Use-after-free in podman (Red Hat package) - CVE-2022-2738
Published: August 22, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error when verifying GPG signature in podman. A remote attacker can can trigger a use-after-free error and perform a denial of service (DoS) attack.
Note, the vulnerability exists due to missing patch for #VU25501 (CVE-2020-8945) in podman Red Hat package.
Affected software
podman
podman-remote
podman-tests
podman-docker
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Anolis OS
How to mitigate CVE-2022-2738
podman - update to 1.6.4-36
podman-remote - update to 1.6.4-36
podman-tests - update to 1.6.4-36
podman-docker - update to 1.6.4-36