RHSA-2023:2758: Moderate: container-tools:rhel8 security, bug fix, and enhancement update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705) golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962) golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664) golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131) golang: io/fs: stack exhaustion in Glob (CVE-2022-30630) golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631) golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632) golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633) golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635) golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148) golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) podman: symlink exchange attack in podman export volume (CVE-2023-0778) golang: crypto/tls: session tickets lack random ticketageadd (CVE-2022-30629) golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 63.1-1.module+el8.8.0+18286+cd236dce - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.205.0-2.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1-63.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/netavarkto a version that resolves this vulnerability.Fixed in 1.5.0-4.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/python-podmanto a version that resolves this vulnerability.Fixed in 4.4.1-1.module+el8.8.0+18275+3a56cc62 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.11.2-0.2.module+el8.8.0+18251+ad5b274c - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03 - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.6-20.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/python3-podmanto a version that resolves this vulnerability.Fixed in 4.4.1-1.module+el8.8.0+18275+3a56cc62 - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/criu-develto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/criu-libsto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/criu-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-gvproxyto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-gvproxy-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65 - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.11.2-0.2.module+el8.8.0+18251+ad5b274c - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03 - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03 - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03 - Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.5.0-2.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.29.1-1.module+el8.8.0+18195+471da4bb.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f.aa - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f.aa - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.6-1.module+el8.8.0+18098+9b44df5f.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1-63.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criu-develto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criu-libsto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/criu-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe.aa - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe.aa - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.1-2.module+el8.8.0+18418+f0e540fe.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.10-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/netavarkto a version that resolves this vulnerability.Fixed in 1.5.0-4.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.8-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-gvproxyto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-gvproxy-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 4.4.1-8.module+el8.8.0+18438+15d3aa65.aa - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.11.2-0.2.module+el8.8.0+18251+ad5b274c.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.11.2-0.2.module+el8.8.0+18251+ad5b274c.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.8.0+18060+3f21f2cc.aa - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03.aa - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03.aa - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03.aa - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-7.module+el8.8.0+18119+e3deee03.aa - Upgrade
Upgrade
golang/compress/gzipto a version that resolves this vulnerability.Patch CVE-2022-30631 - Upgrade
Upgrade
golang/crypto/tlsto a version that resolves this vulnerability.Patch CVE-2022-30629 - Upgrade
Upgrade
golang/encoding/gobto a version that resolves this vulnerability.Patch CVE-2022-30635 - Upgrade
Upgrade
golang/encoding/xmlto a version that resolves this vulnerability.Patch CVE-2022-28131 - Upgrade
Upgrade
golang/encoding/xmlto a version that resolves this vulnerability.Patch CVE-2022-30633 - Upgrade
Upgrade
golang/go/parserto a version that resolves this vulnerability.Patch CVE-2022-1962 - Upgrade
Upgrade
golang/io/fsto a version that resolves this vulnerability.Patch CVE-2022-30630 - Upgrade
Upgrade
golang/math/bigto a version that resolves this vulnerability.Patch CVE-2022-32189 - Upgrade
Upgrade
golang/net/httpto a version that resolves this vulnerability.Patch CVE-2022-41717 - Upgrade
Upgrade
golang/net/httpto a version that resolves this vulnerability.Patch CVE-2022-27664 - Upgrade
Upgrade
golang/net/http/httputilto a version that resolves this vulnerability.Patch CVE-2022-32148 - Upgrade
Upgrade
golang/path/filepathto a version that resolves this vulnerability.Patch CVE-2022-30632 - Upgrade
Upgrade
podmanto a version that resolves this vulnerability.Patch CVE-2023-0778 - Upgrade
Upgrade
container-tools:rhel8to a version that resolves this vulnerability.Patch CVE-2022-1705
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:2758?
The severity of RHSA-2023:2758 is Critical.
How do I fix RHSA-2023:2758?
To fix RHSA-2023:2758, update the affected packages to their patched versions as mentioned in the advisory.
Which packages are affected by RHSA-2023:2758?
Affected packages include podman, buildah, skopeo, runc, and various related container tools.
What types of vulnerabilities are addressed in RHSA-2023:2758?
RHSA-2023:2758 addresses vulnerabilities related to improper sanitization of headers and other security defects.
Is updating required for all systems using the affected packages in RHSA-2023:2758?
Yes, updating is required for all systems using the affected packages to mitigate potential security risks.