This update for apptainer fixes the following issues:
Updated to 1.1.2 which fixed CVE-2022-39237
* CVE-2022-39237: The sif dependency included in Apptainer before this
release does not verify that the hash algorithm(s) used are
cryptographically secure when verifying digital signatures. This
release updates to sif v2.8.1 which corrects this issue. See the
linked advisory for references and a workaround.
Updated to version 1.1.0
* added squashfuse-0.1.105.tar.gz and 70.patch for the build of
squashfuse_ll which will be removed as soon as the multithread patch
is incoperated
* Change squash mounts to prefer to use squashfuse_ll instead of
squashfuse, if available, for improved performance. squashfuse_ll is
not available in factory.
* Also, for even better parallel performance, include a patched
multithreaded version of squashfuse_ll in
* Imply adding ${prefix}/libexec/apptainer/bin to...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-2023-18=1
- openSUSE Leap 15.4 (aarch64 i586 s390x x86_64):
apptainer-1.1.2-lp154.2.1
apptainer-debuginfo-1.1.2-lp154.2.1
https://www.suse.com/security/cve/CVE-2021-44716.html
https://www.suse.com/security/cve/CVE-2021-44717.html
https://www.suse.com/security/cve/CVE-2022-39237.html
Get the latest Linux and open source security news straight to your inbox.