[Git][security-tracker-team/security-tracker][master] 2 commits: Reserve DLA-3735-1 for runc
Daniel Leidert (@dleidert)
dleidert at debian.org
Mon Feb 19 09:55:25 GMT 2024
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker
Commits:
77e961eb by Daniel Leidert at 2024-02-19T03:04:51+01:00
Reserve DLA-3735-1 for runc
- - - - -
f20527be by Daniel Leidert at 2024-02-19T10:47:42+01:00
Merge branch 'master' of salsa.debian.org:security-tracker-team/security-tracker
- - - - -
1 changed file:
- data/dla-needed.txt
Changes:
=====================================
data/dla-needed.txt
=====================================
@@ -249,10 +249,12 @@ ring
NOTE: 20230903: Added by Front-Desk (gladk)
NOTE: 20230928: will be likely hard to fix see https://lists.debian.org/debian-lts/2023/09/msg00035.html (rouca)
--
-runc (dleidert)
+runc
NOTE: 20240204: Added by Front-Desk (ta)
- NOTE: 20240208: Will need 2-3 more days (dleidert)
- NOTE: 20240211: Ready to upload, except for https://lists.debian.org/debian-lts/2024/02/msg00014.html - will wait 2-3 days (dleidert)
+ NOTE: 20240219: Complete fix for CVE-2024-21626 would require backport of
+ NOTE: 20240219: https://github.com/opencontainers/runc/commit/284ba3057e428f8d6c7afcc3b0ac752e525957df and
+ NOTE: 20240219: https://github.com/opencontainers/runc/commit/e9665f4d606b64bf9c4652ab2510da368bfbd951.
+ NOTE: 20240219: But it uses a link to internal/poll.IsPollDescriptor, introduced in Go 1.12, which I cannot backport (dleidert).
--
samba
NOTE: 20230918: Added by Front-Desk (apo)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20ce78fbefbaf1516dbd9e7d6679974b1e985dce...f20527be01dee485467e235605493d25e9e005e1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20ce78fbefbaf1516dbd9e7d6679974b1e985dce...f20527be01dee485467e235605493d25e9e005e1
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240219/3251b580/attachment.htm>
More information about the debian-security-tracker-commits
mailing list