The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4192-1 Container Tags : bci/dotnet-aspnet:6.0 , bci/dotnet-aspnet:6.0-18.24 , bci/dotnet-aspnet:6.0.25 , bci/dotnet-aspnet:6.0.25-18.24 Container Release : 18.24 Severity : moderate Type : security References : 1201384 1218014 CVE-2023-50495 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4891-1 Released: Mon Dec 18 16:31:49 2023 Summary: Security update for ncurses Type: security Severity: moderate References: 1201384,1218014,CVE-2023-50495 This update for ncurses fixes the following issues: - CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014) - Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384) The following package changes have been done: - libncurses6-6.1-150000.5.20.1 updated - terminfo-base-6.1-150000.5.20.1 updated - ncurses-utils-6.1-150000.5.20.1 updated - container:sles15-image-15.0.0-36.5.67 updated . SUSE Container Update Alert: bci/node has been upgraded to resolve security exploits and terminal interface concerns.. Container Updates, Security Patches, bci/dotnet-aspnet. . LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3756-1 Container Tags : bci/python:3 , bci/python:3-14.27 , bci/python:3.6 , bci/python:3.6-14.27 Container Release : 14.27 Severity : important Type : security References : 1206480 1206684 1209998 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216664 CVE-2023-4039 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4450-1 Released: Wed Nov 15 10:55:20 2023 Summary: Recommended update for crypto-policies Type: recommended Severity: moderate References: 1209998 This update for crypto-policies fixes the following issues: - Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands (jsc#PED-5041) - Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby and add a note for transactional systems - Ship the man pages for fips-mode-setup and fips-finish-install - Make the supported versions change in the update-crypto-policies(8) man page persistent (bsc#1209998) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure externaltimezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - crypto-policies-20210917.c9d86d1-150400.3.6.1 updated - container:sles15-image-15.0.0-36.5.54 updated . SUSE Container Update for bci/node introduces critical updates that rectify vulnerabilities and ensure system reliability.. SUSE Container, Python Update, Security Patch. . Severity: Important. LinuxSecurity.com Team
The container bci/bci-micro was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3620-1 Container Tags : bci/bci-micro:15.5 , bci/bci-micro:15.5.12.3 , bci/bci-micro:latest Container Release : 12.3 Severity : important Type : security References : 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 CVE-2023-4039 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4162-1 Released: Mon Oct 23 15:33:03 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Turn cross compiler tos390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.3.3 updated -libstdc++6-13.2.1+git7813-150000.1.3.3 updated . SUSE Container security announcement regarding bci/bci-micro, featuring critical vulnerabilities addressed through significant gcc upgrades and relevant patches.. SUSE Container Update,bci/bci-micro,gcc update,security patches,important advisory. . Severity: Important. LinuxSecurity.com Team
The container bci/bci-micro was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3510-1 Container Tags : bci/bci-micro:15.5 , bci/bci-micro:15.5.12.2 , bci/bci-micro:latest Container Release : 12.2 Severity : important Type : security References : 1215286 1215891 CVE-2023-4813 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4110-1 Released: Wed Oct 18 12:35:26 2023 Summary: Security update for glibc Type: security Severity: important References: 1215286,1215891,CVE-2023-4813 This update for glibc fixes the following issues: Security issue fixed: - CVE-2023-4813: Fixed a potential use-after-free in gaih_inet() (bsc#1215286, BZ #28931) Also a regression from a previous update was fixed: - elf: Align argument of __munmap to page size (bsc#1215891, BZ #28676) The following package changes have been done: - glibc-2.31-150300.63.1 updated . Keep updated on the latest security patches for bci/bci-micro and glibc that tackle significant vulnerabilities. Discover more details within.. Container Security Update, bci/bci-micro, glibc Update. . Severity: Important. LinuxSecurity.com Team
The container bci/dotnet-runtime was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3372-1 Container Tags : bci/dotnet-runtime:7.0 , bci/dotnet-runtime:7.0-16.9 , bci/dotnet-runtime:7.0.11 , bci/dotnet-runtime:7.0.11-16.9 , bci/dotnet-runtime:latest Container Release : 16.9 Severity : important Type : security References : 1215888 1215889 CVE-2023-38545 CVE-2023-38546 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4044-1 Released: Wed Oct 11 09:01:14 2023 Summary: Security update for curl Type: security Severity: important References: 1215888,1215889,CVE-2023-38545,CVE-2023-38546 This update for curl fixes the following issues: - CVE-2023-38545: Fixed a heap buffer overflow in SOCKS5. (bsc#1215888) - CVE-2023-38546: Fixed a cookie injection with none file. (bsc#1215889) The following package changes have been done: - libcurl4-8.0.1-150400.5.32.1 updated . Notice for bci/dotnet-runtime image: this release addresses critical security flaws related to curl, ensuring enhanced protection.. bci/dotnet-runtime,security update,curl issues. . Severity: Important. LinuxSecurity.com Team
The container bci/bci-busybox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-busybox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3155-1 Container Tags : bci/bci-busybox:15.5 , bci/bci-busybox:15.5.11.6 , bci/bci-busybox:latest Container Release : 11.6 Severity : important Type : security References : 1211829 1212819 1212910 1214538 CVE-2022-48174 ----------------------------------------------------------------- The container bci/bci-busybox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3814-1 Released: Wed Sep 27 18:08:17 2023 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1211829,1212819,1212910 This update for glibc fixes the following issues: - nscd: Fix netlink cache invalidation if epoll is used (bsc#1212910, BZ #29415) - Restore lookup of IPv4 mapped addresses in files database (bsc#1212819, BZ #25457) - elf: Remove excessive p_align check on PT_LOAD segments (bsc#1211829, BZ #28688) - elf: Properly align PT_LOAD segments (bsc#1211829, BZ #28676) - ld.so: Always use MAP_COPY to map the first segment (BZ #30452) - add GB18030-2022 charmap (jsc#PED-4908, BZ #30243) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3820-1 Released: Wed Sep 27 18:37:54 2023 Summary: Security update for busybox Type: security Severity: important References: 1214538,CVE-2022-48174 This update for busybox fixes the following issues: - CVE-2022-48174: Fixed stack overflow vulnerability. (bsc#1214538) The following package changes have been done: - busybox-adduser-1.35.0-150500.7.2.3 updated - busybox-attr-1.35.0-150500.7.2.3 updated - busybox-bc-1.35.0-150500.7.2.3 updated - busybox-bind-utils-1.35.0-150500.7.2.3updated - busybox-bzip2-1.35.0-150500.7.2.3 updated - busybox-coreutils-1.35.0-150500.7.2.3 updated - busybox-cpio-1.35.0-150500.7.2.3 updated - busybox-diffutils-1.35.0-150500.7.2.3 updated - busybox-dos2unix-1.35.0-150500.7.2.3 updated - busybox-ed-1.35.0-150500.7.2.3 updated - busybox-findutils-1.35.0-150500.7.2.3 updated - busybox-gawk-1.35.0-150500.7.2.3 updated - busybox-grep-1.35.0-150500.7.2.3 updated - busybox-gzip-1.35.0-150500.7.2.3 updated - busybox-hostname-1.35.0-150500.7.2.3 updated - busybox-iproute2-1.35.0-150500.7.2.3 updated - busybox-iputils-1.35.0-150500.7.2.3 updated - busybox-kbd-1.35.0-150500.7.2.3 updated - busybox-less-1.35.0-150500.7.2.3 updated - busybox-links-1.35.0-150500.7.2.3 updated - busybox-man-1.35.0-150500.7.2.3 updated - busybox-misc-1.35.0-150500.7.2.3 updated - busybox-ncurses-utils-1.35.0-150500.7.2.3 updated - busybox-net-tools-1.35.0-150500.7.2.3 updated - busybox-netcat-1.35.0-150500.7.2.3 updated - busybox-patch-1.35.0-150500.7.2.3 updated - busybox-policycoreutils-1.35.0-150500.7.2.3 updated - busybox-procps-1.35.0-150500.7.2.3 updated - busybox-psmisc-1.35.0-150500.7.2.3 updated - busybox-sed-1.35.0-150500.7.2.3 updated - busybox-selinux-tools-1.35.0-150500.7.2.3 updated - busybox-sendmail-1.35.0-150500.7.2.3 updated - busybox-sharutils-1.35.0-150500.7.2.3 updated - busybox-sh-1.35.0-150500.7.2.3 updated - busybox-syslogd-1.35.0-150500.7.2.3 updated - busybox-sysvinit-tools-1.35.0-150500.7.2.3 updated - busybox-tar-1.35.0-150500.7.2.3 updated - busybox-telnet-1.35.0-150500.7.2.3 updated - busybox-tftp-1.35.0-150500.7.2.3 updated - busybox-time-1.35.0-150500.7.2.3 updated - busybox-traceroute-1.35.0-150500.7.2.3 updated - busybox-tunctl-1.35.0-150500.7.2.3 updated - busybox-unzip-1.35.0-150500.7.2.3 updated - busybox-util-linux-1.35.0-150500.7.2.3 updated - busybox-vi-1.35.0-150500.7.2.3 updated - busybox-vlan-1.35.0-150500.7.2.3 updated - busybox-wget-1.35.0-150500.7.2.3 updated - busybox-which-1.35.0-150500.7.2.3 updated - busybox-whois-1.35.0-150500.7.2.3updated - busybox-xz-1.35.0-150500.7.2.3 updated - busybox-1.35.0-150500.10.3.3 updated - glibc-2.31-150300.58.1 updated . Patch notice for bci/bci-busybox resolving CVE-2022-48174 buffer overflow, included in SUSE container advisory 2023:3155-1.. bci/bci-busybox,SUSE Container Update,Security Update,Busybox Patch. . Severity: Important. LinuxSecurity.com Team
The container bci/bci-init was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1732-1 Container Tags : bci/bci-init:15.4 , bci/bci-init:15.4.26.65 , bci/bci-init:latest Container Release : 26.65 Severity : important Type : security References : 1211430 CVE-2023-2650 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2342-1 Released: Thu Jun 1 11:34:20 2023 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1211430,CVE-2023-2650 This update for openssl-1_1 fixes the following issues: - CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.37.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.37.1 updated - container:sles15-image-15.0.0-27.14.66 updated . SUSE Container Notification for bci/bci-base incorporates essential security patches that tackle vulnerabilities related to exposure of sensitive data.. SUSE Container Update, OpenSSL Security Update, BCI Security Patch. . Severity: Important. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:987-1 Container Tags : bci/python:3 , bci/python:3-35.20 , bci/python:3.6 , bci/python:3.6-35.20 Container Release : 35.20 Severity : moderate Type : security References : 1209624 CVE-2023-0464 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1745-1 Released: Tue Apr 4 09:05:23 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1209624,CVE-2023-0464 This update for openssl-1_1 fixes the following issues: - CVE-2023-0464: Fixed excessive Resource Usage Verifying X.509 Policy Constraints (bsc#1209624). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.31.2 updated - libopenssl1_1-hmac-1.1.1l-150400.7.31.2 updated - openssl-1_1-1.1.1l-150400.7.31.2 updated . The latest security patch for SUSE bci/python, designated SUSE-CU-2023:987-1, resolves vulnerabilities found in openssl-1_1.. bci/python security, SUSE updates, openssl patch, container security, Python security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.