-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 23 Nov 2021 18:42:16 +0800 Source: containerd Architecture: source Version: 1.4.12~ds1-1~deb11u1 Distribution: bullseye Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Shengjing Zhu <zhsj@debian.org> Closes: 998909 Changes: containerd (1.4.12~ds1-1~deb11u1) bullseye; urgency=medium . * New upstream version 1.4.12~ds1 + 1.4.12 * Mitigate CVE-2021-41190: Handle ambiguous OCI manifest parsing * Update pull to try next mirror for non-404 errors * Update pull to handle of non-https urls in descriptors + 1.4.11 * CVE-2021-41103: Fix insufficiently restricted permissions on container root and plugin directories + 1.4.10 * Support "clone3" in default seccomp profile * Fix panic in metadata content writer on copy error + 1.4.9 * Update pull authorization logic on redirect * Fix user agent used for fetching registry authentication tokens + 1.4.8 * CVE-2021-32760: Archive package allows chmod of file outside of unpack target directory + 1.4.7 * Fix invalid validation error checking * Fix error on image pull resume * Refresh patches + Drop CVE-2021-32760 patch + Drop CVE-2021-41103 patch + Refresh 0005-backport-github.com-containerd-containerd-remotes.patch with latest 1.5 release branch * Backport RPi1/RPi0 workaround (Closes: #998909) Checksums-Sha1: 84277ed032a602847fa7f25070fce94934fb6eea 3896 containerd_1.4.12~ds1-1~deb11u1.dsc 92b07e794218779cf80698adaa6de936f387d6cc 1489312 containerd_1.4.12~ds1.orig.tar.xz bb987db717cc6e08603bdb382608bffc27a16c05 27416 containerd_1.4.12~ds1-1~deb11u1.debian.tar.xz eb05af031c3ff9da01d5dcaee54d667614c1eeef 12704 containerd_1.4.12~ds1-1~deb11u1_amd64.buildinfo Checksums-Sha256: a73e1c3746439247ac3667d71f9f7f79c80b83192baccee8edd9722dc8079fc6 3896 containerd_1.4.12~ds1-1~deb11u1.dsc a54b47f4fd13a1ab3c6f142f936b71674222f6c9399df37268b526ae18f3ff9e 1489312 containerd_1.4.12~ds1.orig.tar.xz d43706ca333c5534af93706e01c06c33f05de98ba67db4d101de0ad52f96a47d 27416 containerd_1.4.12~ds1-1~deb11u1.debian.tar.xz 621cdb697bb0843a8aad9135f49793ac629cfd8787a8040dac7ef8c7f1b33aae 12704 containerd_1.4.12~ds1-1~deb11u1_amd64.buildinfo Files: a1e3e33d65616ceb02977ab6795c5e9d 3896 admin optional containerd_1.4.12~ds1-1~deb11u1.dsc 41f6617c41d239409067a017d8c49342 1489312 admin optional containerd_1.4.12~ds1.orig.tar.xz c2bbdbbd9d2f153c6d98e83ad1c59419 27416 admin optional containerd_1.4.12~ds1-1~deb11u1.debian.tar.xz de6c22de838ef85631b15613e09954fe 12704 admin optional containerd_1.4.12~ds1-1~deb11u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iIYEARYIAC4WIQSRhdT1d2eu7mxV1B5/RPol6lUUywUCYapHXRAcemhzakBkZWJp YW4ub3JnAAoJEH9E+iXqVRTLk+oBAPgnOy7z4Pmb28EQKdMsmZb9AGXosPsm3I/Z SHrzK37WAP4hqSSjVrDn0I1r5Hnl4W2eOnLDzZN6qIi0bZBI4/05Cg== =xNfH -----END PGP SIGNATURE-----