[SUSE-SU-2022:3480-1] Security update for buildah

Severity Important
Affected Packages 8
CVEs 3

Security update for buildah

This update for buildah fixes the following issues:

  • Updated to version 1.26.0:
    • CVE-2022-27651: Fixed an issue where containers were incorrectly started with non-empty inheritable Linux process capabilities (bsc#1197870).
    • CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961).
    • CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/buildah?arch=x86_64&distro=sles-15&sp=2 suse buildah < 1.25.1-150100.3.13.12 sles-15 x86_64
Affected pkg:rpm/suse/buildah?arch=x86_64&distro=sles-15&sp=1 suse buildah < 1.25.1-150100.3.13.12 sles-15 x86_64
Affected pkg:rpm/suse/buildah?arch=s390x&distro=sles-15&sp=2 suse buildah < 1.25.1-150100.3.13.12 sles-15 s390x
Affected pkg:rpm/suse/buildah?arch=s390x&distro=sles-15&sp=1 suse buildah < 1.25.1-150100.3.13.12 sles-15 s390x
Affected pkg:rpm/suse/buildah?arch=ppc64le&distro=sles-15&sp=2 suse buildah < 1.25.1-150100.3.13.12 sles-15 ppc64le
Affected pkg:rpm/suse/buildah?arch=ppc64le&distro=sles-15&sp=1 suse buildah < 1.25.1-150100.3.13.12 sles-15 ppc64le
Affected pkg:rpm/suse/buildah?arch=aarch64&distro=sles-15&sp=2 suse buildah < 1.25.1-150100.3.13.12 sles-15 aarch64
Affected pkg:rpm/suse/buildah?arch=aarch64&distro=sles-15&sp=1 suse buildah < 1.25.1-150100.3.13.12 sles-15 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...