Oracle Linux Security Advisory ELSA-2022-1565

http://linux.oracle.com/errata/ELSA-2022-1565.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.x86_64.rpm
buildah-tests-1.19.9-2.module+el8.5.0+20637+38ac8416.x86_64.rpm
cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.noarch.rpm
conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
containers-common-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm
container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.noarch.rpm
crit-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
criu-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
crun-0.18-2.module+el8.5.0+20637+38ac8416.x86_64.rpm
fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.x86_64.rpm
libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
libslirp-devel-4.3.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.x86_64.rpm
podman-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm
podman-catatonit-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm
podman-docker-3.0.1-8.module+el8.5.0+20637+38ac8416.noarch.rpm
podman-plugins-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm
podman-remote-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm
podman-tests-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm
python3-criu-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.x86_64.rpm
skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm
skopeo-tests-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm
slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.x86_64.rpm
udica-0.2.4-1.module+el8.5.0+20637+38ac8416.noarch.rpm

aarch64:
buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.aarch64.rpm
buildah-tests-1.19.9-2.module+el8.5.0+20637+38ac8416.aarch64.rpm
cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.noarch.rpm
conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
containers-common-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm
container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.noarch.rpm
crit-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
criu-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
crun-0.18-2.module+el8.5.0+20637+38ac8416.aarch64.rpm
fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.aarch64.rpm
libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
libslirp-devel-4.3.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.aarch64.rpm
podman-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm
podman-catatonit-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm
podman-docker-3.0.1-8.module+el8.5.0+20637+38ac8416.noarch.rpm
podman-plugins-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm
podman-remote-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm
podman-tests-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm
python3-criu-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.aarch64.rpm
skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm
skopeo-tests-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm
slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.aarch64.rpm
udica-0.2.4-1.module+el8.5.0+20637+38ac8416.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/criu-3.15-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/crun-0.18-2.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/podman-3.0.1-8.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/udica-0.2.4-1.module+el8.5.0+20637+38ac8416.src.rpm

Related CVEs:

CVE-2022-27649
CVE-2022-27651




Description of changes:

buildah
[1.19.9-2]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.19
  (https://github.com/containers/buildah/commit/7c6701d)
- fixes CVE-2022-27651
- Resolves: #2067539

podman
[3.0.1-8]
- update to the latest content of https://github.com/containers/podman/tree/v3.0.1-rhel
  (https://github.com/containers/podman/commit/c5d8129)
- fixes CVE-2022-27649
- Resolves: #2067511

runc
[1.0.0-73.rc95]
- fix podman run --pid=host command causes OCI permission error
- rc95 fixes CVE-2021-30465
- Related: #2070961

_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata

Oracle8: ELSA-2022-1565: container Moderate Security Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

buildah [1.19.9-2] - update to the latest content of https://github.com/containers/buildah/tree/release-1.19 (https://github.com/containers/buildah/commit/7c6701d) - fixes CVE-2022-27651 - Resolves: #2067539 podman [3.0.1-8] - update to the latest content of https://github.com/containers/podman/tree/v3.0.1-rhel (https://github.com/containers/podman/commit/c5d8129) - fixes CVE-2022-27649 - Resolves: #2067511 runc [1.0.0-73.rc95] - fix podman run --pid=host command causes OCI permission error - rc95 fixes CVE-2021-30465 - Related: #2070961

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates/buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/criu-3.15-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/crun-0.18-2.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/podman-3.0.1-8.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/udica-0.2.4-1.module+el8.5.0+20637+38ac8416.src.rpm

x86_64

buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.x86_64.rpm buildah-tests-1.19.9-2.module+el8.5.0+20637+38ac8416.x86_64.rpm cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.noarch.rpm conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.x86_64.rpm containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm containers-common-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.noarch.rpm crit-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm criu-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm crun-0.18-2.module+el8.5.0+20637+38ac8416.x86_64.rpm fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.x86_64.rpm libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm libslirp-devel-4.3.1-1.module+el8.5.0+20637+38ac8416.x86_64.rpm oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.x86_64.rpm podman-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm podman-catatonit-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm podman-docker-3.0.1-8.module+el8.5.0+20637+38ac8416.noarch.rpm podman-plugins-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm podman-remote-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm podman-tests-3.0.1-8.module+el8.5.0+20637+38ac8416.x86_64.rpm python3-criu-3.15-1.module+el8.5.0+20637+38ac8416.x86_64.rpm runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.x86_64.rpm skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm skopeo-tests-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.x86_64.rpm slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.x86_64.rpm udica-0.2.4-1.module+el8.5.0+20637+38ac8416.noarch.rpm

aarch64

buildah-1.19.9-2.module+el8.5.0+20637+38ac8416.aarch64.rpm buildah-tests-1.19.9-2.module+el8.5.0+20637+38ac8416.aarch64.rpm cockpit-podman-29-2.module+el8.5.0+20637+38ac8416.noarch.rpm conmon-2.0.26-1.module+el8.5.0+20637+38ac8416.aarch64.rpm containernetworking-plugins-0.9.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm containers-common-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm container-selinux-2.167.0-1.module+el8.5.0+20637+38ac8416.noarch.rpm crit-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm criu-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm crun-0.18-2.module+el8.5.0+20637+38ac8416.aarch64.rpm fuse-overlayfs-1.4.0-2.module+el8.5.0+20637+38ac8416.aarch64.rpm libslirp-4.3.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm libslirp-devel-4.3.1-1.module+el8.5.0+20637+38ac8416.aarch64.rpm oci-seccomp-bpf-hook-1.2.0-3.module+el8.5.0+20637+38ac8416.aarch64.rpm podman-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm podman-catatonit-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm podman-docker-3.0.1-8.module+el8.5.0+20637+38ac8416.noarch.rpm podman-plugins-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm podman-remote-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm podman-tests-3.0.1-8.module+el8.5.0+20637+38ac8416.aarch64.rpm python3-criu-3.15-1.module+el8.5.0+20637+38ac8416.aarch64.rpm runc-1.0.0-73.rc95.module+el8.5.0+20637+38ac8416.aarch64.rpm skopeo-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm skopeo-tests-1.2.4-1.0.1.module+el8.5.0+20637+38ac8416.aarch64.rpm slirp4netns-1.1.8-1.module+el8.5.0+20637+38ac8416.aarch64.rpm udica-0.2.4-1.module+el8.5.0+20637+38ac8416.noarch.rpm

i386

Severity
Related CVEs: CVE-2022-27649 CVE-2022-27651

Related News