Format: 1.8 Date: Mon, 15 May 2023 13:18:52 +0200 Source: runc Binary: runc Built-For-Profiles: noudeb Architecture: arm64 Version: 1.1.4-0ubuntu1~22.10.3 Distribution: kinetic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: David Fernandez Gonzalez Description: runc - Open Container Project - runtime Changes: runc (1.1.4-0ubuntu1~22.10.3) kinetic-security; urgency=medium . * SECURITY UPDATE: Incorrect access control through /sys/fs/cgroup - debian/patches/CVE-2023-25809.patch: apply MS_RDONLY if /sys/fs/cgroup is bind-mounted or mask if bind source is unavailable in libcontainer/rootfs_linux.go. - CVE-2023-25809 * SECURITY UPDATE: Incorrect access control through /proc and /sys - debian/patches/CVE-2023-27561_2023-28642.patch: Prohibit /proc and /sys to be symlinks in libcontainer/rootfs_linux.go. - CVE-2023-27561 - CVE-2023-28642 Checksums-Sha1: 847945af40d72b1b158124f3aea8a92f6e8e4a93 6128788 runc-dbgsym_1.1.4-0ubuntu1~22.10.3_arm64.ddeb 86f21c8ab14f2d901880d7dc3561691728716af7 6793 runc_1.1.4-0ubuntu1~22.10.3_arm64.buildinfo 4b84dc39b7124f85b0f1eafbf04c4bdf6c2b4d10 4057050 runc_1.1.4-0ubuntu1~22.10.3_arm64.deb Checksums-Sha256: 5c798fe1ed617c9183246491b039babca0f170a714e8eff06d67708aa716f86e 6128788 runc-dbgsym_1.1.4-0ubuntu1~22.10.3_arm64.ddeb 6966de7ece2871729f6904f8aa02309da3e066b8a7439d8e8a1a9e9eaf688dca 6793 runc_1.1.4-0ubuntu1~22.10.3_arm64.buildinfo fed4799ab5851bad81d200cdb932f99cfd5080292f40c919a5411c40c927c4a1 4057050 runc_1.1.4-0ubuntu1~22.10.3_arm64.deb Files: 726784759b48343657038949dd3f5df3 6128788 debug optional runc-dbgsym_1.1.4-0ubuntu1~22.10.3_arm64.ddeb c9ff3cc17a1c214dc3681daf3d1b0da4 6793 devel optional runc_1.1.4-0ubuntu1~22.10.3_arm64.buildinfo 7dfa303bf34456a10801c20e63831e6d 4057050 devel optional runc_1.1.4-0ubuntu1~22.10.3_arm64.deb Original-Maintainer: Debian Go Packaging Team