Fedora 41: buildah 2024-2e8c63e8bf Security Advisory Updates
Summary
The buildah package provides a command line tool which can be used to
* create a working container from scratch
or
* create a working container from an image as a starting point
* mount/umount a working container's root file system for manipulation
* save container's root file system layer to create a new image
* delete a working container or an image
Update Information:
Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41.
Changelog for buildah
* Mon Oct 07 2024 Packit
Change Log
* Mon Oct 7 2024 Packit
References
[ 1 ] Bug #2315691 - CVE-2024-9341 Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library
https://bugzilla.redhat.com/show_bug.cgi?id=2315691
[ 2 ] Bug #2315887 - CVE-2024-9407 Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction
https://bugzilla.redhat.com/show_bug.cgi?id=2315887
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2e8c63e8bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label