Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2017:1965-1

Опубликовано: 12 июл. 2017
Источник: suse-cvrf

Описание

Recommended update for Docker, RunC, Containerd

This update for Containerd, Docker and RunC provides several fixes and enhancements.

Containerd:

  • Update containerd to the version needed for docker-v17.04.0-ce. (bsc#1034053)
  • Fix spurious messages filling journal. (bsc#1032769)
  • Set TasksMax=infinity to make sure runC doesn't start failing randomly.

Docker:

  • Update to version 17.04.0-ce. (bsc#1034053)
  • Fix execids leaks due to bad error handling. (bsc#1037436)
  • Make Apparmor's pkg/aaparser work on read-only root. (bsc#1037607)
  • Improve Docker's systemd configuration. (bsc#1032287)
  • Check if the docker binary is available before attempting to use it. (bsc#1038476)
  • Build man pages for all architectures. (bsc#953182)
  • Fix DNS resolution when Docker host uses 127.0.0.1 as resolver. (bsc#1034063)
  • Enable Delegate=yes, since systemd will safely ignore lvalues it doesn't understand.
  • Update SUSE secrets patch to handle bsc#1030702.
  • Change lvm2 from Requires to Recommends: Docker usually uses a default storage driver, when it's not configured explicitly. This default driver then depends on the underlying system and gets chosen during installation. (bsc#1032644)
  • Disable libseccomp for Leap 42.1, SLE 12 and 12-SP1, because docker needs a higher version. Otherwise, we get the error 'conditional filtering requires libseccomp version >= 2.2.1. (bsc#1028639, bsc#1028638)
  • Add a backport of fix to AppArmor lazy loading docker-exec case.
  • Fix systemd TasksMax default which could throttle docker. (bsc#1026827)
  • Enable pkcs11

For a comprehensive list of changes please refer to /usr/share/doc/packages/docker/CHANGELOG.md

RunC:

  • Update version to the one required by docker-17.04.0-ce. (bsc#1034053)
  • Make sure to ignore cgroup v2 mountpoints. (bsc#1028113)

Список пакетов

SUSE Linux Enterprise Module for Containers 12
containerd-0.2.5+gitr639_422e31c-20.2
docker-17.04.0_ce-98.2
docker-distribution-registry-2.6.1-15.2
docker-libnetwork-0.0.0+git20170119.7b2b1fe-4.1
runc-0.1.1+gitr2947_9c2d8d1-20.3
SUSE OpenStack Cloud 6
containerd-0.2.5+gitr639_422e31c-20.2
docker-17.04.0_ce-98.2
docker-libnetwork-0.0.0+git20170119.7b2b1fe-4.1
runc-0.1.1+gitr2947_9c2d8d1-20.3

Описание

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 12:containerd-0.2.5+gitr639_422e31c-20.2
SUSE Linux Enterprise Module for Containers 12:docker-17.04.0_ce-98.2
SUSE Linux Enterprise Module for Containers 12:docker-distribution-registry-2.6.1-15.2
SUSE Linux Enterprise Module for Containers 12:docker-libnetwork-0.0.0+git20170119.7b2b1fe-4.1

Ссылки