[RHSA-2022:8431] podman security, bug fix, and enhancement update

Severity Low
Affected Packages 25
CVEs 2

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fix(es):

  • podman: possible information disclosure and modification (CVE-2022-2989)

  • buildah: possible information disclosure and modification (CVE-2022-2990)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • (podman image trust) does not support the new trust type "sigstoreSigned " (BZ#2120436)

  • dnf-update broken for podman/catatonit (BZ#2123319)

  • podman creates lock file in /etc/cni/net.d/cni.lock instead of /run/lock/ (BZ#2123905)

  • podman kill may deadlock RHEL 9.1

  • containers config.json gets empty after sudden power loss (BZ#2136278)

  • PANIC podman API service endpoint handler panic (BZ#2136287)

Enhancement(s):

  • Podman volume plugin timeout should be configurable rhel-9.1.0 Z

  • [RFE]Podman support to perform custom actions on unhealthy containers (BZ#2136281)

Package Affected Version
pkg:rpm/redhat/podman?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-tests?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-tests?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-tests?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-tests?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-remote?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-remote?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-remote?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-remote?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-plugins?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-plugins?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-plugins?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-plugins?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-gvproxy?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-gvproxy?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-gvproxy?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-gvproxy?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-docker?distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-catatonit?arch=x86_64&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-catatonit?arch=s390x&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-catatonit?arch=ppc64le&distro=redhat-9.1 < 4.2.0-7.el9_1
pkg:rpm/redhat/podman-catatonit?arch=aarch64&distro=redhat-9.1 < 4.2.0-7.el9_1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/podman?arch=x86_64&distro=redhat-9.1 redhat podman < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman?arch=s390x&distro=redhat-9.1 redhat podman < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman?arch=ppc64le&distro=redhat-9.1 redhat podman < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman?arch=aarch64&distro=redhat-9.1 redhat podman < 4.2.0-7.el9_1 redhat-9.1 aarch64
Affected pkg:rpm/redhat/podman-tests?arch=x86_64&distro=redhat-9.1 redhat podman-tests < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman-tests?arch=s390x&distro=redhat-9.1 redhat podman-tests < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman-tests?arch=ppc64le&distro=redhat-9.1 redhat podman-tests < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman-tests?arch=aarch64&distro=redhat-9.1 redhat podman-tests < 4.2.0-7.el9_1 redhat-9.1 aarch64
Affected pkg:rpm/redhat/podman-remote?arch=x86_64&distro=redhat-9.1 redhat podman-remote < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman-remote?arch=s390x&distro=redhat-9.1 redhat podman-remote < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman-remote?arch=ppc64le&distro=redhat-9.1 redhat podman-remote < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman-remote?arch=aarch64&distro=redhat-9.1 redhat podman-remote < 4.2.0-7.el9_1 redhat-9.1 aarch64
Affected pkg:rpm/redhat/podman-plugins?arch=x86_64&distro=redhat-9.1 redhat podman-plugins < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman-plugins?arch=s390x&distro=redhat-9.1 redhat podman-plugins < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman-plugins?arch=ppc64le&distro=redhat-9.1 redhat podman-plugins < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman-plugins?arch=aarch64&distro=redhat-9.1 redhat podman-plugins < 4.2.0-7.el9_1 redhat-9.1 aarch64
Affected pkg:rpm/redhat/podman-gvproxy?arch=x86_64&distro=redhat-9.1 redhat podman-gvproxy < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman-gvproxy?arch=s390x&distro=redhat-9.1 redhat podman-gvproxy < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman-gvproxy?arch=ppc64le&distro=redhat-9.1 redhat podman-gvproxy < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman-gvproxy?arch=aarch64&distro=redhat-9.1 redhat podman-gvproxy < 4.2.0-7.el9_1 redhat-9.1 aarch64
Affected pkg:rpm/redhat/podman-docker?distro=redhat-9.1 redhat podman-docker < 4.2.0-7.el9_1 redhat-9.1
Affected pkg:rpm/redhat/podman-catatonit?arch=x86_64&distro=redhat-9.1 redhat podman-catatonit < 4.2.0-7.el9_1 redhat-9.1 x86_64
Affected pkg:rpm/redhat/podman-catatonit?arch=s390x&distro=redhat-9.1 redhat podman-catatonit < 4.2.0-7.el9_1 redhat-9.1 s390x
Affected pkg:rpm/redhat/podman-catatonit?arch=ppc64le&distro=redhat-9.1 redhat podman-catatonit < 4.2.0-7.el9_1 redhat-9.1 ppc64le
Affected pkg:rpm/redhat/podman-catatonit?arch=aarch64&distro=redhat-9.1 redhat podman-catatonit < 4.2.0-7.el9_1 redhat-9.1 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...