[PATCH] Initialize nss libraries in Glibc so that the dynamic libraries are loaded...
authorJustin Cormack <justin.cormack@docker.com>
Thu, 25 Jul 2019 14:24:39 +0000 (15:24 +0100)
committerFelix Geyer <fgeyer@debian.org>
Sun, 21 Feb 2021 17:18:35 +0000 (17:18 +0000)
commitddb1e18f5c4f86a4328267bfa3033427968be32d
treedd4065517c605b59aa6b49d07429bc58d37f81f5
parent61ad656e198a08bf5241cd6d81f575ead591b8d0
[PATCH] Initialize nss libraries in Glibc so that the dynamic libraries are loaded in the host environment not in the chroot from untrusted files.

See also OpenVZ https://github.com/kolyshkin/vzctl/blob/a3f732ef751998913fcf0a11b3e05236b51fd7e9/src/enter.c#L227-L234

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
Signed-off-by: Tibor Vass <tibor@docker.com>
(cherry picked from commit a316b10dab79d9298b02c7930958ed52e0ccf4e4)

Gbp-Pq: Name cve-2019-14271-Initialize-nss-libraries-in-Glibc.patch
engine/pkg/chrootarchive/archive.go