FEDORA-2020-a4206f14f1 created by amigadave a year ago for Fedora 31
stable

Update to 0.4.1

This release fixes a privilege escalation bug pointed out by Stephen Röttger, where in some setups bubblewrap can be used to gain root permissions. Only version 0.4.0 is vulnerable, and only if installed setuid while at the same time the kernel supports unprivileged user namespaces. More details in the advisory here:

GHSA-j2qp-rvxj-43vj

Additionally there are some minor changes:

  • Always clear the capability bounding set (cosmetic issue)
  • Make the tests work with libcap >= 2.29
  • Properly report child exit status in some cases

How to install

sudo dnf upgrade --advisory=FEDORA-2020-a4206f14f1

This update has been submitted for testing by amigadave.

a year ago

This update's test gating status has been changed to 'waiting'.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

This update has been pushed to testing.

a year ago

This update's test gating status has been changed to 'greenwave_failed'.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago
User Icon kparal commented & provided feedback a year ago
karma

my flatpak apps work fine

This update can be pushed to stable now if the maintainer wishes

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
security
Severity
low
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago

Automated Test Results