Please login to access the resource
Overview

Request 976494 accepted

- Update to runc v1.1.2. Upstream changelog is available from
https://github.com/opencontainers/runc/releases/tag/v1.1.2.
CVE-2022-24769

* A bug was found in runc where runc exec --cap executed processes with
non-empty inheritable Linux process capabilities, creating an atypical Linux
environment. For more information, see [GHSA-f3fp-gc8g-vw66][] and
CVE-2022-29162.
* `runc spec` no longer sets any inheritable capabilities in the created
example OCI spec (`config.json`) file.

Loading...
Request History
Aleksa Sarai's avatar

cyphar created request

- Update to runc v1.1.2. Upstream changelog is available from
https://github.com/opencontainers/runc/releases/tag/v1.1.2.
CVE-2022-24769

* A bug was found in runc where runc exec --cap executed processes with
non-empty inheritable Linux process capabilities, creating an atypical Linux
environment. For more information, see [GHSA-f3fp-gc8g-vw66][] and
CVE-2022-29162.
* `runc spec` no longer sets any inheritable capabilities in the created
example OCI spec (`config.json`) file.


Aleksa Sarai's avatar

cyphar accepted request

LGTM.

openSUSE Build Service is sponsored by