SUSE-SU-2021:1458-1

    Dashboard / Vulnerabilities / SUSE-SU-2021:1458-1

    SUSE-SU-2021:1458-1

    Published: 30 Apr 2021Last Modified: 4 Feb 2026

    Summary: Security update for containerd, docker, runc

    Details: This update for containerd, docker, runc fixes the following issues: - Docker was updated to 20.10.6-ce * Switch version to use -ce suffix rather than _ce to avoid confusing other tools (bsc#1182476). * CVE-2021-21284: Fixed a potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732) * CVE-2021-21285: Fixed an issue where pulling a malformed Docker image manifest crashes the dockerd daemon (bsc#1181730). - runc was updated to v1.0.0~rc93 (bsc#1182451 and bsc#1184962). * Use the upstream runc package (bsc#1181641, bsc#1181677, bsc#1175821). * Fixed /dev/null is not available (bsc#1168481). * Fixed an issue where podman hangs when spawned by salt-minion process (bsc#1149954). * CVE-2019-19921: Fixed a race condition with shared mounts (bsc#1160452). * CVE-2019-16884: Fixed an LSM bypass via malicious Docker image that mount over a /proc directory (bsc#1152308). * CVE-2019-5736: Fixed potential write attacks to the host runc binary (bsc#1121967). * Fixed an issue where after a kernel-update docker doesn't run (bsc#1131314 bsc#1131553) * Ensure that we always include the version information in runc (bsc#1053532). - Switch to Go 1.13 for build. * CVE-2018-16873: Fixed a potential remote code execution (bsc#1118897). * CVE-2018-16874: Fixed a directory traversal in 'go get' via curly braces in import paths (bsc#1118898). * CVE-2018-16875: Fixed a CPU denial of service (bsc#1118899). * Fixed an issue with building containers (bsc#1095817). - containerd was updated to v1.4.4 * CVE-2021-21334: Fixed a potential information leak through environment variables (bsc#1183397). * Handle a requirement from docker (bsc#1181594). * Install the containerd-shim* binaries and stop creating (bsc#1183024). * update version to the one required by docker (bsc#1034053) - Use -buildmode=pie for tests and binary build (bsc#1048046, bsc#1051429) - Cleanup seccomp builds similar (bsc#1028638). - Update to handle the docker-runc removal, and drop the -kubic flavour (bsc#1181677, bsc#1181749)

    References: https://www.suse.com/support/update/announcement/2021/suse-su-20211458-1/, https://bugzilla.suse.com/1028638, https://bugzilla.suse.com/1034053, https://bugzilla.suse.com/1048046, https://bugzilla.suse.com/1051429, https://bugzilla.suse.com/1053532, https://bugzilla.suse.com/1095817, https://bugzilla.suse.com/1118897, https://bugzilla.suse.com/1118898, https://bugzilla.suse.com/1118899, https://bugzilla.suse.com/1121967, https://bugzilla.suse.com/1131314, https://bugzilla.suse.com/1131553, https://bugzilla.suse.com/1149954, https://bugzilla.suse.com/1152308, https://bugzilla.suse.com/1160452, https://bugzilla.suse.com/1168481, https://bugzilla.suse.com/1175081, https://bugzilla.suse.com/1175821, https://bugzilla.suse.com/1181594, https://bugzilla.suse.com/1181641, https://bugzilla.suse.com/1181677, https://bugzilla.suse.com/1181730, https://bugzilla.suse.com/1181732, https://bugzilla.suse.com/1181749, https://bugzilla.suse.com/1182451, https://bugzilla.suse.com/1182476, https://bugzilla.suse.com/1182947, https://bugzilla.suse.com/1183024, https://bugzilla.suse.com/1183397, https://bugzilla.suse.com/1183855, https://bugzilla.suse.com/1184768, https://bugzilla.suse.com/1184962, https://www.suse.com/security/cve/CVE-2018-16873, https://www.suse.com/security/cve/CVE-2018-16874, https://www.suse.com/security/cve/CVE-2018-16875, https://www.suse.com/security/cve/CVE-2019-16884, https://www.suse.com/security/cve/CVE-2019-19921, https://www.suse.com/security/cve/CVE-2019-5736, https://www.suse.com/security/cve/CVE-2021-21284, https://www.suse.com/security/cve/CVE-2021-21285, https://www.suse.com/security/cve/CVE-2021-21334

    Affected packages

    Package

    Name: containerd

    Purl: pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.4.4-16.38.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2021:1458-1 | CVE-DB