FEDORA-2020-a4206f14f1 created by amigadave 6 months ago for Fedora 31
stable

Update to 0.4.1

This release fixes a privilege escalation bug pointed out by Stephen Röttger, where in some setups bubblewrap can be used to gain root permissions. Only version 0.4.0 is vulnerable, and only if installed setuid while at the same time the kernel supports unprivileged user namespaces. More details in the advisory here:

GHSA-j2qp-rvxj-43vj

Additionally there are some minor changes:

  • Always clear the capability bounding set (cosmetic issue)
  • Make the tests work with libcap >= 2.29
  • Properly report child exit status in some cases

How to install

sudo dnf upgrade --advisory=FEDORA-2020-a4206f14f1

This update has been submitted for testing by amigadave.

6 months ago

This update's test gating status has been changed to 'waiting'.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has been pushed to testing.

6 months ago

This update's test gating status has been changed to 'greenwave_failed'.

5 months ago

This update's test gating status has been changed to 'ignored'.

5 months ago
User Icon kparal commented & provided feedback 5 months ago
karma

my flatpak apps work fine

This update can be pushed to stable now if the maintainer wishes

5 months ago

This update has been submitted for stable by bodhi.

5 months ago

This update has been pushed to stable.

5 months ago

Please login to add feedback.

Metadata
Type
security
Severity
low
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
5 months ago

Automated Test Results