RHEL 8 : container-tools:rhel8 (RHSA-2021:4154)

medium Nessus Plugin ID 155085

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2021:4154 advisory.

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

* buildah: Host environment variables leaked in build container when using chroot isolation (CVE-2021-3602)

* containers/storage: DoS via malicious image (CVE-2021-20291)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1939485

https://bugzilla.redhat.com/show_bug.cgi?id=1941380

https://bugzilla.redhat.com/show_bug.cgi?id=1947432

https://bugzilla.redhat.com/show_bug.cgi?id=1947999

https://bugzilla.redhat.com/show_bug.cgi?id=1952204

https://bugzilla.redhat.com/show_bug.cgi?id=1952698

https://bugzilla.redhat.com/show_bug.cgi?id=1957299

https://bugzilla.redhat.com/show_bug.cgi?id=1957840

https://bugzilla.redhat.com/show_bug.cgi?id=1957904

https://bugzilla.redhat.com/show_bug.cgi?id=1977673

https://bugzilla.redhat.com/show_bug.cgi?id=1978415

https://bugzilla.redhat.com/show_bug.cgi?id=1978556

https://bugzilla.redhat.com/show_bug.cgi?id=1978647

https://bugzilla.redhat.com/show_bug.cgi?id=1979497

https://bugzilla.redhat.com/show_bug.cgi?id=1980212

https://bugzilla.redhat.com/show_bug.cgi?id=1982593

https://bugzilla.redhat.com/show_bug.cgi?id=1982762

https://bugzilla.redhat.com/show_bug.cgi?id=1985499

https://bugzilla.redhat.com/show_bug.cgi?id=1985905

http://www.nessus.org/u?7240878e

http://www.nessus.org/u?ab4f2e56

https://access.redhat.com/security/updates/classification/#moderate

https://access.redhat.com/errata/RHSA-2021:4154

https://bugzilla.redhat.com/show_bug.cgi?id=1914687

https://bugzilla.redhat.com/show_bug.cgi?id=1928935

https://bugzilla.redhat.com/show_bug.cgi?id=1932399

https://bugzilla.redhat.com/show_bug.cgi?id=1933775

https://bugzilla.redhat.com/show_bug.cgi?id=1933776

https://bugzilla.redhat.com/show_bug.cgi?id=1934415

https://bugzilla.redhat.com/show_bug.cgi?id=1934480

https://bugzilla.redhat.com/show_bug.cgi?id=1937641

https://bugzilla.redhat.com/show_bug.cgi?id=1937830

https://bugzilla.redhat.com/show_bug.cgi?id=1940037

https://bugzilla.redhat.com/show_bug.cgi?id=1940054

https://bugzilla.redhat.com/show_bug.cgi?id=1940082

https://bugzilla.redhat.com/show_bug.cgi?id=1940493

https://bugzilla.redhat.com/show_bug.cgi?id=1958353

https://bugzilla.redhat.com/show_bug.cgi?id=1960948

https://bugzilla.redhat.com/show_bug.cgi?id=1966538

https://bugzilla.redhat.com/show_bug.cgi?id=1966872

https://bugzilla.redhat.com/show_bug.cgi?id=1969264

https://bugzilla.redhat.com/show_bug.cgi?id=1972150

https://bugzilla.redhat.com/show_bug.cgi?id=1972209

https://bugzilla.redhat.com/show_bug.cgi?id=1972211

https://bugzilla.redhat.com/show_bug.cgi?id=1972282

https://bugzilla.redhat.com/show_bug.cgi?id=1972648

https://bugzilla.redhat.com/show_bug.cgi?id=1973418

https://bugzilla.redhat.com/show_bug.cgi?id=1976283

https://bugzilla.redhat.com/show_bug.cgi?id=1977280

https://bugzilla.redhat.com/show_bug.cgi?id=1987049

https://bugzilla.redhat.com/show_bug.cgi?id=1993209

https://bugzilla.redhat.com/show_bug.cgi?id=1993249

https://bugzilla.redhat.com/show_bug.cgi?id=1995041

https://bugzilla.redhat.com/show_bug.cgi?id=1998191

https://bugzilla.redhat.com/show_bug.cgi?id=1999144

https://bugzilla.redhat.com/show_bug.cgi?id=2000943

https://bugzilla.redhat.com/show_bug.cgi?id=2004562

https://bugzilla.redhat.com/show_bug.cgi?id=2005018

Plugin Details

Severity: Medium

ID: 155085

File Name: redhat-RHSA-2021-4154.nasl

Version: 1.11

Type: local

Agent: unix

Published: 11/11/2021

Updated: 11/7/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Low

Base Score: 1.9

Temporal Score: 1.5

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-3602

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:conmon, p-cpe:/a:redhat:enterprise_linux:containers-common, p-cpe:/a:redhat:enterprise_linux:crun, p-cpe:/a:redhat:enterprise_linux:python-podman, p-cpe:/a:redhat:enterprise_linux:podman-gvproxy, p-cpe:/a:redhat:enterprise_linux:buildah-tests, p-cpe:/a:redhat:enterprise_linux:buildah, p-cpe:/a:redhat:enterprise_linux:crit, p-cpe:/a:redhat:enterprise_linux:podman-remote, p-cpe:/a:redhat:enterprise_linux:podman, p-cpe:/a:redhat:enterprise_linux:podman-catatonit, p-cpe:/a:redhat:enterprise_linux:libslirp-devel, p-cpe:/a:redhat:enterprise_linux:podman-plugins, p-cpe:/a:redhat:enterprise_linux:podman-tests, p-cpe:/a:redhat:enterprise_linux:python3-podman, p-cpe:/a:redhat:enterprise_linux:criu-libs, p-cpe:/a:redhat:enterprise_linux:containernetworking-plugins, p-cpe:/a:redhat:enterprise_linux:container-selinux, p-cpe:/a:redhat:enterprise_linux:skopeo-tests, p-cpe:/a:redhat:enterprise_linux:podman-docker, p-cpe:/a:redhat:enterprise_linux:oci-seccomp-bpf-hook, p-cpe:/a:redhat:enterprise_linux:runc, p-cpe:/a:redhat:enterprise_linux:toolbox-tests, p-cpe:/a:redhat:enterprise_linux:skopeo, p-cpe:/a:redhat:enterprise_linux:criu-devel, cpe:/o:redhat:enterprise_linux:8, p-cpe:/a:redhat:enterprise_linux:udica, p-cpe:/a:redhat:enterprise_linux:toolbox, p-cpe:/a:redhat:enterprise_linux:libslirp, p-cpe:/a:redhat:enterprise_linux:cockpit-podman, p-cpe:/a:redhat:enterprise_linux:criu, p-cpe:/a:redhat:enterprise_linux:slirp4netns, p-cpe:/a:redhat:enterprise_linux:fuse-overlayfs, p-cpe:/a:redhat:enterprise_linux:python3-criu

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/9/2021

Vulnerability Publication Date: 4/1/2021

Reference Information

CVE: CVE-2021-20291, CVE-2021-3602

CWE: 200, 667

RHSA: 2021:4154