Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1210141 * bsc#1214855 * bsc#1215323 * bsc#1217513 * bsc#1219267 . # Security update for docker Announcement ID: SUSE-SU-2025:20056-1 Release Date: 2025-02-03T08:56:57Z Rating: critical References: * bsc#1210141 * bsc#1214855 * bsc#1215323 * bsc#1217513 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1220339 * bsc#1221916 * bsc#1223409 * bsc#1228324 Cross-References: * CVE-2024-23651 * CVE-2024-23652 * CVE-2024-23653 * CVE-2024-41110 CVSS scores: * CVE-2024-23651 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23651 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-23652 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2024-23652 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2024-23653 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-23653 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41110 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has seven fixes can now be installed. ## Description: This update for docker fixes the following issues: Security fixes: * CVE-2024-23651: Fixed arbitrary files write due to race condition on mounts (bsc#1219267) * CVE-2024-23652: Fixed insufficient validation of parent directory on mount (bsc#1219268) * CVE-2024-23653: Fixed insufficient validation on entitlement on container creation via buildkit (bsc#1219438) * CVE-2024-41110: A Authz zero length regression that could lead to authentication bypass was fixed (bsc#1228324) Other changes: * Update to Docker 25.0.6-ce. * Fix BuildKit's symlink resolution logic to correctly handle non-lexical symlinks. (bsc#1221916) * Write volume options atomically so sudden system crashes won't result in future Docker starts failing due to empty files. (bsc#1214855) * Fixed world writable dockeroverlay files (bsc#1220339) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-64=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-debuginfo-25.0.6_ce-1.1 * docker-25.0.6_ce-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-23651.html * https://www.suse.com/security/cve/CVE-2024-23652.html * https://www.suse.com/security/cve/CVE-2024-23653.html * https://www.suse.com/security/cve/CVE-2024-41110.html * https://bugzilla.suse.com/show_bug.cgi?id=1210141 * https://bugzilla.suse.com/show_bug.cgi?id=1214855 * https://bugzilla.suse.com/show_bug.cgi?id=1215323 * https://bugzilla.suse.com/show_bug.cgi?id=1217513 * https://bugzilla.suse.com/show_bug.cgi?id=1219267 * https://bugzilla.suse.com/show_bug.cgi?id=1219268 * https://bugzilla.suse.com/show_bug.cgi?id=1219438 * https://bugzilla.suse.com/show_bug.cgi?id=1220339 * https://bugzilla.suse.com/show_bug.cgi?id=1221916 * https://bugzilla.suse.com/show_bug.cgi?id=1223409 * https://bugzilla.suse.com/show_bug.cgi?id=1228324 . A significant SUSE update for Docker addresses several vulnerabilities, boosting system stability and security. Evaluations of safety protocols highlighted.. docker update, SUSE security, critical patch, authentication bypass fix. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7169-4 January 09, 2025 linux-azure vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-azure: Linux kernel for Microsoft Azure Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Ext4 file system; - Network traffic control; - VMware vSockets driver; (CVE-2024-49967, CVE-2024-53057, CVE-2024-50264) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 linux-image-6.11.0-1007-azure 6.11.0-1007.7 linux-image-6.11.0-1007-azure-fde 6.11.0-1007.7 linux-image-azure 6.11.0-1007.7 linux-image-azure-fde 6.11.0-1007.7 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7169-4 https://ubuntu.com/security/notices/USN-7169-3 https://ubuntu.com/security/notices/USN-7169-2 https://ubuntu.com/security/notices/USN-7169-1 CVE-2024-49967, CVE-2024-50264, CVE-2024-53057 Package Information: https://launchpad.net/ubuntu/+source/linux-azure/6.11.0-1007.7 . Ubuntu 24.10 Linux kernel has resolved various security vulnerabilities. Please upgrade your system to incorporate the latest security improvements.. Linux kernel Security Advisory, Ubuntu 24.10 Update, Azure Cloud Linux Issues. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12704 http://linux.oracle.com/errata/ELSA-2024-12704.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: e2fsprogs-1.45.4-3.0.7.el7.x86_64.rpm e2fsprogs-1.45.4-3.0.7.el7.i686.rpm e2fsprogs-devel-1.45.4-3.0.7.el7.x86_64.rpm e2fsprogs-devel-1.45.4-3.0.7.el7.i686.rpm e2fsprogs-libs-1.45.4-3.0.7.el7.x86_64.rpm e2fsprogs-libs-1.45.4-3.0.7.el7.i686.rpm e2fsprogs-static-1.45.4-3.0.7.el7.x86_64.rpm e2fsprogs-static-1.45.4-3.0.7.el7.i686.rpm libcom_err-1.45.4-3.0.7.el7.x86_64.rpm libcom_err-1.45.4-3.0.7.el7.i686.rpm libcom_err-devel-1.45.4-3.0.7.el7.x86_64.rpm libcom_err-devel-1.45.4-3.0.7.el7.i686.rpm libss-1.45.4-3.0.7.el7.x86_64.rpm libss-1.45.4-3.0.7.el7.i686.rpm libss-devel-1.45.4-3.0.7.el7.x86_64.rpm libss-devel-1.45.4-3.0.7.el7.i686.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//e2fsprogs-1.45.4-3.0.7.el7.src.rpm Related CVEs: CVE-2022-1304 Description of changes: [1.45.4-3.0.7.el7] - libext2fs: add sanity check to extent manipulation (Srivathsa Dara) [Orabug: 37095032] {CVE-2022-1304} _______________________________________________ El-errata mailing list
An out-of-bounds read/write vulnerability has been fixed in the e2fsck tool of the ext2/ext3/ext4 file system utilities e2fsprogs. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3910-1
* bsc#1208810 * bsc#1216207 * bsc#1216869 Cross-References: . # Security update for slurm_22_05 Announcement ID: SUSE-SU-2023:4581-1 Rating: important References: * bsc#1208810 * bsc#1216207 * bsc#1216869 Cross-References: * CVE-2023-41914 CVSS scores: * CVE-2023-41914 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-41914 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for slurm_22_05 fixes the following issues: * CVE-2023-41914: Fixed a filesystem handling race condition that could have led to an attacker taking control of an arbitrary file, or removing entire directory contents (bsc#1216207). Bug fixes: * Add missing dependencies to slurm-config to plugins package. These should help to tie down the slurm version and help to avoid a package mix (bsc#1216869). * Add missing Provides:, Conflicts: and Obsoletes: to slurm-cray, slurm-hdf5 and slurm-testsuite to avoid package conflicts (bsc#1208810). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4581=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * perl-slurm_22_05-22.05.10-150100.3.6.1 * libslurm38-22.05.10-150100.3.6.1 * slurm_22_05-slurmdbd-22.05.10-150100.3.6.1 * slurm_22_05-lua-22.05.10-150100.3.6.1 * slurm_22_05-sview-22.05.10-150100.3.6.1 * slurm_22_05-sql-debuginfo-22.05.10-150100.3.6.1 *slurm_22_05-22.05.10-150100.3.6.1 * libnss_slurm2_22_05-22.05.10-150100.3.6.1 * libslurm38-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-devel-22.05.10-150100.3.6.1 * slurm_22_05-pam_slurm-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-plugins-22.05.10-150100.3.6.1 * slurm_22_05-munge-22.05.10-150100.3.6.1 * slurm_22_05-rest-22.05.10-150100.3.6.1 * slurm_22_05-torque-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-pam_slurm-22.05.10-150100.3.6.1 * slurm_22_05-rest-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-debugsource-22.05.10-150100.3.6.1 * slurm_22_05-torque-22.05.10-150100.3.6.1 * libpmi0_22_05-debuginfo-22.05.10-150100.3.6.1 * libnss_slurm2_22_05-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-slurmdbd-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-plugins-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-auth-none-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-munge-debuginfo-22.05.10-150100.3.6.1 * perl-slurm_22_05-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-lua-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-node-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-sql-22.05.10-150100.3.6.1 * slurm_22_05-debuginfo-22.05.10-150100.3.6.1 * libpmi0_22_05-22.05.10-150100.3.6.1 * slurm_22_05-sview-debuginfo-22.05.10-150100.3.6.1 * slurm_22_05-node-22.05.10-150100.3.6.1 * slurm_22_05-auth-none-22.05.10-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch) * slurm_22_05-doc-22.05.10-150100.3.6.1 * slurm_22_05-webdoc-22.05.10-150100.3.6.1 * slurm_22_05-config-man-22.05.10-150100.3.6.1 * slurm_22_05-config-22.05.10-150100.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-41914.html * https://bugzilla.suse.com/show_bug.cgi?id=1208810 * https://bugzilla.suse.com/show_bug.cgi?id=1216207 * https://bugzilla.suse.com/show_bug.cgi?id=1216869 . Major security upgrade for SUSE slurm_22_05 addresses key race condition issue, improving overall systemstability.. SUSE Linux, Security Update, Slurm, Race Condition, Package Conflicts. . Severity: Important. LinuxSecurity.com Team
The security update of netatalk, the Apple Filing Protocol service, announced as DLA-3426-1 caused a regression when the netatalk server was configured to use the AppleDouble v2 file system format. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3426-2
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for clone-master-clean-up ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3674-1 Rating: moderate References: #1181050 #1203651 Cross-References: CVE-2021-32000 CVSS scores: CVE-2021-32000 (NVD) : 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVE-2021-32000 (SUSE): 5 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for clone-master-clean-up fixes the following issues: - CVE-2021-32000: Fixed some potentially dangerous file system operations (bsc#1181050). Bugfixes: - Fixed failures to remove btrfs snapshots (bsc#1203651). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3674=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (noarch): clone-master-clean-up-1.8-4.11.1 References: https://www.suse.com/security/cve/CVE-2021-32000.html https://bugzilla.suse.com/1181050 https://bugzilla.suse.com/1203651 . SUSE Security Bulletin: Critical update for resource-deletion-clean-up Announcement ID:SUSE-SU-2022:3675-1. SUSE Update, Clone Master, File System Fix, Security Patch. . LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for clone-master-clean-up ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3667-1 Rating: moderate References: #1181050 #1203651 Cross-References: CVE-2021-32000 CVSS scores: CVE-2021-32000 (NVD) : 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVE-2021-32000 (SUSE): 5 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for clone-master-clean-up fixes the following issues: - CVE-2021-32000: Fixed some potentially dangerous file system operations (bsc#1181050). Bugfixes: - Fixed clone-master-clean-up failing to remove btrfs snapshots (bsc#1203651). PatchInstructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3667=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3667=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-3667=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-3667=1 Package List: - openSUSE Leap 15.4 (noarch): clone-master-clean-up-1.8-150100.3.14.1 - openSUSE Leap 15.3 (noarch): clone-master-clean-up-1.8-150100.3.14.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (noarch): clone-master-clean-up-1.8-150100.3.14.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (noarch): clone-master-clean-up-1.8-150100.3.14.1 References: https://www.suse.com/security/cve/CVE-2021-32000.html https://bugzilla.suse.com/1181050 https://bugzilla.suse.com/1203651 . SUSE Security Patch for clone-instance-removal resolves security flaws. Prompt updates released for impacted systems.. SUSE Update, Clone Master Cleanup, File System Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.