Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2020-0103 Security Update for Opencontainers-Runc Critical Issue

mageia
Calendar Grey February 26, 2020
Dist Mageia Esm H88
The latest opencontainers-runc update has resolved a vulnerability concerning volume sharing in Mageia. It's important to apply the fix immediately.
Updated opencontainers-runc package fixes security vulnerability: An attacker who controls the container image for two containers that share a volume can race volume mounts during...

Summary

Updated opencontainers-runc package fixes security vulnerability:
An attacker who controls the container image for two containers that share a volume can race volume mounts during container initialization, by adding a symlink to the rootfs that points to a directory on the volume (CVE-2019-19921).

References

- https://bugs.mageia.org/show_bug.cgi?id=26173

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2NWDTSREUDLT3UFYS5SBIVQBS4YRA35A/

- https://www.cve.org/CVERecord?id=CVE-2019-19921

Resolution

SRPMS

- 7/core/opencontainers-runc-1.0.0-0.rc10.3.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 26 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0103.html
Type: security
CVE: CVE-2019-19921

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here