SUSE Container Update Advisory: suse/sles12sp5 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:3881-1 Container Tags : suse/sles12sp5:6.8.35 , suse/sles12sp5:latest Container Release : 6.8.35 Severity : important Type : security References : 1219559 1221563 1222285 1226095 1227138 1227227 1228291 1229339 CVE-2023-52425 CVE-2024-5535 ----------------------------------------------------------------- The container suse/sles12sp5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2965-1 Released: Mon Aug 19 15:32:07 2024 Summary: Recommended update for util-linux Type: recommended Severity: important References: 1222285 This update for util-linux fixes the following issues: - Don't delete binaries not common for all architectures. Create an util-linux-extra subpackage instead, so users of third party tools can use them (bsc#1222285). - fix Xen virtualization type misidentification. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2972-1 Released: Tue Aug 20 08:14:12 2024 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1226095 This update for systemd fixes the following issues: - Dynamically allocate the receive buffer (bsc#1226095) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2989-1 Released: Tue Aug 20 16:17:10 2024 Summary: Security update for openssl-1_0_0 Type: security Severity: moderate References: 1227138,1227227,1228291,CVE-2024-5535 This update for openssl-1_0_0 fixes the following issues: - CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138, bsc#1227227) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3004-1 Released: Fri Aug 23 13:27:40 2024 Summary: Security update for expat Type: security Severity: moderate References: 1219559,1221563,CVE-2023-52425 This update for expat fixes the following issues: - CVE-2023-52425: denial of service (resource consumption) caused by processing large tokens (bsc#1219559) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3011-1 Released: Mon Aug 26 13:15:05 2024 Summary: Recommended update for suse-build-key Type: recommended Severity: moderate References: 1229339 This update for suse-build-key fixes the following issue: - extended 2048 bit SUSE SLE 12, 15 GA-SP5 key until 2028 (bsc#1229339). The following package changes have been done: - libblkid1-2.33.2-4.42.4 updated - libexpat1-2.1.0-21.32.1 updated - libfdisk1-2.33.2-4.42.4 updated - libmount1-2.33.2-4.42.4 updated - libopenssl1_0_0-1.0.2p-3.95.1 updated - libsmartcols1-2.33.2-4.42.4 updated - libsystemd0-228-157.63.1 updated - libudev1-228-157.63.1 updated - libuuid1-2.33.2-4.42.4 updated - openssl-1_0_0-1.0.2p-3.95.1 updated - suse-build-key-12.0-7.19.1 updated - util-linux-2.33.2-4.42.4 updated