Cross-References: * CVE-2023-44487 CVSS scores: . # Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t Announcement ID: SUSE-SU-2023:4624-1 Rating: important References: Cross-References: * CVE-2023-44487 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for kubevirt, virt-api-container, virt-controller-container, virt- exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator- container, virt-pr-helper-container fixes the following issues: Update to version 1.1.0 * Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.1.0 Update to version 1.0.1 * Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.0.1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-4624=1 openSUSE-SLE-15.5-2023-4624=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4624=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2023-4624=1 ## Package List: * openSUSE Leap 15.5 (x86_64) *kubevirt-container-disk-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-controller-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-operator-debuginfo-1.1.0-150500.8.6.1 * kubevirt-container-disk-1.1.0-150500.8.6.1 * kubevirt-virt-exportserver-1.1.0-150500.8.6.1 * obs-service-kubevirt_containers_meta-1.1.0-150500.8.6.1 * kubevirt-virt-handler-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-exportproxy-1.1.0-150500.8.6.1 * kubevirt-virt-exportserver-debuginfo-1.1.0-150500.8.6.1 * kubevirt-tests-1.1.0-150500.8.6.1 * kubevirt-tests-debuginfo-1.1.0-150500.8.6.1 * kubevirt-pr-helper-conf-1.1.0-150500.8.6.1 * kubevirt-virt-exportproxy-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-api-1.1.0-150500.8.6.1 * kubevirt-virt-handler-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 * kubevirt-virt-launcher-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-virt-launcher-1.1.0-150500.8.6.1 * kubevirt-virt-controller-1.1.0-150500.8.6.1 * kubevirt-virt-api-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virt-operator-1.1.0-150500.8.6.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 * Containers Module 15-SP5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.0-150500.8.6.1 * kubevirt-virtctl-1.1.0-150500.8.6.1 * kubevirt-manifests-1.1.0-150500.8.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html . Urgent patch release for kubevirt and container modules; immediate application recommended for all vulnerable systems. Kubevirt Update, SUSE Security Fix, Container Vulnerability. . Severity: Critical. LinuxSecurity.com Team
* bsc#1206346 Affected Products: * Containers Module 15-SP4 * Containers Module 15-SP5 . # Security update for container-suseconnect Announcement ID: SUSE-SU-2023:2600-1 Rating: important References: * bsc#1206346 Affected Products: * Containers Module 15-SP4 * Containers Module 15-SP5 * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update of container-suseconnect fixes the following issues: * rebuild the package with the go 1.20 security release (bsc#1206346). ## PatchInstructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-2600=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-2600=1 * SUSE Enterprise Storage 7 zypper in -t patch SUSE-Storage-7-2023-2600=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. * Containers Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2023-2600=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2023-2600=1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-2600=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-2600=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-2600=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-2600=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-2600=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-2600=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-2600=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-2600=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-2600=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Enterprise Storage 7 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE CaaS Platform 4.0 (x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * Containers Module 15-SP4 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * Containers Module 15-SP5 (aarch64 ppc64le s390x x86_64) * container-suseconnect-debuginfo-2.4.0-150000.4.30.1 * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * container-suseconnect-2.4.0-150000.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * container-suseconnect-2.4.0-150000.4.30.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1206346 .Important notice regarding SUSE elements resolving a major concern. Please check the patch guidelines for assistance.. SUSE Security Update, Container-SUSEConnect, SAP Applications, Linux High Performance Computing. . Severity: Important. LinuxSecurity.com Team
* bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 . # Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-t Announcement ID: SUSE-SU-2024:0441-1 Rating: moderate References: * bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one security fix can now be installed. ## Description: This update for kubevirt, virt-api-container, virt-controller-container, virt- exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator- container, virt-pr-helper-container fixes the following issues: Update to version 1.1.1: Release notes are on https://github.com/kubevirt/kubevirt/releases/tag/v1.1.1 * Fix seccomp profile for post-copy migration * Fix firmware path for aarch64 (/usr/share/AAVMF) * Fix test with initially invalid DataVolume (bsc#1218174) The containers were also rebuilt against updated go version. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-441=1 openSUSE-SLE-15.5-2024-441=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-441=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-441=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * kubevirt-virt-controller-1.1.1-150500.8.9.1 *kubevirt-virt-exportproxy-debuginfo-1.1.1-150500.8.9.1 * obs-service-kubevirt_containers_meta-1.1.1-150500.8.9.1 * kubevirt-virt-api-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-exportproxy-1.1.1-150500.8.9.1 * kubevirt-virt-handler-1.1.1-150500.8.9.1 * kubevirt-virt-api-1.1.1-150500.8.9.1 * kubevirt-virt-launcher-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-operator-1.1.1-150500.8.9.1 * kubevirt-virt-exportserver-1.1.1-150500.8.9.1 * kubevirt-container-disk-debuginfo-1.1.1-150500.8.9.1 * kubevirt-tests-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-launcher-1.1.1-150500.8.9.1 * kubevirt-container-disk-1.1.1-150500.8.9.1 * kubevirt-pr-helper-conf-1.1.1-150500.8.9.1 * kubevirt-virt-operator-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-exportserver-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-handler-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virt-controller-debuginfo-1.1.1-150500.8.9.1 * kubevirt-virtctl-debuginfo-1.1.1-150500.8.9.1 * kubevirt-manifests-1.1.1-150500.8.9.1 * kubevirt-virtctl-1.1.1-150500.8.9.1 * kubevirt-tests-1.1.1-150500.8.9.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.1-150500.8.9.1 * kubevirt-manifests-1.1.1-150500.8.9.1 * kubevirt-virtctl-1.1.1-150500.8.9.1 * Containers Module 15-SP5 (x86_64) * kubevirt-virtctl-debuginfo-1.1.1-150500.8.9.1 * kubevirt-manifests-1.1.1-150500.8.9.1 * kubevirt-virtctl-1.1.1-150500.8.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1218174 . Enhancements address kubevirt and virt-api-container vulnerabilities in openSUSE Leap 15.5, reinforcing defenses against potential security exposures.. kubevirt Update, openSUSE Security Patch, Containers Module Update, Virt-Api-Container Patch. . LinuxSecurity.com Team
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.2/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:151-1 Container Tags : suse/sle-micro/5.2/toolbox:12.1 , suse/sle-micro/5.2/toolbox:12.1-6.2.349 , suse/sle-micro/5.2/toolbox:latest Container Release : 6.2.349 Severity : low Type : security References : 1217969 CVE-2023-39804 ----------------------------------------------------------------- The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:70-1 Released: Tue Jan 9 18:29:39 2024 Summary: Security update for tar Type: security Severity: low References: 1217969,CVE-2023-39804 This update for tar fixes the following issues: - CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969). The following package changes have been done: - tar-1.34-150000.3.34.1 updated . SUSE Container Update for suse/sle-micro/5.3/toolbox addresses security issues identified in the latest patch releases.. SUSE Security Update, Container Patch, Tar Security Fix, SUSE Toolbox Update. . Severity: Low. LinuxSecurity.com Team
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:88-1 Container Tags : bci/dotnet-aspnet:7.0 , bci/dotnet-aspnet:7.0-19.1 , bci/dotnet-aspnet:7.0.14 , bci/dotnet-aspnet:7.0.14-19.1 , bci/dotnet-aspnet:latest Container Release : 19.1 Severity : low Type : security References : 1217969 CVE-2023-39804 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:70-1 Released: Tue Jan 9 18:29:39 2024 Summary: Security update for tar Type: security Severity: low References: 1217969,CVE-2023-39804 This update for tar fixes the following issues: - CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969). The following package changes have been done: - tar-1.34-150000.3.34.1 updated - container:sles15-image-15.0.0-36.5.71 updated . Check out the newly released safety notifications for bci/dotnet-aspnet as detailed in advisory ID SUSE-CU-2024:88-2, which tackle minor vulnerabilities.. bci/dotnet-aspnet security update, container patch, tar security fix. . Severity: Low. LinuxSecurity.com Team
The container bci/openjdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4216-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-12.59 , bci/openjdk:latest Container Release : 12.59 Severity : moderate Type : security References : 1201384 1218014 CVE-2023-50495 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4891-1 Released: Mon Dec 18 16:31:49 2023 Summary: Security update for ncurses Type: security Severity: moderate References: 1201384,1218014,CVE-2023-50495 This update for ncurses fixes the following issues: - CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014) - Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384) The following package changes have been done: - libncurses6-6.1-150000.5.20.1 updated - terminfo-base-6.1-150000.5.20.1 updated - ncurses-utils-6.1-150000.5.20.1 updated - container:sles15-image-15.0.0-36.5.67 updated . SUSE Container Security Update for bci/ruby tackling moderate risk issues such as buffer overflows.. SUSE Container Update,bci/openjdk Security,ncurses Fix. . LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4202-1 Container Tags : bci/node:16 , bci/node:16-18.40 , bci/nodejs:16 , bci/nodejs:16-18.40 Container Release : 18.40 Severity : moderate Type : security References : 1201384 1218014 CVE-2023-50495 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4891-1 Released: Mon Dec 18 16:31:49 2023 Summary: Security update for ncurses Type: security Severity: moderate References: 1201384,1218014,CVE-2023-50495 This update for ncurses fixes the following issues: - CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014) - Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384) The following package changes have been done: - libncurses6-6.1-150000.5.20.1 updated - terminfo-base-6.1-150000.5.20.1 updated - ncurses-utils-6.1-150000.5.20.1 updated - container:sles15-image-15.0.0-27.14.129 updated . Notice of critical updates for SUSE's bci/nodejs container iterations, detailing essential enhancements and alterations.. bci/nodejs Security Update, Container Patch, Nodejs Advisories. . LinuxSecurity.com Team
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4184-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.10 , suse/manager/4.3/proxy-httpd:4.3.10.9.43.4 , suse/manager/4.3/proxy-httpd:latest , suse/manager/4.3/proxy-httpd:susemanager-4.3.10 , suse/manager/4.3/proxy-httpd:susemanager-4.3.10.9.43.4 Container Release : 9.43.4 Severity : moderate Type : security References : 1217592 CVE-2023-49083 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4843-1 Released: Thu Dec 14 12:22:44 2023 Summary: Security update for python3-cryptography Type: security Severity: moderate References: 1217592,CVE-2023-49083 This update for python3-cryptography fixes the following issues: - CVE-2023-49083: Fixed a NULL pointer dereference when loading certificates from a PKCS#7 bundle (bsc#1217592). The following package changes have been done: - python3-cryptography-3.3.2-150400.23.1 updated . SUSE updates the suse/manager/4.3/proxy-httpd container, addressing issues and improving security measures.. SUSE Container Update, Proxy-Httpd Security Fix, Python3-Cryptography Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.