* bsc#1222539 Cross-References: * CVE-2024-3177 . # Security update for kubernetes1.24 Announcement ID: SUSE-SU-2024:1403-1 Rating: low References: * bsc#1222539 Cross-References: * CVE-2024-3177 CVSS scores: * CVE-2024-3177 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for kubernetes1.24 fixes the following issues: * CVE-2024-3177: Fixed bypass of mountable secrets policy imposed by the ServiceAccount admission plugin (bsc#1222539) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1403=1 openSUSE-SLE-15.5-2024-1403=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-1403=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * kubernetes1.24-apiserver-1.24.17-150500.3.16.1 * kubernetes1.24-kubelet-1.24.17-150500.3.16.1 * kubernetes1.24-client-common-1.24.17-150500.3.16.1 * kubernetes1.24-kubeadm-1.24.17-150500.3.16.1 * kubernetes1.24-proxy-1.24.17-150500.3.16.1 * kubernetes1.24-controller-manager-1.24.17-150500.3.16.1 * kubernetes1.24-kubelet-common-1.24.17-150500.3.16.1 * kubernetes1.24-scheduler-1.24.17-150500.3.16.1 * kubernetes1.24-client-1.24.17-150500.3.16.1 * openSUSE Leap 15.5 (noarch) * kubernetes1.24-client-fish-completion-1.24.17-150500.3.16.1 * kubernetes1.24-client-bash-completion-1.24.17-150500.3.16.1 * Containers Module 15-SP5 (aarch64 ppc64le s390xx86_64) * kubernetes1.24-client-1.24.17-150500.3.16.1 * kubernetes1.24-client-common-1.24.17-150500.3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3177.html * https://bugzilla.suse.com/show_bug.cgi?id=1222539 . SUSE has issued a minor severity security notice for kubernetes 1.24, focusing on an important concern and offering steps for applying the necessary updates.. Kubernetes Security Update, SUSE Patch Instructions, Container Security Advisory. . Severity: Low. LinuxSecurity.com Team
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2155-1 Container Tags : suse/sle-micro/5.4/toolbox:12.1 , suse/sle-micro/5.4/toolbox:12.1-4.2.54 , suse/sle-micro/5.4/toolbox:latest Container Release : 4.2.54 Severity : moderate Type : security References : 1210996 1211256 1211257 CVE-2023-2426 CVE-2023-2609 CVE-2023-2610 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2640-1 Released: Mon Jun 26 15:09:10 2023 Summary: Security update for vim Type: security Severity: moderate References: 1210996,1211256,1211257,CVE-2023-2426,CVE-2023-2609,CVE-2023-2610 This update for vim fixes the following issues: - CVE-2023-2426: Fixed out-of-range pointer offset (bsc#1210996). - CVE-2023-2609: Fixed NULL pointer dereference (bsc#1211256). - CVE-2023-2610: Fixed integer overflow or wraparound (bsc#1211257). The following package changes have been done: - vim-data-common-9.0.1572-150000.5.46.1 updated - vim-9.0.1572-150000.5.46.1 updated - xxd-9.0.1443-150000.5.43.1 removed . The image suse/sle-micro/5.4/toolbox has been updated to fix security flaws that could be exploited.. Container Update, Toolbox Security, suse/sle-micro Updates. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.