[RHSA-2022:7950] Image Builder security, bug fix, and enhancement update
Severity
Low
Affected Packages
4
CVEs
1
Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.
Security Fix(es):
- golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.
Package | Affected Version |
---|---|
pkg:rpm/redhat/weldr-client?arch=x86_64&distro=redhat-9 | < 35.5-4.el9 |
pkg:rpm/redhat/weldr-client?arch=s390x&distro=redhat-9 | < 35.5-4.el9 |
pkg:rpm/redhat/weldr-client?arch=ppc64le&distro=redhat-9 | < 35.5-4.el9 |
pkg:rpm/redhat/weldr-client?arch=aarch64&distro=redhat-9 | < 35.5-4.el9 |
- ID
- RHSA-2022:7950
- Severity
- low
- URL
- https://access.redhat.com/errata/RHSA-2022:7950
- Published
-
2022-11-15T00:00:00
(22 months ago) - Modified
-
2022-11-15T00:00:00
(22 months ago) - Rights
- Copyright 2022 Red Hat, Inc.
- Other Advisories
-
- ALAS-2023-1731
- ALAS2-2022-1846
- ALPINE:CVE-2022-32189
- ALSA-2022:7129
- ALSA-2022:7548
- ALSA-2022:7950
- ALSA-2023:2193
- ALSA-2023:2236
- ALSA-2023:2357
- ALSA-2023:2758
- ALSA-2023:2802
- ELSA-2022-20693
- ELSA-2022-20694
- ELSA-2022-23681
- ELSA-2022-24267
- ELSA-2022-7129
- ELSA-2022-7548
- ELSA-2022-7950
- ELSA-2023-2357
- ELSA-2023-2758
- ELSA-2023-2802
- FEDORA-2022-1f829990f0
- FREEBSD:7F8D5435-125A-11ED-9A69-10C37B4AC2EA
- GLSA-202208-02
- GO-2022-0537
- MS:CVE-2022-32189
- RHSA-2022:7129
- RHSA-2022:7548
- RHSA-2023:0328
- RHSA-2023:0446
- RHSA-2023:2193
- RHSA-2023:2236
- RHSA-2023:2357
- RHSA-2023:2758
- RHSA-2023:2802
- RLSA-2022:7129
- RLSA-2022:7548
- RLSA-2022:7950
- SUSE-SU-2022:2671-1
- SUSE-SU-2022:2672-1
- SUSE-SU-2023:2312-1
- USN-6038-1
- USN-6038-2
Source | # ID | Name | URL |
---|---|---|---|
Bugzilla | 2113814 | https://bugzilla.redhat.com/2113814 | |
RHSA | RHSA-2022:7950 | https://access.redhat.com/errata/RHSA-2022:7950 | |
CVE | CVE-2022-32189 | https://access.redhat.com/security/cve/CVE-2022-32189 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/redhat/weldr-client?arch=x86_64&distro=redhat-9 | redhat | weldr-client | < 35.5-4.el9 | redhat-9 | x86_64 | |
Affected | pkg:rpm/redhat/weldr-client?arch=s390x&distro=redhat-9 | redhat | weldr-client | < 35.5-4.el9 | redhat-9 | s390x | |
Affected | pkg:rpm/redhat/weldr-client?arch=ppc64le&distro=redhat-9 | redhat | weldr-client | < 35.5-4.el9 | redhat-9 | ppc64le | |
Affected | pkg:rpm/redhat/weldr-client?arch=aarch64&distro=redhat-9 | redhat | weldr-client | < 35.5-4.el9 | redhat-9 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |