{"schema_version": "1.3.1", "id": "RLSA-2023:7202", "modified": "2023-11-28T22:45:08.746280Z", "published": "2023-11-28T22:43:02.525343Z", "related": ["CVE-2023-29406"], "summary": "Moderate: container-tools:4.0 security and bug fix update", "details": "The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* could not find symbol `criu_set_lsm_mount_context` in `libcriu.so` (BZ#2242871)", "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "buildah", "purl": "pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.24.6-7.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "cockpit-podman", "purl": "pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:46-1.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "conmon", "purl": "pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:2.1.4-2.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containernetworking-plugins", "purl": "pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.1.1-5.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containers-common", "purl": "pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1-38.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "container-selinux", "purl": "pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:2.205.0-3.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "criu", "purl": "pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:3.15-3.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "crun", "purl": "pkg:rpm/rocky-linux/crun?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.8.7-1.module+el8.9.0+1580+e76741f0"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "fuse-overlayfs", "purl": "pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.9-2.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libslirp", "purl": "pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.4.0-1.module+el8.9.0+1420+91577025"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "oci-seccomp-bpf-hook", "purl": "pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.5-2.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "podman", "purl": "pkg:rpm/rocky-linux/podman?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:4.0.2-24.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "python-podman", "purl": "pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.0.0-2.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "runc", "purl": "pkg:rpm/rocky-linux/runc?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.1.5-2.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "skopeo", "purl": "pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.6.2-9.module+el8.9.0+1578+aa900b44"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "slirp4netns", "purl": "pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.1.8-3.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "toolbox", "purl": "pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.0.99.4-5.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "udica", "purl": "pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.6-4.module+el8.9.0+1445+07728297"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2023:7202"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2222167"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2242871"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}