[ALSA-2020:4694] Moderate: container-tools:rhel8 security, bug fix, and enhancement update
Type:
security
Severity:
moderate
Release date:
2020-11-03
Description:
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters (CVE-2020-10749) * QEMU: slirp: networking out-of-bounds read information disclosure vulnerability (CVE-2020-10756) * golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages:
  • libslirp-devel-4.3.1-1.module_el8.6.0+2876+9ed4eae2.x86_64.rpm
  • python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+2635+e4386a39.noarch.rpm
  • libslirp-4.3.1-1.module_el8.6.0+2876+9ed4eae2.x86_64.rpm
  • libslirp-devel-4.3.1-1.module_el8.6.0+2876+9ed4eae2.aarch64.rpm
  • libslirp-4.3.1-1.module_el8.6.0+2876+9ed4eae2.aarch64.rpm
  • libslirp-devel-4.3.1-1.module_el8.6.0+2876+9ed4eae2.ppc64le.rpm
  • python-podman-api-1.2.0-0.2.gitd0a45fe.module_el8.5.0+108+00865455.noarch.rpm
  • libslirp-4.3.1-1.module_el8.6.0+2876+9ed4eae2.ppc64le.rpm
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.