Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update containerd_version to >=1.6.12 #1162

Closed
dims opened this issue Jan 31, 2023 · 7 comments
Closed

Update containerd_version to >=1.6.12 #1162

dims opened this issue Jan 31, 2023 · 7 comments
Labels
maintenance Routine dependency updates, baselining, etc.

Comments

@dims
Copy link
Member

dims commented Jan 31, 2023

There's a leak we should pick up newer versions of containerd for:
GHSA-2qjp-425j-52j9

thanks,
Dims

@cartermckinnon
Copy link
Member

I've reached out to the Amazon Linux team about getting this updated; I'll track progress here.

@cartermckinnon cartermckinnon added the maintenance Routine dependency updates, baselining, etc. label Feb 1, 2023
@dims
Copy link
Member Author

dims commented Feb 1, 2023

🙏🏾 thanks @cartermckinnon

@RothAndrew
Copy link

@cartermckinnon what did the Amazon Linux team say?

@mkilchhofer
Copy link

mkilchhofer commented Mar 23, 2023

We at @swisspost would also apreciate this upgrade. We need at least 1.6.7 to have things around seccompProfile fixed:

Allow ptrace(2) by default for kernels >= 4.8 (containerd/containerd#7171)

Our dotnet core workload needs to have PTRACE capabilities to do memory dumps:

@cartermckinnon
Copy link
Member

The AL team has staged 1.6.19 for release to the public repositories. I expect that to happen within a couple of weeks; and we'll release an AMI containing the updated package in quick succession.

@mkilchhofer
Copy link

mkilchhofer commented Apr 11, 2023

Is there already an ETA?
I think it would be a good idea to close two CVEs soon:

image

Update:
Oh since PR #1247 containerd patch version isn't hardcoded anymore.

@cartermckinnon
Copy link
Member

The latest AMI release (v20230406) contains containerd-1.6.19-1.amzn2.0.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maintenance Routine dependency updates, baselining, etc.
Projects
None yet
Development

No branches or pull requests

4 participants