Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

SUSE: 2021:1458-1 Important: Containerd, Docker, Runc Security Update

suse
Calendar Grey April 30, 2021
Scroller Suse
Essential patches released for containerd, docker, and runc tackling various security flaws.
An update that solves 9 vulnerabilities and has 23 fixes is now available

Summary

This update for containerd, docker, runc fixes the following issues: - Docker was updated to 20.10.6-ce * Switch version to use -ce suffix rather than _ce to avoid confusing other tools (bsc#1182476). * CVE-2021-21284: Fixed a potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732) * CVE-2021-21285: Fixed an issue where pulling a malformed Docker image manifest crashes the dockerd daemon (bsc#1181730). - runc was updated to v1.0.0~rc93 (bsc#1182451 and bsc#1184962). * Use the upstream runc package (bsc#1181641, bsc#1181677, bsc#1175821). * Fixed /dev/null is not available (bsc#1168481). * Fixed an issue where podman hangs when spawned by salt-minion process (bsc#1149954). * CVE-2019-19921: Fixed a race condition with shared mounts

References

#1028638 #1034053 #1048046 #1051429 #1053532

#1095817 #1118897 #1118898 #1118899 #1121967

#1131314 #1131553 #1149954 #1152308 #1160452

#1168481 #1175081 #1175821 #1181594 #1181641

#1181677 #1181730 #1181732 #1181749 #1182451

#1182476 #1182947 #1183024 #1183397 #1183855

#1184768 #1184962

Cross- CVE-2018-16873 CVE-2018-16874 CVE-2018-16875

CVE-2019-16884 CVE-2019-19921 CVE-2019-5736

CVE-2021-21284 CVE-2021-21285 CVE-2021-21334

CVSS scores:

CVE-2018-16873 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2018-16873 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2018-16874 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2018-16874 (SUSE): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1458-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.