Skip to content

Conversation

@thaJeztah
Copy link
Member

@thaJeztah thaJeztah commented Apr 6, 2021

opening as draft, because this vendors swarmkit from moby/swarmkit#3002 / moby/swarmkit#2985, which isn't merged yet

vendor: github.com/gogo/protobuf v1.3.2

full diff: gogo/protobuf@v1.3.1...v1.3.2

bump version 1.3.2 for gogo/protobuf due to CVE-2021-3121 reported on
gogo/protobuf version 1.3.1, CVE has been fixed for version 1.3.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

vendor github.com/containerd/containerd 19ee068f93c91f7b9b2a858457f1af2cabc7bc06

full diff: containerd/containerd@0edc412...19ee068

brings in updated protobufs, generated with gogo/protobuf v1.3.2

vendor: github.com/coreos/etcd v3.3.25

full diff: etcd-io/etcd@v3.3.12...v3.3.25

vendor: github.com/docker/swarmkit 5a5494a

full diff: moby/swarmkit@17d8d4e...5a5494a

Updated version of SwarmKit with protos generated with gogo/protobuf v1.3.2
due to CVE-2021-3121 reported on gogo/protobuf version 1.3.1, CVE has been
fixed for version 1.3.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll update this one separately; containerd/continuity@efbc448...1805252

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment on lines +34 to +35
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll update these separately

Comment on lines +55 to +56
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@thaJeztah thaJeztah marked this pull request as ready for review April 17, 2021 10:28
@thaJeztah
Copy link
Member Author

SwarmKit changes were merged, so moved this out of draft

@cpuguy83 @dperny @tonistiigi PTAL

@thaJeztah thaJeztah force-pushed the bump_containerd_protobuf branch 2 times, most recently from e58c5ef to 1be0074 Compare April 20, 2021 21:30
full diff: gogo/protobuf@v1.3.1...v1.3.2

bump version 1.3.2 for gogo/protobuf due to CVE-2021-3121 reported on
gogo/protobuf version 1.3.1, CVE has been fixed for version 1.3.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

Signed-off-by: Sebastiaan van Stijn <[email protected]>
…af2cabc7bc06

full diff: containerd/containerd@55eda46...19ee068

brings in updated protobufs, generated with gogo/protobuf v1.3.2

Signed-off-by: Sebastiaan van Stijn <[email protected]>
full diff: moby/swarmkit@17d8d4e...5a5494a

Updated version of SwarmKit with protos generated with gogo/protobuf v1.3.2
due to CVE-2021-3121 reported on gogo/protobuf version 1.3.1, CVE has been
fixed for version 1.3.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah thaJeztah force-pushed the bump_containerd_protobuf branch from 1be0074 to 1c7585a Compare April 20, 2021 21:46

# containerd
github.com/containerd/containerd 55eda46b22f985cde99b599e469ff9c13994bf68 # master (v1.5.0-dev)
github.com/containerd/containerd 19ee068f93c91f7b9b2a858457f1af2cabc7bc06 # master (v1.5.0-dev)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I imagine this could probably go as far as something like v1.5.0-rc.2 now, right? 😇
(some conceptual overlap with #42308, even if not the same files)

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, I'm planning on updating to latest version; I picked this commit to keep this PR specific to the protobuf v1.3.2 update (although, after discussing, it doesn't directly affect us / not reasonably exploitable)

Copy link
Member

@tianon tianon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM regardless 👍

@cpuguy83 cpuguy83 merged commit 369d0dc into moby:master Apr 22, 2021
@thaJeztah thaJeztah deleted the bump_containerd_protobuf branch April 22, 2021 21:42
thaJeztah added a commit to thaJeztah/docker that referenced this pull request Nov 9, 2021
Possibly more dependencies need to be updated, and instead of this we should cherry-pick.
This is just a quick check "what would it look like if we bumped the version in this branch";

Updating to containerd 1.5

Last containerd update in 20.10 is moby@1f88736 (moby#41688)

- moby@ab1dd80 moby#42274
- moby@5761fca moby#42274
- moby@42ef2c5 moby#42276
- moby@6202322 moby#42254
- moby@7c1c123 moby#42249
- moby@84df737 moby#42636
- moby@4fc2d4d moby#42656
- moby@3d58d13 moby#42697
- moby@582ef29 moby#42994

Signed-off-by: Sebastiaan van Stijn <[email protected]>
thaJeztah added a commit to thaJeztah/docker that referenced this pull request Nov 9, 2021
Possibly more dependencies need to be updated, and instead of this we should cherry-pick.
This is just a quick check "what would it look like if we bumped the version in this branch";

Updating to containerd 1.5

Last containerd update in 20.10 is moby@1f88736 (moby#41688)

- moby@ab1dd80 moby#42274
- moby@5761fca moby#42274
- moby@42ef2c5 moby#42276
- moby@6202322 moby#42254
- moby@7c1c123 moby#42249
- moby@84df737 moby#42636
- moby@4fc2d4d moby#42656
- moby@3d58d13 moby#42697
- moby@582ef29 moby#42994

Signed-off-by: Sebastiaan van Stijn <[email protected]>
thaJeztah added a commit to thaJeztah/docker that referenced this pull request Mar 18, 2022
Possibly more dependencies need to be updated, and instead of this we should cherry-pick.
This is just a quick check "what would it look like if we bumped the version in this branch";

Updating to containerd 1.5

Last containerd update in 20.10 is moby@1f88736 (moby#41688)

- moby@ab1dd80 moby#42274
- moby@5761fca moby#42274
- moby@42ef2c5 moby#42276
- moby@6202322 moby#42254
- moby@7c1c123 moby#42249
- moby@84df737 moby#42636
- moby@4fc2d4d moby#42656
- moby@3d58d13 moby#42697
- moby@582ef29 moby#42994
- moby@458b4aa moby#43025

Signed-off-by: Sebastiaan van Stijn <[email protected]>
thaJeztah added a commit to thaJeztah/docker that referenced this pull request Mar 18, 2022
Possibly more dependencies need to be updated, and instead of this we should cherry-pick.
This is just a quick check "what would it look like if we bumped the version in this branch";

Updating to containerd 1.5

Last containerd update in 20.10 is moby@1f88736 (moby#41688)

- moby@ab1dd80 moby#42274
- moby@5761fca moby#42274
- moby@42ef2c5 moby#42276
- moby@6202322 moby#42254
- moby@7c1c123 moby#42249
- moby@84df737 moby#42636
- moby@4fc2d4d moby#42656
- moby@3d58d13 moby#42697
- moby@582ef29 moby#42994
- moby@458b4aa moby#43025

Signed-off-by: Sebastiaan van Stijn <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants