Fedora 41: buildah 2024-5a61a2fa45 Security Advisory Updates
Summary
The buildah package provides a command line tool which can be used to
* create a working container from scratch
or
* create a working container from an image as a starting point
* mount/umount a working container's root file system for manipulation
* save container's root file system layer to create a new image
* delete a working container or an image
Update Information:
Automatic update for buildah-1.37.5-1.fc41.
Changelog for buildah
* Fri Oct 18 2024 Packit
Change Log
* Fri Oct 18 2024 Packit
References
[ 1 ] Bug #2317462 - CVE-2024-9675 buildah: Buildah allows arbitrary directory mount [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2317462 [ 2 ] Bug #2317464 - CVE-2024-9675 podman: Buildah allows arbitrary directory mount [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2317464 [ 3 ] Bug #2318511 - CVE-2024-9341 podman: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2318511 [ 4 ] Bug #2318514 - CVE-2024-9341 buildah: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2318514 [ 5 ] Bug #2319017 - CVE-2024-9676 buildah: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2319017 [ 6 ] Bug #2319019 - CVE-2024-9676 podman: symlink traversal...
Read the Full AdvisoryUpdate Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5a61a2fa45' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label