SUSE Container Update Advisory: bci/minimal
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2021:572-1
Container Tags        : bci/minimal:15.3 , bci/minimal:15.3.13.53 , bci/minimal:latest
Container Release     : 13.53
Severity              : important
Type                  : security
References            : 1172973 1172974 1187153 1187273 1188623 1190793 1190850 1192160
                        CVE-2019-20838 CVE-2020-14155 CVE-2021-39537 
-----------------------------------------------------------------

The container bci/minimal was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:3490-1
Released:    Wed Oct 20 16:31:55 2021
Summary:     Security update for ncurses
Type:        security
Severity:    moderate
References:  1190793,CVE-2021-39537
This update for ncurses fixes the following issues:

- CVE-2021-39537: Fixed an heap-based buffer overflow in _nc_captoinfo. (bsc#1190793)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:3529-1
Released:    Wed Oct 27 09:23:32 2021
Summary:     Security update for pcre
Type:        security
Severity:    moderate
References:  1172973,1172974,CVE-2019-20838,CVE-2020-14155
This update for pcre fixes the following issues:

Update pcre to version 8.45:

- CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974).
- CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:3564-1
Released:    Wed Oct 27 16:12:08 2021
Summary:     Recommended update for rpm-config-SUSE
Type:        recommended
Severity:    moderate
References:  1190850
This update for rpm-config-SUSE fixes the following issues:

- Support ZSTD compressed kernel modules. (bsc#1190850)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:3786-1
Released:    Wed Nov 24 05:59:13 2021
Summary:     Recommended update for rpm-config-SUSE
Type:        recommended
Severity:    important
References:  1192160
This update for rpm-config-SUSE fixes the following issues:

- Add support for the kernel xz-compressed firmware files (bsc#1192160)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:3799-1
Released:    Wed Nov 24 18:07:54 2021
Summary:     Recommended update for gcc11
Type:        recommended
Severity:    moderate
References:  1187153,1187273,1188623
This update for gcc11 fixes the following issues:

The additional GNU compiler collection GCC 11 is provided:

To select these compilers install the packages:

- gcc11
- gcc-c++11
- and others with 11 prefix.

to select them for building:

- CC='gcc-11'
- CXX='g++-11'

The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


The following package changes have been done:

- libgcc_s1-11.2.1+git610-1.3.9 updated
- libncurses6-6.1-5.9.1 updated
- libpcre1-8.45-20.10.1 updated
- libstdc++6-11.2.1+git610-1.3.9 updated
- rpm-config-SUSE-1-5.6.1 updated
- terminfo-base-6.1-5.9.1 updated
- container:micro-image-15.3.0-3.27 updated
- ca-certificates-mozilla-prebuilt-2.44-21.1 removed

SUSE: 2021:572-1 bci/minimal Security Update

December 7, 2021
The container bci/minimal was updated

Summary

Advisory ID: SUSE-SU-2021:3490-1 Released: Wed Oct 20 16:31:55 2021 Summary: Security update for ncurses Type: security Severity: moderate Advisory ID: SUSE-SU-2021:3529-1 Released: Wed Oct 27 09:23:32 2021 Summary: Security update for pcre Type: security Severity: moderate Advisory ID: SUSE-RU-2021:3564-1 Released: Wed Oct 27 16:12:08 2021 Summary: Recommended update for rpm-config-SUSE Type: recommended Severity: moderate Advisory ID: SUSE-RU-2021:3786-1 Released: Wed Nov 24 05:59:13 2021 Summary: Recommended update for rpm-config-SUSE Type: recommended Severity: important Advisory ID: SUSE-RU-2021:3799-1 Released: Wed Nov 24 18:07:54 2021 Summary: Recommended update for gcc11 Type: recommended Severity: moderate

References

References : 1172973 1172974 1187153 1187273 1188623 1190793 1190850 1192160

CVE-2019-20838 CVE-2020-14155 CVE-2021-39537

1190793,CVE-2021-39537

This update for ncurses fixes the following issues:

- CVE-2021-39537: Fixed an heap-based buffer overflow in _nc_captoinfo. (bsc#1190793)

1172973,1172974,CVE-2019-20838,CVE-2020-14155

This update for pcre fixes the following issues:

Update pcre to version 8.45:

- CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974).

- CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973)

1190850

This update for rpm-config-SUSE fixes the following issues:

- Support ZSTD compressed kernel modules. (bsc#1190850)

1192160

This update for rpm-config-SUSE fixes the following issues:

- Add support for the kernel xz-compressed firmware files (bsc#1192160)

1187153,1187273,1188623

This update for gcc11 fixes the following issues:

The additional GNU compiler collection GCC 11 is provided:

To select these compilers install the packages:

- gcc11

- gcc-c++11

- and others with 11 prefix.

to select them for building:

- CC='gcc-11'

- CXX='g++-11'

The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.

The following package changes have been done:

- libgcc_s1-11.2.1+git610-1.3.9 updated

- libncurses6-6.1-5.9.1 updated

- libpcre1-8.45-20.10.1 updated

- libstdc++6-11.2.1+git610-1.3.9 updated

- rpm-config-SUSE-1-5.6.1 updated

- terminfo-base-6.1-5.9.1 updated

- container:micro-image-15.3.0-3.27 updated

- ca-certificates-mozilla-prebuilt-2.44-21.1 removed

Severity
Container Advisory ID : SUSE-CU-2021:572-1
Container Tags : bci/minimal:15.3 , bci/minimal:15.3.13.53 , bci/minimal:latest
Container Release : 13.53
Severity : important
Type : security

Related News