aws/aws-nitro-enclaves-cli

linuxkit should be bumped to version 1.3.0+ to resolve CVE-2024-23652 and CVE-2024-23653

Closed this issue · 0 comments

Hi Team,

we previously raised an issue to the linuxkit repo to upgrade moby/buildkit to resolve CVE-2024-23652 and CVE-2024-23653: linuxkit/linuxkit#4042

linuxkit have upgraded their version and released it in v1.3.0: https://github.com/linuxkit/linuxkit/releases/tag/v1.3.0

can we bump the version for linuxkit to v1.3.0 (and maybe the latest version v1.4.0) to patch the CVEs