--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2022-5038c3236c
2022-07-31 01:30:22.784813
--------------------------------------------------------------------------------Name        : runc
Product     : Fedora 36
Version     : 1.1.2
Release     : 3.fc36
URL         : https://github.com/opencontainers/runc
Summary     : CLI for running Open Containers
Description :
The runc command can be used to start containers which are packaged
in accordance with the Open Container Initiative's specifications,
and to manage containers running under runc.

--------------------------------------------------------------------------------Update Information:

Rebuild to mitigate
CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang  ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more
information about the specific vulnerabilities.  ----  Update to latest commit
as of 20220719  ----  Added      Experimental: nebula clients can be configured
to act as relays for other nebula clients.     Primarily useful when stubborn
NATs make a direct tunnel impossible. (#678)      Configuration option to report
manually specified ip:ports to lighthouses. (#650)      Windows arm64 build.
(#638)      punchy and most lighthouse config options now support hot reloading.
(#649)  Changed      Build against go 1.18. (#656)      Promoted routines config
from experimental to supported feature. (#702)      Dependencies updated. (#664)
Fixed      Packets destined for the same host that sent it will be returned on
MacOS.     This matches the default behavior of other operating systems. (#501)
unsafe_route configuration will no longer crash on Windows. (#648)      A few
panics that were introduced in 1.5.x. (#657, #658, #675)  Security      You can
set listen.send_recv_error to control the conditions in which     recv_error
messages are sent. Sending these messages can expose the fact     that Nebula is
running on a host, but it speeds up re-handshaking. (#670)  Removed      x509
config stanza support has been removed. (#685)  ----  bump to v4.2.0-rc1  ----fix package dir listing  ----  resolve build issues and list new shell
completion files  ----  Release of stargz snapshotter v0.12.0. Please see the
release note for details: https://github.com/containerd/stargz-snapshotter/releases/tag/v0.12.0   ----  Fix extracting network metric
--------------------------------------------------------------------------------ChangeLog:

* Tue Jul 19 2022 Maxwell G  - 2:1.1.2-3
- Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
  golang
* Mon Jun 27 2022 Maxwell G  - 2:1.1.2-1
- Update to 1.1.2. Fixes rhbz#2069648.
- Mitigate CVE-2022-29162 / GHSA-f3fp-gc8g-vw66.
- Don't pull in git unnecessarily
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-5038c3236c' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Fedora 36: runc 2022-5038c3236c

July 30, 2022
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more in...

Summary

The runc command can be used to start containers which are packaged

in accordance with the Open Container Initiative's specifications,

and to manage containers running under runc.

Rebuild to mitigate

CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more

information about the specific vulnerabilities. ---- Update to latest commit

as of 20220719 ---- Added Experimental: nebula clients can be configured

to act as relays for other nebula clients. Primarily useful when stubborn

NATs make a direct tunnel impossible. (#678) Configuration option to report

manually specified ip:ports to lighthouses. (#650) Windows arm64 build.

(#638) punchy and most lighthouse config options now support hot reloading.

(#649) Changed Build against go 1.18. (#656) Promoted routines config

from experimental to supported feature. (#702) Dependencies updated. (#664)

Fixed Packets destined for the same host that sent it will be returned on

MacOS. This matches the default behavior of other operating systems. (#501)

unsafe_route configuration will no longer crash on Windows. (#648) A few

panics that were introduced in 1.5.x. (#657, #658, #675) Security You can

set listen.send_recv_error to control the conditions in which recv_error

messages are sent. Sending these messages can expose the fact that Nebula is

running on a host, but it speeds up re-handshaking. (#670) Removed x509

config stanza support has been removed. (#685) ---- bump to v4.2.0-rc1 ----fix package dir listing ---- resolve build issues and list new shell

completion files ---- Release of stargz snapshotter v0.12.0. Please see the

release note for details: https://github.com/containerd/stargz-snapshotter/releases/tag/v0.12.0 ---- Fix extracting network metric

* Tue Jul 19 2022 Maxwell G - 2:1.1.2-3

- Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in

golang

* Mon Jun 27 2022 Maxwell G - 2:1.1.2-1

- Update to 1.1.2. Fixes rhbz#2069648.

- Mitigate CVE-2022-29162 / GHSA-f3fp-gc8g-vw66.

- Don't pull in git unnecessarily

su -c 'dnf upgrade --advisory FEDORA-2022-5038c3236c' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

FEDORA-2022-5038c3236c 2022-07-31 01:30:22.784813 Product : Fedora 36 Version : 1.1.2 Release : 3.fc36 URL : https://github.com/opencontainers/runc Summary : CLI for running Open Containers Description : The runc command can be used to start containers which are packaged in accordance with the Open Container Initiative's specifications, and to manage containers running under runc. Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- Update to latest commit as of 20220719 ---- Added Experimental: nebula clients can be configured to act as relays for other nebula clients. Primarily useful when stubborn NATs make a direct tunnel impossible. (#678) Configuration option to report manually specified ip:ports to lighthouses. (#650) Windows arm64 build. (#638) punchy and most lighthouse config options now support hot reloading. (#649) Changed Build against go 1.18. (#656) Promoted routines config from experimental to supported feature. (#702) Dependencies updated. (#664) Fixed Packets destined for the same host that sent it will be returned on MacOS. This matches the default behavior of other operating systems. (#501) unsafe_route configuration will no longer crash on Windows. (#648) A few panics that were introduced in 1.5.x. (#657, #658, #675) Security You can set listen.send_recv_error to control the conditions in which recv_error messages are sent. Sending these messages can expose the fact that Nebula is running on a host, but it speeds up re-handshaking. (#670) Removed x509 config stanza support has been removed. (#685) ---- bump to v4.2.0-rc1 ----fix package dir listing ---- resolve build issues and list new shell completion files ---- Release of stargz snapshotter v0.12.0. Please see the release note for details: https://github.com/containerd/stargz-snapshotter/releases/tag/v0.12.0 ---- Fix extracting network metric * Tue Jul 19 2022 Maxwell G - 2:1.1.2-3 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang * Mon Jun 27 2022 Maxwell G - 2:1.1.2-1 - Update to 1.1.2. Fixes rhbz#2069648. - Mitigate CVE-2022-29162 / GHSA-f3fp-gc8g-vw66. - Don't pull in git unnecessarily su -c 'dnf upgrade --advisory FEDORA-2022-5038c3236c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
Product : Fedora 36
Version : 1.1.2
Release : 3.fc36
URL : https://github.com/opencontainers/runc
Summary : CLI for running Open Containers

Related News