This repository has been archived by the owner on Sep 18, 2020. It is now read-only.
Releases: coreos/manifest
Releases · coreos/manifest
v2514.1.0
v2513.2.0
Announcements:
- CoreOS Container Linux has reached its end of life and is no longer maintained or updated. Migrate to another operating system as soon as possible!
Changes:
- Update EOL warning banners in login prompt and MOTD
v2512.3.0
Announcements:
- CoreOS Container Linux has reached its end of life and is no longer maintained or updated. Migrate to another operating system as soon as possible!
Changes:
- Update EOL warning banners in login prompt and MOTD
v2514.0.0
Announcements:
- CoreOS Container Linux will reach its end of life on May 26, 2020 and will no longer receive updates. We strongly recommend migrating to another operating system as soon as possible.
Changes:
- No changes since last alpha
v2513.1.0
Announcements:
- CoreOS Container Linux will reach its end of life on May 26, 2020 and will no longer receive updates. We strongly recommend migrating to another operating system as soon as possible.
Changes:
- No changes for beta promotion
v2512.2.0
Announcements:
- CoreOS Container Linux will reach its end of life on May 26, 2020 and will no longer receive updates. We strongly recommend migrating to another operating system as soon as possible.
Changes:
- No changes for stable promotion
v2513.0.0
Announcements:
- CoreOS Container Linux will reach its end of life on May 26, 2020 and will no longer receive updates. We strongly recommend migrating to another operating system as soon as possible.
Security fixes:
- Fix e2fsprogs arbitrary code execution via crafted filesystem (CVE-2019-5094)
- Fix Git arbitrary path overwrite, credential leak from credential helpers, remote code execution in recursive clones, and arbitrary command execution via submodules (CVE-2019-1348, CVE-2019-1387, CVE-2019-19604, CVE-2020-11008, CVE-2020-5260)
- Fix libarchive crash or use-after-free via crafted RAR file (CVE-2019-18408, CVE-2020-9308)
- Fix libgcrypt ECDSA timing attack (CVE-2019-13627)
- Fix libidn2 domain impersonation (CVE-2019-12290)
- Fix NSS crashes and heap corruption (CVE-2017-11695, CVE-2017-11696, CVE-2017-11697, CVE-2017-11698, CVE-2018-18508, CVE-2019-11745)
- Fix OpenSSL overflow in Montgomery squaring procedure (CVE-2019-1551)
- Fix SQLite crash and heap corruption (CVE-2019-16168, CVE-2019-5827)
- Fix unzip heap overflow or excessive resource consumption via crafted archive (CVE-2018-1000035, CVE-2019-13232)
- Fix vim arbitrary command execution via crafted file (CVE-2019-12735)
Bug fixes:
- Fix GCE agent crash loop in new installs when using non-Google DNS (#2601)
Changes:
- Fetch container images in docker format rather than ACI by default in
etcd-member.service
,flanneld.service
, andkubelet-wrapper
Updates:
v2512.1.0
Announcements:
- CoreOS Container Linux will reach its end of life on May 26, 2020 and will no longer receive updates. We strongly recommend migrating to another operating system as soon as possible.
Security fixes:
- Fix e2fsprogs arbitrary code execution via crafted filesystem (CVE-2019-5094)
- Fix Git arbitrary path overwrite, credential leak from credential helpers, remote code execution in recursive clones, and arbitrary command execution via submodules (CVE-2019-1348, CVE-2019-1387, CVE-2019-19604, CVE-2020-11008, CVE-2020-5260)
- Fix libarchive crash or use-after-free via crafted RAR file (CVE-2019-18408, CVE-2020-9308)
- Fix libgcrypt ECDSA timing attack (CVE-2019-13627)
- Fix libidn2 domain impersonation (CVE-2019-12290)
- Fix NSS crashes and heap corruption (CVE-2017-11695, CVE-2017-11696, CVE-2017-11697, CVE-2017-11698, CVE-2018-18508, CVE-2019-11745)
- Fix OpenSSL overflow in Montgomery squaring procedure (CVE-2019-1551)
- Fix SQLite crash and heap corruption (CVE-2019-16168, CVE-2019-5827)
- Fix unzip heap overflow or excessive resource consumption via crafted archive (CVE-2018-1000035, CVE-2019-13232)
- Fix vim arbitrary command execution via crafted file (CVE-2019-12735)
Bug fixes:
- Fix GCE agent crash loop in new installs when using non-Google DNS (#2601)
Changes:
- Fetch container images in docker format rather than ACI by default in
etcd-member.service
,flanneld.service
, andkubelet-wrapper
Updates: