SUSE Container Update Advisory: suse/sles12sp4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:963-1
Container Tags        : suse/sles12sp4:26.584 , suse/sles12sp4:latest
Container Release     : 26.584
Severity              : important
Type                  : security
References            : 1191502 1195529 1197244 1198507 1204423 1204968 1205000 1206985
                        1208958 CVE-2022-3821 CVE-2022-4415 CVE-2023-26604 
-----------------------------------------------------------------

The container suse/sles12sp4 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:1776-1
Released:    Wed Apr  5 15:20:19 2023
Summary:     Security update for systemd
Type:        security
Severity:    important
References:  1191502,1195529,1197244,1198507,1204423,1204968,1205000,1206985,1208958,CVE-2022-3821,CVE-2022-4415,CVE-2023-26604
This update for systemd fixes the following issues:

- CVE-2023-26604: Fixed a privilege escalation via the less pager. (bsc#1208958)
- CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).
- CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).

Bug fixes:

- Restrict cpu rule to x86_64, and also update the rule files to make use of the 'CONST{arch}' syntax (bsc#1204423).
- Fixed 'systemd --user' call pam_loginuid when creating user@.service (bsc#1198507).
- Fixed 'systemd-detect-virt' refine hypervisor detection (bsc#1197244).
- Fixed 'udev' 60-persistent-storage-tape.rules: handle duplicate device ID (bsc#1195529).
- Fixed 'man' tweak description of auto/noauto (bsc#1191502).


The following package changes have been done:

- base-container-licenses-3.0-1.342 updated
- container-suseconnect-2.0.0-1.225 updated
- libsystemd0-228-150.108.2 updated
- libudev1-228-150.108.2 updated

SUSE: 2023:963-1 suse/sles12sp4 Security Update

April 6, 2023
The container suse/sles12sp4 was updated

Summary

Advisory ID: SUSE-SU-2023:1776-1 Released: Wed Apr 5 15:20:19 2023 Summary: Security update for systemd Type: security Severity: important

References

References : 1191502 1195529 1197244 1198507 1204423 1204968 1205000 1206985

1208958 CVE-2022-3821 CVE-2022-4415 CVE-2023-26604

1191502,1195529,1197244,1198507,1204423,1204968,1205000,1206985,1208958,CVE-2022-3821,CVE-2022-4415,CVE-2023-26604

This update for systemd fixes the following issues:

- CVE-2023-26604: Fixed a privilege escalation via the less pager. (bsc#1208958)

- CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).

- CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).

Bug fixes:

- Restrict cpu rule to x86_64, and also update the rule files to make use of the 'CONST{arch}' syntax (bsc#1204423).

- Fixed 'systemd --user' call pam_loginuid when creating user@.service (bsc#1198507).

- Fixed 'systemd-detect-virt' refine hypervisor detection (bsc#1197244).

- Fixed 'udev' 60-persistent-storage-tape.rules: handle duplicate device ID (bsc#1195529).

- Fixed 'man' tweak description of auto/noauto (bsc#1191502).

The following package changes have been done:

- base-container-licenses-3.0-1.342 updated

- container-suseconnect-2.0.0-1.225 updated

- libsystemd0-228-150.108.2 updated

- libudev1-228-150.108.2 updated

Severity
Container Advisory ID : SUSE-CU-2023:963-1
Container Tags : suse/sles12sp4:26.584 , suse/sles12sp4:latest
Container Release : 26.584
Severity : important
Type : security

Related News