[GLSA-202407-12] podman: Multiple Vulnerabilities

Severity High
Affected Packages 1
Unaffected Packages 1
CVEs 9

Multiple vulnerabilities have been discovered in Podman, the worst of which could lead to privilege escalation.

Background
Podman is a tool for managing OCI containers and pods with a Docker-compatible CLI.

Description
Please review the referenced CVE identifiers for details.

Impact
Please review the referenced CVE identifiers for details.

Workaround
There is no known workaround at this time.

Resolution
All Podman users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=app-containers/podman-4.9.4"

Package Affected Version
pkg:ebuild/app-containers/podman?distro=gentoo < 4.9.4
Package Unaffected Version
pkg:ebuild/app-containers/podman?distro=gentoo >= 4.9.4
ID
GLSA-202407-12
Severity
high
URL
https://security.gentoo.org/glsa/202407-12
Published
2024-07-05T00:00:00
(2 months ago)
Modified
2024-07-05T00:00:00
(2 months ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2021-4024 CVE-2021-4024 https://nvd.nist.gov/vuln/detail/CVE-2021-4024
CVE CVE-2022-2989 CVE-2022-2989 https://nvd.nist.gov/vuln/detail/CVE-2022-2989
CVE CVE-2023-0778 CVE-2023-0778 https://nvd.nist.gov/vuln/detail/CVE-2023-0778
CVE CVE-2023-48795 CVE-2023-48795 https://nvd.nist.gov/vuln/detail/CVE-2023-48795
CVE CVE-2024-1753 CVE-2024-1753 https://nvd.nist.gov/vuln/detail/CVE-2024-1753
CVE CVE-2024-23651 CVE-2024-23651 https://nvd.nist.gov/vuln/detail/CVE-2024-23651
CVE CVE-2024-23652 CVE-2024-23652 https://nvd.nist.gov/vuln/detail/CVE-2024-23652
CVE CVE-2024-23653 CVE-2024-23653 https://nvd.nist.gov/vuln/detail/CVE-2024-23653
CVE CVE-2024-24786 CVE-2024-24786 https://nvd.nist.gov/vuln/detail/CVE-2024-24786
Bugzilla 829896 Bugzilla #829896 https://bugs.gentoo.org/show_bug.cgi?id=829896
Bugzilla 870931 Bugzilla #870931 https://bugs.gentoo.org/show_bug.cgi?id=870931
Bugzilla 896372 Bugzilla #896372 https://bugs.gentoo.org/show_bug.cgi?id=896372
Bugzilla 921290 Bugzilla #921290 https://bugs.gentoo.org/show_bug.cgi?id=921290
Bugzilla 923751 Bugzilla #923751 https://bugs.gentoo.org/show_bug.cgi?id=923751
Bugzilla 927500 Bugzilla #927500 https://bugs.gentoo.org/show_bug.cgi?id=927500
Bugzilla 927501 Bugzilla #927501 https://bugs.gentoo.org/show_bug.cgi?id=927501
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/app-containers/podman?distro=gentoo app-containers podman < 4.9.4 gentoo
Unaffected pkg:ebuild/app-containers/podman?distro=gentoo app-containers podman >= 4.9.4 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...