Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2023:4727-1 critical: CORS bypass fix in catatonit and containerd

suse
Calendar Grey December 14, 2023
Dist Suse Esm H88
Address critical security issues in SUSE Linux regarding catatonit, containerd, and runc. Prioritize prompt updates to maintain system integrity.
* bsc#1200528 Cross-References: * CVE-2022-1996

Summary

## This update of runc and containerd fixes the following issues: containerd: * Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8 * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528) catatonit: * Update to catatonit v0.2.0. * Change license to GPL-2.0-or-later. * Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done). * Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors). runc: * Update to runc v1.1.10. Upstream changelog is available from

References

* bsc#1200528

Cross-

* CVE-2022-1996

CVSS scores:

* CVE-2022-1996 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2022-1996 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

* CVE-2022-1996 ( NVD ): 9.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected Products:

* Containers Module 15-SP4

* Containers Module 15-SP5

* openSUSE Leap 15.4

* openSUSE Leap 15.5

* openSUSE Leap Micro 5.3

* openSUSE Leap Micro 5.4

* SUSE CaaS Platform 4.0

* SUSE Enterprise Storage 7.1

* SUSE Linux Enterprise High Performance Computing 15 SP1

* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1

* SUSE Linux Enterprise High Performance Computing 15 SP2

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

* SUSE Linux Enterprise High Performance Computing 15 SP3

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4727-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here