Debian Golang-Github-Containers-Storage vulnerabilities
2 known vulnerabilities affecting debian/golang-github-containers-storage.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-9676P3MEDIUMCVSS 6.5fixed in golang-github-containers-storage 1.55.1+ds1-1 (forky)2024
CVE-2024-9676 [MEDIUM] CVE-2024-9676: golang-github-containers-storage - A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vul...
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The con
debian
CVE-2021-20291P4MEDIUMCVSS 6.5fixed in golang-github-containers-storage 1.34.1+ds1-1 (bookworm)2021
CVE-2021-20291 [MEDIUM] CVE-2021-20291: golang-github-containers-storage - A deadlock vulnerability was found in 'github.com/containers/storage' in version...
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream,
debian