Fedora Linux 8716 Published by

A buildah security update has been released for Fedora 35.



SECURITY: Fedora 35 Update: buildah-1.23.4-1.fc35


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-396c568c5e
2022-06-11 01:41:38.477598
--------------------------------------------------------------------------------

Name : buildah
Product : Fedora 35
Version : 1.23.4
Release : 1.fc35
URL :   https://buildah.io
Summary : A command line tool used for creating OCI Images
Description :
The buildah package provides a command line tool which can be used to
* create a working container from scratch
or
* create a working container from an image as a starting point
* mount/umount a working container's root file system for manipulation
* save container's root file system layer to create a new image
* delete a working container or an image

--------------------------------------------------------------------------------
Update Information:

bump to v1.23.4, security fix for CVE-2022-21698 ---- Add missing container
networking dependencies (#2081834)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 2 2022 Lokesh Mandvekar 1.23.4-1
- bump to v.123.4
* Wed May 4 2022 Neal Gompa 1.23.3-3
- Add missing container networking dependencies (#2081834)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2067422 - CVE-2022-21698 buildah: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-35]
  https://bugzilla.redhat.com/show_bug.cgi?id=2067422
[ 2 ] Bug #2081834 - networking is broken when building containers due to missing container networking package dependencies
  https://bugzilla.redhat.com/show_bug.cgi?id=2081834
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-396c568c5e' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________