SUSE-CU-2023:776-1: Security update of suse/sle15

sle-security-updates at sle-security-updates at
Thu Mar 23 08:04:58 UTC 2023

SUSE Container Update Advisory: suse/sle15
Container Advisory ID : SUSE-CU-2023:776-1
Container Tags        : suse/sle15:15.1 , suse/sle15:
Container Release     : 6.2.748
Severity              : important
Type                  : security
References            : 1200441 1206134 1208270 1208271 1208272 1209030 CVE-2022-41720
                        CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532 

The container suse/sle15 was updated. The following patches have been included in this update:

Advisory ID: SUSE-SU-2023:871-1
Released:    Wed Mar 22 14:32:45 2023
Summary:     Security update for container-suseconnect
Type:        security
Severity:    important
References:  1200441,1206134,1208270,1208271,1208272,1209030,CVE-2022-41720,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532

This update of container-suseconnect fixes the following issue:

- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.

- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).
- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).
- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).

- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).

The following package changes have been done:

- container-suseconnect-2.4.0-150000.4.24.1 updated

More information about the sle-security-updates mailing list