Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE: 2024:0194-2 Moderate Keybase-Client Advisory for Threat Fix

opensuse
Calendar Grey August 23, 2024
Dist Opensuse Esm H88
This notification covers a critical vulnerability in the keybase-client referenced by advisory ID openSUSE-SU-2024:0194-2.
An update that fixes one vulnerability is now available

Description

This update for keybase-client fixes the following issues:

Update to version 6.2.8

* Update client CA

* Fix incomplete locking in config file handling.

- Update the Image dependency to address CVE-2023-29408 / boo#1213928.

This is done via the new update-image-tiff.patch.

- Limit parallel test execution as that seems to cause failing builds on

OBS that don't occur locally.

- Integrate KBFS packages previously build via own source package

* Upstream integrated these into the same source.

* Also includes adding kbfs-related patches

ensure-mount-dir-exists.patch and

ensure-service-stop-unmounts-filesystem.patch.

- Upgrade Go version used for compilation to 1.19.

- Use Systemd unit file from upstream source.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2024-194=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

kbfs-6.2.8-bp156.2.3.1

kbfs-debuginfo-6.2.8-bp156.2.3.1

kbfs-git-6.2.8-bp156.2.3.1

kbfs-git-debuginfo-6.2.8-bp156.2.3.1

kbfs-tool-6.2.8-bp156.2.3.1

kbfs-tool-debuginfo-6.2.8-bp156.2.3.1

keybase-client-6.2.8-bp156.2.3.1

keybase-client-debuginfo-6.2.8-bp156.2.3.1

References

https://www.suse.com/security/cve/CVE-2023-29408.html

https://bugzilla.suse.com/1213928

Announcement ID: openSUSE-SU-2024:0194-2
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here