From 431ac3a9f5dcefff21a1d697f48ac6b663d25785 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Tue, 6 Aug 2024 05:38:04 +0000 Subject: [ GLSA 202408-01 ] containerd: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/897960 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202408-01.xml | 43 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 glsa-202408-01.xml (limited to 'glsa-202408-01.xml') diff --git a/glsa-202408-01.xml b/glsa-202408-01.xml new file mode 100644 index 00000000..29248eda --- /dev/null +++ b/glsa-202408-01.xml @@ -0,0 +1,43 @@ + + + + containerd: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in containerd, the worst of which could lead to privilege escalation. + containerd + 2024-08-06 + 2024-08-06 + 897960 + local + + + 1.6.19 + 1.6.19 + + + +

containerd is a daemon with an API and a command line client, to manage containers on one machine. It uses runC to run containers according to the OCI specification.

+
+ +

Multiple vulnerabilities have been discovered in containerd. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All containerd users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-containers/containerd-1.6.19" + +
+ + CVE-2023-25153 + CVE-2023-25173 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad