Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE: 2019:2289-1 Critical: Singularity Security Patch

opensuse
Calendar Grey October 7, 2019
Dist Opensuse Esm H88
openSUSE Security Patch addresses a vulnerability in singularity as noted in Announcement ID openSUSE-SU-2019:2288-1.
An update that solves one vulnerability and has one errata is now available.

Description

This update for singularity fixes the following issues:

singularity was updated to version 3.4.1:

This point release addresses the following issues:

- Fixes an issue where a PID namespace was always being used

- Fixes compilation on non 64-bit architectures

- Allows fakeroot builds for zypper, pacstrap, and debootstrap

- Correctly detects seccomp on OpenSUSE

- Honors GO_MODFLAGS properly in the mconfig generated makefile

- Passes the Mac hostname to the VM in MacOS Singularity builds

- Handles temporary EAGAIN failures when setting up loop devices on recent

kernels.

New version 3.4.0. Many changes since 3.2.1, for the full changelog please

read CHANGELOG.md

Update to version 3.2.1:

This point release fixes the following bugs:

- Allows users to join instances with non-suid workflow

- Removes false warning when seccomp is disabled on the host

- Fixes an issue in the terminal when piping output to commands

- Binds NVIDIA...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP1:

zypper in -t patch openSUSE-2019-2288=1

- openSUSE Backports SLE-15:

zypper in -t patch openSUSE-2019-2288=1

Package List

- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):

singularity-3.4.1-bp151.3.3.1

singularity-debuginfo-3.4.1-bp151.3.3.1

- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):

singularity-3.4.1-bp150.2.10.1

References

https://www.suse.com/security/cve/CVE-2019-11328.html

https://bugzilla.suse.com/1125369

https://bugzilla.suse.com/1128598

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2288-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP1 openSUSE Backports SLE-15 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here