[ALSA-2023:6380] Moderate: runc security update
Type:
security
Severity:
moderate
Release date:
2023-11-14
Description:
The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724) * runc: Rootless runc makes `/sys/fs/cgroup` writable (CVE-2023-25809) * runc: volume mount race condition (regression of CVE-2019-19921) (CVE-2023-27561) * runc: AppArmor can be bypassed when `/proc` inside the container is symlinked with a specific mount configuration (CVE-2023-28642) * runc: integer overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration (CVE-2021-43784) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 runc-1.1.9-1.el9.aarch64.rpm 21d0599589e60a1e6feae25df24cb6af284461ffaf2109b77921a393bd34cb90
ppc64le runc-1.1.9-1.el9.ppc64le.rpm b7d24c52e193f822cd630395e7e8e765750a69edff95f7df70ea575f551ffa3b
s390x runc-1.1.9-1.el9.s390x.rpm 102467e9862bad192c97eb3de75efecea26bb4528b4498efb991d8bdcc8457de
x86_64 runc-1.1.9-1.el9.x86_64.rpm c0429c7fe2ad7bdd76fc6e46b2625c44221267766ab886a265a9ed0c7619ecd7
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.