Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ ALSA-2023:6938 — aardvark-dns (CVE-2022-3064 +16 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Moderate: container-tools:4.0 security and bug fix update

The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.

Security Fix(es):

  • go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
  • golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
  • net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
  • golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
  • golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
  • golang.org/x/net/html: Cross site scripting (CVE-2023-3978)
  • golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
  • golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
  • golang: go/parser: Infinite loop in parsing (CVE-2023-24537)
  • golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
  • golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
  • runc: Rootless runc makes /sys/fs/cgroup writable (CVE-2023-25809)
  • runc: volume mount race condition (regression of CVE-2019-19921) (CVE-2023-27561)
  • runc: AppArmor can be bypassed when /proc inside the container is symlinked with a specific mount configuration (CVE-2023-28642)
  • golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
  • golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Affected software

ALSA-2023:6938 is recorded against 34 packages.

  • aardvark-dns (fixed in 2:1.0.1-38.module_el8.9.0+3627+db8ec155)
  • buildah (fixed in 1:1.24.6-7.module_el8.9.0+3627+db8ec155)
  • buildah-tests (fixed in 1:1.24.6-7.module_el8.9.0+3627+db8ec155)
  • cockpit-podman (fixed in 46-1.module_el8.7.0+3344+5bcd850f)
  • conmon (fixed in 2:2.1.4-2.module_el8.9.0+3627+db8ec155)
  • container-selinux (fixed in 2:2.205.0-3.module_el8.9.0+3627+db8ec155)
  • containernetworking-plugins (fixed in 1:1.1.1-5.module_el8.9.0+3627+db8ec155)
  • containers-common (fixed in 2:1-38.module_el8.9.0+3627+db8ec155)
  • crit (fixed in 3.15-3.module_el8.6.0+2877+8e437bf5)
  • criu (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • criu-devel (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • criu-libs (fixed in 3.15-3.module_el8.6.0+3137+d33c3efb)
  • crun (fixed in 1.8.3-1.module_el8.9.0+3627+db8ec155)
  • fuse-overlayfs (fixed in 1.9-2.module_el8.9.0+3627+db8ec155)
  • libslirp (fixed in 4.4.0-1.module_el8.6.0+3137+d33c3efb)
  • libslirp-devel (fixed in 4.4.0-1.module_el8.6.0+2877+8e437bf5)
  • netavark (fixed in 2:1.0.1-38.module_el8.9.0+3627+db8ec155)
  • oci-seccomp-bpf-hook (fixed in 1.2.5-2.module_el8.8.0+3468+16b86c82)
  • podman (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • podman-catatonit (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • podman-docker (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • podman-gvproxy (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • podman-plugins (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • podman-remote (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
Show the remaining 10 packages
  • podman-tests (fixed in 2:4.0.2-24.module_el8.9.0+3627+db8ec155)
  • python3-criu (fixed in 3.15-3.module_el8.6.0+2877+8e437bf5)
  • python3-podman (fixed in 4.0.0-2.module_el8.9.0+3627+db8ec155)
  • runc (fixed in 1:1.1.5-2.module_el8.9.0+3627+db8ec155)
  • skopeo (fixed in 2:1.6.2-8.module_el8.9.0+3627+db8ec155)
  • skopeo-tests (fixed in 2:1.6.2-8.module_el8.9.0+3627+db8ec155)
  • slirp4netns (fixed in 1.1.8-3.module_el8.9.0+3627+db8ec155)
  • toolbox (fixed in 0.0.99.4-5.module_el8.9.0+3627+db8ec155)
  • toolbox-tests (fixed in 0.0.99.4-5.module_el8.9.0+3627+db8ec155)
  • udica (fixed in 0.2.6-4.module_el8.9.0+3627+db8ec155)

Timeline and source

Published on 14 November 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

access.redhat.com (Advisory)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
access.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
bugzilla.redhat.com (Report)
errata.almalinux.org (Advisory)

Other advisories for this package

aardvark-dns has other advisories on record. If you are patching this one, these are worth checking on the same host:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-11-14
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
aardvark-dns 2:1.0.1-38.module_el8.9.0+3627+db8ec155
buildah 1:1.24.6-7.module_el8.9.0+3627+db8ec155
buildah-tests 1:1.24.6-7.module_el8.9.0+3627+db8ec155
cockpit-podman 46-1.module_el8.7.0+3344+5bcd850f
conmon 2:2.1.4-2.module_el8.9.0+3627+db8ec155
container-selinux 2:2.205.0-3.module_el8.9.0+3627+db8ec155
containernetworking-plugins 1:1.1.1-5.module_el8.9.0+3627+db8ec155
containers-common 2:1-38.module_el8.9.0+3627+db8ec155
crit 3.15-3.module_el8.6.0+2877+8e437bf5
criu 3.15-3.module_el8.6.0+3137+d33c3efb
criu-devel 3.15-3.module_el8.6.0+3137+d33c3efb
criu-libs 3.15-3.module_el8.6.0+3137+d33c3efb
crun 1.8.3-1.module_el8.9.0+3627+db8ec155
fuse-overlayfs 1.9-2.module_el8.9.0+3627+db8ec155
libslirp 4.4.0-1.module_el8.6.0+3137+d33c3efb
libslirp-devel 4.4.0-1.module_el8.6.0+2877+8e437bf5
netavark 2:1.0.1-38.module_el8.9.0+3627+db8ec155
oci-seccomp-bpf-hook 1.2.5-2.module_el8.8.0+3468+16b86c82
podman 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-catatonit 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-docker 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-gvproxy 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-plugins 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-remote 2:4.0.2-24.module_el8.9.0+3627+db8ec155
podman-tests 2:4.0.2-24.module_el8.9.0+3627+db8ec155
python3-criu 3.15-3.module_el8.6.0+2877+8e437bf5
python3-podman 4.0.0-2.module_el8.9.0+3627+db8ec155
runc 1:1.1.5-2.module_el8.9.0+3627+db8ec155
skopeo 2:1.6.2-8.module_el8.9.0+3627+db8ec155
skopeo-tests 2:1.6.2-8.module_el8.9.0+3627+db8ec155
slirp4netns 1.1.8-3.module_el8.9.0+3627+db8ec155
toolbox 0.0.99.4-5.module_el8.9.0+3627+db8ec155
toolbox-tests 0.0.99.4-5.module_el8.9.0+3627+db8ec155
udica 0.2.6-4.module_el8.9.0+3627+db8ec155

References

Similar Threats

Free Vulnerability Check

Is your site affected by ALSA-2023:6938?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ALSA-2023:6938 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesAlmaLinuxAlmaLinux 2023