SUSE-CU-2025:1180-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Feb 21 08:11:37 UTC 2025


SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2025:1180-1
Container Tags        : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.6 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.6.17.5.107 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Container Release     : 17.5.107
Severity              : important
Type                  : security
References            : 1229163 1229164 1233606 1233608 1233609 1233610 1233612 1233613
                        1233614 1233615 1233616 1233617 1234958 1236196 1236316 1236317
                        1237002 1237006 1237008 1237009 1237010 1237011 1237012 1237013
                        1237014 CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777
                        CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782
                        CVE-2024-45783 CVE-2024-49504 CVE-2024-56737 CVE-2025-0622 CVE-2025-0624
                        CVE-2025-0677 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686
                        CVE-2025-0689 CVE-2025-0690 CVE-2025-1118 CVE-2025-1125 
-----------------------------------------------------------------

The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:586-1
Released:    Wed Feb 19 08:28:47 2025
Summary:     Security update for grub2
Type:        security
Severity:    important
References:  1229163,1229164,1233606,1233608,1233609,1233610,1233612,1233613,1233614,1233615,1233616,1233617,1234958,1236316,1236317,1237002,1237006,1237008,1237009,1237010,1237011,1237012,1237013,1237014,CVE-2024-45774,CVE-2024-45775,CVE-2024-45776,CVE-2024-45777,CVE-2024-45778,CVE-2024-45779,CVE-2024-45780,CVE-2024-45781,CVE-2024-45782,CVE-2024-45783,CVE-2024-49504,CVE-2024-56737,CVE-2025-0622,CVE-2025-0624,CVE-2025-0677,CVE-2025-0678,CVE-2025-0684,CVE-2025-0685,CVE-2025-0686,CVE-2025-0689,CVE-2025-0690,CVE-2025-1118,CVE-2025-1125
This update for grub2 fixes the following issues:

- CVE-2024-45781: Fixed strcpy overflow in ufs. (bsc#1233617)
- CVE-2024-56737: Fixed a heap-based buffer overflow in hfs. (bsc#1234958)
- CVE-2024-45782: Fixed strcpy overflow in hfs. (bsc#1233615)
- CVE-2024-45780: Fixed an overflow in tar/cpio. (bsc#1233614)
- CVE-2024-45783: Fixed a refcount overflow in hfsplus. (bsc#1233616)
- CVE-2024-45774: Fixed a heap overflow in JPEG parser. (bsc#1233609)
- CVE-2024-45775: Fixed a missing NULL check in extcmd parser. (bsc#1233610)
- CVE-2024-45776: Fixed an overflow in .MO file handling. (bsc#1233612)
- CVE-2024-45777: Fixed an integer overflow in gettext. (bsc#1233613)
- CVE-2024-45778: Fixed bfs filesystem by removing it from lockdown capable modules. (bsc#1233606)
- CVE-2024-45779: Fixed a heap overflow in bfs. (bsc#1233608)
- CVE-2024-49504: Fixed an issue that can bypass TPM-bound disk encryption on SL(E)M encrypted Images. (bsc#1229164)
- CVE-2025-0624: Fixed an out-of-bounds write during the network boot process. (bsc#1236316)
- CVE-2025-0622: Fixed a use-after-free when handling hooks during module unload in command/gpg . (bsc#1236317)
- CVE-2025-0690: Fixed an integer overflow that may lead to an out-of-bounds write through the read command.
  (bsc#1237012)
- CVE-2025-1118: Fixed an issue where the dump command was not being blocked when grub was in lockdown mode.
  (bsc#1237013)
- CVE-2025-0677: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in ufs.
  (bsc#1237002)
- CVE-2025-0684: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in reiserfs.
  (bsc#1237008)
- CVE-2025-0685: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in jfs.
  (bsc#1237009)
- CVE-2025-0686: Fixed an integer overflow that may lead to an out-of-bounds write when handling symlinks in romfs.
  (bsc#1237010)
- CVE-2025-0689: Fixed a heap-based buffer overflow in udf that may lead to arbitrary code execution. (bsc#1237011)
- CVE-2025-1125: Fixed an integer overflow that may lead to an out-of-bounds write in hfs. (bsc#1237014)
- CVE-2025-0678: Fixed an integer overflow that may lead to an out-of-bounds write in squash4. (bsc#1237006)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:598-1
Released:    Wed Feb 19 14:07:12 2025
Summary:     Recommended update for kernel-firmware
Type:        recommended
Severity:    moderate
References:  1236196
This update for kernel-firmware fixes the following issues:

- Version upgrade 20250122
  * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
  * firmware update for various devices: 
    amdgpu, amlogic, mediatek MT7925, qcom, iwlwifi, rtw89, cirrus, rtl_bt
- Add missing license entries


The following package changes have been done:

- grub2-i386-pc-2.12-150600.8.18.2 updated
- grub2-x86_64-efi-2.12-150600.8.18.2 updated
- grub2-2.12-150600.8.18.2 updated
- kernel-firmware-bnx2-20250122-150600.3.12.3 updated
- kernel-firmware-chelsio-20250122-150600.3.12.3 updated
- kernel-firmware-i915-20250122-150600.3.12.3 updated
- kernel-firmware-intel-20250122-150600.3.12.3 updated
- kernel-firmware-liquidio-20250122-150600.3.12.3 updated
- kernel-firmware-marvell-20250122-150600.3.12.3 updated
- kernel-firmware-mediatek-20250122-150600.3.12.3 updated
- kernel-firmware-mellanox-20250122-150600.3.12.3 updated
- kernel-firmware-network-20250122-150600.3.12.3 updated
- kernel-firmware-platform-20250122-150600.3.12.3 updated
- kernel-firmware-qlogic-20250122-150600.3.12.3 updated
- kernel-firmware-realtek-20250122-150600.3.12.3 updated
- kernel-firmware-usb-network-20250122-150600.3.12.3 updated


More information about the sle-container-updates mailing list