ELBA-2023-3830

ELBA-2023-3830 - container-tools:ol8 bug fix and enhancement update

Type:BUG
Severity:NA
Release Date:2023-07-28

Description


aardvark-dns
buildah
[1:1.29.1-2]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.29
(https://github.com/containers/buildah/commit/f07d2c9)
- Resolves: #2166195

cockpit-podman
[63.1-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/63.1
- Related: #2123641

[63-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/63
- Related: #2123641

[62-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/62
- Related: #2123641

[61-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/61
- Related: #2123641

[60-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/60
- Related: #2123641

[59-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/59
- Related: #2123641

[58-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/58
- Related: #2123641

[57-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/57
- Related: #2123641

[56-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/56
- Related: #2123641

[55-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/55
- Related: #2123641

[54-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/54
- Related: #2123641

[53-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/53
- Related: #2123641

[52-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/52
- Related: #2061390

[51.1-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/51.1
- Related: #2061390

[50-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/50
- Related: #2061390

[49.1-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/49.1
- Related: #2061390

[48-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/48
- Related: #2061390

[47-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/47
- Related: #2061390

conmon
[3:2.1.6-1]
- update to https://github.com/containers/conmon/releases/tag/v2.1.6
- Related: #2123641

[3:2.1.5-1]
- update to https://github.com/containers/conmon/releases/tag/v2.1.5
- Related: #2123641

containernetworking-plugins
[1:1.2.0-1]
- update to https://github.com/containernetworking/plugins/releases/tag/v1.2.0
- Related: #2123641

[1:1.1.1-3]
- BuildRequires: /usr/bin/go-md2man
- Related: #2061390

containers-common
[2:1-64.0.1]
- Updated removed references [Orabug: 33473101] (Alex Burmashev)
- Adjust registries.conf (Nikita Gerasimov)
- remove references to RedHat registry (Nikita Gerasimov)

[2:1-64]
- be sure SYS_CHROOT is in containers.conf + update vendored components
- Resolves: #2183667

container-selinux
[2:2.205.0-2]
- remove watch statements breaking the build on RHEL8.8
- Related: #2179466

[2:2.205.0-1]
- update to https://github.com/containers/container-selinux/releases/tag/v2.205.0
- remove user_namespace class, thanks to Lokesh Mandvekar
- Resolves: #2179466

[2:2.199.0-2]
- revert back to https://github.com/containers/container-selinux/releases/tag/v2.199.0
(2.200.0 fails to build as it relies on the new selinux-policy which is not there yet)
- Related: #2123641

[2:2.200.0-1]
- update to https://github.com/containers/container-selinux/releases/tag/v2.200.0
- Related: #2123641

criu
[3.15-3.0.1]
- Increase XSAFE area to support newer CPUs(Sapphire Rapids)

crun
[1.8.4-2]
- Apply additional criu fix
- Resolves: #2184221

[1.8.4-1]
- update to https://github.com/containers/crun/releases/tag/1.8.4
- Resolves: #2184221

[1.8.1-3]
- fix could not find symbol criu_set_lsm_mount_context in libcriu.so
- Resolves: #2184221

fuse-overlayfs
[1.11-1]
- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.11
- Resolves: #2185132

libslirp
netavark
[2:1.5.1-2]
- Update to 1.5.1 version
- --dns-add get error logs when there is no container attached to the network (2210117)
- netavark: support new 'bclim' parameter for macvlan without CAP_NET_ADMIN on the container

oci-seccomp-bpf-hook
[1.2.8-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.8
- Related: #2123641

[1.2.7-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.7
- Related: #2123641

[1.2.6-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.6
- Related: #2061390

podman
[3:4.4.1-14]
- update to the latest content of https://github.com/containers/podman/tree/v4.4.1-rhel
(https://github.com/containers/podman/commit/ff30585)
(https://github.com/containers/podman/commit/bcea446)

python-podman
[4.4.1-1]
- update to https://github.com/containers/podman-py/releases/tag/v4.4.1
- Related: #2123641

[4.4.0-1]
- update to python-podman-4.4.0
- Related: #2123641

[4.3.0-2]
- upload new source tarball
- Related: #2123641

[4.3.0-1]
- update to https://github.com/containers/podman-py/releases/tag/v4.3.0
- Related: #2123641

[4.2.0-1]
- update to https://github.com/containers/podman-py/releases/tag/v4.2.0
- Related: #2061390

runc
[1:1.1.4-1.0.1]
- rootless: fix /sys/fs/cgroup mounts to prevent CVE-2023-25809
- rootfs: prohibit symlinks that conflicts with readonlyPaths
and/or maskedPaths to prevent CVE-2023-27561
- Prohibit /proc and /sys to be symlinks to prevent CVE-2023-28642
- JIRA: OLDIS-25589

skopeo
[2:1.11.2-0.2]
- fix build
- Related: #2123641

[2:1.11.2-0.1]
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.11
(https://github.com/containers/skopeo/commit/3f98753)
- Related: #2123641

[2:1.11.1-1]
- update to https://github.com/containers/skopeo/releases/tag/v1.11.1
- Related: #2123641

[2:1.11.0-1]
- update to https://github.com/containers/skopeo/releases/tag/v1.11.0
(https://github.com/containers/skopeo/commit/968670116c56023d37e9e98b48346478599c6801)
- Related: #2123641

[2:1.11.0-0.3]
- update to the latest content of https://github.com/containers/skopeo/tree/main
(https://github.com/containers/skopeo/commit/fe15a36)
- Related: #2123641

[2:1.11.0-0.2]
- update to the latest content of https://github.com/containers/skopeo/tree/main
(https://github.com/containers/skopeo/commit/8e09e64)
- Related: #2123641

[2:1.11.0-0.1]
- update to the latest content of https://github.com/containers/skopeo/tree/main
(https://github.com/containers/skopeo/commit/2817510)
- Related: #2123641

[2:1.10.0-1]
- update to https://github.com/containers/skopeo/releases/tag/v1.10.0
- Related: #2123641

slirp4netns
[1.2.0-2]
- BuildRequires: /usr/bin/go-md2man
- Related: #2061390

[1.2.0-1]
- update to https://github.com/rootless-containers/slirp4netns/releases/tag/v1.2.0
- Related: #2061390

udica
[0.2.6-20]
- bump release to preserve update path
- Related: #2139052

[0.2.6-4]
- Bump release to match latest release available in rhel-8.6.1
- Resolves: #2139052




Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) aardvark-dns-1.5.0-2.module+el8.8.0+21045+adcb6a64.src.rpmc7c4a82895f08b42c001013d24fe7cd1-
buildah-1.29.1-2.module+el8.8.0+21056+d98a0860.src.rpmde54d880e091a663366058069077fda5-
cockpit-podman-63.1-1.module+el8.8.0+21045+adcb6a64.src.rpme8947f1b3ada5e7228ff6e5c9a51506a-
conmon-2.1.6-1.module+el8.8.0+21045+adcb6a64.src.rpm4b804f8231cd57c3d1d497d55a002189-
container-selinux-2.205.0-2.module+el8.8.0+21045+adcb6a64.src.rpm67a3ba6359aae527d08a15c1acad3b89-
containernetworking-plugins-1.2.0-1.module+el8.8.0+21045+adcb6a64.src.rpm8873c06761d486813dda7bb79fa9bb6d-
containers-common-1-64.0.1.module+el8.8.0+21056+d98a0860.src.rpmb1b2b7c07485d4c1cb30c230af012d16-
criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.src.rpmd207a7a21195f67752c2592f56d96949-
crun-1.8.4-2.module+el8.8.0+21056+d98a0860.src.rpm1c29a8142b34dc87a2625067cfa8deec-
fuse-overlayfs-1.11-1.module+el8.8.0+21056+d98a0860.src.rpmfd7fe674f3fe56f7f33788f3efd7e687-
libslirp-4.4.0-1.module+el8.8.0+21045+adcb6a64.src.rpm6b38bd2bc85c4498915f108801dec672-
netavark-1.5.1-2.module+el8.8.0+21125+a7f95b8d.src.rpm588e5efcced0efbebc40b47e7a7a4b42-
oci-seccomp-bpf-hook-1.2.8-1.module+el8.8.0+21045+adcb6a64.src.rpmedfe8dcc3938aa4ec1afa650375995bd-
podman-4.4.1-14.module+el8.8.0+21125+a7f95b8d.src.rpm9fd80ddc8fd807fc440d2a503b1192db-
python-podman-4.4.1-1.module+el8.8.0+21045+adcb6a64.src.rpm681226bf4fe2d5838e7cc3284ccc85a2-
runc-1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8.src.rpma71fae08352e8d8aa814e18d42f8b457-
skopeo-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.src.rpmbfed63d8af48529e469608b2fa353c15-
slirp4netns-1.2.0-2.module+el8.8.0+21045+adcb6a64.src.rpm3c1f313b5514362dc73739ae62f5fe1d-
udica-0.2.6-20.module+el8.8.0+21045+adcb6a64.src.rpm35ec8fad5f08d63c6783dc7cb5ead169-
aardvark-dns-1.5.0-2.module+el8.8.0+21045+adcb6a64.aarch64.rpm6dd82fe4c66c90e15199ad85f73d7fe2-
buildah-1.29.1-2.module+el8.8.0+21056+d98a0860.aarch64.rpm778b44a59bca9a2da74efe43e0a3d140-
buildah-tests-1.29.1-2.module+el8.8.0+21056+d98a0860.aarch64.rpm010566d1ff06b3f983e201919cc0856d-
cockpit-podman-63.1-1.module+el8.8.0+21045+adcb6a64.noarch.rpm93948972550b25925f4b662687b9adfa-
conmon-2.1.6-1.module+el8.8.0+21045+adcb6a64.aarch64.rpmf5d45e426e80eb9e37c30db6bd0bc4be-
container-selinux-2.205.0-2.module+el8.8.0+21045+adcb6a64.noarch.rpm4477c8710c84fa8e14a04146b425b00a-
containernetworking-plugins-1.2.0-1.module+el8.8.0+21045+adcb6a64.aarch64.rpm2e57f132085d8e21cf74f3703975b341-
containers-common-1-64.0.1.module+el8.8.0+21056+d98a0860.aarch64.rpm5c3b8586ba63453def557a31e46147b6-
crit-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.aarch64.rpm28b306e69d288b1af68a5afaf5d02aa7-
criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.aarch64.rpmc3439cb41310f90150daf65b55aa0124-
criu-devel-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.aarch64.rpm17f57e7d2c3dbe2602f91bbc1b5ba67d-
criu-libs-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.aarch64.rpmd482305b666153d0f58c6650e90cfe8b-
crun-1.8.4-2.module+el8.8.0+21056+d98a0860.aarch64.rpm3303d31ad839ac646e21a51fff309268-
fuse-overlayfs-1.11-1.module+el8.8.0+21056+d98a0860.aarch64.rpme63c17a25e31bb22a53af010509c0d7d-
libslirp-4.4.0-1.module+el8.8.0+21045+adcb6a64.aarch64.rpm6974f7dc83f6f924dd658e3006cc914e-
libslirp-devel-4.4.0-1.module+el8.8.0+21045+adcb6a64.aarch64.rpm54b84e01e6bb18df847f7123c68bccc8-
netavark-1.5.1-2.module+el8.8.0+21125+a7f95b8d.aarch64.rpm222c3f5f68b6715179438e7680d96137-
oci-seccomp-bpf-hook-1.2.8-1.module+el8.8.0+21045+adcb6a64.aarch64.rpmf859e07b8611597ba67d6ae179a80635-
podman-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpm181fa2c7cbe3cf5b3223fe4662159e46-
podman-catatonit-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpm62feae3fb5bdc4ec32564ed04ac14364-
podman-docker-4.4.1-14.module+el8.8.0+21125+a7f95b8d.noarch.rpmb1f4557dda7026ff47bb4903a7c2f0dc-
podman-gvproxy-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpm6382815a1cb8fc2d1f462a4460d69468-
podman-plugins-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpm291e4c55ac094dfe62dd1c1370846742-
podman-remote-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpm0a8a36c96b10d16777c3f0481d9adc7a-
podman-tests-4.4.1-14.module+el8.8.0+21125+a7f95b8d.aarch64.rpmf1df438e0e73885cd7fe79225b7fa7f0-
python3-criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.aarch64.rpm5b2bcf43367daa0741cf00657b1dedd0-
python3-podman-4.4.1-1.module+el8.8.0+21045+adcb6a64.noarch.rpmf55dce732e5dd6e3c99141706f0862c6-
runc-1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8.aarch64.rpmf284ef080eeec18d4761bcc6c3396040-
skopeo-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.aarch64.rpm3c9dfd631cf8b7fb3938836f424235b7-
skopeo-tests-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.aarch64.rpmf0947ee4a9714d664723f5f8eae55317-
slirp4netns-1.2.0-2.module+el8.8.0+21045+adcb6a64.aarch64.rpmba706ab27d088ca0a4a26705373d6807-
udica-0.2.6-20.module+el8.8.0+21045+adcb6a64.noarch.rpma0ca9718b7f9b254aa73ebb25e742ad6-
Oracle Linux 8 (x86_64) aardvark-dns-1.5.0-2.module+el8.8.0+21045+adcb6a64.src.rpmc7c4a82895f08b42c001013d24fe7cd1-
buildah-1.29.1-2.module+el8.8.0+21056+d98a0860.src.rpmde54d880e091a663366058069077fda5-
cockpit-podman-63.1-1.module+el8.8.0+21045+adcb6a64.src.rpme8947f1b3ada5e7228ff6e5c9a51506a-
conmon-2.1.6-1.module+el8.8.0+21045+adcb6a64.src.rpm4b804f8231cd57c3d1d497d55a002189-
container-selinux-2.205.0-2.module+el8.8.0+21045+adcb6a64.src.rpm67a3ba6359aae527d08a15c1acad3b89-
containernetworking-plugins-1.2.0-1.module+el8.8.0+21045+adcb6a64.src.rpm8873c06761d486813dda7bb79fa9bb6d-
containers-common-1-64.0.1.module+el8.8.0+21056+d98a0860.src.rpmb1b2b7c07485d4c1cb30c230af012d16-
criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.src.rpmd207a7a21195f67752c2592f56d96949-
crun-1.8.4-2.module+el8.8.0+21056+d98a0860.src.rpm1c29a8142b34dc87a2625067cfa8deec-
fuse-overlayfs-1.11-1.module+el8.8.0+21056+d98a0860.src.rpmfd7fe674f3fe56f7f33788f3efd7e687-
libslirp-4.4.0-1.module+el8.8.0+21045+adcb6a64.src.rpm6b38bd2bc85c4498915f108801dec672-
netavark-1.5.1-2.module+el8.8.0+21125+a7f95b8d.src.rpm588e5efcced0efbebc40b47e7a7a4b42-
oci-seccomp-bpf-hook-1.2.8-1.module+el8.8.0+21045+adcb6a64.src.rpmedfe8dcc3938aa4ec1afa650375995bd-
podman-4.4.1-14.module+el8.8.0+21125+a7f95b8d.src.rpm9fd80ddc8fd807fc440d2a503b1192db-
python-podman-4.4.1-1.module+el8.8.0+21045+adcb6a64.src.rpm681226bf4fe2d5838e7cc3284ccc85a2-
runc-1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8.src.rpma71fae08352e8d8aa814e18d42f8b457-
skopeo-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.src.rpmbfed63d8af48529e469608b2fa353c15-
slirp4netns-1.2.0-2.module+el8.8.0+21045+adcb6a64.src.rpm3c1f313b5514362dc73739ae62f5fe1d-
udica-0.2.6-20.module+el8.8.0+21045+adcb6a64.src.rpm35ec8fad5f08d63c6783dc7cb5ead169-
aardvark-dns-1.5.0-2.module+el8.8.0+21045+adcb6a64.x86_64.rpm25ae14c694a1e6ca944424765ab9bf68-
buildah-1.29.1-2.module+el8.8.0+21056+d98a0860.x86_64.rpm346ce0820f82c3b1e703ebbc34d9a9d1-
buildah-tests-1.29.1-2.module+el8.8.0+21056+d98a0860.x86_64.rpm7996d21f92fb9a7f105aae6a661866a9-
cockpit-podman-63.1-1.module+el8.8.0+21045+adcb6a64.noarch.rpm93948972550b25925f4b662687b9adfa-
conmon-2.1.6-1.module+el8.8.0+21045+adcb6a64.x86_64.rpm0e4d5d9aa97900dbf0da336270bb6a75-
container-selinux-2.205.0-2.module+el8.8.0+21045+adcb6a64.noarch.rpm4477c8710c84fa8e14a04146b425b00a-
containernetworking-plugins-1.2.0-1.module+el8.8.0+21045+adcb6a64.x86_64.rpm4fd79d72dee86f75aee3413bc8181174-
containers-common-1-64.0.1.module+el8.8.0+21056+d98a0860.x86_64.rpma6ca249e8e666bed9de881657b5092ce-
crit-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.x86_64.rpmcb77c0c6c96735b2af0b44acade771b7-
criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.x86_64.rpmb86f6842ad9e10e0c61f986916d2af0e-
criu-devel-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.x86_64.rpm228dbc94a81978497e6f50d509e8f2a5-
criu-libs-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.x86_64.rpm74b9f8de8c8248c5c9d216cbe25c4310-
crun-1.8.4-2.module+el8.8.0+21056+d98a0860.x86_64.rpme0ce6450e2aa70366b8752087ef38ab0-
fuse-overlayfs-1.11-1.module+el8.8.0+21056+d98a0860.x86_64.rpm5b5fadbf1d9248b7f1f59289fb114490-
libslirp-4.4.0-1.module+el8.8.0+21045+adcb6a64.x86_64.rpm30f3ee2d8f0296da430854872198ebc9-
libslirp-devel-4.4.0-1.module+el8.8.0+21045+adcb6a64.x86_64.rpm4f4f3409f9e17c0d5021dbdef8f8ab63-
netavark-1.5.1-2.module+el8.8.0+21125+a7f95b8d.x86_64.rpm3e05fe9c26a6058c41cc99ad3c58944a-
oci-seccomp-bpf-hook-1.2.8-1.module+el8.8.0+21045+adcb6a64.x86_64.rpm5a84291fd98259e4883786a17b28cbd1-
podman-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpm11bfe69608661106d3d340d057fb95bc-
podman-catatonit-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpm666b83cd7d9f7d96621b00567efd9949-
podman-docker-4.4.1-14.module+el8.8.0+21125+a7f95b8d.noarch.rpmb1f4557dda7026ff47bb4903a7c2f0dc-
podman-gvproxy-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpm3b956803c730172332031298fe3d8a5c-
podman-plugins-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpm8330bc13d002966e81e7f914a11bb268-
podman-remote-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpm638017baf43ee38c3467b9d5e2b2fbb1-
podman-tests-4.4.1-14.module+el8.8.0+21125+a7f95b8d.x86_64.rpmd71564aa579ad20633fab4860dfb4903-
python3-criu-3.15-3.0.1.module+el8.8.0+21125+a7f95b8d.x86_64.rpmb562cf7f7ebf1541204327df2564e552-
python3-podman-4.4.1-1.module+el8.8.0+21045+adcb6a64.noarch.rpmf55dce732e5dd6e3c99141706f0862c6-
runc-1.1.4-1.0.1.module+el8.8.0+21119+51f68ed8.x86_64.rpmd98a81d2a6620b7c3f70ed9649cc8b81-
skopeo-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.x86_64.rpmd9d4a45d84bf087e8f2b327fbcb174ed-
skopeo-tests-1.11.2-0.2.module+el8.8.0+21045+adcb6a64.x86_64.rpme57a77de3e4bbbb5055adc601eacea3d-
slirp4netns-1.2.0-2.module+el8.8.0+21045+adcb6a64.x86_64.rpm15f472e45a71edd1f6f4fb07c6f5a08e-
udica-0.2.6-20.module+el8.8.0+21045+adcb6a64.noarch.rpma0ca9718b7f9b254aa73ebb25e742ad6-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete