{"schema_version":"1.7.3","id":"ALSA-2022:8431","published":"2022-11-15T00:00:00Z","modified":"2026-02-04T02:41:59.913166Z","related":["CVE-2022-2989","CVE-2022-2990"],"summary":"Low: podman security, bug fix, and enhancement update","details":"The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.\n\nSecurity Fix(es):\n\n* podman: possible information disclosure and modification (CVE-2022-2989)\n* buildah: possible information disclosure and modification (CVE-2022-2990)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* (podman image trust) does not support the new trust type \"sigstoreSigned \" (BZ#2120436)\n* dnf-update broken for podman/catatonit (BZ#2123319)\n* podman creates lock file in /etc/cni/net.d/cni.lock instead of /run/lock/ (BZ#2123905)\n* podman kill may deadlock [AlmaLinux 9.1] (BZ#2124716)\n* containers config.json gets empty after sudden power loss (BZ#2136278)\n* PANIC podman API service endpoint handler panic (BZ#2136287)\n\nEnhancement(s):\n\n* Podman volume plugin timeout should be configurable [almalinux-9.1.0 Z] (BZ#2124676)\n* [RFE]Podman support to perform custom actions on unhealthy containers (BZ#2136281)","affected":[{"package":{"name":"podman","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-catatonit","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-catatonit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-docker","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-docker"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-gvproxy","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-gvproxy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-plugins","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-plugins"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-remote","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-remote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}},{"package":{"name":"podman-tests","ecosystem":"AlmaLinux:9","purl":"pkg:rpm/almalinux/podman-tests"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:4.2.0-7.el9_1"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2022:8431.json"}}],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2022:8431"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2022-2989"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2022-2990"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2121445"},{"type":"REPORT","url":"https://bugzilla.redhat.com/2121453"},{"type":"ADVISORY","url":"https://errata.almalinux.org/9/ALSA-2022-8431.html"}]}