Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ ALSA-2023:2802 — aardvark-dns (CVE-2022-1705 +13 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Moderate: container-tools:4.0 security and bug fix update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
  • golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
  • golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664)
  • golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
  • golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
  • golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
  • golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
  • golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
  • golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
  • golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
  • golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
  • podman: symlink exchange attack in podman export volume (CVE-2023-0778)
  • podman: possible information disclosure and modification (CVE-2022-2989)
  • golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service (CVE-2022-32189)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Affected software

ALSA-2023:2802 is recorded against 34 packages.

  • aardvark-dns (fixed in 2:1.0.1-37.module_el8.8.0+3468+16b86c82)
  • buildah (fixed in 1:1.24.6-5.module_el8.8.0+3468+16b86c82)
  • buildah-tests (fixed in 1:1.24.6-5.module_el8.8.0+3468+16b86c82)
  • cockpit-podman (fixed in 46-1.module_el8.7.0+3344+5bcd850f)
  • conmon (fixed in 2:2.1.4-1.module_el8.7.0+3344+5bcd850f)
  • container-selinux (fixed in 2:2.199.0-1.module_el8.8.0+3468+16b86c82)
  • containernetworking-plugins (fixed in 1:1.1.1-2.module_el8.7.0+3344+5bcd850f)
  • containers-common (fixed in 2:1-37.module_el8.8.0+3468+16b86c82)
  • crit (fixed in 3.15-3.module_el8.6.0+2877+8e437bf5)
  • criu (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • criu-devel (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • criu-libs (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • crun (fixed in 1.6-1.module_el8.8.0+3468+16b86c82)
  • fuse-overlayfs (fixed in 1.9-1.module_el8.7.0+3344+5bcd850f)
  • libslirp (fixed in 4.4.0-1.module_el8.6.0+3137+d33c3efb)
  • libslirp-devel (fixed in 4.4.0-1.module_el8.6.0+2877+8e437bf5)
  • netavark (fixed in 2:1.0.1-37.module_el8.8.0+3468+16b86c82)
  • oci-seccomp-bpf-hook (fixed in 1.2.5-2.module_el8.8.0+3468+16b86c82)
  • podman (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • podman-catatonit (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • podman-docker (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • podman-gvproxy (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • podman-plugins (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • podman-remote (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
Show the remaining 10 packages
  • podman-tests (fixed in 2:4.0.2-20.module_el8.8.0+3468+16b86c82)
  • python3-criu (fixed in 3.15-3.module_el8.6.0+2877+8e437bf5)
  • python3-podman (fixed in 4.0.0-1.module_el8.6.0+2877+8e437bf5)
  • runc (fixed in 1:1.1.4-1.module_el8.7.0+3344+5bcd850f)
  • skopeo (fixed in 2:1.6.2-6.module_el8.8.0+3468+16b86c82)
  • skopeo-tests (fixed in 2:1.6.2-6.module_el8.8.0+3468+16b86c82)
  • slirp4netns (fixed in 1.1.8-2.module_el8.6.0+3137+d33c3efb)
  • toolbox (fixed in 0.0.99.3-7.module_el8.8.0+3468+16b86c82)
  • toolbox-tests (fixed in 0.0.99.3-7.module_el8.8.0+3468+16b86c82)
  • udica (fixed in 0.2.6-3.module_el8.6.0+2886+d33c3efb)

Timeline and source

Published on 16 May 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

access.redhat.com (Advisory)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-05-16
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
aardvark-dns 2:1.0.1-37.module_el8.8.0+3468+16b86c82
buildah 1:1.24.6-5.module_el8.8.0+3468+16b86c82
buildah-tests 1:1.24.6-5.module_el8.8.0+3468+16b86c82
cockpit-podman 46-1.module_el8.7.0+3344+5bcd850f
conmon 2:2.1.4-1.module_el8.7.0+3344+5bcd850f
container-selinux 2:2.199.0-1.module_el8.8.0+3468+16b86c82
containernetworking-plugins 1:1.1.1-2.module_el8.7.0+3344+5bcd850f
containers-common 2:1-37.module_el8.8.0+3468+16b86c82
crit 3.15-3.module_el8.6.0+2877+8e437bf5
criu 3.15-3.module_el8.6.0+3137+d33c3efb
criu-devel 3.15-3.module_el8.6.0+3137+d33c3efb
criu-libs 3.15-3.module_el8.6.0+3137+d33c3efb
crun 1.6-1.module_el8.8.0+3468+16b86c82
fuse-overlayfs 1.9-1.module_el8.7.0+3344+5bcd850f
libslirp 4.4.0-1.module_el8.6.0+3137+d33c3efb
libslirp-devel 4.4.0-1.module_el8.6.0+2877+8e437bf5
netavark 2:1.0.1-37.module_el8.8.0+3468+16b86c82
oci-seccomp-bpf-hook 1.2.5-2.module_el8.8.0+3468+16b86c82
podman 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-catatonit 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-docker 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-gvproxy 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-plugins 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-remote 2:4.0.2-20.module_el8.8.0+3468+16b86c82
podman-tests 2:4.0.2-20.module_el8.8.0+3468+16b86c82
python3-criu 3.15-3.module_el8.6.0+2877+8e437bf5
python3-podman 4.0.0-1.module_el8.6.0+2877+8e437bf5
runc 1:1.1.4-1.module_el8.7.0+3344+5bcd850f
skopeo 2:1.6.2-6.module_el8.8.0+3468+16b86c82
skopeo-tests 2:1.6.2-6.module_el8.8.0+3468+16b86c82
slirp4netns 1.1.8-2.module_el8.6.0+3137+d33c3efb
toolbox 0.0.99.3-7.module_el8.8.0+3468+16b86c82
toolbox-tests 0.0.99.3-7.module_el8.8.0+3468+16b86c82
udica 0.2.6-3.module_el8.6.0+2886+d33c3efb

References

Similar Threats

Free Vulnerability Check

Is your site affected by ALSA-2023:2802?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ALSA-2023:2802 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesAlmaLinuxAlmaLinux 2023