MGASA-2023-0125

Source
https://advisories.mageia.org/MGASA-2023-0125.html
Import Source
https://advisories.mageia.org/MGASA-2023-0125.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0125
Related
Published
2023-04-06T21:20:12Z
Modified
2023-04-06T20:15:16Z
Summary
Updated opencontainers-runc packages fix security vulnerability
Details

/sys/fs/cgroup is writable when cgroupns isn't unshared (CVE-2023-25809) Regression that reintroduced CVE-2019-19921 - Incorrect Access Control leading to Escalation of Privileges (CVE-2023-27561) AppArmor/SELinux bypass with symlinked /proc (CVE-2023-28642)

References
Credits

Affected packages

Mageia:8 / opencontainers-runc

Package

Name
opencontainers-runc
Purl
pkg:rpm/mageia/opencontainers-runc?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.5-1.mga8

Ecosystem specific

{
    "section": "core"
}