SUSE-CU-2023:802-1: Security update of suse/sle15
sle-security-updates at lists.suse.com
sle-security-updates at lists.suse.com
Tue Mar 28 07:05:11 UTC 2023
SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2023:802-1
Container Tags : suse/sle15:15.2 , suse/sle15:15.2.9.5.277
Container Release : 9.5.277
Severity : important
Type : security
References : 1200441 1206134 1208270 1208271 1208272 1209030 CVE-2022-41720
CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-24532
-----------------------------------------------------------------
The container suse/sle15 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:871-1
Released: Wed Mar 22 14:32:45 2023
Summary: Security update for container-suseconnect
Type: security
Severity: important
References: 1200441,1206134,1208270,1208271,1208272,1209030,CVE-2022-41720,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725,CVE-2023-24532
This update of container-suseconnect fixes the following issue:
- container-suseconnect was rebuilt against the current go1.19 release, fixing security issues and other bugs fixed in go1.19.7.
- CVE-2022-41723: Fixed quadratic complexity in HPACK decoding (bsc#1208270).
- CVE-2022-41724: Fixed panic with arge handshake records in crypto/tls (bsc#1208271).
- CVE-2022-41725: Fixed denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208272).
- CVE-2023-24532: Fixed incorrect P-256 ScalarMult and ScalarBaseMult results (bsc#1209030).
- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134).
The following package changes have been done:
- container-suseconnect-2.4.0-150000.4.24.1 updated
More information about the sle-security-updates
mailing list