SUSE-IU-2024:2070-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Dec 20 08:07:50 UTC 2024


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2024:2070-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-4.31 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 4.31
Severity          : moderate
Type              : security
References        : 1212476 1226586 1233420 CVE-2024-52616 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 155
Released:    Thu Dec 19 16:31:30 2024
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1212476,1226586,1233420,CVE-2024-52616
This update for avahi fixes the following issues:

- CVE-2024-52616: Properly randomize query id of DNS packets (bsc#1233420).

Bug fixes:

- No longer supply bogus services to callbacks (bsc#1226586).
- Tag hardening patches as PATCH-FEATURE-OPENSUSE
- Remove dependency on /usr/bin/python3 using %python3_fix_shebang macro (bsc#1212476).


The following package changes have been done:

- SL-Micro-release-6.0-24.38 updated
- libavahi-common3-0.8-6.1 updated
- libavahi-core7-0.8-6.1 updated
- libavahi-client3-0.8-6.1 updated
- avahi-0.8-6.1 updated
- container:SL-Micro-base-container-2.1.3-4.30 updated


More information about the sle-container-updates mailing list