docker-library / docker

Docker Official Image packaging for Docker
Apache License 2.0
1.14k stars 582 forks source link

Patches for 23.0.x #445

Closed haroonc closed 9 months ago

haroonc commented 1 year ago

It appears that the current build for 23.0.6 was done with go 1.19.9. There are a number of CVE fixes in 1.19.10 (e.g. CVE-2023-29404. CVE-2023-29405, CVE-2023-29402).

Are there any plans to publish and other version for 23.0.x to address these issues?

yosifkit commented 1 year ago

Although I can't speak for the moby/moby project and Docker team that publishes the docker binaries that we use from https://download.docker.com/linux/static, I don't see how these vulnerabilities apply since they all only matter when building a go project and do not really apply to running go-built binaries.

tianon commented 9 months ago

(Closing as 23.x is no longer supported here.)