Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 30: FEDORA-2019-2baa1f7b19 Critical: LXC 3.0.4 Container Escape

fedora
Calendar Grey September 6, 2019
Dist Fedora Esm H88
Upgrade LXC to version 3.0.4, addressing a crucial container breakout vulnerability for Fedora 30 users.
Update LXC to version 3.0.4

Summary

Linux Resource Containers provide process and resource isolation without the

overhead of full virtualization.

Update LXC to version 3.0.4. The release announcement can be found

[here](https://discuss.linuxcontainers.org/t/lxc-3-0-4-has-been-released/5080).

* Fri Aug 16 2019 Thomas Moschny - 3.0.4-1

- Update to 3.0.4.

* Thu Jul 25 2019 Fedora Release Engineering - 3.0.3-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

* Sun Apr 28 2019 Thomas Moschny - 3.0.3-3

- Add patch for CVE-2019-5736.

- Build and include init.lxc.static where possible (rhbz#1654366).

[ 1 ] Bug #1664908 - CVE-2019-5736 runc: Execution of malicious containers allows for container escape and access to host filesystem

https://bugzilla.redhat.com/show_bug.cgi?id=1664908

su -c 'dnf upgrade --advisory FEDORA-2019-2baa1f7b19' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 3.0.4
Release: 1.fc30
Summary: Linux Resource Containers

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here