SUSE Container Update Advisory: ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:848-1 Container Tags : suse/sle-micro-rancher/5.3:latest Container Release : 7.2.119 Severity : moderate Type : security References : 1203201 1206483 1206772 1207868 1208595 1209361 1209362 1209533 CVE-2022-4899 CVE-2023-27320 CVE-2023-28486 CVE-2023-28487 ----------------------------------------------------------------- The container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1661-1 Released: Wed Mar 29 10:24:43 2023 Summary: Recommended update for mdadm Type: recommended Severity: moderate References: 1207868 This update for mdadm fixes the following issue: - Update the enable Intel Alderlake RSTe-configuration patca (bsc#1207868) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1665-1 Released: Wed Mar 29 12:55:13 2023 Summary: Security update for sudo Type: security Severity: moderate References: 1203201,1206483,1206772,1208595,1209361,1209362,CVE-2023-27320,CVE-2023-28486,CVE-2023-28487 This update for sudo fixes the following issue: Security issues: - CVE-2023-28486: Fixed sudo does not escape control characters in log messages. (bsc#1209362) - CVE-2023-28487: Fixed sudo does not escape control characters in sudoreplay output. (bsc#1209361) - CVE-2023-27320: Fixed a potential security issue with a double free with per-command chroot sudoers rules (bsc#1208595). Bug fixes: - Fix a situation where 'sudo -U otheruser -l' would dereference a NULL pointer (bsc#1206483) - If NOPASSWD is specified, don't ask for password if command is not found (bsc#1206772). - Do not re-enable the reader when flushing the buffers as part of pty_finish() (bsc#1203201). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1688-1 Released: Wed Mar 29 18:19:10 2023 Summary: Security update for zstd Type: security Severity: moderate References: 1209533,CVE-2022-4899 This update for zstd fixes the following issues: - CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533). The following package changes have been done: - libzstd1-1.5.0-150400.3.3.1 updated - mdadm-4.1-150300.24.24.2 updated - sudo-1.9.9-150400.4.26.1 updated - zstd-1.5.0-150400.3.3.1 updated