SUSE-CU-2023:785-1: Security update of suse/sle15
sle-security-updates at lists.suse.com
sle-security-updates at lists.suse.com
Sat Mar 25 08:04:06 UTC 2023
SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:785-1
Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.115 , suse/sle15:15.3 , suse/sle15:15.3.17.20.115
Container Release : 17.20.115
Severity : important
Type : security
References : 1200441 1206134 1208270 1208271 1208272 1209030 CVE-2022-41720
CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532
-----------------------------------------------------------------
The container suse/sle15 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:871-1
Released: Wed Mar 22 14:32:45 2023
Summary: Security update for container-suseconnect
Type: security
Severity: important
References: 1200441,1206134,1208270,1208271,1208272,1209030,CVE-2022-41720,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532
This update of container-suseconnect fixes the following issue:
- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.
- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).
- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).
- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).
- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).
The following package changes have been done:
- container-suseconnect-2.4.0-150000.4.24.1 updated
More information about the sle-security-updates
mailing list