USN-5311-2
Dashboard / Vulnerabilities / USN-5311-2
USN-5311-2
Summary: containerd regression
Details: USN-5311-1 released updates for contained. Unfortunately, a subsequent update reverted the fix for this CVE by mistake. This update corrects the problem. We apologize for the inconvenience. Original advisory details: It was discovered that containerd allows attackers to gain access to read- only copies of arbitrary files and directories on the host via a specially- crafted image configuration. An attacker could possibly use this issue to obtain sensitive information.
References: https://ubuntu.com/security/notices/USN-5311-2, https://ubuntu.com/security/CVE-2022-23648
Affected packages
Package
Name: containerd
Purl: pkg:deb/ubuntu/[email protected]~20.04.4?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
