Summary: | <app-containers/lxc-5.0.2: file existence disclosure | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | minor | CC: | juippis, virtualization |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/MaherAzzouzi/CVE-2022-47952 | ||
Whiteboard: | B4 [stable?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() The guy apparently made a PR upstream, copy-pasting the CVE description: https://github.com/lxc/lxc/pull/4245 I doubt upstream will find this desirable, seeing as he's only commented out some output functions and hasn't tried to fix the CI issues. https://discuss.linuxcontainers.org/t/lxc-5-0-2-lts-has-been-released/16210 https://gitweb.gentoo.org/repo/gentoo.git/commit/app-containers/lxc?id=c2c4be8ee254b45ac05633a14fec9cff88c21ce9 Thanks, please stabilize when ready. |