Important: podman security update
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783) * go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104) * gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes. Security Fix(es): * golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783) * go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104) * gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2024:6194
- https://access.redhat.com/security/cve/CVE-2024-24783
- https://access.redhat.com/security/cve/CVE-2024-37298
- https://access.redhat.com/security/cve/CVE-2024-6104
- https://bugzilla.redhat.com/2268019
- https://bugzilla.redhat.com/2294000
- https://bugzilla.redhat.com/2295010
- https://errata.almalinux.org/9/ALSA-2024-6194.html