Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update containerd to 1.6.21 #3164

Closed
gillarda opened this issue Jun 2, 2023 · 3 comments
Closed

Update containerd to 1.6.21 #3164

gillarda opened this issue Jun 2, 2023 · 3 comments
Labels
area/packaging Issues related to the packages bundled in Bottlerocket type/enhancement New feature or request

Comments

@gillarda
Copy link

gillarda commented Jun 2, 2023

What I'd like:

I'd like to update container to 1.6.21 which is built against Go 1.19.9, which itself contains fixes for several CVE.

@gillarda gillarda added status/needs-triage Pending triage or re-evaluation type/enhancement New feature or request labels Jun 2, 2023
@yeazelm
Copy link
Contributor

yeazelm commented Jun 2, 2023

Thanks for cutting this issue @gillarda! We aim to update these packages often and will bump to containerd 1.6.21 at some point but we did have some issues with runc versions and are watching Kubernetes upstream (#3165) to ensure we are in lockstep since getting out of sync caused some difficulties recently.

Nonetheless, we build with our SDK which has a newer version of Go than 1.19.9 (bottlerocket-os/bottlerocket-sdk@99aba43) so I don't believe the concern around CVE's holds in this specific case.

@yeazelm yeazelm added area/packaging Issues related to the packages bundled in Bottlerocket and removed status/needs-triage Pending triage or re-evaluation labels Jun 2, 2023
@gillarda
Copy link
Author

gillarda commented Jun 2, 2023

Thank you a lot for your answer @yeazelm !

I was able to confirm that Bottlerocket versions >=1.13.5 and >=1.14.0 were not affected by these CVE (CVE-2023-24538 and CVE-2023-24540).

@arnaldo2792
Copy link
Contributor

We are now in containerd 1.6.23, and the upcoming 1.15 release will include this version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/packaging Issues related to the packages bundled in Bottlerocket type/enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants