RHSA-2022:7529: Moderate: container-tools:3.0 security update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705) cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708) golang: go/parser: stack exhaustion in all Parse functions (CVE-2022-1962) prometheus/clientgolang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131) golang: io/fs: stack exhaustion in Glob (CVE-2022-30630) golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631) golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632) golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633) golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 29-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.189.0-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.4-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.9-6.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.0.26-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 0.9.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 0.18-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.4.0-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.3.1-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-3.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 3.0.1-13.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-73.rc95.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.2.4-2.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.8-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-1.module+el8.7.0+16212+65e1b35f.aa - Upgrade
Upgrade
cri-oto a version that resolves this vulnerability.Patch CVE-2022-1708 - Upgrade
Upgrade
golang compress/gzipto a version that resolves this vulnerability.Patch CVE-2022-30631 - Upgrade
Upgrade
golang encoding/xmlto a version that resolves this vulnerability.Patch CVE-2022-28131 - Upgrade
Upgrade
golang encoding/xmlto a version that resolves this vulnerability.Patch CVE-2022-30633 - Upgrade
Upgrade
golang go/parserto a version that resolves this vulnerability.Patch CVE-2022-1962 - Upgrade
Upgrade
golang io/fsto a version that resolves this vulnerability.Patch CVE-2022-30630 - Upgrade
Upgrade
golang net/http/httputilto a version that resolves this vulnerability.Patch CVE-2022-32148 - Upgrade
Upgrade
golang path/filepathto a version that resolves this vulnerability.Patch CVE-2022-30632 - Upgrade
Upgrade
prometheus/client_golangto a version that resolves this vulnerability.Patch CVE-2022-21698 - Upgrade
Upgrade
container-toolsto a version that resolves this vulnerability.Fixed in 3.0 - Upgrade
Upgrade
golang net/httpto a version that resolves this vulnerability.Patch CVE-2022-1705
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7529?
The severity of RHSA-2022:7529 is classified as important.
How do I fix RHSA-2022:7529?
To fix RHSA-2022:7529, update the affected packages to the recommended versions as specified in the advisory.
What packages are affected by RHSA-2022:7529?
RHSA-2022:7529 affects multiple packages, including podman, buildah, and skopeo among others.
Is there a workaround for RHSA-2022:7529?
There are no officially documented workarounds for RHSA-2022:7529; applying the updates is recommended.
What vulnerabilities are addressed in RHSA-2022:7529?
RHSA-2022:7529 addresses vulnerabilities such as CVE-2022-1705 related to improper sanitization of Transfer-Encoding headers.