{"id":"RLSA-2024:10289","summary":"Moderate: container-tools:rhel8 security update","details":"The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)\n\n* podman: podman machine spawns gvproxy with port bound to all IPs (CVE-2021-4024)\n\n* Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) (CVE-2024-9676)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-02-05T10:15:04.018626Z","published":"2024-12-19T04:18:05.672002Z","upstream":["CVE-2021-33198","CVE-2021-4024","CVE-2024-9676"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2024:10289"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1989575"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2026675"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2317467"}],"affected":[{"package":{"name":"aardvark-dns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/aardvark-dns?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.10.1-2.module+el8.10.0+1874+ce489889"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"buildah","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/buildah?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.33.11-1.module+el8.10.0+1896+b18fa106"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"cockpit-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/cockpit-podman?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:84.1-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"conmon","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/conmon?distro=rocky-linux-8&epoch=3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3:2.1.10-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"containernetworking-plugins","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containernetworking-plugins?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.4.0-5.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"containers-common","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/containers-common?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1-82.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"container-selinux","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/container-selinux?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:2.229.0-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"criu","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/criu?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:3.18-5.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"crun","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/crun?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.14.3-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"fuse-overlayfs","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/fuse-overlayfs?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.13-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"libslirp","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/libslirp?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.4.0-2.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"netavark","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/netavark?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.10.3-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"oci-seccomp-bpf-hook","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/oci-seccomp-bpf-hook?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.10-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/podman?distro=rocky-linux-8&epoch=4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4:4.9.4-18.module+el8.10.0+1896+b18fa106"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"python-podman","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/python-podman?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:4.9.0-3.module+el8.10.0+1896+b18fa106"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"runc","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/runc?distro=rocky-linux-8&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.1.12-5.module+el8.10.0+1874+ce489889"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"skopeo","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/skopeo?distro=rocky-linux-8&epoch=2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:1.14.5-3.module+el8.10.0+1843+6892ab28"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"slirp4netns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/slirp4netns?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.2.3-1.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"toolbox","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/toolbox?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}},{"package":{"name":"udica","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/udica?distro=rocky-linux-8&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.2.6-21.module+el8.10.0+1815+5fe7415e"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2024:10289.json"}}],"schema_version":"1.7.3","credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}