[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2023:6939 -- Redhat aardvark-dns, buildah, cockpit-podman, conmon, container-selinux, containernetworking-plugins, containers-common, criu, crun, fuse-overlayfs, libslirp, netavark, oci-seccomp-bpf-hook, podman, python-podman, runc, skopeo, slirp4netns, toolbox, udica, crit, python3-criu, python3-podman

ID: oval:org.secpod.oval:def:508170Date: (C)2024-01-04   (M)2024-06-24
Class: PATCHFamily: unix




The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix: go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents golang: html/template: improper handling of JavaScript whitespace net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang.org/x/net/html: Cross site scripting golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values containerd: Supplementary groups are not set up properly runc: Rootless runc makes `/sys/fs/cgroup` writable runc: volume mount race condition runc: AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration golang: html/template: improper handling of empty HTML attributes golang: net/ http: insufficient sanitization of Host header For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.9 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 8
Product:
aardvark-dns
buildah
cockpit-podman
conmon
container-selinux
containernetworking-plugins
containers-common
criu
crun
fuse-overlayfs
libslirp
netavark
oci-seccomp-bpf-hook
podman
python-podman
runc
skopeo
slirp4netns
toolbox
udica
crit
python3-criu
python3-podman
Reference:
RHSA-2023:6939
CVE-2022-3064
CVE-2023-24540
CVE-2022-41723
CVE-2022-41724
CVE-2022-41725
CVE-2023-3978
CVE-2023-24534
CVE-2023-24536
CVE-2023-24537
CVE-2023-24538
CVE-2023-24539
CVE-2023-25173
CVE-2023-25809
CVE-2019-19921
CVE-2023-27561
CVE-2023-28642
CVE-2023-29400
CVE-2023-29406
CVE    18
CVE-2019-19921
CVE-2023-25809
CVE-2023-28642
CVE-2023-27561
...

© SecPod Technologies