First published: Tue Mar 10 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> runc: volume mount race condition with shared mounts led to information leak/integrity manipulation (CVE-2019-19921)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/runc | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
redhat/runc | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
redhat/runc-debuginfo | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
redhat/runc-debugsource | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
redhat/runc-debuginfo | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
redhat/runc-debugsource | <1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 | 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2020:0688 is classified as a critical vulnerability affecting Red Hat OpenShift Container Platform.
To fix RHSA-2020:0688, update the runc package to version 1.0.0-63.rc10.rhaos4.2.gitdc9208a.el8.
RHSA-2020:0688 affects the runc package in the Red Hat OpenShift Container Platform deployment.
RHSA-2020:0688 addresses a volume mount race condition in runc that could lead to information leakage or integrity issues.
There are no recommended workarounds for RHSA-2020:0688; applying the update is the only resolution.