Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for containerd, docker, runc fixes the following issues: - Docker was updated to 20.10.6-ce * Switch version to use -ce suffix rather than _ce to avoid confusing other tools (bsc#1182476). * CVE-2021-21284: Fixed a potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732) * CVE-2021-21285: Fixed an issue where pulling a malformed Docker image manifest crashes the dockerd daemon (bsc#1181730). - runc was updated to v1.0.0~rc93 (bsc#1182451 and bsc#1184962). * Use the upstream runc package (bsc#1181641, bsc#1181677, bsc#1175821). * Fixed /dev/null is not available (bsc#1168481). * Fixed an issue where podman hangs when spawned by salt-minion process (bsc#1149954). * CVE-2019-19921: Fixed a race condition with shared mounts
#1028638 #1034053 #1048046 #1051429 #1053532
#1095817 #1118897 #1118898 #1118899 #1121967
#1131314 #1131553 #1149954 #1152308 #1160452
#1168481 #1175081 #1175821 #1181594 #1181641
#1181677 #1181730 #1181732 #1181749 #1182451
#1182476 #1182947 #1183024 #1183397 #1183855
#1184768 #1184962
Cross- CVE-2018-16873 CVE-2018-16874 CVE-2018-16875
CVE-2019-16884 CVE-2019-19921 CVE-2019-5736
CVE-2021-21284 CVE-2021-21285 CVE-2021-21334
CVSS scores:
CVE-2018-16873 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2018-16873 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2018-16874 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2018-16874 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.