Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Oracle Linux 9 ELSA-2024-6194 Critical: Podman Remote Code Execution

oracle
Calendar Grey September 4, 2024
Oracle Linux Logo Esm H88
The Oracle Security Bulletin ELSA-2024-6194 highlights crucial podman modifications along with related corrections aimed at addressing security vulnerabilities.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[4.9.4-10.0.1] - Fixes issue of podman execvp error while using podmansh [Orabug: 36073625] - Improved saving remote build context to tarfile in Podman daemon [Orabug: 36495655] - Add devices on container startup, not on creation - Backport fast gzip for compression [Orabug: 36420418] - overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694] - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404] [4:4.9.4-10] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/6b45bb1) - Resolves: RHEL-53250 [4:4.9.4-9] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/1a2d8e3) - Resolves: RHEL-50507 [4:4.9.4-8] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/affa589) - Resolves: RHEL-45916 [4:4.9.4-7] - update to t...

Read the Full Advisory

SRPMs

https://oss.oracle.com:443/ol9/SRPMS-updates//podman-4.9.4-10.0.1.el9_4.src.rpm

x86_64

podman-4.9.4-10.0.1.el9_4.x86_64.rpm podman-docker-4.9.4-10.0.1.el9_4.noarch.rpm podman-plugins-4.9.4-10.0.1.el9_4.x86_64.rpm podman-remote-4.9.4-10.0.1.el9_4.x86_64.rpm podman-tests-4.9.4-10.0.1.el9_4.x86_64.rpm

aarch64

podman-4.9.4-10.0.1.el9_4.aarch64.rpm podman-docker-4.9.4-10.0.1.el9_4.noarch.rpm podman-plugins-4.9.4-10.0.1.el9_4.aarch64.rpm podman-remote-4.9.4-10.0.1.el9_4.aarch64.rpm podman-tests-4.9.4-10.0.1.el9_4.aarch64.rpm

Severity
critical
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2024-6104 CVE-2024-24783 CVE-2024-37298

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here