Security update for buildah
This update for buildah fixes the following issues: - Updated to version 1.26.0: - CVE-2022-27651: Fixed an issue where containers were incorrectly started with non-empty inheritable Linux process capabilities (bsc#1197870). - CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961). - CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for buildah fixes the following issues: - Updated to version 1.26.0: - CVE-2022-27651: Fixed an issue where containers were incorrectly started with non-empty inheritable Linux process capabilities (bsc#1197870). - CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961). - CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1167864
- https://bugzilla.suse.com/1181961
- https://bugzilla.suse.com/1183043
- https://bugzilla.suse.com/1192999
- https://bugzilla.suse.com/1197870
- https://www.suse.com/security/cve/CVE-2020-10696
- https://www.suse.com/security/cve/CVE-2021-20206
- https://www.suse.com/security/cve/CVE-2022-27651
- https://www.suse.com/support/update/announcement/2022/suse-su-20223480-1/