Lucene search

K
suseSuseOPENSUSE-SU-2021:1625-1
HistoryDec 26, 2021 - 12:00 a.m.

Security update for runc (moderate)

2021-12-2600:00:00
lists.opensuse.org
22

0.008 Low

EPSS

Percentile

81.9%

An update that fixes one vulnerability is now available.

Description:

This update for runc fixes the following issues:

Update to runc v1.0.3.

  • CVE-2021-43784: Fixed a potential vulnerability related to the internal
    usage
    of netlink, which is believed to not be exploitable with any released
    versions of runc (bsc#1193436)
  • Fixed inability to start a container with read-write bind mount of a
    read-only fuse host mount.
  • Fixed inability to start when read-only /dev in set in spec.
  • Fixed not removing sub-cgroups upon container delete, when rootless
    cgroup v2 is used with older systemd.
  • Fixed returning error from GetStats when hugetlb is unsupported (which
    causes excessive logging for kubernetes).

This update was imported from the SUSE:SLE-15:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.2:

    zypper in -t patch openSUSE-2021-1625=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.2x86_64< - openSUSE Leap 15.2 (x86_64):- openSUSE Leap 15.2 (x86_64):.x86_64.rpm