RedHat: RHSA-2020-1230:01 Moderate: skopeo security and bug fix update
Summary
The skopeo command lets you inspect images from container image registries,
get images and image layers, and use signatures to create and verify files.
Security Fix(es):
* proglottis/gpgme: Use-after-free in GPGME bindings during container image
pull (CVE-2020-8945)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* Skopeo doesn't handle HTTP 429 errors properly (BZ#1752775)
* skopeo does not show manifest manifest.list.v2 for special cases
(BZ#1754905)
* skopeo inspect results in panic: runtime error: invalid memory address or
nil pointer dereference (BZ#1769575)
* skopeo should be linked against gpgme-pthread (BZ#1793080)
* docker won't start because registries service won't start (BZ#1812505)
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2020-8945 https://access.redhat.com/security/updates/classification/#moderate
Package List
Red Hat Enterprise Linux 7 Extras:
Source:
skopeo-0.1.40-7.el7_8.src.rpm
ppc64le:
containers-common-0.1.40-7.el7_8.ppc64le.rpm
skopeo-0.1.40-7.el7_8.ppc64le.rpm
skopeo-debuginfo-0.1.40-7.el7_8.ppc64le.rpm
s390x:
containers-common-0.1.40-7.el7_8.s390x.rpm
skopeo-0.1.40-7.el7_8.s390x.rpm
skopeo-debuginfo-0.1.40-7.el7_8.s390x.rpm
x86_64:
containers-common-0.1.40-7.el7_8.x86_64.rpm
skopeo-0.1.40-7.el7_8.x86_64.rpm
skopeo-debuginfo-0.1.40-7.el7_8.x86_64.rpm
Red Hat Enterprise Linux 7 Extras:
Source:
skopeo-0.1.40-7.el7_8.src.rpm
x86_64:
containers-common-0.1.40-7.el7_8.x86_64.rpm
skopeo-0.1.40-7.el7_8.x86_64.rpm
skopeo-debuginfo-0.1.40-7.el7_8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for skopeo is now available for Red Hat Enterprise Linux 7Extras.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux 7 Extras - ppc64le, s390x, x86_64
Bugs Fixed
1752775 - Skopeo doesn't handle HTTP 429 errors properly
1754905 - skopeo does not show manifest manifest.list.v2 for special cases
1795838 - CVE-2020-8945 proglottis/gpgme: Use-after-free in GPGME bindings during container image pull
1812505 - docker won't start because registries service won't start