RHSA-2020:1379: Important: container-tools:rhel8 security and bug fix update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): QEMU: Slirp: potential OOB access due to unsafe snprintf() usages (CVE-2020-8608) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): useradd and groupadd fail under rootless Buildah and podman [stream-container-tools-rhel8-rhel-8.1.1] (BZ#1803495) Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1804188) Podman support for FIPS Mode requires a bind mount inside the container [stream-container-tools-rhel8-rhel-8.1.1/podman] (BZ#1804194) fuse-overlayfs segfault [stream-container-tools-rhel8-rhel-8.1.1/fuse-overlayfs] (BZ#1805016) buildah COPY command is slow when .dockerignore file is not present [stream-container-tools-rhel8-rhel-8.1.1/buildah] (BZ#1806119)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95 - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 11-1.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.6-1.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.124.0-1.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/python-podman-apito a version that resolves this vulnerability.Fixed in 1.2.0-0.2.gitd0a45fe.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0 - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.4-1.module+el8.1.1+4407+ac444e5d - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.1-2.module+el8.1.1+4975+482d6f5d - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/podman-manpagesto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95 - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95 - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95 - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95 - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0 - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57 - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57 - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0 - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0 - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0 - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7 - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.11.6-6.module+el8.1.1+5865+cc793d95.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.6-1.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.3-4.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 0.7.2-5.module+el8.1.1+6114+953c5a57.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 1.6.4-4.module+el8.1.1+5885+44006e55.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-64.rc9.module+el8.1.1+5259+bcdd613a.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0.aa - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0.aa - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 0.1.40-8.module+el8.1.1+5351+506397b0.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.2-3.git21fdece.module+el8.1.1+5657+524a77d7.aa - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.4-1.module+el8.1.1+4407+ac444e5d.aa - Upgrade
Upgrade
stream-container-tools-rhel8-rhel-8.1.1to a version that resolves this vulnerability.Patch BZ#1803495 - Upgrade
Upgrade
stream-container-tools-rhel8-rhel-8.1.1/fuse-overlayfsto a version that resolves this vulnerability.Patch BZ#1805016 - Upgrade
Upgrade
stream-container-tools-rhel8-rhel-8.1.1/buildahto a version that resolves this vulnerability.Patch BZ#1806119 - Upgrade
Upgrade
stream-container-tools-rhel8-rhel-8.1.1/buildahto a version that resolves this vulnerability.Patch BZ#1804188 - Upgrade
Upgrade
stream-container-tools-rhel8-rhel-8.1.1/podmanto a version that resolves this vulnerability.Patch BZ#1804194 - Upgrade
Upgrade
QEMU: Slirpto a version that resolves this vulnerability.Patch CVE-2020-8608 - Compensating control
For Podman FIPS Mode support in stream-container-tools-rhel8-rhel-8.1.1/podman, use a bind mount inside the container.
- Compensating control
For buildah/buildah FIPS Mode support in stream-container-tools-rhel8-rhel-8.1.1/buildah, use a bind mount inside the container.
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1379?
The severity of RHSA-2020:1379 is classified as important.
How do I fix RHSA-2020:1379?
To fix RHSA-2020:1379, you should update the affected packages to the specified versions in the advisory.
What packages are affected by RHSA-2020:1379?
The affected packages include buildah, podman, conmon, skopeo, and others listed in the advisory.
What is the main vulnerability in RHSA-2020:1379?
The main vulnerability involves potential out-of-bounds access due to unsafe snprintf() usages in QEMU Slirp.
Is there a workaround for RHSA-2020:1379?
No specific workaround is recommended for RHSA-2020:1379; updating the affected software is advised.