Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[16.0] runc containerd cves#5453

Merged
rene merged 2 commits into
lf-edge:16.0from
deitch:16.0-runc-containerd-cves
Nov 26, 2025
Merged

[16.0] runc containerd cves#5453
rene merged 2 commits into
lf-edge:16.0from
deitch:16.0-runc-containerd-cves

Conversation

@deitch

@deitch deitch commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

Description

Backport of #5409

PR dependencies

See original PR.

How to test and validate this PR

See original PR

This change bumps runc to v3.3.0, which addresses 3 critical CVEs: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881.
While doing so, it also bumps containerd to v2.2.0.

Signed-off-by: Avi Deitcher <[email protected]>
@rene

rene commented Nov 26, 2025

Copy link
Copy Markdown
Contributor

@deitch:

ERROR: size of /opt/actions-runner/_work/eve/eve/dist/amd64/0.0.0-pr5453-16.0.0-rc4-16-g569bcddf/installer/rootfs-generic.img is greater than 285MB (bigger than allocated partition)

You are missing commit 488c768

@deitch

deitch commented Nov 26, 2025

Copy link
Copy Markdown
Contributor Author

Ah, I cherry-picked only one commit. Fixing.

The old max rootfs size was 285MB, it needs to be 290MB. Still below the actual 300MB
partition size in many live deployments.

Signed-off-by: Avi Deitcher <[email protected]>
@deitch

deitch commented Nov 26, 2025

Copy link
Copy Markdown
Contributor Author

Good catch, thank you @rene ; updated

@rene rene left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@rene rene merged commit 626d16d into lf-edge:16.0 Nov 26, 2025
44 checks passed
@deitch deitch deleted the 16.0-runc-containerd-cves branch November 26, 2025 15:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants