Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 40 Podman: 2024-a267e93f8c Critical Container Security Fix

fedora
Calendar Grey March 27, 2024
Dist Fedora Esm H88
Patch release for podman resolving severe CVE-2024-1753 vulnerability now available in the latest Fedora 40 update.
Security fix for CVE-2024-1753 Automatic update for podman-5.0.0-1.fc40

Summary

podman (Pod Manager) is a fully featured container engine that is a simple

daemonless tool. podman provides a Docker-CLI comparable command line that

eases the transition from other container engines and allows the management of

pods, containers and images. Simply put: alias docker=podman.

Most podman commands can be run as a regular user, without requiring

additional privileges.

podman uses Buildah(1) internally to create container images.

Both tools share image (not container) storage, hence each can use or

manipulate images (but not containers) created by the other.

Manage Pods, Containers and Container Images

%{repo} Simple management tool for pods, containers and images

Update Information:

Security fix for CVE-2024-1753 Automatic update for podman-5.0.0-1.fc40. Changelog for podman * Tue Mar 19 2024 Packit - 5:5.0.0-1 - [packit] 5.0.0 upstream release * Fri Mar 15 2024 Packit - 5:5.0.0~rc7-1 - [packit] 5.0.0-rc7 upstream release * Wed Mar 13 2024 Lokesh Mandvekar - 5:5.0.0~rc6-2 - Resolves: #2269148 - make passt a hard dep * Mon Mar 11 2024 Packit - 5:5.0.0~rc6-1 - [packit] 5.0.0-rc6 upstream release * Fri Mar 08 2024 Packit - 5:5.0.0~rc5-1 - [packit] 5.0.0-rc5 upstream release * Tue Mar 05 2024 Packit - 5:5.0.0~rc4-1 - [packit] 5.0.0-rc4 upstream release * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-5 - Show the toolbox RPMs used to run the tests * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-4 - Avoid running out of storage space when running the Toolbx tests * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-3 - Silence warnings about deprecated grep(1) use in test logs * Fri Mar 01 2024 Debarshi Ray - 5:5.0.0~rc3-2 - Update how Toolbx is spe...

Change Log

* Tue Mar 19 2024 Packit - 5:5.0.0-1 - [packit] 5.0.0 upstream release * Fri Mar 15 2024 Packit - 5:5.0.0~rc7-1 - [packit] 5.0.0-rc7 upstream release * Wed Mar 13 2024 Lokesh Mandvekar - 5:5.0.0~rc6-2 - Resolves: #2269148 - make passt a hard dep * Mon Mar 11 2024 Packit - 5:5.0.0~rc6-1 - [packit] 5.0.0-rc6 upstream release * Fri Mar 8 2024 Packit - 5:5.0.0~rc5-1 - [packit] 5.0.0-rc5 upstream release * Tue Mar 5 2024 Packit - 5:5.0.0~rc4-1 - [packit] 5.0.0-rc4 upstream release * Fri Mar 1 2024 Debarshi Ray - 5:5.0.0~rc3-5 - Show the toolbox RPMs used to run the tests * Fri Mar 1 2024 Debarshi Ray - 5:5.0.0~rc3-4 - Avoid running out of storage space when running the Toolbx tests * Fri Mar 1 2024 Debarshi Ray - 5:5.0.0~rc3-3 - Silence warnings about deprecated grep(1) use in test logs * Fri Mar 1 2024 Debarshi Ray - 5:5.0.0~rc3-2 - Update how Toolbx is spelt * Thu Feb 22 2024 Packit - 5:5.0.0~rc3-1 - [packit] 5.0.0-rc3 upstream release

References


[ 1 ] Bug #2265513 - CVE-2024-1753 buildah: full container escape at build time https://bugzilla.redhat.com/show_bug.cgi?id=2265513

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a267e93f8c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: podman
Product: Fedora 40
Version: 5.0.0
Release: 1.fc40
Summary: Manage Pods, Containers and Container Images

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here