El-errata: ELSA-2020-1379 Important: Oracle Linux 8 container-tools:ol8 security and bug fix update
Oracle Linux Security Advisory ELSA-2020-1379
http://linux.oracle.com/errata/ELSA-2020-1379.html
The following updated rpms for Oracle Linux 8 have been uploaded to the
Unbreakable Linux Network:
x86_64:
buildah-1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079.x86_64.rpm
buildah-tests-1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079.x86_64.rpm
cockpit-podman-11-1.module+el8.1.1+5502+fbec5cc6.noarch.rpm
conmon-2.0.6-1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
container-selinux-2.124.0-1.module+el8.1.1+5502+fbec5cc6.noarch.rpm
containernetworking-plugins-0.8.3-4.0.1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
containers-common-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
fuse-overlayfs-0.7.2-5.module+el8.1.1+5573+1c3f6079.x86_64.rpm
podman-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.x86_64.rpm
podman-docker-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.noarch.rpm
podman-manpages-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.noarch.rpm
podman-remote-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.x86_64.rpm
podman-tests-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.x86_64.rpm
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.1.1+5502+fbec5cc6.noarch.rpm
runc-1.0.0-64.rc9.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
skopeo-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
skopeo-tests-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
slirp4netns-0.4.2-3.git21fdece.module+el8.1.1+5573+1c3f6079.x86_64.rpm
toolbox-0.0.4-1.module+el8.1.1+5502+fbec5cc6.x86_64.rpm
udica-0.2.1-2.module+el8.1.1+5502+fbec5cc6.noarch.rpm
aarch64:
buildah-1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079.aarch64.rpm
buildah-tests-1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079.aarch64.rpm
cockpit-podman-11-1.module+el8.1.1+5502+fbec5cc6.noarch.rpm
conmon-2.0.6-1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
container-selinux-2.124.0-1.module+el8.1.1+5502+fbec5cc6.noarch.rpm
containernetworking-plugins-0.8.3-4.0.1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
containers-common-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
fuse-overlayfs-0.7.2-5.module+el8.1.1+5573+1c3f6079.aarch64.rpm
podman-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.aarch64.rpm
podman-docker-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.noarch.rpm
podman-manpages-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.noarch.rpm
podman-remote-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.aarch64.rpm
podman-tests-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.aarch64.rpm
python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.1.1+5502+fbec5cc6.noarch.rpm
runc-1.0.0-64.rc9.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
skopeo-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
skopeo-tests-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
slirp4netns-0.4.2-3.git21fdece.module+el8.1.1+5573+1c3f6079.aarch64.rpm
toolbox-0.0.4-1.module+el8.1.1+5502+fbec5cc6.aarch64.rpm
udica-0.2.1-2.module+el8.1.1+5502+fbec5cc6.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/buildah-1.11.6-6.0.1.module+el8.1.1+5573+1c3f6079.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/cockpit-podman-11-1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/conmon-2.0.6-1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/container-selinux-2.124.0-1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/containernetworking-plugins-0.8.3-4.0.1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/fuse-overlayfs-0.7.2-5.module+el8.1.1+5573+1c3f6079.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/podman-1.6.4-4.0.1.module+el8.1.1+5573+1c3f6079.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/python-podman-api-1.2.0-0.2.gitd0a45fe.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/runc-1.0.0-64.rc9.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/skopeo-0.1.40-8.0.1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/slirp4netns-0.4.2-3.git21fdece.module+el8.1.1+5573+1c3f6079.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/toolbox-0.0.4-1.module+el8.1.1+5502+fbec5cc6.src.rpm
http://oss.oracle.com/ol8/SRPMS-updates/udica-0.2.1-2.module+el8.1.1+5502+fbec5cc6.src.rpm
Description of changes:
buildah
[1.11.6-6.0.1]
- Fixes troubles with oracle registry login [Orabug: 29937283]
[1.11.6-6]
- fix "COPY command takes long time with buildah"
- Resolves: #1806119
[1.11.6-5]
- fix "Podman support for FIPS Mode requires a bind mount inside the
container"
- Resolves: #1804188
cockpit-podman
[11-1]
- Fix Alert notification in Image Search Modal
- Allow more than a single Error Notification for Container action errors
- Various Alert cleanups
- Translation updates
- Related: RHELPLAN-25138
[10-1]
- Support for user containers
- Show list of containers that use given image
- Show placeholder while loading containers and images
- Fix setting memory limit - bug 1732713
- Add container Terminal - bug 1703245
- Related: RHELPLAN-25138
conmon
[2:2.0.6-1]
- update to 2.0.6
- Related: RHELPLAN-25138
[2:2.0.5-1]
- update to 2.0.5
- Related: RHELPLAN-25138
[2:2.0.4-1]
- update to 2.0.4 bugfix release
- Related: RHELPLAN-25138
[2:2.0.3-2.giteb5fa88]
- BR: systemd-devel
- Related: RHELPLAN-25138
[2:2.0.3-1.giteb5fa88]
- update to 2.0.3
[2:2.0.2-0.1.dev.git422ce21]
- build latest upstream master
[2:2.0.0-2]
- remove BR: go-md2man since no manpages yet
container-selinux
[2:2.124.0-1]
- update to 2.124.0
- Related: RHELPLAN-25138
fuse-overlayfs
[0.7.2-5]
- be sure to work properly also with older rhel8 kernels, thanks to
Giuseppe Scrivano
- Resolves: #1803495
[0.7.2-4]
- latest iteration of segfault fix patch, thanks to Giuseppe Scrivano
- Resolves: #1803495
[0.7.2-3]
- fix "fuse-overlayfs segfault"
- Resolves: #1805016
[0.7.2-2]
- fix "useradd and groupadd fail under rootless Buildah and podman"
- Resolves: #1803495
podman
[1.6.4-4.0.1]
- delivering fix for [Orabug: 29874238] by Nikita Gerasimov
[1.6.4-4]
- fix "podman (1.6.4) rhel 8.1 no route to host from inside container"
- Resolves: #1806900
[1.6.4-3]
- fix "Podman support for FIPS Mode requires a bind mount inside the
container"
- Resolves: #1804194
python-podman-api
[1.2.0-0.2.gitd0a45fe]
- revert update to 1.6.0 due to new python3-pbr dependency which
is not in RHEL
- Related: RHELPLAN-25138
runc
[1.0.0-64.rc9]
- use no_openssl in BUILDTAGS (no vendored crypto in runc)
- Related: RHELPLAN-25138
[1.0.0-63.rc9]
- be sure to use golang >= 1.12.12-4
- Related: RHELPLAN-25138
[1.0.0-62.rc9]
- rebuild because of CVE-2019-9512 and CVE-2019-9514
- Related: RHELPLAN-25138
[1.0.0-61.rc9]
- update to runc 1.0.0-rc9 release
- amend golang deps
- fixes CVE-2019-16884
[1.0.0-60.rc8]
- Resolves: #1721247 - enable fips mode
[1.0.0-59.rc8]
- Resolves: #1720654 - rebase to v1.0.0-rc8
[1.0.0-57.rc5.dev.git2abd837]
- Resolves: #1693424 - podman rootless: cannot specify gid= mount options
skopeo
[0.1.40-8.0.1]
- Add oracle registry into the conf file [Orabug: 29845934]
- Fix oracle registry login issues [Orabug: 29937192]
[1:0.1.40-8]
- change the search order of registries and remove quay.io (#1784267)
slirp4netns
[0.4.2-3.git21fdece]
- Fix CVE-2020-8608
- Related: RHELPLAN-25138
toolbox
[0.0.4-1.el8]
- Update for rhel8.1 container-tools module
udica
[0.2.1-2]
- initial import to container-tools 8.2.0
- Related: RHELPLAN-25139
A container-tools:ol8 security and bug fix update has been released for Oracle Linux 8.