-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade containerd to 1.2.14 #2854
Comments
Why only for 2.6? I'd put this in any version where we use a vulnerable version of Also, why not move to 1.4 in 2.6? |
Good point, so indeed will make sure to have this in the lowest version possible.
Merely a timing issue: we plan on releasing 2.6 next week, not sure we can get 1.4 out by then, let alone have it sufficiently tested. |
Updated description of this issue to detail which versions to target. |
Retrieved from EPEL. See: https://download-ib01.fedoraproject.org/pub/epel/7/SRPMS/Packages/c/containerd-1.2.4-1.el7.src.rpm Cherry-picked from 516191b See: #2854
Component: containerd
Summary:
containerd
1.2 is affected by CVE-2020-15157, and a fix is expected to be released in version 1.2.14, planned for October 15thWe'll need to update our package once this version comes out, starting in MetalK8s 2.5.2 and higher.
Starting with MetalK8s 2.7, we should include
containerd
1.4.x instead.The text was updated successfully, but these errors were encountered: