RHSA-2020:4694: Moderate: container-tools:rhel8 security, bug fix, and enhancement update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): containernetworking/plugins: IPv6 router advertisements allow for MitM attacks on IPv4 clusters (CVE-2020-10749) QEMU: slirp: networking out-of-bounds read information disclosure vulnerability (CVE-2020-10756) golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 18.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.20-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.144.0-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/python-podman-apito a version that resolves this vulnerability.Fixed in 1.2.0-0.2.gitd0a45fe.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.8-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.2-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.15.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.20-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.8.6-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 0.14.1-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.2-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 2.0.5-5.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.14-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-68.rc92.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-2.module+el8.3.0+8221+97165c3f.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4694?
The severity of RHSA-2020:4694 is categorized as important.
How do I fix RHSA-2020:4694?
You can fix RHSA-2020:4694 by updating the affected packages to their fixed versions as specified in the advisory.
Which packages are affected by RHSA-2020:4694?
Affected packages include buildah, podman, conmon, and several others in the Red Hat container-tools module.
What vulnerabilities does RHSA-2020:4694 address?
RHSA-2020:4694 addresses vulnerabilities including CVE-2020-10749 related to MitM attacks on IPv4 clusters.
What versions of packages should I update for RHSA-2020:4694?
You should update to the versions specified in the advisory, such as buildah 1.15.1-2.module+el8.3.0+8221+97165c3f.