SUSE_ALP_Standard/patchinfo.20241113113421635840.269002615871826/_patchinfo

48 lines
2.3 KiB
Plaintext
Raw Normal View History

2024-12-18 17:40:54 +01:00
<patchinfo incident="147">
<!-- generated from request(s) 344275 -->
<issue tracker="bnc" id="1200528">VUL-0: CVE-2022-1996: go-restful: CORS bypass</issue>
<issue tracker="bnc" id="1217070">VUL-0: CVE-2023-47108: TRACKERBUG: otelgrpc: DoS vulnerability in otelgrpc (uncontrolled resource consumption) due to unbound cardinality metrics</issue>
<issue tracker="bnc" id="1221400">VUL-0: CVE-2023-45288: go1.21,go1.22: net/http, x/net/http2: close connections when receiving too many headers</issue>
<issue tracker="bnc" id="1224323">VUL-0: containerd: mitigate power-based side channel attacks (advisory GHSA-jq35-85cj-fj4p)</issue>
<issue tracker="bnc" id="1228553">VUL-0: CVE-2023-45142: TRACKERBUG: otelhttp,otelhttptrace,otelrestful: DoS vulnerability</issue>
<issue tracker="cve" id="2022-1996"/>
<issue tracker="cve" id="2023-45142"/>
<issue tracker="cve" id="2023-45288"/>
<issue tracker="cve" id="2023-47108"/>
<packager>cyphar</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for containerd</summary>
<description>This update for containerd fixes the following issues:
- Update to containerd v1.7.21. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.21
Fixes CVE-2023-47108. bsc#1217070
Fixes CVE-2023-45142. bsc#1228553
- Update to containerd v1.7.17. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.17
- Update to containerd v1.7.16. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.16
CVE-2023-45288 bsc#1221400
- Update to containerd v1.7.15. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.15
- Update to containerd v1.7.14. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.14
- Update to containerd v1.7.13. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.13
- Update to containerd v1.7.12. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.12
- Update to containerd v1.7.11. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.11
GHSA-jq35-85cj-fj4p bsc#1224323
</description>
<package>containerd</package>
<seperate_build_arch/>
2024-12-18 17:40:54 +01:00
</patchinfo>