Lucene search

K
suseSuseOPENSUSE-SU-2021:4171-1
HistoryDec 23, 2021 - 12:00 a.m.

Security update for runc (moderate)

2021-12-2300:00:00
lists.opensuse.org
25
runc
vulnerability fix
netlink
bind mount
read-only fuse
cgroup
hugetlb
patch instructions
opensuse leap 15.3

EPSS

0.008

Percentile

81.9%

An update that fixes one vulnerability is now available.

Description:

This update for runc fixes the following issues:

Update to runc v1.0.3.

  • CVE-2021-43784: Fixed a potential vulnerability related to the internal
    usage
    of netlink, which is believed to not be exploitable with any released
    versions of runc (bsc#1193436)
  • Fixed inability to start a container with read-write bind mount of a
    read-only fuse host mount.
  • Fixed inability to start when read-only /dev in set in spec.
  • Fixed not removing sub-cgroups upon container delete, when rootless
    cgroup v2 is used with older systemd.
  • Fixed returning error from GetStats when hugetlb is unsupported (which
    causes excessive logging for kubernetes).

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.3:

    zypper in -t patch openSUSE-SLE-15.3-2021-4171=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.3aarch64< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.aarch64.rpm
openSUSE Leap15.3ppc64le< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.ppc64le.rpm
openSUSE Leap15.3s390x< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.s390x.rpm
openSUSE Leap15.3x86_64< - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):.x86_64.rpm