Red Hat Security Advisory: container-tools:rhel8 security, bug fix, and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2020-28851 — golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension CVE-2022-1227 — psgo: Privilege escalation in 'podman top' CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2022-27649 — podman: Default inheritable capabilities for linux container should be empty CVE-2022-27650 — crun: Default inheritable capabilities for linux container should be empty CVE-2022-27651 — buildah: Default inheritable capabilities for linux container should be empty
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-27.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-27.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-27.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-27.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.2-4.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.2-4.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.2-4.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.2-4.module+el8.6.0+14673+621cb8be.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.2-4.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.2-4.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.2-4.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.2-4.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.2-4.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.2-4.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.2-4.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.2-4.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.2-4.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.s390x (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.2-4.module+el8.6.0+14673+621cb8be.x86_64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:43-1.module+el8.6.0+14673+621cb8be.noarch (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:43-1.module+el8.6.0+14673+621cb8be.src (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.1.0-1.module+el8.6.0+14673+621cb8be.aarch64 (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.1.0-1.module+el8.6.0+14673+621cb8be.ppc64le (container-tools:rhel8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: The entry point of a container can be modified to use a utility like capsh(1) to drop inheritable capabilities prior to the primary process starting.
🔗 References (32)
- selfhttps://access.redhat.com/errata/RHSA-2022:1762
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.6_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1967642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1982164
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1982784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998835
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2000914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2002721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006678
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009047
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2009296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2017266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2018949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2023112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024229
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2025336
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030599
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2045880
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055487
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059754
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2065292
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2065707
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070368
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1762.json