We have released patches to our AMIs and other infrastructure to address CVE-2016-5195. We recommend all CircleCI Enterprise installations follow the instructions below to update both their Services box and their Builder fleet.
If you have any questions or difficulties please contact enterprise-support@circleci.com.
Update the Services box:
- As always, ensure your data is backed up.
- Shut down CircleCI in the Replicated console (or via the CLI).
- Update the kernel using the provided
install_kernel_master
function below. - Restart the machine.
#!/bin/bash
function install_kernel_master() {
echo '>>> Installing Kernel'
apt-get update
apt-get install linux-image-3.13.0-100-generic linux-headers-3.13.0-100-generic linux-image-extra-3.13.0-100-generic
apt-cache policy linux-image-3.13.0-100-generic linux-headers-3.13.0-100-generic linux-image-extra-3.13.0-100-generic
}
Update the Builder fleet:
For the builder fleet, update the Launch Configuration to use the updated AMI from the list below:
- ap-northeast-1 = “ami-59389e38”
- ap-northeast-2 = “ami-a2e236cc”
- ap-southeast-1 = “ami-a80fa9cb”
- ap-southeast-2 = “ami-53241930”
- eu-central-1 = “ami-5a59a035”
- eu-west-1 = “ami-e0c78993”
- sa-east-1 = “ami-3832af54”
- us-east-1 = “ami-d0396bc7”
- us-west-1 = “ami-76226916”
- us-west-2 = “ami-938420f3”
NOTE: The following AMIs are not maintained by CircleCI, but contain a patched version of stock ubuntu.
- gov-west-1 = “ami-34df6755”
- cn-north-1 = “ami-92f622ff”
If you are using our Terraform scripts, you can download the new script https://github.com/circleci/enterprise-setup/blob/master/circleci.tf and run terraform apply
. We’ve already updated the scripts to include the new AMIs, so terraform should launch new builders automatically with the patched version, and cycle your fleet.
If you are using a non-AWS environment, use the same method to patch your builders you used to patch the Services box.
If any of the above does not apply to your environment, or you encounter issues with your upgrades please contact: enterprise-support@circleci.com.