RHBA-2022:0348MediumCVSS 6.5
Red Hat Bug Fix Advisory: container-tools:3.0 security, bug fix, and enhancement update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-20291 — containers/storage: DoS via malicious image
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.19.9-1.module+el8.5.0+12236+c988d830.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.19.9-1.module+el8.5.0+12236+c988d830.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.19.9-1.module+el8.5.0+12236+c988d830.src (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.19.9-1.module+el8.5.0+12236+c988d830.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.19.9-1.module+el8.5.0+12236+c988d830.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.19.9-1.module+el8.5.0+12236+c988d830.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.19.9-1.module+el8.5.0+12236+c988d830.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.19.9-1.module+el8.5.0+12236+c988d830.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.19.9-1.module+el8.5.0+12236+c988d830.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.19.9-1.module+el8.5.0+12236+c988d830.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.19.9-1.module+el8.5.0+12236+c988d830.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:29-2.module+el8.5.0+10306+3f72d66d.noarch (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:29-2.module+el8.5.0+10306+3f72d66d.src (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.ppc64le (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.s390x (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.src (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.x86_64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-debuginfo-2:2.0.26-1.module+el8.5.0+10306+3f72d66d.aarch64 (container-tools:3.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258