-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 17 Feb 2022 16:29:46 +0100 Source: snapd Built-For-Profiles: noudeb Architecture: source Version: 2.37.4-1+deb10u1 Distribution: buster-security Urgency: medium Maintainer: Michael Hudson-Doyle <mwhudson@debian.org> Changed-By: Michael Vogt <mvo@debian.org> Changes: snapd (2.37.4-1+deb10u1) buster-security; urgency=medium . * SECURITY UPDATE: local privilege escalation - d/p/cve202144730: Add validations of the location of the snap-confine binary within snapd. - d/p/cve202144730: Fix race condition in snap-confine when preparing a private mount namespace for a snap. - CVE-2021-44730 - CVE-2021-44731 Checksums-Sha1: 983fe5ee47f87e6b57b35412b0c7229ec7e87eeb 3524 snapd_2.37.4-1+deb10u1.dsc b12f25e4f149496c4f46a48537689b4fc698215b 1885960 snapd_2.37.4.orig.tar.xz d00645d6f623f4808eafcb296cba61b47617d750 69344 snapd_2.37.4-1+deb10u1.debian.tar.xz 6c29ba582f443d5b4075299005dc4f83d9b25c88 15036 snapd_2.37.4-1+deb10u1_source.buildinfo Checksums-Sha256: dd610b7fdca65ba94c209d7a202f403eb66b9c4b8ae21abcea1dfd3331348487 3524 snapd_2.37.4-1+deb10u1.dsc 03b3a6c32a48c3ac5ee863ce4de284ed70ac4b45e58f165a21b30ee903c7e73f 1885960 snapd_2.37.4.orig.tar.xz 6bff28d2bb16d2bc4a969dcc41c3c0d9a2ba2bdcd9c6054ce0858772feb26c46 69344 snapd_2.37.4-1+deb10u1.debian.tar.xz eda3f4f0fb5593174632d86c8391d1408b1945a16334887f5603280f12610e30 15036 snapd_2.37.4-1+deb10u1_source.buildinfo Files: d6162bc33447800c836024ee0a0ac70d 3524 devel optional snapd_2.37.4-1+deb10u1.dsc bbdc4399f884008c126e2089a25afb70 1885960 devel optional snapd_2.37.4.orig.tar.xz 47fbbf8088f9bd239bc59577bcc68cd3 69344 devel optional snapd_2.37.4-1+deb10u1.debian.tar.xz b4b17bfac4b03943b9b36b15f9990bb2 15036 devel optional snapd_2.37.4-1+deb10u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEE2mxnVNiIdibNBqEomMq7Or1MpZ4FAmIPWTEACgkQmMq7Or1M pZ4Peg/9F9fs6RidmeHfX7vy+fBdHMpbDcCHSnMC5hSadoK6Wr5GRBySSDFjTuMc nExX//6PEhuyXYplclhI7mjq45pTqcagiCyqACtS9d3Q/48oeVY0hV9CmsAvRYZm optGWbA72V+FMg3qwRYIM1aQaxfoW/rsBNwOwSjmVuXnHMyc+G0ynYfXKXOGswBd 6necUn0rcbEaLW7KZPzYdUB+Xz1vET21Padl4qW0HgcmKTp2uqtLOUhahGGGcWZO geMssHHcjIPrVHE4fPgxJPmg5LUrlrDgCEgTHlztpHPtZsBh4xxtfprrd1BTMDUf vq8Cg+oCA2WmzrdC/+kqUmd5I+jibyLFjE+q9JF6GbpFKm2+P+1DnXo31vqjqa9K nxjjChaeQc1m0nlwvfynrWIMj2MLg9FN0LWkStssy5syYaYf0g2OZPi5Si6UKvgr oEjdv9IbMnmsStVGhpS3Cu01mUH11zucZ+wDNILMPTbXajUyFK1T7fBzo21HNvWQ kBOgpxvcDarx+Cbq4uu5vIXNRDZci2FBajHYTO7rvI0gzhXXnkZe1tjAgGvzzGNg 810Zn+C9kI+ZwGEZ3h+W82+0CW+TgKh2Ur2b3/k1Gd9aoxAgR5Y+MoaVK/BRhdCl e6KHcq2rmg0yUZteXANiUYHLDaaZwNS8+TVrF6r9yMZBI1MCSug= =oWgi -----END PGP SIGNATURE-----