Skip to content

runc: update to 1.1.2#469

Merged
Beginner-Go merged 1 commit intocoolsnowwolf:masterfrom
breakings:runc_1.1.2
Jun 8, 2022
Merged

runc: update to 1.1.2#469
Beginner-Go merged 1 commit intocoolsnowwolf:masterfrom
breakings:runc_1.1.2

Conversation

@breakings
Copy link
Contributor

This is the second patch release of the runc 1.1 release branch. It
fixes GHSA-f3fp-gc8g-vw66, a minor security issue (which appears to not be
exploitable) related to process capabilities.

This is a similar bug to the ones found and fixed in Docker and
containerd recently (CVE-2022-24769).

A bug was found in runc where runc exec --cap executed processes with
non-empty inheritable Linux process capabilities, creating an atypical Linux
environment. For more information, see GHSA-f3fp-gc8g-vw66 and
GHSA-f3fp-gc8g-vw66.
runc spec no longer sets any inheritable capabilities in the created
example OCI spec (config.json) file.

@Beginner-Go Beginner-Go merged commit 288d9b4 into coolsnowwolf:master Jun 8, 2022
github-actions bot added a commit to HAN767/lede-packages that referenced this pull request Jun 8, 2022
* https://github.com/coolsnowwolf/packages:
  tailscale: update to 1.26.0 (coolsnowwolf#472)
  libnetwork: update to latest HEAD (coolsnowwolf#471)
  containerd: update to 1.6.6 (coolsnowwolf#470)
  runc: update to 1.1.2 (coolsnowwolf#469)
  docker: Update to v20.10.17 (coolsnowwolf#468)
  dockerd: Update to v20.10.17 (coolsnowwolf#467)
github-actions bot added a commit to swirly0p/lean-packages that referenced this pull request Jun 9, 2022
* https://github.com/coolsnowwolf/packages:
  tailscale: update to 1.26.0 (coolsnowwolf#472)
  libnetwork: update to latest HEAD (coolsnowwolf#471)
  containerd: update to 1.6.6 (coolsnowwolf#470)
  runc: update to 1.1.2 (coolsnowwolf#469)
  docker: Update to v20.10.17 (coolsnowwolf#468)
  dockerd: Update to v20.10.17 (coolsnowwolf#467)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants