RHSA-2020:1485: Moderate: OpenShift Container Platform 4.3.13 runc security update
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime.Security Fix(es): runc: volume mount race condition with shared mounts led to information leak and integrity manipulation (CVE-2019-19921) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.rhaos4.3.el7_8 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.rhaos4.3.el7_8 - Upgrade
Upgrade
OpenShift Container Platform (runc)to a version that resolves this vulnerability.Fixed in 4.3.13
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:1485?
The severity of RHSA-2020:1485 is classified as moderate.
How do I fix RHSA-2020:1485?
To fix RHSA-2020:1485, update the runc package to 1.0.0-66.rc10.rhaos4.3.el7_8.
What product is affected by RHSA-2020:1485?
RHSA-2020:1485 affects the runc package used for container runtimes.
What vulnerability does RHSA-2020:1485 address?
RHSA-2020:1485 addresses a volume mount race condition leading to information leak and integrity manipulation (CVE-2019-19921).
Is there a specific version to look out for in RHSA-2020:1485?
Yes, the specific version to look for in RHSA-2020:1485 is 1.0.0-66.rc10.rhaos4.3.el7_8.