linuxkit should be bumped to version 1.3.0+ to resolve CVE-2024-23652 and CVE-2024-23653
Closed this issue · 0 comments
zepeng811 commented
Hi Team,
we previously raised an issue to the linuxkit repo to upgrade moby/buildkit to resolve CVE-2024-23652 and CVE-2024-23653: linuxkit/linuxkit#4042
linuxkit have upgraded their version and released it in v1.3.0
: https://github.com/linuxkit/linuxkit/releases/tag/v1.3.0
can we bump the version for linuxkit to v1.3.0
(and maybe the latest version v1.4.0
) to patch the CVEs