An update that solves one vulnerability can now be installed.. # distribution-registry-3.1.1-1.1 on GA media Announcement ID: openSUSE-SU-2026:10812-1 Rating: moderate Cross-References: * CVE-2026-41888 CVSS scores: * CVE-2026-41888 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-41888 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the distribution-registry-3.1.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * distribution-registry 3.1.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41888.html . An update for openSUSE Tumbleweed addresses a moderate security issue in distribution-registry affecting system integrity.. openSUSE Tumbleweed, distribution-registry, CVE-2026-41888. . LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4320-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-15.31 , suse/registry:latest Container Release : 15.31 Severity : moderate Type : security References : 1216491 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4974-1 Released: Tue Dec 26 05:02:31 2023 Summary: Security update for distribution Type: security Severity: moderate References: 1216491 This update for distribution fixes the following issues: distribution was updated to 2.8.3 (bsc#1216491): * Pass `BUILDTAGS` argument to `go build` * Enable Go build tags * `reference`: replace deprecated function `SplitHostname` * Dont parse errors as JSON unless Content-Type is set to JSON * update to go 1.20.8 * Set `Content-Type` header in registry client `ReadFrom` * deprecate reference package, migrate to github.com/distribution/reference * `digestset`: deprecate package in favor of `go-digest/digestset` * Do not close HTTP request body in HTTP handler The following package changes have been done: - distribution-registry-2.8.3-150400.9.24.1 updated . SUSE Docker Security Bulletin for suse/docker provides critical enhancements and fixes along with risk assessments and recommendations.. SUSE Registry Update, Security Patch, Container Security, Advisory Update. . LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4220-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-15.30 , suse/registry:latest Container Release : 15.30 Severity : moderate Type : security References : 1201384 1218014 CVE-2023-50495 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4891-1 Released: Mon Dec 18 16:31:49 2023 Summary: Security update for ncurses Type: security Severity: moderate References: 1201384,1218014,CVE-2023-50495 This update for ncurses fixes the following issues: - CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014) - Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384) The following package changes have been done: - libncurses6-6.1-150000.5.20.1 updated - terminfo-base-6.1-150000.5.20.1 updated - container:micro-image-15.5.0-12.8 updated . Enhanced security features for SUSE Container suse/registry addressing segmentation faults and delivering updates for libcurl.. SUSE Registry Update, Container Security, NCurses Patch. . LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3702-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-15.12 , suse/registry:latest Container Release : 15.12 Severity : important Type : security References : 1207399 1214357 1216424 CVE-2023-31122 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4430-1 Released: Mon Nov 13 17:55:09 2023 Summary: Security update for apache2 Type: security Severity: important References: 1207399,1214357,1216424,CVE-2023-31122 This update for apache2 fixes the following issues: - CVE-2023-31122: Fixed an out of bounds read in mod_macro (bsc#1216424). Non-security fixes: - Fixed the content type handling in mod_proxy_http2 (bsc#1214357). - Fixed a floating point exception crash (bsc#1207399). The following package changes have been done: - apache2-utils-2.4.51-150400.6.14.1 updated . SUSE Container Update Bulletin for suse/registry outlines essential fixes and enhancements targeting security vulnerabilities.. SUSE Container Registry Update, Security Advisory, Important Security Patches, Registry Issues. . Severity: Important. LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3543-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-15.9 , suse/registry:latest Container Release : 15.9 Severity : important Type : security References : 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 1215215 1215286 1215891 CVE-2023-4039 CVE-2023-4813 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4105-1 Released: Wed Oct 18 08:15:40 2023 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1215215 This update for openssl-1_1 fixes the following issues: - Displays 'fips' in the version string (bsc#1215215) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4110-1 Released: Wed Oct 18 12:35:26 2023 Summary: Security update for glibc Type: security Severity: important References: 1215286,1215891,CVE-2023-4813 This update for glibc fixes the following issues: Security issue fixed: - CVE-2023-4813: Fixed a potential use-after-free in gaih_inet() (bsc#1215286, BZ #28931) Also a regression from a previous update was fixed: - elf: Align argument of __munmap to page size (bsc#1215891, BZ #28676) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4162-1 Released: Mon Oct 23 15:33:03 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039 This update for gcc13 fixes the followingissues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running thetestsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - glibc-2.31-150300.63.1 updated - libgcc_s1-13.2.1+git7813-150000.1.3.3 updated - libopenssl1_1-1.1.1l-150500.17.19.1 updated - libstdc++6-13.2.1+git7813-150000.1.3.3 updated - openssl-1_1-1.1.1l-150500.17.19.1 updated - container:micro-image-15.5.0-12.3 updated . SUSE refreshes suse/registry with vital patches and improvements to safeguard against major threats and vulnerabilities.. SUSE, Container Security, SUSE Registry Update, Security Fixes, Security Advisory. . Severity: Important. LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2772-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-14.20 , suse/registry:latest Container Release : 14.20 Severity : important Type : security References : 1214248 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3454-1 Released: Mon Aug 28 13:43:18 2023 Summary: Security update for ca-certificates-mozilla Type: security Severity: important References: 1214248 This update for ca-certificates-mozilla fixes the following issues: - Updated to 2.62 state of Mozilla SSL root CAs (bsc#1214248) Added: - Atos TrustedRoot Root CA ECC G2 2020 - Atos TrustedRoot Root CA ECC TLS 2021 - Atos TrustedRoot Root CA RSA G2 2020 - Atos TrustedRoot Root CA RSA TLS 2021 - BJCA Global Root CA1 - BJCA Global Root CA2 - LAWtrust Root CA2 (4096) - Sectigo Public Email Protection Root E46 - Sectigo Public Email Protection Root R46 - Sectigo Public Server Authentication Root E46 - Sectigo Public Server Authentication Root R46 - SSL.com Client ECC Root CA 2022 - SSL.com Client RSA Root CA 2022 - SSL.com TLS ECC Root CA 2022 - SSL.com TLS RSA Root CA 2022 Removed CAs: - Chambers of Commerce Root - E-Tugra Certification Authority - E-Tugra Global Root CA ECC v3 - E-Tugra Global Root CA RSA v3 - Hongkong Post Root CA 1 The following package changes have been done: - ca-certificates-mozilla-2.62-150200.30.1 updated - container:micro-image-15.5.0-11.3 updated . Critical fix deployed for the ubuntu/docker-image, featuring essential updates forca-certificates.firefox.. SUSE Container Update, Container Security Update, SUSE Registry Advisory, ca-certificates Update. . Severity: Important. LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2687-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-14.17 , suse/registry:latest Container Release : 14.17 Severity : important Type : security References : 1214054 CVE-2023-36054 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3325-1 Released: Wed Aug 16 08:26:08 2023 Summary: Security update for krb5 Type: security Severity: important References: 1214054,CVE-2023-36054 This update for krb5 fixes the following issues: - CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054) The following package changes have been done: - krb5-1.20.1-150500.3.3.1 updated . Crucial enhancement released for the SUSE container repository focusing on a DoS vulnerability, promoting improved strength and safety for the system.. SUSE Registry Security, Container Security Update, Registry Update Advisory, DoS Security Fix, SUSE Container Patch. . Severity: Important. LinuxSecurity.com Team
The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2547-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-14.15 , suse/registry:latest Container Release : 14.15 Severity : moderate Type : security References : 1213853 CVE-2023-3817 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3242-1 Released: Tue Aug 8 18:19:40 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.15.1 updated - openssl-1_1-1.1.1l-150500.17.15.1 updated . SUSE Container Update Notice for suse/registry features a significant security fix concerning CVE-2023-3817.. SUSE Container Update, SUSE Security Advisory, registry Update, openssl Security Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.