SUSE-CU-2023:785-1: Security update of suse/sle15

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Sat Mar 25 08:04:06 UTC 2023


SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:785-1
Container Tags        : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.115 , suse/sle15:15.3 , suse/sle15:15.3.17.20.115
Container Release     : 17.20.115
Severity              : important
Type                  : security
References            : 1200441 1206134 1208270 1208271 1208272 1209030 CVE-2022-41720
                        CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:871-1
Released:    Wed Mar 22 14:32:45 2023
Summary:     Security update for container-suseconnect
Type:        security
Severity:    important
References:  1200441,1206134,1208270,1208271,1208272,1209030,CVE-2022-41720,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532

This update of container-suseconnect fixes the following issue:

- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.

- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).
- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).
- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).

- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).


The following package changes have been done:

- container-suseconnect-2.4.0-150000.4.24.1 updated


More information about the sle-security-updates mailing list