buildah-1.33.7-1.el9

エラータID: AXSA:2024-8134:04

Release date: 
Friday, June 7, 2024 - 16:40
Subject: 
buildah-1.33.7-1.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Bug Fix(es):

* TRIAGE CVE-2024-24786 buildah: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON [rhel-9] RHEL9.4 0Day (JIRA:RHEL-28230)

CVE-2024-24786
The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. buildah-1.33.7-1.el9.src.rpm
    MD5: 8a4310362bc5fd94edfa9ba9c77c89fc
    SHA-256: ae932ee749461e137df80f353ab6da5160aa7ec319673ba92096abd063b84de5
    Size: 17.45 MB

Asianux Server 9 for x86_64
  1. buildah-1.33.7-1.el9.x86_64.rpm
    MD5: 67458e291c0945c3e4edcc96e1aff834
    SHA-256: fa937e34ddc66b2819a361040d203cf8228a391720adf0c5ebfcfccd0d6df52d
    Size: 9.40 MB
  2. buildah-tests-1.33.7-1.el9.x86_64.rpm
    MD5: c244f37afe8bb9b7feb43b160fc3ee5d
    SHA-256: 40426af6988c9c7510daf992056c9ea0c9bb0574713338751e0949aabe0fc71a
    Size: 29.51 MB