c5e4f537fe
- Fixes a vulnerability in runc that allows a container escape (CVE-2019-5736) https://github.com/opencontainers/runc/commit/6635b4f0c6af3810594d2770f662f34ddc15b40d, - Includes security fix for `runc run --no-pivot` (`DOCKER_RAMDISK=1`): https://github.com/opencontainers/runc/commit/28a697cce3e4f905dca700eda81d681a30eef9cd (NOTE: the vuln is attackable only when `DOCKER_RAMDISK=1` is set && seccomp is disabled) Signed-off-by: Sebastiaan van Stijn <github@gone.nl> (cherry picked from commit f03698b69a7777b8d30b9c5897504f8704b87676) Signed-off-by: Sebastiaan van Stijn <github@gone.nl> Upstream-commit: c7fca75c035ba0b750f46a9676a376f8e4409f15 Component: engine