VYPR

rpm package

almalinux/criu-devel

pkg:rpm/almalinux/criu-devel

Vulnerabilities (105)

  • CVE-2022-21698HigFeb 15, 2022
    affected < 3.15-3.module_el8.6.0+2751+06427ca3fixed 3.15-3.module_el8.6.0+2751+06427ca3

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde

  • CVE-2021-4024MedDec 23, 2021
    affected < 3.18-5.module_el8.10.0+3876+e55593a8fixed 3.18-5.module_el8.10.0+3876+e55593a8

    A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op

  • CVE-2021-33198HigAug 2, 2021
    affected < 3.18-5.module_el8.10.0+3876+e55593a8fixed 3.18-5.module_el8.10.0+3876+e55593a8

    In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

  • CVE-2021-20291MedApr 1, 2021
    affected < 3.15-3.module_el8.6.0+2751+06427ca3fixed 3.15-3.module_el8.6.0+2751+06427ca3

    A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation wh

  • CVE-2019-19921HigFeb 12, 2020
    affected < 3.15-3.module_el8.6.0+2877+8e437bf5fixed 3.15-3.module_el8.6.0+2877+8e437bf5

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul

Page 6 of 6