Important: container-tools:rhel8 security, bug fix, and enhancement update

Synopsis

Important: container-tools:rhel8 security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Topic

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)
  • containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure (CVE-2019-10214)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1655211 - podman exec seems to assume console even if -ti is not used
  • BZ - 1661597 - Under podman, python recompiles sources even if they are compiled in build time
  • BZ - 1671023 - timeout not working with podman pull on rhel8 beta
  • BZ - 1672581 - podman does not respect -q option while pulling an image
  • BZ - 1674519 - Not able to create volumes using Dockerfile using podman
  • BZ - 1677251 - AVC while running php container [x86_64 only]
  • BZ - 1677264 - There is no certs.d directory for podman currently
  • BZ - 1689255 - don't allow a container to connect to random services
  • BZ - 1690514 - rootless unable to access subscription: non-root podman should read /usr/share/containers/mounts.conf
  • BZ - 1691543 - rootless unable to access subscription: bad permissions on /usr/share/rhel/secrets
  • BZ - 1692513 - unable to mount disk at `/var/lib/containers` via `systemd` unit when `container-selinux` policy installed
  • BZ - 1693154 - Varlink subcommand is missing for podman in rhel-8.0
  • BZ - 1693424 - rootless: cannot specify gid= mount options for unmapped gid in rootless containers
  • BZ - 1707220 - Add event notifications (blocking cockpit-podman)
  • BZ - 1719626 - podman exec rc-code needs to distinguish between stopped containers and non existing ones
  • BZ - 1719994 - [8.1.0] Registries.conf not configured to search registry.access.redhat.com
  • BZ - 1720646 - python-podman-api needs python-psutil at runtime
  • BZ - 1720654 - rebase packages
  • BZ - 1721247 - [rhel-8.1.0] build without the `no_openssl` buildtag
  • BZ - 1721638 - Podman build segfaults on Dockerfiles with RUN instruction
  • BZ - 1723879 - Performance Problems with Podman on systems with IO load
  • BZ - 1728700 - Unable to install container-selinux 2.107
  • BZ - 1730281 - podman leaks kernel memory due to return code stored in tmpfs
  • BZ - 1731117 - podman exec leaks an exec_pid_<hash> file for every exec in tmpfs
  • BZ - 1732508 - CVE-2019-10214 containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure
  • BZ - 1734745 - CVE-2019-14378 QEMU: slirp: heap buffer overflow during packet reassembly
  • BZ - 1734809 - Wrong AppStream ID
  • BZ - 1737077 - after a podman rm --all, sometimes one cannot recreate a previously existing container
  • BZ - 1739961 - cannot find "static" IPAM module and IPAM support for the host-device module
  • BZ - 1740079 - race/corruption: podman failed to launch containers
  • BZ - 1741157 - exit status from command run in container not forwarded to outside
  • BZ - 1743685 - Regression: rootless: podman run --rm hangs

CVEs

References