Important: container-tools:rhel8 security, bug fix, and enhancement update

Related Vulnerabilities: CVE-2022-1227   CVE-2022-21698   CVE-2022-27649   CVE-2022-27650   CVE-2022-27651  

Synopsis

Important: container-tools:rhel8 security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • psgo: Privilege escalation in 'podman top' (CVE-2022-1227)
  • prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
  • podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649)
  • crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650)
  • buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.6 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.6 ppc64le
  • Red Hat Enterprise Linux Server - TUS 8.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 8 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.6 ppc64le
  • Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions 8.6 x86_64

Fixes

  • BZ - 1861760 - RFE: podman - join multiple CNI network and set static IPs for them (multiple static networks)
  • BZ - 1967642 - compilation of container_runtime_run interface leads to errors
  • BZ - 1982164 - Podman volumes with size options
  • BZ - 1982784 - RFE: Full support for network management in the podman compatibility API
  • BZ - 1995900 - Podman does not honor the userns configuration
  • BZ - 1998835 - error loading cached network config: network "podman" not found in CNI cache
  • BZ - 2000914 - Suggest a way forward if coreos/toolbox was used
  • BZ - 2002721 - podman auto update fails to login to registry after podman upgrade to 3.2 [rhel-8.6.0]
  • BZ - 2004993 - Switch to using the Toolbox-specific UBI image by default [rhel-8.6.0]
  • BZ - 2005972 - podman 3.2.3: Recovering from API handler panic: runtime error: index out of range [58] with length 58, goroutine 805 [running]
  • BZ - 2006678 - podman: panic: runtime error: invalid memory address or nil pointer dereference
  • BZ - 2009047 - Networking failure when running Fedora 35 container
  • BZ - 2009296 - No events reported when creating pod with --infra=false
  • BZ - 2017266 - [cockpit-podman] RHEL 8.6 Tier 0 Localization
  • BZ - 2018949 - podman multi stage build failing when using with --pull flag
  • BZ - 2023112 - Podman should be built with the support of 'libsubid'
  • BZ - 2024229 - Healthcheck does not work with podman, after container stop/start
  • BZ - 2025336 - [RFE] Backport GH#12294 PR to Podman - secret: honor custom target= for secrets with type=mount
  • BZ - 2030599 - Creating a podman container with option "--hostname" in a pod with --pod new:test didn't effect correctly
  • BZ - 2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter
  • BZ - 2055487 - BUILDAH-Error locating just-written images while creating multiple container
  • BZ - 2059754 - podman 4.0.1 rootless, without dbus session, blows up after run --uidmap
  • BZ - 2065292 - CentOS Stream 8 podman: symbol lookup error: podman: undefined symbol: seccomp_notify_fd
  • BZ - 2065707 - Removal of invalid vendored project with unwanted license in aardvark-dns/netavark
  • BZ - 2066568 - CVE-2022-27649 podman: Default inheritable capabilities for linux container should be empty
  • BZ - 2066840 - CVE-2022-27651 buildah: Default inheritable capabilities for linux container should be empty
  • BZ - 2066845 - CVE-2022-27650 crun: Default inheritable capabilities for linux container should be empty
  • BZ - 2070368 - CVE-2022-1227 psgo: Privilege escalation in 'podman top'