Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2022:2800-1 Critical: Bci/Bci-Init Container Security Update

suse
Calendar Grey November 2, 2022
Dist Suse Esm H88
Essential security enhancement for bci/bci-init image addressing various exploits and introducing necessary updates.
The container bci/bci-init was updated

Summary

Advisory ID: SUSE-SU-2022:3683-1 Released: Fri Oct 21 11:48:39 2022 Summary: Security update for libksba Type: security Severity: critical Advisory ID: SUSE-SU-2022:3766-1 Released: Wed Oct 26 11:38:01 2022 Summary: Security update for buildah Type: security Severity: important Advisory ID: SUSE-SU-2022:3773-1 Released: Wed Oct 26 12:19:29 2022 Summary: Security update for curl Type: security

References

References : 1087072 1167864 1181961 1202812 1203911 1204111 1204112 1204113

1204137 1204357 1204383 CVE-2020-10696 CVE-2021-20206 CVE-2022-2990

CVE-2022-32221 CVE-2022-3515 CVE-2022-42010 CVE-2022-42011 CVE-2022-42012

1204357,CVE-2022-3515

This update for libksba fixes the following issues:

- CVE-2022-3515: Fixed a possible overflow in the TLV parser (bsc#1204357).

1167864,1181961,1202812,CVE-2020-10696,CVE-2021-20206,CVE-2022-2990

This update for buildah fixes the following issues:

- CVE-2021-20206: Fixed an issue in libcni that could allow an attacker to execute arbitrary binaries on the host (bsc#1181961).

- CVE-2020-10696: Fixed an issue that could lead to files being overwritten during the image building process (bsc#1167864).

Severity
critical
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:2800-1
Container Tags : bci/bci-init:15.3 , bci/bci-init:15.3.21.22
Container Release : 21.22
Severity : critical
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here