This update for build fixes the following issues: \- CVE-2024-22038: Fixed DoS
attacks, information leaks with crafted Git repositories (bnc#1230469)
Other fixes: \- Fixed behaviour when using "\--shell" aka "osc shell" option in
a VM build. Startup is faster and permissions stay intact now.
* fixes for POSIX compatibility for obs-docker-support adn mkbaselibs
* Add support for apk in docker/podman builds
* Add support for 'wget' in Docker images
* Fix debian support for Dockerfile builds
* Fix preinstallimages in containers
* mkosi: add back system-packages used by build-recipe directly
* pbuild: parse the Release files for debian repos
* mkosi: drop most systemd/build-packages deps and use obs_scm directory as
source if present
* improve source copy handling
* Introduce --repos-directory and --containers-directory options
* productcompose: support of building against a baseiso
* preinstallimage: avoid inclusion of build script generated files
*...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-857=1
* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2025-857=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-857=1
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-857=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-857=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-857=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-857=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15...
Read the Full Advisory* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-20250306-150200.19.1
* SUSE Enterprise Storage 7.1 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-20250306-150200.19.1
* openSUSE Leap 15.6 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-initvm-x86_64-20250306-150200.19.1
* build-initvm-aarch64-20250306-150200.19.1
* build-initvm-s390x-20250306-150200.19.1
* build-mkdrpms-20250306-150200.19.1
* build-initvm-powerpc64le-20250306-150200.19.1
* build-20250306-150200.19.1
* Development Tools Module 15-SP6 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-20250306-150200.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-20250306-150200.19.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* build-mkbaselibs-20250306-150200.19.1
* build-20250306-150200.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4...
Read the Full Advisory* bsc#1217269
* bsc#1230469
## References:
* https://www.suse.com/security/cve/CVE-2024-22038.html
* https://bugzilla.suse.com/show_bug.cgi?id=1217269
* https://bugzilla.suse.com/show_bug.cgi?id=1230469
Get the latest Linux and open source security news straight to your inbox.