Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:2145-1 Critical: SUSE Manager Server 4.1 Update

suse
Calendar Grey June 21, 2022
Dist Suse Esm H88
The latest patch resolves several key vulnerabilities in SUSE Manager Server 4.1, significantly improving its security and overall reliability.
An update that solves 5 vulnerabilities, contains two features and has 33 fixes is now available

Summary

This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: - Adapted to build on Enterprise Linux. - Fix build for RedHat 7 - Require Go >= 1.14 also for CentOS - Add support for CentOS - Replace %{?systemd_requires} with %{?systemd_ordering} golang-github-lusitaniae-apache_exporter: - Require building with Go 1.15 - Add %license macro for LICENSE file golang-github-prometheus-node_exporter: - CVE-2022-21698: Update vendor tarball with prometheus/client_golang 1.11.1 (bsc#1196338, jsc#SLE-24238, jsc#SLE-24239) - Update to 1.3.0 * [CHANGE] Add path label to rapl collector #2146 * [CHANGE] Exclude filesystems under /run/credentials #2157 * [CHANGE] Add TCPTimeouts to netstat default filter #2189 * [FEATURE] Add lnstat collector for metrics from /proc/net/stat/ #1771

References

#1173527 #1182742 #1189501 #1190535 #1191143

#1192850 #1193032 #1193238 #1193707 #1194262

#1194447 #1194594 #1194909 #1195561 #1196067

#1196338 #1196407 #1196702 #1196704 #1197356

#1197429 #1197438 #1197488 #1198221 #1198356

#1198686 #1198914 #1199036 #1199142 #1199149

#1199512 #1199528 #1199577 #1199629 #1199677

#1199888 #1200212 #1200606 SLE-24238 SLE-24239

Cross- CVE-2022-21698 CVE-2022-21724 CVE-2022-21952

CVE-2022-26520 CVE-2022-31248

CVSS scores:

CVE-2022-21698 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-21698 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-21724 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-21724 (SUSE): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2145-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here