RHSA-2019:4269HighCVSS 7.5
Red Hat Security Advisory: container-tools:rhel8 security and bug fix update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-16884 — runc: AppArmor/SELinux bypass with malicious image that specifies a volume at /proc CVE-2019-18466 — podman: resolving symlink in host filesystem leads to unexpected results of copy operation
🎯 Affected products159
- Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-0:1.9.0-5.module+el8.1.0+4240+893c1ab8.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:4-1.module+el8.1.0+4081+b29780af.noarch (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:4-1.module+el8.1.0+4081+b29780af.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.123.0-2.module+el8.1.0+4900+9d7326b8.noarch (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.123.0-2.module+el8.1.0+4900+9d7326b8.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.8.1-3.module+el8.1.0+4881+045289ee.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.8.1-3.module+el8.1.0+4881+045289ee.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.8.1-3.module+el8.1.0+4881+045289ee.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.8.1-3.module+el8.1.0+4881+045289ee.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +129 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2019:4269
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1757214
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1764318
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1770176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1774382
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_4269.json