MGASA-2023-0329 - Updated docker packages fix security vulnerabilities and bugs

Publication date: 29 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0329.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-26054,
     CVE-2023-28840,
     CVE-2023-28841,
     CVE-2023-28842

This update fixes several security issues and also solves some other
issues

- manage change of launch option earlier in post process
- Automatically convert -g option to --data-root in installed
  /etc/sysconfig/docker-storage
- Fix CVE-2023-26054 and CVE-2023-2884[0-2]

References:
- https://bugs.mageia.org/show_bug.cgi?id=31733
- https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw
- https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc
- https://github.com/moby/moby/releases/tag/v24.0.5
- https://github.com/moby/moby/releases/tag/v24.0.4
- https://github.com/moby/moby/releases/tag/v24.0.3
- https://github.com/moby/moby/releases/tag/v24.0.2
- https://github.com/moby/moby/releases/tag/v24.0.1
- https://github.com/moby/moby/releases/tag/v24.0.0
- https://github.com/moby/moby/releases/tag/v23.0.3
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26054
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28840
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28841
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28842

SRPMS:
- 9/core/docker-24.0.5-4.mga9
- 9/core/docker-containerd-1.7.3-1.mga9

Mageia 2023-0329: docker security update

This update fixes several security issues and also solves some other issues - manage change of launch option earlier in post process - Automatically convert -g option to --data-ro...

Summary

This update fixes several security issues and also solves some other issues
- manage change of launch option earlier in post process - Automatically convert -g option to --data-root in installed /etc/sysconfig/docker-storage - Fix CVE-2023-26054 and CVE-2023-2884[0-2]

References

- https://bugs.mageia.org/show_bug.cgi?id=31733

- https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw

- https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc

- https://github.com/moby/moby/releases/tag/v24.0.5

- https://github.com/moby/moby/releases/tag/v24.0.4

- https://github.com/moby/moby/releases/tag/v24.0.3

- https://github.com/moby/moby/releases/tag/v24.0.2

- https://github.com/moby/moby/releases/tag/v24.0.1

- https://github.com/moby/moby/releases/tag/v24.0.0

- https://github.com/moby/moby/releases/tag/v23.0.3

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26054

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28840

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28841

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28842

Resolution

MGASA-2023-0329 - Updated docker packages fix security vulnerabilities and bugs

SRPMS

- 9/core/docker-24.0.5-4.mga9

- 9/core/docker-containerd-1.7.3-1.mga9

Severity
Publication date: 29 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0329.html
Type: security
CVE: CVE-2023-26054, CVE-2023-28840, CVE-2023-28841, CVE-2023-28842

Related News