Moderate: buildah security update
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) * golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724) * golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725) * golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534) * golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536) * golang: html/template: backticks not treated as string delimiters (CVE-2023-24538) * golang: html/template: improper sanitization of CSS values (CVE-2023-24539) * containerd: Supplementary groups are not set up properly (CVE-2023-25173) * golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) * golang: net/http: insufficient sanitization of Host header (CVE-2023-29406) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540) * net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723) * golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724) * golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725) * golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534) * golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536) * golang: html/template: backticks not treated as string delimiters (CVE-2023-24538) * golang: html/template: improper sanitization of CSS values (CVE-2023-24539) * containerd: Supplementary groups are not set up properly (CVE-2023-25173) * golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400) * golang: net/http: insufficient sanitization of Host header (CVE-2023-29406) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2023:6473
- https://access.redhat.com/security/cve/CVE-2022-41723
- https://access.redhat.com/security/cve/CVE-2022-41724
- https://access.redhat.com/security/cve/CVE-2022-41725
- https://access.redhat.com/security/cve/CVE-2023-24534
- https://access.redhat.com/security/cve/CVE-2023-24536
- https://access.redhat.com/security/cve/CVE-2023-24538
- https://access.redhat.com/security/cve/CVE-2023-24539
- https://access.redhat.com/security/cve/CVE-2023-24540
- https://access.redhat.com/security/cve/CVE-2023-25173
- https://access.redhat.com/security/cve/CVE-2023-29400
- https://access.redhat.com/security/cve/CVE-2023-29406
- https://bugzilla.redhat.com/2174485
- https://bugzilla.redhat.com/2178358
- https://bugzilla.redhat.com/2178488
- https://bugzilla.redhat.com/2178492
- https://bugzilla.redhat.com/2184481
- https://bugzilla.redhat.com/2184482
- https://bugzilla.redhat.com/2184483
- https://bugzilla.redhat.com/2196026
- https://bugzilla.redhat.com/2196027
- https://bugzilla.redhat.com/2196029
- https://bugzilla.redhat.com/2222167
- https://errata.almalinux.org/9/ALSA-2023-6473.html