nsenter: clone /proc/self/exe to avoid exposing host binary to container · opencontainers/runc@0a8e411 · GitHub
RT : Fix for CVE-2019-5736 (runc container breakout) is now pushed! Make sure you patch your stuff everyone!
Docker 1.11 et plus: Engine is now built on runC and containerd
Docker recently released new versions for their entire platform: Engine was bumped to 1.11, Swarm is now 1.2, and Compose and Machine are respectively 1.7 and 0.7. There is also an associated release…
