[Buildroot] [PATCH/next 1/1] package/lxc: security bump to version 3.2.1

Thomas Petazzoni thomas.petazzoni at bootlin.com
Sat Aug 17 19:59:03 UTC 2019


Hello,

+Peter in Cc.

On Sat, 17 Aug 2019 21:36:27 +0200
Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:

> Hello Thomas,
> 
> Le sam. 17 août 2019 à 15:41, Thomas Petazzoni
> <thomas.petazzoni at bootlin.com> a écrit :
> >
> > On Fri, 16 Aug 2019 19:03:15 +0200
> > Fabrice Fontaine <fontaine.fabrice at gmail.com> wrote:
> >  
> > > - lxc switched from gnutls to openssl since version 3.2.0 and
> > >   https://github.com/lxc/lxc/commit/fa2bb6ba532c5e7f92df8cbae50a68af519f9997
> > > - lxc needs a glibc or musl toolchain since version 3.2.0 and
> > >   https://github.com/lxc/lxc/commit/6400238d08cdf1ca20d49bafb85f4e224348bf9d
> > > - This version includes a security fix (named CVE-2019-5736 on runC):
> > >   https://github.com/lxc/lxc/commit/6400238d08cdf1ca20d49bafb85f4e224348bf9d
> > >
> > > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>  
> >
> > We normally apply security bumps to master. But this one seems like a
> > quite major bump, and it also disables the package for uClibc.  
> Yes I know that's why I marked it for next.
> >
> > Does it make sense to backport just the security fix in master ?  
> I could but this fix will add the glibc or musl toolchain dependency.

OK, so let's bring Peter Korsgaard in Cc. Since he maintains the
stable/LTS branches, it is important to get his call on this issue.

Thanks,

Thomas
-- 
Thomas Petazzoni, CTO, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com



More information about the buildroot mailing list