ALT-BU-2022-5173-1
Branch sisyphus update bulletin.
Package containerd updated to version 1.6.6-alt1 for branch sisyphus in task 301564.
Closed vulnerabilities
BDU:2022-05412
Уязвимость реализации CRI среды выполнения контейнеров Containerd, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-31030
containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimate workloads. Kubernetes and crictl can both be configured to use containerd's CRI implementation; `ExecSync` may be used when running probes or when executing processes via an "exec" facility. This bug has been fixed in containerd 1.6.6 and 1.5.13. Users should update to these versions to resolve the issue. Users unable to upgrade should ensure that only trusted images and commands are used.
- [oss-security] 20220606 CVE-2022-31030: containerd CRI plugin: Host memory exhaustion through ExecSync
- [oss-security] 20220606 CVE-2022-31030: containerd CRI plugin: Host memory exhaustion through ExecSync
- https://github.com/containerd/containerd/commit/c1bcabb4541930f643aa36a2b38655e131346382
- https://github.com/containerd/containerd/commit/c1bcabb4541930f643aa36a2b38655e131346382
- https://github.com/containerd/containerd/security/advisories/GHSA-5ffw-gxpp-mxpf
- https://github.com/containerd/containerd/security/advisories/GHSA-5ffw-gxpp-mxpf
- FEDORA-2022-1da581ac6d
- FEDORA-2022-1da581ac6d
- FEDORA-2022-725ac93b48
- FEDORA-2022-725ac93b48
- GLSA-202401-31
- GLSA-202401-31
- DSA-5162
- DSA-5162
Package qt-creator updated to version 7.0.2-alt2 for branch sisyphus in task 301623.
Closed bugs
Не находит заголовки KSyntaxHighlighting
Package fluent-bit updated to version 1.9.4-alt1 for branch sisyphus in task 301640.
Closed bugs
носит с собой копию luajit
Package kernel-image-un-def updated to version 5.17.14-alt1 for branch sisyphus in task 301643.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-3577
An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.
- https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git/commit/?h=char-misc-next&id=9d64d2405f7d30d49818f6682acd0392348f0fdb
- https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git/commit/?h=char-misc-next&id=9d64d2405f7d30d49818f6682acd0392348f0fdb
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=945a9a8e448b65bec055d37eba58f711b39f66f0
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=945a9a8e448b65bec055d37eba58f711b39f66f0
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc4ef9d5724973193bfa5ebed181dba6de3a56db
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc4ef9d5724973193bfa5ebed181dba6de3a56db
Package kernel-image-std-def updated to version 5.15.46-alt1 for branch sisyphus in task 301644.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2022-3577
An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The reason is incorrect assumption - bigben devices all have inputs. However, malicious devices can break this assumption, leaking to out-of-bound write.
- https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git/commit/?h=char-misc-next&id=9d64d2405f7d30d49818f6682acd0392348f0fdb
- https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/char-misc.git/commit/?h=char-misc-next&id=9d64d2405f7d30d49818f6682acd0392348f0fdb
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=945a9a8e448b65bec055d37eba58f711b39f66f0
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=945a9a8e448b65bec055d37eba58f711b39f66f0
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc4ef9d5724973193bfa5ebed181dba6de3a56db
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fc4ef9d5724973193bfa5ebed181dba6de3a56db
Package livecd-evms updated to version 0.2.5-alt1 for branch sisyphus in task 301557.
Closed bugs
Поддержка установки при загрузке с ventoy
Closed bugs
Поддержка установки при загрузке с ventoy