RHSA-2020:3053: Moderate: container-tools:rhel8 security, bug fix, and enhancement update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): QEMU: slirp: use-after-free in ipreass() function in ipinput.c (CVE-2020-1983) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 17-1.module+el8.2.1+6636+bf4db4ab - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.17-1.module+el8.2.1+6771+3533eb4c - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.135.0-1.module+el8.2.1+6849+893e4f4a - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4 - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/python-podman-apito a version that resolves this vulnerability.Fixed in 1.2.0-0.2.gitd0a45fe.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.7-1.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.1-2.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4 - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4 - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91 - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91 - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91 - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72 - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.17-1.module+el8.2.1+6771+3533eb4c.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26.aa - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c.aa - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c.aa - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c.aa - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91.aa - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91.aa - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91.aa - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6.aa - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26.aa - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26.aa - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72.aa - Upgrade
Upgrade
buildahto a version that resolves this vulnerability.Fixed in 1.14.9-1.module+el8.2.1+6689+748e6520 - Upgrade
Upgrade
cockpit-podmanto a version that resolves this vulnerability.Fixed in 17-1.module+el8.2.1+6636+bf4db4ab - Upgrade
Upgrade
conmonto a version that resolves this vulnerability.Fixed in 2.0.17-1.module+el8.2.1+6771+3533eb4c - Upgrade
Upgrade
container-selinuxto a version that resolves this vulnerability.Fixed in 2.135.0-1.module+el8.2.1+6849+893e4f4a - Upgrade
Upgrade
containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.6-1.module+el8.2.1+6626+598993b4 - Upgrade
Upgrade
containers-commonto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
critto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.0.0-2.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
libslirpto a version that resolves this vulnerability.Fixed in 4.3.0-3.module+el8.2.1+6816+bedf4f91 - Upgrade
Upgrade
podmanto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
podman-dockerto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
podman-remoteto a version that resolves this vulnerability.Fixed in 1.9.3-2.module+el8.2.1+6867+366c07d6 - Upgrade
Upgrade
python-podman-apito a version that resolves this vulnerability.Fixed in 1.2.0-0.2.gitd0a45fe.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
python3-criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.2.1+6750+e53a300c - Upgrade
Upgrade
runcto a version that resolves this vulnerability.Fixed in 1.0.0-66.rc10.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
skopeoto a version that resolves this vulnerability.Fixed in 1.0.0-1.module+el8.2.1+6676+604e1b26 - Upgrade
Upgrade
slirp4netnsto a version that resolves this vulnerability.Fixed in 1.0.1-1.module+el8.2.1+6595+03641d72 - Upgrade
Upgrade
toolboxto a version that resolves this vulnerability.Fixed in 0.0.7-1.module+el8.2.1+6465+1a51e8b6 - Upgrade
Upgrade
udicato a version that resolves this vulnerability.Fixed in 0.2.1-2.module+el8.2.1+6465+1a51e8b6
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:3053?
The severity of RHSA-2020:3053 is classified as a Moderate security vulnerability.
How do I fix RHSA-2020:3053?
To fix RHSA-2020:3053, you should update your affected packages to the specified versions listed in the advisory.
Which packages are affected by RHSA-2020:3053?
Affected packages include buildah, podman, conmon, skopeo, and several others related to container tools.
What is CVE-2020-1983 in relation to RHSA-2020:3053?
CVE-2020-1983 refers to a use-after-free vulnerability in the QEMU slirp component, which is addressed in the RHSA-2020:3053 advisory.
Is it safe to continue using the affected software while waiting for a patch for RHSA-2020:3053?
It is not recommended to continue using the affected software due to potential security risks until you apply the necessary patches.