SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:225-1
Container Tags        : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.97 , suse/sle15:15.3 , suse/sle15:15.3.17.20.97
Container Release     : 17.20.97
Severity              : moderate
Type                  : security
References            : 1183533 1194038 1205646 1206412 1206738 CVE-2021-28153 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:157-1
Released:    Thu Jan 26 15:54:43 2023
Summary:     Recommended update for util-linux
Type:        recommended
Severity:    moderate
References:  1194038,1205646
This update for util-linux fixes the following issues:

- libuuid continuous clock handling for time based UUIDs:
  Prevent use of the new libuuid ABI by uuidd %post before update
  of libuuid1 (bsc#1205646).
- Use chown --quiet to prevent error message if /var/lib/libuuid/clock.txt
  does not exist.
- Fix tests not passing when '@' character is in build path: 
  Fixes rpmbuild %checks fail when @ in the directory path (bsc#1194038).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:174-1
Released:    Thu Jan 26 20:52:38 2023
Summary:     Security update for glib2
Type:        security
Severity:    low
References:  1183533,CVE-2021-28153
This update for glib2 fixes the following issues:

- CVE-2021-28153: Fixed an issue where symlink targets would be incorrectly created as empty files (bsc#1183533).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:176-1
Released:    Thu Jan 26 20:56:20 2023
Summary:     Recommended update for permissions
Type:        recommended
Severity:    moderate
References:  1206738
This update for permissions fixes the following issues:

Update to version 20181225:

* Backport postfix permissions to SLE 15 SP2 (bsc#1206738)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:181-1
Released:    Thu Jan 26 21:55:43 2023
Summary:     Recommended update for procps
Type:        recommended
Severity:    low
References:  1206412
This update for procps fixes the following issues:

- Improve memory handling/usage (bsc#1206412) 
- Make sure that correct library version is installed (bsc#1206412)


The following package changes have been done:

- libblkid1-2.36.2-150300.4.32.1 updated
- libfdisk1-2.36.2-150300.4.32.1 updated
- libglib-2_0-0-2.62.6-150200.3.10.1 updated
- libmount1-2.36.2-150300.4.32.1 updated
- libprocps7-3.3.15-150000.7.28.1 updated
- libsmartcols1-2.36.2-150300.4.32.1 updated
- libuuid1-2.36.2-150300.4.32.1 updated
- permissions-20181225-150200.23.23.1 updated
- procps-3.3.15-150000.7.28.1 updated
- util-linux-2.36.2-150300.4.32.1 updated

SUSE: 2023:225-1 suse/sle15 Security Update

January 28, 2023
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-RU-2023:157-1 Released: Thu Jan 26 15:54:43 2023 Summary: Recommended update for util-linux Type: recommended Severity: moderate Advisory ID: SUSE-SU-2023:174-1 Released: Thu Jan 26 20:52:38 2023 Summary: Security update for glib2 Type: security Severity: low Advisory ID: SUSE-RU-2023:176-1 Released: Thu Jan 26 20:56:20 2023 Summary: Recommended update for permissions Type: recommended Severity: moderate Advisory ID: SUSE-RU-2023:181-1 Released: Thu Jan 26 21:55:43 2023 Summary: Recommended update for procps Type: recommended Severity: low

References

References : 1183533 1194038 1205646 1206412 1206738 CVE-2021-28153

1194038,1205646

This update for util-linux fixes the following issues:

- libuuid continuous clock handling for time based UUIDs:

Prevent use of the new libuuid ABI by uuidd %post before update

of libuuid1 (bsc#1205646).

- Use chown --quiet to prevent error message if /var/lib/libuuid/clock.txt

does not exist.

- Fix tests not passing when '@' character is in build path:

Fixes rpmbuild %checks fail when @ in the directory path (bsc#1194038).

1183533,CVE-2021-28153

This update for glib2 fixes the following issues:

- CVE-2021-28153: Fixed an issue where symlink targets would be incorrectly created as empty files (bsc#1183533).

1206738

This update for permissions fixes the following issues:

Update to version 20181225:

* Backport postfix permissions to SLE 15 SP2 (bsc#1206738)

1206412

This update for procps fixes the following issues:

- Improve memory handling/usage (bsc#1206412)

- Make sure that correct library version is installed (bsc#1206412)

The following package changes have been done:

- libblkid1-2.36.2-150300.4.32.1 updated

- libfdisk1-2.36.2-150300.4.32.1 updated

- libglib-2_0-0-2.62.6-150200.3.10.1 updated

- libmount1-2.36.2-150300.4.32.1 updated

- libprocps7-3.3.15-150000.7.28.1 updated

- libsmartcols1-2.36.2-150300.4.32.1 updated

- libuuid1-2.36.2-150300.4.32.1 updated

- permissions-20181225-150200.23.23.1 updated

- procps-3.3.15-150000.7.28.1 updated

- util-linux-2.36.2-150300.4.32.1 updated

Severity
Container Advisory ID : SUSE-CU-2023:225-1
Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.97 , suse/sle15:15.3 , suse/sle15:15.3.17.20.97
Container Release : 17.20.97
Severity : moderate
Type : security

Related News