SUSE: 2019:1514-1 moderate: docker
Summary
This update for docker fixes the following issues: Security issue fixed: - CVE-2018-15664: Fixed an issue which made docker cp vulnerable to symlink-exchange race attacks (bsc#1096726). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2019-1514=1 - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-1514=1 Package List: - SUSE Linux Enterprise Module for Containers 12 (ppc64le s390x x86_64): docker-18.09.6_ce-98.40.1 docker-debuginfo-18.09.6_ce-98.40.1 docker-debugsource-18.09.6_ce-98.40.1 - SUSE CaaS Platform 3.0 (x86_64): docker-kubic-18.09.6_ce-98.40.1 docker-kubic-debuginfo-18.09.6_ce-98.40.1 docker-kubic-debugsource-18.09.6_ce-98.40.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): docker-18.09.6_ce-98.40.1 docker-debuginfo-18.09.6_ce-98.40.1 docker-debugsource-18.09.6_ce-98.40.1
References
#1096726
Cross- CVE-2018-15664
Affected Products:
SUSE Linux Enterprise Module for Containers 12
SUSE CaaS Platform 3.0
OpenStack Cloud Magnum Orchestration 7
https://www.suse.com/security/cve/CVE-2018-15664.html
https://bugzilla.suse.com/1096726