Ubuntu Security Update USN-5311-2: containerd regression

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,969
Reaction score
80
Credits
-1,257
USN-5311-1 released updates for contained. Unfortunately, a subsequent update reverted the fix for this CVE by mistake. This update corrects the problem. We apologize for the inconvenience. Original advisory details: It was discovered that containerd allows attackers to gain access to read- only copies of arbitrary files and directories on the host via a specially- crafted image configuration. An attacker could possibly use this issue to obtain sensitive information.

Continue reading...
 
Top