[RHSA-2024:2548] podman security and bug fix update

Severity Moderate
Affected Packages 17
CVEs 2

The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.

Security Fixes:

  • podman: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786)

  • podman: buildah: full container escape at build time (CVE-2024-1753)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fixes:

  • liveness probe not called by podman when using httpGet (JIRA:RHEL-28633)

  • Unable to copy image from one virtual machine to another using "podman image scp" (JIRA:RHEL-28629)

  • [v4.9] Backport two docker CLI compatibility fixes (JIRA:RHEL-28636)

  • Issue in podman causing S2I to fail in overwriting ENTRYPOINT (JIRA:RHEL-14922)

  • Need to backport podman fix for SIGSEGV in RHEL 9.3/8.9 for UBI based containers (JIRA:RHEL-26843)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/podman?arch=x86_64&distro=redhat-9.4 redhat podman < 4.9.4-3.el9_4 redhat-9.4 x86_64
Affected pkg:rpm/redhat/podman?arch=s390x&distro=redhat-9.4 redhat podman < 4.9.4-3.el9_4 redhat-9.4 s390x
Affected pkg:rpm/redhat/podman?arch=ppc64le&distro=redhat-9.4 redhat podman < 4.9.4-3.el9_4 redhat-9.4 ppc64le
Affected pkg:rpm/redhat/podman?arch=aarch64&distro=redhat-9.4 redhat podman < 4.9.4-3.el9_4 redhat-9.4 aarch64
Affected pkg:rpm/redhat/podman-tests?arch=x86_64&distro=redhat-9.4 redhat podman-tests < 4.9.4-3.el9_4 redhat-9.4 x86_64
Affected pkg:rpm/redhat/podman-tests?arch=s390x&distro=redhat-9.4 redhat podman-tests < 4.9.4-3.el9_4 redhat-9.4 s390x
Affected pkg:rpm/redhat/podman-tests?arch=ppc64le&distro=redhat-9.4 redhat podman-tests < 4.9.4-3.el9_4 redhat-9.4 ppc64le
Affected pkg:rpm/redhat/podman-tests?arch=aarch64&distro=redhat-9.4 redhat podman-tests < 4.9.4-3.el9_4 redhat-9.4 aarch64
Affected pkg:rpm/redhat/podman-remote?arch=x86_64&distro=redhat-9.4 redhat podman-remote < 4.9.4-3.el9_4 redhat-9.4 x86_64
Affected pkg:rpm/redhat/podman-remote?arch=s390x&distro=redhat-9.4 redhat podman-remote < 4.9.4-3.el9_4 redhat-9.4 s390x
Affected pkg:rpm/redhat/podman-remote?arch=ppc64le&distro=redhat-9.4 redhat podman-remote < 4.9.4-3.el9_4 redhat-9.4 ppc64le
Affected pkg:rpm/redhat/podman-remote?arch=aarch64&distro=redhat-9.4 redhat podman-remote < 4.9.4-3.el9_4 redhat-9.4 aarch64
Affected pkg:rpm/redhat/podman-plugins?arch=x86_64&distro=redhat-9.4 redhat podman-plugins < 4.9.4-3.el9_4 redhat-9.4 x86_64
Affected pkg:rpm/redhat/podman-plugins?arch=s390x&distro=redhat-9.4 redhat podman-plugins < 4.9.4-3.el9_4 redhat-9.4 s390x
Affected pkg:rpm/redhat/podman-plugins?arch=ppc64le&distro=redhat-9.4 redhat podman-plugins < 4.9.4-3.el9_4 redhat-9.4 ppc64le
Affected pkg:rpm/redhat/podman-plugins?arch=aarch64&distro=redhat-9.4 redhat podman-plugins < 4.9.4-3.el9_4 redhat-9.4 aarch64
Affected pkg:rpm/redhat/podman-docker?distro=redhat-9.4 redhat podman-docker < 4.9.4-3.el9_4 redhat-9.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...