rpm package
almalinux/libslirp-devel
pkg:rpm/almalinux/libslirp-devel
Vulnerabilities (112)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-21698 | Hig | 7.5 | < 4.4.0-1.module_el8.6.0+2877+8e437bf5 | 4.4.0-1.module_el8.6.0+2877+8e437bf5 | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde | |
| CVE-2021-4024 | Med | 6.5 | < 4.4.0-2.module_el8.10.0+3909+6e1c1eb7 | 4.4.0-2.module_el8.10.0+3909+6e1c1eb7 | Dec 23, 2021 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op | |
| CVE-2021-33198 | Hig | 7.5 | < 4.4.0-2.module_el8.10.0+3909+6e1c1eb7 | 4.4.0-2.module_el8.10.0+3909+6e1c1eb7 | Aug 2, 2021 | In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method. | |
| CVE-2021-30465 | Hig | 8.5 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | May 27, 2021 | runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on | |
| CVE-2021-20291 | Med | 6.5 | < 4.4.0-1.module_el8.5.0+2613+1b78b731 | 4.4.0-1.module_el8.5.0+2613+1b78b731 | Apr 1, 2021 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation wh | |
| CVE-2021-20199 | Med | 5.9 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Feb 2, 2021 | Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podma | |
| CVE-2020-29652 | Hig | 7.5 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Dec 17, 2020 | A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers. | |
| CVE-2020-14370 | Med | 5.3 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Sep 23, 2020 | An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container wil | |
| CVE-2020-10756 | Med | 6.5 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Jul 9, 2020 | An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of | |
| CVE-2020-14040 | Hig | 7.5 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Jun 17, 2020 | The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM o | |
| CVE-2020-10749 | Med | 6.0 | < 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | 4.3.1-1.module_el8.6.0+2876+9ed4eae2 | Jun 3, 2020 | A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertiseme | |
| CVE-2019-19921 | Hig | 7.0 | < 4.4.0-1.module_el8.6.0+3137+d33c3efb | 4.4.0-1.module_el8.6.0+3137+d33c3efb | Feb 12, 2020 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul |
- affected < 4.4.0-1.module_el8.6.0+2877+8e437bf5fixed 4.4.0-1.module_el8.6.0+2877+8e437bf5
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through unbounde
- affected < 4.4.0-2.module_el8.10.0+3909+6e1c1eb7fixed 4.4.0-2.module_el8.10.0+3909+6e1c1eb7
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is op
- affected < 4.4.0-2.module_el8.10.0+3909+6e1c1eb7fixed 4.4.0-2.module_el8.10.0+3909+6e1c1eb7
In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on
- affected < 4.4.0-1.module_el8.5.0+2613+1b78b731fixed 4.4.0-1.module_el8.5.0+2613+1b78b731
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation wh
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podma
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container wil
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM o
- affected < 4.3.1-1.module_el8.6.0+2876+9ed4eae2fixed 4.3.1-1.module_el8.6.0+2876+9ed4eae2
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertiseme
- affected < 4.4.0-1.module_el8.6.0+3137+d33c3efbfixed 4.4.0-1.module_el8.6.0+3137+d33c3efb
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vul
Page 6 of 6