8000 [release/1.1] Update runc for CVE-2019-16884 by crosbymichael · Pull Request #3688 · containerd/containerd · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

[release/1.1] Update runc for CVE-2019-16884 #3688

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Sep 26, 2019

Conversation

crosbymichael
Copy link
Member

Signed-off-by: Michael Crosby crosbymichael@gmail.com

Signed-off-by: Michael Crosby <crosbymichael@gmail.com>
Copy link
Contributor
@jterry75 jterry75 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member
@dmcgowan dmcgowan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@dmcgowan dmcgowan merged commit ed1b4ef into containerd:release/1.1 Sep 26, 2019
@crosbymichael crosbymichael deleted the runc-cve branch September 26, 2019 18:35
@kolyshkin
Copy link
Contributor

@crosbymichael @dmcgowan Hmm, I see that files patched to fix the runc's CVE-2019-16884 (see opencontainers/runc#2129) are not in this commit (as they are not used by containerd and thus are discarded by vndr). It means this PR is shallow/useless by itself (aside from the fact that it brings some other updates to runc code, not related to the CVE). Or am I missing something? The only thing I can think of is someone copy-pasting the sha from vendor.conf to build runc binary...

@estesp
Copy link
Member
estesp commented Oct 2, 2019

The last sentence is the winner :) It's a packaging detail, so that when we package containerd we are using the properly fixed version of runc:
https://github.com/containerd/containerd/blob/master/script/setup/install-runc#L24

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants
0