Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 15.4: 2023:0018-1 Moderate: Apptainer Digital Signature Fix

opensuse
Calendar Grey January 15, 2023
Dist Opensuse Esm H88
openSUSE has issued a security patch for apptainer addressing three vulnerabilities, one of which relates to an issue with digital signatures.
An update that fixes three vulnerabilities is now available

Description

This update for apptainer fixes the following issues:

Updated to 1.1.2 which fixed CVE-2022-39237

* CVE-2022-39237: The sif dependency included in Apptainer before this

release does not verify that the hash algorithm(s) used are

cryptographically secure when verifying digital signatures. This

release updates to sif v2.8.1 which corrects this issue. See the

linked advisory for references and a workaround.

Updated to version 1.1.0

* added squashfuse-0.1.105.tar.gz and 70.patch for the build of

squashfuse_ll which will be removed as soon as the multithread patch

is incoperated

* Change squash mounts to prefer to use squashfuse_ll instead of

squashfuse, if available, for improved performance. squashfuse_ll is

not available in factory.

* Also, for even better parallel performance, include a patched

multithreaded version of squashfuse_ll in

* Imply adding ${prefix}/libexec/apptainer/bin to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.4:

zypper in -t patch openSUSE-2023-18=1

Package List

- openSUSE Leap 15.4 (aarch64 i586 s390x x86_64):

apptainer-1.1.2-lp154.2.1

apptainer-debuginfo-1.1.2-lp154.2.1

References

https://www.suse.com/security/cve/CVE-2021-44716.html

https://www.suse.com/security/cve/CVE-2021-44717.html

https://www.suse.com/security/cve/CVE-2022-39237.html

Announcement ID: openSUSE-SU-2023:0018-1
Rating: moderate
Affected Products: openSUSE Leap 15.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here