RHSA-2020:0688: Moderate: OpenShift Container Platform 4.2.22 runc security update
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> runc: volume mount race condition with shared mounts led to information leak/integrity manipulation (CVE-2019-19921)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0688?
RHSA-2020:0688 is classified as a critical vulnerability affecting Red Hat OpenShift Container Platform.
How do I fix RHSA-2020:0688?
To fix RHSA-2020:0688, update the runc package to version 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8.
Which software is affected by RHSA-2020:0688?
RHSA-2020:0688 affects the runc package in the Red Hat OpenShift Container Platform deployment.
What specific issue does RHSA-2020:0688 address?
RHSA-2020:0688 addresses a volume mount race condition in runc that could lead to information leakage or integrity issues.
Is there a workaround for RHSA-2020:0688?
There are no recommended workarounds for RHSA-2020:0688; applying the update is the only resolution.