Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:2457-2 Important: bci/golang Use After Free Security Fix

suse
Calendar Grey October 2, 2022
Dist Suse Esm H88
The bci/golang container has been issued a crucial security patch that resolves a significant use-after-free vulnerability. More information is available within.
The container bci/golang was updated

Summary

Advisory ID: SUSE-SU-2022:3489-1 Released: Sat Oct 1 13:35:24 2022 Summary: Security update for expat Type: security Severity: important

References

References : 1203438 CVE-2022-40674

1203438,CVE-2022-40674

This update for expat fixes the following issues:

- CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438).

The following package changes have been done:

- libexpat1-2.4.4-150400.3.9.1 updated

- aaa_base-84.87+git20180409.04c9dae-3.57.1 removed

- bash-4.4-150400.25.22 removed

- bash-sh-4.4-150400.25.22 removed

- coreutils-8.32-150400.7.5 removed

- cpio-2.13-150400.1.98 removed

- cracklib-2.9.7-11.6.1 removed

- cracklib-dict-small-2.9.7-11.6.1 removed

- diffutils-3.6-4.3.1 removed

- file-magic-5.32-7.14.1 removed

- filesystem-15.0-11.8.1 removed

- fillup-1.42-2.18 removed

- findutils-4.8.0-1.20 removed

- glibc-2.31-150300.41.1 removed

- grep-3.1-150000.4.6.1 removed

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2436-1
Container Tags : bci/golang:1.18 , bci/golang:1.18-16.43
Container Release : 16.43
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here