Red Hat Security Advisory: container-tools:4.0 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-45287 — golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. CVE-2024-21626 — runc: file descriptor leak
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-38.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-38.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-38.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- aardvark-dns-2:1.0.1-38.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.6-7.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.6-7.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.6-7.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.6-7.module+el8.9.0+21242+944321bb.src (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-1:1.24.6-7.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.6-7.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.6-7.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.6-7.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-1:1.24.6-7.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.6-7.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.6-7.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.6-7.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-1:1.24.6-7.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.s390x (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-tests-debuginfo-1:1.24.6-7.module+el8.9.0+21242+944321bb.x86_64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:46-1.module+el8.9.0+21242+944321bb.noarch (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- cockpit-podman-0:46-1.module+el8.9.0+21242+944321bb.src (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.1.4-2.module+el8.9.0+21242+944321bb.aarch64 (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- conmon-2:2.1.4-2.module+el8.9.0+21242+944321bb.ppc64le (container-tools:4.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is available for this flaw. Workaround: No current mitigation is available for this vulnerability. Workaround: Red Hat Enterprise Linux (RHEL) and OpenShift ships with SELinux in targeted enforcing mode, which prevents the container processes from accessing host content and mitigates this attack. Dockerfiles can be inspected on the 'RUN' and 'WORKDIR' directives to ensure that there are no escapes or malicious paths, which are an indication of compromise. Limiting access and only using trusted container images can help prevent unauthorized access and malicious attacks.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:0748
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2024-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258725
- externalhttps://issues.redhat.com/browse/RHEL-15029
- externalhttps://issues.redhat.com/browse/RHEL-17145
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0748.json