Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

SUSE: 2021:3323-1 Low: Kubernetes 1.17.17 Backport Security Fix

suse
Calendar Grey October 8, 2021
Scroller Suse
SUSE Security Update includes a Kubernetes update to 1.17.17 addressing CVE-2021-25741 with a low severity rating.
An update that fixes one vulnerability is now available

Summary

== Kubernetes bsc#1189416 kubernetes issue is a backport of the upstream security fix (CVE-2021-25741): https://github.com/kubernetes/kubernetes/pull/104253 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE CaaS Platform 4.0 (noarch): release-notes-caasp-4.2.20210929-4.71.2 skuba-update-1.4.13-3.56.2 - SUSE CaaS Platform 4.0 (x86_64): caasp-release-4.2.6-24.43.2 kubernetes-client-1.17.17-4.25.2

References

#1189416

Cross- CVE-2021-25741

CVSS scores:

CVE-2021-25741 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE CaaS Platform 4.0

https://www.suse.com/security/cve/CVE-2021-25741.html

https://bugzilla.suse.com/1189416

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3323-1
Rating: low

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.