-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: podman security, bug fix, and enhancement update Advisory ID: RHSA-2019:1907-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2019:1907 Issue date: 2019-07-29 CVE Names: CVE-2019-10152 ==================================================================== 1. Summary: An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. The following packages have been upgraded to a later upstream version: podman (1.4.4). (BZ#1717919) Security Fix(es): * podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers (CVE-2019-10152) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Error: pod was given but no pod is specified: invalid argument (BZ#1727873) * Podman stats failed with Error: unable to obtain cgroup stats (BZ#1728242) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1715667 - CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers1717919 - rebase to v1.4.4 1727873 - Error: pod was given but no pod is specified: invalid argument 1728242 - Podman stats failed with Error: unable to obtain cgroup stats 6. Package List: Red Hat Enterprise Linux 7 Extras: Source: podman-1.4.4-2.el7.src.rpm aarch64: podman-1.4.4-2.el7.aarch64.rpm podman-debuginfo-1.4.4-2.el7.aarch64.rpm noarch: podman-docker-1.4.4-2.el7.noarch.rpm ppc64le: podman-1.4.4-2.el7.ppc64le.rpm podman-debuginfo-1.4.4-2.el7.ppc64le.rpm s390x: podman-1.4.4-2.el7.s390x.rpm podman-debuginfo-1.4.4-2.el7.s390x.rpm x86_64: podman-1.4.4-2.el7.x86_64.rpm podman-debuginfo-1.4.4-2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-10152 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXT8cPtzjgjWX9erEAQjL9g//VUvLwFnVZOZczqa63vN2/JTrPd6Hn5xB 7vPWONkxgZqXpq9hvL6Dc0qBqJBv8vqATxlSotlI8wus5xlNqp4qr1WtShlej+Pr GLAbftCPah5jYdSpfNBnpQpKnqkeLwwbVF2cAZWOeb9wmTSJzEm6/kxJy5kf0mGA gQ0SuAXB8cVGXoidEiNBJ74AXLVsJMccvOlZ+5YcKPRBksiemVqvezMoInsbOBpU gyXdct4xCHC2x0T2wjKJ0yMPuGGBNHAs9xLSyINkxAMLtY5Eg+eCyUxiDBnPL7Tx r2FMoupH6J0goblLj5RUMkkWHNLhKJhJUT6D0SLzJVXEOtJGJQC45M0UAmBskLUq l8anAWG5Vkk3vEUvJBw+1/rCvzBLHXB0p7DwAtwtrCaTimqEn8OIIFTfbTRxW0Ud ilQG0+FoKlpA1RNMnFCnPITh/LqS92vhzll+G+tZnvch13wqJiM6BQq5l9uuFSgc T+wk3sdaOLNYyqIuQwRTQll5gppwmCG+0tOqkXpeP1+48GDOXr4XgScZUWKM0qmH jPw3BJOrUqFBYPR7cWLX00nEO/kkFZNThUB+6hjAS566a+45ayYE6s51w8gXCjsQ m1QuvfjcfeQd1ostJwzLOqQCMFZ6t59PiwZpexWoneRiUjrPgBMCfClPrb6/STHP gcXvoQYp09A=brFW -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The podman tool manages pods, container images, and containers. It is part
of the libpod library, which is for applications that use container pods.
Container pods is a concept in Kubernetes.
The following packages have been upgraded to a later upstream version:
podman (1.4.4). (BZ#1717919)
Security Fix(es):
* podman: Improper symlink resolution allows access to host files when
executing `podman cp` on running containers (CVE-2019-10152)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* Error: pod was given but no pod is specified: invalid argument
(BZ#1727873)
* Podman stats failed with Error: unable to obtain cgroup stats
(BZ#1728242)
https://access.redhat.com/security/cve/CVE-2019-10152 https://access.redhat.com/security/updates/classification/#moderate
Red Hat Enterprise Linux 7 Extras:
Source:
podman-1.4.4-2.el7.src.rpm
aarch64:
podman-1.4.4-2.el7.aarch64.rpm
podman-debuginfo-1.4.4-2.el7.aarch64.rpm
noarch:
podman-docker-1.4.4-2.el7.noarch.rpm
ppc64le:
podman-1.4.4-2.el7.ppc64le.rpm
podman-debuginfo-1.4.4-2.el7.ppc64le.rpm
s390x:
podman-1.4.4-2.el7.s390x.rpm
podman-debuginfo-1.4.4-2.el7.s390x.rpm
x86_64:
podman-1.4.4-2.el7.x86_64.rpm
podman-debuginfo-1.4.4-2.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
An update for podman is now available for Red Hat Enterprise Linux 7Extras.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux 7 Extras - aarch64, noarch, ppc64le, s390x, x86_64
1715667 - CVE-2019-10152 podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers1717919 - rebase to v1.4.4
1727873 - Error: pod was given but no pod is specified: invalid argument
1728242 - Podman stats failed with Error: unable to obtain cgroup stats
Get the latest Linux and open source security news straight to your inbox.