SUSE Container Update Advisory: bci/bci-init
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2022:1401-1
Container Tags        : bci/bci-init:15.3 , bci/bci-init:15.3.15.14
Container Release     : 15.14
Severity              : moderate
Type                  : security
References            : 1185637 1192951 1193659 1195283 1196861 1197065 1199166 1200550
                        CVE-2022-1292 CVE-2022-2068 
-----------------------------------------------------------------

The container bci/bci-init was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:2019-1
Released:    Wed Jun  8 16:50:07 2022
Summary:     Recommended update for gcc11
Type:        recommended
Severity:    moderate
References:  1192951,1193659,1195283,1196861,1197065
This update for gcc11 fixes the following issues:

Update to the GCC 11.3.0 release.

* includes SLS hardening backport on x86_64.  [bsc#1195283]
* includes change to adjust gnats idea of the target, fixing the build of gprbuild.  [bsc#1196861]
* fixed miscompile of embedded premake in 0ad on i586.  [bsc#1197065]
* use --with-cpu rather than specifying --with-arch/--with-tune 
* Fix D memory corruption in -M output.
* Fix ICE in is_this_parameter with coroutines.  [bsc#1193659]
* fixes issue with debug dumping together with -o /dev/null
* fixes libgccjit issue showing up in emacs build  [bsc#1192951]
* Package mwaitintrin.h

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:2251-1
Released:    Mon Jul  4 09:52:25 2022
Summary:     Security update for openssl-1_1
Type:        security
Severity:    moderate
References:  1185637,1199166,1200550,CVE-2022-1292,CVE-2022-2068
This update for openssl-1_1 fixes the following issues:
	  
- CVE-2022-1292: Fixed command injection in c_rehash (bsc#1199166).
- CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550)


The following package changes have been done:

- libgcc_s1-11.3.0+git1637-150000.1.9.1 updated
- libopenssl1_1-hmac-1.1.1d-150200.11.48.1 updated
- libopenssl1_1-1.1.1d-150200.11.48.1 updated
- libstdc++6-11.3.0+git1637-150000.1.9.1 updated
- openssl-1_1-1.1.1d-150200.11.48.1 updated
- container:sles15-image-15.0.0-17.17.19 updated

SUSE: 2022:1401-1 bci/bci-init Security Update

July 5, 2022
The container bci/bci-init was updated

Summary

Advisory ID: SUSE-RU-2022:2019-1 Released: Wed Jun 8 16:50:07 2022 Summary: Recommended update for gcc11 Type: recommended Severity: moderate Advisory ID: SUSE-SU-2022:2251-1 Released: Mon Jul 4 09:52:25 2022 Summary: Security update for openssl-1_1 Type: security Severity: moderate

References

References : 1185637 1192951 1193659 1195283 1196861 1197065 1199166 1200550

CVE-2022-1292 CVE-2022-2068

1192951,1193659,1195283,1196861,1197065

This update for gcc11 fixes the following issues:

Update to the GCC 11.3.0 release.

* includes SLS hardening backport on x86_64. [bsc#1195283]

* includes change to adjust gnats idea of the target, fixing the build of gprbuild. [bsc#1196861]

* fixed miscompile of embedded premake in 0ad on i586. [bsc#1197065]

* use --with-cpu rather than specifying --with-arch/--with-tune

* Fix D memory corruption in -M output.

* Fix ICE in is_this_parameter with coroutines. [bsc#1193659]

* fixes issue with debug dumping together with -o /dev/null

* fixes libgccjit issue showing up in emacs build [bsc#1192951]

* Package mwaitintrin.h

1185637,1199166,1200550,CVE-2022-1292,CVE-2022-2068

This update for openssl-1_1 fixes the following issues:

- CVE-2022-1292: Fixed command injection in c_rehash (bsc#1199166).

- CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550)

The following package changes have been done:

- libgcc_s1-11.3.0+git1637-150000.1.9.1 updated

- libopenssl1_1-hmac-1.1.1d-150200.11.48.1 updated

- libopenssl1_1-1.1.1d-150200.11.48.1 updated

- libstdc++6-11.3.0+git1637-150000.1.9.1 updated

- openssl-1_1-1.1.1d-150200.11.48.1 updated

- container:sles15-image-15.0.0-17.17.19 updated

Severity
Container Advisory ID : SUSE-CU-2022:1401-1
Container Tags : bci/bci-init:15.3 , bci/bci-init:15.3.15.14
Container Release : 15.14
Severity : moderate
Type : security

Related News