First published: Tue Nov 10 2020(Updated: )
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.<br>Security Fix(es):<br><li> golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)</li> <li> podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API (CVE-2020-14370)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> podman does not use $TMPDIR loading a tar file (BZ#1877699)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/podman | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman-debuginfo | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman-docker | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman-debuginfo | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
redhat/podman-debuginfo | <1.6.4-26.el7_9 | 1.6.4-26.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:5056 is classified as moderate.
To fix RHSA-2020:5056, update the affected podman packages to version 1.6.4-26.el7_9.
RHSA-2020:5056 impacts the podman, podman-docker, and podman-debuginfo packages.
There is no official workaround for RHSA-2020:5056; upgrading is recommended.
RHSA-2020:5056 addresses a vulnerability in the golang.org/x/text library that could trigger an infinite loop.