Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

SUSE: 2024:3151-1 Important: Buildah Security Fixes for Containers

suse
Calendar Grey September 6, 2024
Dist Suse Esm H88
Key security enhancement for buildah tackles various problems with significant resolutions on SUSE platforms.
* bsc#1221243 * bsc#1221677 * bsc#1224117 Cross-References:

Summary

## This update for buildah fixes the following issues: Update to version 1.35.4: * Bump to Buildah v1.35.4 * CVE-2024-3727 updates (bsc#1224117) * integration test: handle new labels in "bud and test --unsetlabel" * Bump go-jose CVE-2024-28180 * Bump ocicrypt and go-jose CVE-2024-28180 Update to version 1.35.3: * correctly configure /etc/hosts and resolv.conf * buildah: refactor resolv/hosts setup. * CVE-2024-24786 protobuf to 1.33 Update to version 1.35.1: * CVE-2024-1753 container escape fix (bsc#1221677) * Buildah dropped cni support, require netavark instead (bsc#1221243) * Remove obsolete requires libcontainers-image & libcontainers-storage * Require passt for rootless networking (poo#156955) Buildah moved to passt/pasta for rootless networking from slirp4netns

References

* bsc#1221243

* bsc#1221677

* bsc#1224117

Cross-

* CVE-2024-1753

* CVE-2024-24786

* CVE-2024-28180

* CVE-2024-3727

CVSS scores:

* CVE-2024-1753 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

* CVE-2024-24786 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-3727 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products:

* Containers Module 15-SP5

* Containers Module 15-SP6

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise Real Time 15 SP5

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3151-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here