Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 15.0: 2018:3316-1 Moderate Singularity Access Control Fix

opensuse
Calendar Grey October 23, 2018
Dist Opensuse Esm H88
System patch for singularity addresses moderate vulnerabilities in openSUSE, recommending immediate update to enhance security.
An update that fixes one vulnerability is now available.

Description

Singularity was updated to version 2.6.0, bringing features, bugfixes and

security fixes.

Security issues fixed:

- CVE-2018-12021: Fixed access control on systems supporting overlay file

system (boo#1100333).

Highlights of 2.6.0:

- Allow admin to specify a non-standard location for mksquashfs binary at

build time with '--with-mksquashfs' option #1662

- '--nv' option will use

[nvidia-container-cli](https://github.com/NVIDIA/libnvidia-container) if

installed #1681

- [nvliblist.conf]

( onf) now has a section for binaries #1681

- '--nv' can be made default with all action commands in singularity.conf

#1681

- '--nv' can be controlled by env vars '$SINGULARITY_NV' and

'$SINGULARITY_NV_OFF' #1681

- Restore shim init process for proper signal handling and child reaping

when container is initiated in its own PID namespace #1221

- Add '-i' option to image.create to specify the inode ratio. #1759

- Bind...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1223=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2018-1223=1

Package List

- openSUSE Leap 15.0 (x86_64):

libsingularity1-2.6.0-lp150.2.3.1

libsingularity1-debuginfo-2.6.0-lp150.2.3.1

singularity-2.6.0-lp150.2.3.1

singularity-debuginfo-2.6.0-lp150.2.3.1

singularity-debugsource-2.6.0-lp150.2.3.1

singularity-devel-2.6.0-lp150.2.3.1

- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):

libsingularity1-2.6.0-bp150.3.3.1

singularity-2.6.0-bp150.3.3.1

singularity-devel-2.6.0-bp150.3.3.1

References

https://www.suse.com/security/cve/CVE-2018-12021.html

https://bugzilla.suse.com/1100333

--

Announcement ID: openSUSE-SU-2018:3316-1
Rating: moderate
Affected Products: openSUSE Leap 15.0 openSUSE Backports SLE-15

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here