Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE CaaS Platform 3.0: 2018:2704-1 Moderate: Podman Privileges Issue

suse
Calendar Grey September 13, 2018
Dist Suse Esm H88
It's crucial to confirm that your SUSE CaaS Platform 3.0 is fortified with the most recent podman upgrade, which resolves the privilege escalation vulnerabilities.
An update that fixes one vulnerability is now available

Summary

This update for podman to version 0.8.5 fixes the following issues: This security issue was fixed: - CVE-2018-10856: podman did not drop capabilities when executing a container as a non-root user. This resulted in unnecessary privileges being granted to the container (bsc#1097970). For additional non-security changes please refer to the changelog. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 3.0 (x86_64):

References

#1097970

Cross- CVE-2018-10856

Affected Products:

SUSE CaaS Platform 3.0

https://www.suse.com/security/cve/CVE-2018-10856.html

https://bugzilla.suse.com/1097970

Announcement ID: SUSE-SU-2018:2704-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here