buildah-1.29.1-1.el9
エラータID: AXSA:2023-5642:02
The buildah package provides a tool for facilitating building OCI container
images. Among other things, buildah enables you to: Create a working container,
either from scratch or using an image as a starting point; Create an image,
either from a working container or using the instructions in a Dockerfile; Build
both Docker and OCI images.
Security Fix(es):
* golang: net/http: An attacker can cause excessive memory growth in a Go
server accepting HTTP/2 requests (CVE-2022-41717)
* golang: crypto/tls: session tickets lack random ticket_age_add
(CVE-2022-30629)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.
CVE-2022-30629
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
Update packages.
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
N/A
SRPMS
- buildah-1.29.1-1.el9.src.rpm
MD5: f82f0e0d8ac2c990f28950a415f425f8
SHA-256: c1149d9dc332581246ddf52a3615a31f6000e761676b051b5153235c5d5bf0a5
Size: 14.60 MB
Asianux Server 9 for x86_64
- buildah-1.29.1-1.el9.x86_64.rpm
MD5: c438c5efbf689ab9f99e65c09f2ac136
SHA-256: fc1877bf798c51cf2229efabd19b8e5d90d20fba662036434466b0f3c5e58aab
Size: 8.59 MB - buildah-tests-1.29.1-1.el9.x86_64.rpm
MD5: 583deeec2262c6bbf3617303e280c897
SHA-256: 12843f672e8ac5f5d3244506402e156d59e9caf401b383709883ad827d4841a6
Size: 27.45 MB