Hello Kyle,

Thanks for taking the time to report this bug and helping to make Ubuntu
better. The latest runc update indeed introduced many changes regarding
permissions, in an attempt to fix 3 high severity CVEs.

From an initial triage, this seems like an unintended behaviour that was
caused due to hardening of permissions, that should not apply in this
case.

I must note however, that in Ubuntu, in order to fix those issues we
introduced the latest 1.3 tarball from upstream. Thus, I would like to
redirect you to upstream's repo, where you can file a bug with the
maintainers. Fell free to link it here as well, I will leave this one as
unresolved until we figure this out.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2130744

Title:
  runc security upgrade regresses docker tmpfs permission handling

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/runc/+bug/2130744/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to