Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 2024:3754-1 Moderate: Fix for DoS Issue in Buildah Tooling

suse
Calendar Grey October 24, 2024
Dist Suse Esm H88
Patch release for buildah addressing the symlink traversal vulnerability classified with moderate seriousness, as outlined in the SUSE advisory notice.
* bsc#1231698 Cross-References: * CVE-2024-9676

Summary

## This update for buildah fixes the following issues: * CVE-2024-9676: Fixed symlink traversal vulnerability in the containers/storage library that could cause Denial of Service (DoS) (bsc#1231698) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-3754=1 openSUSE-SLE-15.5-2024-3754=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3754=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-3754=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2024-3754=1 ## Package List:

References

* bsc#1231698

Cross-

* CVE-2024-9676

CVSS scores:

* CVE-2024-9676 ( SUSE ): 5.7

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-9676 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-9676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Containers Module 15-SP5

* Containers Module 15-SP6

* openSUSE Leap 15.5

* openSUSE Leap 15.6

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise Real Time 15 SP5

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves one vulnerability can now be installed.

##

Announcement ID: SUSE-SU-2024:3754-1
Release Date: 2024-10-24T03:34:40Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here