Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump containerd to v1.5.9 #613

Closed
jrussett opened this issue Jan 6, 2022 · 0 comments
Closed

Bump containerd to v1.5.9 #613

jrussett opened this issue Jan 6, 2022 · 0 comments

Comments

@jrussett
Copy link
Contributor

jrussett commented Jan 6, 2022

Summary

Addresses CVE-2021-43816

On installations ... with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI),
an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,
regular file on disk for complete read/write access (sans delete).

Additional Info

jrussett added a commit that referenced this issue Jan 6, 2022
Addresses [CVE-2021-43816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43816)

> On installations ... with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI),
> an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,
> regular file on disk for complete read/write access (sans delete).

[#180828310](https://www.pivotaltracker.com/story/show/180828310)
jrussett added a commit that referenced this issue Jan 6, 2022
Addresses [CVE-2021-43816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43816)

> On installations ... with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI),
> an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged,
> regular file on disk for complete read/write access (sans delete).

[#180828310](https://www.pivotaltracker.com/story/show/180828310)
@jrussett jrussett mentioned this issue Jan 6, 2022
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant