docker.socket systemd configurations dosn't exist
umarshalling volume options for volume: unexpected end of JSON input
[trackerbug] docker 24.0.6-ce update
VUL-0: docker: mitigate power-based side channel attacks (advisory GHSA-jq35-85cj-fj4p)
VUL-0: CVE-2024-23651: docker: race condition in mount
VUL-0: CVE-2024-23652: docker: arbitrary deletion of files
VUL-0: CVE-2024-23653: buildkit: BuildKit API doesn't validate entitlement on container creation
docker-24.0.7 makes docker overlay files world writable [ref:_00D1igLOd._500Tr634Oc:ref]
L3: SLES15-SP4: Docker buildx build fails to COPY from build stage using nested links
[trackerbug] docker 25.0.5 update
VUL-0: CVE-2024-41110: docker: Authz zero length regression
cyphar
critical
security
Security update for docker
This update for docker fixes the following issues:
Security fixes:
- CVE-2024-23651: Fixed arbitrary files write due to race condition on mounts (bsc#1219267)
- CVE-2024-23652: Fixed insufficient validation of parent directory on mount (bsc#1219268)
- CVE-2024-23653: Fixed insufficient validation on entitlement on container creation via buildkit (bsc#1219438)
- CVE-2024-41110: A Authz zero length regression that could lead to authentication bypass was fixed (bsc#1228324)
Other changes:
- Update to Docker 25.0.6-ce.
- Fix BuildKit's symlink resolution logic to correctly handle non-lexical
symlinks. (bsc#1221916)
- Write volume options atomically so sudden system crashes won't result in
future Docker starts failing due to empty files. (bsc#1214855)
- Fixed world writable docker overlay files (bsc#1220339)
docker
Updating docker will restart the docker service, which may stop some of your docker containers. Do you want to proceed with the update?