Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE-SU-2025-0217-1 Modest Update for CDI Containers on openSUSE Leap 15.6

opensuse
Calendar Grey January 22, 2025
Scroller Opensuse
Recent enhancements for the container-data-importer on openSUSE tackle moderate vulnerabilities and outline essential installation steps.
An update that contains one feature can now be installed.

Description

This update for cdi-apiserver-container, cdi-cloner-container, cdi-controller-

container, cdi-importer-container, cdi-operator-container, cdi-uploadproxy-

container, cdi-uploadserver-container, containerized-data-importer fixes the

following issues:

Update to version 1.61.0:

* Release notes

* https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.61.0

* https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.60.4

* https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.60.3

* https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.60.2

* Enable aarch64 build for SLE and mark it as techpreview (jsc#PED-10545)

* Install nbdkit-server to avoid pulling unneeded dependencies

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2025-217=1 openSUSE-SLE-15.6-2025-217=1

* Containers Module 15-SP6

zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2025-217=1

Package List

* openSUSE Leap 15.6 (aarch64 x86_64)

* containerized-data-importer-uploadproxy-1.61.0-150600.3.12.1

* containerized-data-importer-uploadproxy-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-uploadserver-1.61.0-150600.3.12.1

* containerized-data-importer-uploadserver-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-operator-1.61.0-150600.3.12.1

* containerized-data-importer-api-1.61.0-150600.3.12.1

* containerized-data-importer-operator-debuginfo-1.61.0-150600.3.12.1

* obs-service-cdi_containers_meta-1.61.0-150600.3.12.1

* containerized-data-importer-cloner-1.61.0-150600.3.12.1

* containerized-data-importer-importer-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-controller-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-controller-1.61.0-150600.3.12.1

* containerized-data-importer-cloner-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-api-debuginfo-1.61.0-150600.3.12.1

* containerized-data-importer-importer-1.61.0-150600.3.12.1

*...

Read the Full Advisory

References

* jsc#PED-10545

## References:

* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-10545&page_caps=&user_role=

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0217-1
Release Date: 2025-01-22T02:53:58Z
Affected Products: * Containers Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.