ALSA-2022:1762
Dashboard / Vulnerabilities / ALSA-2022:1762
ALSA-2022:1762
Summary: Important: container-tools:rhel8 security, bug fix, and enhancement update
Details: The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * psgo: Privilege escalation in 'podman top' (CVE-2022-1227) * prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) * podman: Default inheritable capabilities for linux container should be empty (CVE-2022-27649) * crun: Default inheritable capabilities for linux container should be empty (CVE-2022-27650) * buildah: Default inheritable capabilities for linux container should be empty (CVE-2022-27651) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://access.redhat.com/errata/RHSA-2022:1762, https://access.redhat.com/security/cve/CVE-2022-1227, https://access.redhat.com/security/cve/CVE-2022-21698, https://access.redhat.com/security/cve/CVE-2022-27649, https://access.redhat.com/security/cve/CVE-2022-27650, https://access.redhat.com/security/cve/CVE-2022-27651, https://bugzilla.redhat.com/2045880, https://bugzilla.redhat.com/2066568, https://bugzilla.redhat.com/2066840, https://bugzilla.redhat.com/2066845, https://bugzilla.redhat.com/2070368, https://errata.almalinux.org/8/ALSA-2022-1762.html, https://vulners.com/cve/CVE-2022-1227, https://vulners.com/cve/CVE-2022-21698, https://vulners.com/cve/CVE-2022-27649, https://vulners.com/cve/CVE-2022-27650, https://vulners.com/cve/CVE-2022-27651
Affected packages
Package
Name: aardvark-dns
Purl: pkg:rpm/almalinux/aardvark-dns
Affected ranges
Type: ECOSYSTEM
Events:
