Re: runc CVEs in docker.io

2021-08-07 Thread Dominique Dumont
On mercredi 4 août 2021 14:41:02 CEST Gareth Evans wrote: > > According to runc security tracker, a fixed runc is available for buster, > > albeit in buster's security repository. > > Thanks Dominique, do you have a link for this please? Sorry, my bad. I misread the report. All the best

Re: runc CVEs in docker.io

2021-08-04 Thread Thomas Hochstein
Gareth Evans schrieb: > Given that these are all fixed in Bullseye (and at least the grave > apt-listbugs issue has been fixed in eg Ubuntu since March 2020 [1]) > why not also Buster? [...] > According to > > https://tracker.debian.org/pkg/runc > > there are 3 open security issues in (Stretch

Re: runc CVEs in docker.io

2021-08-04 Thread Gareth Evans
On Mon 2 Aug 2021, at 11:48, Dominique Dumont wrote: > On Tuesday, 27 July 2021 18:07:53 CEST Gareth Evans wrote: > > Given that these are all fixed in Bullseye (and at least the grave > > apt-listbugs issue has been fixed in eg Ubuntu since March 2020 [1]) why > > not also Buster? > >

Re: runc CVEs in docker.io

2021-08-02 Thread Dominique Dumont
On Tuesday, 27 July 2021 18:07:53 CEST Gareth Evans wrote: > Given that these are all fixed in Bullseye (and at least the grave > apt-listbugs issue has been fixed in eg Ubuntu since March 2020 [1]) why > not also Buster? According to runc security tracker, a fixed runc is available for buster,

runc CVEs in docker.io

2021-07-27 Thread Gareth Evans
Hello, I was just trying to install docker.io on Buster stable when apt-listbugs complained about one of the open CVEs listed here: https://security-tracker.debian.org/tracker/source-package/runc Given that these are all fixed in Bullseye (and at least the grave apt-listbugs issue has been