ELSA-2023-6473

ELSA-2023-6473 - buildah security update

Type:SECURITY
Severity:MODERATE
Release Date:2023-11-11

Description


[1.31.3-1.0.1]
- Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117178]

[1:1.31.3-1]
- update to https://github.com/containers/buildah/releases/tag/v1.31.3
- Related: #2176063

[1:1.31.2-1]
- update to https://github.com/containers/buildah/releases/tag/v1.31.2
- Related: #2176063

[1:1.31.1-2]
- build buildah off main branch for early testing of zstd compression
- Related: #2176063

[1:1.31.1-1]
- update to https://github.com/containers/buildah/releases/tag/v1.31.1
- Related: #2176063

[1:1.31.0-1]
- update to https://github.com/containers/buildah/releases/tag/v1.31.0
- Related: #2176063

[1:1.30.0-2]
- rebuild for following CVEs:
CVE-2023-25173 CVE-2022-41724 CVE-2022-41725 CVE-2023-24538 CVE-2023-24534 CVE-2023-24536 CVE-2022-41723 CVE-2023-24539 CVE-2023-24540 CVE-2023-29400
- Resolves: #2175073
- Resolves: #2179958
- Resolves: #2187332
- Resolves: #2187375
- Resolves: #2203696
- Resolves: #2207518

[1:1.30.0-1]
- update to 1.30.0
- Related: #2176063


Related CVEs


CVE-2022-41723
CVE-2023-24534
CVE-2022-41725
CVE-2023-24536
CVE-2023-25173
CVE-2023-29400
CVE-2023-29406
CVE-2023-24540
CVE-2023-24539
CVE-2023-24538
CVE-2022-41724

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) buildah-1.31.3-1.0.1.el9.src.rpmdbc859833beaa464fce7a4e4db3b46e7-ol9_aarch64_appstream
buildah-1.31.3-1.0.1.el9.aarch64.rpmd994e5f84beb41f7044f7ff9384b1876-ol9_aarch64_appstream
buildah-tests-1.31.3-1.0.1.el9.aarch64.rpm0b767d8e048206f47b77bf98284c6932-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) buildah-1.31.3-1.0.1.el9.src.rpmdbc859833beaa464fce7a4e4db3b46e7-ol9_x86_64_appstream
buildah-1.31.3-1.0.1.el9.x86_64.rpmb82c4e0146e8e9bd79b657b4136c30e4-ol9_x86_64_appstream
buildah-tests-1.31.3-1.0.1.el9.x86_64.rpm0492b8f85d1cd00c345694e0676928bd-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete