* bsc#1214612 * bsc#1231208 * bsc#1231499 Cross-References: . # Security update for podman Announcement ID: SUSE-SU-2024:3741-1 Release Date: 2024-10-21T12:33:47Z Rating: moderate References: * bsc#1214612 * bsc#1231208 * bsc#1231499 Cross-References: * CVE-2024-9407 * CVE-2024-9675 CVSS scores: * CVE-2024-9407 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-9407 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2024-9407 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N * CVE-2024-9675 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-9675 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2024-9675 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * Containers Module 15-SP5 * Containers Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for podman fixes the following issues: * CVE-2024-9675: Fixed cache arbitrary directory mount (bsc#1231499). * CVE-2024-9407: Fixed improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction (bsc#1231208). The following non-security bug was fixed: * rootless ipv6 containers can't be started (bsc#1214612). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listedfor your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3741=1 SUSE-2024-3741=1 * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-3741=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3741=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-3741=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-3741=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2024-3741=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * podmansh-4.9.5-150500.3.25.1 * podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * openSUSE Leap 15.5 (noarch) * podman-docker-4.9.5-150500.3.25.1 * openSUSE Leap Micro 5.5 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.25.1 * podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * openSUSE Leap Micro 5.5 (noarch) * podman-docker-4.9.5-150500.3.25.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.25.1 * podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * openSUSE Leap 15.6 (noarch) * podman-docker-4.9.5-150500.3.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.25.1 * podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * podman-docker-4.9.5-150500.3.25.1 * Containers Module 15-SP5 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.25.1 *podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * Containers Module 15-SP5 (noarch) * podman-docker-4.9.5-150500.3.25.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.25.1 * podman-debuginfo-4.9.5-150500.3.25.1 * podman-4.9.5-150500.3.25.1 * podman-remote-4.9.5-150500.3.25.1 * podman-remote-debuginfo-4.9.5-150500.3.25.1 * Containers Module 15-SP6 (noarch) * podman-docker-4.9.5-150500.3.25.1 ## References: * https://www.suse.com/security/cve/CVE-2024-9407.html * https://www.suse.com/security/cve/CVE-2024-9675.html * https://bugzilla.suse.com/show_bug.cgi?id=1214612 * https://bugzilla.suse.com/show_bug.cgi?id=1231208 * https://bugzilla.suse.com/show_bug.cgi?id=1231499 . Podman has released a crucial update enhancing security by addressing input validation flaws and directory mount vulnerabilities, urging users to upgrade promptly for better protection. podman update, SUSE security advisory, container security, moderate threat, software patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.