Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Fedora 35: 2022-396c568c5e Moderate: Buildah DoS Threat Mitigation

fedora
Calendar Grey June 10, 2022
Dist Fedora Esm H88
Fedora Package Update Alert highlights improvements in podman concerning vulnerability fixes and introduces new networking features for container orchestration.
bump to v1.23.4, security fix for CVE-2022-21698 ---- Add missing container networking dependencies (#2081834)

Summary

The buildah package provides a command line tool which can be used to

* create a working container from scratch

or

* create a working container from an image as a starting point

* mount/umount a working container's root file system for manipulation

* save container's root file system layer to create a new image

* delete a working container or an image

bump to v1.23.4, security fix for CVE-2022-21698 ---- Add missing container

networking dependencies (#2081834)

* Thu Jun 2 2022 Lokesh Mandvekar 1.23.4-1

- bump to v.123.4

* Wed May 4 2022 Neal Gompa 1.23.3-3

- Add missing container networking dependencies (#2081834)

[ 1 ] Bug #2067422 - CVE-2022-21698 buildah: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-35]

https://bugzilla.redhat.com/show_bug.cgi?id=2067422

[ 2 ] Bug #2081834 - networking is broken when building containers due to missing container networking package dependencies

https://bugzilla.redhat.com/show_bug.cgi?id=2081834

su -c 'dnf upgrade --advisory FEDORA-2022-396c568c5e' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 35
Version: 1.23.4
Release: 1.fc35
Summary: A command line tool used for creating OCI Images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here