CVE-2022-2738: Use After Free
The podman packages version podman-1.6.4-32.el79 as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 (https://access.redhat.com/errata/RHSA-2022:2190) included an incorrect version of podman that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2020-8945, that was previously corrected in the podman packages in Red Hat Enterprise Linux 7 Extras via RHSA-2020:2117 (https://access.redhat.com/errata/RHSA-2020:2117). The CVE-2022-2738 was assigned to this security regression and it is specific to the podman packages produced by Red Hat.
The original issue - CVE-2020-8945 - could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification. For more details about the original issue, see:
https://access.redhat.com/security/cve/CVE-2020-8945 https://bugzilla.redhat.com/showbug.cgi?id=CVE-2020-8945
Other sources
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signature verification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2738.
What software is affected by this vulnerability?
The podman package with version 1.6.4-36.el7_9 on Red Hat Enterprise Linux 7 Extras is affected by this vulnerability.
What is the severity of CVE-2022-2738?
The severity of CVE-2022-2738 is high.
What is the fix for this vulnerability?
Upgrade the podman package to version 1.6.4-36.el7_9 or higher.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Red Hat Security Advisory RHSA-2022:2190.