{"schema_version": "1.3.1", "id": "RLSA-2024:8846", "modified": "2024-11-08T15:59:30.140809Z", "published": "2024-11-08T15:56:47.559546Z", "related": ["CVE-2024-9341", "CVE-2024-9407", "CVE-2024-9675"], "summary": "Important: container-tools:rhel8 security update", "details": "The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341)\n\n* Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (CVE-2024-9407)\n\n* buildah: Buildah allows arbitrary directory mount (CVE-2024-9675)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "affected": [{"package": {"ecosystem": "Rocky Linux:8", "name": "aardvark-dns", "purl": "pkg:rpm/rocky-linux/aardvark-dns?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.10.1-2.module+el8.10.0+1874+ce489889"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "buildah", "purl": "pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.33.10-1.module+el8.10.0+1880+8e896d1b"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "cockpit-podman", "purl": "pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:84.1-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "conmon", "purl": "pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8&epoch=3"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "3:2.1.10-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containernetworking-plugins", "purl": "pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.4.0-5.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "containers-common", "purl": "pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1-82.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "container-selinux", "purl": "pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:2.229.0-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "criu", "purl": "pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:3.18-5.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "crun", "purl": "pkg:rpm/rocky-linux/crun?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.14.3-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "fuse-overlayfs", "purl": "pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.13-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "libslirp", "purl": "pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.4.0-2.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "netavark", "purl": "pkg:rpm/rocky-linux/netavark?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.10.3-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "oci-seccomp-bpf-hook", "purl": "pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.10-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "podman", "purl": "pkg:rpm/rocky-linux/podman?distro=rocky-linux-8&epoch=4"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "4:4.9.4-15.module+el8.10.0+1880+8e896d1b"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "python-podman", "purl": "pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:4.9.0-2.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "runc", "purl": "pkg:rpm/rocky-linux/runc?distro=rocky-linux-8&epoch=1"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "1:1.1.12-5.module+el8.10.0+1874+ce489889"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "skopeo", "purl": "pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8&epoch=2"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "2:1.14.5-3.module+el8.10.0+1843+6892ab28"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "slirp4netns", "purl": "pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.2.3-1.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "toolbox", "purl": "pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2"}], "database_specific": {"yum_repository": "AppStream"}}]}, {"package": {"ecosystem": "Rocky Linux:8", "name": "udica", "purl": "pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:0.2.6-21.module+el8.10.0+1815+5fe7415e"}], "database_specific": {"yum_repository": "AppStream"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2024:8846"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315691"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2315887"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2317458"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}]}