[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255227

 
 

909

 
 

198741

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RLSA-2022:1762 --- cockpit-podman

ID: oval:org.secpod.oval:def:4500933Date: (C)2023-04-03   (M)2023-11-13
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * psgo: Privilege escalation in "podman top" * prometheus/client_golang: Denial of service using InstrumentHandlerCounter * podman: Default inheritable capabilities for linux container should be empty * crun: Default inheritable capabilities for linux container should be empty * buildah: Default inheritable capabilities for linux container should be empty For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.

Platform:
Rocky Linux 8
Product:
cockpit-podman
libslirp
conmon
python-podman
crun
fuse-overlayfs
containernetworking-plugins
oci-seccomp-bpf-hook
udica
podman
runc
slirp4netns
container-selinux
containers-common
criu
buildah
skopeo
aardvark-dns
crit
netavark
python3-criu
toolbox
python3-podman
Reference:
RLSA-2022:1762
CVE-2022-1227
CVE-2022-21698
CVE-2022-27649
CVE-2022-27650
CVE-2022-27651
CVE    5
CVE-2022-1227
CVE-2022-27649
CVE-2022-27650
CVE-2022-27651
...
CPE    19
cpe:/a:oci-seccomp-bpf-hook:oci-seccomp-bpf-hook
cpe:/a:containernetworking:containernetworking-plugins
cpe:/a:freedesktop:libslirp
cpe:/a:libslirp:slirp4netns
...

© SecPod Technologies