Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2021:3049-1 Important: Kubernetes Security Fix for 4.5

suse
Calendar Grey September 16, 2021
Scroller Suse
SUSE security update provides essential fixes for Kubernetes vulnerabilities, safeguarding the CaaS Platform 4.5.
An update that fixes two vulnerabilities is now available

Summary

== Kubernetes bsc#1189416 kubernetes issue is a backport of the upstream security fix (CVE-2021-25741): https://github.com/kubernetes/kubernetes/pull/104253 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 4.5: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 4.5 (aarch64 x86_64): caasp-release-4.5.5-1.19.3 kubernetes-1.18-kubeadm-1.18.20-4.11.3 kubernetes-1.18-kubelet-1.18.20-4.11.3 skuba-2.1.15-3.15.13.2 - SUSE CaaS Platform 4.5 (noarch):

References

#1182185 #1189416

Cross- CVE-2021-25741 CVE-2021-3121

CVSS scores:

CVE-2021-25741 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-3121 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CVE-2021-3121 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Affected Products:

SUSE CaaS Platform 4.5

https://www.suse.com/security/cve/CVE-2021-25741.html

https://www.suse.com/security/cve/CVE-2021-3121.html

https://bugzilla.suse.com/1182185

https://bugzilla.suse.com/1189416

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3049-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.