Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 482
Alerts This Week
Warning Icon 1 482

SUSE Security Update 2020:3939-1 Critical for Podman Vulnerability Fixes

suse
Calendar Grey December 28, 2020
Scroller Suse
Crucial SUSE patch resolves vulnerabilities in container services and improves capabilities for Docker and libnetwork.
An update that solves one vulnerability, contains one feature and has four fixes is now available

Summary

This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues: Security issues fixed: - CVE-2020-15257: Fixed a privilege escalation in containerd (bsc#1178969). Non-security issues fixed: - Update to containerd v1.3.9, which is needed for Docker v19.03.14-ce and fixes CVE-2020-15257. bsc#1180243 - Update to containerd v1.3.7, which is required for Docker 19.03.13-ce. bsc#1176708 - Update to Docker 19.03.14-ce. See upstream changelog in the packaged /usr/share/doc/packages/docker/CHANGELOG.md. CVE-2020-15257 bsc#1180243 https://github.com/docker-archive/docker-ce/releases/tag/v19.03.14 - Enable fish-completion - Add a patch which makes Docker compatible with firewalld with nftables

References

#1174075 #1176708 #1178801 #1178969 #1180243

SLE-16460

Cross- CVE-2020-15257

Affected Products:

SUSE Linux Enterprise Module for Containers 12

https://www.suse.com/security/cve/CVE-2020-15257.html

https://bugzilla.suse.com/1174075

https://bugzilla.suse.com/1176708

https://bugzilla.suse.com/1178801

https://bugzilla.suse.com/1178969

https://bugzilla.suse.com/1180243

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3938-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.