[El-errata] ELSA-2020-1932 Important: Oracle Linux 8 container-tools:ol8 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed May 13 08:24:42 PDT 2020


Oracle Linux Security Advisory ELSA-2020-1932

http://linux.oracle.com/errata/ELSA-2020-1932.html

The following updated rpms for Oracle Linux 8 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
buildah-1.11.6-8.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
buildah-tests-1.11.6-8.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
cockpit-podman-12-1.module+el8.2.0+7615+180dc822.noarch.rpm
conmon-2.0.6-1.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
containernetworking-plugins-0.8.3-5.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
containers-common-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
container-selinux-2.124.0-1.module+el8.2.0+7615+180dc822.noarch.rpm
crit-3.12-9.module+el8.2.0+7615+180dc822.x86_64.rpm
criu-3.12-9.module+el8.2.0+7615+180dc822.x86_64.rpm
fuse-overlayfs-0.7.2-5.module+el8.2.0+7615+180dc822.x86_64.rpm
podman-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
podman-docker-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.noarch.rpm
podman-remote-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
podman-tests-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
python3-criu-3.12-9.module+el8.2.0+7615+180dc822.x86_64.rpm
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.2.0+7615+180dc822.noarch.rpm
runc-1.0.0-65.rc10.module+el8.2.0+7615+180dc822.x86_64.rpm
skopeo-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
skopeo-tests-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.x86_64.rpm
slirp4netns-0.4.2-3.git21fdece.module+el8.2.0+7615+180dc822.x86_64.rpm
udica-0.2.1-2.module+el8.2.0+7615+180dc822.noarch.rpm

aarch64:
buildah-1.11.6-8.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
buildah-tests-1.11.6-8.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
cockpit-podman-12-1.module+el8.2.0+7615+180dc822.noarch.rpm
conmon-2.0.6-1.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
containernetworking-plugins-0.8.3-5.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
containers-common-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
container-selinux-2.124.0-1.module+el8.2.0+7615+180dc822.noarch.rpm
crit-3.12-9.module+el8.2.0+7615+180dc822.aarch64.rpm
criu-3.12-9.module+el8.2.0+7615+180dc822.aarch64.rpm
fuse-overlayfs-0.7.2-5.module+el8.2.0+7615+180dc822.aarch64.rpm
podman-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
podman-docker-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.noarch.rpm
podman-remote-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
podman-tests-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
python3-criu-3.12-9.module+el8.2.0+7615+180dc822.aarch64.rpm
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.2.0+7615+180dc822.noarch.rpm
runc-1.0.0-65.rc10.module+el8.2.0+7615+180dc822.aarch64.rpm
skopeo-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
skopeo-tests-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.aarch64.rpm
slirp4netns-0.4.2-3.git21fdece.module+el8.2.0+7615+180dc822.aarch64.rpm
udica-0.2.1-2.module+el8.2.0+7615+180dc822.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/buildah-1.11.6-8.0.1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/cockpit-podman-12-1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/conmon-2.0.6-1.0.1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/containernetworking-plugins-0.8.3-5.0.1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/container-selinux-2.124.0-1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/criu-3.12-9.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/fuse-overlayfs-0.7.2-5.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/podman-1.6.4-11.0.1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/runc-1.0.0-65.rc10.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/skopeo-0.1.40-11.0.1.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/slirp4netns-0.4.2-3.git21fdece.module+el8.2.0+7615+180dc822.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/udica-0.2.1-2.module+el8.2.0+7615+180dc822.src.rpm



Description of changes:

buildah
[1.11.6-8.0.1]
- Fixes troubles with oracle registry login [Orabug: 29937283]

[1.11.6-8]
- fix "CVE-2020-10696 buildah: crafted input tar file may lead to local 
file overwriting during image build process"
- Resolves: #1817742

[1.11.6-7]
- fix "COPY command takes long time with buildah"
- Resolves: #1806120

cockpit-podman
[12-1]
- Configure CPU share for system containers
- Translation updates

conmon
[2:2.0.6-1.0.1]
- Remove upstream references [Orabug: 30871880]

[2:2.0.6-1]
- update to 2.0.6
- Related: RHELPLAN-25139

containernetworking-plugins
[0.8.3-5.0.1]
- Disable debuginfo

[0.8.3-5]
- compile with no_openssl
- Related: RHELPLAN-25139

podman
[1.6.4-11.0.1]
- delivering fix for [Orabug: 29874238] by Nikita Gerasimov 
<nikita.gerasimov at oracle.com>

[1.6.4-11]
- fix 'CVE-2020-10696 buildah: crafted input tar file may lead to local 
file overwriting during image build process'
- Resolves: #1817747

python-podman-api
[1.2.0-0.2.gitd0a45fe]
- revert update to 1.6.0 due to new python3-pbr dependency which
is not in RHEL
- Related: RHELPLAN-25139

runc
[1.0.0-65.rc10]
- address CVE-2019-19921 by updating to rc10
- Resolves: #1801887

skopeo
[0.1.40-11.0.1]
- Add oracle registry into the conf file [Orabug: 29845934 31306708]
- Fix oracle registry login issues [Orabug: 29937192]

[1:0.1.40-11]
- add docker.io into the default registry list
- Related: #1810053





More information about the El-errata mailing list