RHSA-2020:0942: Moderate: runc security update
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.Security Fix(es): runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation (CVE-2019-19921) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc8.el7_7 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc8.el7_7
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:0942?
The severity of RHSA-2020:0942 is classified as moderate.
How do I fix RHSA-2020:0942?
To fix RHSA-2020:0942, you should update the runc package to version 1.0.0-66.rc8.el7_7.
What is the main vulnerability addressed in RHSA-2020:0942?
The main vulnerability addressed in RHSA-2020:0942 involves a volume mount race condition in runc that can lead to information leakage and integrity manipulation.
Which package versions are affected by RHSA-2020:0942?
RHSA-2020:0942 affects the runc and runc-debuginfo packages prior to version 1.0.0-66.rc8.el7_7.
Is RHSA-2020:0942 related to container security?
Yes, RHSA-2020:0942 is related to container security as it involves a vulnerability in the runC container runtime.