[ALSA-2024:2245] Moderate: buildah security update
Type:
security
Severity:
moderate
Release date:
2024-05-07
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326) * golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. (CVE-2023-45287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-1.33.6-2.el9.aarch64.rpm 292028669412eac79369299fd33fa27df013f79c0b31d5abbb8962803519c15a
aarch64 buildah-tests-1.33.6-2.el9.aarch64.rpm c1e79d140c34564edb404049785014470dd38a7f47f18b8157b23c5b05c58983
ppc64le buildah-tests-1.33.6-2.el9.ppc64le.rpm 1ecc097b5eed782d65393c4981ccfb06b87dfdc713bff6eb8f62d9dc2576f02f
ppc64le buildah-1.33.6-2.el9.ppc64le.rpm c24fe272b1cd406d2d67621314bce83ccb0df973f4563cc4907e315b7c224f28
s390x buildah-1.33.6-2.el9.s390x.rpm 271fa7bdb4b4c44dd65b584284ce1016899bf9f5dc85139b24bec807cc17f2b7
s390x buildah-tests-1.33.6-2.el9.s390x.rpm 67bc5eff13f5c0ea02cef144f2cc195ed910ca15449c6fd516fc2a9656dc243c
x86_64 buildah-1.33.6-2.el9.x86_64.rpm 00813c474a459fa9d94447525d38c9a488e5c75a382e78b9d0868bf5e7336043
x86_64 buildah-tests-1.33.6-2.el9.x86_64.rpm 5e950517f37da5bf220cb7acafa9f9e6d792f9cb7894bde396849fba7a6980ff
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.