This update for libnvidia-container fixes the following issues:
Update to version 1.18.0.
Security issues fixed:
* CVE-2024-0132: time-of-check time-of-use (TOCTOU) race condition in default
configuration via specifically crafted container image (bsc#1231033).
* CVE-2024-0133: data tampering in host file system via specially crafted
container image (bsc#1231032).
Other updates and bugfixes:
* updated to 1.18.0
* Add clock_gettime to allowed syscalls
* Fix pointer accessing local variable out of scope
* Require version match between libnvidia-container-tools and libnvidia-
container1
* Add libnvidia-gpucomp.so to the list of compute libs
* Use VERSION_ prefix for version parts in makefiles
* Add additional logging
* Do not discard container flags when --cuda-compat-mode is not specified
* Remove unneeded --no-cntlibs argument from list command
* Add cuda-compat-mode flag to configure command
* Skip files when user has insufficient...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2026-558=1
* Containers Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-558=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-558=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-558=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-558=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-558=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-558=1
* SUSE Linux Enterprise Server 15 SP5...
Read the Full Advisory* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
* libnvidia-container1-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container-devel-1.18.0-150200.5.9.1
* libnvidia-container-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container1-1.18.0-150200.5.9.1
* libnvidia-container-debugsource-1.18.0-150200.5.9.1
* libnvidia-container-tools-1.18.0-150200.5.9.1
* libnvidia-container-tools-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container-static-1.18.0-150200.5.9.1
* Containers Module 15-SP7 (aarch64 ppc64le x86_64)
* libnvidia-container1-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container-devel-1.18.0-150200.5.9.1
* libnvidia-container-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container1-1.18.0-150200.5.9.1
* libnvidia-container-debugsource-1.18.0-150200.5.9.1
* libnvidia-container-tools-1.18.0-150200.5.9.1
* libnvidia-container-tools-debuginfo-1.18.0-150200.5.9.1
* libnvidia-container-static-1.18.0-150200.5.9.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
*...
Read the Full Advisory* bsc#1231032
* bsc#1231033
## References:
* https://www.suse.com/security/cve/CVE-2024-0132.html
* https://www.suse.com/security/cve/CVE-2024-0133.html
* https://bugzilla.suse.com/show_bug.cgi?id=1231032
* https://bugzilla.suse.com/show_bug.cgi?id=1231033
Get the latest Linux and open source security news straight to your inbox.