snapd.git
3 years ago[PATCH 1/9] cmd/snap-seccomp: use upstream seccomp package
Zygmunt Krynicki [Thu, 17 Jan 2019 13:48:46 +0000 (15:48 +0200)]
[PATCH 1/9] cmd/snap-seccomp: use upstream seccomp package

Upstream snapd uses a fork that carries additional compatibility patch
required to build snapd for Ubuntu 14.04. This patch is not required with
the latest snapshot of the upstream seccomp golang bindings but they are
neither released upstream nor backported (in their entirety) to Ubuntu
14.04.

The forked seccomp library is not packaged in Debian. As such, to build
snapd, we need to switch to the regular, non-forked package name.

Signed-off-by: Zygmunt Krynicki <me@zygoon.pl>
Signed-off-by: Maciej Borzecki <maciej.zenon.borzecki@canonical.com>
Gbp-Pq: Name 0001-cmd-snap-seccomp-use-upstream-seccomp-package.patch

3 years agosnapd (2.49-1+deb11u1) bullseye-security; urgency=high
Michael Vogt [Wed, 16 Feb 2022 09:56:34 +0000 (09:56 +0000)]
snapd (2.49-1+deb11u1) bullseye-security; urgency=high

  * SECURITY UPDATE: local privilege escalation
    - 0015-cve-2021-44730-44731-4120.patch: Add validations of the
      location of the snap-confine binary within snapd.
    - 0015-cve-2021-44730-44731-4120: Fix race condition in snap-confine
      when preparing a private mount namespace for a snap.
    - 0016-cve-2021-2021-44730-44731-4120-auto-remove.patch: automatic
      remove vulnerable inactive core/snapd snaps
    - CVE-2021-44730
    - CVE-2021-44731
  * SECURITY UPDATE: data injection from malicious snaps
    - 0015-cve-2021-44730-44731-4120: Add validations of snap content
      interface and layout paths in snapd
    - CVE-2021-4120
    - LP: #1949368

[dgit import unpatched snapd 2.49-1+deb11u1]

3 years agoImport snapd_2.49-1+deb11u1.debian.tar.xz
Michael Vogt [Wed, 16 Feb 2022 09:56:34 +0000 (09:56 +0000)]
Import snapd_2.49-1+deb11u1.debian.tar.xz

[dgit import tarball snapd 2.49-1+deb11u1 snapd_2.49-1+deb11u1.debian.tar.xz]

4 years agoImport snapd_2.49.orig.tar.gz
Michael Vogt [Wed, 24 Feb 2021 08:23:51 +0000 (08:23 +0000)]
Import snapd_2.49.orig.tar.gz

[dgit import orig snapd_2.49.orig.tar.gz]