Hash: SHA256

             AUSCERT External Security Bulletin Redistribution

                        Security update for buildah
                             20 November 2020


        AusCERT Security Bulletin Summary

Product:           buildah
Publisher:         SUSE
Operating System:  SUSE
Impact/Access:     Create Arbitrary Files   -- Remote with User Interaction
                   Access Confidential Data -- Remote/Unauthenticated      
                   Reduced Security         -- Remote/Unauthenticated      
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-10696 CVE-2019-10214 

Reference:         ESB-2020.1664

Original Bulletin: 

- --------------------------BEGIN INCLUDED TEXT--------------------

SUSE Security Update: Security update for buildah


Announcement ID:   SUSE-SU-2020:3423-1
Rating:            moderate
References:        #1165184 #1167864
Cross-References:  CVE-2019-10214 CVE-2020-10696
Affected Products:
                   SUSE Linux Enterprise Module for Containers 15-SP2
                   SUSE Linux Enterprise Module for Containers 15-SP1

An update that fixes two vulnerabilities is now available.


This update for buildah fixes the following issues:
buildah was updated to v1.17.0 (bsc#1165184):

  o Handle cases where other tools mount/unmount containers
  o overlay.MountReadOnly: support RO overlay mounts
  o overlay: use fusermount for rootless umounts
  o overlay: fix umount
  o Switch default log level of Buildah to Warn. Users need to see these
  o Drop error messages about OCI/Docker format to Warning level
  o build(deps): bump github.com/containers/common from 0.26.0 to 0.26.2
  o tests/testreport: adjust for API break in storage v1.23.6
  o build(deps): bump github.com/containers/storage from 1.23.5 to 1.23.7
  o build(deps): bump github.com/fsouza/go-dockerclient from 1.6.5 to 1.6.6
  o copier: put: ignore Typeflag="g"
  o Use curl to get repo file (fix #2714)
  o build(deps): bump github.com/containers/common from 0.25.0 to 0.26.0
  o build(deps): bump github.com/spf13/cobra from 1.0.0 to 1.1.1
  o Remove docs that refer to bors, since we're not using it
  o Buildah bud should not use stdin by default
  o bump containerd, docker, and golang.org/x/sys
  o Makefile: cross: remove windows.386 target
  o copier.copierHandlerPut: don't check length when there are errors
  o Stop excessive wrapping
  o CI: require that conformance tests pass
  o bump(github.com/openshift/imagebuilder) to v1.1.8
  o Skip tlsVerify insecure BUILD_REGISTRY_SOURCES
  o Fix build path wrong containers/podman#7993
  o refactor pullpolicy to avoid deps
  o build(deps): bump github.com/containers/common from 0.24.0 to 0.25.0
  o CI: run gating tasks with a lot more memory
  o ADD and COPY: descend into excluded directories, sometimes
  o copier: add more context to a couple of error messages
  o copier: check an error earlier
  o copier: log stderr output as debug on success
  o Update nix pin with make nixpkgs
  o Set directory ownership when copied with ID mapping
  o build(deps): bump github.com/sirupsen/logrus from 1.6.0 to 1.7.0
  o build(deps): bump github.com/containers/common from 0.23.0 to 0.24.0
  o Cirrus: Remove bors artifacts
  o Sort build flag definitions alphabetically
  o ADD: only expand archives at the right time
  o Remove configuration for bors
  o Shell Completion for podman build flags
  o Bump c/common to v0.24.0
  o New CI check: xref --help vs man pages
  o CI: re-enable several linters
  o Move --userns-uid-map/--userns-gid-map description into buildah man page
  o add: preserve ownerships and permissions on ADDed archives
  o Makefile: tweak the cross-compile target
  o Bump containers/common to v0.23.0
  o chroot: create bind mount targets 0755 instead of 0700
  o Change call to Split() to safer SplitN()
  o chroot: fix handling of errno seccomp rules
  o build(deps): bump github.com/containers/image/v5 from 5.5.2 to 5.6.0
  o Add In Progress section to contributing
  o integration tests: make sure tests run in ${topdir}/tests
  o Run(): ignore containers.conf's environment configuration
  o Warn when setting healthcheck in OCI format
  o Cirrus: Skip git-validate on branches
  o tools: update git-validation to the latest commit
  o tools: update golangci-lint to v1.18.0
  o Add a few tests of push command
  o Add(): fix handling of relative paths with no ContextDir
  o build(deps): bump github.com/containers/common from 0.21.0 to 0.22.0
  o Lint: Use same linters as podman
  o Validate: reference HEAD
  o Fix buildah mount to display container names not ids
  o Update nix pin with make nixpkgs
  o Add missing --format option in buildah from man page
  o Fix up code based on codespell
  o build(deps): bump github.com/openshift/imagebuilder from 1.1.6 to 1.1.7
  o build(deps): bump github.com/containers/storage from 1.23.4 to 1.23.5
  o Improve buildah completions
  o Cirrus: Fix validate commit epoch
  o Fix bash completion of manifest flags
  o Uniform some man pages
  o Update Buildah Tutorial to address BZ1867426
  o Update bash completion of manifest add sub command
  o copier.Get(): hard link targets shouldn't be relative paths
  o build(deps): bump github.com/onsi/gomega from 1.10.1 to 1.10.2
  o Pass timestamp down to history lines
  o Timestamp gets updated everytime you inspect an image
  o bud.bats: use absolute paths in newly-added tests
  o contrib/cirrus/lib.sh: don't use CN for the hostname
  o tests: Add some tests
  o Update manifest add man page
  o Extend flags of manifest add
  o build(deps): bump github.com/containers/storage from 1.23.3 to 1.23.4
  o build(deps): bump github.com/onsi/ginkgo from 1.14.0 to 1.14.1
  o CI: expand cross-compile checks

Update to v1.16.2:

  o fix build on 32bit arches
  o containerImageRef.NewImageSource(): don't always force timestamps
  o Add fuse module warning to image readme
  o Heed our retry delay option values when retrying commit/pull/push
  o Switch to containers/common for seccomp
  o Use --timestamp rather then --omit-timestamp
  o docs: remove outdated notice
  o docs: remove outdated notice
  o build-using-dockerfile: add a hidden --log-rusage flag
  o build(deps): bump github.com/containers/image/v5 from 5.5.1 to 5.5.2
  o Discard ReportWriter if user sets options.Quiet
  o build(deps): bump github.com/containers/common from 0.19.0 to 0.20.3
  o Fix ownership of content copied using COPY --from
  o newTarDigester: zero out timestamps in tar headers
  o Update nix pin with `make nixpkgs`
  o bud.bats: correct .dockerignore integration tests
  o Use pipes for copying
  o run: include stdout in error message
  o run: use the correct error for errors.Wrapf
  o copier: un-export internal types
  o copier: add Mkdir()
  o in_podman: don't get tripped up by $CIRRUS_CHANGE_TITLE
  o docs/buildah-commit.md: tweak some wording, add a --rm example
  o imagebuildah: don't blank out destination names when COPYing
  o Replace retry functions with common/pkg/retry
  o StageExecutor.historyMatches: compare timestamps using .Equal
  o Update vendor of containers/common
  o Fix errors found in coverity scan
  o Change namespace handling flags to better match podman commands
  o conformance testing: ignore buildah.BuilderIdentityAnnotation labels
  o Vendor in containers/storage v1.23.0
  o Add buildah.IsContainer interface
  o Avoid feeding run_buildah to pipe
  o fix(buildahimage): add xz dependency in buildah image
  o Bump github.com/containers/common from 0.15.2 to 0.18.0
  o Howto for rootless image building from OpenShift
  o Add --omit-timestamp flag to buildah bud
  o Update nix pin with `make nixpkgs`
  o Shutdown storage on failures
  o Handle COPY --from when an argument is used
  o Bump github.com/seccomp/containers-golang from 0.5.0 to 0.6.0
  o Cirrus: Use newly built VM images
  o Bump github.com/opencontainers/runc from 1.0.0-rc91 to 1.0.0-rc92
  o Enhance the .dockerignore man pages
  o conformance: add a test for COPY from subdirectory
  o fix bug manifest inspct
  o Add documentation for .dockerignore
  o Add BuilderIdentityAnnotation to identify buildah version
  o DOC: Add quay.io/containers/buildah image to README.md
  o Update buildahimages readme
  o fix spelling mistake in "info" command result display
  o Don't bind /etc/host and /etc/resolv.conf if network is not present
  o blobcache: avoid an unnecessary NewImage()
  o Build static binary with `buildGoModule`
  o copier: split StripSetidBits into StripSetuidBit/StripSetgidBit/
  o tarFilterer: handle multiple archives
  o Fix a race we hit during conformance tests
  o Rework conformance testing
  o Update 02-registries-repositories.md
  o test-unit: invoke cmd/buildah tests with --flags
  o parse: fix a type mismatch in a test
  o Fix compilation of tests/testreport/testreport
  o build.sh: log the version of Go that we're using
  o test-unit: increase the test timeout to 40/45 minutes
  o Add the "copier" package
  o Fix & add notes regarding problematic language in codebase
  o Add dependency on github.com/stretchr/testify/require
  o CompositeDigester: add the ability to filter tar streams
  o BATS tests: make more robust
  o vendor golang.org/x/text@v0.3.3
  o Switch golang 1.12 to golang 1.13
  o imagebuildah: wait for stages that might not have even started yet
  o chroot, run: not fail on bind mounts from /sys
  o chroot: do not use setgroups if it is blocked
  o Set engine env from containers.conf
  o imagebuildah: return the right stage's image as the "final" image
  o Fix a help string
  o Deduplicate environment variables
  o switch containers/libpod to containers/podman
  o Bump github.com/containers/ocicrypt from 1.0.2 to 1.0.3
  o Bump github.com/opencontainers/selinux from 1.5.2 to 1.6.0
  o Mask out /sys/dev to prevent information leak
  o linux: skip errors from the runtime kill
  o Mask over the /sys/fs/selinux in mask branch
  o Add VFS additional image store to container
  o tests: add auth tests
  o Allow "readonly" as alias to "ro" in mount options
  o Ignore OS X specific consistency mount option
  o Bump github.com/onsi/ginkgo from 1.13.0 to 1.14.0
  o Bump github.com/containers/common from 0.14.0 to 0.15.2
  o Rootless Buildah should default to IsolationOCIRootless
  o imagebuildah: fix inheriting multi-stage builds
  o Make imagebuildah.BuildOptions.Architecture/OS optional
  o Make imagebuildah.BuildOptions.Jobs optional
  o Resolve a possible race in imagebuildah.Executor.startStage()
  o Switch scripts to use containers.conf
  o Bump openshift/imagebuilder to v1.1.6
  o Bump go.etcd.io/bbolt from 1.3.4 to 1.3.5
  o buildah, bud: support --jobs=N for parallel execution
  o executor: refactor build code inside new function
  o Add bud regression tests
  o Cirrus: Fix missing htpasswd in registry img
  o docs: clarify the 'triples' format
  o CHANGELOG.md: Fix markdown formatting
  o Add nix derivation for static builds
  o Bump to v1.16.0-dev

  o Update to v1.15.1
  o Mask over the /sys/fs/selinux in mask branch
  o chroot: do not use setgroups if it is blocked
  o chroot, run: not fail on bind mounts from /sys
  o Allow "readonly" as alias to "ro" in mount options
  o Add VFS additional image store to container
  o vendor golang.org/x/text@v0.3.3
  o Make imagebuildah.BuildOptions.Architecture/OS optional

Update to v1.15.0:

  o Add CVE-2020-10696 to CHANGELOG.md and changelog.txt
  o fix lighttpd example
  o remove dependency on openshift struct
  o Warn on unset build arguments
  o vendor: update seccomp/containers-golang to v0.4.1
  o Updated docs
  o clean up comments
  o update exit code for tests
  o Implement commit for encryption
  o implementation of encrypt/decrypt push/pull/bud/from
  o fix resolve docker image name as transport
  o Add preliminary profiling support to the CLI
  o Evaluate symlinks in build context directory
  o fix error info about get signatures for containerImageSource
  o Add Security Policy
  o Cirrus: Fixes from review feedback
  o imagebuildah: stages shouldn't count as their base images
  o Update containers/common v0.10.0
  o Add registry to buildahimage Dockerfiles
  o Cirrus: Use pre-installed VM packages + F32
  o Cirrus: Re-enable all distro versions
  o Cirrus: Update to F31 + Use cache images
  o golangci-lint: Disable gosimple
  o Lower number of golangci-lint threads
  o Fix permissions on containers.conf
  o Don't force tests to use runc
  o Return exit code from failed containers
  o cgroup_manager should be under [engine]
  o Use c/common/pkg/auth in login/logout
  o Cirrus: Temporarily disable Ubuntu 19 testing
  o Add containers.conf to stablebyhand build
  o Update gitignore to exclude test Dockerfiles
  o Remove warning for systemd inside of container

Update to v1.14.6:

  o Make image history work correctly with new args handling
  o Don't add args to the RUN environment from the Builder

Update to v1.14.5:

  o Revert FIPS mode change

Update to v1.14.4:

  o Update unshare man page to fix script example
  o Fix compilation errors on non linux platforms
  o Preserve volume uid and gid through subsequent commands
  o Fix potential CVE in tarfile w/ symlink
  o Fix .dockerignore with globs and ! commands

Update to v1.14.2:

  o Search for local runtime per values in containers.conf
  o Set correct ownership on working directory
  o Improve remote manifest retrieval
  o Correct a couple of incorrect format specifiers
  o manifest push --format: force an image type, not a list type
  o run: adjust the order in which elements are added to $
  o getDateAndDigestAndSize(): handle creation time not being set
  o Make the commit id clear like Docker
  o Show error on copied file above context directory in build
  o pull/from/commit/push: retry on most failures
  o Repair buildah so it can use containers.conf on the server side
  o Fixing formatting & build instructions
  o Fix XDG_RUNTIME_DIR for authfile
  o Show validation command-line

Update to v1.14.0:

  o getDateAndDigestAndSize(): use manifest.Digest
  o Touch up os/arch doc
  o chroot: handle slightly broken seccomp defaults
  o buildahimage: specify fuse-overlayfs mount options
  o parse: don't complain about not being able to rename something to itself
  o Fix build for 32bit platforms
  o Allow users to set OS and architecture on bud
  o Fix COPY in containerfile with envvar
  o Add --sign-by to bud/commit/push, --remove-signatures for pull/push
  o Add support for containers.conf
  o manifest push: add --format option

Update to v1.13.1:

  o copyFileWithTar: close source files at the right time
  o copy: don't digest files that we ignore
  o Check for .dockerignore specifically
  o Don't setup excludes, if their is only one pattern to match
  o set HOME env to /root on chroot-isolation by default
  o docs: fix references to containers-*.5
  o fix bug Add check .dockerignore COPY file
  o buildah bud --volume: run from tmpdir, not source dir
  o Fix imageNamePrefix to give consistent names in buildah-from
  o cpp: use -traditional and -undef flags
  o discard outputs coming from onbuild command on buildah-from --quiet
  o make --format columnizing consistent with buildah images
  o Fix option handling for volumes in build
  o Rework overlay pkg for use with libpod
  o Fix buildahimage builds for buildah
  o Add support for FIPS-Mode backends
  o Set the TMPDIR for pulling/pushing image to $TMPDIR

Update to v1.12.0:

  o Allow ADD to use http src
  o imgtype: reset storage opts if driver overridden
  o Start using containers/common
  o overlay.bats typo: fuse-overlays should be fuse-overlayfs
  o chroot: Unmount with MNT_DETACH instead of UnmountMountpoints()
  o bind: don't complain about missing mountpoints
  o imgtype: check earlier for expected manifest type
  o Add history names support

Update to v1.11.6:

  o Handle missing equal sign in --from and --chown flags for COPY/ADD
  o bud COPY does not download URL
  o Fix .dockerignore exclude regression
  o commit(docker): always set ContainerID and ContainerConfig
  o Touch up commit man page image parameter
  o Add builder identity annotations.

Update to v1.11.5:

  o buildah: add "manifest" command
  o pkg/supplemented: add a package for grouping images together
  o pkg/manifests: add a manifest list build/manipulation API
  o Update for ErrUnauthorizedForCredentials API change in containers/image
  o Update for manifest-lists API changes in containers/image
  o version: also note the version of containers/image
  o Move to containers/image v5.0.0
  o Enable --device directory as src device
  o Add clarification to the Tutorial for new users
  o Silence "using cache" to ensure -q is fully quiet
  o Move runtime flag to bud from common
  o Commit: check for storage.ErrImageUnknown using errors.Cause()
  o Fix crash when invalid COPY --from flag is specified.

Update to v1.11.4:

  o buildah: add a "manifest" command
  o pkg/manifests: add a manifest list build/manipulation API
  o Update for ErrUnauthorizedForCredentials API change in containers/image
  o Update for manifest-lists API changes in containers/image
  o Move to containers/image v5.0.0
  o Enable --device directory as src device
  o Add clarification to the Tutorial for new users
  o Silence "using cache" to ensure -q is fully quiet
  o Move runtime flag to bud from common
  o Commit: check for storage.ErrImageUnknown using errors.Cause()
  o Fix crash when invalid COPY --from flag is specified.

Update to v1.11.3:

  o Add cgroups2
  o Add support for retrieving context from stdin "-"
  o Added tutorial on how to include Buildah as library
  o Fix --build-args handling
  o Print build 'STEP' line to stdout, not stderr
  o Use Containerfile by default

Update to v1.11.2:

  o Add some cleanup code
  o Move devices code to unit specific directory.

Update to v1.11.1:

  o Add --devices flag to bud and from
  o Add support for /run/.containerenv
  o Allow mounts.conf entries for equal source and destination paths
  o Fix label and annotation for 1-line Dockerfiles
  o Preserve file and directory mount permissions
  o Replace --debug=false with --log-level=error
  o Set TMPDIR to /var/tmp by default
  o Truncate output of too long image names
  o Ignore EmptyLayer if Squash is set

Update to v1.11.0:

  o Add --digestfile and Re-add push statement as debug
  o Add --log-level command line option and deprecate --debug
  o Add security-related volume options to validator
  o Allow buildah bud to be called without arguments
  o Allow to override build date with SOURCE_DATE_EPOCH
  o Correctly detect ExitError values from Run()
  o Disable empty logrus timestamps to reduce logger noise
  o Fix directory pull image names
  o Fix handling of /dev/null masked devices
  o Fix possible runtime panic on bud
  o Update bud/from help to contain indicator for --dns=none
  o Update documentation about bud
  o Update shebangs to take env into consideration
  o Use content digests in ADD/COPY history entries
  o add support for cgroupsV2
  o add: add a DryRun flag to AddAndCopyOptions
  o add: handle hard links when copying with .dockerignore
  o add: teach copyFileWithTar() about symlinks and directories
  o imagebuilder: fix detection of referenced stage roots
  o pull/commit/push: pay attention to $BUILD_REGISTRY_SOURCES
  o run_linux: fix mounting /sys in a userns

Update to v1.10.1:

  o Add automatic apparmor tag discovery
  o Add overlayfs to fuse-overlayfs tip
  o Bug fix for volume minus syntax
  o Bump container/storage v1.13.1 and containers/image v3.0.1
  o Bump containers/image to v3.0.2 to fix keyring issue
  o Fix bug whereby --get-login has no effect
  o Bump github.com/containernetworking/cni to v0.7.1
  o Add appamor-pattern requirement

  o Update build process to match the latest repository architecture
  o Update to v1.10.0
  o vendor github.com/containers/image@v3.0.0
  o Remove GO111MODULE in favor of -mod=vendor
  o Vendor in containers/storage v1.12.16
  o Add '-' minus syntax for removal of config values
  o tests: enable overlay tests for rootless
  o rootless, overlay: use fuse-overlayfs
  o vendor github.com/containers/image@v2.0.1
  o Added '-' syntax to remove volume config option
  o delete successfully pushed message
  o Add golint linter and apply fixes
  o vendor github.com/containers/storage@v1.12.15
  o Change wait to sleep in buildahimage readme
  o Handle ReadOnly images when deleting images
  o Add support for listing read/only images
  o from/import: record the base image's digest, if it has one
  o Fix CNI version retrieval to not require network connection
  o Add misspell linter and apply fixes
  o Add goimports linter and apply fixes
  o Add stylecheck linter and apply fixes
  o Add unconvert linter and apply fixes
  o image: make sure we don't try to use zstd compression
  o run.bats: skip the "z" flag when testing --mount
  o Update to runc v1.0.0-rc8
  o Update to match updated runtime-tools API
  o bump github.com/opencontainers/runtime-tools to v0.9.0
  o Build e2e tests using the proper build tags
  o Add unparam linter and apply fixes
  o Run: correct a typo in the --cap-add help text
  o unshare: add a --mount flag
  o fix push check image name is not empty
  o add: fix slow copy with no excludes
  o Add errcheck linter and fix missing error check
  o Improve tests/tools/Makefile parallelism and abstraction
  o Fix response body not closed resource leak
  o Switch to golangci-lint
  o Add gomod instructions and mailing list links
  o On Masked path, check if /dev/null already mounted before mounting
  o Update to containers/storage v1.12.13
  o Refactor code in package imagebuildah
  o Add rootless podman with NFS issue in documentation
  o Add --mount for buildah run
  o import method ValidateVolumeOpts from libpod
  o Fix typo
  o Makefile: set GO111MODULE=off
  o rootless: add the built-in slirp DNS server
  o Update docker/libnetwork to get rid of outdated sctp package
  o Update buildah-login.md
  o migrate to go modules
  o install.md: mention go modules
  o tests/tools: go module for test binaries
  o fix --volume splits comma delimited option
  o Add bud test for RUN with a priv'd command
  o vendor logrus v1.4.2
  o pkg/cli: panic when flags can't be hidden
  o pkg/unshare: check all errors
  o pull: check error during report write
  o run_linux.go: ignore unchecked errors
  o conformance test: catch copy error
  o chroot/run_test.go: export funcs to actually be executed
  o tests/imgtype: ignore error when shutting down the store
  o testreport: check json error
  o bind/util.go: remove unused func
  o rm chroot/util.go
  o imagebuildah: remove unused dedupeStringSlice
  o StageExecutor: EnsureContainerPath: catch error from SecureJoin()
  o imagebuildah/build.go: return instead of branching
  o rmi: avoid redundant branching
  o conformance tests: nilness: allocate map
  o imagebuildah/build.go: avoid redundant filepath.Join()
  o imagebuildah/build.go: avoid redundant os.Stat()
  o imagebuildah: omit comparison to bool
  o fix "ineffectual assignment" lint errors
  o docker: ignore "repeats json tag" lint error
  o pkg/unshare: use ... instead of iterating a slice
  o conformance: bud test: use raw strings for regexes
  o conformance suite: remove unused func/var
  o buildah test suite: remove unused vars/funcs
  o testreport: fix golangci-lint errors
  o util: remove redundant return statement
  o chroot: only log clean-up errors
  o images_test: ignore golangci-lint error
  o blobcache: log error when draining the pipe
  o imagebuildah: check errors in deferred calls
  o chroot: fix error handling in deferred funcs
  o cmd: check all errors
  o chroot/run_test.go: check errors
  o chroot/run.go: check errors in deferred calls
  o imagebuildah.Executor: remove unused onbuild field
  o docker/types.go: remove unused struct fields
  o util: use strings.ContainsRune instead of index check
  o Cirrus: Initial implementation
  o buildah-run: fix-out-of-range panic (2)
  o Update containers/image to v2.0.0
  o run: fix hang with run and --isolation=chroot
  o run: fix hang when using run
  o chroot: drop unused function call
  o remove --> before imgageID on build
  o Always close stdin pipe
  o Write deny to setgroups when doing single user mapping
  o Avoid including linux/memfd.h
  o Add a test for the symlink pointing to a directory
  o Add missing continue
  o Fix the handling of symlinks to absolute paths
  o Only set default network sysctls if not rootless
  o Support --dns=none like podman
  o fix bug --cpu-shares parsing typo
  o Fix validate complaint
  o Update vendor on containers/storage to v1.12.10
  o Create directory paths for COPY thereby ensuring correct perms
  o imagebuildah: use a stable sort for comparing build args
  o imagebuildah: tighten up cache checking
  o bud.bats: add a test verying the order of --build-args
  o add -t to podman run
  o imagebuildah: simplify screening by top layers
  o imagebuildah: handle ID mappings for COPY --from
  o imagebuildah: apply additionalTags ourselves
  o bud.bats: test additional tags with cached images
  o bud.bats: add a test for WORKDIR and COPY with absolute destinations
  o Cleanup Overlay Mounts content
  o Add support for file secret mounts
  o Add ability to skip secrets in mounts file
  o allow 32bit builds
  o fix tutorial instructions
  o imagebuilder: pass the right contextDir to Add()
  o add: use fileutils.PatternMatcher for .dockerignore
  o bud.bats: add another .dockerignore test
  o unshare: fallback to single usermapping
  o addHelperSymlink: clear the destination on os.IsExist errors
  o bud.bats: test replacing symbolic links
  o imagebuildah: fix handling of destinations that end with '/'
  o bud.bats: test COPY with a final "/" in the destination
  o linux: add check for sysctl before using it
  o Rework buildahimamges
  o build context: support https git repos
  o Add a test for ENV special chars behaviour
  o Check in new Dockerfiles
  o Apply custom SHELL during build time
  o config: expand variables only at the command line
  o SetEnv: we only need to expand v once
  o Add default /root if empty on chroot iso
  o Add support for Overlay volumes into the container.
  o Export buildah validate volume functions so it can share code with libpod
  o Bump baseline test to F30
  o Fix rootless handling of /dev/shm size
  o Avoid fmt.Printf() in the library
  o imagebuildah: tighten cache checking back up
  o Handle WORKDIR with dangling target
  o Default Authfile to proper path
  o Make buildah run --isolation follow BUILDAH_ISOLATION environment
  o Vendor in latest containers/storage and containers/image
  o getParent/getChildren: handle layerless images
  o imagebuildah: recognize cache images for layerless images
  o bud.bats: test scratch images with --layers caching
  o Get CHANGELOG.md updates
  o Add some symlinks to test our .dockerignore logic
  o imagebuildah: addHelper: handle symbolic links
  o commit/push: use an everything-allowed policy
  o Correct manpage formatting in files section
  o Remove must be root statement from buildah doc
  o Change image names to stable, testing and upstream
  o Don't create directory on container
  o Replace kubernetes/pause in tests with k8s.gcr.io/pause
  o imagebuildah: don't remove intermediate images if we need them
  o Rework buildahimagegit to buildahimageupstream
  o Fix Transient Mounts
  o Handle WORKDIRs that are symlinks
  o allow podman to build a client for windows
  o Touch up 1.9-dev to 1.9.0-dev
  o Resolve symlink when checking container path
  o commit: commit on every instruction, but not always with layers
  o CommitOptions: drop the unused OnBuild field
  o makeImageRef: pass in the whole CommitOptions structure
  o cmd: API cleanup: stores before images
  o run: check if SELinux is enabled
  o Fix buildahimages Dockerfiles to include support for additionalimages
    mounted from host.
  o Detect changes in rootdir
  o Fix typo in buildah-pull(1)
  o Vendor in latest containers/storage
  o Keep track of any build-args used during buildah bud --layers
  o commit: always set a parent ID
  o imagebuildah: rework unused-argument detection
  o fix bug dest path when COPY .dockerignore
  o Move Host IDMAppings code from util to unshare
  o Add BUILDAH_ISOLATION rootless back
  o Travis CI: fail fast, upon error in any step
  o imagebuildah: only commit images for intermediate stages if we have to
  o Use errors.Cause() when checking for IsNotExist errors
  o auto pass http_proxy to container
  o imagebuildah: don't leak image structs
  o Add Dockerfiles for buildahimages
  o Bump to Replace golang 1.10 with 1.12
  o add --dns* flags to buildah bud
  o Add hack/build_speed.sh test speeds on building container images
  o Create buildahimage Dockerfile for Quay
  o rename 'is' to 'expect_output'
  o squash.bats: test squashing in multi-layered builds
  o bud.bats: test COPY --from in a Dockerfile while using the cache
  o commit: make target image names optional
  o Fix bud-args to allow comma separation
  o oops, missed some tests in commit.bats
  o new helper: expect_line_count
  o New tests for #1467 (string slices in cmdline opts)
  o Workarounds for dealing with travis; review feedback
  o BATS tests - extensive but minor cleanup
  o imagebuildah: defer pulling images for COPY --from
  o imagebuildah: centralize COMMIT and image ID output
  o Travis: do not use traviswait
  o imagebuildah: only initialize imagebuilder configuration once per stage
  o Make cleaner error on Dockerfile build errors
  o unshare: move to pkg/
  o unshare: move some code from cmd/buildah/unshare
  o Fix handling of Slices versus Arrays
  o imagebuildah: reorganize stage and per-stage logic
  o imagebuildah: add empty layers for instructions
  o Add missing step in installing into Ubuntu
  o fix bug in .dockerignore support
  o imagebuildah: deduplicate prepended "FROM" instructions
  o Touch up intro
  o commit: set created-by to the shell if it isn't set
  o commit: check that we always set a "created-by"
  o docs/buildah.md: add "containers-" prefixes under "SEE ALSO"

Update to v1.7.2

  o Updates vendored containers/storage to latest version
  o rootless: by default use the host network namespace

  o Full changelog: https://github.com/containers/buildah/releases/tag/v1.6

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  o SUSE Linux Enterprise Module for Containers 15-SP2:
    zypper in -t patch SUSE-SLE-Module-Containers-15-SP2-2020-3423=1
  o SUSE Linux Enterprise Module for Containers 15-SP1:
    zypper in -t patch SUSE-SLE-Module-Containers-15-SP1-2020-3423=1

Package List:

  o SUSE Linux Enterprise Module for Containers 15-SP2 (aarch64 ppc64le s390x
  o SUSE Linux Enterprise Module for Containers 15-SP1 (aarch64 ppc64le s390x


  o https://www.suse.com/security/cve/CVE-2019-10214.html
  o https://www.suse.com/security/cve/CVE-2020-10696.html
  o https://bugzilla.suse.com/1165184
  o https://bugzilla.suse.com/1167864

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:


Australian Computer Emergency Response Team
The University of Queensland
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
Comment: http://www.auscert.org.au/render.html?it=1967