Summary: | <app-containers/lxc-5.0.2: file existence disclosure | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | minor | CC: | juippis, virtualization |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/MaherAzzouzi/CVE-2022-47952 | ||
Whiteboard: | B4 [glsa?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() The guy apparently made a PR upstream, copy-pasting the CVE description: https://github.com/lxc/lxc/pull/4245 I doubt upstream will find this desirable, seeing as he's only commented out some output functions and hasn't tried to fix the CI issues. https://discuss.linuxcontainers.org/t/lxc-5-0-2-lts-has-been-released/16210 https://gitweb.gentoo.org/repo/gentoo.git/commit/app-containers/lxc?id=c2c4be8ee254b45ac05633a14fec9cff88c21ce9 Thanks, please stabilize when ready. commit f565998a51b1e190e4595d726873e1775b2bc4c8 Author: Joonas Niilola <juippis@gentoo.org> Date: Wed Feb 22 09:11:49 2023 +0200 app-containers/lxc: drop 5.0.1-r2 Tree is clean of this version. |