The container bci/golang was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2858-1 Container Tags : bci/golang:1.17 , bci/golang:1.17-29.72 Container Release : 29.72 Severity : important Type : security References : 1204708 CVE-2022-43680 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3884-1 Released: Mon Nov 7 10:59:26 2022 Summary: Security update for expat Type: security Severity: important References: 1204708,CVE-2022-43680 This update for expat fixes the following issues: - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708). The following package changes have been done: - libexpat1-2.4.4-150400.3.12.1 updated . Crucial patch released for SUSE's bci/golang addresses significant vulnerabilities, bolstering safeguards for containers.. bci/golang update, container security, expat patch, SUSE advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for expat ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3884-1 Rating: important References: #1204708 Cross-References: CVE-2022-43680 CVSS scores: CVE-2022-43680 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-43680 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for expat fixes the following issues: - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3884=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-3884=1 - SUSE Linux Enterprise Micro 5.3: zypper in -t patch SUSE-SLE-Micro-5.3-2022-3884=1 Package List: - openSUSE Leap 15.4(aarch64 ppc64le s390x x86_64): expat-2.4.4-150400.3.12.1 expat-debuginfo-2.4.4-150400.3.12.1 expat-debugsource-2.4.4-150400.3.12.1 libexpat-devel-2.4.4-150400.3.12.1 libexpat1-2.4.4-150400.3.12.1 libexpat1-debuginfo-2.4.4-150400.3.12.1 - openSUSE Leap 15.4 (x86_64): expat-32bit-debuginfo-2.4.4-150400.3.12.1 libexpat-devel-32bit-2.4.4-150400.3.12.1 libexpat1-32bit-2.4.4-150400.3.12.1 libexpat1-32bit-debuginfo-2.4.4-150400.3.12.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): expat-2.4.4-150400.3.12.1 expat-debuginfo-2.4.4-150400.3.12.1 expat-debugsource-2.4.4-150400.3.12.1 libexpat-devel-2.4.4-150400.3.12.1 libexpat1-2.4.4-150400.3.12.1 libexpat1-debuginfo-2.4.4-150400.3.12.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (x86_64): expat-32bit-debuginfo-2.4.4-150400.3.12.1 libexpat1-32bit-2.4.4-150400.3.12.1 libexpat1-32bit-debuginfo-2.4.4-150400.3.12.1 - SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64): expat-debuginfo-2.4.4-150400.3.12.1 expat-debugsource-2.4.4-150400.3.12.1 libexpat1-2.4.4-150400.3.12.1 libexpat1-debuginfo-2.4.4-150400.3.12.1 References: https://www.suse.com/security/cve/CVE-2022-43680.html https://bugzilla.suse.com/1204708 . SUSE Security Patch for expat addresses a memory corruption vulnerability. Critical update information outlined.. SUSE Security Update, expat Patch, Linux Enterprise Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for expat ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3489-1 Rating: important References: #1203438 Cross-References: CVE-2022-40674 CVSS scores: CVE-2022-40674 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-40674 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for expat fixes the following issues: - CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3489=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-3489=1 - SUSE Linux Enterprise Micro 5.3: zypper in -t patch SUSE-SLE-Micro-5.3-2022-3489=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): expat-2.4.4-150400.3.9.1 expat-debuginfo-2.4.4-150400.3.9.1 expat-debugsource-2.4.4-150400.3.9.1 libexpat-devel-2.4.4-150400.3.9.1 libexpat1-2.4.4-150400.3.9.1 libexpat1-debuginfo-2.4.4-150400.3.9.1 - openSUSE Leap 15.4 (x86_64): expat-32bit-debuginfo-2.4.4-150400.3.9.1 libexpat-devel-32bit-2.4.4-150400.3.9.1 libexpat1-32bit-2.4.4-150400.3.9.1 libexpat1-32bit-debuginfo-2.4.4-150400.3.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): expat-2.4.4-150400.3.9.1 expat-debuginfo-2.4.4-150400.3.9.1 expat-debugsource-2.4.4-150400.3.9.1 libexpat-devel-2.4.4-150400.3.9.1 libexpat1-2.4.4-150400.3.9.1 libexpat1-debuginfo-2.4.4-150400.3.9.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (x86_64): expat-32bit-debuginfo-2.4.4-150400.3.9.1 libexpat1-32bit-2.4.4-150400.3.9.1 libexpat1-32bit-debuginfo-2.4.4-150400.3.9.1 - SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64): expat-debuginfo-2.4.4-150400.3.9.1 expat-debugsource-2.4.4-150400.3.9.1 libexpat1-2.4.4-150400.3.9.1 libexpat1-debuginfo-2.4.4-150400.3.9.1 References: https://www.suse.com/security/cve/CVE-2022-40674.html https://bugzilla.suse.com/1203438 . SUSE Security Notice for libxml2 detailing critical patches and recommendations for impacted software to strengthen overall system security.. Expat Security Update, SUSE System Fixes, Threat Management, Patch Guidance. . Severity: Important. LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:216-1 Container Tags : bci/python:3.6 , bci/python:3.6-10.11 Container Release : 10.11 Severity : important Type : security References : 1191826 1192637 1194178 1194265 1194968 1195054 1195217 CVE-2021-3997 CVE-2022-23852 CVE-2022-23990 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:383-1 Released: Tue Feb 15 17:47:36 2022 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1194265 This update for cyrus-sasl fixes the following issues: - Fixed an issue when in postfix 'sasl' authentication with password fails. (bsc#1194265) - Add config parameter '--with-dblib=gdbm' - Avoid converting of '/etc/sasldb2 by every update. Convert '/etc/sasldb2' only if it is a Berkeley DB. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:498-1 Released: Fri Feb 18 10:46:56 2022 Summary: Security update for expat Type: security Severity: important References: 1195054,1195217,CVE-2022-23852,CVE-2022-23990 This update for expat fixes the following issues: - CVE-2022-23852: Fixed signed integer overflow in XML_GetBuffer (bsc#1195054). - CVE-2022-23990: Fixed integer overflow in the doProlog function (bsc#1195217). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:520-1 Released: Fri Feb 18 12:45:19 2022 Summary: Recommended update for rpm Type: recommended Severity: moderate References: 1194968 This update for rpm fixes the followingissues: - Revert unwanted /usr/bin/python to /usr/bin/python2 change we got with the update to 4.14.3 (bsc#1194968) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:539-1 Released: Mon Feb 21 13:47:51 2022 Summary: Security update for systemd Type: security Severity: moderate References: 1191826,1192637,1194178,CVE-2021-3997 This update for systemd fixes the following issues: - CVE-2021-3997: Fixed an uncontrolled recursion in systemd's systemd-tmpfiles (bsc#1194178). The following non-security bugs were fixed: - udev/net_id: don't generate slot based names if multiple devices might claim the same slot (bsc#1192637) - localectl: don't omit keymaps files that are symlinks (bsc#1191826) The following package changes have been done: - libexpat1-2.2.5-3.12.1 updated - libsasl2-3-2.1.27-150300.4.3.1 updated - libsystemd0-246.16-150300.7.39.1 updated - libudev1-246.16-150300.7.39.1 updated - rpm-ndb-4.14.3-150300.46.1 updated - container:sles15-image-15.0.0-17.8.81 updated . Essential updates for bci/python container resolving multiple vulnerabilities, incorporating fixes for expat alongside systemd improvements.. bci/python Update, Container Security, Python Patches, SUSE Updates. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.