Information disclosure in Podman - CVE-2021-4024
Published: December 8, 2021
Vulnerability identifier: #VU58668
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4024
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the "podman machine" function. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Podman
Gentoo Linux
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Fedora
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
buildah
buildah-tests
containers-common
conmon
container-selinux
podman
crit
criu
criu-devel
criu-libs
python3-criu
podman (Red Hat package)
podman-cni-config
podman-debuginfo
podman-docker
podman-remote
podman-remote-debuginfo
libslirp
libslirp-devel
python3-podman
app-containers/podman
podman-tests
podman-plugins
podman-gvproxy
podman-catatonit
cockpit-podman
Gentoo Linux
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Containers
openSUSE Leap
Fedora
toolbox-tests
toolbox
udica
runc
slirp4netns
oci-seccomp-bpf-hook
containernetworking-plugins
aardvark-dns
netavark
fuse-overlayfs
crun
skopeo-tests
skopeo
buildah
buildah-tests
containers-common
conmon
container-selinux
podman
crit
criu
criu-devel
criu-libs
python3-criu
podman (Red Hat package)
podman-cni-config
podman-debuginfo
podman-docker
podman-remote
podman-remote-debuginfo
libslirp
libslirp-devel
python3-podman
app-containers/podman
podman-tests
podman-plugins
podman-gvproxy
podman-catatonit
cockpit-podman
How to mitigate CVE-2021-4024
Install updates from vendor's website.
Podman - update to 3.4.3
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-5.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-3.0.1
skopeo - update to 1.14.5-3.0.1
buildah - update to 1.33.11-1
buildah-tests - update to 1.33.11-1
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
podman - addressed in versions 3.4.4-1.fc34, 3.4.4-1.fc35
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
podman-cni-config - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-debuginfo - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-docker - update to 4.3.1-150400.4.11.1
podman-remote - update to 4.3.1-150400.4.11.1
podman-remote-debuginfo - update to 4.3.1-150400.4.11.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
app-containers/podman - update to 4.9.4
podman-tests - update to 4.9.4-18.0.1
podman-remote - update to 4.9.4-18.0.1
podman-plugins - update to 4.9.4-18.0.1
podman-gvproxy - update to 4.9.4-18.0.1
podman-catatonit - update to 4.9.4-18.0.1
podman - update to 4.9.4-18.0.1
podman-docker - update to 4.9.4-18.0.1
cockpit-podman - update to 84.1-1
toolbox-tests - update to 0.0.99.5-2.0.1
toolbox - update to 0.0.99.5-2.0.1
udica - update to 0.2.6-21
runc - update to 1.1.12-5.0.1
slirp4netns - update to 1.2.3-1
oci-seccomp-bpf-hook - update to 1.2.10-1
containernetworking-plugins - update to 1.4.0-5.0.1
aardvark-dns - update to 1.10.1-2.0.1
netavark - update to 1.10.3-1.0.1
fuse-overlayfs - update to 1.13-1.0.1
crun - update to 1.14.3-2
skopeo-tests - update to 1.14.5-3.0.1
skopeo - update to 1.14.5-3.0.1
buildah - update to 1.33.11-1
buildah-tests - update to 1.33.11-1
containers-common - update to 1-82.0.1
conmon - update to 2.1.10-1
container-selinux - update to 2.229.0-2
podman - addressed in versions 3.4.4-1.fc34, 3.4.4-1.fc35
crit - update to 3.18-5.0.1
criu - update to 3.18-5.0.1
criu-devel - update to 3.18-5.0.1
criu-libs - update to 3.18-5.0.1
python3-criu - update to 3.18-5.0.1
podman (Red Hat package) - update to 4.2.0-3.el9
podman-cni-config - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-debuginfo - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman - addressed in versions 4.3.1-150300.9.15.1, 4.3.1-150400.4.11.1
podman-docker - update to 4.3.1-150400.4.11.1
podman-remote - update to 4.3.1-150400.4.11.1
podman-remote-debuginfo - update to 4.3.1-150400.4.11.1
libslirp - update to 4.4.0-2
libslirp-devel - update to 4.4.0-2
python3-podman - update to 4.9.0-3
app-containers/podman - update to 4.9.4
podman-tests - update to 4.9.4-18.0.1
podman-remote - update to 4.9.4-18.0.1
podman-plugins - update to 4.9.4-18.0.1
podman-gvproxy - update to 4.9.4-18.0.1
podman-catatonit - update to 4.9.4-18.0.1
podman - update to 4.9.4-18.0.1
podman-docker - update to 4.9.4-18.0.1
cockpit-podman - update to 84.1-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Podman
- Red Hat Enterprise Linux 9 update for podman
- SUSE update for podman
- SUSE update for podman
- Multiple vulnerabilities in Oracle Linux
- Gentoo update for podman
- Red Hat Enterprise Linux 8 update for the container-tools:rhel8 module
- Fedora 35 update for podman
- Fedora 34 update for podman
- Anolis OS update for container-tools:an8 module