Skip to content

[release/1.6 backport] update runc binary and vendor to v1.1.2#6936

Merged
kzys merged 2 commits intocontainerd:release/1.6from
thaJeztah:1.6_bump_runc
May 12, 2022
Merged

[release/1.6 backport] update runc binary and vendor to v1.1.2#6936
kzys merged 2 commits intocontainerd:release/1.6from
thaJeztah:1.6_bump_runc

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

This is the second patch release of the runc 1.1 release branch. It
fixes CVE-2022-29162, a minor security issue (which appears to not be
exploitable) related to process capabilities.

This is a similar bug to the ones found and fixed in Docker and
containerd recently (CVE-2022-24769).

  • A bug was found in runc where runc exec --cap executed processes with
    non-empty inheritable Linux process capabilities, creating an atypical Linux
    environment. For more information, see GHSA-f3fp-gc8g-vw66 and CVE-2022-29162.
  • runc spec no longer sets any inheritable capabilities in the created
    example OCI spec (config.json) file.

@estesp
Copy link
Copy Markdown
Member

estesp commented May 12, 2022

I think we will need #6941 before this will pass CI

thaJeztah added 2 commits May 13, 2022 01:02
This is the second patch release of the runc 1.1 release branch. It
fixes CVE-2022-29162, a minor security issue (which appears to not be
exploitable) related to process capabilities.

This is a similar bug to the ones found and fixed in Docker and
containerd recently (CVE-2022-24769).

- A bug was found in runc where runc exec --cap executed processes with
  non-empty inheritable Linux process capabilities, creating an atypical Linux
  environment. For more information, see GHSA-f3fp-gc8g-vw66 and CVE-2022-29162.
- runc spec no longer sets any inheritable capabilities in the created
  example OCI spec (config.json) file.

Signed-off-by: Sebastiaan van Stijn <[email protected]>
(cherry picked from commit 25858d6)
Signed-off-by: Sebastiaan van Stijn <[email protected]>
no changes in vendored code

Signed-off-by: Sebastiaan van Stijn <[email protected]>
(cherry picked from commit c4ce13a)
Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
Copy link
Copy Markdown
Member Author

I think we will need #6941 before this will pass CI

Saw it was merged, so did a quick rebase

@kzys kzys merged commit 1bb7d39 into containerd:release/1.6 May 12, 2022
@thaJeztah thaJeztah deleted the 1.6_bump_runc branch May 12, 2022 23:44
@AkihiroSuda
Copy link
Copy Markdown
Member

@dmcgowan Do we plan to release v1.6.5 with this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants