This update for cockpit fixes the following issues:
- new version 320:
* pam-ssh-add: Fix insecure killing of session ssh-agent (boo#1226040,
CVE-2024-6126)
- changes in older versions:
* Storage: Btrfs snapshots
* Podman: Add image pull action
* Files: Bookmark support
* webserver: System user changes
* Metrics: Grafana setup now prefers Valkey
- Invalid json against the storaged manifest boo#1227299
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2024-206=1
- openSUSE Backports SLE-15-SP6 (aarch64 ppc64le s390x x86_64):
cockpit-320-bp156.2.6.3
cockpit-bridge-320-bp156.2.6.3
cockpit-devel-320-bp156.2.6.3
cockpit-pcp-320-bp156.2.6.3
cockpit-ws-320-bp156.2.6.3
- openSUSE Backports SLE-15-SP6 (noarch):
cockpit-doc-320-bp156.2.6.3
cockpit-kdump-320-bp156.2.6.3
cockpit-networkmanager-320-bp156.2.6.3
cockpit-packagekit-320-bp156.2.6.3
cockpit-selinux-320-bp156.2.6.3
cockpit-storaged-320-bp156.2.6.3
cockpit-system-320-bp156.2.6.3
https://www.suse.com/security/cve/CVE-2024-6126.html
https://bugzilla.suse.com/1226040
https://bugzilla.suse.com/1227299
Get the latest Linux and open source security news straight to your inbox.