- Issued:
- 2019-07-29
- Updated:
- 2019-07-29
RHSA-2019:1910 - Security Advisory
Synopsis
Moderate: docker security and bug fix update
Type/Severity
Security Advisory: Moderate
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for docker is now available for Red Hat Enterprise Linux 7 Extras.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Docker is an open-source engine that automates the deployment of any application as a lightweight, portable, self-sufficient container that runs virtually anywhere.
Security Fix(es):
- docker: symlink-exchange race attacks in docker cp (CVE-2018-15664)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- slowness of system shutdown when containers are being stopped - dockerd is unable to communicate with rhel-push-plugin (BZ#1714032)
- journald Log() in dockerd causes nil pointer dereference when PutMessage() is called before reading msg.Source (BZ#1720363)
- regression: docker cp: Rel: can't make /..../a relative to a (BZ#1723491)
- Regression: docker cp: can no longer pull image files (BZ#1727488)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Enterprise Linux Server 7 x86_64
- Red Hat Enterprise Linux for IBM z Systems 7 s390x
- Red Hat Enterprise Linux for Power, little endian 7 ppc64le
- Red Hat Enterprise Linux for ARM 64 7 aarch64
- Red Hat Enterprise Linux for Power 9 7 ppc64le
- Red Hat Enterprise Linux for IBM System z (Structure A) 7 s390x
Fixes
- BZ - 1714722 - CVE-2018-15664 docker: symlink-exchange race attacks in docker cp
- BZ - 1723491 - regression: docker cp: Rel: can't make /..../a relative to a
CVEs
Red Hat Enterprise Linux Server 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
x86_64 | |
docker-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: bf62c28dca95326c3573a23f34bdfa8e87672cd9f4403d3bc92f7b0383105113 |
docker-client-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 0d2c703b3e810194513b731e917abd73bc888aa64858504501a62fdd8034664b |
docker-common-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: c529177f6d9e360ba91514ea103a2612493280c0ed4be4e1d951ede6d8111f7a |
docker-debuginfo-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 2bb1d9f2d2d1bdae3cd1a26549b7bf9a212cf17c70a4bb33c72e42e9d91d4ae4 |
docker-logrotate-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 670330b0dd276a2dd2af4a0b357c71b0d4a4c91efd6d97e603a208a5891718fa |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 37e311e23f08eb42162214ad003a0287609d63c2674f161b52e4267a276d4858 |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: a5ccc345626f51f14b7ecbdb2a16277a14eaad82bbb6e8382622ed7c510e2225 |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 89b05c627cb8ecc4e500058ba59d48f22c464cc9a1722ba2d96b4c6487ff3663 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.x86_64.rpm | SHA-256: 9cd4b2219a9cc5bfe96ed3a5035d30218d2b309c27b549310b9a59ed5b13a956 |
Red Hat Enterprise Linux for IBM z Systems 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
s390x | |
docker-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 24a79554f02140ec0df366d279d90a315ca6038c2c3b2659537737402654d713 |
docker-client-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 273c326050ab4e36ee7a5e427ce298ab9bd3abf76127c9afb1abf8bc1228ed3e |
docker-common-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 7fd184930e72f1833bd3c7d89ece3737c7dc6d6b6e6eefee4ae31d6096e7ca9b |
docker-debuginfo-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 2c4b657d6ee687b8f0a71fc83bfdc549f26dd009e4c1ea9c8413ba4dac177d29 |
docker-logrotate-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 9fd01e974b161bc65c71974a297531f1af10b373ca8266872d9efb96f2989024 |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: edc8e9b1b011234d5cf68f02ade3b4027bd6a3057a97e6d1113e022a69bb0e79 |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 723d24343a46a056e9cf04775a62b1e583fe32c44aad16e0b43f8755a98499c4 |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: c3a9704c024229a6e579d21d46075070813c4b0645483dd17d503d5e1db9a1f9 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 11aa6c616f8df2876a2c4c8f7cde2383baeb5995b744e5c9abac932e6766b05d |
Red Hat Enterprise Linux for Power, little endian 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
ppc64le | |
docker-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: d5456570b9c0bea587e79ebcf93c91a89183f8b6da7ff6748bc44dd2520c4573 |
docker-client-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 94bdb6b98a704b41d3ea03760a8a15dc41a974a10b239e167d83501bb641686f |
docker-common-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 6bdca5dc3d62b5524c52ea8f73536cb1104e2b4ea4349cb67ec28909f5239276 |
docker-debuginfo-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 45122c1c47b8b3320c8d7980de86100f20df72d2d3a0336296cdfe8f79b6fa06 |
docker-logrotate-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 01d3cf218cc4b17ec4bfa69877510546f4bc632dd7fed5e5b4f639431cb4fa04 |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 32e1bd8d0d3a298cd853ed8fda2b401e121fdb13f7829809b23b8d654798a7aa |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 879a94457f4c29e3af555d5b832085d9748d4c11d1ffebea91d9e1ecbc50a57d |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 0d69c640b534a8c64c760920a024dc0016ffea30910e7d0e8fd4f40a9ef76c57 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: e44efdc02b0b7182fdca24f974e96fc985950da15c9b62b082d579e9052d667d |
Red Hat Enterprise Linux for ARM 64 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
aarch64 | |
docker-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: 2382dc9e093f8b281689c4e7009e28ed6c319cb467049a3e9e7bd83d324a7fa8 |
docker-client-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: 7f38777c78c649f87a2b1c19dbeb25ae1ec2983c8f027a9cd932007137dbeb5e |
docker-common-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: 14cb4b54b9ed6cf6405b610d358336f0a0438fdba20a7cd93d9172b262b36cb9 |
docker-debuginfo-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: fbad81b50a6c005d2c9a7dd57de53861f48177f37966233b19c4ee6b4aee6d69 |
docker-logrotate-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: d5c332395bf647378fdbc54817d965d97be961708177fa77062a0dbfb0f8179b |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: 51905fcc660299cefd1f8ecbba822702da1f9b5966e303dc53abd985a597d3db |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: a354488f753aa83a96cebaed9a000bf5b4381a6d3808bc1f7ca3205ab520fae2 |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: ffbaf308ca96e6219734150d92d5168e664501cfcd73f41330e81d74f604d4b7 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.aarch64.rpm | SHA-256: 3883a7a1a2d8a86e107b01ae440cb300780ef6e46d9a99ab7bedf52dce2d8302 |
Red Hat Enterprise Linux for Power 9 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
ppc64le | |
docker-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: d5456570b9c0bea587e79ebcf93c91a89183f8b6da7ff6748bc44dd2520c4573 |
docker-client-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 94bdb6b98a704b41d3ea03760a8a15dc41a974a10b239e167d83501bb641686f |
docker-common-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 6bdca5dc3d62b5524c52ea8f73536cb1104e2b4ea4349cb67ec28909f5239276 |
docker-debuginfo-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 45122c1c47b8b3320c8d7980de86100f20df72d2d3a0336296cdfe8f79b6fa06 |
docker-logrotate-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 01d3cf218cc4b17ec4bfa69877510546f4bc632dd7fed5e5b4f639431cb4fa04 |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 32e1bd8d0d3a298cd853ed8fda2b401e121fdb13f7829809b23b8d654798a7aa |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 879a94457f4c29e3af555d5b832085d9748d4c11d1ffebea91d9e1ecbc50a57d |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: 0d69c640b534a8c64c760920a024dc0016ffea30910e7d0e8fd4f40a9ef76c57 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.ppc64le.rpm | SHA-256: e44efdc02b0b7182fdca24f974e96fc985950da15c9b62b082d579e9052d667d |
Red Hat Enterprise Linux for IBM System z (Structure A) 7
SRPM | |
---|---|
docker-1.13.1-102.git7f2769b.el7.src.rpm | SHA-256: 6510663f69b483e3e976ca4eccd04153d2e6bd5d5affbbea01adb2552be0de02 |
s390x | |
docker-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 24a79554f02140ec0df366d279d90a315ca6038c2c3b2659537737402654d713 |
docker-client-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 273c326050ab4e36ee7a5e427ce298ab9bd3abf76127c9afb1abf8bc1228ed3e |
docker-common-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 7fd184930e72f1833bd3c7d89ece3737c7dc6d6b6e6eefee4ae31d6096e7ca9b |
docker-debuginfo-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 2c4b657d6ee687b8f0a71fc83bfdc549f26dd009e4c1ea9c8413ba4dac177d29 |
docker-logrotate-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 9fd01e974b161bc65c71974a297531f1af10b373ca8266872d9efb96f2989024 |
docker-lvm-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: edc8e9b1b011234d5cf68f02ade3b4027bd6a3057a97e6d1113e022a69bb0e79 |
docker-novolume-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 723d24343a46a056e9cf04775a62b1e583fe32c44aad16e0b43f8755a98499c4 |
docker-rhel-push-plugin-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: c3a9704c024229a6e579d21d46075070813c4b0645483dd17d503d5e1db9a1f9 |
docker-v1.10-migrator-1.13.1-102.git7f2769b.el7.s390x.rpm | SHA-256: 11aa6c616f8df2876a2c4c8f7cde2383baeb5995b744e5c9abac932e6766b05d |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.