Skip to content

[v1.13] backport fixes for CVE-2022-1227 (Podman v1.6.4)#1206

Merged
giuseppe merged 2 commits intocontainers:release-1.13from
vrothberg:1.13-backports
Apr 20, 2022
Merged

[v1.13] backport fixes for CVE-2022-1227 (Podman v1.6.4)#1206
giuseppe merged 2 commits intocontainers:release-1.13from
vrothberg:1.13-backports

Conversation

@vrothberg
Copy link
Copy Markdown
Member

Bump to v1.13.7 at the same time. Note that there is also a v1.13-stable branch which I find confusing. Podman v1.6.4 is vendoring c/storage v1.13.6, so we are good in this case.

@giuseppe @rhatdan @lsm5 PTAL

Cc: @TomSweeneyRedHat

Let the dance continue man_dancing woman_dancing

@vrothberg
Copy link
Copy Markdown
Member Author

@cevich the CI images are gone. Any chance we can get them back?

cyphar and others added 2 commits April 19, 2022 14:15
While the IDMapping methods are preferable for most users, sometimes it
is necessary to map a single ID using a given mapping. In particular
this is needed for psgo to be able to map the user and group entries in
/proc/$pid/status using the user namespace of the target process.

Required to resolve CVE-2022-1227 for Podman v1.6.4.

Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
Backported-by: Valentin Rothberg <vrothberg@redhat.com>
* pkg: idtools: export RawTo{Container,Host}

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
@vrothberg
Copy link
Copy Markdown
Member Author

@rhatdan PTAL

@cevich
Copy link
Copy Markdown
Member

cevich commented Apr 19, 2022

@cevich the CI images are gone. Any chance we can get them back?

Unlikely, these images predate sanity 😆 Seriously, I have zero keepalive jobs setup on this repo. It was discussed a few times and deemed not worth the effort. I'm open to changing that stance, if similar unavailability is going to potentially cause future pain w/o workarounds.

@rhatdan
Copy link
Copy Markdown
Member

rhatdan commented Apr 19, 2022

LGTM

@vrothberg
Copy link
Copy Markdown
Member Author

@giuseppe can we get this in?

Copy link
Copy Markdown
Member

@giuseppe giuseppe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@giuseppe giuseppe merged commit e762e0e into containers:release-1.13 Apr 20, 2022
@vrothberg vrothberg deleted the 1.13-backports branch April 20, 2022 08:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants