rpm package
almalinux/slirp4netns
pkg:rpm/almalinux/slirp4netns
Vulnerabilities (114)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-24539 | Hig | 7.3 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | May 11, 2023 | Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untru | |
| CVE-2023-24538 | Cri | 9.8 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Apr 6, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the act | |
| CVE-2023-24537 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Apr 6, 2023 | Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow. | |
| CVE-2023-24536 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Apr 6, 2023 | Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can under | |
| CVE-2023-24534 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Apr 6, 2023 | HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more m | |
| CVE-2023-28642 | Med | 6.1 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Mar 29, 2023 | runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibitin | |
| CVE-2023-25809 | Med | 5.0 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Mar 29, 2023 | runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes `/sys/fs/cgroup` writable in following conditons: 1. when runc is executed inside the user namespace, and the `config.json` does n | |
| CVE-2023-0778 | Med | 6.8 | < 1.2.0-2.module_el8.7.0+3407+95aa0ca9 | 1.2.0-2.module_el8.7.0+3407+95aa0ca9 | Mar 27, 2023 | A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system. | |
| CVE-2023-27561 | Hig | 7.0 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Mar 3, 2023 | runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this is | |
| CVE-2022-41725 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Feb 28, 2023 | A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package wi | |
| CVE-2022-41724 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Feb 28, 2023 | Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly | |
| CVE-2022-41723 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Feb 28, 2023 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. | |
| CVE-2023-25173 | Med | 5.3 | < 1.2.1-1.module_el8.9.0+3643+9234dc3b | 1.2.1-1.module_el8.9.0+3643+9234dc3b | Feb 16, 2023 | containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group acces | |
| CVE-2022-3064 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Dec 27, 2022 | Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory. | |
| CVE-2022-41717 | Med | 5.3 | < 1.2.0-2.module_el8.7.0+3407+95aa0ca9 | 1.2.0-2.module_el8.7.0+3407+95aa0ca9 | Dec 8, 2022 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the s | |
| CVE-2022-41715 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Oct 14, 2022 | Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm | |
| CVE-2022-2880 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Oct 14, 2022 | Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy s | |
| CVE-2022-2879 | Hig | 7.5 | < 1.1.8-3.module_el8.9.0+3627+db8ec155 | 1.1.8-3.module_el8.9.0+3627+db8ec155 | Oct 14, 2022 | Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 Mi | |
| CVE-2022-2990 | Hig | 7.1 | < 1.2.0-2.module_el8.6.0+3070+1510fbd1 | 1.2.0-2.module_el8.6.0+3070+1510fbd1 | Sep 13, 2022 | An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissi | |
| CVE-2022-2989 | Hig | 7.1 | < 1.2.0-2.module_el8.6.0+3070+1510fbd1 | 1.2.0-2.module_el8.6.0+3070+1510fbd1 | Sep 13, 2022 | An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissio |
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untru
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the act
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow.
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems from several causes: 1. mime/multipart.Reader.ReadForm limits the total memory a parsed multipart form can consume. ReadForm can under
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
HTTP and MIME header parsing can allocate large amounts of memory, even when parsing small inputs, potentially leading to a denial of service. Certain unusual patterns of input data can cause the common function used to parse HTTP and MIME headers to allocate substantially more m
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration. This issue has been fixed in runc version 1.1.5, by prohibitin
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
runc is a CLI tool for spawning and running containers according to the OCI specification. In affected versions it was found that rootless runc makes `/sys/fs/cgroup` writable in following conditons: 1. when runc is executed inside the user namespace, and the `config.json` does n
- affected < 1.2.0-2.module_el8.7.0+3407+95aa0ca9fixed 1.2.0-2.module_el8.7.0+3407+95aa0ca9
A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this is
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package wi
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
- affected < 1.2.1-1.module_el8.9.0+3643+9234dc3bfixed 1.2.1-1.module_el8.9.0+3643+9234dc3b
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group acces
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
- affected < 1.2.0-2.module_el8.7.0+3407+95aa0ca9fixed 1.2.0-2.module_el8.7.0+3407+95aa0ca9
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the s
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively sm
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy s
- affected < 1.1.8-3.module_el8.9.0+3627+db8ec155fixed 1.1.8-3.module_el8.9.0+3627+db8ec155
Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to allocate unbounded amounts of memory, potentially causing resource exhaustion or panics. After fix, Reader.Read limits the maximum size of header blocks to 1 Mi
- affected < 1.2.0-2.module_el8.6.0+3070+1510fbd1fixed 1.2.0-2.module_el8.6.0+3070+1510fbd1
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissi
- affected < 1.2.0-2.module_el8.6.0+3070+1510fbd1fixed 1.2.0-2.module_el8.6.0+3070+1510fbd1
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissio
Page 4 of 6