snapd (2.54.3-1) unstable; urgency=high
authorMichael Vogt <mvo@debian.org>
Wed, 23 Feb 2022 09:04:21 +0000 (09:04 +0000)
committerMichael Vogt <mvo@debian.org>
Wed, 23 Feb 2022 09:04:21 +0000 (09:04 +0000)
commit588c7d1bb801e86cc1aecd3ea5b112098c1d68fd
tree0e70c7356d051e5c93c7dc30b1c39d40812ea940
parent1f5f3c47fedccdb3608e65454602a39357b12b8c
parentbcc1d9e122d8daf363e1769e8619b61aa5c5165e
snapd (2.54.3-1) unstable; urgency=high

  * SECURITY UPDATE: Local privilege escalation
    - snap-confine: Add validations of the location of the snap-confine
      binary within snapd.
    - snap-confine: Fix race condition in snap-confine when preparing a
      private mount namespace for a snap.
    - CVE-2021-44730
    - CVE-2021-44731
  * SECURITY UPDATE: Data injection from malicious snaps
    - interfaces: Add validations of snap content interface and layout
      paths in snapd.
    - CVE-2021-4120
    - LP: #1949368

[dgit import unpatched snapd 2.54.3-1]
34 files changed:
debian/README.Source
debian/changelog
debian/compat
debian/control
debian/copyright
debian/gbp.conf
debian/golang-github-snapcore-snapd-dev.install
debian/not-installed
debian/patches/0002-cmd-snap-seccomp-skip-tests-that-fail-on-4.19.patch
debian/patches/0003-cmd-snap-seccomp-skip-tests-that-use-m32.patch
debian/patches/0004-cmd-snap-skip-tests-depending-on-text-wrapping.patch
debian/patches/0005-advisor-errtracker-use-upstream-bolt-package.patch
debian/patches/0007-i18n-use-dummy-localizations-to-avoid-dependencies.patch
debian/patches/0010-man-page-sections.patch
debian/patches/series
debian/rules
debian/snap-confine.maintscript
debian/snapd.autoimport.udev
debian/snapd.dirs
debian/snapd.install
debian/snapd.links
debian/snapd.lintian-overrides
debian/snapd.maintscript
debian/snapd.manpages
debian/snapd.postinst
debian/snapd.postrm
debian/snapd.prerm
debian/source/format
debian/source/options
debian/tests/README.md
debian/tests/control
debian/tests/integrationtests
debian/tests/testconfig.json
debian/watch