SUSE Container Update Advisory: bci/nodejs
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2022:1605-1
Container Tags        : bci/node:16 , bci/node:16-8.19 , bci/node:latest , bci/nodejs:16 , bci/nodejs:16-8.19 , bci/nodejs:latest
Container Release     : 8.19
Severity              : important
Type                  : security
References            : 1193282 1200855 1201325 1201326 1201327 1201328 1201560 1201640
                        CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215 
-----------------------------------------------------------------

The container bci/nodejs was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:2491-1
Released:    Thu Jul 21 14:34:35 2022
Summary:     Security update for nodejs16
Type:        security
Severity:    important
References:  1201325,1201326,1201327,1201328,CVE-2022-32212,CVE-2022-32213,CVE-2022-32214,CVE-2022-32215
This update for nodejs16 fixes the following issues:

- CVE-2022-32212: Fixed DNS rebinding in --inspect via invalid IP addresses (bsc#1201328).
- CVE-2022-32213: Fixed HTTP request smuggling due to flawed parsing of Transfer-Encoding (bsc#1201325).
- CVE-2022-32214: Fixed HTTP request smuggling due to improper delimiting of header fields (bsc#1201326).
- CVE-2022-32215: Fixed HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (bsc#1201327).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:2493-1
Released:    Thu Jul 21 14:35:08 2022
Summary:     Recommended update for rpm-config-SUSE
Type:        recommended
Severity:    moderate
References:  1193282
This update for rpm-config-SUSE fixes the following issues:

- Add SBAT values macros for other packages (bsc#1193282)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:2494-1
Released:    Thu Jul 21 15:16:42 2022
Summary:     Recommended update for glibc
Type:        recommended
Severity:    important
References:  1200855,1201560,1201640
This update for glibc fixes the following issues:

- Remove tunables from static tls surplus patch which caused crashes (bsc#1200855)
- i386: Disable check_consistency for GCC 5 and above (bsc#1201640, BZ #25788)


The following package changes have been done:

- glibc-2.31-150300.37.1 updated
- rpm-config-SUSE-1-150400.14.3.1 updated
- nodejs16-16.16.0-150400.3.3.2 updated
- npm16-16.16.0-150400.3.3.2 updated
- container:sles15-image-15.0.0-27.11.4 updated

SUSE: 2022:1605-1 bci/nodejs Security Update

July 22, 2022
The container bci/nodejs was updated

Summary

Advisory ID: SUSE-SU-2022:2491-1 Released: Thu Jul 21 14:34:35 2022 Summary: Security update for nodejs16 Type: security Severity: important Advisory ID: SUSE-RU-2022:2493-1 Released: Thu Jul 21 14:35:08 2022 Summary: Recommended update for rpm-config-SUSE Type: recommended Severity: moderate Advisory ID: SUSE-RU-2022:2494-1 Released: Thu Jul 21 15:16:42 2022 Summary: Recommended update for glibc Type: recommended Severity: important

References

References : 1193282 1200855 1201325 1201326 1201327 1201328 1201560 1201640

CVE-2022-32212 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215

1201325,1201326,1201327,1201328,CVE-2022-32212,CVE-2022-32213,CVE-2022-32214,CVE-2022-32215

This update for nodejs16 fixes the following issues:

- CVE-2022-32212: Fixed DNS rebinding in --inspect via invalid IP addresses (bsc#1201328).

- CVE-2022-32213: Fixed HTTP request smuggling due to flawed parsing of Transfer-Encoding (bsc#1201325).

- CVE-2022-32214: Fixed HTTP request smuggling due to improper delimiting of header fields (bsc#1201326).

- CVE-2022-32215: Fixed HTTP request smuggling due to incorrect parsing of multi-line Transfer-Encoding (bsc#1201327).

1193282

This update for rpm-config-SUSE fixes the following issues:

- Add SBAT values macros for other packages (bsc#1193282)

1200855,1201560,1201640

This update for glibc fixes the following issues:

- Remove tunables from static tls surplus patch which caused crashes (bsc#1200855)

- i386: Disable check_consistency for GCC 5 and above (bsc#1201640, BZ #25788)

The following package changes have been done:

- glibc-2.31-150300.37.1 updated

- rpm-config-SUSE-1-150400.14.3.1 updated

- nodejs16-16.16.0-150400.3.3.2 updated

- npm16-16.16.0-150400.3.3.2 updated

- container:sles15-image-15.0.0-27.11.4 updated

Severity
Container Advisory ID : SUSE-CU-2022:1605-1
Container Tags : bci/node:16 , bci/node:16-8.19 , bci/node:latest , bci/nodejs:16 , bci/nodejs:16-8.19 , bci/nodejs:latest
Container Release : 8.19
Severity : important
Type : security

Related News