Skip to content

[20.10 backport] update containerd binary to v1.5.10#43329

Merged
thaJeztah merged 1 commit intomoby:20.10from
thaJeztah:20.10_backport_update_containerd_binary_1.5.10
Mar 4, 2022
Merged

[20.10 backport] update containerd binary to v1.5.10#43329
thaJeztah merged 1 commit intomoby:20.10from
thaJeztah:20.10_backport_update_containerd_binary_1.5.10

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

(partial) cherry-pick of #43327 (windows dockerfile doesn't have containerd yet in the 20.10 branch)

Welcome to the v1.5.10 release of containerd!

The tenth patch release for containerd 1.5 includes a fix for CVE-2022-23648
and other issues.

Notable Updates

  • Use fs.RootPath when mounting volumes (GHSA-crp2-qrr5-8pq7)
  • Return init pid when clean dead shim in runc.v1/v2 shims
  • Handle sigint/sigterm in shimv2
  • Use readonly mount to read user/group info

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

@thaJeztah
Copy link
Copy Markdown
Member Author

ah... crap; merge conflict in master (in Dockerfile.windows), due to the golang change; I'll fix that one, and cherry-pick again to at least have the correct commit

@thaJeztah thaJeztah marked this pull request as draft March 4, 2022 18:31
Welcome to the v1.5.10 release of containerd!

The tenth patch release for containerd 1.5 includes a fix for [CVE-2022-23648][1]
and other issues.

Notable Updates

- Use fs.RootPath when mounting volumes (GHSA-crp2-qrr5-8pq7)
- Return init pid when clean dead shim in runc.v1/v2 shims
- Handle sigint/sigterm in shimv2
- Use readonly mount to read user/group info

[1]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23648
[2]: GHSA-crp2-qrr5-8pq7

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit 2c8f0a0)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
@thaJeztah thaJeztah force-pushed the 20.10_backport_update_containerd_binary_1.5.10 branch from e7d75d0 to 180f3b9 Compare March 4, 2022 18:36
@thaJeztah thaJeztah marked this pull request as ready for review March 4, 2022 18:36
@thaJeztah
Copy link
Copy Markdown
Member Author

thaJeztah commented Mar 4, 2022

alrighty; fixed that (temporarily moved back to 'draft' to make sure master gets merged first)

@thaJeztah thaJeztah marked this pull request as draft March 4, 2022 18:50
@thaJeztah thaJeztah marked this pull request as ready for review March 4, 2022 20:16
@thaJeztah
Copy link
Copy Markdown
Member Author

master went green and is merged; merging this one as well

@thaJeztah thaJeztah merged commit c3dec60 into moby:20.10 Mar 4, 2022
@thaJeztah thaJeztah deleted the 20.10_backport_update_containerd_binary_1.5.10 branch March 4, 2022 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants