Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz-snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 so this release fixes GHSA-hmfx-3pcx-653p (CVE-2023-25173) and GHSA-259w-8hf6-59c2 (CVE-2023-25153). This release uses Go 1.20.1 so this release fixes CVE-2022-41717 .. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-62ce942e75 2023-03-11 03:04:11.190331 --------------------------------------------------------------------------------Name : stargz-snapshotter Product : Fedora 38 Version : 0.14.2 Release : 1.fc38 URL : https://github.com/containerd/stargz-snapshotter Summary : Fast container image distribution plugin with lazy pulling Description : Fast container image distribution plugin with lazy pulling --------------------------------------------------------------------------------Update Information: Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz-snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 so this release fixes GHSA-hmfx-3pcx-653p (CVE-2023-25173) and GHSA-259w-8hf6-59c2 (CVE-2023-25153). This release uses Go 1.20.1 so this release fixes CVE-2022-41717 . --------------------------------------------------------------------------------ChangeLog: * Mon Mar 6 2023 RH Container Bot - 0.14.2-1 - auto bump to v0.14.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-62ce942e75' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Release of stargz snapshotter v0.10.1. This release contains the mitigation for CVE-2021-41190. Please see the release note for details. https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.1 ---- Update to v0.10.0. See changes at https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d250fc2622 2021-11-29 01:10:04.950380 --------------------------------------------------------------------------------Name : stargz-snapshotter Product : Fedora 34 Version : 0.10.1 Release : 1.fc34 URL : https://github.com/containerd/stargz-snapshotter Summary : Fast container image distribution plugin with lazy pulling Description : Fast container image distribution plugin with lazy pulling --------------------------------------------------------------------------------Update Information: Release of stargz snapshotter v0.10.1. This release contains the mitigation for CVE-2021-41190. Please see the release note for details. https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.1 ----Update to v0.10.0. See changes at https://github.com/containerd/stargz-snapshotter/releases/tag/v0.10.0 --------------------------------------------------------------------------------ChangeLog: * Thu Nov 18 2021 RH Container Bot - 0.10.1-1 - autobuilt v0.10.1 * Fri Nov 12 2021 RH Container Bot - 0.10.0-1 - autobuilt v0.10.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-d250fc2622' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to upstream aa2d5a97cdc4 for CVE-2021-21334. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f049305892 2021-03-19 19:51:22.366042 --------------------------------------------------------------------------------Name : golang-github-containerd-cri Product : Fedora 34 Version : 1.19.0 Release : 3.20210307gitaa2d5a9.fc34 URL : https://github.com/containerd/cri Summary : Containerd Plugin for Kubernetes Container Runtime Interface Description : Cri is a native plugin of containerd 1.1 and above. It is built into containerd and enabled by default. --------------------------------------------------------------------------------Update Information: Update to upstream aa2d5a97cdc4 for CVE-2021-21334 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 7 2021 Olivier Lemasle - 1:1.19.0-3 - Update to upstream aa2d5a97cdc4 for CVE-2021-21334 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f049305892' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.