Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Announcement ID: | SUSE-SU-2019:2117-1 |
---|---|
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves four vulnerabilities and has three security fixes can now be installed.
Description:
This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:
Docker:
- CVE-2019-14271: Fixed a code injection if the nsswitch facility dynamically loaded a library inside a chroot (bsc#1143409).
- CVE-2019-13509: Fixed an information leak in the debug log (bsc#1142160).
- Update to version 19.03.1-ce, see changelog at /usr/share/doc/packages/docker/CHANGELOG.md (bsc#1142413, bsc#1139649).
runc:
- Use %config(noreplace) for /etc/docker/daemon.json (bsc#1138920).
- Update to runc 425e105d5a03, which is required by Docker (bsc#1139649).
containerd:
- CVE-2019-5736: Fixed a container breakout vulnerability (bsc#1121967).
- Update to containerd v1.2.6, which is required by docker (bsc#1139649).
golang-github-docker-libnetwork:
- Update to version git.fc5a7d91d54cc98f64fc28f9e288b46a0bee756c, which is required by docker (bsc#1142413, bsc#1139649).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
Containers Module 15
zypper in -t patch SUSE-SLE-Module-Containers-15-2019-2117=1
-
Containers Module 15-SP1
zypper in -t patch SUSE-SLE-Module-Containers-15-SP1-2019-2117=1
Package List:
-
Containers Module 15 (ppc64le s390x x86_64)
- docker-libnetwork-debuginfo-0.7.0.1+gitr2800_fc5a7d91d54c-4.15.1
- docker-19.03.1_ce-6.26.2
- docker-debuginfo-19.03.1_ce-6.26.2
- containerd-1.2.6-5.16.1
- docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.21.2
- docker-runc-debuginfo-1.0.0rc8+gitr3826_425e105d5a03-6.21.2
- docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-4.15.1
-
Containers Module 15 (noarch)
- docker-bash-completion-19.03.1_ce-6.26.2
-
Containers Module 15-SP1 (aarch64 ppc64le s390x x86_64)
- docker-libnetwork-debuginfo-0.7.0.1+gitr2800_fc5a7d91d54c-4.15.1
- docker-19.03.1_ce-6.26.2
- docker-debuginfo-19.03.1_ce-6.26.2
- containerd-1.2.6-5.16.1
- docker-runc-1.0.0rc8+gitr3826_425e105d5a03-6.21.2
- docker-runc-debuginfo-1.0.0rc8+gitr3826_425e105d5a03-6.21.2
- docker-libnetwork-0.7.0.1+gitr2800_fc5a7d91d54c-4.15.1
-
Containers Module 15-SP1 (noarch)
- docker-bash-completion-19.03.1_ce-6.26.2
References:
- https://www.suse.com/security/cve/CVE-2018-10892.html
- https://www.suse.com/security/cve/CVE-2019-13509.html
- https://www.suse.com/security/cve/CVE-2019-14271.html
- https://www.suse.com/security/cve/CVE-2019-5736.html
- https://bugzilla.suse.com/show_bug.cgi?id=1100331
- https://bugzilla.suse.com/show_bug.cgi?id=1121967
- https://bugzilla.suse.com/show_bug.cgi?id=1138920
- https://bugzilla.suse.com/show_bug.cgi?id=1139649
- https://bugzilla.suse.com/show_bug.cgi?id=1142160
- https://bugzilla.suse.com/show_bug.cgi?id=1142413
- https://bugzilla.suse.com/show_bug.cgi?id=1143409