[ALSA-2024:9459] Important: buildah security update
Type:
security
Severity:
important
Release date:
2024-11-18
Description:
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155) * encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156) * go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158) * Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341) * Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407) * buildah: Buildah allows arbitrary directory mount (CVE-2024-9675) * Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) (CVE-2024-9676) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 buildah-tests-1.37.5-1.el9_5.aarch64.rpm 3592912d853646ab170150852c10ee0062bf76cbab4e4bef9e4148ab415511bb
aarch64 buildah-1.37.5-1.el9_5.aarch64.rpm 68ca3737ca4de3a49b4781951b0645cd218eba3dce55ba9a843e3066bfab6bfb
ppc64le buildah-1.37.5-1.el9_5.ppc64le.rpm e30cdb268a139004c855673ba30a5793f5e0ff4c975ef5b17d02aec864b4f973
ppc64le buildah-tests-1.37.5-1.el9_5.ppc64le.rpm f16bad7345de09d7c0748a499d36e4fac10aeb4ebec94d43009305faaec5f279
s390x buildah-1.37.5-1.el9_5.s390x.rpm a014dd0e7136aab5be3c19916de77a949fb976e4443cfba67b492502c6e37c71
s390x buildah-tests-1.37.5-1.el9_5.s390x.rpm bdd58dcc077d2d7faba14c33d8ce576e3e3119e81be8de9cbaa94e73c9df1cc1
x86_64 buildah-1.37.5-1.el9_5.x86_64.rpm 770bfc0f3d72452743e0769eae42a48253d14a28e2e6b56e34a2c2b321977c8b
x86_64 buildah-tests-1.37.5-1.el9_5.x86_64.rpm e66ab223dbff823a51cfd26cd9cd56fe2d4af7eab1ad9ffdf860797874e7ecd3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.