ELSA-2021-0531

ELSA-2021-0531 - container-tools:ol8 security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2021-02-20

Description


buildah
[1.16.7-4.0.1]
- Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)

[1.16.7-4]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.16
(https://github.com/containers/buildah/commit/aaed66b)
- Related: #1888571

[1.16.7-3]
- revert back to buildah-1.16 for the quarterly release
- Related: #1888571

[1.19.0-2]
- bump version to refrect buildah upgrade
- Related: #1888571

[1.16.7-2]
- bump to release-1.19 branch
- Related: #1888571

[1.16.5-5]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.16
(https://github.com/containers/buildah/commit/56ed75b)
- Related: #1888571

[1.16.5-4]
- simplify spec file
- use short commit ID in tarball name
- Related: #1888571

[1.16.5-3]
- update to the latest content of https://github.com/containers/buildah/tree/release-1.16
(https://github.com/containers/buildah/commit/9e02bf9)
- Related: #1888571

[1.16.5-2]
- use shortcommit ID in branch tarball name
- Related: #1888571

[1.16.5-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

cockpit-podman
[27.1-3]
- run much more tests - patch from Matej Marusak
- Related: #1888571

[27.1-2]
- gating tests - always set VM password
- Related: #1888571

[27.1-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/27.1
- Related: #1888571

[27-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/27
- Related: #1888571

[26-1]
- update to https://github.com/cockpit-project/cockpit-podman/releases/tag/26
- Related: #1888571

[25-5]
- remove redundant patch
- Related: #1888571

[25-4]
- replace docker.io with quay.io for gating tests due do
docker.io new pull rate limit requirements
- Related: #1888571

[25-3]
- test: Cleanup images before pulling the ones we need - thanks to Matej Marusak
- Related: #1888571

[25-2]
- remove hack in tests
- add LICENSE
- Related: #1888571

[25-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

conmon
[2:2.0.22-3]
- exclude i686 as golang is not suppoerted there
- Related: #1888571

[2:2.0.22-2]
- add BR: golang, go-md2man
- add man pages
- Related: #1888571

[2:2.0.22-1]
- update to https://github.com/containers/conmon/releases/tag/v2.0.22
- Related: #1888571

[2:2.0.21-3]
- simplify spec
- Related: #1888571

[2:2.0.21-2]
- be sure to harden the linked binary
- compile with debuginfo enabled
- Related: #1888571

[2:2.0.21-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

containernetworking-plugins
[0.9.0-1]
- update to https://github.com/containernetworking/plugins/releases/tag/v0.9.0
- Related: #1888571

container-selinux
[2:2.155.0-1]
- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0
- Related: #1888571

[2:2.154.0-1]
- update to
https://github.com/containers/container-selinux/releases/tag/v2.154.0
- Related: #1888571

[2:2.153.0-1]
- update to
https://github.com/containers/container-selinux/releases/tag/v2.153.0
- Related: #1888571

[2:2.152.0-1]
- update to
https://github.com/containers/container-selinux/releases/tag/v2.152.0
- Related: #1888571

[2:2.151.0-1]
- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0
- Related: #1888571

[2:2.150.0-1]
- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0
- Related: #1888571

[2:2.145.0-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Resolves: #1873064

criu
[3.15-1]
- update to https://github.com/checkpoint-restore/criu/releases/tag/v3.15
- Related: #1888571

[3.14-2]
- fix 'Need to fix bugs found by coverity.'
- Related: #1821193

[3.14-1]
- synchronize containter-tools 8.3.0 with 8.2.1
- Related: #1821193

crun
[0.16-2]
- exclude i686 because of build failures
- Related: #1888571

[0.16-1]
- update to https://github.com/containers/crun/releases/tag/0.16
- Related: #1888571

[0.15.1-1]
- update to https://github.com/containers/crun/releases/tag/0.15.1
- Related: #1888571

[0.15-2]
- backport 'exec: check read bytes from sync' (gscrivan@redhat.com)
(https://github.com/containers/crun/issues/511)
- Related: #1888571

[0.15-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

fuse-overlayfs
[1.3.0-2]
- disable openat2 syscall again - still unsupported in current RHEL8 kernel
- Resolves: #1921863

[1.3.0-1]
- update to https://github.com/containers/fuse-overlayfs/releases/tag/v1.3.0
- Related: #1888571

[1.2.0-3]
- be sure to harden the linked binary
- Related: #1888571

[1.2.0-2]
- ensure fuse module is loaded
- Related: #1888571

[1.2.0-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

libslirp
oci-seccomp-bpf-hook
[1.2.0-1]
- update to https://github.com/containers/oci-seccomp-bpf-hook/releases/tag/v1.2.0
- Related: #1888571

podman
[2.2.1-7.0.1]
- Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)

[2.2.1-7]
- Resolves: #1925928 - Fix varlink GetVersion()
- Upstream PR: https://github.com/containers/podman/pull/9274

[2.2.1-6]
- update to the latest content of https://github.com/containers/podman/tree/v2.2.1-rhel
(https://github.com/containers/podman/commit/1741f15)
- Related: #1888571

[2.2.1-5]
- update to the latest content of https://github.com/containers/podman/tree/v2.2.1-rhel
(https://github.com/containers/podman/commit/b5bc6a7)
- Related: #1877188

[2.2.1-4]
- add Requires: oci-runtime
- Related: #1888571

[2.2.1-3]
- update to the latest content of https://github.com/containers/podman/tree/v2.2.1-rhel
(https://github.com/containers/podman/commit/14c35f6)
- Related: #1888571

[2.2.1-2]
- update to https://github.com/containers/dnsname/releases/tag/v1.1.1

[2.2.1-1]
- update to the latest content of https://github.com/containers/podman/tree/v2.2.1-rhel
(https://github.com/containers/podman/commit/a0d478e)
- Related: #1888571

[2.2.0-2]
- attempt to fix gatng tests
- Related: #1888571

[2.2.0-1]
- update to https://github.com/containers/podman/releases/tag/v2.2.0
- Related: #1888571

[2.1.1-3]
- attempt to fix linker error with golang-1.15
- add Requires: httpd-tools to tests, needed to work around
missing htpasswd in docker registry image, thanks to Ed Santiago
- Related: #1888571

[2.1.1-2]
- update to the latest content of https://github.com/containers/podman/tree/v2.1.1-rhel
(https://github.com/containers/podman/commit/450615a)
- Resolves: #1873204
- Resolves: #1884668

[2.1.1-1]
- update podman to 2.1.1-rhel
- Resolves: #1743687
- Resolves: #1811570
- Resolves: #1869322
- Resolves: #1678546
- Resolves: #1853455
- Resolves: #1874271

python-podman-api
[1.2.0-0.2.gitd0a45fe]
- revert update to 1.6.0 due to new python3-pbr dependency which
is not in RHEL
- Related: RHELPLAN-25139

[1.2.0-0.1.gitd0a45fe]
- Initial package

runc
[1.0.0-70.rc92]
- add Provides: oci-runtime = 1
- Related: #1888571

[1.0.0-69.rc92]
- still use ExcludeArch as go_arches macro is broken for 8.4
- Related: #1888571

skopeo
[1:1.2.0-9.0.1]
- Handling redirect from the docker registry [Orabug: 29874238] (Nikita Gerasimov)
- Add oracle registry into the conf file [Orabug: 29845934 31306708]

[1:1.2.0-9]
- upload proper source tarball
- Related: #1888571

[1:1.2.0-8]
- revert back to version aimed at 8.3.1 - skopeo-1.2.0
- also downgrade versions of vendored libraries
- Related: #1888571

[1:1.2.1-1]
- update vendored component versions
- update to the latest content of https://github.com/containers/skopeo/tree/release-1.2
(https://github.com/containers/skopeo/commit/2e90a8a)
- Related: #1888571

[1:1.2.0-6]
- always build with debuginfo
- use less verbose output when compiling
- Related: #1888571

[1:1.2.0-5]
- re-sync config files
- assure events_logger = 'file'
- Related: #1888571

[1:1.2.0-4]
- change default logging mechanism to use for container engine events
in containers.conf to be events_logger = 'file' - it should fix
RHEL gating tests for podman nonroot (thanks to Dan Walsh)
- Related: #1888571

[1:1.2.0-3]
- simplify spec file
- use short commit ID in tarball name
- Related: #1888571

[1:1.2.0-2]
- use shortcommit ID in branch tarball name
- Related: #1888571

[1:1.2.0-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

slirp4netns
[1.1.8-1]
- update to
https://github.com/rootless-containers/slirp4netns/releases/tag/v1.1.8
- Related: #1888571

[1.1.7-2]
- exclude i686 because of build failures
- Related: #1888571

[1.1.7-1]
- update to
https://github.com/rootless-containers/slirp4netns/releases/tag/v1.1.7
- Related: #1888571

[1.1.6-2]
- - be sure to harden the linked binary
- Related: #1888571

[1.1.6-1]
- update to
https://github.com/rootless-containers/slirp4netns/releases/tag/v1.1.6
- Related: #1888571

udica
[0.2.4-1]
- update to https://github.com/containers/udica/releases/tag/v0.2.4
- Related: #1888571

[0.2.3-1]
- synchronize with stream-container-tools-rhel8-rhel-8.4.0
- Related: #1888571

[0.2.2-1]
- https://github.com/containers/udica/releases/tag/v0.2.2
- Related: #1821193


Related CVEs


CVE-2020-14370

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) buildah-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.src.rpm0d06b0fb66682de65af0644f09f40571-
cockpit-podman-27.1-3.module+el8.3.1+9659+c1901784.src.rpm41980527614657cb1db7b300cb85a848-
conmon-2.0.22-3.module+el8.3.1+9659+c1901784.src.rpme6b250efcc7be3f90b9983d119728204-
container-selinux-2.155.0-1.module+el8.3.1+9659+c1901784.src.rpm1c320f7562e6f4fb2a6f98667720f3f0-
containernetworking-plugins-0.9.0-1.module+el8.3.1+9659+c1901784.src.rpm8369559a0255eb70dd102f4401f04bee-
criu-3.15-1.module+el8.3.1+9659+c1901784.src.rpmd250a7c0bf31bf88784a18d9138c3132-
crun-0.16-2.module+el8.3.1+9659+c1901784.src.rpmec98c55689403067ff9d5be71272facc-
fuse-overlayfs-1.3.0-2.module+el8.3.1+9659+c1901784.src.rpm56cda07d89acb1029bed294ef4a76137-
libslirp-4.3.1-1.module+el8.3.1+9659+c1901784.src.rpmf0124412f0ef5d04f849f0bcfbf20907-
oci-seccomp-bpf-hook-1.2.0-1.module+el8.3.1+9659+c1901784.src.rpmda640586da744f09014ac94dfe9bfbf0-
podman-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.src.rpmc7b4858be6f6d75dea6bacbbb05434e1-
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784.src.rpm991bc70ff21d43d11ccb076655e9f18b-
runc-1.0.0-70.rc92.module+el8.3.1+9659+c1901784.src.rpm6a7b82d25d2fe34bd6dc65648c307565-
skopeo-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.src.rpm8fca3aa60ee3289feeb2b548dd707b5a-
slirp4netns-1.1.8-1.module+el8.3.1+9659+c1901784.src.rpm31595fa4bbca22cbe4aa51439c8a2786-
udica-0.2.4-1.module+el8.3.1+9659+c1901784.src.rpmed934acb7de882de08354dafa74fba0f-
buildah-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.aarch64.rpm13b923eb132ad07667dea8217aa78c44-
buildah-tests-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.aarch64.rpmf5527cb7541797654723cc456440dadd-
cockpit-podman-27.1-3.module+el8.3.1+9659+c1901784.noarch.rpm1b1080d7f90d5cc03c2c68e3a66ae6c3-
conmon-2.0.22-3.module+el8.3.1+9659+c1901784.aarch64.rpm6ffb875173d912c552f9a67d87b4e2f3-
container-selinux-2.155.0-1.module+el8.3.1+9659+c1901784.noarch.rpm9ebb44f2348784f7f4d3652efd11b248-
containernetworking-plugins-0.9.0-1.module+el8.3.1+9659+c1901784.aarch64.rpm37fa0707fb40391b045a71867f86e637-
containers-common-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.aarch64.rpm9fbb639acaebbecc12247d410a622c97-
crit-3.15-1.module+el8.3.1+9659+c1901784.aarch64.rpm10301b8712ab27bd3f8eb4c7b110be44-
criu-3.15-1.module+el8.3.1+9659+c1901784.aarch64.rpmc126f6aaf2620a38d993acd7b0ba99cb-
crun-0.16-2.module+el8.3.1+9659+c1901784.aarch64.rpm7b6243965d7f8ec6bec378690d29edd0-
fuse-overlayfs-1.3.0-2.module+el8.3.1+9659+c1901784.aarch64.rpmf2ea5014900027ad179f12f46a2e7a23-
libslirp-4.3.1-1.module+el8.3.1+9659+c1901784.aarch64.rpmded02de876512b20e3eabb8fdee8c037-
libslirp-devel-4.3.1-1.module+el8.3.1+9659+c1901784.aarch64.rpm0d8105979195a6e08c0cec2b2cc510dd-
oci-seccomp-bpf-hook-1.2.0-1.module+el8.3.1+9659+c1901784.aarch64.rpm684c5c35f9f94800927e0fa83b0b6fdd-
podman-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.aarch64.rpmeaeb6896957410b07ad62c06e5bb0f5a-
podman-catatonit-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.aarch64.rpmc911171609f0eb0de4cc51c48537c525-
podman-docker-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.noarch.rpmd44bf217af17ccbc00ccb499fe0435db-
podman-plugins-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.aarch64.rpmb56214bb0d1969a46feffcddac0c4ee5-
podman-remote-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.aarch64.rpm38f2e7082cc1c60063c00f7e003527cf-
podman-tests-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.aarch64.rpme59d9420d0a14ca2f5f9920cce6407f8-
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784.noarch.rpmcf91de78fe54b0ca223aba49abe74a1a-
python3-criu-3.15-1.module+el8.3.1+9659+c1901784.aarch64.rpmd2bf083b1c719a30933443aadc4bc331-
runc-1.0.0-70.rc92.module+el8.3.1+9659+c1901784.aarch64.rpm7ccfe75f4664a575805e7180c0976084-
skopeo-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.aarch64.rpm3880f1998eed9e5c12b8fbe2d3ce32c8-
skopeo-tests-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.aarch64.rpmf3cfaa75fb851cb425b768578225a4ee-
slirp4netns-1.1.8-1.module+el8.3.1+9659+c1901784.aarch64.rpm549502f74b9206ae7b4d2dc3632df4e7-
udica-0.2.4-1.module+el8.3.1+9659+c1901784.noarch.rpmc916937b219f3d74e358b16c38f35a93-
Oracle Linux 8 (x86_64) buildah-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.src.rpm0d06b0fb66682de65af0644f09f40571-
cockpit-podman-27.1-3.module+el8.3.1+9659+c1901784.src.rpm41980527614657cb1db7b300cb85a848-
conmon-2.0.22-3.module+el8.3.1+9659+c1901784.src.rpme6b250efcc7be3f90b9983d119728204-
container-selinux-2.155.0-1.module+el8.3.1+9659+c1901784.src.rpm1c320f7562e6f4fb2a6f98667720f3f0-
containernetworking-plugins-0.9.0-1.module+el8.3.1+9659+c1901784.src.rpm8369559a0255eb70dd102f4401f04bee-
criu-3.15-1.module+el8.3.1+9659+c1901784.src.rpmd250a7c0bf31bf88784a18d9138c3132-
crun-0.16-2.module+el8.3.1+9659+c1901784.src.rpmec98c55689403067ff9d5be71272facc-
fuse-overlayfs-1.3.0-2.module+el8.3.1+9659+c1901784.src.rpm56cda07d89acb1029bed294ef4a76137-
libslirp-4.3.1-1.module+el8.3.1+9659+c1901784.src.rpmf0124412f0ef5d04f849f0bcfbf20907-
oci-seccomp-bpf-hook-1.2.0-1.module+el8.3.1+9659+c1901784.src.rpmda640586da744f09014ac94dfe9bfbf0-
podman-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.src.rpmc7b4858be6f6d75dea6bacbbb05434e1-
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784.src.rpm991bc70ff21d43d11ccb076655e9f18b-
runc-1.0.0-70.rc92.module+el8.3.1+9659+c1901784.src.rpm6a7b82d25d2fe34bd6dc65648c307565-
skopeo-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.src.rpm8fca3aa60ee3289feeb2b548dd707b5a-
slirp4netns-1.1.8-1.module+el8.3.1+9659+c1901784.src.rpm31595fa4bbca22cbe4aa51439c8a2786-
udica-0.2.4-1.module+el8.3.1+9659+c1901784.src.rpmed934acb7de882de08354dafa74fba0f-
buildah-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.x86_64.rpmb33d310c9aed8cb88aa3496ce04a7718-
buildah-tests-1.16.7-4.0.1.module+el8.3.1+9659+c1901784.x86_64.rpm11b56c57876fe9e8e69dffeca4081845-
cockpit-podman-27.1-3.module+el8.3.1+9659+c1901784.noarch.rpm1b1080d7f90d5cc03c2c68e3a66ae6c3-
conmon-2.0.22-3.module+el8.3.1+9659+c1901784.x86_64.rpmd40dad676e63388e502beee2dc5a0db6-
container-selinux-2.155.0-1.module+el8.3.1+9659+c1901784.noarch.rpm9ebb44f2348784f7f4d3652efd11b248-
containernetworking-plugins-0.9.0-1.module+el8.3.1+9659+c1901784.x86_64.rpm9954b0f942edfbc5430598314bbb43ee-
containers-common-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.x86_64.rpmac119d104c9ead113f90ccb62719d981-
crit-3.15-1.module+el8.3.1+9659+c1901784.x86_64.rpmb07eeb73124fdb34f148f2d882dd2c74-
criu-3.15-1.module+el8.3.1+9659+c1901784.x86_64.rpm7136b57e8c82fc25930278f6d7321096-
crun-0.16-2.module+el8.3.1+9659+c1901784.x86_64.rpmb05384a8767778c8b81a17bd3f135a15-
fuse-overlayfs-1.3.0-2.module+el8.3.1+9659+c1901784.x86_64.rpmc1d3c69e9bd15a4fb86d36bf1b1e227b-
libslirp-4.3.1-1.module+el8.3.1+9659+c1901784.x86_64.rpm013a98869ad0ee1793318d694f771a90-
libslirp-devel-4.3.1-1.module+el8.3.1+9659+c1901784.x86_64.rpm35d774f8328946c4b5ef701e3335fce8-
oci-seccomp-bpf-hook-1.2.0-1.module+el8.3.1+9659+c1901784.x86_64.rpm9b40d2d14fd0cf26acb9be4497053c52-
podman-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.x86_64.rpm9754f1407c197459b93c496bb7cde679-
podman-catatonit-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.x86_64.rpmd0693b3c00ae56d24067cf8a80cd6dc2-
podman-docker-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.noarch.rpmd44bf217af17ccbc00ccb499fe0435db-
podman-plugins-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.x86_64.rpme57dd39176b5e1deb950604eaf794ad0-
podman-remote-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.x86_64.rpmfaa4886e50e09e70a2b565d10c47aded-
podman-tests-2.2.1-7.0.1.module+el8.3.1+9659+c1901784.x86_64.rpm084e7145c5768ab3bc18938eb83704f6-
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.3.1+9659+c1901784.noarch.rpmcf91de78fe54b0ca223aba49abe74a1a-
python3-criu-3.15-1.module+el8.3.1+9659+c1901784.x86_64.rpm47659f9eba20561ee03e5e7dfd4e92f0-
runc-1.0.0-70.rc92.module+el8.3.1+9659+c1901784.x86_64.rpmaebe3dc5c2a7067d52dcb09efd0d8200-
skopeo-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.x86_64.rpm9da7e9e161fd56f720f4085cff0bc371-
skopeo-tests-1.2.0-9.0.1.module+el8.3.1+9659+c1901784.x86_64.rpmec79f52aa7c5eb1cd324b3602001d7cd-
slirp4netns-1.1.8-1.module+el8.3.1+9659+c1901784.x86_64.rpm9ca52f7bc888b9fcebb6927e3a1414f4-
udica-0.2.4-1.module+el8.3.1+9659+c1901784.noarch.rpmc916937b219f3d74e358b16c38f35a93-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete