========================================================================== Ubuntu Security Notice USN-5776-1 December 13, 2022 containerd vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in containerd. Software Description: - containerd: daemon to control runC Details: It was discovered that containerd incorrectly handled memory when receiving certain faulty Exec or ExecSync commands. A remote attacker could possibly use this issue to cause a denial of service or crash containerd. (CVE-2022-23471, CVE-2022-31030) It was discovered that containerd incorrectly set up inheritable file capabilities. An attacker could possibly use this issue to escalate privileges inside a container. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24769) It was discovered that containerd incorrectly handled access to encrypted container images when using imgcrypt library. A remote attacker could possibly use this issue to access encrypted images from other users. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-24778) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: containerd 1.6.4-0ubuntu1.1 Ubuntu 22.04 LTS: containerd 1.5.9-0ubuntu3.1 Ubuntu 20.04 LTS: containerd 1.5.9-0ubuntu1~20.04.6 Ubuntu 18.04 LTS: containerd 1.5.9-0ubuntu1~18.04.2 After a standard system update you need to restart containerd to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5776-1 CVE-2022-23471, CVE-2022-24769, CVE-2022-24778, CVE-2022-31030 Package Information: https://launchpad.net/ubuntu/+source/containerd/1.6.4-0ubuntu1.1 https://launchpad.net/ubuntu/+source/containerd/1.5.9-0ubuntu3.1 https://launchpad.net/ubuntu/+source/containerd/1.5.9-0ubuntu1~20.04.6 https://launchpad.net/ubuntu/+source/containerd/1.5.9-0ubuntu1~18.04.2