Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #237810

runc CVEs in docker.io

From "Gareth Evans" <donotspam@fastmail.fm>
Newsgroups linux.debian.user
Subject runc CVEs in docker.io
Date 2021-07-27 18:10 +0200
Message-ID <CFxOx-6zn-5@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


Hello,

I was just trying to install docker.io on Buster stable when apt-listbugs complained about one of the open CVEs listed here:

https://security-tracker.debian.org/tracker/source-package/runc

Given that these are all fixed in Bullseye (and at least the grave apt-listbugs issue has been fixed in eg Ubuntu since March 2020 [1]) why not also Buster?

apt-listbugs said:

... CVE-2019-16884 (Fixed: runc/1.0.0~rc9+dfsg1-1) ...

According to 

https://tracker.debian.org/pkg/runc

there are 3 open security issues in (Stretch and) Buster (though I imagine Debian's support for Stretch has ended with EOL in 2020?) - do fixes like this come in batches?  

Thanks,
Gareth

[1] https://ubuntu.com/security/notices/USN-4297-1

Back to linux.debian.user | Previous | NextNext in thread | Find similar | Unroll thread


Thread

runc CVEs in docker.io "Gareth Evans" <donotspam@fastmail.fm> - 2021-07-27 18:10 +0200
  Re: runc CVEs in docker.io Dominique Dumont <dod@debian.org> - 2021-08-02 12:50 +0200
    Re: runc CVEs in docker.io "Gareth Evans" <donotspam@fastmail.fm> - 2021-08-04 14:50 +0200
      Re: runc CVEs in docker.io Dominique Dumont <dominique.dumont@netc.fr> - 2021-08-07 16:30 +0200
  Re: runc CVEs in docker.io Thomas Hochstein <thh@thh.name> - 2021-08-04 18:40 +0200

csiph-web