpm
  • slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39.aarch64.rpm
  • containernetworking-plugins-0.8.3-4.module_el8.5.0+2635+e4386a39.aarch64.rpm
  • containernetworking-plugins-0.8.3-4.module_el8.5.0+108+00865455.ppc64le.rpm
  • python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+108+00865455.noarch.rpm
  • cockpit-podman-11-1.module_el8.5.0+108+00865455.noarch.rpm
  • slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+108+00865455.ppc64le.rpm
  • udica-0.2.1-2.module_el8.5.0+108+00865455.noarch.rpm
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.