Multiple vulnerabilities were discovered in runc, the Open Container Project runtime, which is often used with virtualization environments such as Docker. Malicious Docker images or OCI bundles could breach isolation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3369-1
Update LXC to the latest stable release. The full list of changes can be found [here](https://linuxcontainers.org/lxc/news/#lxc-114-release-announcement6th-of-october-2015).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9f8f4b182a 2015-11-01 01:51:21.166430 -------------------------------------------------------------------------------- Name : lxc Product : Fedora 23 Version : 1.1.4 Release : 2.fc23 URL : https://linuxcontainers.org/ Summary : Linux Resource ContainersDescription : Linux Resource Containers provide process and resource isolation without the overhead of full virtualization. -------------------------------------------------------------------------------- Update Information: Update LXC to the latest stable release. The full list of changes can be found [here](https://linuxcontainers.org/lxc/news/#lxc-114-release-announcement6th-of-october-2015). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1267844 - CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container https://bugzilla.redhat.com/show_bug.cgi?id=1267844 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lxc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.