USN-5521-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5521-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5521-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5521-1
Related
Published
2022-07-15T13:48:23.024458Z
Modified
2022-07-15T13:48:23.024458Z
Summary
containerd vulnerabilities
Details

It was discovered that containerd insufficiently restricted permissions on container root and plugin directories. If a user or automated system were tricked into launching a specially crafted container image, a remote attacker could traverse directory contents and modify files and execute programs on the host file system, possibly leading to privilege escalation. (CVE-2021-41103)

It was discovered that containerd incorrectly handled file permission changes. If a user or automated system were tricked into launching a specially crafted container image, a remote attacker could change permissions on files on the host file system and possibly escalate privileges. (CVE-2021-32760)

It was discovered that containerd allows attackers to gain access to read- only copies of arbitrary files and directories on the host via a specially- crafted image configuration. An attacker could possibly use this issue to obtain sensitive information. (CVE-2022-23648)

It was discovered that containerd incorrectly handled certain memory operations. A remote attacker could use this to cause a denial of service. (CVE-2022-31030)

References

Affected packages

Ubuntu:Pro:16.04:LTS / containerd

Package

Name
containerd
Purl
pkg:deb/ubuntu/containerd@1.2.6-0ubuntu1~16.04.6+esm2?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.6-0ubuntu1~16.04.6+esm2

Affected versions

0.*

0.2.1-0ubuntu4~16.04
0.2.3-0ubuntu1~16.04
0.2.5-0ubuntu1~16.04.1

1.*

1.2.6-0ubuntu1~16.04.2
1.2.6-0ubuntu1~16.04.3
1.2.6-0ubuntu1~16.04.4
1.2.6-0ubuntu1~16.04.5
1.2.6-0ubuntu1~16.04.6
1.2.6-0ubuntu1~16.04.6+esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "golang-github-docker-containerd-dev": "1.2.6-0ubuntu1~16.04.6+esm2",
            "containerd": "1.2.6-0ubuntu1~16.04.6+esm2"
        }
    ]
}