package/containerd: security bump to version 1.5.13

Fixes the following security issues:

- CVE-2022-31030: containerd CRI plugin: Host memory exhaustion through
  ExecSync

  A bug was found in containerd's CRI implementation where programs inside a
  container can cause the containerd daemon to consume memory without bound
  during invocation of the ExecSync API.  This can cause containerd to
  consume all available memory on the computer, denying service to other
  legitimate workloads.  Kubernetes and crictl can both be configured to use
  containerd's CRI implementation; ExecSync may be used when running probes
  or when executing processes via an "exec" facility.

https://github.com/containerd/containerd/security/advisories/GHSA-5ffw-gxpp-mxpf

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
This commit is contained in:
Peter Korsgaard
2022-09-14 22:04:26 +02:00
parent 5652dfab34
commit 52d19b7c4d
2 changed files with 2 additions and 2 deletions

View File

@@ -1,3 +1,3 @@
# Computed locally
sha256 02b79d5e2b07b5e64cd28f1fe84395ee11eef95fc49fd923a9ab93022b148be6 containerd-1.5.11.tar.gz
sha256 ac75e2a5552163c203f836f5e9feac349f78f7956e8da228c372a12554b1ee40 containerd-1.5.13.tar.gz
sha256 4bbe3b885e8cd1907ab4cf9a41e862e74e24b5422297a4f2fe524e6a30ada2b4 LICENSE

View File

@@ -4,7 +4,7 @@
#
################################################################################
CONTAINERD_VERSION = 1.5.11
CONTAINERD_VERSION = 1.5.13
CONTAINERD_SITE = $(call github,containerd,containerd,v$(CONTAINERD_VERSION))
CONTAINERD_LICENSE = Apache-2.0
CONTAINERD_LICENSE_FILES = LICENSE