MGASA-2023-0213

Advisory lineage Upstream: 13 Downstream: 0
Published: 07 Jul 2023, 05:54
Last modified:16 Apr 2026, 04:43

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Jul 2023, 05:54
Published
Vulnerability first disclosed
16 Apr 2026, 04:43
Last Modified
Vulnerability information updated

Description

Updated skopeo/buildah/podman packages fix security vulnerability Information disclosure flaw was found in Buildah (CVE-2021-3602) podman allows forwarding hosts ports to vm from within vm (CVE-2021-4024) Allows use "../" separators in containernetworking/cni to reference binaries such as 'reboot' in network configuration (CVE-2021-20206) github.com/containers/storage ddos via crafted tar file (CVE-2021-20291) buildah improper checking of X.509 certificate (CVE-2021-34558) buildah improper Content-Type checking (CVE-2021-41190) podman privilege escalation (CVE-2022-1227) podman incorrect handling of the supplementary groups (CVE-2022-2989) buildah incorrect handling of the supplementary groups (CVE-2022-2990) skopeo/podman Denial of Service through unbounded cardinality, and potential memory exhaustion (CVE-2022-21698) buildah/podman AddHostKey denail of service (CVE-2022-27191) podman inheritable file capabilities (CVE-2022-27649) buildah inheritable file capabilities (CVE-2022-27651)

Affected Systems

  • mageiabuildah

    < 1.30.0-1.mga8

  • mageiaconmon

    < 2.1.5-1.mga8

  • mageiapodman

    < 4.5.1-1.mga8

  • mageiaskopeo

    < 1.12.0-2.mga8

References (46)