Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 481
Alerts This Week
Warning Icon 1 481

SUSE: 2022:961-1 Important Security Update For Bci/Bci-Init Container

suse
Calendar Grey May 11, 2022
Scroller Suse
SUSE releases an update for the bci/bci-init container, implementing security patches that resolve significant vulnerabilities. Review the recent improvements.
The container bci/bci-init was updated

Summary

Advisory ID: SUSE-SU-2022:1617-1 Released: Tue May 10 14:40:12 2022 Summary: Security update for gzip Type: security Severity: important Advisory ID: SUSE-RU-2022:1626-1 Released: Tue May 10 15:55:13 2022 Summary: Recommended update for systemd Type: recommended Severity: moderate

References

References : 1198062 1198090 1198114 1198922 CVE-2022-1271

1198062,1198922,CVE-2022-1271

This update for gzip fixes the following issues:

- CVE-2022-1271: Fix escaping of malicious filenames. (bsc#1198062)

1198090,1198114

This update for systemd fixes the following issues:

- tmpfiles.d: only 'w+' can have multiple lines for the same path (bsc#1198090)

- journald: make sure journal_file_open() doesn't leave a corrupted file around after failing (bsc#1198114)

- tmpfiles: constify item_compatible() parameters- test tmpfiles: add a test for 'w+'

- test: add test checking tmpfiles conf file precedence

- journald: make use of CLAMP() in cache_space_refresh()

- journal-file: port journal_file_open() to openat_report_new()

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2022:961-1
Container Tags : bci/bci-init:15.3 , bci/bci-init:15.3.14.12 , bci/bci-init:latest
Container Release : 14.12
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.