mirror of
https://github.com/linuxkit/linuxkit.git
synced 2025-11-01 21:37:36 +00:00
As of the time of this patch, the CVE was not available yet in the mitre db. Signed-off-by: Tycho Andersen <tycho@docker.com>
821 B
821 B
LinuxKit Security Events
The incomplete list below is an assessment of some CVEs, and LinuxKit's resilience (or not) to them.
Bugs mitigated:
- CVE-2017-1000363:
This CVE requires
CONFIG_PRINTER=y, so we are not vulnerable. - CVE-2017-2636
(exploit post):
This CVE requires
CONFIG_N_HDLC={y|m}, which LinuxKit does not specify, and so is not vulnerable. - CVE-2016-10229
This CVE only applies to kernels
<= 4.5, <= 4.4.21. By using recent kernels (specifically, kernels=> 4.9, >= 4.4.21, LinuxKit mitigates this bug.