Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update docker/runc version on summerwind/actions-runner #3259

Open
klepiz opened this issue Feb 2, 2024 · 1 comment · May be fixed by #3262
Open

update docker/runc version on summerwind/actions-runner #3259

klepiz opened this issue Feb 2, 2024 · 1 comment · May be fixed by #3262
Labels
community Community contribution enhancement New feature or request needs triage Requires review from the maintainers

Comments

@klepiz
Copy link

klepiz commented Feb 2, 2024

What would you like added? and Why is this needed?

As cause of the recent docker vulnerabilty https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/,
urrently the lastest version of summerwind/actions-runner contains Docker version 24.0.7, build afdd53b, Docker required to be updated to Docker Engine 4.25.2 and runc 1.1.12 which contains a fix CVE-2024-24557, CVE-2024-23650, CVE-2024-23651, CVE-2024-23652 and CVE-2024-23653 and CVE-2024-21626

Questions

Is there a faster way to update the docker/runc version for actions-runner-controller? my current k8s master/nodes are already updated to the latest version of runc

@klepiz klepiz added community Community contribution enhancement New feature or request needs triage Requires review from the maintainers labels Feb 2, 2024
@luisrussi
Copy link

Any updates here in how to proceed?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
community Community contribution enhancement New feature or request needs triage Requires review from the maintainers
Projects
None yet
2 participants