RHSA-2020:1926HighCVSS 8.8
Red Hat Security Advisory: container-tools:1.0 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-10696 — buildah: Crafted input tar file may lead to local file overwrite during image build process
🎯 Affected products146
- Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debuginfo-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- buildah-debugsource-0:1.5-4.gite94b4f9.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.124.0-1.gitf958d0c.module+el8.2.0+6370+6fb6c8ca.noarch (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- container-selinux-2:2.124.0-1.gitf958d0c.module+el8.2.0+6370+6fb6c8ca.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.src (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debuginfo-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.ppc64le (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.s390x (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containernetworking-plugins-debugsource-0:0.7.4-3.git9ebe139.module+el8.2.0+6370+6fb6c8ca.x86_64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- containers-common-1:0.1.32-4.git1715c90.module+el8.2.0+6370+6fb6c8ca.aarch64 (container-tools:1.0) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +116 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2020:1926
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1776313
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1813776
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817651
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1926.json