Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE Leap 15.3: 2022:0770-1 Moderate Threat Buildah Update

opensuse
Calendar Grey March 9, 2022
Dist Opensuse Esm H88
An update has been issued for openSUSE, targeting three identified issues within buildah, classified under moderate severity. Installation guidelines are provided for users.
An update that fixes three vulnerabilities, contains one feature is now available

Description

This update for buildah fixes the following issues:

buildah was updated to version 1.23.1:

Update to version 1.22.3:

* Update dependencies

* Post-branch commit

* Accept repositories on login/logout

Update to version 1.22.0:

* c/image, c/storage, c/common vendor before Podman 3.3 release

* Proposed patch for 3399 (shadowutils)

* Fix handling of --restore shadow-utils

* runtime-flag (debug) test: handle old & new runc

* Allow dst and destination for target in secret mounts

* Multi-arch: Always push updated version-tagged img

* imagebuildah.stageExecutor.prepare(): remove pseudonym check

* refine dangling filter

* Chown with environment variables not set should fail

* Just restore protections of shadow-utils

* Remove specific kernel version number requirement from install.md

* Multi-arch image workflow: Make steps generic

* chroot: fix environment value leakage to intermediate processes

* Update nix pin with `make...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-770=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

buildah-1.23.1-150300.8.3.1

References

https://www.suse.com/security/cve/CVE-2019-10214.html

https://www.suse.com/security/cve/CVE-2020-10696.html

https://www.suse.com/security/cve/CVE-2021-20206.html

https://bugzilla.suse.com/1187812

https://bugzilla.suse.com/1192999

Announcement ID: openSUSE-SU-2022:0770-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here