SUSE Container Update Advisory: rancher/elemental-rt-channel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:1544-1 Container Tags : rancher/elemental-rt-channel:1.4.3 , rancher/elemental-rt-channel:1.4.3-2.2.122 , rancher/elemental-rt-channel:latest Container Release : 2.2.122 Severity : moderate Type : security References : 1217445 1217589 1218866 1220441 ----------------------------------------------------------------- The container rancher/elemental-rt-channel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:870-1 Released: Wed Mar 13 13:05:14 2024 Summary: Security update for glibc Type: security Severity: moderate References: 1217445,1217589,1218866 This update for glibc fixes the following issues: Security issues fixed: - qsort: harden handling of degenerated / non transient compare function (bsc#1218866) Other issues fixed: - getaddrinfo: translate ENOMEM to EAI_MEMORY (bsc#1217589, BZ #31163) - aarch64: correct CFI in rawmemchr (bsc#1217445, BZ #31113) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1231-1 Released: Thu Apr 11 15:20:40 2024 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1220441 This update for glibc fixes the following issues: - duplocale: protect use of global locale (bsc#1220441, BZ #23970) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1272-1 Released: Fri Apr 12 16:24:28 2024 Summary: Recommended update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, operator-image Type: recommended Severity: moderate References: This update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, operator-image contains the following fixes: - Update to version 1.4.3: * registration: allow dots in machineInventory names * registration: decouple replacing data-labels from sanitizing strings * registration: move sanitize code in sanitizeString() * V1.4.x fix channel synchronization (#683) * linter: fix copyright dates * Make linter happy The following package changes have been done: - glibc-2.31-150300.71.1 updated - elemental-register-1.4.3-150500.3.3.3 updated - aaa_base-84.87+git20180409.04c9dae-150300.10.6.2 removed - bash-4.4-150400.25.22 removed - bash-sh-4.4-150400.25.22 removed - cni-1.1.2-150500.3.2.1 removed - coreutils-8.32-150400.7.5 removed - cpio-2.13-150400.3.3.1 removed - cracklib-2.9.7-11.6.1 removed - cracklib-dict-small-2.9.7-11.6.1 removed - dbus-1-1.12.2-150400.18.8.1 removed - diffutils-3.6-4.3.1 removed - file-5.32-7.14.1 removed - file-magic-5.32-7.14.1 removed - fillup-1.42-2.18 removed - findutils-4.8.0-1.20 removed - gawk-4.2.1-150000.3.3.1 removed - gettext-runtime-0.20.2-1.43 removed - glibc-locale-base-2.31-150300.63.1 removed - gpg2-2.2.27-150300.3.8.1 removed - grep-3.1-150000.4.6.1 removed - gzip-1.10-150200.10.1 removed - hostname-3.16-2.22 removed - info-6.5-4.17 removed - iproute2-5.14-150400.1.8 removed - kbd-2.4.0-150400.5.6.1 removed - kbd-legacy-2.4.0-150400.5.6.1 removed - krb5-1.20.1-150500.3.3.1 removed - libacl1-2.2.52-4.3.1 removed - libapparmor1-3.0.4-150500.11.9.1 removed - libargon2-1-0.0+git20171227.670229c-2.14 removed - libassuan0-2.5.5-150000.4.5.2 removed - libattr1-2.4.47-2.19 removed - libaudit1-3.0.6-150400.4.13.1 removed - libblkid1-2.37.4-150500.9.3.1 removed - libbrotlicommon1-1.0.7-3.3.1 removed - libbrotlidec1-1.0.7-3.3.1 removed - libbz2-1-1.0.8-150400.1.122 removed - libcap-ng0-0.7.9-4.37 removed - libcap2-2.63-150400.3.3.1 removed - libcom_err2-1.46.4-150400.3.3.1 removed - libcontainers-common-20230214-150500.4.6.1 removed - libcontainers-sles-mounts-20230214-150500.4.6.1 removed - libcrack2-2.9.7-11.6.1 removed - libcrypt1-4.4.15-150300.4.7.1 removed - libcryptsetup12-2.4.3-150400.3.3.1 removed - libcurl4-8.0.1-150400.5.41.1 removed - libdbus-1-3-1.12.2-150400.18.8.1 removed - libdevmapper1_03-2.03.22_1.02.196-150500.7.9.1 removed - libdw1-0.185-150400.5.3.1 removed - libeconf0-0.5.2-150400.3.6.1 removed - libelf1-0.185-150400.5.3.1 removed - libexpat1-2.4.4-150400.3.12.1 removed - libfdisk1-2.37.4-150500.9.3.1 removed - libffi7-3.2.1.git259-10.8 removed - libgcc_s1-13.2.1+git7813-150000.1.6.1 removed - libgcrypt20-1.9.4-150500.10.19 removed - libgdbm4-1.12-1.418 removed - libglib-2_0-0-2.70.5-150400.3.8.1 removed - libgmp10-6.1.2-4.9.1 removed - libgpg-error0-1.42-150400.1.101 removed - libgpgme11-1.16.0-150400.1.80 removed - libidn2-0-2.2.0-3.6.1 removed - libip4tc2-1.8.7-1.1 removed - libjitterentropy3-3.4.0-150000.1.9.1 removed - libjson-c3-0.13-3.3.1 removed - libkeyutils1-1.6.3-5.6.1 removed - libkmod2-29-4.15.1 removed - libksba8-1.3.5-150000.4.6.1 removed - libldap-2_4-2-2.4.46-150200.14.17.1 removed - libldap-data-2.4.46-150200.14.17.1 removed - libltdl7-2.4.6-3.4.1 removed - liblua5_3-5-5.3.6-3.6.1 removed - liblz4-1-1.9.3-150400.1.7 removed - liblzma5-5.2.3-150000.4.7.1 removed - libmagic1-5.32-7.14.1 removed - libmnl0-1.0.4-1.25 removed - libmount1-2.37.4-150500.9.3.1 removed - libmspack0-0.6-3.14.1 removed - libncurses6-6.1-150000.5.20.1 removed - libnghttp2-14-1.40.0-150200.12.1 removed - libnpth0-1.5-2.11 removed - libnsl2-1.2.0-2.44 removed - libopenssl1_1-1.1.1l-150500.17.22.1 removed - libp11-kit0-0.23.22-150500.8.3.1 removed - libpcre1-8.45-150000.20.13.1 removed - libpcre2-8-0-10.39-150400.4.9.1 removed - libpopt0-1.16-3.22 removed - libpsl5-0.20.1-150000.3.3.1 removed - libreadline7-7.0-150400.25.22 removed - libsasl2-3-2.1.28-150500.1.1 removed - libseccomp2-2.5.3-150400.2.4 removed - libselinux1-3.4-150500.1.12 removed - libsemanage-conf-3.4-150500.1.12 removed - libsemanage2-3.4-150500.1.12 removed - libsepol2-3.4-150500.1.18 removed - libslirp0-4.7.0+44-150500.2.1 removed - libsmartcols1-2.37.4-150500.9.3.1 removed - libsqlite3-0-3.44.0-150000.3.23.1 removed - libssh-config-0.9.8-150400.3.3.1 removed - libssh4-0.9.8-150400.3.3.1 removed - libstdc++6-13.2.1+git7813-150000.1.6.1 removed - libsystemd0-249.17-150400.8.40.1 removed - libtextstyle0-0.20.2-1.43 removed - libtirpc-netconfig-1.3.4-150300.3.23.1 removed - libtirpc3-1.3.4-150300.3.23.1 removed - libudev1-249.17-150400.8.40.1 removed - libunistring2-0.9.10-1.1 removed - libusb-1_0-0-1.0.24-150400.3.3.1 removed - libutempter0-1.1.6-3.42 removed - libuuid1-2.37.4-150500.9.3.1 removed - libverto1-0.2.6-3.20 removed - libxml2-2-2.10.3-150500.5.11.1 removed - libxslt1-1.1.34-150400.3.3.1 removed - libxtables12-1.8.7-1.1 removed - libz1-1.2.13-150500.4.3.1 removed - libzio1-1.06-2.20 removed - libzstd1-1.5.0-150400.3.3.1 removed - login_defs-4.8.1-150500.1.10 removed - ncurses-utils-6.1-150000.5.20.1 removed - netcfg-11.6-3.3.1 removed - pam-1.3.0-150000.6.66.1 removed - pam-config-1.1-3.3.1 removed - perl-5.26.1-150300.17.14.1 removed - perl-base-5.26.1-150300.17.14.1 removed - permissions-20201225-150400.5.16.1 removed - pinentry-1.1.0-4.3.1 removed - pkg-config-0.29.2-1.436 removed - rpm-4.14.3-150400.59.3.1 removed - rpm-config-SUSE-1-150400.14.3.1 removed - runc-1.1.10-150000.55.1 removed - sed-4.4-11.6 removed - shadow-4.8.1-150500.1.10 removed - slirp4netns-1.2.0-150500.1.1 removed - system-group-hardware-20170617-150400.24.2.1 removed - system-user-nobody-20170617-150400.24.2.1 removed - systemd-249.17-150400.8.40.1 removed - systemd-default-settings-0.7-3.2.1 removed - systemd-default-settings-branding-SLE-0.7-3.2.1 removed - systemd-presets-common-SUSE-15-150500.20.3.1 removed - systemd-rpm-macros-14-150000.7.36.1 removed - sysuser-shadow-3.2-150400.3.5.3 removed - tar-1.34-150000.3.34.1 removed - terminfo-base-6.1-150000.5.20.1 removed - timezone-2023c-150000.75.23.1 removed - update-alternatives-1.19.0.4-150000.4.4.1 removed - util-linux-2.37.4-150500.9.3.1 removed - which-2.21-2.20 removed - xz-5.2.3-150000.4.7.1 removed