FEDORA-2020-8bef0cd310 created by amigadave 6 months ago for Fedora 32
stable

Update to 0.4.1

This release fixes a privilege escalation bug pointed out by Stephen Röttger, where in some setups bubblewrap can be used to gain root permissions. Only version 0.4.0 is vulnerable, and only if installed setuid while at the same time the kernel supports unprivileged user namespaces. More details in the advisory here:

GHSA-j2qp-rvxj-43vj

Additionally there are some minor changes:

  • Always clear the capability bounding set (cosmetic issue)
  • Make the tests work with libcap >= 2.29
  • Properly report child exit status in some cases

How to install

sudo dnf upgrade --advisory=FEDORA-2020-8bef0cd310

This update has been submitted for testing by amigadave.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has been pushed to testing.

6 months ago
User Icon atim provided feedback 6 months ago
karma
User Icon frantisekz commented & provided feedback 6 months ago
karma

Seems to work well

This update can be pushed to stable now if the maintainer wishes

6 months ago

This update has been submitted for stable by amigadave.

6 months ago

This update has been pushed to stable.

5 months ago

Please login to add feedback.

Metadata
Type
security
Severity
low
Karma
2
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
5 months ago

Automated Test Results