package/docker-engine: security bump to version 20.10.3
authorChristian Stewart <christian@paral.in>
Wed, 10 Feb 2021 23:52:02 +0000 (15:52 -0800)
committerPeter Korsgaard <peter@korsgaard.com>
Thu, 11 Feb 2021 15:51:37 +0000 (16:51 +0100)
Security fixes:

 - CVE-2021-21285 Prevent an invalid image from crashing docker daemon
 - CVE-2021-21284 Lock down file permissions to prevent remapped root from accessing docker state
 - Ensure AppArmor and SELinux profiles are applied when building with BuildKit

Signed-off-by: Christian Stewart <christian@paral.in>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/docker-engine/docker-engine.hash
package/docker-engine/docker-engine.mk

index 2519ddaecd7a1bb49b32ef00cc520e40788ca93c..69ebd113ea4d7e97a606a14a574769801c46b5c4 100644 (file)
@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  f0fda46a82bf8f624eb349370358891d3bc65ef3e320675226f17dba8f62566d  docker-engine-20.10.1.tar.gz
+sha256  62bb03f197b8a064da568e62639f6834f91c8cfc9273126a978847becc214c31  docker-engine-20.10.3.tar.gz
 sha256  7c87873291f289713ac5df48b1f2010eb6963752bbd6b530416ab99fc37914a8  LICENSE
index 058960119a0c68a49120a41840fc6cc63a9e3f26..bbc97af8b5ae1009ec102d4a8eef978ca4b0ff1b 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-DOCKER_ENGINE_VERSION = 20.10.1
+DOCKER_ENGINE_VERSION = 20.10.3
 DOCKER_ENGINE_SITE = $(call github,moby,moby,v$(DOCKER_ENGINE_VERSION))
 
 DOCKER_ENGINE_LICENSE = Apache-2.0