-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 May 2025 19:09:56 +0200 Source: containerd Architecture: source Version: 1.4.13~ds1-1~deb11u5 Distribution: bullseye-security Urgency: medium Maintainer: Debian Go Packaging Team <team+pkg-go@tracker.debian.org> Changed-By: Andreas Henriksson <andreas@fatal.se> Closes: 1100806 Changes: containerd (1.4.13~ds1-1~deb11u5) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS security team. * CVE-2024-40635: large UID:GID (>32bit) can overflow, runs as root (Closes: #1100806) Checksums-Sha1: cad080651d97753c343a7ffe77fa114ffa29af46 4477 containerd_1.4.13~ds1-1~deb11u5.dsc e432ebbd421db3d84c6990a8e4fe4f1396c2884a 1488960 containerd_1.4.13~ds1.orig.tar.xz 753332e091662cdc65243e3d81f85b132709fbee 32896 containerd_1.4.13~ds1-1~deb11u5.debian.tar.xz 81e6c521615cf15afce10d368a419f7dace71f26 6473 containerd_1.4.13~ds1-1~deb11u5_source.buildinfo Checksums-Sha256: 307093de0c37607d44b27fca25b654c1d85e2b9fa905c19d1418707fd7b4f725 4477 containerd_1.4.13~ds1-1~deb11u5.dsc 867588af3fa86d4a9ff4e2330dfa5db2df480a81e5f73a20d321b20f7c596a0f 1488960 containerd_1.4.13~ds1.orig.tar.xz a146961bc69dfe22e7bbf9a55beb0c7172a8eb72f7f94487433906091b95a6f2 32896 containerd_1.4.13~ds1-1~deb11u5.debian.tar.xz 46ec7f3ca1e40b7c362d04c06b8f47634aaca1530152fc34ff63ef0dc17822ef 6473 containerd_1.4.13~ds1-1~deb11u5_source.buildinfo Files: 531a651401548d8dd194d0324161ffcc 4477 admin optional containerd_1.4.13~ds1-1~deb11u5.dsc 3958d3c535cdde744769515c30e618ff 1488960 admin optional containerd_1.4.13~ds1.orig.tar.xz 01a80dc9ed56ef885f1cc71742fe166c 32896 admin optional containerd_1.4.13~ds1-1~deb11u5.debian.tar.xz 083f93a6ca1a9cc48d967afab88f681c 6473 admin optional containerd_1.4.13~ds1-1~deb11u5_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmgXoaMACgkQC8R9xk0T UwYhHw/+LRYwZIWaXbEpnanNL07j8Hw1elN8r2jVD2Tjvhn00pqfGyt8BuDzKf/p 1FGm09rktPdil+gcaG70Cm1d7D1ZlrVRkVg2eKM7eVCeYh3eyOR0MEC02ggofdVf AjljVLxoweiNtMPHwlSXIOUNq6BibwCP8+Jkx7aAcYgPJ8KQY1GLGhSl0g7s9JgI ndElh/rGkRSFU7MwpqEOjK9giu1de9JFx8Wvm4zCXp7xqUTiaz/D4Maua4Jmscwc dxbNO5D5xZ3uU+HY7ct9mc5CqGgS5q1BOOKwusxYbKXeAMgb+vIXRkbRMlvDeqG4 ESjMDxvWcFu14607fJXKYlqJ6BqKdFtUR9QMnn0OE9Kf3fG/ZSaWgAyiSoxV3msJ LJ+L3JVWYqpkyAG4LKV1wbo9/8X1VRFrmYcLTFV9g72Yhq0zvP6xFbXhJniUSU5n rFMUMJ0RsEqExHFLVmCJBY8AbZKfKoQOJJbsrqKeoCEJH+Yu+JAIa/wUTEVatJQB 6GXjHMLYP705UyqfA069UY/Q9Krmb43Mc39wnfO/Wf4uxt654bnDT7VU3tXnSqYr rp0FpSPPh8FwarrYUiTjUdNczdCkphFwAT6Vb21JWt6FOgCnEBssI6BYjgFf/kIB lIBYaDOoGos1h0nGcvD/9G2qhehdaN2a1q+Zkwtw4kxXwXwIXrY= =dR/o -----END PGP SIGNATURE-----