Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: 更新 docker v25.0.3 #392

Merged
merged 1 commit into from Feb 21, 2024
Merged

Conversation

fit2bot
Copy link
Contributor

@fit2bot fit2bot commented Feb 2, 2024

25.0.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release contains security fixes for the following CVEs
affecting Docker Engine and its components.

CVE Component Fix version Severity
CVE-2024-21626 runc 1.1.12 High, CVSS 8.6
CVE-2024-23651 BuildKit 1.12.5 High, CVSS 8.7
CVE-2024-23652 BuildKit 1.12.5 High, CVSS 8.7
CVE-2024-23653 BuildKit 1.12.5 High, CVSS 7.7
CVE-2024-23650 BuildKit 1.12.5 Medium, CVSS 5.5
CVE-2024-24557 Docker Engine 25.0.2 Medium, CVSS 6.9

The potential impacts of the above vulnerabilities include:

  • Unauthorized access to the host filesystem
  • Compromising the integrity of the build cache
  • In the case of CVE-2024-21626, a scenario that could lead to full container escape

For more information about the security issues addressed in this release,
refer to the blog post.
For details about each vulnerability, see the relevant security advisory:

Packaging updates

@fit2bot fit2bot requested a review from a team February 2, 2024 07:47
@wojiushixiaobai wojiushixiaobai changed the title feat: 更新 docker v25.0.2 feat: 更新 docker v25.0.3 Feb 8, 2024
@BaiJiangJie BaiJiangJie merged commit 83a5c5d into dev Feb 21, 2024
3 checks passed
@BaiJiangJie BaiJiangJie deleted the pr@dev@upgrade_docker_version branch February 21, 2024 07:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
3 participants