Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE 2022:2744-1 Critical: Buildah and Curl Security Fix

suse
Calendar Grey October 28, 2022
Dist Suse Esm H88
SUSE Container Update Announcement for suse/sle15 featuring essential updates addressing security vulnerabilities along with enhancements to buildah and curl components.
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2022:3766-1 Released: Wed Oct 26 11:38:01 2022 Summary: Security update for buildah Type: security Severity: important Advisory ID: SUSE-SU-2022:3773-1 Released: Wed Oct 26 12:19:29 2022 Summary: Security update for curl Type: security Severity: important Advisory ID: SUSE-RU-2022:3776-1 Released: Wed Oct 26 14:06:43 2022 Summary: Recommended update for permissions Type: recommended

References

References : 1167864 1181961 1202812 1203911 1204137 1204383 1204397 1204690

CVE-2020-10696 CVE-2021-20206 CVE-2021-46848 CVE-2022-2990 CVE-2022-32221

1167864,1181961,1202812,CVE-2020-10696,CVE-2021-20206,CVE-2022-2990

This update for buildah fixes the following issues:

- CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961).

- CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).

- CVE-2022-2990: Fixed possible information disclosure and modification / bsc#1202812

Buildah was updated to version 1.27.1:

* run: add container gid to additional groups

- Add fix for CVE-2022-2990 / bsc#1202812

Update to version 1.27.0:

Severity
critical
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2744-1
Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.57 , suse/sle15:15.3 , suse/sle15:15.3.17.20.57
Container Release : 17.20.57
Severity : critical
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here