Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE CaaS Platform 4.0: SUSE-SU-2020:3760-1 Moderate: Security Fixes

suse
Calendar Grey December 11, 2020
Dist Suse Esm H88
SUSE unveils a vital security patch aimed at resolving vulnerabilities in Kubernetes, etcd, and Helm, providing solutions for various concerns.
An update that fixes 8 vulnerabilities is now available

Summary

= Required Actions == Kubernetes & etcd (Security fixes) This fix involves an upgrade of Kubernetes and some add-ons. See ates.html#_updating_kubernetes_components for the upgrade procedure. == Skuba & helm/helm3 In order to update skuba and helm or helm 3, you need to update the management workstation. See detailed instructions at ates.html#_update_management_workstation = Known Issues Modifying the file `/etc/sysconfig/kubelet` directly is not supported: documentation at us.html#_configuring_kubelet Be sure to check the Release Notes at https://www.suse.com/releasenotes/x86_64/SUSE-CAASP/4/index.html for any additional known issues or behavioral changes. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1174219 #1174951 #1176752 #1176753 #1176754

#1176755 #1177661 #1177662

Cross- CVE-2020-15106 CVE-2020-15112 CVE-2020-15184

CVE-2020-15185 CVE-2020-15186 CVE-2020-15187

CVE-2020-8565 CVE-2020-8566

Affected Products:

SUSE Linux Enterprise Module for Containers 15-SP1

SUSE CaaS Platform 4.0

https://www.suse.com/security/cve/CVE-2020-15106.html

https://www.suse.com/security/cve/CVE-2020-15112.html

https://www.suse.com/security/cve/CVE-2020-15184.html

https://www.suse.com/security/cve/CVE-2020-15185.html

https://www.suse.com/security/cve/CVE-2020-15186.html

https://www.suse.com/security/cve/CVE-2020-15187.html

https://www.suse.com/security/cve/CVE-2020-8565.html

https://www.suse.com/security/cve/CVE-2020-8566.html

Announcement ID: SUSE-SU-2020:3760-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here