[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[bug#34446] Runc container escape patches CVE-2019-5736
From: |
Leo Famulari |
Subject: |
[bug#34446] Runc container escape patches CVE-2019-5736 |
Date: |
Mon, 11 Feb 2019 18:37:08 -0500 |
User-agent: |
Mutt/1.11.2 (2019-01-07) |
These patches aim to fix CVE-2019-5736 in runc / Docker:
https://seclists.org/oss-sec/2019/q1/119
However, after applying these patches, Docker fails to build as shown
below. Runc, docker-cli, and containerd still build.
Please help :)
------
phase `setup-environment' succeeded after 0.0 seconds
starting phase `build'
# WARNING! I don't seem to be running in a Docker container.
# The result of this command might be an incorrect build, and will not be
# officially supported.
#
# Try this instead: make all
#
Removing bundles/
---> Making bundle: dynbinary (in bundles/dynbinary)
Building: bundles/dynbinary-daemon/dockerd-dev
# github.com/docker/docker/vendor/github.com/docker/libnetwork/iptables
.gopath/src/github.com/docker/docker/vendor/github.com/docker/libnetwork/iptables/iptables.go:90:15:
undefined: exec.Guix_doesnt_want_LookPath
.gopath/src/github.com/docker/docker/vendor/github.com/docker/libnetwork/iptables/iptables.go:90:45:
invalid character U+005C '\'
Backtrace:
4 (primitive-load "/gnu/store/n5jmx2wksfvcrwlpv2zafd5hany…")
In ice-9/eval.scm:
191:35 3 (_ _)
In srfi/srfi-1.scm:
863:16 2 (every1 #<procedure ac28a0 at /gnu/store/rkv7z31csb2xa…> …)
In
/gnu/store/rkv7z31csb2xandzhnvm5kc0i78pf0ay-module-import/guix/build/gnu-build-system.scm:
799:28 1 (_ _)
In
/gnu/store/rkv7z31csb2xandzhnvm5kc0i78pf0ay-module-import/guix/build/utils.scm:
616:6 0 (invoke _ . _)
/gnu/store/rkv7z31csb2xandzhnvm5kc0i78pf0ay-module-import/guix/build/utils.scm:616:6:
In procedure invoke:
Throw to key `srfi-34' with args `(#<condition &invoke-error [program:
"hack/make.sh" arguments: ("dynbinary") exit-status: 2 term-signal: #f
stop-signal: #f] 491cc0>)'.
builder for `/gnu/store/ihdm0nlw118mrb8wq127864g9pgrmghk-docker-18.09.2.drv'
failed with exit code 1
build of /gnu/store/ihdm0nlw118mrb8wq127864g9pgrmghk-docker-18.09.2.drv failed
View build log at
'/var/log/guix/drvs/ih/dm0nlw118mrb8wq127864g9pgrmghk-docker-18.09.2.drv.bz2'.
guix build: error: build of
`/gnu/store/ihdm0nlw118mrb8wq127864g9pgrmghk-docker-18.09.2.drv' failed
------
signature.asc
Description: PGP signature
- [bug#34446] Runc container escape patches CVE-2019-5736,
Leo Famulari <=