SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2020:94-1 Container Tags : suse/sle15:15.0 , suse/sle15:15.0.4.22.169 Container Release : 4.22.169 Severity : moderate Type : security References : 1159003 1166106 1166481 1166848 CVE-2019-18802 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:722-1 Released: Thu Mar 19 11:21:57 2020 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1159003,1166481,CVE-2019-18802 This update for nghttp2 fixes the following issues: nghttp2 was update to version 1.40.0 (bsc#1166481) - lib: Add nghttp2_check_authority as public API - lib: Fix the bug that stream is closed with wrong error code - lib: Faster huffman encoding and decoding - build: Avoid filename collision of static and dynamic lib - build: Add new flag ENABLE_STATIC_CRT for Windows - build: cmake: Support building nghttpx with systemd - third-party: Update neverbleed to fix memory leak - nghttpx: Fix bug that mruby is incorrectly shared between backends - nghttpx: Reconnect h1 backend if it lost connection before sending headers - nghttpx: Returns 408 if backend timed out before sending headers - nghttpx: Fix request stal ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:727-1 Released: Thu Mar 19 13:57:15 2020 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1166848 This update for openssl-1_1 fixes the following issues: - Fix a locking issue uncovered by the python testsuite (bsc#1166848) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:729-1 Released: Thu Mar 19 14:44:22 2020 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1166106 This update for glibc fixes the following issues: - Allow dlopen of filter object to work (bsc#1166106, BZ #16272) The following package changes have been done: - glibc-2.26-13.42.1 updated - libnghttp2-14-1.40.0-3.6.3 updated - libopenssl1_1-1.1.0i-4.44.1 updated - openssl-1_1-1.1.0i-4.44.1 updated