runc: security bump to fix CVE-2016-9962
authorPeter Korsgaard <peter@korsgaard.com>
Sun, 22 Jan 2017 21:39:56 +0000 (22:39 +0100)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Mon, 23 Jan 2017 08:07:48 +0000 (19:07 +1100)
commitd6706dc430ebb1dade6f90a8d45503c23abec99d
treee8ad51d763c2dd1ef2f46d964c645f47b398092d
parent157ddf77e403c6ee00faef44fc32f8f679964204
runc: security bump to fix CVE-2016-9962

RunC allowed additional container processes via runc exec to be ptraced by
the pid 1 of the container.  This allows the main processes of the
container, if running as root, to gain access to file-descriptors of these
new processes during the initialization and can lead to container escapes or
modification of runC state before the process is fully placed inside the
container.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/runc/runc.hash
package/runc/runc.mk