Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

openSUSE: 2020:1433-1 Moderate: docker-distribution Memory Allocation Issue

opensuse
Calendar Grey September 18, 2020
Dist Opensuse Esm H88
Patch issued to resolve a vulnerability in docker-distribution for openSUSE, improving resource allocation control.
An update that solves one vulnerability and has one errata is now available.

Description

This update for docker-distribution fixes the following issues:

- Enable build on %arm (which include armv6), not only on armv7

- Enable ppc64le

- Use correct URL to project

- Remove fillup, we don't ship a sysconfig file

- Correct systemd requires

- Enable build on ARM

- Upgraded to 2.7.1

- Support for OCI images added

- Fix upgrade issues from 2.6.x

- Update Go version to 1.11

- Switch to multi-stage Dockerfile

- Validations enabled by default with new disabled config option

- Optimize health check performance

- Create separate permission for deleting objects in a repo

- Fix storage driver error propagation for manifest GETs

- Fix forwarded header resolution

- Add prometheus metrics

- Disable schema1 manifest by default

- Graceful shutdown

- TLS: remove ciphers that do not support perfect forward secrecy

- Fix registry stripping newlines from manifests

- Add bugsnag logrus hook

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-1433=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

docker-distribution-registry-2.7.1-bp152.4.3.1

References

https://www.suse.com/security/cve/CVE-2017-11468.html

https://bugzilla.suse.com/1033172

https://bugzilla.suse.com/1049850

--

Announcement ID: openSUSE-SU-2020:1433-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here