RLSA-2021:4154
Dashboard / Vulnerabilities / RLSA-2021:4154
Summary: Moderate: container-tools:rhel8 security, bug fix, and enhancement update
Details: The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc. Security Fix(es): * buildah: Host environment variables leaked in build container when using chroot isolation (CVE-2021-3602) * containers/storage: DoS via malicious image (CVE-2021-20291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.
References: https://errata.rockylinux.org/RLSA-2021:4154, https://bugzilla.redhat.com/show_bug.cgi?id=1914687, https://bugzilla.redhat.com/show_bug.cgi?id=1928935, https://bugzilla.redhat.com/show_bug.cgi?id=1932399, https://bugzilla.redhat.com/show_bug.cgi?id=1933775, https://bugzilla.redhat.com/show_bug.cgi?id=1933776, https://bugzilla.redhat.com/show_bug.cgi?id=1934415, https://bugzilla.redhat.com/show_bug.cgi?id=1934480, https://bugzilla.redhat.com/show_bug.cgi?id=1937641, https://bugzilla.redhat.com/show_bug.cgi?id=1937830, https://bugzilla.redhat.com/show_bug.cgi?id=1939485, https://bugzilla.redhat.com/show_bug.cgi?id=1940037, https://bugzilla.redhat.com/show_bug.cgi?id=1940054, https://bugzilla.redhat.com/show_bug.cgi?id=1940082, https://bugzilla.redhat.com/show_bug.cgi?id=1940493, https://bugzilla.redhat.com/show_bug.cgi?id=1941380, https://bugzilla.redhat.com/show_bug.cgi?id=1947432, https://bugzilla.redhat.com/show_bug.cgi?id=1947999, https://bugzilla.redhat.com/show_bug.cgi?id=1952204, https://bugzilla.redhat.com/show_bug.cgi?id=1952698, https://bugzilla.redhat.com/show_bug.cgi?id=1957299, https://bugzilla.redhat.com/show_bug.cgi?id=1957840, https://bugzilla.redhat.com/show_bug.cgi?id=1957904, https://bugzilla.redhat.com/show_bug.cgi?id=1958353, https://bugzilla.redhat.com/show_bug.cgi?id=1960948, https://bugzilla.redhat.com/show_bug.cgi?id=1966538, https://bugzilla.redhat.com/show_bug.cgi?id=1966872, https://bugzilla.redhat.com/show_bug.cgi?id=1969264, https://bugzilla.redhat.com/show_bug.cgi?id=1972150, https://bugzilla.redhat.com/show_bug.cgi?id=1972209, https://bugzilla.redhat.com/show_bug.cgi?id=1972211, https://bugzilla.redhat.com/show_bug.cgi?id=1972282, https://bugzilla.redhat.com/show_bug.cgi?id=1972648, https://bugzilla.redhat.com/show_bug.cgi?id=1973418, https://bugzilla.redhat.com/show_bug.cgi?id=1976283, https://bugzilla.redhat.com/show_bug.cgi?id=1977280, https://bugzilla.redhat.com/show_bug.cgi?id=1977673, https://bugzilla.redhat.com/show_bug.cgi?id=1978415, https://bugzilla.redhat.com/show_bug.cgi?id=1978556, https://bugzilla.redhat.com/show_bug.cgi?id=1978647, https://bugzilla.redhat.com/show_bug.cgi?id=1979497, https://bugzilla.redhat.com/show_bug.cgi?id=1980212, https://bugzilla.redhat.com/show_bug.cgi?id=1982593, https://bugzilla.redhat.com/show_bug.cgi?id=1982762, https://bugzilla.redhat.com/show_bug.cgi?id=1985499, https://bugzilla.redhat.com/show_bug.cgi?id=1985905, https://bugzilla.redhat.com/show_bug.cgi?id=1987049, https://bugzilla.redhat.com/show_bug.cgi?id=1993209, https://bugzilla.redhat.com/show_bug.cgi?id=1993249, https://bugzilla.redhat.com/show_bug.cgi?id=1995041, https://bugzilla.redhat.com/show_bug.cgi?id=1998191, https://bugzilla.redhat.com/show_bug.cgi?id=1999144, https://bugzilla.redhat.com/show_bug.cgi?id=2000943, https://bugzilla.redhat.com/show_bug.cgi?id=2004562, https://bugzilla.redhat.com/show_bug.cgi?id=2005018
Affected packages
Package
Name: buildah
Purl: pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8-5-legacy&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
