Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE: 2024:4205-1 moderate: docker-stable security update details

suse
Calendar Grey December 5, 2024
Dist Suse Esm H88
An important SUSE security notice. New updates for docker-stable released featuring essential patches and enhancements.
* bsc#1214855 * bsc#1221916 * bsc#1228324 * bsc#1230331 * bsc#1230333

Summary

## This update for docker-stable fixes the following issues: * Remove DOCKER_NETWORK_OPTS from docker.service. This was removed from sysconfig a long time ago, and apparently this causes issues with systemd in some cases. * Update --add-runtime to point to correct binary path. * Further merge docker and docker-stable specfiles to minimise the differences. The main thing is that we now include both halves of the Conflicts/Provides/Obsoletes dance in both specfiles. * Update to docker-buildx v0.17.1 to match standalone docker-buildx package we are replacing. See upstream changelog online at * Allow users to disable SUSE secrets support by setting DOCKER_SUSE_SECRETS_ENABLE=0 in /etc/sysconfig/docker. bsc#1231348

References

* bsc#1214855

* bsc#1221916

* bsc#1228324

* bsc#1230331

* bsc#1230333

* bsc#1231348

* jsc#PED-11185

* jsc#PED-8585

Cross-

* CVE-2024-41110

CVSS scores:

* CVE-2024-41110 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that solves one vulnerability, contains two features and has five

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-41110.html

* https://bugzilla.suse.com/show_bug.cgi?id=1214855

* https://bugzilla.suse.com/show_bug.cgi?id=1221916

Announcement ID: SUSE-SU-2024:4205-1
Release Date: 2024-12-05T14:58:05Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here