Comprehensive Mageia Docker Security Update Details
Summary
This update fixes several security issues and also solves some other
issues
- manage change of launch option earlier in post process
- Automatically convert -g option to --data-root in installed
/etc/sysconfig/docker-storage
- Fix CVE-2023-26054 and CVE-2023-2884[0-2]
References
- https://bugs.mageia.org/show_bug.cgi?id=31733
- https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw
- https://github.com/moby/buildkit/security/advisories/GHSA-gc89-7gcr-jxqc
- https://github.com/moby/moby/releases/tag/v24.0.5
- https://github.com/moby/moby/releases/tag/v24.0.4
- https://github.com/moby/moby/releases/tag/v24.0.3
- https://github.com/moby/moby/releases/tag/v24.0.2
- https://github.com/moby/moby/releases/tag/v24.0.1
- https://github.com/moby/moby/releases/tag/v24.0.0
- https://github.com/moby/moby/releases/tag/v23.0.3
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-26054
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28840
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28841
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28842
Resolution
MGASA-2023-0329 - Updated docker packages fix security vulnerabilities and bugs
SRPMS
- 9/core/docker-24.0.5-4.mga9
- 9/core/docker-containerd-1.7.3-1.mga9