container 1.3.1

1.3.1
Added 1
  • Add container skill
Fixed 1
  • Fix tmpfs mount source field left empty for --mount type=tmpfs
Security 6
  • Fix unchecked id that could allow creating a container or executing a container process to delete files outside its bundle
  • Fix ContainerizationOCI accepting unvalidated OCI descriptor digests that could enable path traversal in the local content store
  • Fix loading an OCI image layout that could read host files through a symlink
  • Fix RegistryClient following the WWW-Authenticate realm without validating its host or scheme
  • Fix unpacking a crafted image layer with a long invalid file name that could crash the unpacking process
  • Fix unpacking a crafted image layer with an invalid length extended-attribute name that could crash the unpacking process

From container

This patch release addresses a number of security issues in the Containerization package:

  • GHSA-x7pf-2jmj-pgcq - Creating a container or executing a container process can delete files outside its bundle through an unchecked id
  • GHSA-f689-h8m7-3jp2 - ContainerizationOCI accepts unvalidated OCI descriptor digests, enabling path traversal in the local content store
  • GHSA-r3h2-rgqf-9hv9 - Loading an OCI image layout can read host files through a symlink
  • GHSA-mx96-5vvg-x2mg - CVE-2026-65388 - RegistryClient follows the WWW-Authenticate realm without validating its host or scheme
  • GHSA-697p-8837-37h3 - Unpacking a crafted image layer with a long(invalid) file name crashes the unpacking process
  • GHSA-g3rx-2m58-rr63 - Unpacking a crafted image layer with an invalid length extended-attribute name crashes the unpacking process
What's Changed
New Contributors

Full Changelog: https://github.com/apple/container/compare/1.3.0...1.3.1

View original

Upgraded? How did it go?

Discussion