buildroot/package/containerd
Peter Korsgaard 52d19b7c4d package/containerd: security bump to version 1.5.13
Fixes the following security issues:

- CVE-2022-31030: containerd CRI plugin: Host memory exhaustion through
  ExecSync

  A bug was found in containerd's CRI implementation where programs inside a
  container can cause the containerd daemon to consume memory without bound
  during invocation of the ExecSync API.  This can cause containerd to
  consume all available memory on the computer, denying service to other
  legitimate workloads.  Kubernetes and crictl can both be configured to use
  containerd's CRI implementation; ExecSync may be used when running probes
  or when executing processes via an "exec" facility.

https://github.com/containerd/containerd/security/advisories/GHSA-5ffw-gxpp-mxpf

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
2022-09-14 22:04:26 +02:00
..
Config.in
containerd.hash package/containerd: security bump to version 1.5.13 2022-09-14 22:04:26 +02:00
containerd.mk package/containerd: security bump to version 1.5.13 2022-09-14 22:04:26 +02:00