snapd (2.37.4-1+deb10u2) buster-security; urgency=medium
authorAlex Murray <alex.murray@canonical.com>
Tue, 29 Nov 2022 12:01:21 +0000 (12:01 +0000)
committerAlex Murray <alex.murray@canonical.com>
Tue, 29 Nov 2022 12:01:21 +0000 (12:01 +0000)
commitc5ccb56dd6cd3e234089aee05d6af846d8128319
tree4fcc39d17c9b789d673e857640aac72bc9fecbc8
parentaaede0e1c96e61f4d2697ad194ba7fe749d112ee
parent7f5ba927a8f320294c69ebe3111c7e0de1d59180
snapd (2.37.4-1+deb10u2) buster-security; urgency=medium

  * SECURITY UPDATE: Local privilege escalation
    - snap-confine: Fix race condition in snap-confine when preparing a
      private tmp mount namespace for a snap
    - CVE-2022-3328

[dgit import unpatched snapd 2.37.4-1+deb10u2]
42 files changed:
debian/changelog
debian/compat
debian/control
debian/copyright
debian/gbp.conf
debian/golang-github-snapcore-snapd-dev.install
debian/not-installed
debian/patches/0001-cmd-snap-seccomp-use-upstream-seccomp-package.patch
debian/patches/0002-cmd-snap-seccomp-skip-tests-that-fail-on-4.19.patch
debian/patches/0003-cmd-snap-seccomp-skip-tests-that-use-m32.patch
debian/patches/0004-cmd-snap-skip-tests-depending-on-text-wrapping.patch
debian/patches/0005-advisor-errtracker-use-upstream-bolt-package.patch
debian/patches/0006-systemd-disable-snapfuse-system.patch
debian/patches/0007-i18n-use-dummy-localizations-to-avoid-dependencies.patch
debian/patches/0010-man-page-sections.patch
debian/patches/cve202144730/0010-cmd-libsnap-confine-private-Fix-use-of-uninitialised.patch
debian/patches/cve202144730/0011-cmd-libsnap-confine-private-Defend-against-hardlink-.patch
debian/patches/cve202144730/0012-cmd-libsnap-confine-private-Don-t-fail-open-on-appar.patch
debian/patches/cve202144730/0013-cmd-libsnap-confine-private-Tighten-AppArmor-label-c.patch
debian/patches/cve202144730/0014-cmd-snap-confine-Remove-execute-permission-from-AppA.patch
debian/patches/cve202144730/0015-cmd-snap-confine-Prevent-user-controlled-race-in-set.patch
debian/patches/cve20223328/0016-cve-2022-3328-1.patch
debian/patches/cve20223328/0017-cve-2022-3328-2.patch
debian/patches/series
debian/rules
debian/snap-confine.maintscript
debian/snapd.autoimport.udev
debian/snapd.dirs
debian/snapd.install
debian/snapd.links
debian/snapd.lintian-overrides
debian/snapd.maintscript
debian/snapd.manpages
debian/snapd.postinst
debian/snapd.postrm
debian/source/format
debian/source/options
debian/tests/README.md
debian/tests/control
debian/tests/integrationtests
debian/tests/testconfig.json
debian/watch