Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 35: FEDORA-2022-a7d438b30b Moderate: Stargz-Snapshotter DoS

fedora
Calendar Grey April 14, 2022
Dist Fedora Esm H88
The newly launched stargz-snapshotter for Fedora 35 enhances fast container image distribution and effectively mitigates security issues related to CVE-2022-21698.
Security fix for CVE-2022-21698

Summary

Fast container image distribution plugin with lazy pulling

Security fix for CVE-2022-21698

* Tue Apr 5 2022 Lokesh Mandvekar 0.10.2-1

- fix bundled provides

* Tue Apr 5 2022 Lokesh Mandvekar None-1

- Resolves: #2045880, #2067450 - Security fix for CVE-2022-21698

* Thu Mar 24 2022 Lokesh Mandvekar 0.11.3-2

- Resolves: #2045880, #2067450 - Security fix for CVE-2022-21698

* Thu Mar 24 2022 Lokesh Mandvekar 0.11.3-1

- bump to v0.11.3

* Sat Jan 22 2022 Fedora Release Engineering 0.10.1-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild

[ 1 ] Bug #2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter

https://bugzilla.redhat.com/show_bug.cgi?id=2045880

su -c 'dnf upgrade --advisory FEDORA-2022-a7d438b30b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 35
Version: 0.10.2
Release: 1.fc35
Summary: Fast container image distribution plugin with lazy pulling

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here