SUSE-CU-2024:3881-1: Security update of suse/sles12sp5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Aug 27 14:04:20 UTC 2024


SUSE Container Update Advisory: suse/sles12sp5
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2024:3881-1
Container Tags        : suse/sles12sp5:6.8.35 , suse/sles12sp5:latest
Container Release     : 6.8.35
Severity              : important
Type                  : security
References            : 1219559 1221563 1222285 1226095 1227138 1227227 1228291 1229339
                        CVE-2023-52425 CVE-2024-5535 
-----------------------------------------------------------------

The container suse/sles12sp5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2965-1
Released:    Mon Aug 19 15:32:07 2024
Summary:     Recommended update for util-linux
Type:        recommended
Severity:    important
References:  1222285
This update for util-linux fixes the following issues:

- Don't delete binaries not common for all architectures. Create an
  util-linux-extra subpackage instead, so users of third party
  tools can use them (bsc#1222285).
- fix Xen virtualization type misidentification.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2972-1
Released:    Tue Aug 20 08:14:12 2024
Summary:     Recommended update for systemd
Type:        recommended
Severity:    moderate
References:  1226095
This update for systemd fixes the following issues:


- Dynamically allocate the receive buffer (bsc#1226095)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2989-1
Released:    Tue Aug 20 16:17:10 2024
Summary:     Security update for openssl-1_0_0
Type:        security
Severity:    moderate
References:  1227138,1227227,1228291,CVE-2024-5535
This update for openssl-1_0_0 fixes the following issues:

- CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138, bsc#1227227)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3004-1
Released:    Fri Aug 23 13:27:40 2024
Summary:     Security update for expat
Type:        security
Severity:    moderate
References:  1219559,1221563,CVE-2023-52425
This update for expat fixes the following issues:

- CVE-2023-52425: denial of service (resource consumption) caused by processing large tokens (bsc#1219559)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3011-1
Released:    Mon Aug 26 13:15:05 2024
Summary:     Recommended update for suse-build-key
Type:        recommended
Severity:    moderate
References:  1229339
This update for suse-build-key fixes the following issue:

- extended 2048 bit SUSE SLE 12, 15 GA-SP5 key until 2028 (bsc#1229339).


The following package changes have been done:

- libblkid1-2.33.2-4.42.4 updated
- libexpat1-2.1.0-21.32.1 updated
- libfdisk1-2.33.2-4.42.4 updated
- libmount1-2.33.2-4.42.4 updated
- libopenssl1_0_0-1.0.2p-3.95.1 updated
- libsmartcols1-2.33.2-4.42.4 updated
- libsystemd0-228-157.63.1 updated
- libudev1-228-157.63.1 updated
- libuuid1-2.33.2-4.42.4 updated
- openssl-1_0_0-1.0.2p-3.95.1 updated
- suse-build-key-12.0-7.19.1 updated
- util-linux-2.33.2-4.42.4 updated


More information about the sle-container-updates mailing list