SUSE-CU-2024:3881-1: Security update of suse/sles12sp5
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Aug 27 14:04:20 UTC 2024
SUSE Container Update Advisory: suse/sles12sp5
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2024:3881-1
Container Tags : suse/sles12sp5:6.8.35 , suse/sles12sp5:latest
Container Release : 6.8.35
Severity : important
Type : security
References : 1219559 1221563 1222285 1226095 1227138 1227227 1228291 1229339
CVE-2023-52425 CVE-2024-5535
-----------------------------------------------------------------
The container suse/sles12sp5 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2965-1
Released: Mon Aug 19 15:32:07 2024
Summary: Recommended update for util-linux
Type: recommended
Severity: important
References: 1222285
This update for util-linux fixes the following issues:
- Don't delete binaries not common for all architectures. Create an
util-linux-extra subpackage instead, so users of third party
tools can use them (bsc#1222285).
- fix Xen virtualization type misidentification.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2972-1
Released: Tue Aug 20 08:14:12 2024
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1226095
This update for systemd fixes the following issues:
- Dynamically allocate the receive buffer (bsc#1226095)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2989-1
Released: Tue Aug 20 16:17:10 2024
Summary: Security update for openssl-1_0_0
Type: security
Severity: moderate
References: 1227138,1227227,1228291,CVE-2024-5535
This update for openssl-1_0_0 fixes the following issues:
- CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138, bsc#1227227)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3004-1
Released: Fri Aug 23 13:27:40 2024
Summary: Security update for expat
Type: security
Severity: moderate
References: 1219559,1221563,CVE-2023-52425
This update for expat fixes the following issues:
- CVE-2023-52425: denial of service (resource consumption) caused by processing large tokens (bsc#1219559)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3011-1
Released: Mon Aug 26 13:15:05 2024
Summary: Recommended update for suse-build-key
Type: recommended
Severity: moderate
References: 1229339
This update for suse-build-key fixes the following issue:
- extended 2048 bit SUSE SLE 12, 15 GA-SP5 key until 2028 (bsc#1229339).
The following package changes have been done:
- libblkid1-2.33.2-4.42.4 updated
- libexpat1-2.1.0-21.32.1 updated
- libfdisk1-2.33.2-4.42.4 updated
- libmount1-2.33.2-4.42.4 updated
- libopenssl1_0_0-1.0.2p-3.95.1 updated
- libsmartcols1-2.33.2-4.42.4 updated
- libsystemd0-228-157.63.1 updated
- libudev1-228-157.63.1 updated
- libuuid1-2.33.2-4.42.4 updated
- openssl-1_0_0-1.0.2p-3.95.1 updated
- suse-build-key-12.0-7.19.1 updated
- util-linux-2.33.2-4.42.4 updated
More information about the sle-container-updates
mailing list