Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE Linux 15-SP1: 2020:0440-1 Moderate: Python-Azure-Agent Data Leak

suse
Calendar Grey February 24, 2020
Dist Suse Esm H88
SUSE Security Patch for python-azure-agent resolves a significant vulnerability concerning the management of swapfile that could lead to unauthorized data exposure.
An update that fixes one vulnerability is now available

Summary

This update for python-azure-agent fixes the following issues: python-azure-agent was updated to version 2.2.45 (jsc#ECO-80) + Add support for Gen2 VM resource disks + Use alternate systemd detection + Fix /proc/net/route requirement that causes errors on FreeBSD + Add cloud-init auto-detect to prevent multiple provisioning mechanisms from relying on configuration for coordination + Disable cgroups when daemon is setup incorrectly + Remove upgrade extension loop for the same goal state + Add container id for extension telemetry events + Be more exact when detecting IMDS service health + Changing add_event to start sending missing fields From 2.2.44 update: + Remove outdated extension ZIP packages + Improved error handling when starting extensions using systemd + Reduce provisioning time of some custom images

References

#1127838

Cross- CVE-2019-0804

Affected Products:

SUSE Linux Enterprise Module for Public Cloud 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

https://www.suse.com/security/cve/CVE-2019-0804.html

https://bugzilla.suse.com/1127838

Announcement ID: SUSE-SU-2020:0440-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here