Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE MicroOS 5.1: SUSE-SU-2021:4171-1 Moderate: runc Security Update

suse
Calendar Grey December 23, 2021
Dist Suse Esm H88
New update released for runc addressing a significant vulnerability affecting SUSE MicroOS containers and associated platforms.
An update that fixes one vulnerability is now available

Summary

This update for runc fixes the following issues: Update to runc v1.0.3. * CVE-2021-43784: Fixed a potential vulnerability related to the internal usage of netlink, which is believed to not be exploitable with any released versions of runc (bsc#1193436) * Fixed inability to start a container with read-write bind mount of a read-only fuse host mount. * Fixed inability to start when read-only /dev in set in spec. * Fixed not removing sub-cgroups upon container delete, when rootless cgroup v2 is used with older systemd. * Fixed returning error from GetStats when hugetlb is unsupported (which causes excessive logging for kubernetes). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1193436

Cross- CVE-2021-43784

CVSS scores:

CVE-2021-43784 (NVD) : 6 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Affected Products:

SUSE MicroOS 5.1

SUSE MicroOS 5.0

SUSE Linux Enterprise Module for Containers 15-SP3

SUSE Linux Enterprise Module for Containers 15-SP2

SUSE Enterprise Storage 7

https://www.suse.com/security/cve/CVE-2021-43784.html

https://bugzilla.suse.com/1193436

Announcement ID: SUSE-SU-2021:4171-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here