Summary: | <app-containers/docker-24.0.4: vulnerability in bundled buildkit | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | ajak, gyakovlev, williamh |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc | ||
Whiteboard: | B4 [glsa+] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() > Fixed in buildkit-0.11.4. moby (docker) bumped its bundled buildkit in 24.0 betas/RCs:
And thus I suppose 24.0.4 is the first fixed version for us.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=72515324253c8d95723f4e5308eb0fe41ebed5cd commit 72515324253c8d95723f4e5308eb0fe41ebed5cd Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-09-28 07:32:55 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-09-28 07:33:05 +0000 [ GLSA 202409-29 ] Docker: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/816273 Bug: https://bugs.gentoo.org/869407 Bug: https://bugs.gentoo.org/877653 Bug: https://bugs.gentoo.org/886509 Bug: https://bugs.gentoo.org/903804 Bug: https://bugs.gentoo.org/905336 Bug: https://bugs.gentoo.org/925022 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202409-29.xml | 60 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) |