Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues: Update Docker to 19.03.15-ce: - CVE-2021-21284: potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732) - CVE-2021-21285: malformed Docker image manifest crashes the dockerd daemon (bsc#1181730) - CVE-2020-15157: containerd: credentials leaking during image pull (bsc#1177598)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues: Update Docker to 19.03.15-ce: - CVE-2021-21284: potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732) - CVE-2021-21285: malformed Docker image manifest crashes the dockerd daemon (bsc#1181730) - CVE-2020-15157: containerd: credentials leaking during image pull (bsc#1177598)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1065609
- https://bugzilla.suse.com/1153367
- https://bugzilla.suse.com/1157330
- https://bugzilla.suse.com/1158590
- https://bugzilla.suse.com/1176708
- https://bugzilla.suse.com/1177598
- https://bugzilla.suse.com/1178801
- https://bugzilla.suse.com/1180401
- https://bugzilla.suse.com/1181730
- https://bugzilla.suse.com/1181732
- https://www.suse.com/security/cve/CVE-2020-15157
- https://www.suse.com/security/cve/CVE-2021-21284
- https://www.suse.com/security/cve/CVE-2021-21285
- https://www.suse.com/support/update/announcement/2021/suse-su-20210445-1/