[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252212

 
 

909

 
 

196748

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2019:4269-01 -- Redhat buildah, cockpit-podman, container-selinux, containernetworking-plugins, fuse-overlayfs, oci-systemd-hook, oci-umount, podman, python-podman-api, runc, skopeo, slirp4netns, toolbox

ID: oval:org.secpod.oval:def:66674Date: (C)2020-11-09   (M)2024-05-22
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: * HTTP/2: flood using PING frames results in unbounded memory growth * HTTP/2: flood using HEADERS frames results in unbounded memory growth * runc: AppArmor/SELinux bypass with malicious image that specifies a volume at /proc For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: * avc: podman run --security-opt label=type:svirt_qemu_net_t * backport json-file logging support to 1.4.2 * Selinux won"t allow SCTP inter pod communication

Platform:
Red Hat Enterprise Linux 8
Product:
buildah
cockpit-podman
container-selinux
containernetworking-plugins
fuse-overlayfs
oci-systemd-hook
oci-umount
podman
python-podman-api
runc
skopeo
slirp4netns
toolbox
Reference:
RHSA-2019:4269-01
CVE-2019-9512
CVE-2019-9514
CVE-2019-16884
CVE-2019-18466
CVE    4
CVE-2019-18466
CVE-2019-16884
CVE-2019-9512
CVE-2019-9514
...

© SecPod Technologies