Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE 15.4/15.5 Security Advisory: Important Prometheus Update

opensuse
Calendar Grey February 27, 2024
Dist Opensuse Esm H88
Mitigating significant weaknesses in golang-github-prometheus-prometheus through a crucial security enhancement for openSUSE.
This update for golang-github-prometheus-prometheus fixes the following issues: golang-github-prometheus-prometheus:

Description

This update for golang-github-prometheus-prometheus fixes the following issues:

golang-github-prometheus-prometheus:

* Security issues fixed in this version update to 2.37.6:

* CVE-2022-46146: Fix basic authentication bypass vulnerability (bsc#1208049,

jsc#PED-3576)

* CVE-2022-41715: Update our regexp library to fix upstream (bsc#1204023)

* CVE-2022-41723: Fixed go issue to avoid quadratic complexity in HPACK

decoding (bsc#1208298)

* Other non-security bugs fixed and changes in this version update to 2.37.6:

* [BUGFIX] TSDB: Turn off isolation for Head compaction to fix a memory leak.

* [BUGFIX] TSDB: Fix 'invalid magic number 0' error on Prometheus startup.

* [BUGFIX] Agent: Fix validation of flag options and prevent WAL from growing

more than desired.

* [BUGFIX] Properly close file descriptor when logging unfinished queries.

* [BUGFIX] TSDB: In the WAL watcher metrics, expose the type="exemplar" label

instead of type="unknown" for exemplar records.

* [BUGFIX]...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-2598=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-2598=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-2598=1

* SUSE Manager Proxy 4.2 Module 4.2

zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.2-2023-2598=1

* SUSE Manager Proxy 4.3 Module 4.3

zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2023-2598=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* firewalld-prometheus-config-0.1-150100.4.17.1

* golang-github-prometheus-prometheus-2.37.6-150100.4.17.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* firewalld-prometheus-config-0.1-150100.4.17.1

* golang-github-prometheus-prometheus-2.37.6-150100.4.17.1

* SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64)

* golang-github-prometheus-prometheus-2.37.6-150100.4.17.1

* SUSE Manager Proxy 4.2 Module 4.2 (aarch64 ppc64le s390x x86_64)

* golang-github-prometheus-prometheus-2.37.6-150100.4.17.1

* SUSE Manager Proxy 4.3 Module 4.3 (aarch64 ppc64le s390x x86_64)

* golang-github-prometheus-prometheus-2.37.6-150100.4.17.1

References

* bsc#1204023

* bsc#1208049

* bsc#1208298

* jsc#MSQA-665

* jsc#PED-3576

## References:

* https://www.suse.com/security/cve/CVE-2022-41715.html

* https://www.suse.com/security/cve/CVE-2022-41723.html

* https://www.suse.com/security/cve/CVE-2022-46146.html

* https://bugzilla.suse.com/show_bug.cgi?id=1204023

* https://bugzilla.suse.com/show_bug.cgi?id=1208049

* https://bugzilla.suse.com/show_bug.cgi?id=1208298

*

*

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:2598-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here