{"id":"RLSA-2021:4154","summary":"Moderate: container-tools:rhel8 security, bug fix, and enhancement update","details":"The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* buildah: Host environment variables leaked in build container when using chroot isolation (CVE-2021-3602)\n\n* containers/storage: DoS via malicious image (CVE-2021-20291)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.","modified":"2026-02-04T08:45:14.455572Z","published":"2021-11-09T08:24:51Z","upstream":["CVE-2021-20291","CVE-2021-3602"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2021:4154"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1914687"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1928935"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1932399"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1933775"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1933776"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1934415"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1934480"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1937641"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1937830"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1939485"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1940037"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1940054"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1940082"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1940493"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1941380"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1947432"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1947999"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1952204"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1952698"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1957299"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1957840"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1957904"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1958353"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1960948"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1966538"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1966872"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1969264"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1972150"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1972209"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1972211"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1972282"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1972648"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1973418"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1976283"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1977280"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1977673"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1978415"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1978556"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1978647"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1979497"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1980212"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1982593"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1982762"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1985499"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1985905"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1987049"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1993209"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1993249"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1995041"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1998191"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1999144"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2000943"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2004562"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2005018"}],"affected":[{"package":{"name":"buildah","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.22.3-2.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"cockpit-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:33-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"conmon","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8-4-legacy&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.0.29-1.module+el8.4.0+643+525e162a"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"conmon","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8-5-legacy&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.0.29-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"containernetworking-plugins","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0.0-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"containers-common","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8-5-legacy&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1-2.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"container-selinux","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8-4-legacy&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.167.0-1.module+el8.4.0+653+ad26b47d"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"container-selinux","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8-5-legacy&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.167.0-1.module+el8.5.0+709+440d5e7e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"criu","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.15-3.module+el8.7.0+1077+0e4f03d4"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"criu","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/criu?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.15-3.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"criu","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/criu?distro=rocky-linux-8-6-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.15-3.module+el8.6.0+1054+50b00ff4"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"crun","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/crun?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"fuse-overlayfs","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.7.1-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"libslirp","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.4.0-1.module+el8.7.0+1077+0e4f03d4"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"libslirp","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.4.0-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"libslirp","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8-6-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.4.0-1.module+el8.6.0+1054+50b00ff4"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"oci-seccomp-bpf-hook","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.3-3.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"oci-seccomp-bpf-hook","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8-6-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.3-3.module+el8.6.0+784+32aef5de"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/podman?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.3.1-9.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"python-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.2.0-2.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"runc","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/runc?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.0.2-1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"skopeo","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8-5-legacy&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.4.2-0.1.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.8-1.module+el8.7.0+1076+9b1c11c1"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.8-1.module+el8.4.0+537+38cf4e42"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.8-1.module+el8.5.0+709+440d5e7e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8-6-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.8-1.module+el8.6.0+783+10209741"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"toolbox","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.0.99.3-0.4.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"toolbox","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8-6-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.0.99.3-0.4.module+el8.6.0+784+32aef5de"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}},{"package":{"name":"udica","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/udica?distro=rocky-linux-8-5-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.2.5-2.module+el8.5.0+710+4c471e88"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2021:4154.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}