Moderate: podman security and bug fix update
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fixes: * podman: jose-go: improper handling of highly compressed data (CVE-2024-28180) * podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290) * podman: jose: resource exhaustion (CVE-2024-28176)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fixes: * podman: jose-go: improper handling of highly compressed data (CVE-2024-28180) * podman: golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290) * podman: jose: resource exhaustion (CVE-2024-28176)
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2024:3826
- https://access.redhat.com/security/cve/CVE-2023-45290
- https://access.redhat.com/security/cve/CVE-2024-28176
- https://access.redhat.com/security/cve/CVE-2024-28180
- https://bugzilla.redhat.com/2268017
- https://bugzilla.redhat.com/2268820
- https://bugzilla.redhat.com/2268854
- https://errata.almalinux.org/9/ALSA-2024-3826.html