Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Products & Services

    Products

    Support

    • Production Support
    • Development Support
    • Product Life Cycles

    Services

    • Consulting
    • Technical Account Management
    • Training & Certifications

    Documentation

    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    All Documentation

    Ecosystem Catalog

    • Red Hat Partner Ecosystem
    • Partner Resources
  • Tools

    Tools

    • Troubleshoot a product issue
    • Packages
    • Errata

    Customer Portal Labs

    • Configuration
    • Deployment
    • Security
    • Troubleshoot
    All labs

    Red Hat Insights

    Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

    Learn More
    Go to Insights
  • Security

    Red Hat Product Security Center

    Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

    Product Security Center

    Security Updates

    • Security Advisories
    • Red Hat CVE Database
    • Security Labs

    Keep your systems secure with Red Hat's specialized responses to security vulnerabilities.

    View Responses

    Resources

    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community

    Customer Portal Community

    • Discussions
    • Private Groups
    Community Activity

    Customer Events

    • Red Hat Convergence
    • Red Hat Summit

    Stories

    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
Or troubleshoot an issue.

Select Your Language

  • English
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Integration
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
  • Red Hat JBoss Data Virtualization
  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
All Products
Red Hat Product Errata RHSA-2022:8008 - Security Advisory
Issued:
2022-11-15
Updated:
2022-11-15

RHSA-2022:8008 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: buildah security and bug fix update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for buildah is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.

Security Fix(es):

  • containers/storage: DoS via malicious image (CVE-2021-20291)
  • golang: net: lookup functions may return invalid host names (CVE-2021-33195)
  • golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)
  • golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents (CVE-2021-33198)
  • golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)
  • podman: possible information disclosure and modification (CVE-2022-2989)
  • buildah: possible information disclosure and modification (CVE-2022-2990)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 1939485 - CVE-2021-20291 containers/storage: DoS via malicious image
  • BZ - 1989564 - CVE-2021-33195 golang: net: lookup functions may return invalid host names
  • BZ - 1989570 - CVE-2021-33197 golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty
  • BZ - 1989575 - CVE-2021-33198 golang: math/big.Rat: may cause a panic or an unrecoverable fatal error if passed inputs with very large exponents
  • BZ - 2064702 - CVE-2022-27191 golang: crash in a golang.org/x/crypto/ssh server
  • BZ - 2081835 - networking is broken when building containers due to missing container networking package dependencies
  • BZ - 2121445 - CVE-2022-2989 podman: possible information disclosure and modification
  • BZ - 2121453 - CVE-2022-2990 buildah: possible information disclosure and modification

CVEs

  • CVE-2021-20291
  • CVE-2021-33195
  • CVE-2021-33197
  • CVE-2021-33198
  • CVE-2022-2989
  • CVE-2022-2990
  • CVE-2022-27191

References

  • https://access.redhat.com/security/updates/classification/#moderate
  • https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
buildah-1.27.0-2.el9.src.rpm SHA-256: 06ec618ff51a64900a0d856f6fed79947335f3011559fd7278c130eaef73a635
x86_64
buildah-1.27.0-2.el9.x86_64.rpm SHA-256: b9f388eed9275e44f0e95f0be935f864e88d16dca8774152e7264d318988b454
buildah-debuginfo-1.27.0-2.el9.x86_64.rpm SHA-256: dcbf32c97d18902a0547e72daf1bfc1aef8775650aec6348e63f4ca222a4e735
buildah-debugsource-1.27.0-2.el9.x86_64.rpm SHA-256: 974fe9dc4cfac4a7a488880373013119d8fb34e716b48988cf46f36624187b9e
buildah-tests-1.27.0-2.el9.x86_64.rpm SHA-256: a90c9440a7ea5cf55371954a8f97e6f48005af8901c91c43b539e968d1c16a76
buildah-tests-debuginfo-1.27.0-2.el9.x86_64.rpm SHA-256: 6bb4246f3631699fa4027895dd70730b233aca5285bc996d925b8dd1984f15f8

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
buildah-1.27.0-2.el9.src.rpm SHA-256: 06ec618ff51a64900a0d856f6fed79947335f3011559fd7278c130eaef73a635
s390x
buildah-1.27.0-2.el9.s390x.rpm SHA-256: d73983a0211b3500b6623effaccfda26e87e5950e73b3fdc39732c9bc5623828
buildah-debuginfo-1.27.0-2.el9.s390x.rpm SHA-256: da5c65316e7c91be136e422e93a3f84fab566a4ecf208c7069763489bfd400d6
buildah-debugsource-1.27.0-2.el9.s390x.rpm SHA-256: 75f0749670cd58983c2efa13805110a5137f0cffb897dc846e71640b4ef3ecae
buildah-tests-1.27.0-2.el9.s390x.rpm SHA-256: 9aaaf210c7c89173143eb1197a5b699827cb45ebcc35370d719a894e294800d5
buildah-tests-debuginfo-1.27.0-2.el9.s390x.rpm SHA-256: c7d976ff72800fd7d270af6d7bcbbacb7f55538ec85c79487b9444b85e879bd8

Red Hat Enterprise Linux for Power, little endian 9

SRPM
buildah-1.27.0-2.el9.src.rpm SHA-256: 06ec618ff51a64900a0d856f6fed79947335f3011559fd7278c130eaef73a635
ppc64le
buildah-1.27.0-2.el9.ppc64le.rpm SHA-256: c2b4a0aeabd6ce024a517bba79dca0a7106b61df1d528a7e364af740c0fc7a00
buildah-debuginfo-1.27.0-2.el9.ppc64le.rpm SHA-256: 974cc38333952d0e06aaf2462bf8534261252f4ec566b8a09eb9b2eec27e38e8
buildah-debugsource-1.27.0-2.el9.ppc64le.rpm SHA-256: 788553ab3cd9f810dbad7d37236a9f15d41caf26b6b4d92b24c3dcd225441dcc
buildah-tests-1.27.0-2.el9.ppc64le.rpm SHA-256: 6f3f930bb5442bd15b2c70e3f85d8c80961d8a6727d813141a3554f9ee7e33b7
buildah-tests-debuginfo-1.27.0-2.el9.ppc64le.rpm SHA-256: a03c810179572b763d3f99b76d25415ec4183bda98e7a7e41728c82692288576

Red Hat Enterprise Linux for ARM 64 9

SRPM
buildah-1.27.0-2.el9.src.rpm SHA-256: 06ec618ff51a64900a0d856f6fed79947335f3011559fd7278c130eaef73a635
aarch64
buildah-1.27.0-2.el9.aarch64.rpm SHA-256: 776f5a88315ee9128a11b5010bf493bee29f3542df06e9aeb6697d70796b4d6a
buildah-debuginfo-1.27.0-2.el9.aarch64.rpm SHA-256: a60828504119202ff9080e31b3cafb81b5830eb33121b215bda33999657569a6
buildah-debugsource-1.27.0-2.el9.aarch64.rpm SHA-256: 77c44a15e1324b8ad16ef0c46135febc9e16e118024289c7801e5c61925393f8
buildah-tests-1.27.0-2.el9.aarch64.rpm SHA-256: 7a335df370ed295ee6cd247e166700d1309fddda70817ca9b3fce1e0d7d2ad19
buildah-tests-debuginfo-1.27.0-2.el9.aarch64.rpm SHA-256: eb295b366e1a72d9c26204562fedd754982d915226abc745edb0e36a9b698d33

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2023 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter