runc 1.1.7-0ubuntu1~20.04.2 source package in Ubuntu

Changelog

runc (1.1.7-0ubuntu1~20.04.2) focal-security; urgency=medium

  * SECURITY UPDATE: container escape vulnerability
    - d/p/0001-Fix-File-to-Close.patch: Fix File to Close
    - d/p/0002-init-verify-after-chdir-that-cwd-is-inside-the-conta.patch:
      init: verify after chdir that cwd is inside the container
    - d/p/0003-setns-init-do-explicit-lookup-of-execve-argument-ear.patch:
      setns init: do explicit lookup of execve argument early
    - d/p/0004-init-close-internal-fds-before-execve.patch: init: close
      internal fds before execve
    - d/p/0005-cgroup-plug-leaks-of-sys-fs-cgroup-handle.patch: cgroup:
      plug leaks of /sys/fs/cgroup handle
    - d/p/0006-libcontainer-mark-all-non-stdio-fds-O_CLOEXEC-before.patch:
      ibcontainer: mark all non-stdio fds O_CLOEXEC before spawning init
    - CVE-2024-21626

 -- Nishit Majithia <email address hidden>  Wed, 24 Jan 2024 16:33:42 +0530

Upload details

Uploaded by:
Nishit Majithia
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
devel
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates main misc
Focal security main misc

Downloads

File Size SHA-256 Checksum
runc_1.1.7.orig.tar.xz 1.4 MiB 86444cc07461b81bbcb8d15c5fc2cad20afc64a70be0fc623073538aa91bafdd
runc_1.1.7-0ubuntu1~20.04.2.debian.tar.xz 17.8 KiB 3c6a2362a586ab79af4713eb2d6f6d46cac79dbe1c229713067e5d1e22d38567
runc_1.1.7-0ubuntu1~20.04.2.dsc 2.3 KiB d0b66369d8e95af3a032ca1dc72cb489f679c9ad9285aa1338b2d96e641b1c86

View changes file

Binary packages built by this source

golang-github-opencontainers-runc-dev: Open Container Project - development files

 "runc" is a command line client for running applications packaged according
 to the Open Container Format (OCF) and is a compliant implementation of
 the Open Container Project specification.
 .
 This package provides development files formerly known as
 "github.com/docker/libcontainer".

runc: Open Container Project - runtime

 "runc" is a command line client for running applications packaged according
 to the Open Container Format (OCF) and is a compliant implementation of
 the Open Container Project specification.

runc-dbgsym: debug symbols for runc