Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2021:293-1 Critical: Cpio Remote Code Execution Risk

suse
Calendar Grey August 26, 2021
Dist Suse Esm H88
Stay informed about essential updates for SUSE/SLE15 that address critical vulnerabilities, especially those enabling remote code execution threats
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2021:2689-1 Released: Mon Aug 16 10:54:52 2021 Summary: Security update for cpio Type: security Severity: important Advisory ID: SUSE-RU-2021:2763-1 Released: Tue Aug 17 17:16:22 2021 Summary: Recommended update for cpio Type: recommended Severity: critical Advisory ID: SUSE-RU-2021:2780-1 Released: Thu Aug 19 16:09:15 2021 Summary: Recommended update for cpio Type: recommended

References

References : 1188571 1189206 1189465 1189465 CVE-2021-36222 CVE-2021-38185

CVE-2021-38185

1189206,CVE-2021-38185

This update for cpio fixes the following issues:

It was possible to trigger Remote code execution due to a integer overflow (CVE-2021-38185, bsc#1189206)

1189465

This update for cpio fixes the following issues:

- A regression in last update would cause builds to hang on various architectures(bsc#1189465)

1189465,CVE-2021-38185

This update for cpio fixes the following issues:

- A regression in the previous update could lead to crashes (bsc#1189465)

1188571,CVE-2021-36222

This update for krb5 fixes the following issues:

- CVE-2021-36222: Fixed KDC null deref on bad encrypted challenge. (bsc#1188571)

Severity
critical
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2021:293-1
Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.8
Container Release : 9.5.8
Severity : critical
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here