SUSE-CU-2025:3426-1: Security update of suse/sles/15.7/virt-launcher

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu May 15 07:26:48 UTC 2025


SUSE Container Update Advisory: suse/sles/15.7/virt-launcher
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2025:3426-1
Container Tags        : suse/sles/15.7/virt-launcher:1.5.0 , suse/sles/15.7/virt-launcher:1.5.0-150700.1.3 , suse/sles/15.7/virt-launcher:1.5.0.34.138
Container Release     : 34.138
Severity              : important
Type                  : security
References            : 1232234 1234128 1234452 1234713 1235481 1235751 1236033 1237374
                        1239883 1240414 CVE-2024-10041 CVE-2025-31115 
-----------------------------------------------------------------

The container suse/sles/15.7/virt-launcher was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1134-1
Released:    Thu Apr  3 16:17:44 2025
Summary:     Security update for apparmor
Type:        security
Severity:    moderate
References:  1234452
This update for apparmor fixes the following issue:

- Allow dovecot-auth to execute unix check password from /sbin, not only from /usr/bin (bsc#1234452).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1137-1
Released:    Thu Apr  3 17:11:02 2025
Summary:     Security update for xz
Type:        security
Severity:    important
References:  1240414,CVE-2025-31115
This update for xz fixes the following issues:

- CVE-2025-31115: Fixed heap use after free and writing to an address based on the null pointer plus an offset (bsc#1240414)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1161-1
Released:    Mon Apr  7 17:29:45 2025
Summary:     Recommended update for vim
Type:        recommended
Severity:    moderate
References:  1235751
This update for vim fixes the following issues:

- Regression patch to fix (bsc#1235751).
- Version update 9.1.1176

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1198-1
Released:    Fri Apr 11 09:46:09 2025
Summary:     Recommended update for glibc
Type:        recommended
Severity:    important
References:  1234128,1234713,1239883
This update for glibc fixes the following issues:

- Fix the lost wakeup from a bug in signal stealing (bsc#1234128)
- Mark functions in libc_nonshared.a as hidden (bsc#1239883)
- Bump minimal kernel version to 4.3 to enable use of direct socketcalls
  on x86-32 and s390x (bsc#1234713)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1242-1
Released:    Mon Apr 14 12:43:18 2025
Summary:     Recommended update for aaa_base
Type:        recommended
Severity:    moderate
References:  1235481,1236033
This update for aaa_base fixes the following issues:

- SP6 logrotate and rcsyslog binary (bsc#1236033)
- Update detection for systemd in rc.status
- Mountpoint for cgroup changed with cgroup2
- If a user switches the login shell respect the already set PATH
  environment (bsc#1235481)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1245-1
Released:    Mon Apr 14 13:31:49 2025
Summary:     Recommended update for pkg-config
Type:        recommended
Severity:    moderate
References:  1237374
This update for rsync fixes the following issues:

- Security scan found old glib in pkg-config (bsc#1237374).
- This update for pkg-config changes attribute to the author who actually
  makes the change

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1291-1
Released:    Wed Apr 16 09:41:51 2025
Summary:     Recommended update for timezone
Type:        recommended
Severity:    moderate
References:  
This update for timezone fixes the following issues:

- Version update 2025b
  * New zone for Aysen Region in Chile (America/Coyhaique) which
    moves from -04/-03 to -03
- Refresh patches for philippines historical data and china tzdata

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1334-1
Released:    Thu Apr 17 09:03:05 2025
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1232234,CVE-2024-10041
This update for pam fixes the following issues:

- CVE-2024-10041: sensitive data exposure while performing authentications. (bsc#1232234)


The following package changes have been done:

- glibc-2.38-150600.14.29.1 updated
- liblzma5-5.4.1-150600.3.3.1 updated
- libzstd1-1.5.7-150700.1.2 updated
- libuuid1-2.40.4-150700.2.4 updated
- libsmartcols1-2.40.4-150700.2.4 updated
- libnghttp2-14-1.64.0-150700.1.5 updated
- libgpg-error0-1.50-150700.1.8 updated
- libglib-2_0-0-2.78.6-150600.4.11.1 updated
- findutils-4.10.0-150700.2.6 updated
- libgcrypt20-1.11.0-150700.3.5 updated
- libblkid1-2.40.4-150700.2.4 updated
- libxml2-2-2.12.10-150700.2.1 updated
- libopenssl3-3.2.3-150700.3.20 updated
- grep-3.11-150700.1.8 updated
- libmount1-2.40.4-150700.2.4 updated
- libfdisk1-2.40.4-150700.2.4 updated
- libopenssl-3-fips-provider-3.2.3-150700.3.20 updated
- sles-release-15.7-150700.28.1 updated
- permissions-20240826-150700.14.4 updated
- pam-1.3.0-150000.6.76.1 updated
- util-linux-2.40.4-150700.2.4 updated
- aaa_base-84.87+git20180409.04c9dae-150300.10.28.2 updated
- timezone-2025b-150600.91.6.2 updated
- kbd-2.4.0-150700.13.3 updated
- kubevirt-container-disk-1.5.0-150700.1.3 updated
- libapparmor1-3.1.7-150600.5.6.1 updated
- libbpf1-1.5.0-150700.1.3 updated
- libdevmapper1_03-2.03.24_1.02.198-150700.5.3 updated
- libexpat1-2.6.4-150700.1.4 updated
- libgmodule-2_0-0-2.78.6-150600.4.11.1 updated
- libgobject-2_0-0-2.78.6-150600.4.11.1 updated
- libnettle8-3.10.1-150700.2.16 updated
- libusdm0-24.09.0-150700.1.3 updated
- pkg-config-0.29.2-150600.15.6.3 updated
- qemu-accel-tcg-x86-9.2.2-150700.1.4 updated
- qemu-hw-usb-host-9.2.2-150700.1.4 updated
- qemu-ipxe-9.2.2-150700.1.4 updated
- qemu-seabios-9.2.21.16.3_3_g3d33c746-150700.1.4 updated
- qemu-vgabios-9.2.21.16.3_3_g3d33c746-150700.1.4 updated
- vim-data-common-9.1.1176-150500.20.24.2 updated
- xz-5.4.1-150600.3.3.1 updated
- zstd-1.5.7-150700.1.2 updated
- libndctl6-80-150700.1.3 updated
- libhogweed6-3.10.1-150700.2.16 updated
- virtiofsd-1.12.0-150700.1.8 updated
- qemu-hw-usb-redirect-9.2.2-150700.1.4 updated
- libqat4-24.09.0-150700.1.3 updated
- iproute2-6.4-150600.7.6.1 updated
- vim-small-9.1.1176-150500.20.24.2 updated
- xen-libs-4.20.0_10-150700.1.3 updated
- libqatzip3-1.2.0-150700.1.2 updated
- qemu-img-9.2.2-150700.1.4 updated
- libgio-2_0-0-2.78.6-150600.4.11.1 updated
- glib2-tools-2.78.6-150600.4.11.1 updated
- libvirt-libs-11.0.0-150700.2.3 updated
- rdma-core-54.0-150700.1.9 updated
- libvirt-daemon-log-11.0.0-150700.2.3 updated
- libvirt-client-11.0.0-150700.2.3 updated
- kubevirt-virt-launcher-1.5.0-150700.1.3 updated
- swtpm-0.9.0-150700.1.4 updated
- libibverbs1-54.0-150700.1.9 updated
- libmlx5-1-54.0-150700.1.9 updated
- libvirt-daemon-common-11.0.0-150700.2.3 updated
- libmlx4-1-54.0-150700.1.9 updated
- libmana1-54.0-150700.1.9 updated
- libhns1-54.0-150700.1.9 updated
- libefa1-54.0-150700.1.9 updated
- libibverbs-54.0-150700.1.9 updated
- librdmacm1-54.0-150700.1.9 updated
- qemu-ovmf-x86_64-202408-150700.1.3 updated
- qemu-x86-9.2.2-150700.1.4 updated
- qemu-9.2.2-150700.1.4 updated
- libvirt-daemon-driver-qemu-11.0.0-150700.2.3 updated
- container:sles15-image-15.7.0-3.68 updated


More information about the sle-container-updates mailing list