[ALSA-2020:1379] Important: container-tools:rhel8 security and bug fix update
Type:
security
Severity:
important
Release date:
2020-04-07
Description:
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * QEMU: Slirp: potential OOB access due to unsafe snprintf() usages (CVE-2020-8608) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * useradd and groupadd fail under rootless Buildah and podman [stream-container-tools-rhel8-rhel-8.1.1] (BZ#1803495) * Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1804188) * Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/podman] (BZ#1804194) * fuse-overlayfs segfault [stream-container-tools-rhel8-rhel-8.1.1/fuse-overlayfs] (BZ#1805016) * buildah COPY command is slow when .dockerignore file is not present [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1806119)
Updated packages listed below:
Architecture Package Checksum
aarch64 slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39.aarch64.rpm 2786570cbf046a16552fe8233eee3a7d5ab9166149e4f93c34d0866eac85f4b0
aarch64 containernetworking-plugins-0.8.3-4.module_el8.5.0+2635+e4386a39.aarch64.rpm 3fc278dc589b45a61931e18a3858f4df6df283432593810e12a22135486e5628
noarch cockpit-podman-11-1.module_el8.5.0+108+00865455.noarch.rpm 3525134cda7e981fe2ded68c4813ce09c7efece2c6d8c3f8f4b4da268c647f86
noarch udica-0.2.1-2.module_el8.5.0+108+00865455.noarch.rpm 49cfff6dc507f3d74fb6e02a7fd3da4cf45ab5291e37c150c487a8bd14eb2884
noarch python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+2635+e4386a39.noarch.rpm 6014c5c3fb0e8b251cf8fe13d9dc538fe94d16ae2bfbf82206773d07378a433e
noarch cockpit-podman-11-1.module_el8.5.0+2635+e4386a39.noarch.rpm 691ee7e18ff98e8dcd548dbb4737bb9dd7755779f6aba83e688b66a32fdf2ecf
noarch udica-0.2.1-2.module_el8.5.0+2635+e4386a39.noarch.rpm 9b886f6e05c447d885e09a28818a3bd3b96d150c5b5498cf2e71df0a54c891a0
noarch python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+108+00865455.noarch.rpm bb7cecd971e77ee0ad43f29b3351871450f3fb08b180f0fae99cc0bf904cc0b5
ppc64le containernetworking-plugins-0.8.3-4.module_el8.5.0+108+00865455.ppc64le.rpm 4aa34a1d9ae2e5e4d3d582b8f88a5a4be19dee53577dc43de68c41652f3715d1
ppc64le slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+108+00865455.ppc64le.rpm a33c8ba5b6acbf644a149fd9f64317b4443ae46ebe4b2f7f30ab6ca7c953eca3
x86_64 containernetworking-plugins-0.8.3-4.module_el8.5.0+2635+e4386a39.x86_64.rpm 1fe0f63af6df749a7c1a66a5706677b9d98308002b72f928c89bc8835a22a6a3
x86_64 slirp4netns-0.4.2-3.git21fdece.module_el8.5.0+2635+e4386a39.x86_64.rpm 872ed560d33d70e3e657deeedd8b39852165aed41071d03fdfc22107a83e0b37
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.