[ELSA-2022-7469] container-tools:4.0 security and bug fix update

Severity Moderate
Affected Packages 32
CVEs 3

buildah
[1:1.24.5-2]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.24
(https://github.com/containers/buildah/commit/8cc4586)
- Related: #2061390

[1:1.24.5-1]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.24
(https://github.com/containers/buildah/commit/83c5f26)
- Related: #2061390

cockpit-podman
[46-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/46
- Related: #2061390

conmon
[2:2.1.4-1]
- update to https://github.com/containers/conmon/releases/tag/v2.1.4
- Related: #2061390

containernetworking-plugins
[1:1.1.1-2]
- bump golang BR to 1.17.7
- Related: #2061390

[1:1.1.1-1]
- update to https://github.com/containernetworking/plugins/releases/tag/v1.1.1
- Related: #2061390

containers-common
[2:1-35.0.1]
- Updated removed references Orabug: 33473101
- Adjust registries.conf (Nikita Gerasimov)
- remove references to RedHat registry (Nikita Gerasimov)

[2:1-35]
- update vendored components and configuration files
- Related: #2061390

[2:1-34]
- update shortnames and be sure to remove rhel-els
- Related: #2061390

[2:1-33]
- additional fix for unqualified registries
- Related: #2061390

oci-seccomp-bpf-hook
[1.2.5-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.5
- Related: #2061390

podman
[2:4.0.2-8]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/33084eb)
- Related: #2061390

[2:4.0.2-7]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/3efe4c2)
- Related: #2061390

[2:4.0.2-6]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/bfc8b36)
- Related: #2061390

[2:4.0.2-5]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/2e12f02)
- Related: #2061390

[2:4.0.2-4]
- update gvisor-tap-vsock to 0.2.0 to fix compilation with golang 1.18
- Related: #2061390

[2:4.0.2-3]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/6cb5039)
- Related: #2061390

[2:4.0.2-2]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/ce91610)
- Related: #2061390

[2:4.0.2-1]
- update to the latest content of https://github.com/containers/podman/tree/v4.0-rhel
(https://github.com/containers/podman/commit/94aa329)
- Related: #2061390

python-podman
[4.0.0-1]
- bump to v4.0.0
- Related: #2001445

runc
[1:1.1.4-1]
- update to https://github.com/opencontainers/runc/releases/tag/v1.1.4
- Related: #2061390

skopeo
[2:1.6.2-5]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.6
(https://github.com/containers/skopeo/commit/c20c32d)
- Related: #2061390

[2:1.6.2-4]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.6
(https://github.com/containers/skopeo/commit/f952195)
- Related: #2061390

[2:1.6.2-3]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.6
(https://github.com/containers/skopeo/commit/4414e52)
- Related: #2061390

[2:1.6.2-2]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.6
(https://github.com/containers/skopeo/commit/4336972)
- Related: #2061390

[2:1.6.2-1]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.6
(https://github.com/containers/skopeo/commit/540efb3)
- Related: #2061390

slirp4netns
[1.1.8-2]
- fix gating - dont use insecure functions - thanks to Marc-Andre Lureau
- Related: #2001445

[1.1.8-1]
- update to
https://github.com/rootless-containers/slirp4netns/releases/tag/v1.1.8
- Related: #1883490

udica
[0.2.6-3]
- Make sure each section of the inspect exists before accessing (#2027662)

[0.2.6-2]
- Require container-selinux shipping policy templates (#2005866)

[0.2.6-1]
- update to https://github.com/containers/udica/releases/tag/v0.2.6
- Related: #2001445

Package Affected Version
pkg:rpm/oraclelinux/udica?distro=oraclelinux-8.7 < 0.2.6-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/slirp4netns?distro=oraclelinux-8.7 < 1.1.8-2.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/skopeo?distro=oraclelinux-8.7 < 1.6.2-5.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/skopeo-tests?distro=oraclelinux-8.7 < 1.6.2-5.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/runc?distro=oraclelinux-8.7 < 1.1.4-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/python3-podman?distro=oraclelinux-8.7 < 4.0.0-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/python3-criu?distro=oraclelinux-8.7 < 3.15-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-tests?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-remote?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-plugins?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-gvproxy?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-docker?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/podman-catatonit?distro=oraclelinux-8.7 < 4.0.2-8.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/oci-seccomp-bpf-hook?distro=oraclelinux-8.7 < 1.2.5-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/netavark?distro=oraclelinux-8.7 < 1.0.1-35.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/libslirp?distro=oraclelinux-8.7 < 4.4.0-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/libslirp-devel?distro=oraclelinux-8.7 < 4.4.0-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/fuse-overlayfs?distro=oraclelinux-8.7 < 1.9-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/crun?distro=oraclelinux-8.7 < 1.5-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/criu?distro=oraclelinux-8.7 < 3.15-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/criu-libs?distro=oraclelinux-8.7 < 3.15-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/criu-devel?distro=oraclelinux-8.7 < 3.15-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/crit?distro=oraclelinux-8.7 < 3.15-3.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/containers-common?distro=oraclelinux-8.7 < 1-35.0.1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/containernetworking-plugins?distro=oraclelinux-8.7 < 1.1.1-2.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/container-selinux?distro=oraclelinux-8.7 < 2.189.0-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/conmon?distro=oraclelinux-8.7 < 2.1.4-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/cockpit-podman?distro=oraclelinux-8.7 < 46-1.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/buildah?distro=oraclelinux-8.7 < 1.24.5-2.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/buildah-tests?distro=oraclelinux-8.7 < 1.24.5-2.module+el8.7.0+20872+81cbf159
pkg:rpm/oraclelinux/aardvark-dns?distro=oraclelinux-8.7 < 1.0.1-35.module+el8.7.0+20872+81cbf159
ID
ELSA-2022-7469
Severity
moderate
URL
https://linux.oracle.com/errata/ELSA-2022-7469.html
Published
2022-11-15T00:00:00
(22 months ago)
Modified
2022-11-15T00:00:00
(22 months ago)
Rights
Copyright 2022 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/udica?distro=oraclelinux-8.7 oraclelinux udica < 0.2.6-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/slirp4netns?distro=oraclelinux-8.7 oraclelinux slirp4netns < 1.1.8-2.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/skopeo?distro=oraclelinux-8.7 oraclelinux skopeo < 1.6.2-5.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/skopeo-tests?distro=oraclelinux-8.7 oraclelinux skopeo-tests < 1.6.2-5.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/runc?distro=oraclelinux-8.7 oraclelinux runc < 1.1.4-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/python3-podman?distro=oraclelinux-8.7 oraclelinux python3-podman < 4.0.0-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/python3-criu?distro=oraclelinux-8.7 oraclelinux python3-criu < 3.15-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman?distro=oraclelinux-8.7 oraclelinux podman < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-tests?distro=oraclelinux-8.7 oraclelinux podman-tests < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-remote?distro=oraclelinux-8.7 oraclelinux podman-remote < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-plugins?distro=oraclelinux-8.7 oraclelinux podman-plugins < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-gvproxy?distro=oraclelinux-8.7 oraclelinux podman-gvproxy < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-docker?distro=oraclelinux-8.7 oraclelinux podman-docker < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/podman-catatonit?distro=oraclelinux-8.7 oraclelinux podman-catatonit < 4.0.2-8.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/oci-seccomp-bpf-hook?distro=oraclelinux-8.7 oraclelinux oci-seccomp-bpf-hook < 1.2.5-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/netavark?distro=oraclelinux-8.7 oraclelinux netavark < 1.0.1-35.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/libslirp?distro=oraclelinux-8.7 oraclelinux libslirp < 4.4.0-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/libslirp-devel?distro=oraclelinux-8.7 oraclelinux libslirp-devel < 4.4.0-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/fuse-overlayfs?distro=oraclelinux-8.7 oraclelinux fuse-overlayfs < 1.9-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/crun?distro=oraclelinux-8.7 oraclelinux crun < 1.5-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/criu?distro=oraclelinux-8.7 oraclelinux criu < 3.15-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/criu-libs?distro=oraclelinux-8.7 oraclelinux criu-libs < 3.15-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/criu-devel?distro=oraclelinux-8.7 oraclelinux criu-devel < 3.15-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/crit?distro=oraclelinux-8.7 oraclelinux crit < 3.15-3.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/containers-common?distro=oraclelinux-8.7 oraclelinux containers-common < 1-35.0.1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/containernetworking-plugins?distro=oraclelinux-8.7 oraclelinux containernetworking-plugins < 1.1.1-2.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/container-selinux?distro=oraclelinux-8.7 oraclelinux container-selinux < 2.189.0-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/conmon?distro=oraclelinux-8.7 oraclelinux conmon < 2.1.4-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/cockpit-podman?distro=oraclelinux-8.7 oraclelinux cockpit-podman < 46-1.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/buildah?distro=oraclelinux-8.7 oraclelinux buildah < 1.24.5-2.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/buildah-tests?distro=oraclelinux-8.7 oraclelinux buildah-tests < 1.24.5-2.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
Affected pkg:rpm/oraclelinux/aardvark-dns?distro=oraclelinux-8.7 oraclelinux aardvark-dns < 1.0.1-35.module+el8.7.0+20872+81cbf159 oraclelinux-8.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...