Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Announcement ID: | SUSE-SU-2021:0445-1 |
---|---|
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves three vulnerabilities and has seven security fixes can now be installed.
Description:
This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
Update Docker to 19.03.15-ce:
- CVE-2021-21284: potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732)
- CVE-2021-21285: malformed Docker image manifest crashes the dockerd daemon (bsc#1181730)
- CVE-2020-15157: containerd: credentials leaking during image pull (bsc#1177598)
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Containers Module 12
zypper in -t patch SUSE-SLE-Module-Containers-12-2021-445=1
Package List:
-
Containers Module 12 (ppc64le s390x x86_64)
- docker-libnetwork-0.7.0.1+gitr2908_55e924b8a842-37.1
- docker-19.03.15_ce-98.60.2
- docker-debuginfo-19.03.15_ce-98.60.2
- docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8a842-37.1
- containerd-1.3.9-16.35.1
- docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-1.52.1
References:
- https://www.suse.com/security/cve/CVE-2020-15157.html
- https://www.suse.com/security/cve/CVE-2021-21284.html
- https://www.suse.com/security/cve/CVE-2021-21285.html
- https://bugzilla.suse.com/show_bug.cgi?id=1065609
- https://bugzilla.suse.com/show_bug.cgi?id=1153367
- https://bugzilla.suse.com/show_bug.cgi?id=1157330
- https://bugzilla.suse.com/show_bug.cgi?id=1158590
- https://bugzilla.suse.com/show_bug.cgi?id=1176708
- https://bugzilla.suse.com/show_bug.cgi?id=1177598
- https://bugzilla.suse.com/show_bug.cgi?id=1178801
- https://bugzilla.suse.com/show_bug.cgi?id=1180401
- https://bugzilla.suse.com/show_bug.cgi?id=1181730
- https://bugzilla.suse.com/show_bug.cgi?id=1181732