package/docker-containerd: security bump to version 1.4.3
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 1 Dec 2020 22:23:46 +0000 (23:23 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 2 Dec 2020 07:16:00 +0000 (08:16 +0100)
commit1e1d1278c7112f44ce694958047ee512f20b4360
treeba7089c43f5e4c42db744b58ffebc7d61e63a7b0
parentc5c66282ba33095eb195881d6f5ca56e92c7f12e
package/docker-containerd: security bump to version 1.4.3

Fixes the following security issue:

- CVE-2020-15257: Access controls for the shim’s API socket verified that
  the connecting process had an effective UID of 0, but did not otherwise
  restrict access to the abstract Unix domain socket.  This would allow
  malicious containers running in the same network namespace as the shim,
  with an effective UID of 0 but otherwise reduced privileges, to cause new
  processes to be run with elevated privileges.

For more details, see the advisory:
https://github.com/containerd/containerd/security/advisories/GHSA-36xw-fx78-c5r4

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/docker-containerd/docker-containerd.hash
package/docker-containerd/docker-containerd.mk