Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE 12 SP5: 2024:4319-1 important: docker security fixes

suse
Calendar Grey December 16, 2024
Dist Suse Esm H88
A significant security patch for docker was issued on December 13, 2024, tackling critical vulnerabilities and implementing enhancements in SUSE.
* bsc#1217070 * bsc#1228324 * bsc#1228553 * bsc#1229806 * bsc#1230294

Summary

## This update for docker fixes the following issues: * Update docker-buildx to v0.19.2. See upstream changelog online at . Some notable changelogs from the last update: * * * Add a new toggle file /etc/docker/suse-secrets-enable which allows users to disable the SUSEConnect integration with Docker (which creates special mounts in /run/secrets to allow container-suseconnect to authenticate containers with registries on registered hosts). bsc#1231348 bsc#1232999 In order to disable these mounts, just do echo 0 > /etc/docker/suse-secrets-enable and restart Docker. In order to re-enable them, just do

References

* bsc#1217070

* bsc#1228324

* bsc#1228553

* bsc#1229806

* bsc#1230294

* bsc#1230331

* bsc#1230333

* bsc#1231348

* bsc#1232999

* bsc#1233819

Cross-

* CVE-2023-45142

* CVE-2023-47108

* CVE-2024-41110

CVSS scores:

* CVE-2023-45142 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-45142 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-47108 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-47108 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-41110 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:4319-1
Release Date: 2024-12-13T20:16:51Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here