container-tools:rhel8 security update

エラータID: AXSA:2024-8686:01

Release date: 
Tuesday, August 20, 2024 - 16:42
Subject: 
container-tools:rhel8 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
* golang: net/[http:](http:) memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)
* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)
* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)
* containers/image: digest type does not guarantee valid type (CVE-2024-3727)
* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* go-retryable[http:](http:) url might write sensitive information to log file (CVE-2024-6104)
* gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-45290
When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.
CVE-2024-1394
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.
CVE-2024-24783
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.
CVE-2024-24784
The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in different trust decisions being made by programs using different parsers.
CVE-2024-24789
The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.
CVE-2024-3727
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
CVE-2024-37298
gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens it up to malicious attacks regarding memory allocations, taking advantage of the sparse slice functionality. Any use of `schema.Decoder.Decode()` on a struct with arrays of other structs could be vulnerable to this memory exhaustion vulnerability. Version 1.4.1 contains a patch for the issue.
CVE-2024-6104
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

Modularity name: "container-tools"
Stream name: "rhel8"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. aardvark-dns-1.10.0-1.module+el8+1796+203facf7.src.rpm
    MD5: 2dfc32a8e1c57ee659df8b8158f988ec
    SHA-256: 35a694b9120bda44730cc25bc74c0ad7df747ad14788238a933d70282f51b930
    Size: 6.04 MB
  2. buildah-1.33.8-4.module+el8+1796+203facf7.src.rpm
    MD5: b2e55e0df9f89f7d8ba539bde57d60b3
    SHA-256: c6bf1a2c9f7ee8387f01c17434525d84f29ea7b5832371e17f3ab6b85259eea6
    Size: 17.48 MB
  3. cockpit-podman-84.1-1.module+el8+1796+203facf7.src.rpm
    MD5: fd7099892422ddb7ceb24b9e71500ed5
    SHA-256: 100b41b28510b2cc6098aba71c50dae74079b29c0f94e2bc1f282d1c52022389
    Size: 1.27 MB
  4. conmon-2.1.10-1.module+el8+1796+203facf7.src.rpm
    MD5: 5cfe639c9c3bffc3a63d90655a2c1710
    SHA-256: 3356050e56de1743620eba23c154109baef35d01514740d74c60e239bbcbc5e0
    Size: 133.59 kB
  5. containernetworking-plugins-1.4.0-5.module+el8+1796+203facf7.src.rpm
    MD5: 1c7d3b8428fb441b4eb0095b1c6e7552
    SHA-256: 0c861eafb72a5f542cfd4ddf3914616f4e95f9bd0aecb77c439fc547268a98b6
    Size: 3.62 MB
  6. containers-common-1-82.module+el8+1796+203facf7.src.rpm
    MD5: dc88f7a3878af965af4896c524222289
    SHA-256: 7f69b24c633516a51ad10287f878d286b4be52dc8ca64633a85706b5071f6513
    Size: 145.63 kB
  7. container-selinux-2.229.0-2.module+el8+1796+203facf7.src.rpm
    MD5: 511def261466bd72fcb9c2f48f0157e3
    SHA-256: d5147b5a1e4828c89b5f2cd2f4140fc7a006895f7607331e87c0f87cd778d9ac
    Size: 65.58 kB
  8. criu-3.18-5.module+el8+1796+203facf7.src.rpm
    MD5: cd94c67d589830d6e5541e86634ef4e7
    SHA-256: 3ca5528b6b18a18960e3771a16a195230216f8d8abb8a9146d7f65a5fded4f2a
    Size: 1.32 MB
  9. crun-1.14.3-2.module+el8+1796+203facf7.src.rpm
    MD5: 4e50cf9cc314450043edbef7f1c08547
    SHA-256: addb039896d63f96e74c7e05628911cfdd1d6e81e73c99d42d5704f0ebebad69
    Size: 1.68 MB
  10. fuse-overlayfs-1.13-1.module+el8+1796+203facf7.src.rpm
    MD5: 890f8ddd030ec14e20e181bbb29d3b20
    SHA-256: f0932d598a02bb2e77487745a9101dd725e097595f68256d72366f90a589be1f
    Size: 112.28 kB
  11. libslirp-4.4.0-2.module+el8+1796+203facf7.src.rpm
    MD5: 16b9224605561f3ce8317f9a3e0c6e2d
    SHA-256: 0429239bbd774d9b692fb9325d3c6661cc0322346dd73d3e05add86650238229
    Size: 114.97 kB
  12. netavark-1.10.3-1.module+el8+1796+203facf7.src.rpm
    MD5: 7c82e3f6edd56551909502c1ef5b3475
    SHA-256: 8f8f2982acfc8de4c35be7d455e98ec1b5d81f9ceacfa3c913dac04e4c5600bf
    Size: 15.51 MB
  13. oci-seccomp-bpf-hook-1.2.10-1.module+el8+1796+203facf7.src.rpm
    MD5: 66aca58543fe316776e8164950bda01d
    SHA-256: ff7b2556ecb3b8a6029fd512c9959af6173510d09cc4f8a066aa566a7097b69f
    Size: 1.43 MB
  14. podman-4.9.4-12.module+el8+1796+203facf7.src.rpm
    MD5: 07b78fbe287740bfc46184e0c4883e7c
    SHA-256: b47e9e501f677ba7f986a7b0fd42b6c8552307b113d6ebc613e562e18ac2bdc2
    Size: 32.58 MB
  15. python-podman-4.9.0-2.module+el8+1796+203facf7.src.rpm
    MD5: e41a021387f9779bef086707f3295b38
    SHA-256: 50983b74ca76b1f8a8da44334565cbe3ede31bc3afe48fe23a771a090dc04e75
    Size: 188.06 kB
  16. runc-1.1.12-4.module+el8+1796+203facf7.src.rpm
    MD5: 0d9273f3f100a7d109f139e8018a03e0
    SHA-256: 81ff8177c1021a37c8971c1f08b39b4132c12c66879ef3caf9cef402b369646e
    Size: 2.38 MB
  17. skopeo-1.14.5-3.module+el8+1796+203facf7.src.rpm
    MD5: 206d8ab10e31e0f84dffe118abeb94a3
    SHA-256: e9743f45657b51f99621a300662b319d587205aebf3d7c7344acf95eeb234403
    Size: 10.00 MB
  18. slirp4netns-1.2.3-1.module+el8+1796+203facf7.src.rpm
    MD5: 5fe35b428476071e8c2adbae8410b525
    SHA-256: 247f6e8f384cb2c03475cd04cde14c273550df91d22689306c07639bcbd07f65
    Size: 76.05 kB
  19. toolbox-0.0.99.5-2.module+el8+1796+203facf7.src.rpm
    MD5: 356ee909c3b869b683fa0b6a73966202
    SHA-256: f1509707d93ddf9ad30246c53aa8d42bd67353a7f7ff05d1533a8560ae1a66fd
    Size: 1.10 MB
  20. udica-0.2.6-21.module+el8+1796+203facf7.src.rpm
    MD5: fef46b5b40f59958e5f9a188b048c828
    SHA-256: 21775999ae514bcb8be2037b5d5b3af7a724334fb3a7bb9f9b73e8241bf20579
    Size: 134.32 kB

Asianux Server 8 for x86_64
  1. aardvark-dns-1.10.0-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 50b1af72d1016399fbeb6597140ee796
    SHA-256: 4c9e8073eb83875e778150d9ae723b4eeed127a6d666d1cee96874c39dc6d21b
    Size: 969.21 kB
  2. buildah-1.33.8-4.module+el8+1796+203facf7.x86_64.rpm
    MD5: d34a87476e6d70aa0660fd819f0f10f7
    SHA-256: 9dcf9dbd66b13b8e9f361864bcccd04e181ba335ce806eb4da85f25f1e9af055
    Size: 9.66 MB
  3. buildah-debugsource-1.33.8-4.module+el8+1796+203facf7.x86_64.rpm
    MD5: f499c4c3ac48a4d916017314d39d982a
    SHA-256: 57110013a2be58cb43f570925e38521f0b74af6f860ec3ba168dd3b37833c192
    Size: 6.12 MB
  4. buildah-tests-1.33.8-4.module+el8+1796+203facf7.x86_64.rpm
    MD5: de9eff149ace1c819c6a81b6c0fd1fd6
    SHA-256: 0dae88b7ff030d58ad2406ea4812734b9385b709d66fb7e1a8e5eab0e07f5549
    Size: 30.62 MB
  5. cockpit-podman-84.1-1.module+el8+1796+203facf7.noarch.rpm
    MD5: a650639e4d14e9eef15a6fb4aecd1d2e
    SHA-256: e4753f8d501eb1ccd9b5ed09b531d4d26f38b820eb9ea332b623137253446165
    Size: 682.92 kB
  6. conmon-2.1.10-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 22ec1ab90eacc3befd82caf5bc20c4ea
    SHA-256: f7ca1aa75158441f2b8d65f76447daa7df1193f5ae433e49543207aa241c034e
    Size: 56.82 kB
  7. conmon-debugsource-2.1.10-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: e3f55f21d5d51cc1fde838cd8003c564
    SHA-256: 7d42afd7fd6e956655c9931687bf2e083820b1c1de07c9b9781ad1152f4b5525
    Size: 50.46 kB
  8. containernetworking-plugins-1.4.0-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 9f981e1364b2144614686b070d857d3d
    SHA-256: b877ebb5dedc802437610e9b57c58c1080c628060486d7aece8f6d77a92aa807
    Size: 22.02 MB
  9. containernetworking-plugins-debugsource-1.4.0-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 55f470db8fa7297850210eb809f9ae4e
    SHA-256: f936ffae04a561f1d0161afef289d0239769b5aba73be750b8a0d9ea0c0068d8
    Size: 429.96 kB
  10. containers-common-1-82.module+el8+1796+203facf7.x86_64.rpm
    MD5: 059a1e83bd1df4400e5942d8c2a7024d
    SHA-256: 6f2c19418458cff8e8e041b4a4c3beb5d0d39a00e81d72abef46da4d7be9f59d
    Size: 142.03 kB
  11. container-selinux-2.229.0-2.module+el8+1796+203facf7.noarch.rpm
    MD5: d7120ca61d3fe3368ff2eac4ce5bda84
    SHA-256: abfc48c38003149a7f134ab8d6e8b53ef7a0043f5b2f92816f7419e3196e786e
    Size: 69.43 kB
  12. crit-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 52623c74dde72e63c29a6618314adc76
    SHA-256: 6bee507a027bd8ae8f96bc40745673f95a7339d879d82e44de140371ee9a3280
    Size: 22.10 kB
  13. criu-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 7930a9b85241731e00f41c6b273b25e6
    SHA-256: a0879ff1cbfaec8e709dd903da9bd26b2444e29f48b9b0161872473aa1c4d81c
    Size: 563.13 kB
  14. criu-debugsource-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 0115d03cca564128c27f2ce8b5da3ae4
    SHA-256: 541b8a37f7aa4ea64b508ddd694dcfb23e7d80d17d815524aa5be6114b3de41c
    Size: 729.80 kB
  15. criu-devel-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: f6b9bc2854c7d88144ab47dd2a7ff166
    SHA-256: f9f0c9b9e9b4d68e014babda9f90f8ceb24d63ac59f9b034f4e243d15112d7e4
    Size: 28.23 kB
  16. criu-libs-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: 884f68ab3c5f23877cf87c50f3478f41
    SHA-256: da9bc41b428ababdd81d52f788cdb9d9ab5b4f73dc49462be5e7128a8543dd5f
    Size: 38.16 kB
  17. crun-1.14.3-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: 9e1e6f4bc17cb474d8ecec6c4252934a
    SHA-256: a0890634a16997e20304885543a375b57825337a3344b1d2d11926d3fd11132c
    Size: 256.58 kB
  18. crun-debugsource-1.14.3-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: 82aae89e84d9f0b294a23c16283c51d6
    SHA-256: 095f1925db5a5fb55bbc3d76afef790e4b1fd49ebc495040f034462e8f98988b
    Size: 204.13 kB
  19. fuse-overlayfs-1.13-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 29570afea843f66d5e12897520d9403c
    SHA-256: 65430db284b119067de95df9630d4ea6b4cc129f672083aa2eee480f1ba4686e
    Size: 68.74 kB
  20. fuse-overlayfs-debugsource-1.13-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 9615e88e2ce1e8dd76f35c1a084a92b1
    SHA-256: 2af6fd121062063eb0ee1bb60b0a5d3f2abdc3663f058f4685d5a017f7e1ebe2
    Size: 55.61 kB
  21. libslirp-4.4.0-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: a7147784ee1c342b9912df11fb310511
    SHA-256: 236abf484d18083b44537121d4d828004ab10281f4c3c2eaaf6f340fcf780206
    Size: 69.28 kB
  22. libslirp-debugsource-4.4.0-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: c7ee43d936f4bc5c1dcdcb8afeeac48d
    SHA-256: 97ec78ecb3d1dd43ea949a3525adb8ca9927a92dc9e608d97035aef0799ec183
    Size: 114.54 kB
  23. libslirp-devel-4.4.0-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: 823170910163787043754c462b8779c9
    SHA-256: fa52ef1b62b07420c0e15a213006dc8283f89422038966ff92ac6cb4f2968b34
    Size: 11.41 kB
  24. netavark-1.10.3-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: ad7969ec2f82f6f83574a449382fd40d
    SHA-256: fc24da0aec8702583635f1eeb8d03fbe200d0a87bd74fe9cec06eeaa8b3cb190
    Size: 4.11 MB
  25. oci-seccomp-bpf-hook-1.2.10-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: e18a637ab0ae534cbf889eb71395698a
    SHA-256: b68447044ec3295f78b45e61276c0d01e0b9970269c4e6e224d8fb2d3610137d
    Size: 1.13 MB
  26. oci-seccomp-bpf-hook-debugsource-1.2.10-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 79dec6ea4c7159b18954cb5d8cd4b806
    SHA-256: fa9ef955db5e76e91db30865d66efc29909466ecd4384dcd2f75f029f18c4585
    Size: 247.94 kB
  27. podman-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: fc574ce8c9b9e18cc80a8f9cd33d899f
    SHA-256: 1dd3149d5d74eb1051a7e295c08a05f0a83b72a46b254e558381705097c285c2
    Size: 16.07 MB
  28. podman-catatonit-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: d17be829cc3e76716d179784acff488a
    SHA-256: 797db5baf4b64cea8682426c22081f40ae3e3d610115c1fb3ec30e57459afbcc
    Size: 372.56 kB
  29. podman-debugsource-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: 056f2e27d4d61afc7a61eff361bcfea7
    SHA-256: 6e6517feca7d08ef39a6a6e0f7cccc47f43aebad663727ef91be1b105ca3cd28
    Size: 9.33 MB
  30. podman-docker-4.9.4-12.module+el8+1796+203facf7.noarch.rpm
    MD5: 81e5aa045620a8fcb79ff5e52bf1b9a8
    SHA-256: dc587c4365c7d5a9437f94417da84c0c51200515b648ce02d6e493eae0ecdbe2
    Size: 113.75 kB
  31. podman-gvproxy-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: 93bccf18fd32334f4adc25f5e0b85e1e
    SHA-256: 4b749fa36b47548239ce68d66ea6d92c60b99162e2e04d3b1328e14fab01df02
    Size: 3.86 MB
  32. podman-plugins-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: 3df4eaf8371cce847d352c683a34f44c
    SHA-256: 84921958b2ada532f9e05d3916d392cc59c419b81f7d94c77eaa40e0dc4c44d5
    Size: 1.33 MB
  33. podman-remote-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: a93824d10edf3a7c208f3a8445966a14
    SHA-256: 654b4f0cbcced456363a34350cbe339df51a1622b32fc50576193609fe721f26
    Size: 10.48 MB
  34. podman-tests-4.9.4-12.module+el8+1796+203facf7.x86_64.rpm
    MD5: 263ae0b456c60f4c624bf15ecefe72d4
    SHA-256: afe658af9a3684ab97313c97e80b73dfdded8ad1656ef12573b97fe557816f37
    Size: 265.14 kB
  35. python3-criu-3.18-5.module+el8+1796+203facf7.x86_64.rpm
    MD5: d15a98a7e0c329f145b57da7d9463014
    SHA-256: 4475cba94ec579c444ec2c9046d63ba708116a5637e442b8a793b3f8884be29a
    Size: 177.27 kB
  36. python3-podman-4.9.0-2.module+el8+1796+203facf7.noarch.rpm
    MD5: 6cd52d8bb1d61afd7e2a8d45a0f39ef0
    SHA-256: ffc57628ecb65458f6fe66fc496453eee5fd14955c5de0921b7b13c035300764
    Size: 155.29 kB
  37. runc-1.1.12-4.module+el8+1796+203facf7.x86_64.rpm
    MD5: d6e759547d2fffeeeca1cd655864d194
    SHA-256: d7277661ebfc3f17a1aadd705ed383c1388b0a18086be00cb5f72c7a7128194c
    Size: 3.14 MB
  38. runc-debugsource-1.1.12-4.module+el8+1796+203facf7.x86_64.rpm
    MD5: ded4bb28306bb853c30c246c5f7f9057
    SHA-256: 4a778646d46df41acff48f6ef290adbbca849b41fae7970e92acadd458949c29
    Size: 893.83 kB
  39. skopeo-1.14.5-3.module+el8+1796+203facf7.x86_64.rpm
    MD5: 1d490ca7c8142ce34ec718e3e9bc8d94
    SHA-256: 077b1421b4b54d3196697c276e5f945d6610ad83821f732e5eba32af50d58ba6
    Size: 8.82 MB
  40. skopeo-tests-1.14.5-3.module+el8+1796+203facf7.x86_64.rpm
    MD5: e81d69705867b334fd9a2d146b4fdd7a
    SHA-256: e8c573dd9774239627a902ceb48fa7edadfe552004c91129a4a31e4a8669419a
    Size: 785.40 kB
  41. slirp4netns-1.2.3-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: 4b1e7489d5c46d8012226763f82798c4
    SHA-256: d3a80a5bd2755533915e66f8578a9a817af978b5cd347000e4afc71b047b8080
    Size: 54.91 kB
  42. slirp4netns-debugsource-1.2.3-1.module+el8+1796+203facf7.x86_64.rpm
    MD5: d7352e59e8277a93ff6852ec66b0d3dc
    SHA-256: 0d86c1842f43034b6a155c738728f87458f459e998505a037b226a082913951d
    Size: 43.73 kB
  43. toolbox-0.0.99.5-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: c0e05970ec308b88c1544ad2a2fcdbd1
    SHA-256: defc0883081cf10e38a588645767c54c4c7549fe0ab88f32e0113d40fd918c1a
    Size: 2.52 MB
  44. toolbox-debugsource-0.0.99.5-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: 042bf865b0ae13c16c5c12cdbb43c48d
    SHA-256: 66d944b8d7a4c7633efd778d610d60e77acb3293d14a0898d112fda7c2df6c78
    Size: 571.82 kB
  45. toolbox-tests-0.0.99.5-2.module+el8+1796+203facf7.x86_64.rpm
    MD5: 5c267fe2a30d0ca96788d121812867d2
    SHA-256: dc1eb0108ad68ca96a86188c600ff2479e920eb723734c9379b8bd00741bb23d
    Size: 43.69 kB
  46. udica-0.2.6-21.module+el8+1796+203facf7.noarch.rpm
    MD5: 1a7fbee222eba533da47a57940100c63
    SHA-256: 3185115c3046997c9c936012c5bd7baef5f055e7b046440c92e3ac26a2a67e88
    Size: 48.26 kB