{"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2024:3826","synopsis":"Moderate: podman security and bug fix update","severity":"SEVERITY_MODERATE","topic":"An update is available for podman.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.\n\nSecurity Fixes:\n\n* podman: jose-go: improper handling of highly compressed data (CVE-2024-28180)\n\n* podman: golang: net\/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)\n\n* podman: jose: resource exhaustion (CVE-2024-28176)","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2268017","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2268017","description":""},{"ticket":"2268820","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2268820","description":""},{"ticket":"2268854","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2268854","description":""}],"cves":[{"name":"CVE-2023-45290","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-45290","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-28176","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-28176","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-28180","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-28180","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-06-14T14:00:40.182624Z","rpms":{"Rocky Linux 9":{"nvras":["podman-4:4.9.4-4.el9_4.aarch64.rpm","podman-4:4.9.4-4.el9_4.ppc64le.rpm","podman-4:4.9.4-4.el9_4.s390x.rpm","podman-4:4.9.4-4.el9_4.src.rpm","podman-4:4.9.4-4.el9_4.x86_64.rpm","podman-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm","podman-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm","podman-debuginfo-4:4.9.4-4.el9_4.s390x.rpm","podman-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm","podman-debugsource-4:4.9.4-4.el9_4.aarch64.rpm","podman-debugsource-4:4.9.4-4.el9_4.ppc64le.rpm","podman-debugsource-4:4.9.4-4.el9_4.s390x.rpm","podman-debugsource-4:4.9.4-4.el9_4.x86_64.rpm","podman-docker-4:4.9.4-4.el9_4.noarch.rpm","podman-plugins-4:4.9.4-4.el9_4.aarch64.rpm","podman-plugins-4:4.9.4-4.el9_4.ppc64le.rpm","podman-plugins-4:4.9.4-4.el9_4.s390x.rpm","podman-plugins-4:4.9.4-4.el9_4.x86_64.rpm","podman-plugins-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm","podman-plugins-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm","podman-plugins-debuginfo-4:4.9.4-4.el9_4.s390x.rpm","podman-plugins-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm","podman-remote-4:4.9.4-4.el9_4.aarch64.rpm","podman-remote-4:4.9.4-4.el9_4.ppc64le.rpm","podman-remote-4:4.9.4-4.el9_4.s390x.rpm","podman-remote-4:4.9.4-4.el9_4.x86_64.rpm","podman-remote-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm","podman-remote-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm","podman-remote-debuginfo-4:4.9.4-4.el9_4.s390x.rpm","podman-remote-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm","podman-tests-4:4.9.4-4.el9_4.aarch64.rpm","podman-tests-4:4.9.4-4.el9_4.ppc64le.rpm","podman-tests-4:4.9.4-4.el9_4.s390x.rpm","podman-tests-4:4.9.4-4.el9_4.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}

Rocky Linux: RLSA-2024:3826 podman security and bug fix update Security Advisories Updates

June 14, 2024
An update is available for podman. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Summary

An update is available for podman. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fixes: * podman: jose-go: improper handling of highly compressed data (CVE-2024-28180) * podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290) * podman: jose: resource exhaustion (CVE-2024-28176)

RPMs

podman-4:4.9.4-4.el9_4.aarch64.rpm

podman-4:4.9.4-4.el9_4.ppc64le.rpm

podman-4:4.9.4-4.el9_4.s390x.rpm

podman-4:4.9.4-4.el9_4.src.rpm

podman-4:4.9.4-4.el9_4.x86_64.rpm

podman-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm

podman-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm

podman-debuginfo-4:4.9.4-4.el9_4.s390x.rpm

podman-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm

podman-debugsource-4:4.9.4-4.el9_4.aarch64.rpm

podman-debugsource-4:4.9.4-4.el9_4.ppc64le.rpm

podman-debugsource-4:4.9.4-4.el9_4.s390x.rpm

podman-debugsource-4:4.9.4-4.el9_4.x86_64.rpm

podman-docker-4:4.9.4-4.el9_4.noarch.rpm

podman-plugins-4:4.9.4-4.el9_4.aarch64.rpm

podman-plugins-4:4.9.4-4.el9_4.ppc64le.rpm

podman-plugins-4:4.9.4-4.el9_4.s390x.rpm

podman-plugins-4:4.9.4-4.el9_4.x86_64.rpm

podman-plugins-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm

podman-plugins-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm

podman-plugins-debuginfo-4:4.9.4-4.el9_4.s390x.rpm

podman-plugins-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm

podman-remote-4:4.9.4-4.el9_4.aarch64.rpm

podman-remote-4:4.9.4-4.el9_4.ppc64le.rpm

podman-remote-4:4.9.4-4.el9_4.s390x.rpm

podman-remote-4:4.9.4-4.el9_4.x86_64.rpm

podman-remote-debuginfo-4:4.9.4-4.el9_4.aarch64.rpm

podman-remote-debuginfo-4:4.9.4-4.el9_4.ppc64le.rpm

podman-remote-debuginfo-4:4.9.4-4.el9_4.s390x.rpm

podman-remote-debuginfo-4:4.9.4-4.el9_4.x86_64.rpm

podman-tests-4:4.9.4-4.el9_4.aarch64.rpm

podman-tests-4:4.9.4-4.el9_4.ppc64le.rpm

podman-tests-4:4.9.4-4.el9_4.s390x.rpm

podman-tests-4:4.9.4-4.el9_4.x86_64.rpm

References

No References

CVEs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45290

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28176

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28180

Severity
Name: RLSA-2024:3826
Affected Products: Rocky Linux 9

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2268017

https://bugzilla.redhat.com/show_bug.cgi?id=2268820

https://bugzilla.redhat.com/show_bug.cgi?id=2268854


Related News