Replies: 2 comments 10 replies
-
From what I understand, you can't upgrade the version of runc or containerd underlying RKE2 without upgrading RKE2 itself. I'm very interested in the ETA on a patched version of RKE2 if one doesn't already exist, but I'm scanning the available versions as we speak. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Looks like there's an open RKE2 issue to patch the vulnerability: #5340 |
Beta Was this translation helpful? Give feedback.
10 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Snyk posted a container breakout vulnerability at the end of January that impacts container environments like docker + kubernetes (by extension, RKE2) and it looks like it can be remediated by updating the local version of runc to a newer version. That version of runc looks to be much newer than the version of runc included in docker images for RKE2's stable release channel (v1.26.12+rke2r1).
What does Rancher Labs recommend for remediating this CVE until a patch hardening the vulnerbility is developed and released?
If there's a better place to discuss this issue, please let me know.
Beta Was this translation helpful? Give feedback.
All reactions