package/docker-containerd: security bump to 1.4.4
authorChristian Stewart <christian@paral.in>
Fri, 12 Mar 2021 22:48:31 +0000 (14:48 -0800)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sun, 14 Mar 2021 15:49:20 +0000 (16:49 +0100)
Security fix for CVE-2021-21334:

https://github.com/containerd/containerd/security/advisories/GHSA-6g2q-w5j3-fwh4

Other changes:

 - Fix container create in CRI to prevent possible environment variable leak between containers
 - Update shim server to return grpc NotFound error
 - Add bounds on max oom_score_adj value for shim's AdjustOOMScore
 - Update task manager to use fresh context when calling shim shutdown
 - Update Docker resolver to avoid possible concurrent map access panic
 - Update shim's log file open flags to avoid containerd hang on syscall open
 - Fix incorrect usage calculation

Signed-off-by: Christian Stewart <christian@paral.in>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/docker-containerd/docker-containerd.hash
package/docker-containerd/docker-containerd.mk

index c5cfc137b834d78fd72d350b3f6f033c1fe08754..bb544e8d6012bb46ed45c197c3e27a1274583f12 100644 (file)
@@ -1,3 +1,3 @@
 # Computed locally
-sha256 bc6d9452c700af0ebc09c0da8ddba55be4c03ac8928e72ca92d98905800c8018  docker-containerd-1.4.3.tar.gz
+sha256  ac62c64664bf62fd44df0891c896eecdb6d93def3438271d7892dca75bc069d1  docker-containerd-1.4.4.tar.gz
 sha256 4bbe3b885e8cd1907ab4cf9a41e862e74e24b5422297a4f2fe524e6a30ada2b4  LICENSE
index 626889e5f425ced936d63627f3456704a98f4d67..e229d9cb548d65a28487bbcb60ddd4a3ba22b999 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-DOCKER_CONTAINERD_VERSION = 1.4.3
+DOCKER_CONTAINERD_VERSION = 1.4.4
 DOCKER_CONTAINERD_SITE = $(call github,containerd,containerd,v$(DOCKER_CONTAINERD_VERSION))
 DOCKER_CONTAINERD_LICENSE = Apache-2.0
 DOCKER_CONTAINERD_LICENSE_FILES = LICENSE