{"schema_version": "1.3.1", "id": "RLSA-2024:8038", "modified": "2024-10-25T17:18:45.275430Z", "published": "2024-10-25T17:16:21.716473Z", "related": ["CVE-2023-45290", "CVE-2024-34155", "CVE-2024-34156", "CVE-2024-34158"], "summary": "Important: container-tools:rhel8 security update", "details": "The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)\n\n* go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155)\n\n* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)\n\n* go/build/constraint: golang: Calling Parse on a \"// +build\" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "aardvark-dns", "purl": "pkg:rpm/rocky-linux/aardvark-dns?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.10.1-2.module+el8.10.0+1874+ce489889"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "buildah", "purl": "pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.33.8-4.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "cockpit-podman", "purl": "pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:84.1-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "conmon", "purl": "pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8&epoch=3"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "3:2.1.10-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containernetworking-plugins", "purl": "pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.4.0-5.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containers-common", "purl": "pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1-82.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "container-selinux", "purl": "pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:2.229.0-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "criu", "purl": "pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:3.18-5.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "crun", "purl": "pkg:rpm/rocky-linux/crun?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.14.3-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "fuse-overlayfs", "purl": "pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.13-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libslirp", "purl": "pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.4.0-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "netavark", "purl": "pkg:rpm/rocky-linux/netavark?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.10.3-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "oci-seccomp-bpf-hook", "purl": "pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.10-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "podman", "purl": "pkg:rpm/rocky-linux/podman?distro=rocky-linux-8&epoch=4"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "4:4.9.4-13.module+el8.10.0+1871+e6fa1069"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "python-podman", "purl": "pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.9.0-2.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "runc", "purl": "pkg:rpm/rocky-linux/runc?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.1.12-5.module+el8.10.0+1874+ce489889"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "skopeo", "purl": "pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.14.5-3.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "slirp4netns", "purl": "pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.3-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "toolbox", "purl": "pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "udica", "purl": "pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.6-21.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2024:8038"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268017"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310527"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310528"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310529"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}