[RLSA-2022:7950] Image Builder security, bug fix, and enhancement update
An update is available for cockpit-composer, weldr-client. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
Image Builder is a service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood.
Security Fix(es):
- golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.
Package | Affected Version |
---|---|
pkg:rpm/rockylinux/weldr-client?arch=x86_64&distro=rockylinux-9 | < 35.5-4.el9 |
pkg:rpm/rockylinux/weldr-client?arch=aarch64&distro=rockylinux-9 | < 35.5-4.el9 |
pkg:rpm/rockylinux/python3-osbuild?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/osbuild?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/osbuild-selinux?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/osbuild-ostree?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/osbuild-lvm2?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/osbuild-luks2?arch=noarch&distro=rockylinux-9 | < 65-1.el9.rocky.0.1 |
pkg:rpm/rockylinux/cockpit-composer?arch=noarch&distro=rockylinux-9 | < 41-1.el9 |
- ID
- RLSA-2022:7950
- Severity
- low
- URL
- https://errata.rockylinux.org/RLSA-2022:7950
- Published
-
2022-11-15T06:11:56
(22 months ago) - Modified
-
2023-02-02T14:07:22
(19 months ago) - Rights
- Copyright 2023 Rocky Enterprise Software Foundation
- Other Advisories
-
- ALAS-2023-1731
- ALAS2-2022-1846
- ALPINE:CVE-2022-32189
- ALSA-2022:7129
- ALSA-2022:7548
- ALSA-2022:7950
- ALSA-2023:2193
- ALSA-2023:2236
- ALSA-2023:2357
- ALSA-2023:2758
- ALSA-2023:2802
- ELSA-2022-20693
- ELSA-2022-20694
- ELSA-2022-23681
- ELSA-2022-24267
- ELSA-2022-7129
- ELSA-2022-7548
- ELSA-2022-7950
- ELSA-2023-2357
- ELSA-2023-2758
- ELSA-2023-2802
- FEDORA-2022-1f829990f0
- FREEBSD:7F8D5435-125A-11ED-9A69-10C37B4AC2EA
- GLSA-202208-02
- GO-2022-0537
- MS:CVE-2022-32189
- RHSA-2022:7129
- RHSA-2022:7548
- RHSA-2022:7950
- RHSA-2023:0328
- RHSA-2023:0446
- RHSA-2023:2193
- RHSA-2023:2236
- RHSA-2023:2357
- RHSA-2023:2758
- RHSA-2023:2802
- RLSA-2022:7129
- RLSA-2022:7548
- SUSE-SU-2022:2671-1
- SUSE-SU-2022:2672-1
- SUSE-SU-2023:2312-1
- USN-6038-1
- USN-6038-2
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2022-32189 | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32189 | |
Bugzilla | 2059869 | https://bugzilla.redhat.com/show_bug.cgi?id=2059869 | |
Bugzilla | 2059870 | https://bugzilla.redhat.com/show_bug.cgi?id=2059870 | |
Bugzilla | 2060061 | https://bugzilla.redhat.com/show_bug.cgi?id=2060061 | |
Bugzilla | 2062597 | https://bugzilla.redhat.com/show_bug.cgi?id=2062597 | |
Bugzilla | 2064087 | https://bugzilla.redhat.com/show_bug.cgi?id=2064087 | |
Bugzilla | 2088459 | https://bugzilla.redhat.com/show_bug.cgi?id=2088459 | |
Bugzilla | 2105961 | https://bugzilla.redhat.com/show_bug.cgi?id=2105961 | |
Bugzilla | 2110864 | https://bugzilla.redhat.com/show_bug.cgi?id=2110864 | |
Bugzilla | 2113814 | https://bugzilla.redhat.com/show_bug.cgi?id=2113814 | |
Bugzilla | 2118831 | https://bugzilla.redhat.com/show_bug.cgi?id=2118831 | |
Bugzilla | 2123055 | https://bugzilla.redhat.com/show_bug.cgi?id=2123055 | |
Bugzilla | 2123210 | https://bugzilla.redhat.com/show_bug.cgi?id=2123210 | |
Self | RLSA-2022:7950 | https://errata.rockylinux.org/RLSA-2022:7950 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/rockylinux/weldr-client?arch=x86_64&distro=rockylinux-9 | rockylinux | weldr-client | < 35.5-4.el9 | rockylinux-9 | x86_64 | |
Affected | pkg:rpm/rockylinux/weldr-client?arch=aarch64&distro=rockylinux-9 | rockylinux | weldr-client | < 35.5-4.el9 | rockylinux-9 | aarch64 | |
Affected | pkg:rpm/rockylinux/python3-osbuild?arch=noarch&distro=rockylinux-9 | rockylinux | python3-osbuild | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/osbuild?arch=noarch&distro=rockylinux-9 | rockylinux | osbuild | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/osbuild-selinux?arch=noarch&distro=rockylinux-9 | rockylinux | osbuild-selinux | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/osbuild-ostree?arch=noarch&distro=rockylinux-9 | rockylinux | osbuild-ostree | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/osbuild-lvm2?arch=noarch&distro=rockylinux-9 | rockylinux | osbuild-lvm2 | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/osbuild-luks2?arch=noarch&distro=rockylinux-9 | rockylinux | osbuild-luks2 | < 65-1.el9.rocky.0.1 | rockylinux-9 | noarch | |
Affected | pkg:rpm/rockylinux/cockpit-composer?arch=noarch&distro=rockylinux-9 | rockylinux | cockpit-composer | < 41-1.el9 | rockylinux-9 | noarch |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |