Skip to content

Confusing release notes for addressing the CVE-2019-5736 #8278

@singhjagmohan1000

Description

@singhjagmohan1000

Problem description

Update runc for addressing the cve-2019-5736.

Problem location

https://docs.docker.com/engine/release-notes/#18062

  • I couldn't find the information I wanted. I expected to find it near the following URL:

The latest release documents says "Update runc to address a critical vulnerability that allows specially-crafted containers to gain administrative privileges on the host. CVE-2019-5736".
I think runc is part of the docker engine, as I have not installed runc on my systems explicitly. So How do we update this.
Maybe it meant to say the runc has been updated with current release. So it is really confusing. Can I get more explanation.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions