=========================================================================Ubuntu Security Notice USN-4881-1
March 17, 2021

containerd vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS

Summary:

The system could be made to expose sensitive information.

Software Description:
- containerd: daemon to control runC

Details:

It was discovered that containerd incorrectly handled certain environment
variables. Contrary to expectations, a container could receive environment
variables defined for a different container, possibly containing sensitive
information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  containerd                      1.3.7-0ubuntu3.3

Ubuntu 20.04 LTS:
  containerd                      1.3.3-0ubuntu2.3

After a standard system update you need to restart containerd to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4881-1
  CVE-2021-21334

Package Information:
  https://launchpad.net/ubuntu/+source/containerd/1.3.7-0ubuntu3.3
  https://launchpad.net/ubuntu/+source/containerd/1.3.3-0ubuntu2.3

Ubuntu 4881-1: containerd vulnerability

March 17, 2021
The system could be made to expose sensitive information.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: containerd 1.3.7-0ubuntu3.3 Ubuntu 20.04 LTS: containerd 1.3.3-0ubuntu2.3 After a standard system update you need to restart containerd to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4881-1

CVE-2021-21334

Severity
March 17, 2021

Package Information

https://launchpad.net/ubuntu/+source/containerd/1.3.7-0ubuntu3.3 https://launchpad.net/ubuntu/+source/containerd/1.3.3-0ubuntu2.3

Related News