Skip to content

[release/1.1 backport] Update runc to 6635b4f (CVE-2019-5736)#2999

Merged
dmcgowan merged 1 commit intocontainerd:release/1.1from
thaJeztah:1.1_backport_bump_runc_cve_2019-5736
Feb 11, 2019
Merged

[release/1.1 backport] Update runc to 6635b4f (CVE-2019-5736)#2999
dmcgowan merged 1 commit intocontainerd:release/1.1from
thaJeztah:1.1_backport_bump_runc_cve_2019-5736

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

backport of #2997 for the 1.1 branch

Includes opencontainers/runc@6635b4f,
which fixes a vulnerability in runc that allows a container escape (CVE-2019-5736)

golang.org/x/sys was at a different version on this branch, so I re-ran vndr for that dependency to resolve that

⚠️ verify if including the x/sys change is ok, otherwise I can just include the runc bump here

Includes opencontainers/runc@6635b4f,
which fixes a vulnerability in runc that allows a container escape (CVE-2019-5736)

Signed-off-by: Sebastiaan van Stijn <[email protected]>
(cherry picked from commit 14eaad0)
Signed-off-by: Sebastiaan van Stijn <[email protected]>
Copy link
Copy Markdown
Member

@estesp estesp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@estesp estesp mentioned this pull request Feb 11, 2019
Copy link
Copy Markdown
Member

@dmcgowan dmcgowan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@dmcgowan dmcgowan merged commit 878924b into containerd:release/1.1 Feb 11, 2019
@thaJeztah thaJeztah deleted the 1.1_backport_bump_runc_cve_2019-5736 branch February 11, 2019 22:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants