All of lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2
@ 2024-04-28 17:01 Peter Korsgaard
  2024-04-28 17:01 ` [Buildroot] [PATCH 2/2] package/docker-cli: bump version to 26.0.2 Peter Korsgaard
  2024-04-29 12:02 ` [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Yann E. MORIN
  0 siblings, 2 replies; 3+ messages in thread
From: Peter Korsgaard @ 2024-04-28 17:01 UTC (permalink / raw)
  To: buildroot; +Cc: Christian Stewart

Fixes the following security issues:

CVE-2024-32473: Ensure IPv6 is disabled on interfaces only allocated an IPv4
address by the engine

https://github.com/moby/moby/security/advisories/GHSA-x84c-p2g9-rqv9

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
 package/docker-engine/docker-engine.hash | 2 +-
 package/docker-engine/docker-engine.mk   | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/package/docker-engine/docker-engine.hash b/package/docker-engine/docker-engine.hash
index 5c76b99af3..91bc3d8df2 100644
--- a/package/docker-engine/docker-engine.hash
+++ b/package/docker-engine/docker-engine.hash
@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  fae1aabb63ed5cf6d302a5f4266ed092716b1cea9a974a9d61154ef31b03c302  docker-engine-26.0.0.tar.gz
+sha256  f1cf6a2e69607daa0e2ae9b5be752dc269ab30dee16f5f2180f7ff7f29270606  docker-engine-26.0.2.tar.gz
 sha256  7c87873291f289713ac5df48b1f2010eb6963752bbd6b530416ab99fc37914a8  LICENSE
diff --git a/package/docker-engine/docker-engine.mk b/package/docker-engine/docker-engine.mk
index 86106d3ccb..f8dc87050f 100644
--- a/package/docker-engine/docker-engine.mk
+++ b/package/docker-engine/docker-engine.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-DOCKER_ENGINE_VERSION = 26.0.0
+DOCKER_ENGINE_VERSION = 26.0.2
 DOCKER_ENGINE_SITE = $(call github,moby,moby,v$(DOCKER_ENGINE_VERSION))
 
 DOCKER_ENGINE_LICENSE = Apache-2.0
-- 
2.39.2

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [Buildroot] [PATCH 2/2] package/docker-cli: bump version to 26.0.2
  2024-04-28 17:01 [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Peter Korsgaard
@ 2024-04-28 17:01 ` Peter Korsgaard
  2024-04-29 12:02 ` [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Yann E. MORIN
  1 sibling, 0 replies; 3+ messages in thread
From: Peter Korsgaard @ 2024-04-28 17:01 UTC (permalink / raw)
  To: buildroot; +Cc: Christian Stewart

https://github.com/moby/moby/releases/tag/v26.0.2

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
---
 package/docker-cli/docker-cli.hash | 2 +-
 package/docker-cli/docker-cli.mk   | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/package/docker-cli/docker-cli.hash b/package/docker-cli/docker-cli.hash
index 26558814c1..d8bfb1d824 100644
--- a/package/docker-cli/docker-cli.hash
+++ b/package/docker-cli/docker-cli.hash
@@ -1,3 +1,3 @@
 # Locally calculated
-sha256  96ed5d7c33a12f505d13fa03fa48f94cb41cf871178df0df84aa0b76839ad321  docker-cli-26.0.0.tar.gz
+sha256  b047e180c94452b4375f7e43997286e5a5712e66b1280574974b2e117b4e43bd  docker-cli-26.0.2.tar.gz
 sha256  2d81ea060825006fc8f3fe28aa5dc0ffeb80faf325b612c955229157b8c10dc0  LICENSE
diff --git a/package/docker-cli/docker-cli.mk b/package/docker-cli/docker-cli.mk
index 5f9242329a..69c6f12f3c 100644
--- a/package/docker-cli/docker-cli.mk
+++ b/package/docker-cli/docker-cli.mk
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-DOCKER_CLI_VERSION = 26.0.0
+DOCKER_CLI_VERSION = 26.0.2
 DOCKER_CLI_SITE = $(call github,docker,cli,v$(DOCKER_CLI_VERSION))
 
 DOCKER_CLI_LICENSE = Apache-2.0
-- 
2.39.2

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2
  2024-04-28 17:01 [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Peter Korsgaard
  2024-04-28 17:01 ` [Buildroot] [PATCH 2/2] package/docker-cli: bump version to 26.0.2 Peter Korsgaard
@ 2024-04-29 12:02 ` Yann E. MORIN
  1 sibling, 0 replies; 3+ messages in thread
From: Yann E. MORIN @ 2024-04-29 12:02 UTC (permalink / raw)
  To: Peter Korsgaard; +Cc: Christian Stewart, buildroot

Peter, All,

On 2024-04-28 19:01 +0200, Peter Korsgaard spake thusly:
> Fixes the following security issues:
> 
> CVE-2024-32473: Ensure IPv6 is disabled on interfaces only allocated an IPv4
> address by the engine
> 
> https://github.com/moby/moby/security/advisories/GHSA-x84c-p2g9-rqv9
> 
> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>

Both applied to master, thanks.

Regards,
Yann E. MORIN.

> ---
>  package/docker-engine/docker-engine.hash | 2 +-
>  package/docker-engine/docker-engine.mk   | 2 +-
>  2 files changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/package/docker-engine/docker-engine.hash b/package/docker-engine/docker-engine.hash
> index 5c76b99af3..91bc3d8df2 100644
> --- a/package/docker-engine/docker-engine.hash
> +++ b/package/docker-engine/docker-engine.hash
> @@ -1,3 +1,3 @@
>  # Locally calculated
> -sha256  fae1aabb63ed5cf6d302a5f4266ed092716b1cea9a974a9d61154ef31b03c302  docker-engine-26.0.0.tar.gz
> +sha256  f1cf6a2e69607daa0e2ae9b5be752dc269ab30dee16f5f2180f7ff7f29270606  docker-engine-26.0.2.tar.gz
>  sha256  7c87873291f289713ac5df48b1f2010eb6963752bbd6b530416ab99fc37914a8  LICENSE
> diff --git a/package/docker-engine/docker-engine.mk b/package/docker-engine/docker-engine.mk
> index 86106d3ccb..f8dc87050f 100644
> --- a/package/docker-engine/docker-engine.mk
> +++ b/package/docker-engine/docker-engine.mk
> @@ -4,7 +4,7 @@
>  #
>  ################################################################################
>  
> -DOCKER_ENGINE_VERSION = 26.0.0
> +DOCKER_ENGINE_VERSION = 26.0.2
>  DOCKER_ENGINE_SITE = $(call github,moby,moby,v$(DOCKER_ENGINE_VERSION))
>  
>  DOCKER_ENGINE_LICENSE = Apache-2.0
> -- 
> 2.39.2
> 
> _______________________________________________
> buildroot mailing list
> buildroot@buildroot.org
> https://lists.buildroot.org/mailman/listinfo/buildroot

-- 
.-----------------.--------------------.------------------.--------------------.
|  Yann E. MORIN  | Real-Time Embedded | /"\ ASCII RIBBON | Erics' conspiracy: |
| +33 662 376 056 | Software  Designer | \ / CAMPAIGN     |  ___               |
| +33 561 099 427 `------------.-------:  X  AGAINST      |  \e/  There is no  |
| http://ymorin.is-a-geek.org/ | _/*\_ | / \ HTML MAIL    |   v   conspiracy.  |
'------------------------------^-------^------------------^--------------------'
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2024-04-29 12:02 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-04-28 17:01 [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Peter Korsgaard
2024-04-28 17:01 ` [Buildroot] [PATCH 2/2] package/docker-cli: bump version to 26.0.2 Peter Korsgaard
2024-04-29 12:02 ` [Buildroot] [PATCH 1/2] package/docker-engine: security bump to version 26.0.2 Yann E. MORIN

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.