First published: Fri Jan 22 2021(Updated: )
A flaw was found in libcni. A user may be able to change the "type:" field in a CNI configuration to an arbitrary path and could execute arbitrary binaries on a host. Upstream patch: <a href="https://github.com/containernetworking/cni/pull/808">https://github.com/containernetworking/cni/pull/808</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Container Network Interface | <0.8.1 | |
go/github.com/containernetworking/cni | <0.8.1 | 0.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)