[ubuntu/jammy-updates] containerd 1.5.9-0ubuntu3.1 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Tue Dec 13 08:58:39 UTC 2022
containerd (1.5.9-0ubuntu3.1) jammy-security; urgency=medium
* SECURITY UPDATE: Memory exhaustion through Exec
- debian/patches/CVE-2022-23471.patch: Prevent goroutine leak in Exec
in pkg/cri/streaming/remotecommand/httpstream.go.
- CVE-2022-23471
* SECURITY UPDATE: Privilege escalation by inheritable file capabilities.
- debian/patches/CVE-2022-24769.patch: Unassign the Inheritable
capability in oci/spec.go and oci/spec_opts.go.
- CVE-2022-24769
* SECURITY UPDATE: Improper access to images due to imgcrypt.
- debian/patches/CVE-2022-24778.patch: perform proper
authentication by adding platforms in
vendor/github.com/containerd/imgcrypt/images/
encryption/encryption.go.
- CVE-2022-24778
* SECURITY UPDATE: Memory exhaustion through ExecSync.
- debian/patches/CVE-2022-31030.patch: limit the response size
of ExecSync in pkg/cri/server/container_execsync.go.
- CVE-2022-31030
Date: 2022-12-12 11:20:09.523078+00:00
Changed-By: David Fernandez Gonzalez <david.fernandezgonzalez at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/containerd/1.5.9-0ubuntu3.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list