RedHat: RHSA-2021-1796:01 Moderate: container-tools:rhel8 security, bug fix,
Summary
The container-tools module contains tools for working with containers,
notably podman, buildah, skopeo, and runc.
Security Fix(es):
* golang: crypto/ssh: crafted authentication request can lead to nil
pointer dereference (CVE-2020-29652)
* podman: Remote traffic to rootless containers is seen as orginating from
localhost (CVE-2021-20199)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.
Summary
Solution
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
References
https://access.redhat.com/security/cve/CVE-2020-29652 https://access.redhat.com/security/cve/CVE-2021-20199 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/
Package List
Red Hat Enterprise Linux AppStream (v. 8):
Source:
buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.src.rpm
cockpit-podman-29-2.module+el8.4.0+10607+f4da7515.src.rpm
conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.src.rpm
container-selinux-2.158.0-1.module+el8.4.0+10607+f4da7515.src.rpm
containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.src.rpm
criu-3.15-1.module+el8.4.0+10607+f4da7515.src.rpm
crun-0.18-1.module+el8.4.0+10607+f4da7515.src.rpm
fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.src.rpm
libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.src.rpm
oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.src.rpm
podman-3.0.1-6.module+el8.4.0+10607+f4da7515.src.rpm
runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.src.rpm
skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.src.rpm
slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.src.rpm
toolbox-0.0.8-1.module+el8.4.0+10607+f4da7515.src.rpm
udica-0.2.4-1.module+el8.4.0+10607+f4da7515.src.rpm
aarch64:
buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
buildah-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
buildah-debugsource-1.19.7-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
buildah-tests-1.19.7-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
buildah-tests-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
conmon-debuginfo-2.0.26-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
conmon-debugsource-2.0.26-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
containernetworking-plugins-debuginfo-0.9.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
containernetworking-plugins-debugsource-0.9.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
containers-common-1.2.2-8.module+el8.4.0+10607+f4da7515.aarch64.rpm
crit-3.15-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
criu-3.15-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
criu-debuginfo-3.15-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
criu-debugsource-3.15-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
crun-0.18-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
crun-debuginfo-0.18-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
crun-debugsource-0.18-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
fuse-overlayfs-debuginfo-1.4.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
fuse-overlayfs-debugsource-1.4.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
libslirp-debuginfo-4.3.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
libslirp-debugsource-4.3.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
libslirp-devel-4.3.1-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
oci-seccomp-bpf-hook-debuginfo-1.2.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
oci-seccomp-bpf-hook-debugsource-1.2.0-2.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-catatonit-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-catatonit-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-debugsource-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-plugins-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-plugins-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-remote-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-remote-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
podman-tests-3.0.1-6.module+el8.4.0+10607+f4da7515.aarch64.rpm
python3-criu-3.15-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.aarch64.rpm
runc-debuginfo-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.aarch64.rpm
runc-debugsource-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.aarch64.rpm
skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.aarch64.rpm
skopeo-debuginfo-1.2.2-8.module+el8.4.0+10607+f4da7515.aarch64.rpm
skopeo-debugsource-1.2.2-8.module+el8.4.0+10607+f4da7515.aarch64.rpm
skopeo-tests-1.2.2-8.module+el8.4.0+10607+f4da7515.aarch64.rpm
slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
slirp4netns-debuginfo-1.1.8-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
slirp4netns-debugsource-1.1.8-1.module+el8.4.0+10607+f4da7515.aarch64.rpm
noarch:
cockpit-podman-29-2.module+el8.4.0+10607+f4da7515.noarch.rpm
container-selinux-2.158.0-1.module+el8.4.0+10607+f4da7515.noarch.rpm
podman-docker-3.0.1-6.module+el8.4.0+10607+f4da7515.noarch.rpm
toolbox-0.0.8-1.module+el8.4.0+10607+f4da7515.noarch.rpm
udica-0.2.4-1.module+el8.4.0+10607+f4da7515.noarch.rpm
ppc64le:
buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
buildah-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
buildah-debugsource-1.19.7-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
buildah-tests-1.19.7-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
buildah-tests-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
conmon-debuginfo-2.0.26-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
conmon-debugsource-2.0.26-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
containernetworking-plugins-debuginfo-0.9.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
containernetworking-plugins-debugsource-0.9.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
containers-common-1.2.2-8.module+el8.4.0+10607+f4da7515.ppc64le.rpm
crit-3.15-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
criu-3.15-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
criu-debuginfo-3.15-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
criu-debugsource-3.15-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
crun-0.18-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
crun-debuginfo-0.18-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
crun-debugsource-0.18-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
fuse-overlayfs-debuginfo-1.4.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
fuse-overlayfs-debugsource-1.4.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
libslirp-debuginfo-4.3.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
libslirp-debugsource-4.3.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
libslirp-devel-4.3.1-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
oci-seccomp-bpf-hook-debuginfo-1.2.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
oci-seccomp-bpf-hook-debugsource-1.2.0-2.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-catatonit-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-catatonit-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-debugsource-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-plugins-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-plugins-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-remote-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-remote-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
podman-tests-3.0.1-6.module+el8.4.0+10607+f4da7515.ppc64le.rpm
python3-criu-3.15-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.ppc64le.rpm
runc-debuginfo-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.ppc64le.rpm
runc-debugsource-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.ppc64le.rpm
skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.ppc64le.rpm
skopeo-debuginfo-1.2.2-8.module+el8.4.0+10607+f4da7515.ppc64le.rpm
skopeo-debugsource-1.2.2-8.module+el8.4.0+10607+f4da7515.ppc64le.rpm
skopeo-tests-1.2.2-8.module+el8.4.0+10607+f4da7515.ppc64le.rpm
slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
slirp4netns-debuginfo-1.1.8-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
slirp4netns-debugsource-1.1.8-1.module+el8.4.0+10607+f4da7515.ppc64le.rpm
s390x:
buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.s390x.rpm
buildah-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.s390x.rpm
buildah-debugsource-1.19.7-1.module+el8.4.0+10607+f4da7515.s390x.rpm
buildah-tests-1.19.7-1.module+el8.4.0+10607+f4da7515.s390x.rpm
buildah-tests-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.s390x.rpm
conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.s390x.rpm
conmon-debuginfo-2.0.26-1.module+el8.4.0+10607+f4da7515.s390x.rpm
conmon-debugsource-2.0.26-1.module+el8.4.0+10607+f4da7515.s390x.rpm
containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
containernetworking-plugins-debuginfo-0.9.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
containernetworking-plugins-debugsource-0.9.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
containers-common-1.2.2-8.module+el8.4.0+10607+f4da7515.s390x.rpm
crit-3.15-1.module+el8.4.0+10607+f4da7515.s390x.rpm
criu-3.15-1.module+el8.4.0+10607+f4da7515.s390x.rpm
criu-debuginfo-3.15-1.module+el8.4.0+10607+f4da7515.s390x.rpm
criu-debugsource-3.15-1.module+el8.4.0+10607+f4da7515.s390x.rpm
crun-0.18-1.module+el8.4.0+10607+f4da7515.s390x.rpm
crun-debuginfo-0.18-1.module+el8.4.0+10607+f4da7515.s390x.rpm
crun-debugsource-0.18-1.module+el8.4.0+10607+f4da7515.s390x.rpm
fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
fuse-overlayfs-debuginfo-1.4.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
fuse-overlayfs-debugsource-1.4.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
libslirp-debuginfo-4.3.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
libslirp-debugsource-4.3.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
libslirp-devel-4.3.1-1.module+el8.4.0+10607+f4da7515.s390x.rpm
oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
oci-seccomp-bpf-hook-debuginfo-1.2.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
oci-seccomp-bpf-hook-debugsource-1.2.0-2.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-catatonit-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-catatonit-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-debugsource-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-plugins-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-plugins-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-remote-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-remote-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
podman-tests-3.0.1-6.module+el8.4.0+10607+f4da7515.s390x.rpm
python3-criu-3.15-1.module+el8.4.0+10607+f4da7515.s390x.rpm
runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.s390x.rpm
runc-debuginfo-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.s390x.rpm
runc-debugsource-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.s390x.rpm
skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.s390x.rpm
skopeo-debuginfo-1.2.2-8.module+el8.4.0+10607+f4da7515.s390x.rpm
skopeo-debugsource-1.2.2-8.module+el8.4.0+10607+f4da7515.s390x.rpm
skopeo-tests-1.2.2-8.module+el8.4.0+10607+f4da7515.s390x.rpm
slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.s390x.rpm
slirp4netns-debuginfo-1.1.8-1.module+el8.4.0+10607+f4da7515.s390x.rpm
slirp4netns-debugsource-1.1.8-1.module+el8.4.0+10607+f4da7515.s390x.rpm
x86_64:
buildah-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
buildah-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
buildah-debugsource-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
buildah-tests-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
buildah-tests-debuginfo-1.19.7-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
conmon-2.0.26-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
conmon-debuginfo-2.0.26-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
conmon-debugsource-2.0.26-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
containernetworking-plugins-0.9.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
containernetworking-plugins-debuginfo-0.9.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
containernetworking-plugins-debugsource-0.9.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
containers-common-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm
crit-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
criu-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
criu-debuginfo-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
criu-debugsource-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
crun-0.18-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
crun-debuginfo-0.18-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
crun-debugsource-0.18-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
fuse-overlayfs-1.4.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
fuse-overlayfs-debuginfo-1.4.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
fuse-overlayfs-debugsource-1.4.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
libslirp-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
libslirp-debuginfo-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
libslirp-debugsource-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
libslirp-devel-4.3.1-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
oci-seccomp-bpf-hook-1.2.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
oci-seccomp-bpf-hook-debuginfo-1.2.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
oci-seccomp-bpf-hook-debugsource-1.2.0-2.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-catatonit-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-catatonit-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-debugsource-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-plugins-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-plugins-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-remote-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-remote-debuginfo-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
podman-tests-3.0.1-6.module+el8.4.0+10607+f4da7515.x86_64.rpm
python3-criu-3.15-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
runc-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.x86_64.rpm
runc-debuginfo-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.x86_64.rpm
runc-debugsource-1.0.0-70.rc92.module+el8.4.0+10607+f4da7515.x86_64.rpm
skopeo-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm
skopeo-debuginfo-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm
skopeo-debugsource-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm
skopeo-tests-1.2.2-8.module+el8.4.0+10607+f4da7515.x86_64.rpm
slirp4netns-1.1.8-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
slirp4netns-debuginfo-1.1.8-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
slirp4netns-debugsource-1.1.8-1.module+el8.4.0+10607+f4da7515.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
Topic
An update for the container-tools:rhel8 module is now available for Red HatEnterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
Bugs Fixed
1707078 - Image signature only has one docker registry reference, would like the ability to have two hostnames sign them.
1724946 - Can not verify signed image signature in OCP 4
1726442 - SIGTERM from systemd to containers|conmon on shutdown causes unexpected results
1763007 - --log-opt for podman run does not work as expected
1770037 - (podman sign) does not handle multi-arch images
1798278 - subscription-manager recommends drags in too much into RHCOS
1811773 - [RFE] cockpit-podman ability to set selinux contexts for volumes
1838233 - address coverity warnings
1841485 - podman exec is fragile in the presence of signals
1844199 - [RFE] Add remapIdentity suggestion to simplify policy configuration
1853455 - podman ignores infra_command option from containers.conf
1860176 - OCI Runtime kata-runtime is in use by a container, but is not available
1867892 - running containerized buildah leads to error
1881894 - podman-remote: dial unix ///run/podman/podman.sock: connect: no such file or directory
1897282 - podman-wait requiring units for interval when it is documented as optional
1897594 - update description and summary for container-tools module for 8.3.0
1902979 - podman run fails to update /etc/hosts when --uidmap is provided
1903813 - [RFE] Ship preconfigured /etc/containers/registries.d/ files with containers-common
1904549 - POST to /networks/create with docker compatible API results in panic
1908883 - CVE-2020-29652 golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference
1915383 - Podman "--format" does not support "join"
1918554 - error bind mounting /dev from host into mount namespace: mkdir /var/tmp/buildah396339746/mnt/rootfs/dev: operation not permitted
1919050 - CVE-2021-20199 podman: Remote traffic to rootless containers is seen as orginating from localhost
1921128 - [gss][podman]Getting the error while starting container "Error: readlink /var/lib/containers/storage/overlay/l/XXX no such file or directory"
1923986 - podman: Installation instructions for rootless podman do not work
1924146 - RFE Bind mounting host volume using Podman REST API
1931545 - podman 3.0.1 ships with a v2 go module
1931785 - shortname for ubi8-minimal leads to "Repo not found" error
1932083 - Podman will pull image for rootless CNI
1935376 - Regression: Overlay mounts is broken on existing directories.
1935922 - Unable to run multi-stage builds with rootless buildah container
1936927 - regressions cp command in Podman v3.0
1937487 - Podman socket failing to connect with long uid
1938234 - Variety of errors during rootless container image creation