Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 40: Security Fix For Netavark and Podman - CVE-2024-1753

fedora
Calendar Grey March 27, 2024
Dist Fedora Esm H88
Patch release and system update for Fedora's netavark and podman software mitigating CVE-2024-1753 vulnerability.
Security fix for CVE-2024-1753 Automatic update for podman-5.0.0-1.fc40

Summary

OCI network stack

Netavark is a rust based network stack for containers. It is being

designed to work with Podman but is also applicable for other OCI

container management applications.

Netavark is a tool for configuring networking for Linux containers.

Its features include:

* Configuration of container networks via JSON configuration file

* Creation and management of required network interfaces,

including MACVLAN networks

* All required firewall configuration to perform NAT and port

forwarding as required for containers

* Support for iptables and firewalld at present, with support

for nftables planned in a future release

* Support for rootless containers

* Support for IPv4 and IPv6

* Support for container DNS resolution via aardvark-dns.

Update Information:

Security fix for CVE-2024-1753 Automatic update for podman-5.0.0-1.fc40. Changelog for podman * Tue Mar 19 2024 Packit - 5:5.0.0-1 - [packit] 5.0.0 upstream release * Fri Mar 15 2024 Packit - 5:5.0.0~rc7-1 - [packit] 5.0.0-rc7 upstream release * Wed Mar 13 2024 Lokesh Mandvekar - 5:5.0.0~rc6-2 - Resolves: #2269148 - make passt a hard dep * Mon Mar 11 2024 Packit - 5:5.0.0~rc6-1 - [packit] 5.0.0-rc6 upstream release * Fri Mar 08 2024 Packit - 5:5.0.0~rc5-1 - [packit] 5.0.0-rc5 upstream release * Tue Mar 05 2024 Packit - 5:5.0.0~rc4-1 - [packit] 5.0.0-rc4 upstream release * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-5 - Show the toolbox RPMs used to run the tests * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-4 - Avoid running out of storage space when running the Toolbx tests * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-3 - Silence warnings about deprecated grep(1) use in test logs * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-2 - Update how Toolbx is spe...

Change Log

* Wed Mar 20 2024 Lokesh Mandvekar - 0:1.10.3-3 - rebuild for podman 5 f40 bodhi * Wed Mar 13 2024 Lokesh Mandvekar - 0:1.10.3-2 - make aardvark-dns a hard dep across the board

References


[ 1 ] Bug #2265513 - CVE-2024-1753 buildah: full container escape at build time https://bugzilla.redhat.com/show_bug.cgi?id=2265513

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a267e93f8c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: netavark
Product: Fedora 40
Version: 1.10.3
Release: 3.fc40
Summary: OCI network stack

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here