snapd (2.37.4-1+deb10u1) buster-security; urgency=medium
authorMichael Vogt <mvo@debian.org>
Thu, 17 Feb 2022 15:29:46 +0000 (15:29 +0000)
committerMichael Vogt <mvo@debian.org>
Thu, 17 Feb 2022 15:29:46 +0000 (15:29 +0000)
commit1458fa5ba364c9c17f53f86c4afc66384fd5f5f8
tree5dc4e035950ae3a771f3c4106fa8fb7d3620954a
parentaaede0e1c96e61f4d2697ad194ba7fe749d112ee
parent0a6869fde2383398fac6cf3516ba1e48ff9bb0cf
snapd (2.37.4-1+deb10u1) buster-security; urgency=medium

   * SECURITY UPDATE: local privilege escalation
    - d/p/cve202144730: Add validations of the
      location of the snap-confine binary within snapd.
    - d/p/cve202144730: Fix race condition in snap-confine
      when preparing a private mount namespace for a snap.
    - CVE-2021-44730
    - CVE-2021-44731

[dgit import unpatched snapd 2.37.4-1+deb10u1]
40 files changed:
debian/changelog
debian/compat
debian/control
debian/copyright
debian/gbp.conf
debian/golang-github-snapcore-snapd-dev.install
debian/not-installed
debian/patches/0001-cmd-snap-seccomp-use-upstream-seccomp-package.patch
debian/patches/0002-cmd-snap-seccomp-skip-tests-that-fail-on-4.19.patch
debian/patches/0003-cmd-snap-seccomp-skip-tests-that-use-m32.patch
debian/patches/0004-cmd-snap-skip-tests-depending-on-text-wrapping.patch
debian/patches/0005-advisor-errtracker-use-upstream-bolt-package.patch
debian/patches/0006-systemd-disable-snapfuse-system.patch
debian/patches/0007-i18n-use-dummy-localizations-to-avoid-dependencies.patch
debian/patches/0010-man-page-sections.patch
debian/patches/cve202144730/0010-cmd-libsnap-confine-private-Fix-use-of-uninitialised.patch
debian/patches/cve202144730/0011-cmd-libsnap-confine-private-Defend-against-hardlink-.patch
debian/patches/cve202144730/0012-cmd-libsnap-confine-private-Don-t-fail-open-on-appar.patch
debian/patches/cve202144730/0013-cmd-libsnap-confine-private-Tighten-AppArmor-label-c.patch
debian/patches/cve202144730/0014-cmd-snap-confine-Remove-execute-permission-from-AppA.patch
debian/patches/cve202144730/0015-cmd-snap-confine-Prevent-user-controlled-race-in-set.patch
debian/patches/series
debian/rules
debian/snap-confine.maintscript
debian/snapd.autoimport.udev
debian/snapd.dirs
debian/snapd.install
debian/snapd.links
debian/snapd.lintian-overrides
debian/snapd.maintscript
debian/snapd.manpages
debian/snapd.postinst
debian/snapd.postrm
debian/source/format
debian/source/options
debian/tests/README.md
debian/tests/control
debian/tests/integrationtests
debian/tests/testconfig.json
debian/watch