SUSE-CU-2025:5096-1: Security update of bci/gcc
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Jul 9 07:16:16 UTC 2025
SUSE Container Update Advisory: bci/gcc
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2025:5096-1
Container Tags : bci/gcc:14 , bci/gcc:14.2 , bci/gcc:14.2-10.16 , bci/gcc:latest
Container Release : 10.16
Severity : moderate
Type : security
References : 1240366 1242827 1243935 CVE-2025-27587 CVE-2025-4598
-----------------------------------------------------------------
The container bci/gcc was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2236-1
Released: Mon Jul 7 14:58:53 2025
Summary: Security update for openssl-3
Type: security
Severity: moderate
References: 1240366,CVE-2025-27587
This update for openssl-3 fixes the following issues:
- CVE-2025-27587: Fixed Minerva side channel vulnerability in P-384 (bsc#1240366).
- Backport mdless cms signing support [jsc#PED-12895]
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2244-1
Released: Tue Jul 8 10:44:02 2025
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1242827,1243935,CVE-2025-4598
This update for systemd fixes the following issues:
- CVE-2025-4598: Fixed race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump (bsc#1243935).
Other bugfixes:
- logs-show: get timestamp and boot ID only when necessary (bsc#1242827).
The following package changes have been done:
- libopenssl3-3.2.3-150700.5.10.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.10.1 updated
- libsystemd0-254.25-150600.4.40.1 updated
- container:registry.suse.com-bci-bci-base-15.7-5796b2ea9eb033483ca60e09f9a5a6445df5299e288d32559b320afb2adb50ae-0 updated
More information about the sle-container-updates
mailing list