containerd could be made to behave unexpectedly.
Software Description:
- containerd-app: open and reliable container runtime
- containerd: open and reliable container runtime library
Details:
Benjamin Koltermann discovered that containerd incorrectly handled large
user id values. This could result in containers possibly being run as root,
contrary to expectations.
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 containerd 2.0.0~rc3-0ubuntu1.1 Ubuntu 24.04 LTS containerd 1.7.24-0ubuntu1~24.04.2 golang-github-containerd-containerd-dev 1.6.24~ds1-1ubuntu1.2+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS containerd 1.7.24-0ubuntu1~22.04.2 golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~22.04.8 Ubuntu 20.04 LTS containerd 1.7.24-0ubuntu1~20.04.2 golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~20.04.8 Ubuntu 18.04 LTS containerd 1.6.12-0ubuntu1~18.04.1+esm2 Available with Ubuntu Pro golang-github-containerd-containerd-dev 1.6.12-0ubuntu1~18.04.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS containerd 1.2.6-0ubuntu1~16.04.6+esm5 Available with Ubuntu Pro golang-github-docker-containerd-dev 1.2.6-0ubuntu1~16.04.6+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-7374-1
CVE-2024-40635
Get the latest Linux and open source security news straight to your inbox.