RHSA-2020:2116: Important: buildah security and bug fix update
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.Security Fix(es): buildah: Crafted input tar file may lead to local file overwrite during image build process (CVE-2020-10696) containers/image: Container images read entire image manifest into memory (CVE-2020-1702) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): buildah is not expanding env vars in file paths (BZ#1822031)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2116?
RHSA-2020:2116 has a moderate severity rating.
How do I fix RHSA-2020:2116?
You can fix RHSA-2020:2116 by updating the buildah package to version 1.11.6-11.el7_8.
What software is affected by RHSA-2020:2116?
The affected software includes the buildah and buildah-debuginfo packages.
What platforms does RHSA-2020:2116 impact?
RHSA-2020:2116 impacts various architectures including x86_64 and ppc64le.
Is there a known issue associated with RHSA-2020:2116?
Yes, RHSA-2020:2116 relates to several known issues as documented in the relevant Bugzilla reports.