[ALSA-2024:8112] Important: buildah security update
Type:
security
Severity:
important
Release date:
2024-10-16
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155) * encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156) * go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158) * Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-1.33.9-1.el9_4.aarch64.rpm 3998f7103a816538cbffb72733f0a53a4a5aa186f35a16d146982bf62b9a6713
aarch64 buildah-tests-1.33.9-1.el9_4.aarch64.rpm 9f5998cf6b56ecf79caa0cdcf74c3347f7d92c3f713f30bf43a7173ec2a5e51c
ppc64le buildah-1.33.9-1.el9_4.ppc64le.rpm 48e313abc264ac371afe536d6bdedec27115f86b7bdd28a5078cdd7ed98fbadc
ppc64le buildah-tests-1.33.9-1.el9_4.ppc64le.rpm d10c0eeb4e4221ff7875a20e933dc8b587522633e57ade6e49176d6091b5b3c3
s390x buildah-tests-1.33.9-1.el9_4.s390x.rpm 1c206ed116a0b25cc4d5d04cba370dd147faafaf9ea75680ba225e34b8f493bb
s390x buildah-1.33.9-1.el9_4.s390x.rpm 5f3f4e7c7ea7c575d8030c06354d91caa96bdeca055db0c299de2dd87c3151bb
x86_64 buildah-tests-1.33.9-1.el9_4.x86_64.rpm 75247b05b48d3811374b16bc32e86d071337e9327dbcb4eb714cb69c3bc396cd
x86_64 buildah-1.33.9-1.el9_4.x86_64.rpm b419ffef73b2eefb350b6b17facc26cc8ff0f8d0ba1c54c812a29816ecfdbdb6
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.