mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
package/runc: security bump to version 1.3.5
Fixes the following security issues (1.3.3): - CVE-2025-31133: container escape via "masked path" abuse due to mount race conditions https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2 - CVE-2025-52565: container escape with malicious config due to /dev/console mount and related races https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r - CVE-2025-52881: container escape and denial of service due to arbitrary write gadgets and procfs write redirects https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm In addition, 1.3.4 and 1.3.5 fixes a number of regressions. For details, see the release notes: https://github.com/opencontainers/runc/releases/tag/v1.3.1 https://github.com/opencontainers/runc/releases/tag/v1.3.2 https://github.com/opencontainers/runc/releases/tag/v1.3.3 https://github.com/opencontainers/runc/releases/tag/v1.3.4 https://github.com/opencontainers/runc/releases/tag/v1.3.5 Signed-off-by: Peter Korsgaard <peter@korsgaard.com> Reviewed-by: Christian Stewart <christian@aperture.us> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
@@ -1,3 +1,3 @@
|
||||
# Locally computed
|
||||
sha256 3262492ce42bea0919ee1a2d000b6f303fd14877295bc38d094876b55fdd448b runc-1.3.0-go2.tar.gz
|
||||
sha256 72620f9b0e62d8da80c0c08a6265ab10d24330c544115c30713ba1429bde706d runc-1.3.5-go2.tar.gz
|
||||
sha256 552a739c3b25792263f731542238b92f6f8d07e9a488eae27e6c4690038a8243 LICENSE
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
################################################################################
|
||||
|
||||
RUNC_VERSION = 1.3.0
|
||||
RUNC_VERSION = 1.3.5
|
||||
RUNC_SITE = $(call github,opencontainers,runc,v$(RUNC_VERSION))
|
||||
RUNC_LICENSE = Apache-2.0, LGPL-2.1 (libseccomp)
|
||||
RUNC_LICENSE_FILES = LICENSE
|
||||
|
||||
Reference in New Issue
Block a user