[ubuntu/kinetic-security] containerd 1.6.4-0ubuntu1.1 (Accepted)

David Fernandez Gonzalez david.fernandezgonzalez at canonical.com
Tue Dec 13 07:43:55 UTC 2022


containerd (1.6.4-0ubuntu1.1) kinetic-security; urgency=medium

  * SECURITY UPDATE: Memory exhaustion through Exec
    - debian/patches/CVE-2022-23471.patch: Prevent goroutine leak in Exec
      in pkg/cri/streaming/remotecommand/httpstream.go.
    - CVE-2022-23471
  * SECURITY UPDATE: Memory exhaustion through ExecSync.
    - debian/patches/CVE-2022-31030.patch: limit the response size
      of ExecSync in pkg/cri/server/container_execsync.go.
    - CVE-2022-31030

Date: 2022-12-12 11:26:09.479091+00:00
Changed-By: David Fernandez Gonzalez <david.fernandezgonzalez at canonical.com>
https://launchpad.net/ubuntu/+source/containerd/1.6.4-0ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the kinetic-changes mailing list