Moderate: container-tools:rhel8 security, bug fix, and enhancement update

Synopsis

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

Type/Severity

Security Advisory: Moderate

Topic

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters (CVE-2020-10749)
  • QEMU: slirp: networking out-of-bounds read information disclosure vulnerability (CVE-2020-10756)
  • golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 1682970 - [RFE] Default location of setting up HTTP_Proxy for podman
  • BZ - 1752079 - podman docker command fails at COPY - overwriting existing file
  • BZ - 1785242 - container-tools: Provides: docker gone from podman-docker subpackage
  • BZ - 1800815 - "podman login" writes auth.json in a location "skopeo copy" does not expect
  • BZ - 1801874 - Podman segmentation error when a Dockerfile specifies an image by its digest
  • BZ - 1804193 - Podman support for FIPS Mode requires a bind mount inside the container [container-tools-rhel8-rhel-8.3.0/podman]
  • BZ - 1804195 - Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.2.0/podman]
  • BZ - 1813845 - [RFE] HTTP/REST API for podman
  • BZ - 1814928 - "podman exec -it" will hang with leading keyboard input
  • BZ - 1818694 - Golang panic when pushing image to a scaled image-registry
  • BZ - 1821193 - Update container-tools 8.3.0 components to stable releases
  • BZ - 1822038 - buildah is not expanding env vars in file paths [stream-container-tools-rhel8-rhel-8.3.0/buildah]
  • BZ - 1825789 - Crash on filtering anonymous images
  • BZ - 1827794 - Podman search does not have pagination support
  • BZ - 1833220 - CVE-2020-10749 containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters
  • BZ - 1835986 - CVE-2020-10756 QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
  • BZ - 1837755 - --init feature useless out of the box
  • BZ - 1847544 - Socket-activated Varlink (io.podman.socket) fails after first call
  • BZ - 1849557 - Rootless Podman does not properly close and remove temporary files
  • BZ - 1850230 - Using toolbox with fedora:latest image fails, exec fails with "OCI runtime command not found"
  • BZ - 1853230 - The output from "podman images" is malformed if a repository contains a port
  • BZ - 1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
  • BZ - 1857606 - error loading kheaders module
  • BZ - 1858862 - Podman build from url failed to get correct temp directory for store files
  • BZ - 1860126 - podman run namespace in man page ambiguous
  • BZ - 1866153 - podman search doesn't add limit to a query against v2. By default v2 returns 100 items.
  • BZ - 1866833 - Podman 1.9.3 fails to run container when /etc/secuity/limits.conf is used
  • BZ - 1867447 - error bind mounting /dev from host into mount namespace
  • BZ - 1868612 - Image tag not derived correctly
  • BZ - 1872263 - Update podman to 2.0.5
  • BZ - 1877463 - Remove oci-seccomp-bpf-hook package from default packages installed by container-tools-rhel8-8.3.0
  • BZ - 1879622 - `podman images --all` fails on images with digest

CVEs

References