{"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2022:8008","synopsis":"Moderate: buildah security and bug fix update","severity":"SEVERITY_MODERATE","topic":"An update for buildah is now available for Rocky Linux 9.\nRocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","description":"The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. \nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"1939485","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1939485","description":"CVE-2021-20291 containers\/storage: DoS via malicious image"},{"ticket":"1989564","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1989564","description":"CVE-2021-33195 golang: net: lookup functions may return invalid host names"},{"ticket":"1989570","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1989570","description":"CVE-2021-33197 golang: net\/http\/httputil: ReverseProxy forwards connection headers if first one is empty"},{"ticket":"1989575","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1989575","description":"CVE-2021-33198 golang: math\/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents"},{"ticket":"2064702","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2064702","description":"CVE-2022-27191 golang: crash in a golang.org\/x\/crypto\/ssh server"},{"ticket":"2081835","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2081835","description":"networking is broken when building containers due to missing container networking package dependencies"},{"ticket":"2121445","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2121445","description":"CVE-2022-2989 podman: possible information disclosure and modification"},{"ticket":"2121453","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2121453","description":"CVE-2022-2990 buildah: possible information disclosure and modification"}],"cves":[{"name":"CVE-2022-27191","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-27191.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","cvss3BaseScore":"7.5","cwe":"CWE-327"}],"references":[],"publishedAt":"2023-01-25T21:21:29.156891Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}

Rocky Linux: RLSA-2022:8008 buildah security and bug fix update

January 25, 2023
An update for buildah is now available for Rocky Linux 9. Rocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate

Summary

An update for buildah is now available for Rocky Linux 9. Rocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.


RPMs

References

No References

CVEs

https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2022-27191.json

Severity
Name: RLSA-2022:8008
Affected Products: Rocky Linux 9

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=1939485

https://bugzilla.redhat.com/show_bug.cgi?id=1989564

https://bugzilla.redhat.com/show_bug.cgi?id=1989570

https://bugzilla.redhat.com/show_bug.cgi?id=1989575

https://bugzilla.redhat.com/show_bug.cgi?id=2064702

https://bugzilla.redhat.com/show_bug.cgi?id=2081835

https://bugzilla.redhat.com/show_bug.cgi?id=2121445

https://bugzilla.redhat.com/show_bug.cgi?id=2121453


Related News