Thanks to visit codestin.com
Credit goes to github.com

Skip to content

CVE fixes suse-v29.4.0 - #12

Open
val4oss wants to merge 2 commits into
SUSE:suse-v29.4.0from
val4oss:suse-v29.4.0-cve-2026-41568
Open

CVE fixes suse-v29.4.0#12
val4oss wants to merge 2 commits into
SUSE:suse-v29.4.0from
val4oss:suse-v29.4.0-cve-2026-41568

Conversation

@val4oss

@val4oss val4oss commented Jul 7, 2026

Copy link
Copy Markdown

CVE-2026-41568: daemon/copy: Fix symlink escape in mount destination creation
CVE-2026-14362: HashiCorp memberlist fix DOS

@val4oss
val4oss force-pushed the suse-v29.4.0-cve-2026-41568 branch from 51721d5 to f815c05 Compare July 15, 2026 10:02
@val4oss
val4oss requested a review from rcmadhankumar July 15, 2026 10:22
@val4oss
val4oss force-pushed the suse-v29.4.0-cve-2026-41568 branch from f815c05 to 54630d3 Compare August 21, 2026 13:26
@val4oss val4oss changed the title daemon/copy: Fix symlink escape in mount destination creation CVE fixes suse-v29.4.0 Aug 21, 2026

@danishprakash danishprakash left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The commit messages are missing bugzilla refs, SUSE-Bugs: bsc#<>, can you add those?

vvoland and others added 2 commits August 25, 2026 16:30
…creation

Use os.Root to scope all filesystem operations in createIfNotExists to
the container root directory.

This prevents a TOCTOU attack where a container process swaps a path
component with a symlink between GetResourcePath resolution and
directory/file creation, which could allow writing to arbitrary host
paths outside the container.

Signed-off-by: Paweł Gronowski <[email protected]>
(cherry picked from commit 64a22d8)

SUSE-Bugs: bsc#1268280<https://bugzilla.suse.com/show_bug.cgi?id=1268280>
* hashicorp/memberlist@371698b

limit remote state header values (moby#357)

The header of a push-pull state message contains a count of nodes and user state
length. As an optimization, both of these fields are used to pre-allocate memory
to receive the remote state before copying it off the wire. But if the header
mismatches the actual state, a very small pull-push state message (or at least
one below the message size limit) can be used to consume excess memory on the
receiver.

Limit the memory allocated such that the maximum amount allocated cannot exceed
the maximum actual size of the push-pull state, either in number of nodes or
size of the user state.

Ref: https://hashicorp.atlassian.net/browse/SECVULN-42161
Ref: https://hashicorp.atlassian.net/browse/NMD-1523

hashicorp/memberlist@bc32294

limit user message length (moby#361)

readUserMsg sizes make([]byte, header.UserMsgLen) from the wire header with no bound, so a small userMsg frame declaring a large length forces a large allocation on the receiver. This is the userMsg path of the same issue moby#357 fixed for push-pull state.

Fixes: moby#360

hashicorp/memberlist@7de15ac

limit decompressed message size (moby#363)

decompressBuffer drains the LZW reader with io.Copy into an unbounded buffer, so a small compressMsg expands without limit and can exhaust memory. Cap the output at maxDecompressedBytes with io.CopyN and error past it.

SUSE-Bugs: bsc#1271209<https://bugzilla.suse.com/show_bug.cgi?id=1271209>
@val4oss
val4oss force-pushed the suse-v29.4.0-cve-2026-41568 branch from 54630d3 to a051727 Compare August 25, 2026 14:34
@val4oss

val4oss commented Aug 25, 2026

Copy link
Copy Markdown
Author

The commit messages are missing bugzilla refs, SUSE-Bugs: bsc#<>, can you add those?

Thanks for the information, reference to bug added in the commits. Is it good ?

@val4oss
val4oss requested a review from danishprakash August 25, 2026 14:35

@danishprakash danishprakash left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants