Skip to content

1.0 CBL-Mariner March 2022 Update

Choose a tag to compare

@jslobodzian jslobodzian released this 14 Mar 18:18
· 627 commits to 1.0 since this release

Upgrade kernel to 5.10.102.1 to address CVE-2021-3752, CVE-2021-3753, CVE-2021-4032, CVE-2021-20322, CVE-2021-45402, CVE-2022-0264, CVE-2022-0847 (Dirty Pipe CVE Fix), CVE-2022-24448, CVE-2022-24958, CVE-2022-24959, CVE-2022-25258, CVE-2022-25375

Upgrade Open JDK8 to fix CVE-2022-21282 CVE-2022-21293 CVE-2022-21294 CVE-2022-21296 CVE-2022-21299 CVE-2022-21305 CVE-2022-21340 CVE-2022-21341 CVE-2022-21360 CVE-2022-21365

Upgrade vim to 8.2.4495 to fix CVE-2022-0729

Patch moby-contianerd to fix CVE-2022-23648

Upgrade clamav to fix CVE-2022-20698

Upgrade MariaDB to 10.3.34 to fix CVE-2021-46661, CVE-2021-46662, CVE-2021-46663, CVE-2021-46664, CVE-2021-46665, CVE-2021-46668

Enable Perl Compatible Regular Expression (pcre) JIT feature

Distroless containers now include rpm manifest to support Distroless Container CVE scanning by Qualys.

Fix python3 self test for compatibility with newer expat