This update for firejail fixes the following issues:
firejail was updated to version 0.9.70:
-CVE-2022-31214: - root escalation in --join logic (boo#1199148) Reported
by Matthias Gerstner, working exploit code was provided to our
development team. In the same time frame, the problem was independently
reported by Birk Blechschmidt. Full working exploit code was also
provided.
- feature: enable shell tab completion with --tab (#4936)
- feature: disable user profiles at compile time (#4990)
- feature: Allow resolution of .local names with avahi-daemon in the
apparmor
- profile (#5088)
- feature: always log seccomp errors (#5110)
- feature: firecfg --guide, guided user configuration (#5111)
- feature: --oom, kernel OutOfMemory-killer (#5122)
- modif: --ids feature needs to be enabled at compile time (#5155)
- modif: --nettrace only available to root user
- rework: whitelist restructuring (#4985)
- rework: firemon, speed up...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2022-10015=1
- openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64):
firejail-0.9.70-bp153.2.6.1
https://www.suse.com/security/cve/CVE-2022-31214.html
https://bugzilla.suse.com/1199148
Get the latest Linux and open source security news straight to your inbox.