Last week, Snyk, announced multiple CVEs affecting Docker, containerd, AWS EKS, Red Hat, Ubuntu, and hundreds of products shipping runc or buildkit. I'll explain what's going on and how I see the risk in these vulnerabilities, and maybe we'll go down memory lane with a history of container breakout bugs.
Runc
CVE-2024-21626
BuildKit
CVE-2024-23650
CVE-2024-23651
CVE-2024-23652
CVE-2024-23653
Moby
CVE-2024-2455
🗞️ Sign up for my weekly newsletter for the latest on upcoming guests and what I'm releasing: https://www.bretfisher.com/newsletter/
Topics
=====
Snyk "Leaky Vessels" CVE-2024-21626 https://snyk.io/blog/cve-2024-21626-r...
Docker Security Advisory https://www.docker.com/blog/docker-se...
NVD CVE https://nvd.nist.gov/vuln/detail/CVE-...
Runc https://github.com/opencontainers/run...
The Secure Developer Podcast episode deep dive https://www.devseccon.com/the-secure-...
Bret Fisher
=========
/ bretfisher
/ bretefisher
https://www.bretfisher.com
Join my Community 🤜🤛
================
💌 Weekly newsletter on upcoming guests and stuff I'm working on: https://www.bretfisher.com/newsletter/
💬 Join the discussion on our Discord chat server / discord
👨🏫 Coupons for my Docker and Kubernetes courses https://www.bretfisher.com/courses/
🎙️ Podcast of this show https://www.bretfisher.com/podcast
Show Music 🎵
==========
waiting music: Jakarta - Bonsaye https://www.epidemicsound.com/track/Y...
intro music: I Need A Remedy (Instrumental Version) - Of Men And Wolves https://www.epidemicsound.com/track/z...
outro music: Electric Ballroom - Quesa https://www.epidemicsound.com/track/K...
Смотрите видео Docker & Kubernetes container breakout security bug CVE-2024-21626 (Stream 253) онлайн, длительностью часов минут секунд в хорошем качестве, которое загружено на канал Bret Fisher Docker and DevOps 01 Январь 1970. Делитесь ссылкой на видео в социальных сетях, чтобы ваши подписчики и друзья так же посмотрели это видео. Данный видеоклип посмотрели 2,824 раз и оно понравилось 59 посетителям.