Описание
Security update for Docker and dependencies
This update for Docker and its dependencies fixes the following issues:
- fix runc and containerd revisions (bsc#1009961)
docker:
- Updates version 1.11.2 to 1.12.3 (bsc#1004490, bsc#996015, bsc#995058)
- Fix ambient capability usage in containers (bsc#1007249, CVE-2016-8867)
- Change the internal mountpoint name to not use ':' as that character can be considered a special character by other tools. (bsc#999582)
- Add dockerd(8) man page.
- Package docker-proxy (which was split out of the docker binary in 1.12). (bsc#995620)
- Docker 'migrator' prevents installing 'docker', if docker 1.9 was installed before but there were no images. (bsc#995102)
- Specify an 'OCI' runtime for our runc package explicitly. (bsc#978260)
- Use gcc6-go instead of gcc5-go (bsc#988408)
For a detailed description of all fixes and improvements, please refer to:
https://github.com/docker/docker/releases/tag/v1.12.3 https://github.com/docker/docker/blob/v1.12.2/CHANGELOG.md https://github.com/docker/docker/releases/tag/v1.12.1 https://github.com/docker/docker/releases/tag/v1.12.0
containerd:
- Update to current version required from Docker 1.12.3.
- Add missing Requires(post): %fillup_prereq. (bsc#1006368)
- Use gcc6-go instead of gcc5-go. (bsc#988408)
runc:
- Update to current version required from Docker 1.12.3.
- Use gcc6-go instead of gcc5-go. (bsc#988408)
rubygem-excon:
- Updates version from 0.39.6 to 0.52.0.
For a detailed description of all fixes and improvements, please refer to the installed changelog.txt.
rubygem-docker-api:
- Updated version from 1.17.0 to 1.31.0.
Список пакетов
SUSE Linux Enterprise Module for Containers 12
SUSE OpenStack Cloud 6
Ссылки
- Link for SUSE-SU-2016:3084-1
- E-Mail link for SUSE-SU-2016:3084-1
- SUSE Security Ratings
- SUSE Bug 1004490
- SUSE Bug 1006368
- SUSE Bug 1007249
- SUSE Bug 1009961
- SUSE Bug 974208
- SUSE Bug 978260
- SUSE Bug 983015
- SUSE Bug 987198
- SUSE Bug 988408
- SUSE Bug 989566
- SUSE Bug 995058
- SUSE Bug 995102
- SUSE Bug 995620
- SUSE Bug 996015
- SUSE Bug 999582
- SUSE CVE CVE-2016-8867 page
Описание
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Затронутые продукты
Ссылки
- CVE-2016-8867
- SUSE Bug 1007249