First published: Mon Aug 22 2022(Updated: )
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.<br>Security Fix(es):<br><li> podman: Security regression of CVE-2020-8945 due to source code management issue (CVE-2022-2738)</li> <li> podman: Security regression of CVE-2020-14370 due to source code management issue (CVE-2022-2739)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> podman-1.6.4-32 prints a `Error: read unixpacket` when running in interactive mode (BZ#2087994)</li> <li> systemd managed container doesn't start serving web traffic despite of starting on system startup. (BZ#2096449)</li> <li> Can not Add url with podman build (BZ#2112217)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/podman | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman-debuginfo | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman-docker | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman-debuginfo | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
redhat/podman-debuginfo | <1.6.4-36.el7_9 | 1.6.4-36.el7_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2022:6119 addresses a security regression of CVE-2020-8945 affecting the Podman tool.
To fix RHSA-2022:6119, update Podman to version 1.6.4-36.el7_9 or later.
RHSA-2022:6119 affects Red Hat Enterprise Linux systems utilizing Podman versions prior to 1.6.4-36.el7_9.
RHSA-2022:6119 impacts the Podman, Podman-debuginfo, and Podman-docker packages.
The vulnerability in RHSA-2022:6119 could potentially allow unauthorized access due to misconfiguration in Podman's security settings.