SUSE-SU-2022:3480-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3480-1
SUSE-SU-2022:3480-1
Summary: Security update for buildah
Details: This update for buildah fixes the following issues: - Updated to version 1.26.0: - CVE-2022-27651: Fixed an issue where containers were incorrectly started with non-empty inheritable Linux process capabilities (bsc#1197870). - CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961). - CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223480-1/, https://bugzilla.suse.com/1167864, https://bugzilla.suse.com/1181961, https://bugzilla.suse.com/1183043, https://bugzilla.suse.com/1192999, https://bugzilla.suse.com/1197870, https://www.suse.com/security/cve/CVE-2020-10696, https://www.suse.com/security/cve/CVE-2021-20206, https://www.suse.com/security/cve/CVE-2022-27651
Affected packages
Package
Name: buildah
Purl: pkg:rpm/suse/buildah&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
