Container summary for suse/sle-micro/5.5


SUSE-IU-2024:1603-1

Container Advisory IDSUSE-IU-2024:1603-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.170 , suse/sle-micro/5.5:latest
Container Release5.5.170
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3753-1
ReleasedThu Oct 24 05:34:09 2024
SummarySecurity update for podman
Typesecurity
Severitymoderate
References1231698,CVE-2024-9676
Description:

This update for podman fixes the following issues:


SUSE-IU-2024:1584-1

Container Advisory IDSUSE-IU-2024:1584-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.169 , suse/sle-micro/5.5:latest
Container Release5.5.169
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3741-1
ReleasedMon Oct 21 14:33:31 2024
SummarySecurity update for podman
Typesecurity
Severitymoderate
References1214612,1231208,1231499,CVE-2024-9407,CVE-2024-9675
Description:

This update for podman fixes the following issues:


The following non-security bug was fixed:


SUSE-IU-2024:1578-1

Container Advisory IDSUSE-IU-2024:1578-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.168 , suse/sle-micro/5.5:latest
Container Release5.5.168
The following patches have been included in this update:

SUSE-IU-2024:1577-1

Container Advisory IDSUSE-IU-2024:1577-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.167 , suse/sle-micro/5.5:latest
Container Release5.5.167
The following patches have been included in this update:

SUSE-IU-2024:1563-1

Container Advisory IDSUSE-IU-2024:1563-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.166 , suse/sle-micro/5.5:latest
Container Release5.5.166
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3659-1
ReleasedWed Oct 16 15:12:47 2024
SummaryRecommended update for gcc14
Typerecommended
Severitymoderate
References1188441,1210959,1214915,1219031,1220724,1221601
Description:

This update for gcc14 fixes the following issues:
This update ships the GNU Compiler Collection GCC 14.2. (jsc#PED-10474)
The compiler runtime libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 13 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP5 and SP6, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
To use gcc14 compilers use:


For a full changelog with all new GCC14 features, check out
https://gcc.gnu.org/gcc-14/changes.html



SUSE-IU-2024:1496-1

Container Advisory IDSUSE-IU-2024:1496-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.164 , suse/sle-micro/5.5:latest
Container Release5.5.164
The following patches have been included in this update:

SUSE-IU-2024:1492-1

Container Advisory IDSUSE-IU-2024:1492-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.163 , suse/sle-micro/5.5:latest
Container Release5.5.163
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3597-1
ReleasedFri Oct 11 10:39:52 2024
SummaryRecommended update for bash
Typerecommended
Severitymoderate
References1227807
Description:

This update for bash fixes the following issues:


SUSE-IU-2024:1486-1

Container Advisory IDSUSE-IU-2024:1486-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.160 , suse/sle-micro/5.5:latest
Container Release5.5.160
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3546-1
ReleasedTue Oct 8 16:04:40 2024
SummarySecurity update for podman
Typesecurity
Severitymoderate
References1231230,CVE-2024-6104,CVE-2024-9341
Description:

This update for podman fixes the following issues:


Advisory IDSUSE-RU-2024:3588-1
ReleasedThu Oct 10 15:34:10 2024
SummaryRecommended update for elemental-toolkit
Typerecommended
Severitymoderate
References
Description:

This update for elemental-toolkit contains the following fix:


SUSE-IU-2024:1462-1

Container Advisory IDSUSE-IU-2024:1462-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.155 , suse/sle-micro/5.5:latest
Container Release5.5.155
The following patches have been included in this update:

SUSE-IU-2024:1445-1

Container Advisory IDSUSE-IU-2024:1445-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.153 , suse/sle-micro/5.5:latest
Container Release5.5.153
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3521-1
ReleasedFri Oct 4 09:29:43 2024
SummaryRecommended update for dracut
Typerecommended
Severitymoderate
References1230110,1230330
Description:

This update for dracut fixes the following issue:


Advisory IDSUSE-RU-2024:3527-1
ReleasedFri Oct 4 15:27:07 2024
SummaryRecommended update for e2fsprogs
Typerecommended
Severitymoderate
References1230145
Description:

This update for e2fsprogs fixes the following issue:


SUSE-IU-2024:1438-1

Container Advisory IDSUSE-IU-2024:1438-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.149 , suse/sle-micro/5.5:latest
Container Release5.5.149
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3216-1
ReleasedThu Sep 12 13:05:20 2024
SummarySecurity update for expat
Typesecurity
Severitymoderate
References1229930,1229931,1229932,CVE-2024-45490,CVE-2024-45491,CVE-2024-45492
Description:

This update for expat fixes the following issues:


Advisory IDSUSE-SU-2024:3222-1
ReleasedThu Sep 12 13:20:47 2024
SummarySecurity update for runc
Typesecurity
Severitylow
References1230092,CVE-2024-45310
Description:

This update for runc fixes the following issues:


Advisory IDSUSE-RU-2024:3237-1
ReleasedFri Sep 13 11:49:56 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1229476
Description:

This update for util-linux fixes the following issue:


Advisory IDSUSE-RU-2024:3242-1
ReleasedFri Sep 13 15:57:29 2024
SummaryRecommended update for strace
Typerecommended
Severitymoderate
References1228216
Description:

This update for strace fixes the following issue:


Advisory IDSUSE-RU-2024:3300-1
ReleasedWed Sep 18 14:27:53 2024
SummaryRecommended update for ncurses
Typerecommended
Severitymoderate
References1229028
Description:

This update for ncurses fixes the following issues:


Advisory IDSUSE-RU-2024:3451-1
ReleasedThu Sep 26 09:10:50 2024
SummaryRecommended update for pam-config
Typerecommended
Severitymoderate
References1227216
Description:

This update for pam-config fixes the following issues:


Advisory IDSUSE-RU-2024:3477-1
ReleasedFri Sep 27 15:22:22 2024
SummaryRecommended update for curl
Typerecommended
Severitymoderate
References1230516
Description:

This update for curl fixes the following issue:


Advisory IDSUSE-RU-2024:3481-1
ReleasedFri Sep 27 15:58:46 2024
SummaryRecommended update for mdadm
Typerecommended
Severitymoderate
References1226413
Description:

This update for mdadm fixes the following issues:


Advisory IDSUSE-RU-2024:3487-1
ReleasedFri Sep 27 19:56:02 2024
SummaryRecommended update for logrotate
Typerecommended
Severitymoderate
References
Description:

This update for logrotate fixes the following issues:


Advisory IDSUSE-RU-2024:3503-1
ReleasedTue Oct 1 16:13:07 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1228661
Description:

This update for glibc fixes the following issue:


SUSE-IU-2024:1200-1

Container Advisory IDSUSE-IU-2024:1200-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.122 , suse/sle-micro/5.5:latest
Container Release5.5.122
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3211-1
ReleasedWed Sep 11 17:40:13 2024
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1230093,CVE-2024-8096
Description:

This update for curl fixes the following issues:


SUSE-IU-2024:1191-1

Container Advisory IDSUSE-IU-2024:1191-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.120 , suse/sle-micro/5.5:latest
Container Release5.5.120
The following patches have been included in this update:

SUSE-IU-2024:1181-1

Container Advisory IDSUSE-IU-2024:1181-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.119 , suse/sle-micro/5.5:latest
Container Release5.5.119
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3167-1
ReleasedMon Sep 9 12:31:59 2024
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1228043
Description:

This update for glibc fixes the following issue:


SUSE-IU-2024:1172-1

Container Advisory IDSUSE-IU-2024:1172-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.117 , suse/sle-micro/5.5:latest
Container Release5.5.117
The following patches have been included in this update:

SUSE-IU-2024:1165-1

Container Advisory IDSUSE-IU-2024:1165-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.116 , suse/sle-micro/5.5:latest
Container Release5.5.116
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3146-1
ReleasedThu Sep 5 09:14:53 2024
SummaryRecommended update for dracut
Typerecommended
Severitymoderate
References1228398,1228847
Description:

This update for dracut fixes the following issues:


Advisory IDSUSE-SU-2024:3149-1
ReleasedThu Sep 5 17:05:36 2024
SummarySecurity update for systemd
Typesecurity
Severitymoderate
References1218297,1221479,1226414,1228091,CVE-2023-7008
Description:

This update for systemd fixes the following issues:


Other fixes:


SUSE-IU-2024:1157-1

Container Advisory IDSUSE-IU-2024:1157-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.111 , suse/sle-micro/5.5:latest
Container Release5.5.111
The following patches have been included in this update:

SUSE-IU-2024:1149-1

Container Advisory IDSUSE-IU-2024:1149-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.109 , suse/sle-micro/5.5:latest
Container Release5.5.109
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3131-1
ReleasedTue Sep 3 17:42:24 2024
SummaryRecommended update for mozilla-nss
Typerecommended
Severitymoderate
References1224113
Description:

This update for mozilla-nss fixes the following issues:


SUSE-IU-2024:1148-1

Container Advisory IDSUSE-IU-2024:1148-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.107 , suse/sle-micro/5.5:latest
Container Release5.5.107
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3086-1
ReleasedTue Sep 3 08:57:32 2024
SummarySecurity update for glib2
Typesecurity
Severitylow
References1224044,CVE-2024-34397
Description:

This update for glib2 fixes the following issues:


SUSE-IU-2024:1139-1

Container Advisory IDSUSE-IU-2024:1139-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.105 , suse/sle-micro/5.5:latest
Container Release5.5.105
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:3080-1
ReleasedMon Sep 2 16:43:54 2024
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1228535,CVE-2024-7264
Description:

This update for curl fixes the following issues:
- CVE-2024-7264: Fixed out-of-bounds read in ASN.1 date parser GTime2str() (bsc#1228535)


Advisory IDSUSE-SU-2024:3081-1
ReleasedMon Sep 2 16:44:33 2024
SummarySecurity update for kernel-firmware
Typesecurity
Severityimportant
References1229069,CVE-2023-31315
Description:

This update for kernel-firmware fixes the following issues:


SUSE-IU-2024:1128-1

Container Advisory IDSUSE-IU-2024:1128-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.103 , suse/sle-micro/5.5:latest
Container Release5.5.103
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:3053-1
ReleasedWed Aug 28 09:52:37 2024
SummaryRecommended update for selinux-policy
Typerecommended
Severitymoderate
References1229701
Description:

This update for selinux-policy fixes the following issues:
Update to version 20230511+git17.e258ac27:


SUSE-IU-2024:1081-1

Container Advisory IDSUSE-IU-2024:1081-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.102 , suse/sle-micro/5.5:latest
Container Release5.5.102
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2659-1
ReleasedTue Jul 30 15:37:52 2024
SummarySecurity update for shadow
Typesecurity
Severityimportant
References916845,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-RU-2024:2664-1
ReleasedTue Jul 30 15:47:13 2024
SummaryRecommended update for open-vm-tools
Typerecommended
Severitymoderate
References1227181
Description:

This update for open-vm-tools fixes the following issues:


Advisory IDSUSE-RU-2024:2684-1
ReleasedWed Jul 31 20:04:41 2024
SummaryRecommended update for mozilla-nss
Typerecommended
Severitymoderate
References1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388
Description:

This update for mozilla-nss fixes the following issues:




Update to NSS 3.101.2:



update to NSS 3.101.1:

update to NSS 3.101:


Update to NSS 3.100:

Update to NSS 3.99:

Update to NSS 3.98:

Update to NSS 3.97:

Update to NSS 3.96.1:

Update to NSS 3.95:

Update to NSS 3.94:

Update to NSS 3.93:

Update to NSS 3.92:

Update to NSS 3.91:

Update to NSS 3.90.3:


Advisory IDSUSE-RU-2024:2696-1
ReleasedThu Aug 1 15:20:51 2024
SummaryRecommended update for dracut
Typerecommended
Severitymoderate
References1208690,1226412,1226529
Description:

This update for dracut fixes the following issues:


Advisory IDSUSE-RU-2024:2765-1
ReleasedTue Aug 6 10:33:41 2024
SummaryRecommended update for container-selinux
Typerecommended
Severitymoderate
References1227442
Description:

This update for container-selinux fixes the following issue:


Advisory IDSUSE-RU-2024:2791-1
ReleasedTue Aug 6 16:35:06 2024
SummaryRecommended update for various 32bit packages
Typerecommended
Severitymoderate
References1228322
Description:


This update of various packages delivers 32bit variants to allow running Wine on SLE PackageHub 15 SP6.


Advisory IDSUSE-RU-2024:2799-1
ReleasedWed Aug 7 08:19:10 2024
SummaryRecommended update for runc
Typerecommended
Severityimportant
References1214960
Description:

This update for runc fixes the following issues:


Advisory IDSUSE-SU-2024:2809-1
ReleasedWed Aug 7 09:49:44 2024
SummarySecurity update for shadow
Typesecurity
Severitymoderate
References1228770,CVE-2013-4235
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-RU-2024:2887-1
ReleasedTue Aug 13 10:52:45 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1159034,1194818,1222285
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-SU-2024:2891-1
ReleasedTue Aug 13 11:39:53 2024
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1226463,1227138,CVE-2024-5535
Description:

This update for openssl-1_1 fixes the following issues:


Other fixes:


Advisory IDSUSE-RU-2024:2967-1
ReleasedMon Aug 19 15:41:29 2024
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1194818
Description:

This update for pam fixes the following issue:


SUSE-IU-2024:683-1

Container Advisory IDSUSE-IU-2024:683-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.67 , suse/sle-micro/5.5:latest
Container Release5.5.67
The following patches have been included in this update:

SUSE-IU-2024:665-1

Container Advisory IDSUSE-IU-2024:665-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.65 , suse/sle-micro/5.5:latest
Container Release5.5.65
The following patches have been included in this update:

SUSE-IU-2024:642-1

Container Advisory IDSUSE-IU-2024:642-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.63 , suse/sle-micro/5.5:latest
Container Release5.5.63
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2401-1
ReleasedThu Jul 11 06:36:43 2024
SummarySecurity update for oniguruma
Typesecurity
Severitymoderate
References1141157,CVE-2019-13225
Description:

This update for oniguruma fixes the following issues:


SUSE-IU-2024:624-1

Container Advisory IDSUSE-IU-2024:624-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.62 , suse/sle-micro/5.5:latest
Container Release5.5.62
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:2302-1
ReleasedThu Jul 4 16:21:10 2024
SummarySecurity update for krb5
Typesecurity
Severityimportant
References1227186,1227187,CVE-2024-37370,CVE-2024-37371
Description:

This update for krb5 fixes the following issues:


Advisory IDSUSE-RU-2024:2325-1
ReleasedMon Jul 8 15:07:46 2024
SummaryRecommended update for xfsprogs
Typerecommended
Severitymoderate
References1227150
Description:

This update for xfsprogs fixes the following issue:


SUSE-IU-2024:600-1

Container Advisory IDSUSE-IU-2024:600-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.58 , suse/sle-micro/5.5:latest
Container Release5.5.58
The following patches have been included in this update:
Advisory IDSUSE-OU-2024:2282-1
ReleasedTue Jul 2 22:41:28 2024
SummaryOptional update for openscap, scap-security-guide
Typeoptional
Severitymoderate
References
Description:


This update for scap-security-guide and openscap provides the SCAP tooling for SLE Micro 5.3, 5.4, 5.5.
This includes shipping openscap dependencies libxmlsec1-1 and libxmlsec1-openssl for SLE Micro.


Advisory IDSUSE-SU-2024:2283-1
ReleasedTue Jul 2 23:12:19 2024
SummarySecurity update for libndp
Typesecurity
Severityimportant
References1225771,CVE-2024-5564
Description:

This update for libndp fixes the following issues:


Advisory IDSUSE-SU-2024:2286-1
ReleasedWed Jul 3 08:26:16 2024
SummarySecurity update for podman
Typesecurity
Severitymoderate
References1227052,CVE-2024-6104
Description:

This update for podman fixes the following issues:


Advisory IDSUSE-SU-2024:2290-1
ReleasedWed Jul 3 11:35:00 2024
SummarySecurity update for libxml2
Typesecurity
Severitylow
References1224282,CVE-2024-34459
Description:

This update for libxml2 fixes the following issues:


Advisory IDSUSE-RU-2024:2291-1
ReleasedWed Jul 3 12:43:47 2024
SummaryRecommended update for elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image1.5, seedimage-builder1.5
Typerecommended
Severitymoderate
References
Description:

This update for elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image1.5, seedimage-builder1.5 contains the following fixes:
Changes in elemental-operator1.5:


Changes in elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image1.5, seedimage-builder1.5:


SUSE-IU-2024:567-1

Container Advisory IDSUSE-IU-2024:567-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.50 , suse/sle-micro/5.5:latest
Container Release5.5.50
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2236-1
ReleasedWed Jun 26 13:01:03 2024
SummaryRecommended update for sysconfig
Typerecommended
Severityimportant
References1185882,1194557,1199093
Description:

This update for sysconfig fixes the following issues:


SUSE-IU-2024:558-1

Container Advisory IDSUSE-IU-2024:558-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.45 , suse/sle-micro/5.5:latest
Container Release5.5.45
The following patches have been included in this update:

SUSE-IU-2024:555-1

Container Advisory IDSUSE-IU-2024:555-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.43 , suse/sle-micro/5.5:latest
Container Release5.5.43
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2086-1
ReleasedWed Jun 19 11:48:24 2024
SummaryRecommended update for gcc13
Typerecommended
Severitymoderate
References1188441
Description:

This update for gcc13 fixes the following issues:
Update to GCC 13.3 release


SUSE-IU-2024:543-1

Container Advisory IDSUSE-IU-2024:543-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.38 , suse/sle-micro/5.5:latest
Container Release5.5.38
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:2024-1
ReleasedThu Jun 13 16:15:18 2024
SummaryRecommended update for jitterentropy
Typerecommended
Severitymoderate
References1209627
Description:

This update for jitterentropy fixes the following issues:


Updated to 3.4.1


Advisory IDSUSE-SU-2024:2031-1
ReleasedFri Jun 14 13:06:15 2024
SummarySecurity update for podman
Typesecurity
Severityimportant
References1224122,1226136,CVE-2024-24786,CVE-2024-3727
Description:

This update for podman fixes the following issues:


Advisory IDSUSE-SU-2024:2051-1
ReleasedTue Jun 18 09:16:01 2024
SummarySecurity update for openssl-1_1
Typesecurity
Severityimportant
References1225551,CVE-2024-4741
Description:

This update for openssl-1_1 fixes the following issues:


SUSE-IU-2024:486-1

Container Advisory IDSUSE-IU-2024:486-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.30 , suse/sle-micro/5.5:latest
Container Release5.5.30
The following patches have been included in this update:

SUSE-IU-2024:484-1

Container Advisory IDSUSE-IU-2024:484-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.28 , suse/sle-micro/5.5:latest
Container Release5.5.28
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:1895-1
ReleasedMon Jun 3 09:00:20 2024
SummarySecurity update for glibc
Typesecurity
Severityimportant
References1221940,1223423,1223424,1223425,CVE-2024-33599,CVE-2024-33600,CVE-2024-33601,CVE-2024-33602
Description:

This update for glibc fixes the following issues:



SUSE-IU-2024:468-1

Container Advisory IDSUSE-IU-2024:468-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.24 , suse/sle-micro/5.5:latest
Container Release5.5.24
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1876-1
ReleasedFri May 31 06:47:32 2024
SummaryRecommended update for aaa_base
Typerecommended
Severitymoderate
References1221361
Description:

This update for aaa_base fixes the following issues:


Advisory IDSUSE-RU-2024:1888-1
ReleasedFri May 31 19:09:00 2024
SummaryRecommended update for suse-module-tools
Typerecommended
Severitymoderate
References1216717,1223278,1224320
Description:

This update for suse-module-tools fixes the following issues:


SUSE-IU-2024:467-1

Container Advisory IDSUSE-IU-2024:467-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.18 , suse/sle-micro/5.5:latest
Container Release5.5.18
The following patches have been included in this update:

SUSE-IU-2024:464-1

Container Advisory IDSUSE-IU-2024:464-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.15 , suse/sle-micro/5.5:latest
Container Release5.5.15
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1802-1
ReleasedTue May 28 16:20:18 2024
SummaryRecommended update for e2fsprogs
Typerecommended
Severitymoderate
References1223596
Description:

This update for e2fsprogs fixes the following issues:
EA Inode handling fixes:


Advisory IDSUSE-SU-2024:1808-1
ReleasedTue May 28 22:12:38 2024
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1222548,CVE-2024-2511
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-RU-2024:1810-1
ReleasedWed May 29 08:58:01 2024
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1218609,1220117,1223605
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-SU-2024:1830-1
ReleasedWed May 29 14:08:50 2024
SummarySecurity update for glib2
Typesecurity
Severitylow
References1224044,CVE-2024-34397
Description:

This update for glib2 fixes the following issues:


Advisory IDSUSE-RU-2024:1841-1
ReleasedWed May 29 18:04:59 2024
SummaryRecommended update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image, operator-image1.5, seedimage-builder
Typerecommended
Severitymoderate
References
Description:

This update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image, operator-image1.5, seedimage-builder contains the following fixes:
Changes in elemental-operator:


Changes in elemental-operator-crds-helm, elemental-operator-helm, operator-image, seedimage-builder:
Changes in elemental-operator1.5:
Changes in elemental-operator1.5-crds-helm, elemental-operator1.5-helm, operator-image1.5:


SUSE-IU-2024:447-1

Container Advisory IDSUSE-IU-2024:447-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.2 , suse/sle-micro/5.5:latest
Container Release5.5.2
The following patches have been included in this update:

SUSE-IU-2024:443-1

Container Advisory IDSUSE-IU-2024:443-1
Container Tagssuse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.5.2 , suse/sle-micro/5.5:latest
Container Release5.5.2
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1769-1
ReleasedThu May 23 16:26:19 2024
SummaryRecommended update for SLE-Micro, SLE-Micro-base, SLE-Micro-kvm, SLE-Micro-rt, build-iso, build-iso-base, elemental, elemental-channel-image, elemental-channel1.5-image, elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, elemental-rt-channel-image, elemental-rt-channel1.5-image, elemental-toolkit, operator-image1.5, seedimage-builder, seedimage-builder1.5, systemd-presets-branding-SLE-Micro-for-Rancher
Typerecommended
Severityimportant
References1218560
Description:

This update for SLE-Micro, SLE-Micro-base, SLE-Micro-kvm, SLE-Micro-rt, build-iso, build-iso-base, elemental, elemental-channel-image, elemental-channel1.5-image, elemental-operator1.5, elemental-operator1.5-crds-helm, elemental-operator1.5-helm, elemental-rt-channel-image, elemental-rt-channel1.5-image, elemental-toolkit, operator-image1.5, seedimage-builder, seedimage-builder1.5, systemd-presets-branding-SLE-Micro-for-Rancher fixes the following issues:
Changes in SLE-Micro:


Changes in SLE-Micro-base:


Changes in SLE-Micro-kvm:


Changes in SLE-Micro-rt:


Changes in build-iso:


Changes in build-iso-base:


Changes in elemental:


Changes in elemental-channel-image:


Changes in elemental-channel1.5-image:



Changes in elemental-operator1.5:




























































































Changes in elemental-operator1.5-crds-helm:


























Changes in elemental-operator1.5-helm:




























Changes in elemental-rt-channel-image:




Changes in elemental-rt-channel1.5-image:




Changes in elemental-toolkit:



Changes in operator-image1.5:






Changes in seedimage-builder:

Changes in seedimage-builder1.5:






SUSE-IU-2024:442-1

Container Advisory IDSUSE-IU-2024:442-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.111 , suse/sle-micro/5.5:latest
Container Release4.2.111
The following patches have been included in this update:

SUSE-IU-2024:439-1

Container Advisory IDSUSE-IU-2024:439-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.109 , suse/sle-micro/5.5:latest
Container Release4.2.109
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:1762-1
ReleasedWed May 22 16:14:17 2024
SummarySecurity update for perl
Typesecurity
Severityimportant
References1082216,1082233,1213638,CVE-2018-6798,CVE-2018-6913
Description:

This update for perl fixes the following issues:
Security issues fixed:


Non-security issue fixed:


SUSE-IU-2024:436-1

Container Advisory IDSUSE-IU-2024:436-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.107 , suse/sle-micro/5.5:latest
Container Release4.2.107
The following patches have been included in this update:

SUSE-IU-2024:434-1

Container Advisory IDSUSE-IU-2024:434-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.105 , suse/sle-micro/5.5:latest
Container Release4.2.105
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1665-1
ReleasedThu May 16 08:00:09 2024
SummaryRecommended update for coreutils
Typerecommended
Severitymoderate
References1221632
Description:

This update for coreutils fixes the following issues:


Advisory IDSUSE-RU-2024:1671-1
ReleasedThu May 16 10:56:43 2024
SummaryRecommended update for open-vm-tools
Typerecommended
Severityimportant
References1054800,1062837,1121964,1133623,1141969,1143452,1171003,1171764,1172693,1196803,1196804,1205962,1217478,1217796,1222089,474076,481137,944615,952645,994598
Description:

This update for open-vm-tools fixes the following issues:


SUSE-IU-2024:433-1

Container Advisory IDSUSE-IU-2024:433-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.102 , suse/sle-micro/5.5:latest
Container Release4.2.102
The following patches have been included in this update:

SUSE-IU-2024:430-1

Container Advisory IDSUSE-IU-2024:430-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.99 , suse/sle-micro/5.5:latest
Container Release4.2.99
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1623-1
ReleasedMon May 13 14:10:44 2024
SummaryRecommended update for libcontainers-common
Typerecommended
Severitymoderate
References1197030,1213556,1216443
Description:

This update for libcontainers-common fixes the following issues:
New release 20240206:


New release 20231204:

* Fix specification of unix:///run * libimage/layer_tree: if parent is empty and a manifest list then ignore check. * Split up util package into pkg/password, pkg/copy, pkg/version * Remove ActiveDestination method to move into podman * Default machine CPUs to Cores/2 * pkg/config: do NOT set StaticDir and VolumeDir * Implement negated label match function * chore: import packages only once

* overlay, composefs: mount loop device RO * Run codespell on code * store: serialize container deletion * pkg/system: reduce retry timeout for EnsureRemoveAll * overlay, composefs: use data-only lower layers * store: call RecordWrite() before graphDriver Cleanup()

* Use constants and types from opencontainers/image-spec/specs-go/v1 * progress: set Current before Refill * copy: fix nil pointer dereference when checking compression algorithm * ociarchive: Add new ArchiveFileNotFoundError
New release 20230913:

* Adding IO decorator to copy progress bar * Ensure we close HTTP connections on all paths * manifest: ListUpdate add imgspecv1.Platform field * pkg/docker: use the same default auth path as macOS on FreeBSD * blob: TryReusingBlobWithOptions consider RequiredCompression if set * Fix tests of the ostree transport * helpers_test,cleanup: correct argument order * Make temporary names container/image specific * listupdate,oci: instance show read-only annotations and CompressionAlgorithmNames * Fix TestOCI1IndexChooseInstanc * Refactor data passing in c/image/copy * Update module github.com/sigstore/fulcio to v1.4.0 * copy/multiple: instanceCopyCopy honor UpdateCompressionAlgorithms * Update vendor of containers/storage * copy/single: accept custom *Options and wrap arguments in copySingleImageOptions * Improve transport documentation * copy: implement instanceCopyClone for zstd compression * copy/multiple: priority of instanceCopyCopy must be higher than instanceCopyClone * Clarify where mirrors are used * Update x/exp/slices, and some small slice-related cleanups * Use consistent example domains in #2069 * copy: add support for ForceCompressionFormat * storage.storageImageDestination.Commit(): leverage image options * Rename SKOPEO_CI_TAG to SKOPEO_CI_BRANCH * [CI:DOCS] Add cirrus-cron retry/monitor jobs * [release-5.27] Fix the branch we use for determining a git-validation starting point * OCI image-spec / distribution-spec v1.1 updates, first round * Merge release branch into main * BREAKING: Update for move of github.com/theupdateframework/go-tuf/encrypted * Update module github.com/containers/ocicrypt to v1.1.8 * fix removal of temp file in GetBlob on Windows * Fix build with golangci-lint 1.54.2 * Implement, and default to, a SQLite BlobInfoCache instead of BoltDB * Update dependencies of docker/docker * Correctly handle encryption/decryption changes in non-OCI formats
New release 20230814:

* Fix error if continueWrite/continueRead pipe open fails * pkg/regexp: make sure that &Regexp implements the interfaces * Remove use of fillGo18FileTypeBits

* Don't completely silently ignore non-OCI manifests in OCI layouts

* Change default image volume mode to 'nullfs' on FreeBSD * [v0.55][CI-DOCS] remove zstd:chunked from docs * libimage: harden lookup by digest * libimage: HasDifferentDigest: add InsecureSkipTLSVerify option

(https://github.com/containers/podman/issues/19327)


SUSE-IU-2024:429-1

Container Advisory IDSUSE-IU-2024:429-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.97 , suse/sle-micro/5.5:latest
Container Release4.2.97
The following patches have been included in this update:

SUSE-IU-2024:425-1

Container Advisory IDSUSE-IU-2024:425-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.96 , suse/sle-micro/5.5:latest
Container Release4.2.96
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:1598-1
ReleasedFri May 10 11:50:36 2024
SummarySecurity update for less
Typesecurity
Severityimportant
References1222849,CVE-2024-32487
Description:

This update for less fixes the following issues:


SUSE-IU-2024:421-1

Container Advisory IDSUSE-IU-2024:421-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.94 , suse/sle-micro/5.5:latest
Container Release4.2.94
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1566-1
ReleasedThu May 9 12:33:21 2024
SummaryRecommended update for catatonit
Typerecommended
Severitymoderate
References
Description:

This update for catatonit fixes the following issues:


SUSE-IU-2024:379-1

Container Advisory IDSUSE-IU-2024:379-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.93 , suse/sle-micro/5.5:latest
Container Release4.2.93
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:1557-1
ReleasedWed May 8 11:42:34 2024
SummarySecurity update for rpm
Typesecurity
Severitymoderate
References1189495,1191175,1218686,CVE-2021-3521
Description:

This update for rpm fixes the following issues:
Security fixes:


Other fixes:


SUSE-IU-2024:365-1

Container Advisory IDSUSE-IU-2024:365-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.91 , suse/sle-micro/5.5:latest
Container Release4.2.91
The following patches have been included in this update:

SUSE-IU-2024:363-1

Container Advisory IDSUSE-IU-2024:363-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.89 , suse/sle-micro/5.5:latest
Container Release4.2.89
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1487-1
ReleasedThu May 2 10:43:53 2024
SummaryRecommended update for aaa_base
Typerecommended
Severitymoderate
References1211721,1221361,1221407,1222547
Description:

This update for aaa_base fixes the following issues:


SUSE-IU-2024:354-1

Container Advisory IDSUSE-IU-2024:354-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.87 , suse/sle-micro/5.5:latest
Container Release4.2.87
The following patches have been included in this update:

SUSE-IU-2024:353-1

Container Advisory IDSUSE-IU-2024:353-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.85 , suse/sle-micro/5.5:latest
Container Release4.2.85
The following patches have been included in this update:
Advisory IDSUSE-RU-2024:1342-1
ReleasedThu Apr 18 16:35:49 2024
SummaryRecommended update for unixODBC, libtool and libssh2_org
Typerecommended
Severitymoderate
References1221622,1221941
Description:

This update for unixODBC, libtool and libssh2_org fixes the following issue:


Advisory IDSUSE-RU-2024:1366-1
ReleasedMon Apr 22 11:04:32 2024
SummaryRecommended update for openssh
Typerecommended
Severitymoderate
References1216474,1218871,1221123,1222831
Description:

This update for openssh fixes the following issues:



This makes ssh update the known_hosts stored keys with all published versions by the server (after it's authenticated with an existing key), which will allow to identify the server with a different key if the existing key is considered insecure at some point in the future (bsc#1222831).


Advisory IDSUSE-SU-2024:1375-1
ReleasedMon Apr 22 14:56:13 2024
SummarySecurity update for glibc
Typesecurity
Severityimportant
References1222992,CVE-2024-2961
Description:

This update for glibc fixes the following issues:


Advisory IDSUSE-SU-2024:1376-1
ReleasedMon Apr 22 16:13:38 2024
SummarySecurity update for polkit
Typesecurity
Severitylow
References1209282
Description:

This update for polkit fixes the following issues:


Advisory IDSUSE-RU-2024:1398-1
ReleasedTue Apr 23 13:58:22 2024
SummaryRecommended update for systemd-default-settings
Typerecommended
Severitymoderate
References
Description:

This update for systemd-default-settings fixes the following issues:


Advisory IDSUSE-RU-2024:1458-1
ReleasedMon Apr 29 07:47:34 2024
SummaryRecommended update for vim
Typerecommended
Severitymoderate
References1220763
Description:

This update for vim fixes the following issues:


SUSE-IU-2024:325-1

Container Advisory IDSUSE-IU-2024:325-1
Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.70 , suse/sle-micro/5.5:latest
Container Release4.2.70
The following patches have been included in this update:
Advisory IDSUSE-SU-2024:295-1
ReleasedThu Feb 1 08:23:17 2024
SummarySecurity update for runc
Typesecurity
Severityimportant
References1218894,CVE-2024-21626
Description:

This update for runc fixes the following issues:
Update to runc v1.1.11:


Advisory IDSUSE-RU-2024:322-1
ReleasedFri Feb 2 15:13:26 2024
SummaryRecommended update for aaa_base
Typerecommended
Severitymoderate
References1107342,1215434
Description:

This update for aaa_base fixes the following issues:


Advisory IDSUSE-RU-2024:408-1
ReleasedWed Feb 7 11:06:37 2024
SummaryRecommended update for podman
Typerecommended
Severitymoderate
References1217828
Description:

This update for podman fixes the following issues:








Advisory IDSUSE-SU-2024:459-1
ReleasedTue Feb 13 15:28:56 2024
SummarySecurity update for runc
Typesecurity
Severityimportant
References1218894,CVE-2024-21626
Description:

This update for runc fixes the following issues:

The following CVE was already fixed with the previous release.
  • CVE-2024-21626: Fixed container breakout.

  • Advisory IDSUSE-RU-2024:527-1
    ReleasedMon Feb 19 10:03:27 2024
    SummaryRecommended update for conmon
    Typerecommended
    Severitymoderate
    References1215806,1217773
    Description:

    This update for conmon fixes the following issues:


    Bug fixes:
    * Fix incorrect free in conn_sock * logging: Respect log-size-max immediately after open

    Bug fixes:
    * fix some issues flagged by SAST scan * src: fix write after end of buffer * src: open all files with O_CLOEXEC * oom-score: restore oom score before running exit command
    Features:
    * Forward more messages on the sd-notify socket * logging: -l passthrough accepts TTYs
    * [bsc#1215806]
    Update to version 2.1.8:
    * stdio: ignore EIO for terminals (bsc#1217773) * ensure console socket buffers are properly sized * conmon: drop return after pexit() * ctrl: make accept4 failures fatal * logging: avoid opening /dev/null for each write * oom: restore old OOM score * Use default umask 0022 * cli: log parsing errors to stderr * Changes to build conmon for riscv64 * Changes to build conmon for ppc64le * Fix close_other_fds on FreeBSD


    Advisory IDSUSE-SU-2024:549-1
    ReleasedTue Feb 20 17:05:52 2024
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitymoderate
    References1219243,CVE-2024-0727
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2024:555-1
    ReleasedTue Feb 20 17:22:17 2024
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1219576,CVE-2024-25062
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2024:596-1
    ReleasedThu Feb 22 20:05:29 2024
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1218215,CVE-2023-51385
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-SU-2024:597-1
    ReleasedThu Feb 22 20:07:11 2024
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1216198,CVE-2023-5388
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.90.2:


    Advisory IDSUSE-RU-2024:614-1
    ReleasedMon Feb 26 11:31:18 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severityimportant
    References1216752
    Description:

    This update for rpm fixes the following issues:


    Advisory IDSUSE-RU-2024:615-1
    ReleasedMon Feb 26 11:32:32 2024
    SummaryRecommended update for netcfg
    Typerecommended
    Severitymoderate
    References1211886
    Description:

    This update for netcfg fixes the following issues:


    Advisory IDSUSE-RU-2024:637-1
    ReleasedTue Feb 27 10:06:55 2024
    SummaryRecommended update for duktape
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for duktape fixes the following issues:


    Advisory IDSUSE-SU-2024:764-1
    ReleasedTue Mar 5 13:46:25 2024
    SummarySecurity update for wpa_supplicant
    Typesecurity
    Severityimportant
    References1219975,CVE-2023-52160
    Description:

    This update for wpa_supplicant fixes the following issues:


    Advisory IDSUSE-RU-2024:766-1
    ReleasedTue Mar 5 13:50:28 2024
    SummaryRecommended update for libssh
    Typerecommended
    Severityimportant
    References1220385
    Description:

    This update for libssh fixes the following issues:


    Advisory IDSUSE-RU-2024:792-1
    ReleasedThu Mar 7 09:55:23 2024
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-SU-2024:794-1
    ReleasedThu Mar 7 10:33:17 2024
    SummarySecurity update for sudo
    Typesecurity
    Severityimportant
    References1219026,1220389,CVE-2023-42465
    Description:

    This update for sudo fixes the following issues:


    Advisory IDSUSE-SU-2024:305-1
    ReleasedMon Mar 11 14:15:37 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,1219238,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:


    Advisory IDSUSE-RU-2024:846-1
    ReleasedTue Mar 12 13:31:27 2024
    SummaryRecommended update for selinux-policy
    Typerecommended
    Severitymoderate
    References1220361
    Description:

    This update for selinux-policy fixes the following issues:


    Advisory IDSUSE-RU-2024:861-1
    ReleasedWed Mar 13 09:12:30 2024
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1218232
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2024:870-1
    ReleasedWed Mar 13 13:05:14 2024
    SummarySecurity update for glibc
    Typesecurity
    Severitymoderate
    References1217445,1217589,1218866
    Description:

    This update for glibc fixes the following issues:
    Security issues fixed:


    Other issues fixed:


    Advisory IDSUSE-SU-2024:876-1
    ReleasedWed Mar 13 15:45:34 2024
    SummarySecurity update for sudo
    Typesecurity
    Severityimportant
    References1221134,1221151,CVE-2023-42465
    Description:

    This update for sudo fixes the following issues:


    Advisory IDSUSE-RU-2024:903-1
    ReleasedFri Mar 15 06:57:36 2024
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitymoderate
    References1200731
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2024:907-1
    ReleasedFri Mar 15 08:57:38 2024
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1215377
    Description:

    This update for audit fixes the following issue:


    Advisory IDSUSE-RU-2024:929-1
    ReleasedTue Mar 19 06:36:24 2024
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1219321
    Description:

    This update for coreutils fixes the following issues:


    Advisory IDSUSE-RU-2024:980-1
    ReleasedMon Mar 25 06:18:28 2024
    SummaryRecommended update for pam-config
    Typerecommended
    Severitymoderate
    References1219767
    Description:

    This update for pam-config fixes the following issues:


    Advisory IDSUSE-RU-2024:982-1
    ReleasedMon Mar 25 12:56:33 2024
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1217964
    Description:

    This update for systemd-rpm-macros fixes the following issue:


    Advisory IDSUSE-RU-2024:984-1
    ReleasedMon Mar 25 16:04:44 2024
    SummaryRecommended update for runc
    Typerecommended
    Severityimportant
    References1192051,1221050
    Description:

    This update for runc fixes the following issues:


    This allows running 15 SP6 containers on older distributions.


    Advisory IDSUSE-SU-2024:997-1
    ReleasedTue Mar 26 11:03:37 2024
    SummarySecurity update for krb5
    Typesecurity
    Severityimportant
    References1220770,1220771,1220772,CVE-2024-26458,CVE-2024-26461,CVE-2024-26462
    Description:

    This update for krb5 fixes the following issues:


    Advisory IDSUSE-SU-2024:1007-1
    ReleasedWed Mar 27 10:51:42 2024
    SummarySecurity update for shadow
    Typesecurity
    Severitymoderate
    References1144060,1176006,1188307,1203823,1205502,1206627,1210507,1213189,1214806,CVE-2023-29383,CVE-2023-4641
    Description:

    This update for shadow fixes the following issues:


    The following non-security bugs were fixed:
    lock files after power interruptions
  • bsc#1206627: Add --prefix support to passwd, chpasswd and chage
  • bsc#1205502: useradd audit event user id field cannot be interpretedd

  • Advisory IDSUSE-SU-2024:1014-1
    ReleasedWed Mar 27 18:33:55 2024
    SummarySecurity update for avahi
    Typesecurity
    Severitymoderate
    References1216594,1216598,CVE-2023-38469,CVE-2023-38471
    Description:

    This update for avahi fixes the following issues:


    Advisory IDSUSE-RU-2024:1015-1
    ReleasedThu Mar 28 06:08:11 2024
    SummaryRecommended update for sed
    Typerecommended
    Severityimportant
    References1221218
    Description:

    This update for sed fixes the following issues:


    Advisory IDSUSE-RU-2024:1080-1
    ReleasedTue Apr 2 06:50:10 2024
    SummaryRecommended update for xfsprogs-scrub
    Typerecommended
    Severitylow
    References1190495
    Description:

    This update for xfsprogs-scrub fixes the following issues:


    Advisory IDSUSE-RU-2024:1081-1
    ReleasedTue Apr 2 06:50:44 2024
    SummaryRecommended update for dracut
    Typerecommended
    Severityimportant
    References1217083,1219841,1220485,1221675
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-RU-2024:1091-1
    ReleasedTue Apr 2 12:18:46 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for rpm fixes the following issues:



    Advisory IDSUSE-RU-2024:1104-1
    ReleasedWed Apr 3 14:29:58 2024
    SummaryRecommended update for docker, containerd, rootlesskit, catatonit, slirp4netns, fuse-overlayfs
    Typerecommended
    Severityimportant
    References
    Description:

    This update for docker fixes the following issues:


    The other packages in the update (containerd, rootlesskit, catatonit, slirp4netns, fuse-overlayfs) are no-change rebuilds required because the corresponding binary packages were missing in a number of repositories, thus making docker not installable on some products.


    Advisory IDSUSE-SU-2024:1129-1
    ReleasedMon Apr 8 09:12:08 2024
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1219559,1221289,CVE-2023-52425,CVE-2024-28757
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2024:1133-1
    ReleasedMon Apr 8 11:29:02 2024
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1220061,CVE-2023-45918
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-SU-2024:1146-1
    ReleasedMon Apr 8 11:34:54 2024
    SummarySecurity update for podman
    Typesecurity
    Severityimportant
    References1221677,CVE-2024-1753
    Description:

    This update for podman fixes the following issues:


    Advisory IDSUSE-SU-2024:1151-1
    ReleasedMon Apr 8 11:36:23 2024
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1221665,1221667,CVE-2024-2004,CVE-2024-2398
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2024:1167-1
    ReleasedMon Apr 8 15:11:11 2024
    SummarySecurity update for nghttp2
    Typesecurity
    Severityimportant
    References1221399,CVE-2024-28182
    Description:

    This update for nghttp2 fixes the following issues:


    Advisory IDSUSE-SU-2024:1172-1
    ReleasedTue Apr 9 09:52:32 2024
    SummarySecurity update for util-linux
    Typesecurity
    Severityimportant
    References1207987,1221831,CVE-2024-28085
    Description:

    This update for util-linux fixes the following issues:


    Advisory IDSUSE-RU-2024:1175-1
    ReleasedTue Apr 9 10:06:40 2024
    SummaryRecommended update for multipath-tools
    Typerecommended
    Severitymoderate
    References1212440,1213809,1219142,1220374
    Description:

    This update for multipath-tools fixes the following issues:


    * Avoid setting queue_if_no_path on multipath maps for which the no_path_retry timeout has expired * Fixed memory and error handling for code using aio (marginal path code, directio path checker) * libmultipath: fixed max_sectors_kb on adding path * Fixed warnings reported by udevadm verify * libmultipath: use directio checker for LIO targets * multipathd.service: remove 'Also=multipathd.socket' * libmultipathd: avoid parsing errors due to unsupported designators * libmultipath: return 'pending' state when port is in transition * multipath.rules: fixed 'smart' bug with failed valid path check * libmpathpersist: fixed resource leak in update_map_pr() * libmultipath: keep renames from stopping other multipath actions


    Advisory IDSUSE-SU-2024:1192-1
    ReleasedWed Apr 10 09:14:37 2024
    SummarySecurity update for less
    Typesecurity
    Severityimportant
    References1219901,CVE-2022-48624
    Description:

    This update for less fixes the following issues:


    Advisory IDSUSE-RU-2024:1201-1
    ReleasedThu Apr 11 10:47:59 2024
    SummaryRecommended update for xfsprogs-scrub and jctools
    Typerecommended
    Severitylow
    References1190495,1213418
    Description:

    This update for xfsprogs-scrub fixes the following issues:


    Advisory IDSUSE-RU-2024:1206-1
    ReleasedThu Apr 11 12:56:24 2024
    SummaryRecommended update for rpm
    Typerecommended
    Severitymoderate
    References1222259
    Description:

    This update for rpm fixes the following issues:


    Advisory IDSUSE-RU-2024:1231-1
    ReleasedThu Apr 11 15:20:40 2024
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1220441
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-RU-2024:1253-1
    ReleasedFri Apr 12 08:15:18 2024
    SummaryRecommended update for gcc13
    Typerecommended
    Severitymoderate
    References1210959,1214934,1217450,1217667,1218492,1219031,1219520,1220724,1221239
    Description:

    This update for gcc13 fixes the following issues:


    Advisory IDSUSE-RU-2024:1272-1
    ReleasedFri Apr 12 16:24:28 2024
    SummaryRecommended update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, operator-image
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for elemental-operator, elemental-operator-crds-helm, elemental-operator-helm, operator-image contains the following fixes:



    Advisory IDSUSE-SU-2024:1287-1
    ReleasedMon Apr 15 15:03:40 2024
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1215005,1217316,1217320,1217321,1217324,1217326,1217329,1217330,1217432,1219581,CVE-2023-4750,CVE-2023-48231,CVE-2023-48232,CVE-2023-48233,CVE-2023-48234,CVE-2023-48235,CVE-2023-48236,CVE-2023-48237,CVE-2023-48706,CVE-2024-22667
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.1.0111, fixes the following security problems


    SUSE-IU-2024:92-1

    Container Advisory IDSUSE-IU-2024:92-1
    Container Tagssuse/sle-micro/5.5:2.0.2 , suse/sle-micro/5.5:2.0.2-4.2.20 , suse/sle-micro/5.5:latest
    Container Release4.2.20
    The following patches have been included in this update:
    Advisory IDSUSE-SU-2018:1292-1
    ReleasedMon Jul 9 11:57:14 2018
    SummarySecurity update for openslp
    Typesecurity
    Severityimportant
    References1090638,CVE-2017-17833
    Description:

    This update for openslp fixes the following issues:


    Advisory IDSUSE-RU-2018:1332-1
    ReleasedTue Jul 17 09:01:19 2018
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1073299,1093392
    Description:

    This update for timezone provides the following fixes:


    Advisory IDSUSE-SU-2018:2340-1
    ReleasedFri Oct 19 16:05:53 2018
    SummarySecurity update for fuse
    Typesecurity
    Severitymoderate
    References1101797,CVE-2018-10906
    Description:

    This update for fuse fixes the following issues:


    Advisory IDSUSE-RU-2018:2463-1
    ReleasedThu Oct 25 14:48:34 2018
    SummaryRecommended update for timezone, timezone-java
    Typerecommended
    Severitymoderate
    References1104700,1112310
    Description:


    This update for timezone, timezone-java fixes the following issues:
    The timezone database was updated to 2018f:


    Other bugfixes:


    Advisory IDSUSE-RU-2018:2513-1
    ReleasedMon Oct 29 11:11:23 2018
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1089883
    Description:


    This update for sysstat fixes the following issues:
    Sysstat was updated to 12.0.2, bringing new features and bugfixes (fate#326576, bsc#1089883)


    Please look at http://sebastien.godard.pagesperso-orange.fr/ for a more detailed history of changes.


    Advisory IDSUSE-RU-2018:2550-1
    ReleasedWed Oct 31 16:16:56 2018
    SummaryRecommended update for timezone, timezone-java
    Typerecommended
    Severitymoderate
    References1113554
    Description:

    This update provides the latest time zone definitions (2018g), including the following change:


    Advisory IDSUSE-RU-2018:2569-1
    ReleasedFri Nov 2 19:00:18 2018
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1110700
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2018:2607-1
    ReleasedWed Nov 7 15:42:48 2018
    SummaryOptional update for gcc8
    Typerecommended
    Severitylow
    References1084812,1084842,1087550,1094222,1102564
    Description:


    The GNU Compiler GCC 8 is being added to the Development Tools Module by this update.
    The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
    Various optimizers have been improved in GCC 8, several of bugs fixed, quite some new warnings added and the error pin-pointing and fix-suggestions have been greatly improved.
    The GNU Compiler page for GCC 8 contains a summary of all the changes that have happened:
    https://gcc.gnu.org/gcc-8/changes.html
    Also changes needed or common pitfalls when porting software are described on:
    https://gcc.gnu.org/gcc-8/porting_to.html


    Advisory IDSUSE-RU-2018:2641-1
    ReleasedMon Nov 12 20:39:30 2018
    SummaryRecommended update for nfsidmap
    Typerecommended
    Severitymoderate
    References1098217
    Description:

    This update for nfsidmap fixes the following issues:


    Advisory IDSUSE-RU-2018:2742-1
    ReleasedThu Nov 22 13:28:36 2018
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References969953
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-SU-2018:2825-1
    ReleasedMon Dec 3 15:35:02 2018
    SummarySecurity update for pam
    Typesecurity
    Severityimportant
    References1115640,CVE-2018-17953
    Description:

    This update for pam fixes the following issue:
    Security issue fixed:


    Advisory IDSUSE-SU-2018:2861-1
    ReleasedThu Dec 6 14:32:01 2018
    SummarySecurity update for ncurses
    Typesecurity
    Severityimportant
    References1103320,1115929,CVE-2018-19211
    Description:

    This update for ncurses fixes the following issues:
    Security issue fixed:


    Non-security issue fixed:


    Advisory IDSUSE-RU-2018:2961-1
    ReleasedMon Dec 17 19:51:40 2018
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References1098697,1112780
    Description:

    This update for psmisc provides the following fix:


    Advisory IDSUSE-SU-2018:3044-1
    ReleasedFri Dec 21 18:47:21 2018
    SummarySecurity update for MozillaFirefox, mozilla-nspr and mozilla-nss
    Typesecurity
    Severityimportant
    References1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498
    Description:

    This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues:
    Issues fixed in MozillaFirefox:


    Issues fixed in mozilla-nss:

    Issues fixed in mozilla-nspr:


    Advisory IDSUSE-RU-2019:44-1
    ReleasedTue Jan 8 13:07:32 2019
    SummaryRecommended update for acl
    Typerecommended
    Severitylow
    References953659
    Description:

    This update for acl fixes the following issues:


    Advisory IDSUSE-RU-2019:102-1
    ReleasedTue Jan 15 18:02:58 2019
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1120402
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-SU-2019:247-1
    ReleasedWed Feb 6 07:18:45 2019
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1123043,CVE-2019-6706
    Description:

    This update for lua53 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:495-1
    ReleasedTue Feb 26 16:42:35 2019
    SummarySecurity update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc
    Typesecurity
    Severityimportant
    References1048046,1051429,1114832,1118897,1118898,1118899,1121967,1124308,CVE-2018-16873,CVE-2018-16874,CVE-2018-16875,CVE-2019-5736
    Description:

    This update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc fixes the following issues:
    Security issues fixed:


    Other changes and fixes:


    Advisory IDSUSE-SU-2019:571-1
    ReleasedThu Mar 7 18:13:46 2019
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
    Description:

    This update for file fixes the following issues:
    The following security vulnerabilities were addressed:


    Advisory IDSUSE-SU-2019:748-1
    ReleasedTue Mar 26 14:35:56 2019
    SummarySecurity update for libmspack
    Typesecurity
    Severitymoderate
    References1113038,1113039,CVE-2018-18584,CVE-2018-18585
    Description:

    This update for libmspack fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:788-1
    ReleasedThu Mar 28 11:55:06 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1119687,CVE-2018-20346
    Description:

    This update for sqlite3 to version 3.27.2 fixes the following issue:
    Security issue fixed:


    Release notes: https://www.sqlite.org/releaselog/3_27_2.html


    Advisory IDSUSE-RU-2019:790-1
    ReleasedThu Mar 28 12:06:17 2019
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1130557
    Description:

    This update for timezone fixes the following issues:
    timezone was updated 2019a:


    Advisory IDSUSE-SU-2019:806-1
    ReleasedFri Mar 29 13:16:51 2019
    SummarySecurity update for sysstat
    Typesecurity
    Severitylow
    References1117001,1117260,CVE-2018-19416,CVE-2018-19517
    Description:

    This update for sysstat fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:926-1
    ReleasedWed Apr 10 16:33:12 2019
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1120610,1130496,CVE-2018-20482,CVE-2019-9923
    Description:

    This update for tar fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:1127-1
    ReleasedThu May 2 09:39:24 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1130325,1130326,CVE-2019-9936,CVE-2019-9937
    Description:

    This update for sqlite3 to version 3.28.0 fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-RU-2019:1229-1
    ReleasedTue May 14 11:05:55 2019
    SummaryRecommended update for sensors
    Typerecommended
    Severitymoderate
    References1108468,1116021
    Description:

    This update for sensors fixes the following issues:
    sensors was updated to version 3.5.0:
    The following changes were done:



    * Fix systemd paths. * Add detection of Fintek F81768. * Only probe I/O ports on x86. * Add detection of Nuvoton NCT6793D. * Add detection of Microchip MCP9808. * Mark F71868A as supported by the f71882fg driver. * Mark F81768D as supported by the f71882fg driver. * Mark F81866D as supported by the f71882fg driver. * Add detection of various ITE chips. * Add detection of Nuvoton NCT6795D. * Add detection of DDR4 SPD. * Add detection of ITE IT8987D. * Add detection of AMD Family 17h temperature sensors. * Add detection of AMD KERNCZ SMBus controller. * Add detection of various Intel SMBus controllers. * Add detection of Giantec GT30TS00. * Add detection of ONS CAT34TS02C and CAT34TS04. * Add detection of AMD Family 15h Model 60+ temperature sensors. * Add detection of Nuvoton NCT6796D. * Add detection of AMD Family 15h Model 70+ temperature sensors.

    * Add hardwired inputs of NCT6795D * Add hardwired inputs of F71868A * Add hardwired NCT6796D inputs

    * Add support for SENSORS_BUS_TYPE_SCSI, add support for power min, lcrit, min_alarm, lcrit_alarm. * Handle hwmon device with thermal device parent (bsc#1108468).


    Advisory IDSUSE-SU-2019:1368-1
    ReleasedTue May 28 13:15:38 2019
    SummaryRecommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root
    Typesecurity
    Severityimportant
    References1134524,CVE-2019-5021
    Description:

    This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:


    Advisory IDSUSE-RU-2019:1616-1
    ReleasedFri Jun 21 11:04:39 2019
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References1134659
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-RU-2019:1631-1
    ReleasedFri Jun 21 11:17:21 2019
    SummaryRecommended update for xz
    Typerecommended
    Severitylow
    References1135709
    Description:

    This update for xz fixes the following issues:
    Add SUSE-Public-Domain licence as some parts of xz utils (liblzma, xz, xzdec, lzmadec, documentation, translated messages, tests, debug, extra directory) are in public domain licence [bsc#1135709]


    Advisory IDSUSE-RU-2019:1815-1
    ReleasedThu Jul 11 07:47:55 2019
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1140016
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-RU-2019:1892-1
    ReleasedThu Jul 18 15:54:35 2019
    SummaryRecommended update for openslp
    Typerecommended
    Severitymoderate
    References1117969,1136136
    Description:

    This update for openslp fixes the following issues:


    Advisory IDSUSE-RU-2019:1998-1
    ReleasedFri Jul 26 16:13:22 2019
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1138767
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-RU-2019:2142-1
    ReleasedWed Aug 14 18:14:04 2019
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1141322
    Description:


    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.45 (bsc#1141322) :


    mozilla-nspr was updated to version 4.21


    Advisory IDSUSE-RU-2019:2189-1
    ReleasedWed Aug 21 10:12:23 2019
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1142470
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-RU-2019:2218-1
    ReleasedMon Aug 26 11:29:57 2019
    SummaryRecommended update for pinentry
    Typerecommended
    Severitymoderate
    References1141883
    Description:

    This update for pinentry fixes the following issues:


    Advisory IDSUSE-SU-2019:2223-1
    ReleasedTue Aug 27 15:42:56 2019
    SummarySecurity update for podman, slirp4netns and libcontainers-common
    Typesecurity
    Severitymoderate
    References1096726,1123156,1123387,1135460,1136974,1137860,1143386,CVE-2018-15664,CVE-2019-10152,CVE-2019-6778
    Description:


    This is a version update for podman to version 1.4.4 (bsc#1143386).
    Additional changes by SUSE on top:


    Version update podman to v1.4.4:

    - Podman now has greatly improved support for containers using multiple OCI runtimes. Containers now remember if they were created with a different runtime using --runtime and will always use that runtime - The cached and delegated options for volume mounts are now allowed for Docker compatability (#3340) - The podman diff command now supports the --latest flag

    - Fixed a bug where rootless Podman would attempt to use the entire root configuration if no rootless configuration was present for the user, breaking rootless Podman for new installations - Fixed a bug where rootless Podman's pause process would block SIGTERM, preventing graceful system shutdown and hanging until the system's init send SIGKILL - Fixed a bug where running Podman as root with sudo -E would not work after running rootless Podman at least once - Fixed a bug where options for tmpfs volumes added with the --tmpfs flag were being ignored - Fixed a bug where images with no layers could not properly be displayed and removed by Podman - Fixed a bug where locks were not properly freed on failure to create a container or pod - Fixed a bug where podman cp on a single file would create a directory at the target and place the file in it (#3384) - Fixed a bug where podman inspect --format '{{.Mounts}}' would print a hexadecimal address instead of a container's mounts - Fixed a bug where rootless Podman would not add an entry to container's /etc/hosts files for their own hostname (#3405) - Fixed a bug where podman ps --sync would segfault (#3411) - Fixed a bug where podman generate kube would produce an invalid ports configuration (#3408)

    - Updated containers/storage to v1.12.13 - Podman now performs much better on systems with heavy I/O load - The --cgroup-manager flag to podman now shows the correct default setting in help if the default was overridden by libpod.conf - For backwards compatability, setting --log-driver=json-file in podman run is now supported as an alias for --log-driver=k8s-file. This is considered deprecated, and json-file will be moved to a new implementation in the future ([#3363](https://github.com/containers/libpo\ d/issues/3363)) - Podman's default libpod.conf file now allows the crun OCI runtime to be used if it is installed
    Update podman to v1.4.2:

    Updated podman to version 1.4.0 (bsc#1137860) and (bsc#1135460)



    Update to storage v1.12.10:

    slirp4netns was updated to 0.3.0:

    This update also includes:


    Advisory IDSUSE-SU-2019:2533-1
    ReleasedThu Oct 3 15:02:50 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1150137,CVE-2019-16168
    Description:

    This update for sqlite3 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:2693-1
    ReleasedWed Oct 16 16:43:30 2019
    SummaryRecommended update for rpcbind
    Typerecommended
    Severitymoderate
    References1142343
    Description:

    This update for rpcbind fixes the following issues:


    Advisory IDSUSE-RU-2019:2722-1
    ReleasedMon Oct 21 11:14:20 2019
    SummaryRecommended update for pciutils-ids
    Typerecommended
    Severitymoderate
    References1127840,1133581
    Description:

    This is a version update for pciutils-ids to version 20190830 (bsc#1133581, bsc#1127840)


    Advisory IDSUSE-SU-2019:2730-1
    ReleasedMon Oct 21 16:04:57 2019
    SummarySecurity update for procps
    Typesecurity
    Severityimportant
    References1092100,1121753,CVE-2018-1122,CVE-2018-1123,CVE-2018-1124,CVE-2018-1125,CVE-2018-1126
    Description:

    This update for procps fixes the following issues:
    procps was updated to 3.3.15. (bsc#1092100)
    Following security issues were fixed:



    Also this non-security issue was fixed:

    The update to 3.3.15 contains the following fixes:


    Advisory IDSUSE-SU-2019:2749-1
    ReleasedWed Oct 23 09:08:41 2019
    SummarySecurity update for sysstat
    Typesecurity
    Severitymoderate
    References1150114,CVE-2019-16167
    Description:

    This update for sysstat fixes the following issue:


    Advisory IDSUSE-RU-2019:2762-1
    ReleasedThu Oct 24 07:08:44 2019
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1150451
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-SU-2019:2810-1
    ReleasedTue Oct 29 14:56:44 2019
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1131314,1131553,1152308,CVE-2019-16884
    Description:

    This update for runc fixes the following issues:
    Security issue fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:2997-1
    ReleasedMon Nov 18 15:16:38 2019
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
    Description:

    This update for ncurses fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2019:3061-1
    ReleasedMon Nov 25 17:34:22 2019
    SummarySecurity update for gcc9
    Typesecurity
    Severitymoderate
    References1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
    Description:



    This update includes the GNU Compiler Collection 9.
    A full changelog is provided by the GCC team on:
    https://www.gnu.org/software/gcc/gcc-9/changes.html

    The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages.
    To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it.

    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:3086-1
    ReleasedThu Nov 28 10:02:24 2019
    SummarySecurity update for libidn2
    Typesecurity
    Severitymoderate
    References1154884,1154887,CVE-2019-12290,CVE-2019-18224
    Description:

    This update for libidn2 to version 2.2.0 fixes the following issues:


    Advisory IDSUSE-RU-2019:3104-1
    ReleasedFri Nov 29 06:47:08 2019
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1144923,SLE-5958
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-SU-2019:3395-1
    ReleasedMon Dec 30 14:05:06 2019
    SummarySecurity update for mozilla-nspr, mozilla-nss
    Typesecurity
    Severitymoderate
    References1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.47.1:
    Security issues fixed:


    mozilla-nspr was updated to version 4.23:


    Advisory IDSUSE-OU-2020:52-1
    ReleasedThu Jan 9 10:09:11 2020
    SummaryOptional update for openslp
    Typeoptional
    Severitylow
    References1149792
    Description:

    This update for openslp doesn't fix any user visible bugs.


    Advisory IDSUSE-RU-2020:225-1
    ReleasedFri Jan 24 06:49:07 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:525-1
    ReleasedFri Feb 28 11:49:36 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1164562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:689-1
    ReleasedFri Mar 13 17:09:01 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:


    This update for PAM fixes the following issue:


    Advisory IDSUSE-SU-2020:697-1
    ReleasedMon Mar 16 13:17:10 2020
    SummarySecurity update for cni, cni-plugins, conmon, fuse-overlayfs, podman
    Typesecurity
    Severitymoderate
    References1155217,1160460,1164390,CVE-2019-18466
    Description:

    This update for cni, cni-plugins, conmon, fuse-overlayfs, podman fixes the following issues:
    podman was updated to 1.8.0:



    Update podman to v1.8.0 (bsc#1160460):

    - The podman system service command has been added, providing a preview of Podman's new Docker-compatible API. This API is still very new, and not yet ready for production use, but is available for early testing - Rootless Podman now uses Rootlesskit for port forwarding, which should greatly improve performance and capabilities - The podman untag command has been added to remove tags from images without deleting them - The podman inspect command on images now displays previous names they used - The podman generate systemd command now supports a --new option to generate service files that create and run new containers instead of managing existing containers - Support for --log-opt tag= to set logging tags has been added to the journald log driver - Added support for using Seccomp profiles embedded in images for podman run and podman create via the new --seccomp-policy CLI flag - The podman play kube command now honors pull policy

    - Fixed a bug where the podman cp command would not copy the contents of directories when paths ending in /. were given - Fixed a bug where the podman play kube command did not properly locate Seccomp profiles specified relative to localhost - Fixed a bug where the podman info command for remote Podman did not show registry information - Fixed a bug where the podman exec command did not support having input piped into it - Fixed a bug where the podman cp command with rootless Podman on CGroups v2 systems did not properly determine if the container could be paused while copying - Fixed a bug where the podman container prune --force command could possible remove running containers if they were started while the command was running - Fixed a bug where Podman, when run as root, would not properly configure slirp4netns networking when requested - Fixed a bug where podman run --userns=keep-id did not work when the user had a UID over 65535 - Fixed a bug where rootless podman run and podman create with the --userns=keep-id option could change permissions on /run/user/$UID and break KDE - Fixed a bug where rootless Podman could not be run in a systemd service on systems using CGroups v2 - Fixed a bug where podman inspect would show CPUShares as 0, instead of the default (1024), when it was not explicitly set - Fixed a bug where podman-remote push would segfault - Fixed a bug where image healthchecks were not shown in the output of podman inspect - Fixed a bug where named volumes created with containers from pre-1.6.3 releases of Podman would be autoremoved with their containers if the --rm flag was given, even if they were given names - Fixed a bug where podman history was not computing image sizes correctly - Fixed a bug where Podman would not error on invalid values to the --sort flag to podman images - Fixed a bug where providing a name for the image made by podman commit was mandatory, not optional as it should be - Fixed a bug where the remote Podman client would append an extra ' to %PATH - Fixed a bug where the podman build command would sometimes ignore the -f option and build the wrong Containerfile - Fixed a bug where the podman ps --filter command would only filter running containers, instead of all containers, if --all was not passed - Fixed a bug where the podman load command on compressed images would leave an extra copy on disk - Fixed a bug where the podman restart command would not properly clean up the network, causing it to function differently from podman stop; podman start - Fixed a bug where setting the --memory-swap flag to podman create and podman run to -1 (to indicate unlimited) was not supported

    - Initial work on version 2 of the Podman remote API has been merged, but is still in an alpha state and not ready for use. Read more here - Many formatting corrections have been made to the manpages - The changes to address (#5009) may cause anonymous volumes created by Podman versions 1.6.3 to 1.7.0 to not be removed when their container is removed - Updated vendored Buildah to v1.13.1 - Updated vendored containers/storage to v1.15.8 - Updated vendored containers/image to v5.2.0


    Update podman to v1.7.0

    - Added support for setting a static MAC address for containers - Added support for creating macvlan networks with podman network create, allowing Podman containers to be attached directly to networks the host is connected to - The podman image prune and podman container prune commands now support the --filter flag to filter what will be pruned, and now prompts for confirmation when run without --force (#4410 and #4411) - Podman now creates CGroup namespaces by default on systems using CGroups v2 (#4363) - Added the podman system reset command to remove all Podman files and perform a factory reset of the Podman installation - Added the --history flag to podman images to display previous names used by images (#4566) - Added the --ignore flag to podman rm and podman stop to not error when requested containers no longer exist - Added the --cidfile flag to podman rm and podman stop to read the IDs of containers to be removed or stopped from a file - The podman play kube command now honors Seccomp annotations (#3111) - The podman play kube command now honors RunAsUser, RunAsGroup, and selinuxOptions - The output format of the podman version command has been changed to better match docker version when using the --format flag - Rootless Podman will no longer initialize containers/storage twice, removing a potential deadlock preventing Podman commands from running while an image was being pulled (#4591) - Added tmpcopyup and notmpcopyup options to the --tmpfs and --mount type=tmpfs flags to podman create and podman run to control whether the content of directories are copied into tmpfs filesystems mounted over them - Added support for disabling detaching from containers by setting empty detach keys via --detach-keys='' - The podman build command now supports the --pull and --pull-never flags to control when images are pulled during a build - The podman ps -p command now shows the name of the pod as well as its ID (#4703) - The podman inspect command on containers will now display the command used to create the container - The podman info command now displays information on registry mirrors (#4553)

    - Fixed a bug where Podman would use an incorrect runtime directory as root, causing state to be deleted after root logged out and making Podman in systemd services not function properly - Fixed a bug where the --change flag to podman import and podman commit was not being parsed properly in many cases - Fixed a bug where detach keys specified in libpod.conf were not used by the podman attach and podman exec commands, which always used the global default ctrl-p,ctrl-q key combination (#4556) - Fixed a bug where rootless Podman was not able to run podman pod stats even on CGroups v2 enabled systems (#4634) - Fixed a bug where rootless Podman would fail on kernels without the renameat2 syscall (#4570) - Fixed a bug where containers with chained network namespace dependencies (IE, container A using --net container=B and container B using --net container=C) would not properly mount /etc/hosts and /etc/resolv.conf into the container (#4626) - Fixed a bug where podman run with the --rm flag and without -d could, when run in the background, throw a 'container does not exist' error when attempting to remove the container after it exited - Fixed a bug where named volume locks were not properly reacquired after a reboot, potentially leading to deadlocks when trying to start containers using the volume (#4605 and #4621) - Fixed a bug where Podman could not completely remove containers if sent SIGKILL during removal, leaving the container name unusable without the podman rm --storage command to complete removal (#3906) - Fixed a bug where checkpointing containers started with --rm was allowed when --export was not specified (the container, and checkpoint, would be removed after checkpointing was complete by --rm) (#3774) - Fixed a bug where the podman pod prune command would fail if containers were present in the pods and the --force flag was not passed (#4346) - Fixed a bug where containers could not set a static IP or static MAC address if they joined a non-default CNI network (#4500) - Fixed a bug where podman system renumber would always throw an error if a container was mounted when it was run - Fixed a bug where podman container restore would fail with containers using a user namespace - Fixed a bug where rootless Podman would attempt to use the journald events backend even on systems without systemd installed - Fixed a bug where podman history would sometimes not properly identify the IDs of layers in an image (#3359) - Fixed a bug where containers could not be restarted when Conmon v2.0.3 or later was used - Fixed a bug where Podman did not check image OS and Architecture against the host when starting a container - Fixed a bug where containers in pods did not function properly with the Kata OCI runtime (#4353) - Fixed a bug where `podman info --format '{{ json . }}' would not produce JSON output (#4391) - Fixed a bug where Podman would not verify if files passed to --authfile existed (#4328) - Fixed a bug where podman images --digest would not always print digests when they were available - Fixed a bug where rootless podman run could hang due to a race with reading and writing events - Fixed a bug where rootless Podman would print warning-level logs despite not be instructed to do so (#4456) - Fixed a bug where podman pull would attempt to fetch from remote registries when pulling an unqualified image using the docker-daemon transport (#4434) - Fixed a bug where podman cp would not work if STDIN was a pipe - Fixed a bug where podman exec could stop accepting input if anything was typed between the command being run and the exec session starting (#4397) - Fixed a bug where podman logs --tail 0 would print all lines of a container's logs, instead of no lines (#4396) - Fixed a bug where the timeout for slirp4netns was incorrectly set, resulting in an extremely long timeout (#4344) - Fixed a bug where the podman stats command would print CPU utilizations figures incorrectly (#4409) - Fixed a bug where the podman inspect --size command would not print the size of the container's read/write layer if the size was 0 (#4744) - Fixed a bug where the podman kill command was not properly validating signals before use (#4746) - Fixed a bug where the --quiet and --format flags to podman ps could not be used at the same time - Fixed a bug where the podman stop command was not stopping exec sessions when a container was created without a PID namespace (--pid=host) - Fixed a bug where the podman pod rm --force command was not removing anonymous volumes for containers that were removed - Fixed a bug where the podman checkpoint command would not export all changes to the root filesystem of the container if performed more than once on the same container (#4606) - Fixed a bug where containers started with --rm would not be automatically removed on being stopped if an exec session was running inside the container (#4666)

    - The fixes to runtime directory path as root can cause strange behavior if an upgrade is performed while containers are running - Updated vendored Buildah to v1.12.0 - Updated vendored containers/storage library to v1.15.4 - Updated vendored containers/image library to v5.1.0 - Kata Containers runtimes (kata-runtime, kata-qemu, and kata-fc) are now present in the default libpod.conf, but will not be available unless Kata containers is installed on the system - Podman previously did not allow the creation of containers with a memory limit lower than 4MB. This restriction has been removed, as the crun runtime can create containers with significantly less memory
    Update podman to v1.6.4
    Update podman to v1.6.2

    - Added a --runtime flag to podman system migrate to allow the OCI runtime for all containers to be reset, to ease transition to the crun runtime on CGroups V2 systems until runc gains full support - The podman rm command can now remove containers in broken states which previously could not be removed - The podman info command, when run without root, now shows information on UID and GID mappings in the rootless user namespace - Added podman build --squash-all flag, which squashes all layers (including those of the base image) into one layer - The --systemd flag to podman run and podman create now accepts a string argument and allows a new value, always, which forces systemd support without checking if the the container entrypoint is systemd

    - Fixed a bug where the podman top command did not work on systems using CGroups V2 (#4192) - Fixed a bug where rootless Podman could double-close a file, leading to a panic - Fixed a bug where rootless Podman could fail to retrieve some containers while refreshing the state - Fixed a bug where podman start --attach --sig-proxy=false would still proxy signals into the container - Fixed a bug where Podman would unconditionally use a non-default path for authentication credentials (auth.json), breaking podman login integration with skopeo and other tools using the containers/image library - Fixed a bug where podman ps --format=json and podman images --format=json would display null when no results were returned, instead of valid JSON - Fixed a bug where podman build --squash was incorrectly squashing all layers into one, instead of only new layers - Fixed a bug where rootless Podman would allow volumes with options to be mounted (mounting volumes requires root), creating an inconsistent state where volumes reported as mounted but were not (#4248) - Fixed a bug where volumes which failed to unmount could not be removed (#4247) - Fixed a bug where Podman incorrectly handled some errors relating to unmounted or missing containers in containers/storage - Fixed a bug where podman stats was broken on systems running CGroups V2 when run rootless (#4268) - Fixed a bug where the podman start command would print the short container ID, instead of the full ID - Fixed a bug where containers created with an OCI runtime that is no longer available (uninstalled or removed from the config file) would not appear in podman ps and could not be removed via podman rm - Fixed a bug where containers restored via podman container restore --import would retain the CGroup path of the original container, even if their container ID changed; thus, multiple containers created from the same checkpoint would all share the same CGroup

    - The default PID limit for containers is now set to 4096. It can be adjusted back to the old default (unlimited) by passing --pids-limit 0 to podman create and podman run - The podman start --attach command now automatically attaches STDIN if the container was created with -i - The podman network create command now validates network names using the same regular expression as container and pod names - The --systemd flag to podman run and podman create will now only enable systemd mode when the binary being run inside the container is /sbin/init, /usr/sbin/init, or ends in systemd (previously detected any path ending in init or systemd) - Updated vendored Buildah to 1.11.3 - Updated vendored containers/storage to 1.13.5 - Updated vendored containers/image to 4.0.1
    Update podman to v1.6.1

    - The podman network create, podman network rm, podman network inspect, and podman network ls commands have been added to manage CNI networks used by Podman - The podman volume create command can now create and mount volumes with options, allowing volumes backed by NFS, tmpfs, and many other filesystems - Podman can now run containers without CGroups for better integration with systemd by using the --cgroups=disabled flag with podman create and podman run. This is presently only supported with the crun OCI runtime - The podman volume rm and podman volume inspect commands can now refer to volumes by an unambiguous partial name, in addition to full name (e.g. podman volume rm myvol to remove a volume named myvolume) (#3891) - The podman run and podman create commands now support the --pull flag to allow forced re-pulling of images (#3734) - Mounting volumes into a container using --volume, --mount, and --tmpfs now allows the suid, dev, and exec mount options (the inverse of nosuid, nodev, noexec) (#3819) - Mounting volumes into a container using --mount now allows the relabel=Z and relabel=z options to relabel mounts. - The podman push command now supports the --digestfile option to save a file containing the pushed digest - Pods can now have their hostname set via podman pod create --hostname or providing Pod YAML with a hostname set to podman play kube (#3732) - The podman image sign command now supports the --cert-dir flag - The podman run and podman create commands now support the --security-opt label=filetype:$LABEL flag to set the SELinux label for container files - The remote Podman client now supports healthchecks

    - Fixed a bug where remote podman pull would panic if a Varlink connection was not available (#4013) - Fixed a bug where podman exec would not properly set terminal size when creating a new exec session (#3903) - Fixed a bug where podman exec would not clean up socket symlinks on the host (#3962) - Fixed a bug where Podman could not run systemd in containers that created a CGroup namespace - Fixed a bug where podman prune -a would attempt to prune images used by Buildah and CRI-O, causing errors (#3983) - Fixed a bug where improper permissions on the ~/.config directory could cause rootless Podman to use an incorrect directory for storing some files - Fixed a bug where the bash completions for podman import threw errors - Fixed a bug where Podman volumes created with podman volume create would not copy the contents of their mountpoint the first time they were mounted into a container (#3945) - Fixed a bug where rootless Podman could not run podman exec when the container was not run inside a CGroup owned by the user (#3937) - Fixed a bug where podman play kube would panic when given Pod YAML without a securityContext (#3956) - Fixed a bug where Podman would place files incorrectly when storage.conf configuration items were set to the empty string (#3952) - Fixed a bug where podman build did not correctly inherit Podman's CGroup configuration, causing crashed on CGroups V2 systems (#3938) - Fixed a bug where remote podman run --rm would exit before the container was completely removed, allowing race conditions when removing container resources (#3870) - Fixed a bug where rootless Podman would not properly handle changes to /etc/subuid and /etc/subgid after a container was launched - Fixed a bug where rootless Podman could not include some devices in a container using the --device flag (#3905) - Fixed a bug where the commit Varlink API would segfault if provided incorrect arguments (#3897) - Fixed a bug where temporary files were not properly cleaned up after a build using remote Podman (#3869) - Fixed a bug where podman remote cp crashed instead of reporting it was not yet supported (#3861) - Fixed a bug where podman exec would run as the wrong user when execing into a container was started from an image with Dockerfile USER (or a user specified via podman run --user) (#3838) - Fixed a bug where images pulled using the oci: transport would be improperly named - Fixed a bug where podman varlink would hang when managed by systemd due to SD_NOTIFY support conflicting with Varlink (#3572) - Fixed a bug where mounts to the same destination would sometimes not trigger a conflict, causing a race as to which was actually mounted - Fixed a bug where podman exec --preserve-fds caused Podman to hang (#4020) - Fixed a bug where removing an unmounted container that was unmounted might sometimes not properly clean up the container (#4033) - Fixed a bug where the Varlink server would freeze when run in a systemd unit file (#4005) - Fixed a bug where Podman would not properly set the $HOME environment variable when the OCI runtime did not set it - Fixed a bug where rootless Podman would incorrectly print warning messages when an OCI runtime was not found (#4012) - Fixed a bug where named volumes would conflict with, instead of overriding, tmpfs filesystems added by the --read-only-tmpfs flag to podman create and podman run - Fixed a bug where podman cp would incorrectly make the target directory when copying to a symlink which pointed to a nonexistent directory (#3894) - Fixed a bug where remote Podman would incorrectly read STDIN when the -i flag was not set (#4095) - Fixed a bug where podman play kube would create an empty pod when given an unsupported YAML type (#4093) - Fixed a bug where podman import --change improperly parsed CMD (#4000) - Fixed a bug where rootless Podman on systems using CGroups V2 would not function with the cgroupfs CGroups manager - Fixed a bug where rootless Podman could not correctly identify the DBus session address, causing containers to fail to start (#4162) - Fixed a bug where rootless Podman with slirp4netns networking would fail to start containers due to mount leaks

    - Significant changes were made to Podman volumes in this release. If you have pre-existing volumes, it is strongly recommended to run podman system renumber after upgrading. - Version 0.8.1 or greater of the CNI Plugins is now required for Podman - Version 2.0.1 or greater of Conmon is strongly recommended - Updated vendored Buildah to v1.11.2 - Updated vendored containers/storage library to v1.13.4 - Improved error messages when trying to create a pod with no name via podman play kube - Improved error messages when trying to run podman pause or podman stats on a rootless container on a system without CGroups V2 enabled - TMPDIR has been set to /var/tmp by default to better handle large temporary files - podman wait has been optimized to detect stopped containers more rapidly - Podman containers now include a ContainerManager annotation indicating they were created by libpod - The podman info command now includes information about slirp4netns and fuse-overlayfs if they are available - Podman no longer sets a default size of 65kb for tmpfs filesystems - The default Podman CNI network has been renamed in an attempt to prevent conflicts with CRI-O when both are run on the same system. This should only take effect on system restart - The output of podman volume inspect has been more closely matched to docker volume inspect

    Update podman to v1.5.1

    - The hostname of pods is now set to the pod's name

    - Fixed a bug where podman run and podman create did not honor the --authfile option (#3730) - Fixed a bug where containers restored with podman container restore --import would incorrectly duplicate the Conmon PID file of the original container - Fixed a bug where podman build ignored the default OCI runtime configured in libpod.conf - Fixed a bug where podman run --rm (or force-removing any running container with podman rm --force) were not retrieving the correct exit code (#3795) - Fixed a bug where Podman would exit with an error if any configured hooks directory was not present - Fixed a bug where podman inspect and podman commit would not use the correct CMD for containers run with podman play kube - Fixed a bug created pods when using rootless Podman and CGroups V2 (#3801) - Fixed a bug where the podman events command with the --since or --until options could take a very long time to complete
    - Rootless Podman will now inherit OCI runtime configuration from the root configuration (#3781) - Podman now properly sets a user agent while contacting registries (#3788)

    Update podman to v1.5.0

    - Podman containers can now join the user namespaces of other containers with --userns=container:$ID, or a user namespace at an arbitary path with --userns=ns:$PATH - Rootless Podman can experimentally squash all UIDs and GIDs in an image to a single UID and GID (which does not require use of the newuidmap and newgidmap executables) by passing --storage-opt ignore_chown_errors - The podman generate kube command now produces YAML for any bind mounts the container has created (#2303) - The podman container restore command now features a new flag, --ignore-static-ip, that can be used with --import to import a single container with a static IP multiple times on the same host - Added the ability for podman events to output JSON by specifying --format=json - If the OCI runtime or conmon binary cannot be found at the paths specified in libpod.conf, Podman will now also search for them in the calling user's path - Added the ability to use podman import with URLs (#3609) - The podman ps command now supports filtering names using regular expressions (#3394) - Rootless Podman containers with --privileged set will now mount in all host devices that the user can access - The podman create and podman run commands now support the --env-host flag to forward all environment variables from the host into the container - Rootless Podman now supports healthchecks (#3523) - The format of the HostConfig portion of the output of podman inspect on containers has been improved and synced with Docker - Podman containers now support CGroup namespaces, and can create them by passing --cgroupns=private to podman run or podman create - The podman create and podman run commands now support the --ulimit=host flag, which uses any ulimits currently set on the host for the container - The podman rm and podman rmi commands now use different exit codes to indicate 'no such container' and 'container is running' errors - Support for CGroups V2 through the crun OCI runtime has been greatly improved, allowing resource limits to be set for rootless containers when the CGroups V2 hierarchy is in use

    - Fixed a bug where a race condition could cause podman restart to fail to start containers with ports - Fixed a bug where containers restored from a checkpoint would not properly report the time they were started at - Fixed a bug where podman search would return at most 25 results, even when the maximum number of results was set higher - Fixed a bug where podman play kube would not honor capabilities set in imported YAML (#3689) - Fixed a bug where podman run --env, when passed a single key (to use the value from the host), would set the environment variable in the container even if it was not set on the host (#3648) - Fixed a bug where podman commit --changes would not properly set environment variables - Fixed a bug where Podman could segfault while working with images with no history - Fixed a bug where podman volume rm could remove arbitrary volumes if given an ambiguous name (#3635) - Fixed a bug where podman exec invocations leaked memory by not cleaning up files in tmpfs - Fixed a bug where the --dns and --net=container flags to podman run and podman create were not mutually exclusive (#3553) - Fixed a bug where rootless Podman would be unable to run containers when less than 5 UIDs were available - Fixed a bug where containers in pods could not be removed without removing the entire pod (#3556) - Fixed a bug where Podman would not properly clean up all CGroup controllers for created cgroups when using the cgroupfs CGroup driver - Fixed a bug where Podman containers did not properly clean up files in tmpfs, resulting in a memory leak as containers stopped - Fixed a bug where healthchecks from images would not use default settings for interval, retries, timeout, and start period when they were not provided by the image (#3525) - Fixed a bug where healthchecks using the HEALTHCHECK CMD format where not properly supported (#3507) - Fixed a bug where volume mounts using relative source paths would not be properly resolved (#3504) - Fixed a bug where podman run did not use authorization credentials when a custom path was specified (#3524) - Fixed a bug where containers checkpointed with podman container checkpoint did not properly set their finished time - Fixed a bug where running podman inspect on any container not created with podman run or podman create (for example, pod infra containers) would result in a segfault (#3500) - Fixed a bug where healthcheck flags for podman create and podman run were incorrectly named (#3455) - Fixed a bug where Podman commands would fail to find targets if a partial ID was specified that was ambiguous between a container and pod (#3487) - Fixed a bug where restored containers would not have the correct SELinux label - Fixed a bug where Varlink endpoints were not working properly if more was not correctly specified - Fixed a bug where the Varlink PullImage endpoint would crash if an error occurred (#3715) - Fixed a bug where the --mount flag to podman create and podman run did not allow boolean arguments for its ro and rw options (#2980) - Fixed a bug where pods did not properly share the UTS namespace, resulting in incorrect behavior from some utilities which rely on hostname (#3547) - Fixed a bug where Podman would unconditionally append ENTRYPOINT to CMD during podman commit (and when reporting CMD in podman inspect) (#3708) - Fixed a bug where podman events with the journald events backend would incorrectly print 6 previous events when only new events were requested (#3616) - Fixed a bug where podman port would exit prematurely when a port number was specified (#3747) - Fixed a bug where passing . as an argument to the --dns-search flag to podman create and podman run was not properly clearing DNS search domains in the container

    - Updated vendored Buildah to v1.10.1 - Updated vendored containers/image to v3.0.2 - Updated vendored containers/storage to v1.13.1 - Podman now requires conmon v2.0.0 or higher - The podman info command now displays the events logger being in use - The podman inspect command on containers now includes the ID of the pod a container has joined and the PID of the container's conmon process - The -v short flag for podman --version has been re-added - Error messages from podman pull should be significantly clearer - The podman exec command is now available in the remote client - The podman-v1.5.0.tar.gz file attached is podman packaged for MacOS. It can be installed using Homebrew.
    conmon was included in version 2.0.10. (bsc#1160460, bsc#1164390, jsc#ECO-1048, jsc#SLE-11485, jsc#SLE-11331):
    fuse-overlayfs was updated to v0.7.6 (bsc#1160460)

    cni was updated to 0.7.1:

    Update to version 0.7.1 (bsc#1160460):

    + invoke : ensure custom envs of CNIArgs are prepended to process envs + add GetNetworkListCachedResult to CNI interface + delegate : allow delegation funcs override CNI_COMMAND env automatically in heritance

    + Update cnitool documentation for spec v0.4.0 + Add cni-route-override to CNI plugin list
    Update to version 0.7.0:

    + Use more RFC2119 style language in specification (must, should...) + add notes about ADD/DEL ordering + Make the container ID required and unique. + remove the version parameter from ADD and DEL commands. + Network interface name matters + be explicit about optional and required structure members + add CHECK method + Add a well-known error for 'try again' + SPEC.md: clarify meaning of 'routes'

    + pkg/types: Makes IPAM concrete type + libcni: return error if Type is empty + skel: VERSION shouldn't block on stdin + non-pointer instances of types.Route now correctly marshal to JSON + libcni: add ValidateNetwork and ValidateNetworkList functions + pkg/skel: return error if JSON config has no network name + skel: add support for plugin version string + libcni: make exec handling an interface for better downstream testing + libcni: api now takes a Context to allow operations to be timed out or cancelled + types/version: add helper to parse PrevResult + skel: only print about message, not errors + skel,invoke,libcni: implementation of CHECK method + cnitool: Honor interface name supplied via CNI_IFNAME environment variable. + cnitool: validate correct number of args + Don't copy gw from IP4.Gateway to Route.GW When converting from 0.2.0 + add PrintTo method to Result interface + Return a better error when the plugin returns none
    cni-plugins was updated to 0.8.4:
    Update to version 0.8.4 (bsc#1160460):

    Update to version 0.8.3:



    * bugfix: defer after err check, or it may panic (#391). * portmap: Fix dual-stack support (#379). * firewall: don't return error in DEL if prevResult is not found (#390). * bump up libcni back to v0.7.1 (#377).

    * contributing doc: revise test script name to run (#396). * contributing doc: describe cnitool installation (#397).
    Update plugins to v0.8.2

    * Support 'args' in static and tuning * Add Loopback DSR support, allow l2tunnel networks to be used with the l2bridge plugin * host-local: return error if same ADD request is seen twice * bandwidth: fix collisions * Support ips capability in static and mac capability in tuning * pkg/veth: Make host-side veth name configurable

    Updated plugins to v0.8.1:

    * bridge: fix ipMasq setup to use correct source address * fix compilation error on 386 * bandwidth: get bandwidth interface in host ns through container interface

    Updated plugins to v0.8.0:

    * bandwidth - limit incoming and outgoing bandwidth * firewall - add containers to firewall rules * sbr - convert container routes to source-based routes * static - assign a fixed IP address * win-bridge, win-overlay: Windows plugins

    * CHECK Support * macvlan: - Allow to configure empty ipam for macvlan - Make master config optional * bridge: - Add vlan tag to the bridge cni plugin - Allow the user to assign VLAN tag - L2 bridge Implementation. * dhcp: - Include Subnet Mask option parameter in DHCPREQUEST - Add systemd unit file to activate socket with systemd - Add container ifName to the dhcp clientID, making the clientID value * flannel: - Pass through runtimeConfig to delegate * host-local: - host-local: add ifname to file tracking IP address used * host-device: - Support the IPAM in the host-device - Handle empty netns in DEL for loopback and host-device * tuning: - adds 'ip link' command related feature into tuning
    from version v0.7.5:


    Advisory IDSUSE-RU-2020:825-1
    ReleasedTue Mar 31 13:30:37 2020
    SummaryRecommended update for openslp
    Typerecommended
    Severitymoderate
    References1165050,1165121
    Description:

    This update for openslp fixes the following issues:


    Advisory IDSUSE-RU-2020:917-1
    ReleasedFri Apr 3 15:02:25 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2020:944-1
    ReleasedTue Apr 7 15:49:33 2020
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1149954,1160452,CVE-2019-19921
    Description:

    This update for runc fixes the following issues:
    runc was updated to v1.0.0~rc10


    Advisory IDSUSE-SU-2020:948-1
    ReleasedWed Apr 8 07:44:21 2020
    SummarySecurity update for gmp, gnutls, libnettle
    Typesecurity
    Severitymoderate
    References1152692,1155327,1166881,1168345,CVE-2020-11501
    Description:

    This update for gmp, gnutls, libnettle fixes the following issues:
    Security issue fixed:


    FIPS related bugfixes:


    Advisory IDSUSE-RU-2020:1181-1
    ReleasedTue May 5 12:02:39 2020
    SummaryRecommended update for pciutils-ids
    Typerecommended
    Severitymoderate
    References1170160
    Description:

    This update for pciutils-ids fixes the following issues:


    Advisory IDSUSE-RU-2020:1226-1
    ReleasedFri May 8 10:51:05 2020
    SummaryRecommended update for gcc9
    Typerecommended
    Severitymoderate
    References1149995,1152590,1167898
    Description:

    This update for gcc9 fixes the following issues:
    This update ships the GCC 9.3 release.


    Advisory IDSUSE-RU-2020:1266-1
    ReleasedWed May 13 10:20:54 2020
    SummaryRecommended update for jq
    Typerecommended
    Severitymoderate
    References1170838
    Description:

    This update for jq fixes the following issues:
    jq was updated to version 1.6:

    '.' for the program, regardless of stdin/stdout
  • fix: Make sorting stable regardless of qsort.


  • Advisory IDSUSE-SU-2020:1294-1
    ReleasedMon May 18 07:38:36 2020
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1154661,1169512,CVE-2019-18218
    Description:

    This update for file fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2020:1298-1
    ReleasedMon May 18 07:42:49 2020
    SummarySecurity update for libbsd
    Typesecurity
    Severitymoderate
    References1160551,CVE-2019-20367
    Description:

    This update for libbsd fixes the following issues:


    Advisory IDSUSE-RU-2020:1303-1
    ReleasedMon May 18 09:40:36 2020
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1169582
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-RU-2020:1308-1
    ReleasedMon May 18 10:05:46 2020
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References1170247
    Description:

    This update for psmisc fixes the following issues:


    Advisory IDSUSE-RU-2020:1328-1
    ReleasedMon May 18 17:16:04 2020
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1155271
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-SU-2020:1419-1
    ReleasedTue May 26 12:23:30 2020
    SummarySecurity update for sysstat
    Typesecurity
    Severitylow
    References1159104,CVE-2019-19725
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-SU-2020:1493-1
    ReleasedWed May 27 18:55:51 2020
    SummarySecurity update for libmspack
    Typesecurity
    Severitylow
    References1130489,1141680,CVE-2019-1010305
    Description:

    This update for libmspack fixes the following issues:
    Security issue fixed:

    Other issue addressed:


    Advisory IDSUSE-RU-2020:1542-1
    ReleasedThu Jun 4 13:24:37 2020
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1172055
    Description:

    This update for timezone fixes the following issue:


    Advisory IDSUSE-SU-2020:1677-1
    ReleasedThu Jun 18 18:16:39 2020
    SummarySecurity update for mozilla-nspr, mozilla-nss
    Typesecurity
    Severityimportant
    References1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nss was updated to version 3.53

    Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes
    mozilla-nspr to version 4.25


    Advisory IDSUSE-RU-2020:1954-1
    ReleasedSat Jul 18 03:07:15 2020
    SummaryRecommended update for cracklib
    Typerecommended
    Severitymoderate
    References1172396
    Description:

    This update for cracklib fixes the following issues:


    Advisory IDSUSE-RU-2020:2080-1
    ReleasedWed Jul 29 20:09:09 2020
    SummaryRecommended update for libtool
    Typerecommended
    Severitymoderate
    References1171566
    Description:


    This update for libtool provides missing the libltdl 32bit library. (bsc#1171566)


    Advisory IDSUSE-RU-2020:2083-1
    ReleasedThu Jul 30 10:27:59 2020
    SummaryRecommended update for diffutils
    Typerecommended
    Severitymoderate
    References1156913
    Description:

    This update for diffutils fixes the following issue:


    Advisory IDSUSE-RU-2020:2470-1
    ReleasedWed Sep 2 23:29:43 2020
    SummaryRecommended update for lshw
    Typerecommended
    Severitymoderate
    References1168865,1169668,1172156
    Description:

    This update for lshw fixes the following issues:


    Advisory IDSUSE-SU-2020:2731-1
    ReleasedThu Sep 24 07:42:32 2020
    SummarySecurity update for conmon, fuse-overlayfs, libcontainers-common, podman
    Typesecurity
    Severitymoderate
    References1162432,1164090,1165738,1171578,1174075,1175821,1175957,CVE-2020-1726
    Description:

    This update for conmon, fuse-overlayfs, libcontainers-common, podman fixes the following issues:
    podman was updated to v2.0.6 (bsc#1175821)


    * Fixed a bug where running systemd in a container on a cgroups v1 system would fail. * Fixed a bug where /etc/passwd could be re-created every time a container is restarted if the container's /etc/passwd did not contain an entry for the user the container was started as. * Fixed a bug where containers without an /etc/passwd file specifying a non-root user would not start. * Fixed a bug where the --remote flag would sometimes not make remote connections and would instead attempt to run Podman locally.
    Update to v2.0.6:

    - Rootless Podman will now add an entry to /etc/passwd for the user who ran Podman if run with --userns=keep-id. - The podman system connection command has been reworked to support multiple connections, and reenabled for use! - Podman now has a new global flag, --connection, to specify a connection to a remote Podman API instance.

    - Podman's automatic systemd integration (activated by the --systemd=true flag, set by default) will now activate for containers using /usr/local/sbin/init as their command, instead of just /usr/sbin/init and /sbin/init (and any path ending in systemd). - Seccomp profiles specified by the --security-opt seccomp=... flag to podman create and podman run will now be honored even if the container was created using --privileged.

    - Fixed a bug where the podman play kube would not honor the hostIP field for port forwarding (#5964). - Fixed a bug where the podman generate systemd command would panic on an invalid restart policy being specified (#7271). - Fixed a bug where the podman images command could take a very long time (several minutes) to complete when a large number of images were present. - Fixed a bug where the podman logs command with the --tail flag would not work properly when a large amount of output would be printed ((#7230)[https://github.com//issues/7230]). - Fixed a bug where the podman exec command with remote Podman would not return a non-zero exit code when the exec session failed to start (e.g. invoking a non-existent command) (#6893). - Fixed a bug where the podman load command with remote Podman would did not honor user-specified tags (#7124). - Fixed a bug where the podman system service command, when run as a non-root user by Systemd, did not properly handle the Podman pause process and would not restart properly as a result (#7180). - Fixed a bug where the --publish flag to podman create, podman run, and podman pod create did not properly handle a host IP of 0.0.0.0 (attempting to bind to literal 0.0.0.0, instead of all IPs on the system) (#7104). - Fixed a bug where the podman start --attach command would not print the container's exit code when the command exited due to the container exiting. - Fixed a bug where the podman rm command with remote Podman would not remove volumes, even if the --volumes flag was specified (#7128). - Fixed a bug where the podman run command with remote Podman and the --rm flag could exit before the container was fully removed. - Fixed a bug where the --pod new:... flag to podman run and podman create would create a pod that did not share any namespaces. - Fixed a bug where the --preserve-fds flag to podman run and podman exec could close the wrong file descriptors while trying to close user-provided descriptors after passing them into the container. - Fixed a bug where default environment variables ($PATH and $TERM) were not set in containers when not provided by the image. - Fixed a bug where pod infra containers were not properly unmounted after exiting. - Fixed a bug where networks created with podman network create with an IPv6 subnet did not properly set an IPv6 default route. - Fixed a bug where the podman save command would not work properly when its output was piped to another command (#7017). - Fixed a bug where containers using a systemd init on a cgroups v1 system could leak mounts under /sys/fs/cgroup/systemd to the host. - Fixed a bug where podman build would not generate an event on completion (#7022). - Fixed a bug where the podman history command with remote Podman printed incorrect creation times for layers (#7122). - Fixed a bug where Podman would not create working directories specified by the container image if they did not exist. - Fixed a bug where Podman did not clear CMD from the container image if the user overrode ENTRYPOINT (#7115). - Fixed a bug where error parsing image names were not fully reported (part of the error message containing the exact issue was dropped). - Fixed a bug where the podman images command with remote Podman did not support printing image tags in Go templates supplied to the --format flag (#7123). - Fixed a bug where the podman rmi --force command would not attempt to unmount containers it was removing, which could cause a failure to remove the image. - Fixed a bug where the podman generate systemd --new command could incorrectly quote arguments to Podman that contained whitespace, leading to nonfunctional unit files (#7285). - Fixed a bug where the podman version command did not properly include build time and Git commit. - Fixed a bug where running systemd in a Podman container on a system that did not use the systemd cgroup manager would fail (#6734). - Fixed a bug where capabilities from --cap-add were not properly added when a container was started as a non-root user via --user. - Fixed a bug where Pod infra containers were not properly cleaned up when they stopped, causing networking issues (#7103).

    - Fixed a bug where the libpod and compat Build endpoints did not accept the application/tar content type (instead only accepting application/x-tar) (#7185). - Fixed a bug where the libpod Exists endpoint would attempt to write a second header in some error conditions (#7197). - Fixed a bug where compat and libpod Network Inspect and Network Remove endpoints would return a 500 instead of 404 when the requested network was not found. - Added a versioned _ping endpoint (e.g. http://localhost/v1.40/_ping). - Fixed a bug where containers started through a systemd-managed instance of the REST API would be shut down when podman system service shut down due to its idle timeout (#7294). - Added stronger parameter verification for the libpod Network Create endpoint to ensure subnet mask is a valid value. - The Pod URL parameter to the Libpod Container List endpoint has been deprecated; the information previously gated by the Pod boolean will now be included in the response unconditionally.

    Update to v2.0.4


    Update to v2.0.3

    Update to podman v2.0.2

    Update to podman v2.0.0

    Update to podman v1.9.3:

    Update podman to v1.9.1:

    - Fixed a bug where healthchecks could become nonfunctional if container log paths were manually set with --log-path and multiple container logs were placed in the same directory - Fixed a bug where rootless Podman could, when using an older libpod.conf, print numerous warning messages about an invalid CGroup manager config - Fixed a bug where rootless Podman would sometimes fail to close the rootless user namespace when joining it
    Update podman to v1.9.0:

    - Experimental support has been added for podman run --userns=auto, which automatically allocates a unique UID and GID range for the new container's user namespace - The podman play kube command now has a --network flag to place the created pod in one or more CNI networks - The podman commit command now supports an --iidfile flag to write the ID of the committed image to a file - Initial support for the new containers.conf configuration file has been added. containers.conf allows for much more detailed configuration of some Podman functionality

    - There has been a major cleanup of the podman info command resulting in breaking changes. Many fields have been renamed to better suit usage with APIv2 - All uses of the --timeout flag have been switched to prefer the alternative --time. The --timeout flag will continue to work, but man pages and --help will use the --time flag instead

    - Fixed a bug where some volume mounts from the host would sometimes not properly determine the flags they should use when mounting - Fixed a bug where Podman was not propagating $PATH to Conmon and the OCI runtime, causing issues for some OCI runtimes that required it - Fixed a bug where rootless Podman would print error messages about missing support for systemd cgroups when run in a container with no cgroup support - Fixed a bug where podman play kube would not properly handle container-only port mappings (#5610) - Fixed a bug where the podman container prune command was not pruning containers in the created and configured states - Fixed a bug where Podman was not properly removing CNI IP address allocations after a reboot (#5433) - Fixed a bug where Podman was not properly applying the default Seccomp profile when --security-opt was not given at the command line

    - Many Libpod API endpoints have been added, including Changes, Checkpoint, Init, and Restore - Resolved issues where the podman system service command would time out and exit while there were still active connections - Stability overall has greatly improved as we prepare the API for a beta release soon with Podman 2.0

    - The default infra image for pods has been upgraded to k8s.gcr.io/pause:3.2 (from 3.1) to address a bug in the architecture metadata for non-AMD64 images - The slirp4netns networking utility in rootless Podman now uses Seccomp filtering where available for improved security - Updated Buildah to v1.14.8 - Updated containers/storage to v1.18.2 - Updated containers/image to v5.4.3 - Updated containers/common to v0.8.1

    Update podman to v1.8.2:

    - Initial support for automatically updating containers managed via Systemd unit files has been merged. This allows containers to automatically upgrade if a newer version of their image becomes available

    - Fixed a bug where unit files generated by podman generate systemd --new would not force containers to detach, causing the unit to time out when trying to start - Fixed a bug where podman system reset could delete important system directories if run as rootless on installations created by older Podman (#4831) - Fixed a bug where image built by podman build would not properly set the OS and Architecture they were built with (#5503) - Fixed a bug where attached podman run with --sig-proxy enabled (the default), when built with Go 1.14, would repeatedly send signal 23 to the process in the container and could generate errors when the container stopped (#5483) - Fixed a bug where rootless podman run commands could hang when forwarding ports - Fixed a bug where rootless Podman would not work when /proc was mounted with the hidepid option set - Fixed a bug where the podman system service command would use large amounts of CPU when --timeout was set to 0 (#5531)

    - Initial support for Libpod endpoints related to creating and operating on image manifest lists has been added - The Libpod Healthcheck and Events API endpoints are now supported - The Swagger endpoint can now handle cases where no Swagger documentation has been generated
    Update podman to v1.8.1:

    - Many networking-related flags have been added to podman pod create to enable customization of pod networks, including --add-host, --dns, --dns-opt, --dns-search, --ip, --mac-address, --network, and --no-hosts - The podman ps --format=json command now includes the ID of the image containers were created with - The podman run and podman create commands now feature an --rmi flag to remove the image the container was using after it exits (if no other containers are using said image) ([#4628](https://github.com/containers/libpod/issues/4628)) - The podman create and podman run commands now support the --device-cgroup-rule flag (#4876) - While the HTTP API remains in alpha, many fixes and additions have landed. These are documented in a separate subsection below - The podman create and podman run commands now feature a --no-healthcheck flag to disable healthchecks for a container (#5299) - Containers now recognize the io.containers.capabilities label, which specifies a list of capabilities required by the image to run. These capabilities will be used as long as they are more restrictive than the default capabilities used - YAML produced by the podman generate kube command now includes SELinux configuration passed into the container via --security-opt label=... (#4950)

    - Fixed CVE-2020-1726, a security issue where volumes manually populated before first being mounted into a container could have those contents overwritten on first being mounted into a container - Fixed a bug where Podman containers with user namespaces in CNI networks with the DNS plugin enabled would not have the DNS plugin's nameserver added to their resolv.conf ([#5256](https://github.com/containers/libpod/issues/5256)) - Fixed a bug where trailing / characters in image volume definitions could cause them to not be overridden by a user-specified mount at the same location ([#5219](https://github.com/containers/libpod/issues/5219)) - Fixed a bug where the label option in libpod.conf, used to disable SELinux by default, was not being respected (#5087) - Fixed a bug where the podman login and podman logout commands required the registry to log into be specified (#5146) - Fixed a bug where detached rootless Podman containers could not forward ports (#5167) - Fixed a bug where rootless Podman could fail to run if the pause process had died - Fixed a bug where Podman ignored labels that were specified with only a key and no value (#3854) - Fixed a bug where Podman would fail to create named volumes when the backing filesystem did not support SELinux labelling (#5200) - Fixed a bug where --detach-keys='' would not disable detaching from a container (#5166) - Fixed a bug where the podman ps command was too aggressive when filtering containers and would force --all on in too many situations - Fixed a bug where the podman play kube command was ignoring image configuration, including volumes, working directory, labels, and stop signal (#5174) - Fixed a bug where the Created and CreatedTime fields in podman images --format=json were misnamed, which also broke Go template output for those fields ([#5110](https://github.com/containers/libpod/issues/5110)) - Fixed a bug where rootless Podman containers with ports forwarded could hang when started (#5182) - Fixed a bug where podman pull could fail to parse registry names including port numbers - Fixed a bug where Podman would incorrectly attempt to validate image OS and architecture when starting containers - Fixed a bug where Bash completion for podman build -f would not list available files that could be built (#3878) - Fixed a bug where podman commit --change would perform incorrect validation, resulting in valid changes being rejected (#5148) - Fixed a bug where podman logs --tail could take large amounts of memory when the log file for a container was large (#5131) - Fixed a bug where Podman would sometimes incorrectly generate firewall rules on systems using firewalld - Fixed a bug where the podman inspect command would not display network information for containers properly if a container joined multiple CNI networks ([#4907](https://github.com/containers/libpod/issues/4907)) - Fixed a bug where the --uts flag to podman create and podman run would only allow specifying containers by full ID (#5289) - Fixed a bug where rootless Podman could segfault when passed a large number of file descriptors - Fixed a bug where the podman port command was incorrectly interpreting additional arguments as container names, instead of port numbers - Fixed a bug where units created by podman generate systemd did not depend on network targets, and so could start before the system network was ready (#4130) - Fixed a bug where exec sessions in containers which did not specify a user would not inherit supplemental groups added to the container via --group-add - Fixed a bug where Podman would not respect the $TMPDIR environment variable for placing large temporary files during some operations (e.g. podman pull) ([#5411](https://github.com/containers/libpod/issues/5411))

    - Initial support for secure connections to servers via SSH tunneling has been added - Initial support for the libpod create and logs endpoints for containers has been added - Added a /swagger/ endpoint to serve API documentation - The json endpoint for containers has received many fixes - Filtering images and containers has been greatly improved, with many bugs fixed and documentation improved - Image creation endpoints (commit, pull, etc) have seen many fixes - Server timeout has been fixed so that long operations will no longer trigger the timeout and shut the server down - The stats endpoint for containers has seen major fixes and now provides accurate output - Handling the HTTP 304 status code has been fixed for all endpoints - Many fixes have been made to API documentation to ensure it matches the code

    - The Created field to podman images --format=json has been renamed to CreatedSince as part of the fix for (#5110). Go templates using the old name shou ld still work - The CreatedTime field to podman images --format=json has been renamed to CreatedAt as part of the fix for (#5110). Go templates using the old name should still work - The before filter to podman images has been renamed to since for Docker compatibility. Using before will still work, but documentation has been changed to use the new since filter - Using the --password flag to podman login now warns that passwords are being passed in plaintext - Some common cases where Podman would deadlock have been fixed to warn the user that podman system renumber must be run to resolve the deadlock

    conmon was update to v2.0.20 (bsc#1175821)


    - Add option to delay execution of exit command

    - tty: flush pending data when fd is ready

    - store status while waiting for pid

    - drop usage of splice(2) - avoid hanging on stdin - stdio: sometimes quit main loop after io is done - ignore sigpipe

    - oom: fix potential race between verification steps

    - log: reject --log-tag with k8s-file - chmod std files pipes - adjust score to -1000 to prevent conmon from ever being OOM killed - container OOM: verify cgroup hasn't been cleaned up before reporting OOM - journal logging: write to /dev/null instead of -1
    fuse-overlayfs was updated to 1.1.2 (bsc#1175821):

    libcontainers-common was updated to fix:






    Advisory IDSUSE-RU-2020:2735-1
    ReleasedThu Sep 24 13:32:25 2020
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1173034
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2020:2782-1
    ReleasedTue Sep 29 11:40:22 2020
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severityimportant
    References1176932
    Description:

    This update for systemd-rpm-macros fixes the following issues:



    Advisory IDSUSE-SU-2020:2947-1
    ReleasedFri Oct 16 15:23:07 2020
    SummarySecurity update for gcc10, nvptx-tools
    Typesecurity
    Severitymoderate
    References1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844
    Description:

    This update for gcc10, nvptx-tools fixes the following issues:
    This update provides the GCC10 compiler suite and runtime libraries.
    The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by the gcc10 variants.
    The new compiler variants are available with '-10' suffix, you can specify them via:
    CC=gcc-10 CXX=g++-10
    or similar commands.
    For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
    Changes in nvptx-tools:


    Advisory IDSUSE-RU-2020:2958-1
    ReleasedTue Oct 20 12:24:55 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:2983-1
    ReleasedWed Oct 21 15:03:03 2020
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1176123
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-RU-2020:3012-1
    ReleasedThu Oct 22 22:36:57 2020
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1174227
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-SU-2020:3091-1
    ReleasedThu Oct 29 16:35:37 2020
    SummarySecurity update for MozillaThunderbird and mozilla-nspr
    Typesecurity
    Severityimportant
    References1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969
    Description:

    This update for MozillaThunderbird and mozilla-nspr fixes the following issues:



    Advisory IDSUSE-RU-2020:3099-1
    ReleasedThu Oct 29 19:33:41 2020
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-RU-2020:3123-1
    ReleasedTue Nov 3 09:48:13 2020
    SummaryRecommended update for timezone
    Typerecommended
    Severityimportant
    References1177460,1178346,1178350,1178353
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-RU-2020:3308-1
    ReleasedThu Nov 12 14:20:07 2020
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1177747
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-RU-2020:3462-1
    ReleasedFri Nov 20 13:14:35 2020
    SummaryRecommended update for pam and sudo
    Typerecommended
    Severitymoderate
    References1174593,1177858,1178727
    Description:

    This update for pam and sudo fixes the following issue:
    pam:


    sudo:


    Advisory IDSUSE-RU-2020:3620-1
    ReleasedThu Dec 3 17:03:55 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:3791-1
    ReleasedMon Dec 14 17:39:19 2020
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gzip fixes the following issue:


    Advisory IDSUSE-OU-2020:3795-1
    ReleasedMon Dec 14 17:43:26 2020
    SummaryOptional update for systemd-rpm-macros
    Typeoptional
    Severitylow
    References1059627,1178481,1179020
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2020:3942-1
    ReleasedTue Dec 29 12:22:01 2020
    SummaryRecommended update for libidn2
    Typerecommended
    Severitymoderate
    References1180138
    Description:

    This update for libidn2 fixes the following issues:


    Advisory IDSUSE-RU-2021:179-1
    ReleasedWed Jan 20 13:38:51 2021
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:





    Advisory IDSUSE-RU-2021:220-1
    ReleasedTue Jan 26 14:00:51 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for keyutils fixes the following issues:


    Advisory IDSUSE-RU-2021:271-1
    ReleasedMon Feb 1 21:04:13 2021
    SummaryRecommended update for lshw
    Typerecommended
    Severitymoderate
    References1181411
    Description:

    This update for lshw fixes the following issues:


    Advisory IDSUSE-RU-2021:293-1
    ReleasedWed Feb 3 12:52:34 2021
    SummaryRecommended update for gmp
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-RU-2021:301-1
    ReleasedThu Feb 4 08:46:27 2021
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:



    Advisory IDSUSE-OU-2021:339-1
    ReleasedMon Feb 8 13:16:07 2021
    SummaryOptional update for pam
    Typeoptional
    Severitylow
    References
    Description:

    This update for pam fixes the following issues:


    This patch is optional to be installed - it doesn't fix any bugs.


    Advisory IDSUSE-RU-2021:707-1
    ReleasedThu Mar 4 09:19:36 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1177039
    Description:

    This update for systemd-rpm-macros fixes the following issues:




    Advisory IDSUSE-RU-2021:795-1
    ReleasedTue Mar 16 10:28:02 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References1182661,1183012,1183051
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-SU-2021:930-1
    ReleasedWed Mar 24 12:09:23 2021
    SummarySecurity update for nghttp2
    Typesecurity
    Severityimportant
    References1172442,1181358,CVE-2020-11080
    Description:

    This update for nghttp2 fixes the following issues:


    Advisory IDSUSE-RU-2021:953-1
    ReleasedThu Mar 25 14:37:26 2021
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References1178407
    Description:

    This update for psmisc fixes the following issues:


    Advisory IDSUSE-SU-2021:974-1
    ReleasedMon Mar 29 19:31:27 2021
    SummarySecurity update for tar
    Typesecurity
    Severitylow
    References1181131,CVE-2021-20193
    Description:

    This update for tar fixes the following issues:
    CVE-2021-20193: Memory leak in read_header() in list.c (bsc#1181131)


    Advisory IDSUSE-SU-2021:1007-1
    ReleasedThu Apr 1 17:47:20 2021
    SummarySecurity update for MozillaFirefox
    Typesecurity
    Severityimportant
    References1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987
    Description:

    This update for MozillaFirefox fixes the following issues:


    Advisory IDSUSE-RU-2021:1018-1
    ReleasedTue Apr 6 14:29:13 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1180713
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1169-1
    ReleasedTue Apr 13 15:01:42 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitylow
    References1181976
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1289-1
    ReleasedWed Apr 21 14:02:46 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1177047
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1424-1
    ReleasedThu Apr 29 06:22:32 2021
    SummaryRecommended update for openslp
    Typerecommended
    Severitymoderate
    References1166637,1184008
    Description:

    This update for openslp fixes the following issues:


    Advisory IDSUSE-RU-2021:1549-1
    ReleasedMon May 10 13:48:00 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1185417
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1583-1
    ReleasedWed May 12 13:40:35 2021
    SummaryRecommended update for sensors
    Typerecommended
    Severitymoderate
    References1185183
    Description:

    This update for sensors fixes the following issues:


    Advisory IDSUSE-RU-2021:1643-1
    ReleasedWed May 19 13:51:48 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1181443,1184358,1185562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:1861-1
    ReleasedFri Jun 4 09:59:40 2021
    SummaryRecommended update for gcc10
    Typerecommended
    Severitymoderate
    References1029961,1106014,1178577,1178624,1178675,1182016
    Description:

    This update for gcc10 fixes the following issues:


    Advisory IDSUSE-RU-2021:1935-1
    ReleasedThu Jun 10 10:45:09 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for gzip fixes the following issue:


    Advisory IDSUSE-RU-2021:1937-1
    ReleasedThu Jun 10 10:47:09 2021
    SummaryRecommended update for nghttp2
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for nghttp2 fixes the following issue:


    Advisory IDSUSE-SU-2021:1954-1
    ReleasedFri Jun 11 10:45:09 2021
    SummarySecurity update for containerd, docker, runc
    Typesecurity
    Severityimportant
    References1168481,1175081,1175821,1181594,1181641,1181677,1181730,1181732,1181749,1182451,1182476,1182947,1183024,1183855,1184768,1184962,1185405,CVE-2021-21284,CVE-2021-21285,CVE-2021-21334,CVE-2021-30465
    Description:

    This update for containerd, docker, runc fixes the following issues:
    Docker was updated to 20.10.6-ce (bsc#1184768, bsc#1182947, bsc#1181594)


    runc was updated to v1.0.0~rc93 (bsc#1182451, bsc#1175821 bsc#1184962).

    containerd was updated to v1.4.4


    Advisory IDSUSE-RU-2021:2002-1
    ReleasedThu Jun 17 17:27:47 2021
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for open-vm-tools fixes the following issue:


    Advisory IDSUSE-RU-2021:2146-1
    ReleasedWed Jun 23 17:55:14 2021
    SummaryRecommended update for openssh
    Typerecommended
    Severitymoderate
    References1115550,1174162
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-RU-2021:2173-1
    ReleasedMon Jun 28 14:59:45 2021
    SummaryRecommended update for automake
    Typerecommended
    Severitymoderate
    References1040589,1047218,1182604,1185540,1186049
    Description:

    This update for automake fixes the following issues:


    This update for pcre fixes the following issues:

    This update for brp-check-suse fixes the following issues:


    Advisory IDSUSE-RU-2021:2179-1
    ReleasedMon Jun 28 17:36:37 2021
    SummaryRecommended update for thin-provisioning-tools
    Typerecommended
    Severitymoderate
    References1184124
    Description:

    This update for thin-provisioning-tools fixes the following issues:


    Advisory IDSUSE-RU-2021:2193-1
    ReleasedMon Jun 28 18:38:43 2021
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1184124
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-SU-2021:2196-1
    ReleasedTue Jun 29 09:41:39 2021
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1175448,1175449,CVE-2020-24370,CVE-2020-24371
    Description:

    This update for lua53 fixes the following issues:
    Update to version 5.3.6:


    Advisory IDSUSE-RU-2021:2224-1
    ReleasedThu Jul 1 13:48:44 2021
    SummaryRecommended update for psmisc
    Typerecommended
    Severityimportant
    References1185208
    Description:

    This update for psmisc fixes the following issues:


    Advisory IDSUSE-OU-2021:2248-1
    ReleasedMon Jul 5 15:40:28 2021
    SummaryRecommended update for sysstat
    Typeoptional
    Severitylow
    References1186827
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-RU-2021:2286-1
    ReleasedFri Jul 9 17:38:53 2021
    SummaryRecommended update for dosfstools
    Typerecommended
    Severitymoderate
    References1172863
    Description:

    This update for dosfstools fixes the following issue:


    Advisory IDSUSE-SU-2021:2320-1
    ReleasedWed Jul 14 17:01:06 2021
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2021:2456-1
    ReleasedThu Jul 22 15:28:39 2021
    SummaryRecommended update for pam-config
    Typerecommended
    Severitymoderate
    References1187091
    Description:

    This update for pam-config fixes the following issues:


    Advisory IDSUSE-RU-2021:2568-1
    ReleasedThu Jul 29 14:18:37 2021
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1029961,1185103,1185175,1187567
    Description:

    This update for open-vm-tools fixes the following issues:
    Update to 11.3.0 (bsc#1187567)


    Advisory IDSUSE-RU-2021:2573-1
    ReleasedThu Jul 29 14:21:52 2021
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1188127
    Description:

    This update for timezone fixes the following issue:

    the IANA time zone database package, in addition to 'zone1970.tab', as before. This makes sure time zone aliases are now correctly supported. This update adds the 'tzdata.zi' file (bsc#1188127).


    Advisory IDSUSE-RU-2021:2606-1
    ReleasedWed Aug 4 13:16:09 2021
    SummaryRecommended update for libcbor
    Typerecommended
    Severitymoderate
    References1102408
    Description:

    This update for libcbor fixes the following issues:


    Advisory IDSUSE-RU-2021:2627-1
    ReleasedThu Aug 5 12:10:46 2021
    SummaryRecommended maintenance update for systemd-default-settings
    Typerecommended
    Severitymoderate
    References1188348
    Description:

    This update for systemd-default-settings fixes the following issue:


    Advisory IDSUSE-SU-2021:2802-1
    ReleasedFri Aug 20 10:47:08 2021
    SummarySecurity update for libmspack
    Typesecurity
    Severitymoderate
    References1103032,CVE-2018-14679,CVE-2018-14681,CVE-2018-14682
    Description:

    This update for libmspack fixes the following issues:


    Advisory IDSUSE-RU-2021:2895-1
    ReleasedTue Aug 31 19:40:32 2021
    SummaryRecommended update for unixODBC
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for unixODBC fixes the following issues:




    Advisory IDSUSE-RU-2021:2899-1
    ReleasedWed Sep 1 08:30:58 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1186282,1187332
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2021:2962-1
    ReleasedMon Sep 6 18:23:01 2021
    SummaryRecommended update for runc
    Typerecommended
    Severitycritical
    References1189743
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-RU-2021:3001-1
    ReleasedThu Sep 9 15:08:13 2021
    SummaryRecommended update for netcfg
    Typerecommended
    Severitymoderate
    References1189683
    Description:

    This update for netcfg fixes the following issues:


    Advisory IDSUSE-RU-2021:3052-1
    ReleasedThu Sep 16 10:05:24 2021
    SummaryRecommended update for lshw
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for lshw fixes the following issues:


    Advisory IDSUSE-RU-2021:3115-1
    ReleasedThu Sep 16 14:04:26 2021
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829
    Description:

    This update for mozilla-nspr fixes the following issues:
    mozilla-nspr was updated to version 4.32:



    Mozilla NSS was updated to version 3.68:

    update to NSS 3.67

    update to NSS 3.66

    update to NSS 3.65

    update to NSS 3.64
    disable_crypto_vsx.
  • bmo#1698320 - replace __builtin_cpu_supports('vsx') with
  • ppc_crypto_support() for clang.
  • bmo#1613235 - Add POWER ChaCha20 stream cipher vector
  • acceleration.
    Fixed in 3.63
    initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1683520 - ECCKiila P521, change syntax of nested structs
  • initialization to prevent build isses with GCC 4.8.
  • bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual
  • scalar multiplication.
  • bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683.
  • bmo#1694214 - tstclnt can't enable middlebox compat mode.
  • bmo#1694392 - NSS does not work with PKCS #11 modules not supporting
  • profiles.
  • bmo#1685880 - Minor fix to prevent unused variable on early return.
  • bmo#1685880 - Fix for the gcc compiler version 7 to support setenv
  • with nss build.
  • bmo#1693217 - Increase nssckbi.h version number for March 2021 batch
  • of root CA changes, CA list version 2.48.
  • bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's
  • 'Chambers of Commerce' and 'Global Chambersign' roots.
  • bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER.
  • bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS.
  • bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS.
  • bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs
  • from NSS.
  • bmo#1687822 - Turn off Websites trust bit for the “Staat der
  • Nederlanden Root CA - G3” root cert in NSS.
  • bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce
  • Root - 2008' and 'Global Chambersign Root - 2008’.
  • bmo#1694291 - Tracing fixes for ECH.

  • update to NSS 3.62
    can corrupt 'cachedCertTable'
  • bmo#1690583 - Fix CH padding extension size calculation
  • bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail
  • bmo#1690421 - Install packaged libabigail in docker-builds image
  • bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing
  • bmo#1674819 - Fixup a51fae403328, enum type may be signed
  • bmo#1681585 - Add ECH support to selfserv
  • bmo#1681585 - Update ECH to Draft-09
  • bmo#1678398 - Add Export/Import functions for HPKE context
  • bmo#1678398 - Update HPKE to draft-07

  • update to NSS 3.61
    values under certain conditions.
  • bmo#1684300 - Fix default PBE iteration count when NSS is compiled
  • with NSS_DISABLE_DBM.
  • bmo#1651411 - Improve constant-timeness in RSA operations.
  • bmo#1677207 - Upgrade Google Test version to latest release.
  • bmo#1654332 - Add aarch64-make target to nss-try.

  • Update to NSS 3.60.1:
    Notable changes in NSS 3.60:
    Update to NSS 3.59.1:
    PKCS11 modules
    Update to NSS 3.59:
    Notable changes:

    Bugfixes
    root certs when SHA1 signatures are disabled.
  • bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to
  • solve some test intermittents
  • bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in
  • our CVE-2020-25648 fix that broke purple-discord (boo#1179382)
  • bmo#1666891 - Support key wrap/unwrap with RSA-OAEP
  • bmo#1667989 - Fix gyp linking on Solaris
  • bmo#1668123 - Export CERT_AddCertToListHeadWithData and
  • CERT_AddCertToListTailWithData from libnss
  • bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA
  • bmo#1663091 - Remove unnecessary assertions in the streaming
  • ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds
  • bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS.

  • update to NSS 3.58
    Bugs fixed:

    update to NSS 3.57

    update to NSS 3.56
    Notable changes
    detection.
  • bmo#1652729 - Add build flag to disable RC2 and relocate to
  • lib/freebl/deprecated.
  • bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay.
  • bmo#1588941 - Send empty certificate message when scheme selection
  • fails.
  • bmo#1652032 - Fix failure to build in Windows arm64 makefile
  • cross-compilation.
  • bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent.
  • bmo#1653975 - Fix 3.53 regression by setting 'all' as the default
  • makefile target.
  • bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert.
  • bmo#1659814 - Fix interop.sh failures with newer tls-interop
  • commit and dependencies.
  • bmo#1656519 - NSPR dependency updated to 4.28

  • update to NSS 3.55
    Notable changes
    Relevant Bugfixes

    update to NSS 3.54
    Notable changes


    Bugs fixed
    Root Certification Authority; C=TW' root.
  • bmo#1645199 - Remove AddTrust root certificates.
  • bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate.
  • bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root
  • certificate.
  • bmo#1618402 - Remove Symantec root certificates and disable email trust
  • bit.
  • bmo#1640516 - NSS 3.54 should depend on NSPR 4.26.
  • bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c.
  • bmo#1642153 - Fix infinite recursion building NSS.
  • bmo#1642638 - Fix fuzzing assertion crash.
  • bmo#1642871 - Enable SSL_SendSessionTicket after resumption.
  • bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs.
  • bmo#1643557 - Fix numerous compile warnings in NSS.
  • bmo#1644774 - SSL gtests to use ClearServerCache when resetting
  • self-encrypt keys.
  • bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c.
  • bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding.

  • Advisory IDSUSE-RU-2021:3182-1
    ReleasedTue Sep 21 17:04:26 2021
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1189996
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-RU-2021:3203-1
    ReleasedThu Sep 23 14:41:35 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1189537,1190190
    Description:

    This update for kmod fixes the following issues:



    Advisory IDSUSE-SU-2021:3291-1
    ReleasedWed Oct 6 16:45:36 2021
    SummarySecurity update for glibc
    Typesecurity
    Severitymoderate
    References1186489,1187911,CVE-2021-33574,CVE-2021-35942
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2021:3490-1
    ReleasedWed Oct 20 16:31:55 2021
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1190793,CVE-2021-39537
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2021:3494-1
    ReleasedWed Oct 20 16:48:46 2021
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1190052
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:3500-1
    ReleasedFri Oct 22 09:42:21 2021
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1190987
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-SU-2021:3506-1
    ReleasedMon Oct 25 10:20:22 2021
    SummarySecurity update for containerd, docker, runc
    Typesecurity
    Severityimportant
    References1102408,1185405,1187704,1188282,1190826,1191015,1191121,1191334,1191355,1191434,CVE-2021-30465,CVE-2021-32760,CVE-2021-41089,CVE-2021-41091,CVE-2021-41092,CVE-2021-41103
    Description:

    This update for containerd, docker, runc fixes the following issues:
    Docker was updated to 20.10.9-ce. (bsc#1191355)
    See upstream changelog in the packaged /usr/share/doc/packages/docker/CHANGELOG.md.
    CVE-2021-41092 CVE-2021-41089 CVE-2021-41091 CVE-2021-41103
    container was updated to v1.4.11, to fix CVE-2021-41103. bsc#1191355



    Update to runc v1.0.2. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.2

    Update to runc v1.0.1. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.1

    Update to runc v1.0.0. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.0.0
    ! The usage of relative paths for mountpoints will now produce a warning (such configurations are outside of the spec, and in future runc will produce an error when given such configurations).
    Update to runc v1.0.0~rc95. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc95
    This release of runc contains a fix for CVE-2021-30465, and users are strongly recommended to update (especially if you are providing semi-limited access to spawn containers to untrusted users). (bsc#1185405)
    Update to runc v1.0.0~rc94. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc94
    Breaking Changes:
    Regression Fixes:


    Advisory IDSUSE-RU-2021:3510-1
    ReleasedTue Oct 26 11:22:15 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1191987
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3529-1
    ReleasedWed Oct 27 09:23:32 2021
    SummarySecurity update for pcre
    Typesecurity
    Severitymoderate
    References1172973,1172974,CVE-2019-20838,CVE-2020-14155
    Description:

    This update for pcre fixes the following issues:
    Update pcre to version 8.45:


    Advisory IDSUSE-RU-2021:3792-1
    ReleasedWed Nov 24 06:12:09 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1192104
    Description:

    This update for kmod fixes the following issues:


    Advisory IDSUSE-RU-2021:3799-1
    ReleasedWed Nov 24 18:07:54 2021
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1187153,1187273,1188623
    Description:

    This update for gcc11 fixes the following issues:
    The additional GNU compiler collection GCC 11 is provided:
    To select these compilers install the packages:


    to select them for building:

    The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


    Advisory IDSUSE-RU-2021:3872-1
    ReleasedThu Dec 2 07:25:55 2021
    SummaryRecommended update for cracklib
    Typerecommended
    Severitymoderate
    References1191736
    Description:

    This update for cracklib fixes the following issues:


    Advisory IDSUSE-RU-2021:3883-1
    ReleasedThu Dec 2 11:47:07 2021
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:
    Update timezone to 2021e (bsc#1177460)


    Advisory IDSUSE-RU-2021:3891-1
    ReleasedFri Dec 3 10:21:49 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1029961,1113013,1187654
    Description:

    This update for keyutils fixes the following issues:


    keyutils was updated to 1.6.3 (jsc#SLE-20016):

    Updated to 1.6:

    Updated to 1.5.11 (bsc#1113013)


    Advisory IDSUSE-SU-2021:3942-1
    ReleasedMon Dec 6 14:46:05 2021
    SummarySecurity update for brotli
    Typesecurity
    Severitymoderate
    References1175825,CVE-2020-8927
    Description:

    This update for brotli fixes the following issues:


    Advisory IDSUSE-SU-2021:3946-1
    ReleasedMon Dec 6 14:57:42 2021
    SummarySecurity update for gmp
    Typesecurity
    Severitymoderate
    References1192717,CVE-2021-43618
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-SU-2021:3950-1
    ReleasedMon Dec 6 14:59:37 2021
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1190975,CVE-2021-41617
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-RU-2021:3980-1
    ReleasedThu Dec 9 16:42:19 2021
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1191592
    Description:


    glibc was updated to fix the following issue:


    Advisory IDSUSE-RU-2021:4009-1
    ReleasedMon Dec 13 11:24:43 2021
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-SU-2021:4153-1
    ReleasedWed Dec 22 11:00:48 2021
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1183137,CVE-2021-28041
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-RU-2021:4165-1
    ReleasedWed Dec 22 22:52:11 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1193430
    Description:

    This update for kmod fixes the following issues:


    Advisory IDSUSE-SU-2021:4171-1
    ReleasedThu Dec 23 09:55:13 2021
    SummarySecurity update for runc
    Typesecurity
    Severitymoderate
    References1193436,CVE-2021-43784
    Description:

    This update for runc fixes the following issues:
    Update to runc v1.0.3.


    Advisory IDSUSE-SU-2022:69-1
    ReleasedThu Jan 13 15:12:30 2022
    SummarySecurity update for libmspack
    Typesecurity
    Severitylow
    References1113040,CVE-2018-18586
    Description:

    This update for libmspack fixes the following issues:


    Advisory IDSUSE-RU-2022:84-1
    ReleasedMon Jan 17 04:40:30 2022
    SummaryRecommended update for dosfstools
    Typerecommended
    Severitymoderate
    References1172863,1188401
    Description:

    This update for dosfstools fixes the following issues:


    Advisory IDSUSE-SU-2022:184-1
    ReleasedTue Jan 25 18:20:56 2022
    SummarySecurity update for json-c
    Typesecurity
    Severityimportant
    References1171479,CVE-2020-12762
    Description:

    This update for json-c fixes the following issues:


    Advisory IDSUSE-RU-2022:207-1
    ReleasedThu Jan 27 09:24:49 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2022:330-1
    ReleasedFri Feb 4 09:29:08 2022
    SummarySecurity update for glibc
    Typesecurity
    Severityimportant
    References1194640,1194768,1194770,1194785,CVE-2021-3999,CVE-2022-23218,CVE-2022-23219
    Description:


    This update for glibc fixes the following issues:


    Features added:


    Advisory IDSUSE-RU-2022:353-1
    ReleasedTue Feb 8 17:41:48 2022
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:



    Advisory IDSUSE-RU-2022:519-1
    ReleasedFri Feb 18 12:44:57 2022
    SummaryRecommended update for sysstat
    Typerecommended
    Severitymoderate
    References1194679
    Description:

    This update for sysstat fixes the following issues:


    Advisory IDSUSE-RU-2022:572-1
    ReleasedThu Feb 24 11:58:05 2022
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References1194172
    Description:

    This update for psmisc fixes the following issues:


    Advisory IDSUSE-RU-2022:775-1
    ReleasedWed Mar 9 12:55:03 2022
    SummaryRecommended update for pciutils
    Typerecommended
    Severitymoderate
    References1192862
    Description:

    This update for pciutils fixes the following issues:


    Advisory IDSUSE-RU-2022:789-1
    ReleasedThu Mar 10 11:22:05 2022
    SummaryRecommended update for update-alternatives
    Typerecommended
    Severitymoderate
    References1195654
    Description:

    This update for update-alternatives fixes the following issues:


    Advisory IDSUSE-RU-2022:808-1
    ReleasedFri Mar 11 06:07:58 2022
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1195468
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2022:861-1
    ReleasedTue Mar 15 23:31:21 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1182959,1195149,1195792,1195856
    Description:

    This update for openssl-1_1 fixes the following issues:
    openssl-1_1:

    glibc:
    linux-glibc-devel:

    libxcrypt:

    zlib:


    Advisory IDSUSE-RU-2022:936-1
    ReleasedTue Mar 22 18:10:17 2022
    SummaryRecommended update for filesystem and systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1196275,1196406
    Description:

    This update for filesystem and systemd-rpm-macros fixes the following issues:
    filesystem:


    systemd-rpm-macros:


    Advisory IDSUSE-RU-2022:1047-1
    ReleasedWed Mar 30 16:20:56 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1196093,1197024
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2022:1118-1
    ReleasedTue Apr 5 18:34:06 2022
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-SU-2022:1158-1
    ReleasedTue Apr 12 14:44:43 2022
    SummarySecurity update for xz
    Typesecurity
    Severityimportant
    References1198062,CVE-2022-1271
    Description:

    This update for xz fixes the following issues:


    Advisory IDSUSE-RU-2022:1281-1
    ReleasedWed Apr 20 12:26:38 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1374-1
    ReleasedMon Apr 25 15:02:13 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1191157,1197004
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2022:1409-1
    ReleasedTue Apr 26 12:54:57 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1195628,1196107
    Description:

    This update for gcc11 fixes the following issues:


    Advisory IDSUSE-RU-2022:1451-1
    ReleasedThu Apr 28 10:47:22 2022
    SummaryRecommended update for perl
    Typerecommended
    Severitymoderate
    References1193489
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-RU-2022:1491-1
    ReleasedTue May 3 07:09:44 2022
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References1194172
    Description:

    This update for psmisc fixes the following issues:


    Advisory IDSUSE-SU-2022:1548-1
    ReleasedThu May 5 16:45:28 2022
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1029961,1120610,1130496,1181131,CVE-2018-20482,CVE-2019-9923,CVE-2021-20193
    Description:

    This update for tar fixes the following issues:







    Advisory IDSUSE-SU-2022:1617-1
    ReleasedTue May 10 14:40:12 2022
    SummarySecurity update for gzip
    Typesecurity
    Severityimportant
    References1198062,1198922,CVE-2022-1271
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2022:1655-1
    ReleasedFri May 13 15:36:10 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1197794
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:1658-1
    ReleasedFri May 13 15:40:20 2022
    SummaryRecommended update for libpsl
    Typerecommended
    Severityimportant
    References1197771
    Description:

    This update for libpsl fixes the following issues:


    Advisory IDSUSE-SU-2022:1670-1
    ReleasedMon May 16 10:06:30 2022
    SummarySecurity update for openldap2
    Typesecurity
    Severityimportant
    References1199240,CVE-2022-29155
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2022:1709-1
    ReleasedTue May 17 17:35:47 2022
    SummaryRecommended update for libcbor
    Typerecommended
    Severityimportant
    References1197743
    Description:

    This update for libcbor fixes the following issues:


    Advisory IDSUSE-SU-2022:1718-1
    ReleasedTue May 17 17:44:43 2022
    SummarySecurity update for e2fsprogs
    Typesecurity
    Severityimportant
    References1198446,CVE-2022-1304
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-RU-2022:1887-1
    ReleasedTue May 31 09:24:18 2022
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1040589
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-RU-2022:1899-1
    ReleasedWed Jun 1 10:43:22 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severityimportant
    References1198176
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1909-1
    ReleasedWed Jun 1 16:25:35 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1198751
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-RU-2022:2019-1
    ReleasedWed Jun 8 16:50:07 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1192951,1193659,1195283,1196861,1197065
    Description:

    This update for gcc11 fixes the following issues:
    Update to the GCC 11.3.0 release.


    Advisory IDSUSE-RU-2022:2093-1
    ReleasedWed Jun 15 17:08:05 2022
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1196803,1196804
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-SU-2022:2294-1
    ReleasedWed Jul 6 13:34:15 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:2305-1
    ReleasedWed Jul 6 13:38:42 2022
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1200734,1200735,1200736,1200737,CVE-2022-32205,CVE-2022-32206,CVE-2022-32207,CVE-2022-32208
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2022:2341-1
    ReleasedFri Jul 8 16:09:12 2022
    SummarySecurity update for containerd, docker and runc
    Typesecurity
    Severityimportant
    References1192051,1199460,1199565,1200088,1200145,CVE-2022-29162,CVE-2022-31030
    Description:

    This update for containerd, docker and runc fixes the following issues:
    containerd:


    docker:

    runc:
    Update to runc v1.1.3.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.3.

    Update to runc v1.1.2.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.2.
    Security issue fixed:


    Update to runc v1.1.1.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.1.

    Update to runc v1.1.0.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.0.

    Update to runc v1.1.0~rc1.
    Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.0-rc.1.


    Advisory IDSUSE-SU-2022:2360-1
    ReleasedTue Jul 12 12:01:39 2022
    SummarySecurity update for pcre2
    Typesecurity
    Severityimportant
    References1199232,CVE-2022-1586
    Description:

    This update for pcre2 fixes the following issues:


    Advisory IDSUSE-SU-2022:2361-1
    ReleasedTue Jul 12 12:05:01 2022
    SummarySecurity update for pcre
    Typesecurity
    Severityimportant
    References1199232,CVE-2022-1586
    Description:

    This update for pcre fixes the following issues:


    Advisory IDSUSE-SU-2022:2396-1
    ReleasedThu Jul 14 11:57:58 2022
    SummarySecurity update for logrotate
    Typesecurity
    Severityimportant
    References1192449,1199652,1200278,1200802,CVE-2022-1348
    Description:

    This update for logrotate fixes the following issues:
    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-RU-2022:2406-1
    ReleasedFri Jul 15 11:49:01 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1197718,1199140,1200334,1200855
    Description:

    This update for glibc fixes the following issues:


    This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).


    Advisory IDSUSE-RU-2022:2469-1
    ReleasedThu Jul 21 04:38:31 2022
    SummaryRecommended update for systemd
    Typerecommended
    Severityimportant
    References1137373,1181658,1194708,1195157,1197570,1198732,1200170,1201276
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:2493-1
    ReleasedThu Jul 21 14:35:08 2022
    SummaryRecommended update for rpm-config-SUSE
    Typerecommended
    Severitymoderate
    References1193282
    Description:

    This update for rpm-config-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2022:2494-1
    ReleasedThu Jul 21 15:16:42 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severityimportant
    References1200855,1201560,1201640
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2022:2533-1
    ReleasedFri Jul 22 17:37:15 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Mozilla NSPR was updated to version 4.34:


    Advisory IDSUSE-SU-2022:2546-1
    ReleasedMon Jul 25 14:43:22 2022
    SummarySecurity update for gpg2
    Typesecurity
    Severityimportant
    References1196125,1201225,CVE-2022-34903
    Description:

    This update for gpg2 fixes the following issues:


    Advisory IDSUSE-SU-2022:2566-1
    ReleasedWed Jul 27 15:04:49 2022
    SummarySecurity update for pcre2
    Typesecurity
    Severityimportant
    References1199235,CVE-2022-1587
    Description:

    This update for pcre2 fixes the following issues:


    Advisory IDSUSE-SU-2022:2595-1
    ReleasedFri Jul 29 16:00:42 2022
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
    Description:

    This update for mozilla-nss fixes the following issues:
    Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:


    Version update to NSS 3.79:

    Version update to NSS 3.78.1:

    Version update to NSS 3.78:

    Version update to NSS 3.77:

    Version update to NSS 3.76.1

    Version update to NSS 3.75

    Version update to NSS 3.74


    Version update to NSS 3.73.1:

    Version update to NSS 3.73

    Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures
    Version update to NSS 3.72

    Version update to NSS 3.71

    Version update to NSS 3.70

    Version update to NSS 3.69.1:

    NSS 3.69:

    Version Update to 3.68.4 (bsc#1200027)


    Advisory IDSUSE-SU-2022:2632-1
    ReleasedWed Aug 3 09:51:00 2022
    SummarySecurity update for permissions
    Typesecurity
    Severityimportant
    References1198720,1200747,1201385
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:2717-1
    ReleasedTue Aug 9 12:54:16 2022
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1198627,CVE-2022-29458
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2022:2735-1
    ReleasedWed Aug 10 04:31:41 2022
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1200657
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-RU-2022:2796-1
    ReleasedFri Aug 12 14:34:31 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for jitterentropy fixes the following issues:
    jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
    This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library, used by other FIPS libraries.


    Advisory IDSUSE-SU-2022:2825-1
    ReleasedTue Aug 16 17:12:47 2022
    SummarySecurity update for rsync
    Typesecurity
    Severityimportant
    References1201840,CVE-2022-29154
    Description:

    This update for rsync fixes the following issues:


    Advisory IDSUSE-RU-2022:2844-1
    ReleasedThu Aug 18 14:41:25 2022
    SummaryRecommended update for tar
    Typerecommended
    Severityimportant
    References1202436
    Description:

    This update for tar fixes the following issues:



    Advisory IDSUSE-RU-2022:2901-1
    ReleasedFri Aug 26 03:34:23 2022
    SummaryRecommended update for elfutils
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for elfutils fixes the following issues:


    Advisory IDSUSE-RU-2022:2904-1
    ReleasedFri Aug 26 05:28:34 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1198341
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2022:2920-1
    ReleasedFri Aug 26 15:17:02 2022
    SummaryRecommended update for systemd
    Typerecommended
    Severityimportant
    References1195059,1201795
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:2929-1
    ReleasedMon Aug 29 11:21:47 2022
    SummaryRecommended update for timezone
    Typerecommended
    Severityimportant
    References1202310
    Description:

    This update for timezone fixes the following issue:


    Advisory IDSUSE-SU-2022:2936-1
    ReleasedMon Aug 29 14:34:13 2022
    SummarySecurity update for open-vm-tools
    Typesecurity
    Severityimportant
    References1202657,1202733,CVE-2022-31676
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-RU-2022:2939-1
    ReleasedMon Aug 29 14:49:17 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1201298,1202645
    Description:

    This update for mozilla-nss fixes the following issues:
    Update to NSS 3.79.1 (bsc#1202645)



    Advisory IDSUSE-RU-2022:2944-1
    ReleasedWed Aug 31 05:39:14 2022
    SummaryRecommended update for procps
    Typerecommended
    Severityimportant
    References1181475
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-SU-2022:3003-1
    ReleasedFri Sep 2 15:01:44 2022
    SummarySecurity update for curl
    Typesecurity
    Severitylow
    References1202593,CVE-2022-35252
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2022:3019-1
    ReleasedMon Sep 5 11:00:23 2022
    SummaryRecommended update for lshw
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for lshw fixes the following issues:


    Advisory IDSUSE-RU-2022:3127-1
    ReleasedWed Sep 7 04:36:10 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1198752,1200800
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:3133-1
    ReleasedWed Sep 7 05:55:52 2022
    SummaryRecommended update for sg3_utils
    Typerecommended
    Severitymoderate
    References1199248
    Description:

    This update for sg3_utils fixes the following issues:


    Advisory IDSUSE-RU-2022:3262-1
    ReleasedTue Sep 13 15:34:29 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1199140
    Description:


    This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)


    Advisory IDSUSE-SU-2022:3271-1
    ReleasedWed Sep 14 06:45:39 2022
    SummarySecurity update for perl
    Typesecurity
    Severitymoderate
    References1047178,CVE-2017-6512
    Description:

    This update for perl fixes the following issues:


    Advisory IDSUSE-RU-2022:3304-1
    ReleasedMon Sep 19 11:43:25 2022
    SummaryRecommended update for libassuan
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libassuan fixes the following issues:


    Advisory IDSUSE-SU-2022:3305-1
    ReleasedMon Sep 19 11:45:57 2022
    SummarySecurity update for libtirpc
    Typesecurity
    Severityimportant
    References1201680,CVE-2021-46828
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-SU-2022:3307-1
    ReleasedMon Sep 19 13:26:51 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-SU-2022:3327-1
    ReleasedWed Sep 21 12:47:17 2022
    SummarySecurity update for oniguruma
    Typesecurity
    Severityimportant
    References1142847,1150130,1157805,1164550,1164569,1177179,CVE-2019-13224,CVE-2019-16163,CVE-2019-19203,CVE-2019-19204,CVE-2019-19246,CVE-2020-26159
    Description:

    This update for oniguruma fixes the following issues:


    Advisory IDSUSE-RU-2022:3328-1
    ReleasedWed Sep 21 12:48:56 2022
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1202870
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-SU-2022:3353-1
    ReleasedFri Sep 23 15:23:40 2022
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1203018,CVE-2022-31252
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:3435-1
    ReleasedTue Sep 27 14:55:38 2022
    SummaryRecommended update for runc
    Typerecommended
    Severityimportant
    References1202821
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-RU-2022:3452-1
    ReleasedWed Sep 28 12:13:43 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1201942
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2022:3489-1
    ReleasedSat Oct 1 13:35:24 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1203438,CVE-2022-40674
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-RU-2022:3555-1
    ReleasedMon Oct 10 14:05:12 2022
    SummaryRecommended update for aaa_base
    Typerecommended
    Severityimportant
    References1199492
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2022:3683-1
    ReleasedFri Oct 21 11:48:39 2022
    SummarySecurity update for libksba
    Typesecurity
    Severitycritical
    References1204357,CVE-2022-3515
    Description:

    This update for libksba fixes the following issues:
    - CVE-2022-3515: Fixed a possible overflow in the TLV parser (bsc#1204357).


    Advisory IDSUSE-SU-2022:3785-1
    ReleasedWed Oct 26 20:20:19 2022
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1204383,1204386,CVE-2022-32221,CVE-2022-42916
    Description:

    This update for curl fixes the following issues:
    - CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383). - CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386).


    Advisory IDSUSE-RU-2022:3787-1
    ReleasedThu Oct 27 04:41:09 2022
    SummaryRecommended update for permissions
    Typerecommended
    Severityimportant
    References1194047,1203911
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:3806-1
    ReleasedThu Oct 27 17:21:11 2022
    SummarySecurity update for dbus-1
    Typesecurity
    Severityimportant
    References1087072,1204111,1204112,1204113,CVE-2022-42010,CVE-2022-42011,CVE-2022-42012
    Description:

    This update for dbus-1 fixes the following issues:
    - CVE-2022-42010: Fixed potential crash that could be triggered by an invalid signature (bsc#1204111). - CVE-2022-42011: Fixed an out of bounds read caused by a fixed length array (bsc#1204112). - CVE-2022-42012: Fixed a use-after-free that could be trigged by a message in non-native endianness with out-of-band Unix file descriptor (bsc#1204113).
    Bugfixes:
    - Disable asserts (bsc#1087072).


    Advisory IDSUSE-RU-2022:3851-1
    ReleasedWed Nov 2 12:34:17 2022
    SummaryRecommended update for rsync
    Typerecommended
    Severityimportant
    References1202970,1204538
    Description:

    This update for rsync fixes the following issues:


    Advisory IDSUSE-RU-2022:3873-1
    ReleasedFri Nov 4 14:58:08 2022
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.34.1:


    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729):

    Other fixes that were applied:


    Advisory IDSUSE-SU-2022:3884-1
    ReleasedMon Nov 7 10:59:26 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1204708,CVE-2022-43680
    Description:

    This update for expat fixes the following issues:
    - CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).


    Advisory IDSUSE-RU-2022:3904-1
    ReleasedTue Nov 8 10:52:13 2022
    SummaryRecommended update for openssh
    Typerecommended
    Severitymoderate
    References1192439
    Description:

    This update for openssh fixes the following issue:


    Advisory IDSUSE-RU-2022:3910-1
    ReleasedTue Nov 8 13:05:04 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issue:


    Advisory IDSUSE-RU-2022:3927-1
    ReleasedWed Nov 9 14:55:47 2022
    SummaryRecommended update for runc
    Typerecommended
    Severitymoderate
    References1202021,1202821
    Description:

    This update for runc fixes the following issues:


    Advisory IDSUSE-RU-2022:3958-1
    ReleasedFri Nov 11 15:20:45 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298,1202870,1204729
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.79.2 (bsc#1204729)



    Advisory IDSUSE-SU-2022:3999-1
    ReleasedTue Nov 15 17:08:04 2022
    SummarySecurity update for systemd
    Typesecurity
    Severitymoderate
    References1204179,1204968,CVE-2022-3821
    Description:

    This update for systemd fixes the following issues:




    Advisory IDSUSE-RU-2022:4062-1
    ReleasedFri Nov 18 09:05:07 2022
    SummaryRecommended update for libusb-1_0
    Typerecommended
    Severitymoderate
    References1201590
    Description:

    This update for libusb-1_0 fixes the following issues:


    Advisory IDSUSE-RU-2022:4066-1
    ReleasedFri Nov 18 10:43:00 2022
    SummaryRecommended update for timezone
    Typerecommended
    Severityimportant
    References1177460,1202324,1204649,1205156
    Description:

    This update for timezone fixes the following issues:
    Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156):


    Advisory IDSUSE-SU-2022:4081-1
    ReleasedFri Nov 18 15:40:46 2022
    SummarySecurity update for dpkg
    Typesecurity
    Severitylow
    References1199944,CVE-2022-1664
    Description:

    This update for dpkg fixes the following issues:


    Advisory IDSUSE-RU-2022:4135-1
    ReleasedMon Nov 21 00:13:40 2022
    SummaryRecommended update for libeconf
    Typerecommended
    Severitymoderate
    References1198165
    Description:

    This update for libeconf fixes the following issues:



    Advisory IDSUSE-RU-2022:4160-1
    ReleasedTue Nov 22 10:10:37 2022
    SummaryRecommended update for nfsidmap
    Typerecommended
    Severitymoderate
    References1200901
    Description:

    This update for nfsidmap fixes the following issues:


    Advisory IDSUSE-RU-2022:4256-1
    ReleasedMon Nov 28 12:36:32 2022
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
    The Go, D and Ada language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2022:4311-1
    ReleasedFri Dec 2 11:02:43 2022
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitycritical
    References
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-RU-2022:4312-1
    ReleasedFri Dec 2 11:16:47 2022
    SummaryRecommended update for tar
    Typerecommended
    Severitymoderate
    References1200657,1203600
    Description:

    This update for tar fixes the following issues:


    Advisory IDSUSE-RU-2022:4492-1
    ReleasedWed Dec 14 13:52:39 2022
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1198980,1201298
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-RU-2022:4499-1
    ReleasedThu Dec 15 10:48:49 2022
    SummaryRecommended update for openssh
    Typerecommended
    Severitymoderate
    References1179465
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-SU-2022:4597-1
    ReleasedWed Dec 21 10:13:11 2022
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1206308,1206309,CVE-2022-43551,CVE-2022-43552
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-feature-2022:4601-1
    ReleasedWed Dec 21 12:23:59 2022
    SummaryFeature update for GNOME 41
    Typefeature
    Severitymoderate
    References1175622,1179584,1188882,1196205,1200581,1203274,1204867,944832
    Description:

    This update for GNOME 41 fixes the following issues:
    atkmm1_6:


    eog:

    evince:

    evolution: evolution-data-center:

    folks:

    gcr:

    geocode-glib:

    gjs:


    glib2:


    gnome-control-center:

    gnome-desktop:

    gnome-music:

    gnome-remote-desktop:

    gnome-session:
    gnome-shell:
    gnome-software:


    gnome-terminal:

    gnome-user-docs:

    gspell:

    gtkmm3:

    gtk-vnc:

    gupnp-av:
    gvfs:

    libgsf:

    libmediaart:

    libnma:

    libnotify:

    libpeas:

    librsvg:

    libsecret:

    mutter:

    nautilus:

    orca:

    python-cairo:

    python-gobject:

    trackers-python:

    vala:

    xdg-desktop-portal-gnome:


    Advisory IDSUSE-SU-2022:4628-1
    ReleasedWed Dec 28 09:23:13 2022
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1206337,CVE-2022-46908
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-SU-2022:4629-1
    ReleasedWed Dec 28 09:24:07 2022
    SummarySecurity update for systemd
    Typesecurity
    Severityimportant
    References1200723,1205000,CVE-2022-4415
    Description:

    This update for systemd fixes the following issues:


    Bug fixes:


    Advisory IDSUSE-RU-2023:25-1
    ReleasedThu Jan 5 09:51:41 2023
    SummaryRecommended update for timezone
    Typerecommended
    Severitymoderate
    References1177460
    Description:

    This update for timezone fixes the following issues:
    Version update from 2022f to 2022g (bsc#1177460):


    Advisory IDSUSE-RU-2023:48-1
    ReleasedMon Jan 9 10:37:54 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1199467
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2023:52-1
    ReleasedMon Jan 9 10:43:57 2023
    SummaryRecommended update for xfsprogs
    Typerecommended
    Severitymoderate
    References1205266,1205272,1205284,1205377
    Description:

    This update for xfsprogs fixes the following issues:


    Advisory IDSUSE-RU-2023:54-1
    ReleasedMon Jan 9 10:49:19 2023
    SummaryRecommended update for bash-completion
    Typerecommended
    Severitymoderate
    References1200791
    Description:

    This update for bash-completion fixes the following issues:


    Advisory IDSUSE-SU-2023:56-1
    ReleasedMon Jan 9 11:13:43 2023
    SummarySecurity update for libksba
    Typesecurity
    Severitymoderate
    References1206579,CVE-2022-47629
    Description:

    This update for libksba fixes the following issues:


    Advisory IDSUSE-SU-2023:119-1
    ReleasedFri Jan 20 10:28:07 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1204272,1207038,CVE-2022-23491,CVE-2022-3479
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-RU-2023:179-1
    ReleasedThu Jan 26 21:54:30 2023
    SummaryRecommended update for tar
    Typerecommended
    Severitylow
    References1202436
    Description:

    This update for tar fixes the following issue:


    Advisory IDSUSE-RU-2023:181-1
    ReleasedThu Jan 26 21:55:43 2023
    SummaryRecommended update for procps
    Typerecommended
    Severitylow
    References1206412
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-SU-2023:201-1
    ReleasedFri Jan 27 15:24:15 2023
    SummarySecurity update for systemd
    Typesecurity
    Severitymoderate
    References1204944,1205000,1207264,CVE-2022-4415
    Description:

    This update for systemd fixes the following issues:


    Non-security fixes:


    Advisory IDSUSE-SU-2023:348-1
    ReleasedFri Feb 10 15:08:41 2023
    SummarySecurity update for less
    Typesecurity
    Severitymoderate
    References1207815,CVE-2022-46663
    Description:

    This update for less fixes the following issues:
    - CVE-2022-46663: Fixed denial-of-service by printing specially crafted escape sequences to the terminal (bsc#1207815).


    Advisory IDSUSE-SU-2023:429-1
    ReleasedWed Feb 15 17:41:22 2023
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1207990,1207991,1207992,CVE-2023-23914,CVE-2023-23915,CVE-2023-23916
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2023:434-1
    ReleasedThu Feb 16 09:08:05 2023
    SummarySecurity update for mozilla-nss
    Typesecurity
    Severityimportant
    References1208138,CVE-2023-0767
    Description:

    This update for mozilla-nss fixes the following issues:
    Updated to NSS 3.79.4 (bsc#1208138):
    - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.


    Advisory IDSUSE-SU-2023:463-1
    ReleasedMon Feb 20 16:33:39 2023
    SummarySecurity update for tar
    Typesecurity
    Severitymoderate
    References1202436,1207753,CVE-2022-48303
    Description:

    This update for tar fixes the following issues:


    Bug fixes:


    Advisory IDSUSE-RU-2023:464-1
    ReleasedMon Feb 20 18:11:37 2023
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-SU-2023:557-1
    ReleasedTue Feb 28 09:29:15 2023
    SummarySecurity update for libxslt
    Typesecurity
    Severityimportant
    References1208574,CVE-2021-30560
    Description:

    This update for libxslt fixes the following issues:


    Advisory IDSUSE-RU-2023:617-1
    ReleasedFri Mar 3 16:49:06 2023
    SummaryRecommended update for jitterentropy
    Typerecommended
    Severitymoderate
    References1207789
    Description:

    This update for jitterentropy fixes the following issues:


    Advisory IDSUSE-RU-2023:709-1
    ReleasedFri Mar 10 16:04:41 2023
    SummaryRecommended update for console-setup
    Typerecommended
    Severitymoderate
    References1202853
    Description:

    This update for console-setup and kbd fixes the following issue:


    Advisory IDSUSE-RU-2023:776-1
    ReleasedThu Mar 16 17:29:23 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:
    This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
    SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes

    This update ship the GCC 12 compiler suite and its base libraries.
    The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
    The new compilers for C, C++, and Fortran are provided in the SUSE Linux Enterprise Module for Development Tools.
    To use gcc12 compilers use:


    For a full changelog with all new GCC12 features, check out
    https://gcc.gnu.org/gcc-12/changes.html


    Advisory IDSUSE-RU-2023:875-1
    ReleasedWed Mar 22 19:17:54 2023
    SummaryRecommended update for sg3_utils
    Typerecommended
    Severitymoderate
    References1207706
    Description:

    This update for sg3_utils fixes the following issues:


    Advisory IDSUSE-SU-2023:1582-1
    ReleasedMon Mar 27 10:31:52 2023
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1209209,1209210,1209211,1209212,1209214,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2023:1688-1
    ReleasedWed Mar 29 18:19:10 2023
    SummarySecurity update for zstd
    Typesecurity
    Severitymoderate
    References1209533,CVE-2022-4899
    Description:

    This update for zstd fixes the following issues:


    Advisory IDSUSE-SU-2023:1718-1
    ReleasedFri Mar 31 15:47:34 2023
    SummarySecurity update for glibc
    Typesecurity
    Severitymoderate
    References1207571,1207957,1207975,1208358,CVE-2023-0687
    Description:

    This update for glibc fixes the following issues:
    Security issue fixed:


    Other issues fixed:


    Advisory IDSUSE-RU-2023:1779-1
    ReleasedThu Apr 6 08:16:58 2023
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1208432
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2023:1805-1
    ReleasedTue Apr 11 10:12:41 2023
    SummaryRecommended update for timezone
    Typerecommended
    Severityimportant
    References
    Description:

    This update for timezone fixes the following issues:


    Advisory IDSUSE-RU-2023:1809-1
    ReleasedTue Apr 11 11:47:44 2023
    SummaryRecommended update for haveged
    Typerecommended
    Severitymoderate
    References1203079
    Description:

    This update for haveged fixes the following issues:


    Advisory IDSUSE-RU-2023:1813-1
    ReleasedTue Apr 11 13:39:36 2023
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitylow
    References1208880
    Description:

    This update for open-vm-tools fixes the following issue:


    Advisory IDSUSE-RU-2023:1880-1
    ReleasedTue Apr 18 11:11:27 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitylow
    References1208079
    Description:

    This update for systemd-rpm-macros fixes the following issue:


    Advisory IDSUSE-RU-2023:1939-1
    ReleasedFri Apr 21 11:14:30 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1191546,1207209,1208242,1208999
    Description:

    This update for mozilla-nss fixes the following issues:


    Advisory IDSUSE-SU-2023:1994-1
    ReleasedTue Apr 25 13:53:25 2023
    SummarySecurity update for avahi
    Typesecurity
    Severitymoderate
    References1210328,CVE-2023-1981
    Description:

    This update for avahi fixes the following issues:


    Advisory IDSUSE-SU-2023:2003-1
    ReleasedTue Apr 25 18:05:42 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1168481,1208962,1209884,1209888,CVE-2023-25809,CVE-2023-27561,CVE-2023-28642
    Description:

    This update for runc fixes the following issues:
    Update to runc v1.1.5:
    Security fixes:


    Other fixes:
    - Fix the inability to use `/dev/null` when inside a container. - Fix changing the ownership of host's `/dev/null` caused by fd redirection (bsc#1168481). - Fix rare runc exec/enter unshare error on older kernels. - nsexec: Check for errors in `write_log()`. - Drop version-specific Go requirement.


    Advisory IDSUSE-RU-2023:2039-1
    ReleasedWed Apr 26 11:42:49 2023
    SummaryRecommended update for lshw
    Typerecommended
    Severitymoderate
    References1209531
    Description:

    This update for lshw fixes the following issues:


    Advisory IDSUSE-SU-2023:2060-1
    ReleasedThu Apr 27 17:04:25 2023
    SummarySecurity update for glib2
    Typesecurity
    Severitymoderate
    References1209713,1209714,1210135,CVE-2023-24593,CVE-2023-25180
    Description:

    This update for glib2 fixes the following issues:


    The following non-security bug was fixed:


    Advisory IDSUSE-RU-2023:2104-1
    ReleasedThu May 4 21:05:30 2023
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1209122
    Description:

    This update for procps fixes the following issue:


    Advisory IDSUSE-SU-2023:2111-1
    ReleasedFri May 5 14:34:00 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1210434,CVE-2023-29491
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2023:2131-1
    ReleasedTue May 9 13:35:24 2023
    SummaryRecommended update for openssh
    Typerecommended
    Severityimportant
    References1207014
    Description:

    This update for openssh fixes the following issues:


    Advisory IDSUSE-RU-2023:2159-1
    ReleasedWed May 10 16:49:20 2023
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1205962,1209128
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:2224-1
    ReleasedWed May 17 09:53:54 2023
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322
    Description:

    This update for curl adds the following feature:
    Update to version 8.0.1 (jsc#PED-2580)


    Advisory IDSUSE-RU-2023:2240-1
    ReleasedWed May 17 19:56:54 2023
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1203141,1207410
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-SU-2023:2256-1
    ReleasedFri May 19 15:26:43 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1200441
    Description:


    This update of runc fixes the following issues:


    Advisory IDSUSE-RU-2023:2307-1
    ReleasedMon May 29 10:29:49 2023
    SummaryRecommended update for kbd
    Typerecommended
    Severitylow
    References1210702
    Description:

    This update for kbd fixes the following issue:


    Advisory IDSUSE-RU-2023:2481-1
    ReleasedFri Jun 9 15:18:12 2023
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1210909,1211072,1211080
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-RU-2023:2482-1
    ReleasedMon Jun 12 07:19:53 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1211272
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-SU-2023:2484-1
    ReleasedMon Jun 12 08:49:58 2023
    SummarySecurity update for openldap2
    Typesecurity
    Severitymoderate
    References1211795,CVE-2023-2953
    Description:

    This update for openldap2 fixes the following issues:


    Advisory ID29171
    ReleasedTue Jun 20 12:29:00 2023
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1201627,1207534,1211430,CVE-2022-4304,CVE-2023-2650
    Description:

    This update for openssl-1_1 fixes the following issues:



    Advisory IDSUSE-SU-2023:2604-1
    ReleasedThu Jun 22 09:48:53 2023
    SummarySecurity update for open-vm-tools
    Typesecurity
    Severitymoderate
    References1210695,1212143,CVE-2023-20867
    Description:

    This update for open-vm-tools fixes the following issues:


    Bug fixes:


    Advisory IDSUSE-RU-2023:2615-1
    ReleasedThu Jun 22 14:50:55 2023
    SummaryRecommended update for mdadm
    Typerecommended
    Severityimportant
    References1208618
    Description:

    This update for mdadm fixes the following issues:


    Advisory IDSUSE-RU-2023:2625-1
    ReleasedFri Jun 23 17:16:11 2023
    SummaryRecommended update for gcc12
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gcc12 fixes the following issues:


    * includes regression and other bug fixes


    Advisory IDSUSE-RU-2023:2658-1
    ReleasedTue Jun 27 14:46:15 2023
    SummaryRecommended update for containerd, docker, runc
    Typerecommended
    Severitymoderate
    References1207004,1208074,1210298,1211578
    Description:

    This update for containerd, docker, runc fixes the following issues:


    Advisory IDSUSE-RU-2023:2740-1
    ReleasedFri Jun 30 10:57:08 2023
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1212662
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-SU-2023:2765-1
    ReleasedMon Jul 3 20:28:14 2023
    SummarySecurity update for libcap
    Typesecurity
    Severitymoderate
    References1211418,1211419,CVE-2023-2602,CVE-2023-2603
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-RU-2023:2788-1
    ReleasedThu Jul 6 11:51:02 2023
    SummaryRecommended update for mozilla-nspr, mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nspr, mozilla-nss fixes the following issues:
    mozilla-nspr was updated to version 4.35


    mozilla-nss was update to NSS 3.90:


    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84
    update to NSS 3.83

    update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2811-1
    ReleasedWed Jul 12 11:56:18 2023
    SummaryRecommended update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt fixes the following issues:
    This update provides a feature update to the FIDO2 stack.
    Changes in libfido2:


    * New API calls:
    + fido_assert_empty_allow_list; + fido_cred_empty_exclude_list.
    * fido2-token: fix issue when listing large blobs.

    * Support for COSE_ES384. * Improved support for FIDO 2.1 authenticators.
    * New API calls:
    + es384_pk_free; + es384_pk_from_EC_KEY; + es384_pk_from_EVP_PKEY; + es384_pk_from_ptr; + es384_pk_new; + es384_pk_to_EVP_PKEY; + fido_cbor_info_certs_len; + fido_cbor_info_certs_name_ptr; + fido_cbor_info_certs_value_ptr; + fido_cbor_info_maxrpid_minpinlen; + fido_cbor_info_minpinlen; + fido_cbor_info_new_pin_required; + fido_cbor_info_rk_remaining; + fido_cbor_info_uv_attempts; + fido_cbor_info_uv_modality.
    * Documentation and reliability fixes.

    * Experimental PCSC support; enable with -DUSE_PCSC. * Improved OpenSSL 3.0 compatibility. * Use RFC1951 raw deflate to compress CTAP 2.1 largeBlobs. * winhello: advertise 'uv' instead of 'clientPin'. * winhello: support hmac-secret in fido_dev_get_assert(). * New API calls:
    + fido_cbor_info_maxlargeblob.
    * Documentation and reliability fixes. * Separate build and regress targets.

    * bio: fix CTAP2 canonical CBOR encoding in fido_bio_dev_enroll_*(); gh#480. * New API calls:
    - fido_dev_info_set; - fido_dev_io_handle; - fido_dev_new_with_info; - fido_dev_open_with_info. * Cygwin and NetBSD build fixes. * Documentation and reliability fixes. * Support for TPM 2.0 attestation of COSE_ES256 credentials.

    * Enabled NFC support on Linux. * Support for FIDO 2.1 'minPinLength' extension. * Support for COSE_EDDSA, COSE_ES256, and COSE_RS1 attestation. * Support for TPM 2.0 attestation. * Support for device timeouts; see fido_dev_set_timeout(). * New API calls:
    - es256_pk_from_EVP_PKEY; - fido_cred_attstmt_len; - fido_cred_attstmt_ptr; - fido_cred_pin_minlen; - fido_cred_set_attstmt; - fido_cred_set_pin_minlen; - fido_dev_set_pin_minlen_rpid; - fido_dev_set_timeout; - rs256_pk_from_EVP_PKEY.
    * Reliability and portability fixes. * Better handling of HID devices without identification strings; gh#381.

    * Better support for FIDO 2.1 authenticators. * Support for attestation format 'none'. * New API calls:
    - fido_assert_set_clientdata; - fido_cbor_info_algorithm_cose; - fido_cbor_info_algorithm_count; - fido_cbor_info_algorithm_type; - fido_cbor_info_transports_len; - fido_cbor_info_transports_ptr; - fido_cred_set_clientdata; - fido_cred_set_id; - fido_credman_set_dev_rk; - fido_dev_is_winhello.
    * fido2-token: new -Sc option to update a resident credential. * Documentation and reliability fixes. * HID access serialisation on Linux.

    * hid_win: detect devices with vendor or product IDs > 0x7fff * Support for FIDO 2.1 authenticator configuration. * Support for FIDO 2.1 UV token permissions. * Support for FIDO 2.1 'credBlobs' and 'largeBlobs' extensions. * New API calls * New fido_init flag to disable fido_dev_open’s U2F fallback * Experimental NFC support on Linux.


    * Documentation and reliability fixes.
    * New API calls:
    + fido_cred_authdata_raw_len; + fido_cred_authdata_raw_ptr; + fido_cred_sigcount; + fido_dev_get_uv_retry_count; + fido_dev_supports_credman. * Hardened Windows build. * Native FreeBSD and NetBSD support. * Use CTAP2 canonical CBOR when combining hmac-secret and credProtect.

    Changes in python-fido2:

    * Don't fail device discovery when hidraw doesn't support HIDIOCGRAWUNIQ * Support the latest Windows webauthn.h API (included in Windows 11). * Add product name and serial number to HidDescriptors. * Remove the need for the uhid-freebsd dependency on FreeBSD.

    * Add new CTAP error codes and improve handling of unknown codes. * Client: API changes to better support extensions. * Client.make_credential now returns a AuthenticatorAttestationResponse, which holds the AttestationObject and ClientData, as well as any client extension results for the credential. * Client.get_assertion now returns an AssertionSelection object, which is used to select between multiple assertions * Renames: The CTAP1 and CTAP2 classes have been renamed to Ctap1 and Ctap2, respectively. * ClientPin: The ClientPin API has been restructured to support multiple PIN protocols, UV tokens, and token permissions. * CTAP 2.1 PRE: Several new features have been added for CTAP 2.1 * HID: The platform specific HID code has been revamped

    * Bugfix: WindowsClient.make_credential error when resident key requirement is unspecified.

    * New fido2.webauthn classes modeled after the W3C WebAuthn spec introduced. * CTAP2 send_cbor/make_credential/get_assertion and U2fClient request/authenticate timeout arguments replaced with event used to cancel a request. * Fido2Client:
    - make_credential/get_assertion now take WebAuthn options objects. - timeout is now provided in ms in WebAuthn options objects. Event based cancelation also available by passing an Event.
    * Fido2Server:
    - ATTESTATION, USER_VERIFICATION, and AUTHENTICATOR_ATTACHMENT enums have been replaced with fido2.webauthn classes. - RelyingParty has been replaced with PublicKeyCredentialRpEntity, and name is no longer optional. - Options returned by register_begin/authenticate_begin now omit unspecified values if they are optional, instead of filling in default values. - Fido2Server.allowed_algorithms now contains a list of PublicKeyCredentialParameters instead of algorithm identifiers. - Fido2Server.timeout is now in ms and of type int.
    * Support native WebAuthn API on Windows through WindowsClient.

    * Support for the TPM attestation format. * Allow passing custom challenges to register/authenticate in Fido2Server. * Bugfix: CTAP2 CANCEL command response handling fixed. * Bugfix: Fido2Client fix handling of empty allow_list. * Bugfix: Fix typo in CTAP2.get_assertions() causing it to fail.

    * Enforce canonical CBOR on Authenticator responses by default. * PCSC: Support extended APDUs. * Server: Verify that UP flag is set. * U2FFido2Server: Implement AppID exclusion extension. * U2FFido2Server: Allow custom U2F facet verification. * Bugfix: U2FFido2Server.authenticate_complete now returns the result.

    * Add support for NFC devices using PCSC. * Add support for the hmac-secret Authenticator extension. * Honor max credential ID length and number of credentials to Authenticator. * Add close() method to CTAP devices to explicitly release their resources.

    * Don't fail if CTAP2 Info contains unknown fields. * Replace cbor loads/dumps functions with encode/decode/decode_from. * Server: Add support for AuthenticatorAttachment. * Server: Add support for more key algorithms. * Client: Expose CTAP2 Info object as Fido2Client.info.
    Changes in yubikey-manager:

    * Dependency: Add support for python-fido2 1.x * Fix: Drop stated support for Click 6 as features from 7 are being used.

    * Bugfix: Fix error message for invalid modhex when programing a YubiOTP credential. * Bugfix: Fix issue with displaying a Steam credential when it is the only account. * Bugfix: Prevent installation of files in site-packages root. * Bugfix: Fix cleanup logic in PIV for protected management key. * Add support for token identifier when programming slot-based HOTP. * Add support for programming NDEF in text mode. * Dependency: Add support for Cryptography ⇐ 38.

    ** Bugfix release: Fix broken naming for 'YubiKey 4', and a small OATH issue with touch Steam credentials.

    ** Improve handling of YubiKey device reboots. ** More consistently mask PIN/password input in prompts. ** Support switching mode over CCID for YubiKey Edge. ** Run pkill from PATH instead of fixed location.

    ** Bugfix: Fix PIV feature detection for some YubiKey NEO versions. ** Bugfix: Fix argument short form for --period when adding TOTP credentials. ** Bugfix: More strict validation for some arguments, resulting in better error messages. ** Bugfix: Correctly handle TOTP credentials using period != 30 AND touch_required. ** Bugfix: Fix prompting for access code in the otp settings command (now uses '-A -').

    * Add support for fido reset over NFC. * Bugfix: The --touch argument to piv change-management-key was ignored. * Bugfix: Don’t prompt for password when importing PIV key/cert if file is invalid. * Bugfix: Fix setting touch-eject/auto-eject for YubiKey 4 and NEO. * Bugfix: Detect PKCS#12 format when outer sequence uses indefinite length. * Dependency: Add support for Click 8.

    * Update device names * Add read_info output to the --diagnose command, and show exception types. * Bugfix: Fix read_info for YubiKey Plus. * Add support for YK5-based FIPS YubiKeys. * Bugfix: Fix OTP device enumeration on Win32. * Drop reliance on libusb and libykpersonalize. * Support the 'fido' and 'otp' subcommands over NFC * New 'ykman --diagnose' command to aid in troubleshooting. * New 'ykman apdu' command for sending raw APDUs over the smart card interface. * New 'yubikit' package added for custom development and advanced scripting. * OpenPGP: Add support for KDF enabled YubiKeys. * Static password: Add support for FR, IT, UK and BEPO keyboard layouts.

    * Add support for YubiKey 5C NFC * OpenPGP: set-touch now performs compatibility checks before prompting for PIN * OpenPGP: Improve error messages and documentation for set-touch * PIV: read-object command no longer adds a trailing newline * CLI: Hint at missing permissions when opening a device fails * Linux: Improve error handling when pcscd is not running * Windows: Improve how .DLL files are loaded, thanks to Marius Gabriel Mihai for reporting this! * Bugfix: set-touch now accepts the cached-fixed option * Bugfix: Fix crash in OtpController.prepare_upload_key() error parsing * Bugfix: Fix crash in piv info command when a certificate slot contains an invalid certificate * Library: PivController.read_certificate(slot) now wraps certificate parsing exceptions in new exception type InvalidCertificate * Library: PivController.list_certificates() now returns None for slots containing invalid certificate, instead of raising an exception

    * Add support for YubiKey 5Ci * OpenPGP: the info command now prints OpenPGP specification version as well * OpenPGP: Update support for attestation to match OpenPGP v3.4 * PIV: Use UTC time for self-signed certificates * OTP: Static password now supports the Norman keyboard layout

    * Add support for new YubiKey Preview and lightning form factor * FIDO: Support for credential management * OpenPGP: Support for OpenPGP attestation, cardholder certificates and cached touch policies * OTP: Add flag for using numeric keypad when sending digits

    * OTP: Add initial support for uploading Yubico OTP credentials to YubiCloud * Don’t automatically select the U2F applet on YubiKey NEO, it might be blocked by the OS * ChalResp: Always pad challenge correctly * Bugfix: Don’t crash with older versions of cryptography * Bugfix: Password was always prompted in OATH command, even if sent as argument
    Changes in yubikey-manager-qt:

    * Compatibility update for ykman 5.0.1. * Update to Python 3.11. * Update product images.

    * Update device names and images. * PIV: Fix import of certificate.

    * Improved error handling when using Security Key Series devices. * PIV: Fix generation of certificate in slot 9c.

    * Fix detection of YubiKey Plus * Compatibility update for yubikey-manager 4.0 * Bugfix: Device caching with multiple devices * Drop dependencies on libusb and libykpers. * Add additional product names and images

    * Add support for YubiKey 5C NFC

    * OTP: Add option to upload YubiOTP credential to YubiCloud * Linux: Show hint about pcscd service if opening device fails * Bugfix: Signal handling now compatible with Python 3.8

    * Add suppport for YubiKey 5Ci * PIV: Use UTC time for self-signed certificates

    * Add support for new YubiKey Preview * PIV: The popup for the management key now have a 'Use default' option * Windows: Fix issue with importing PIV certificates * Bugfix: generate static password now works correctly


    Advisory IDSUSE-RU-2023:2814-1
    ReleasedWed Jul 12 22:05:25 2023
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1185116,1202118
    Description:

    This update for mozilla-nss fixes the following issues:
    mozilla-nss was updated to NSS 3.90:



    update to NSS 3.89.1

    update to NSS 3.89

    update to NSS 3.88.1

    update to NSS 3.88

    update to NSS 3.87

    update to NSS 3.86

    update to NSS 3.85

    update to NSS 3.84

    update to NSS 3.83
    with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing
  • Added ECH client support to BoGo shim. Changed
  • CHInner creation to skip TLS 1.2 only extensions to comply with BoGo
  • Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs
  • Update BoGo tests to recent BoringSSL version
  • Bump minimum NSPR version to 4.34.1

  • update to NSS 3.82

    update to NSS 3.81



    update to NSS 3.80
    by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record.
  • Mark 3.79 as an ESR release.
  • Bump nssckbi version number for June.
  • Remove Hellenic Academic 2011 Root.
  • Add E-Tugra Roots.
  • Add Certainly Roots.
  • Add DigitCert Roots.
  • Protect SFTKSlot needLogin with slotLock.
  • Compare signature and signatureAlgorithm fields in legacy certificate verifier.
  • Uninitialized value in cert_VerifyCertChainOld.
  • Unchecked return code in sec_DecodeSigAlg.
  • Uninitialized value in cert_ComputeCertType.
  • Avoid data race on primary password change.
  • Replace ppc64 dcbzl intrinisic.
  • Allow LDFLAGS override in makefile builds.

  • Advisory IDSUSE-RU-2023:2827-1
    ReleasedFri Jul 14 11:27:47 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:2847-1
    ReleasedMon Jul 17 08:40:42 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1210004
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-RU-2023:2855-1
    ReleasedMon Jul 17 16:35:21 2023
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1212260
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-SU-2023:2877-1
    ReleasedWed Jul 19 09:43:42 2023
    SummarySecurity update for dbus-1
    Typesecurity
    Severitymoderate
    References1212126,CVE-2023-34969
    Description:

    This update for dbus-1 fixes the following issues:


    Advisory IDSUSE-SU-2023:2882-1
    ReleasedWed Jul 19 11:49:39 2023
    SummarySecurity update for perl
    Typesecurity
    Severityimportant
    References1210999,CVE-2023-31484
    Description:

    This update for perl fixes the following issues:

    - CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).


    Advisory IDSUSE-RU-2023:2885-1
    ReleasedWed Jul 19 16:58:43 2023
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1208721,1209229,1211828
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2023:2891-1
    ReleasedWed Jul 19 21:14:33 2023
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1213237,CVE-2023-32001
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2023:2901-1
    ReleasedThu Jul 20 09:49:16 2023
    SummaryRecommended update for lvm2
    Typerecommended
    Severityimportant
    References1212613
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2023:2918-1
    ReleasedThu Jul 20 12:00:17 2023
    SummaryRecommended update for gpgme
    Typerecommended
    Severitymoderate
    References1089497
    Description:

    This update for gpgme fixes the following issues:
    gpgme:

    libassuan:


    Advisory IDSUSE-RU-2023:2922-1
    ReleasedThu Jul 20 18:34:03 2023
    SummaryRecommended update for libfido2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libfido2 fixes the following issues:


    Advisory IDSUSE-RU-2023:2934-1
    ReleasedFri Jul 21 12:46:57 2023
    SummaryRecommended update for libcontainers-common
    Typerecommended
    Severitymoderate
    References1211124
    Description:

    This update for libcontainers-common fixes the following issues:


    Advisory IDSUSE-SU-2023:2945-1
    ReleasedMon Jul 24 09:37:30 2023
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1186673,1209536,1213004,1213008,1213504,CVE-2023-38408
    Description:

    This update for openssh fixes the following issues:




    Advisory IDSUSE-SU-2023:2965-1
    ReleasedTue Jul 25 12:30:22 2023
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitymoderate
    References1213487,CVE-2023-3446
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2023:2966-1
    ReleasedTue Jul 25 14:26:14 2023
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2023:2988-1
    ReleasedWed Jul 26 16:33:30 2023
    SummarySecurity update for conmon
    Typesecurity
    Severityimportant
    References1208737,1209307
    Description:

    This update for conmon fixes the following issues:
    conmon was updated to version 2.1.7:
    - Bumped go version to 1.19 (bsc#1209307).
    Bugfixes:
    - Fixed leaking symbolic links in the opt_socket_path directory - Fixed oom handling issues (bsc#1208737). - Fixed OOM watcher for cgroupv2 `oom_kill` events


    Advisory IDSUSE-SU-2023:3019-1
    ReleasedFri Jul 28 21:26:50 2023
    SummarySecurity update for kernel-firmware
    Typesecurity
    Severitymoderate
    References1213286,CVE-2023-20593
    Description:

    This update for kernel-firmware fixes the following issues:
    Updated to version 20230724 (git commit 59fbffa9ec8e):
    - CVE-2023-20593: Fixed AMD ucode for ZenBleed vulnerability (bsc#1213286).

    Bugfixes:
    - Fix qcom ASoC tglp WHENCE entry - Group all Conexant V4L devices together - Makefile, copy-firmware: support xz/zstd compressed firmware - Updated NXP SR150 UWB firmware - WHENCE: Cleanup Realtek BT firmware provenance - WHENCE: comment out duplicate MediaTek firmware - amdgpu: Add GC 11.0.4 firmware - amdgpu: Add PSP 13.0.11 firmware - amdgpu: DMCUB updates for DCN 3.1.4 and 3.1.5 - amdgpu: DMCUB updates for various AMDGPU asics - amdgpu: Update DCN 3.1.4 firmware - amdgpu: Update GC 11.0.1 and 11.0.4 - amdgpu: Update GC 11.0.1 firmware - amdgpu: Update PSP 13.0.4 firmware - amdgpu: Update SDMA 6.0.1 firmware - amdgpu: add initial GC 11.0.3 firmware - amdgpu: add initial PSP 13.0.10 firmware - amdgpu: add initial SDMA 6.0.3 firmware - amdgpu: add initial SMU 13.0.10 firmware - amdgpu: update 13.0.8 firmware for amd.5.5 release - amdgpu: update DCN 3.1.6 DMCUB firmware - amdgpu: update DMCUB to v0.0.172.0 for various AMDGPU ASICs - amdgpu: update DMCUB to v0.0.175.0 for various AMDGPU ASICs - amdgpu: update GC 10.3.6 firmware for amd.5.5 release - amdgpu: update GC 10.3.7 firmware for amd.5.5 release - amdgpu: update GC 11.0.0 firmware for amd.5.5 release - amdgpu: update GC 11.0.1 firmware for amd.5.5 release - amdgpu: update GC 11.0.2 firmware for amd.5.5 release - amdgpu: update GC 11.0.4 firmware for amd.5.5 release - amdgpu: update PSP 13.0.0 firmware for amd.5.5 release - amdgpu: update PSP 13.0.11 firmware for amd.5.5 release - amdgpu: update PSP 13.0.4 firmware for amd.5.5 release - amdgpu: update PSP 13.0.7 firmware for amd.5.5 release - amdgpu: update Picasso VCN firmware - amdgpu: update SDMA 6.0.1 firmware for amd.5.5 release - amdgpu: update SMU 13.0.0 firmware for amd.5.5 release - amdgpu: update SMU 13.0.7 firmware for amd.5.5 release - amdgpu: update VCN 4.0.0 firmware - amdgpu: update VCN 4.0.0 firmware for amd.5.5 release - amdgpu: update VCN 4.0.4 firmware for amd.5.5 release - amdgpu: update aldebaran firmware for amd.5.5 release - amdgpu: update arcturus firmware for amd.5.5 release - amdgpu: update beige goby firmware for amd.5.5 release - amdgpu: update dimgrey cavefish firmware for amd.5.5 release - amdgpu: update green sardine VCN firmware - amdgpu: update green sardine firmware for amd.5.5 release - amdgpu: update navi10 firmware for amd.5.5 release - amdgpu: update navi12 firmware for amd.5.5 release - amdgpu: update navi14 firmware for amd.5.5 release - amdgpu: update navy flounder firmware for amd.5.5 release - amdgpu: update psp 13.0.5 firmware for amd.5.5 release - amdgpu: update raven VCN firmware - amdgpu: update raven2 VCN firmware - amdgpu: update renoir VCN firmware - amdgpu: update renoir firmware for amd.5.5 release - amdgpu: update sienna cichlid firmware for amd.5.5 release - amdgpu: update vangogh firmware for amd.5.5 release - amdgpu: update vcn 3.1.2 firmware for amd.5.5 release - amdgpu: update vega10 firmware for amd.5.5 release - amdgpu: update vega12 firmware for amd.5.5 release - amdgpu: update vega20 firmware for amd.5.5 release - amdgpu: update yellow carp firmware for amd.5.5 release - ath10k: QCA4019 hw1.0: update board-2.bin - ath10k: QCA6174 hw3.0: update board-2.bin - ath10k: QCA9888 hw2.0: update board-2.bin - ath10k: QCA9984 hw1.0: update board-2.bin - ath10k: QCA99X0 hw2.0: update board-2.bin - ath11k: IPQ6018 hw1.0: update board-2.bin - ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 - ath11k: IPQ8074 hw2.0: update board-2.bin - ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 - ath11k: QCN9074 hw1.0: update to WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1 - ath11k: WCN6750 hw1.0: update to WLAN.MSL.1.0.1-01160-QCAMSLSWPLZ-1 - ath11k: WCN6855 hw2.0: update board-2.bin - brcm: Add symlinks from Pine64 devices to AW-CM256SM.txt - check_whence: Check link targets are valid - check_whence: error if File: is actually a link - check_whence: error if symlinks are in-tree - check_whence: error on directory listed as File - check_whence: error on duplicate file entries - check_whence: strip quotation marks - cirrus: Add CS35L41 firmware for ASUS ROG 2023 Models - cirrus: Add firmware and tuning files for HP G10 series laptops - cirrus: Add firmware and tuning files for Lenovo ThinkPad P1 Gen 6 - cirrus: Add firmware for new Asus ROG Laptops - cnm: update chips&media wave521c firmware. - copy-firmware: drop obsolete backticks, quote - copy-firmware: quote deskdir and dirname - copy-firmware: silence the last shellcheck warnings - copy-firmware: tweak sed invocation - cxgb4: Update firmware to revision 1.27.3.0 - fix broken cirrus firmware symlinks - i915: Add GuC v70.6.6 for MTL - i915: Add HuC v8.5.0 for MTL - i915: update DG2 GuC to v70.8.0 - i915: update to GuC 70.8.0 and HuC 8.5.1 for MTL - ice: update ice DDP comms package to 1.3.40.0 - ice: update ice DDP wireless_edge package to 1.3.10.0 - iwlwifi: add new FWs from core78-32 release - iwlwifi: add new FWs from core80-39 release - iwlwifi: update 9000-family firmwares to core78-32 - iwlwifi: update cc/Qu/QuZ firmwares for core80-39 release - linux-firmware: Add firmware for Cirrus CS35L41 on Lenovo Laptops - linux-firmware: Amphion: Update vpu firmware - linux-firmware: Update AMD cpu microcode - linux-firmware: Update AMD cpu microcode - linux-firmware: Update AMD fam17h cpu microcode - linux-firmware: Update firmware file for Intel Bluetooth AX200 - linux-firmware: Update firmware file for Intel Bluetooth AX201 - linux-firmware: Update firmware file for Intel Bluetooth AX203 - linux-firmware: Update firmware file for Intel Bluetooth AX210 - linux-firmware: Update firmware file for Intel Bluetooth AX211 - linux-firmware: add firmware for MT7981 - linux-firmware: update firmware for MT7916 - linux-firmware: update firmware for MT7921 WiFi device - linux-firmware: update firmware for MT7922 WiFi device - linux-firmware: update firmware for MT7981 - linux-firmware: update firmware for mediatek bluetooth chip (MT7921) - linux-firmware: update firmware for mediatek bluetooth chip (MT7922) - linux-firmware: update firmware for mediatek bluetooth chip (MT7922) - linux-firmware: update qat firmware - linux-firmware: wilc1000: update WILC1000 firmware to v16.0 - mediatek: Update mt8195 SCP firmware to support 10bit mode - mediatek: Update mt8195 SCP firmware to support hevc - mt76xx: Move the old Mediatek WiFi firmware to mediatek - nvidia: update Tu10x and Tu11x signed firmware to support newer Turing HW - qca: Update firmware files for BT chip WCN6750 - qcom: Add Audio firmware for SC8280XP X13s - qcom: Update the microcode files for Adreno a630 GPUs. - qcom: apq8016: add Dragonboard 410c WiFi and modem firmware - qcom: sdm845: rename the modem firmware - qcom: sdm845: update remoteproc firmware - rtl_bt: Add firmware and config files for RTL8851B - rtl_bt: Update RTL8761B BT UART firmware to 0x9DC6_D922 - rtl_bt: Update RTL8761B BT USB firmware to 0xDFC6_D922 - rtl_bt: Update RTL8852A BT USB firmware to 0xDAC7_480D - rtl_bt: Update RTL8852B BT USB firmware to 0xDBC6_B20F - rtl_bt: Update RTL8852C BT USB firmware to 0x040D_7225 - rtl_nic: update firmware of USB devices - rtlwifi: Add firmware v6.0 for RTL8192FU - rtlwifi: Update firmware for RTL8188EU to v28.0 - rtw88: 8822c: Update normal firmware to v9.9.15 - rtw89: 8851b: add firmware v0.29.41.0 - rtw89: 8852b: update format-1 fw to v0.29.29.1 - rtw89: 8852c: update fw to v0.27.56.13 - wfx: update to firmware 3.16.1


    Advisory IDSUSE-RU-2023:3088-1
    ReleasedTue Aug 1 09:52:03 2023
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitymoderate
    References1212496
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2023:3102-1
    ReleasedTue Aug 1 14:11:53 2023
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1213517
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2023:3178-1
    ReleasedThu Aug 3 13:16:15 2023
    SummaryRecommended update for multipath-tools
    Typerecommended
    Severitymoderate
    References1212440,1212854
    Description:

    This update for multipath-tools fixes the following issues:


    Advisory IDSUSE-RU-2023:3217-1
    ReleasedMon Aug 7 16:51:10 2023
    SummaryRecommended update for cryptsetup
    Typerecommended
    Severitymoderate
    References1211079
    Description:

    This update for cryptsetup fixes the following issues:


    Advisory IDSUSE-SU-2023:3242-1
    ReleasedTue Aug 8 18:19:40 2023
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitymoderate
    References1213853,CVE-2023-3817
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2023:3276-1
    ReleasedFri Aug 11 10:20:40 2023
    SummaryRecommended update for apparmor
    Typerecommended
    Severitymoderate
    References1213472
    Description:

    This update for apparmor fixes the following issues:


    Advisory IDSUSE-SU-2023:3298-1
    ReleasedFri Aug 11 20:04:17 2023
    SummarySecurity update for kernel-firmware
    Typesecurity
    Severitymoderate
    References1213287,CVE-2023-20569
    Description:

    This update for kernel-firmware fixes the following issues:


    Advisory IDSUSE-SU-2023:3325-1
    ReleasedWed Aug 16 08:26:08 2023
    SummarySecurity update for krb5
    Typesecurity
    Severityimportant
    References1214054,CVE-2023-36054
    Description:

    This update for krb5 fixes the following issues:


    Advisory IDSUSE-SU-2023:3327-1
    ReleasedWed Aug 16 08:45:25 2023
    SummarySecurity update for pcre2
    Typesecurity
    Severitymoderate
    References1213514,CVE-2022-41409
    Description:

    This update for pcre2 fixes the following issues:
    - CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514).


    Advisory IDSUSE-RU-2023:3393-1
    ReleasedWed Aug 23 17:41:55 2023
    SummaryRecommended update for dracut
    Typerecommended
    Severityimportant
    References1214081
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-RU-2023:3410-1
    ReleasedThu Aug 24 06:56:32 2023
    SummaryRecommended update for audit
    Typerecommended
    Severitymoderate
    References1201519,1204844
    Description:

    This update for audit fixes the following issues:


    Advisory IDSUSE-feature-2023:3413-1
    ReleasedThu Aug 24 07:32:09 2023
    SummaryFeature update for LibreOffice and xmlsec1
    Typefeature
    Severityimportant
    References1198666,1200085,1204040,1209242,1210687,1211746,CVE-2023-0950,CVE-2023-2255
    Description:

    This update for LibreOffice and xmlsec1 fixes the following issue: libreoffice:


    xmlsec1:


    Advisory IDSUSE-SU-2023:3440-1
    ReleasedMon Aug 28 08:57:10 2023
    SummarySecurity update for gawk
    Typesecurity
    Severitylow
    References1214025,CVE-2023-4156
    Description:

    This update for gawk fixes the following issues:


    Advisory IDSUSE-RU-2023:3451-1
    ReleasedMon Aug 28 12:15:22 2023
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1186606,1194609,1208194,1209741,1210702,1211576,1212434,1213185,1213575,1213873
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2023:3470-1
    ReleasedTue Aug 29 10:49:33 2023
    SummaryRecommended update for parted
    Typerecommended
    Severitylow
    References1182142,1193412
    Description:

    This update for parted fixes the following issues:


    Advisory IDSUSE-SU-2023:3472-1
    ReleasedTue Aug 29 10:55:16 2023
    SummarySecurity update for procps
    Typesecurity
    Severitylow
    References1214290,CVE-2023-4016
    Description:

    This update for procps fixes the following issues:
    - CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290).


    Advisory IDSUSE-RU-2023:3485-1
    ReleasedTue Aug 29 14:20:56 2023
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1214071
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-SU-2023:3497-1
    ReleasedWed Aug 30 21:25:05 2023
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1210996,1211256,1211257,1211461,CVE-2023-2426,CVE-2023-2609,CVE-2023-2610
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.0 with patch level 1572.


    Advisory IDSUSE-SU-2023:3507-1
    ReleasedThu Aug 31 19:58:03 2023
    SummarySecurity update for open-vm-tools
    Typesecurity
    Severityimportant
    References1214566,CVE-2023-20900
    Description:

    This update for open-vm-tools fixes the following issues:


    This update also ships a open-vm-tools-containerinfo plugin. (jsc#PED-3421)


    Advisory IDSUSE-RU-2023:3577-1
    ReleasedMon Sep 11 15:04:01 2023
    SummaryRecommended update for crypto-policies
    Typerecommended
    Severitylow
    References1209998
    Description:

    This update for crypto-policies fixes the following issues:


    Advisory IDSUSE-RU-2023:3611-1
    ReleasedFri Sep 15 09:28:36 2023
    SummaryRecommended update for sysuser-tools
    Typerecommended
    Severitymoderate
    References1195391,1205161,1207778,1213240,1214140
    Description:

    This update for sysuser-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:3661-1
    ReleasedMon Sep 18 21:44:09 2023
    SummarySecurity update for gcc12
    Typesecurity
    Severityimportant
    References1214052,CVE-2023-4039
    Description:

    This update for gcc12 fixes the following issues:


    Advisory IDSUSE-SU-2023:3666-1
    ReleasedMon Sep 18 21:52:18 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severityimportant
    References1214768,CVE-2023-39615
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2023:3717-1
    ReleasedThu Sep 21 06:51:51 2023
    SummaryRecommended update for apparmor
    Typerecommended
    Severitymoderate
    References1214458
    Description:

    This update for apparmor fixes the following issues:


    Advisory IDSUSE-RU-2023:3780-1
    ReleasedTue Sep 26 10:58:21 2023
    SummaryRecommended update hidapi
    Typerecommended
    Severitymoderate
    References1214535
    Description:


    This update for hidapi ships the missing libhidapi-raw0 library to SLE and Leap Micro 5.3 and 5.4.


    Advisory IDSUSE-RU-2023:3798-1
    ReleasedWed Sep 27 10:32:31 2023
    SummaryRecommended update for libcontainers-common
    Typerecommended
    Severityimportant
    References1215291
    Description:

    This update for libcontainers-common fixes the following issues:


    Advisory IDSUSE-RU-2023:3814-1
    ReleasedWed Sep 27 18:08:17 2023
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1211829,1212819,1212910
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2023:3823-1
    ReleasedWed Sep 27 18:42:38 2023
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1215026,CVE-2023-38039
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2023:3835-1
    ReleasedWed Sep 27 19:20:31 2023
    SummarySecuritys update for open-vm-tools
    Typesecurity
    Severityimportant
    References1205927,1214850,CVE-2023-20900
    Description:

    This update for open-vm-tools fixes the following issues:
    Update to 12.3.0 (build 22234872) (bsc#1214850)


    - This release integrates CVE-2023-20900 without the need for a patch. For more information on this vulnerability and its impact on VMware products, see https://www.vmware.com/security/advisories/VMSA-2023-0019.html. - A tools.conf configuration setting is available to temporaily direct Linux quiesced snaphots to restore pre open-vm-tools 12.2.0 behavior of ignoring file systems already frozen. - Building of the VMware Guest Authentication Service (VGAuth) using 'xml-security-c' and 'xerces-c' is being deprecated. - A number of Coverity reported issues have been addressed. - A number of GitHub issues and pull requests have been handled. Please see the Resolves Issues section of the Release Notes. - For issues resolved in this release, see the Resolved Issues section of the Release Notes.


    Advisory IDSUSE-SU-2023:3952-1
    ReleasedTue Oct 3 20:06:23 2023
    SummarySecurity update for runc
    Typesecurity
    Severityimportant
    References1212475
    Description:


    This update of runc fixes the following issues:


    Upstream changelog is available from .


    Advisory IDSUSE-SU-2023:3954-1
    ReleasedTue Oct 3 20:09:47 2023
    SummarySecurity update for libeconf
    Typesecurity
    Severityimportant
    References1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181
    Description:

    This update for libeconf fixes the following issues:
    Update to version 0.5.2.


    Advisory IDSUSE-RU-2023:3970-1
    ReleasedWed Oct 4 14:17:12 2023
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1215578
    Description:

    This update for dracut fixes the following issues:


    Advisory IDSUSE-RU-2023:3978-1
    ReleasedThu Oct 5 11:45:05 2023
    SummaryRecommended update for nfs-utils
    Typerecommended
    Severitymoderate
    References1157881,1200710,1209859,1212594
    Description:

    This update for nfs-utils fixes the following issues:


    Advisory IDSUSE-RU-2023:3985-1
    ReleasedThu Oct 5 14:05:51 2023
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severityimportant
    References1201066,1212957,1213428,1213822
    Description:

    This update for suse-module-tools fixes the following issues:


    Advisory IDSUSE-SU-2023:3997-1
    ReleasedFri Oct 6 14:13:56 2023
    SummarySecurity update for nghttp2
    Typesecurity
    Severityimportant
    References1215713,CVE-2023-35945
    Description:

    This update for nghttp2 fixes the following issues:


    Advisory IDSUSE-RU-2023:4003-1
    ReleasedMon Oct 9 08:29:33 2023
    SummaryRecommended update for apparmor
    Typerecommended
    Severitymoderate
    References1215596
    Description:

    This update for apparmor fixes the following issues:


    Advisory IDSUSE-SU-2023:4022-1
    ReleasedTue Oct 10 11:06:12 2023
    SummarySecurity update for conmon
    Typesecurity
    Severityimportant
    References1215806
    Description:

    This update for conmon fixes the following issues:
    conmon is rebuild with go1.21 to capture current stability, bug and security fixes. (bsc#1215806)


    Advisory IDSUSE-SU-2023:4044-1
    ReleasedWed Oct 11 09:01:14 2023
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1215888,1215889,CVE-2023-38545,CVE-2023-38546
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2023:4073-1
    ReleasedFri Oct 13 11:40:26 2023
    SummaryRecommended update for rpm
    Typerecommended
    Severitylow
    References
    Description:

    This update for rpm fixes the following issue:


    Advisory IDSUSE-SU-2023:4075-1
    ReleasedFri Oct 13 14:02:33 2023
    SummarySecurity update for cni-plugins
    Typesecurity
    Severityimportant
    References1212475,1216006
    Description:


    This update of cni-plugins fixes the following issues:


    Advisory IDSUSE-SU-2023:4076-1
    ReleasedFri Oct 13 14:02:51 2023
    SummarySecurity update for cni
    Typesecurity
    Severityimportant
    References1212475,1216006
    Description:


    This update of cni fixes the following issues:


    Advisory IDSUSE-RU-2023:4105-1
    ReleasedWed Oct 18 08:15:40 2023
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1215215
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2023:4110-1
    ReleasedWed Oct 18 12:35:26 2023
    SummarySecurity update for glibc
    Typesecurity
    Severityimportant
    References1215286,1215891,CVE-2023-4813
    Description:

    This update for glibc fixes the following issues:
    Security issue fixed:


    Also a regression from a previous update was fixed:


    Advisory IDSUSE-RU-2023:4112-1
    ReleasedWed Oct 18 13:04:43 2023
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1205927
    Description:

    This update for open-vm-tools fixes the following issue:


    Advisory IDSUSE-SU-2023:4136-1
    ReleasedThu Oct 19 14:15:02 2023
    SummarySecurity update for suse-module-tools
    Typesecurity
    Severityimportant
    References1205767,1210335,CVE-2023-1829,CVE-2023-23559
    Description:

    This update for suse-module-tools fixes the following issues:


    - CVE-2023-1829: Blacklisted the Linux kernel tcindex classifier module (bsc#1210335). - CVE-2023-23559: Blacklisted the Linux kernel RNDIS modules (bsc#1205767, jsc#PED-5731).


    Advisory IDSUSE-RU-2023:4138-1
    ReleasedThu Oct 19 17:15:38 2023
    SummaryRecommended update for systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for systemd-rpm-macros fixes the following issues:


    Advisory IDSUSE-RU-2023:4139-1
    ReleasedFri Oct 20 10:06:58 2023
    SummaryRecommended update for containerd, runc
    Typerecommended
    Severitymoderate
    References1215323
    Description:

    This update for containerd, runc fixes the following issues:
    runc was updated to v1.1.9. Upstream changelog is available from
    https://github.com/opencontainers/runc/releases/tag/v1.1.9
    containerd was updated to containerd v1.7.7 for Docker v24.0.6-ce. Upstream release notes:


    Advisory IDSUSE-RU-2023:4153-1
    ReleasedFri Oct 20 19:27:58 2023
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1215313
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2023:4154-1
    ReleasedFri Oct 20 19:33:25 2023
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1107342,1215434
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2023:4162-1
    ReleasedMon Oct 23 15:33:03 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4200-1
    ReleasedWed Oct 25 12:04:29 2023
    SummarySecurity update for nghttp2
    Typesecurity
    Severityimportant
    References1216123,1216174,CVE-2023-44487
    Description:

    This update for nghttp2 fixes the following issues:


    Advisory IDSUSE-SU-2023:4215-1
    ReleasedThu Oct 26 12:19:25 2023
    SummarySecurity update for zlib
    Typesecurity
    Severitymoderate
    References1216378,CVE-2023-45853
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-SU-2023:4227-1
    ReleasedFri Oct 27 11:26:20 2023
    SummarySecurity update for open-vm-tools
    Typesecurity
    Severityimportant
    References1216432,1216433,CVE-2023-34058,CVE-2023-34059
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-RU-2023:4268-1
    ReleasedMon Oct 30 16:51:57 2023
    SummaryRecommended update for pciutils
    Typerecommended
    Severityimportant
    References1215265
    Description:

    This update for pciutils fixes the following issues:


    Advisory IDSUSE-RU-2023:4310-1
    ReleasedTue Oct 31 14:10:47 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467)
    * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage
    Update to 1.3.3:


    Update to 1.3.2:

    Update to 1.3.1:


    Advisory IDSUSE-RU-2023:4446-1
    ReleasedWed Nov 15 07:20:00 2023
    SummaryRecommended update for open-vm-tools
    Typerecommended
    Severitymoderate
    References1216670
    Description:

    This update for open-vm-tools fixes the following issues:


    Advisory IDSUSE-RU-2023:4450-1
    ReleasedWed Nov 15 10:55:20 2023
    SummaryRecommended update for crypto-policies
    Typerecommended
    Severitymoderate
    References1209998
    Description:

    This update for crypto-policies fixes the following issues:
    - Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands (jsc#PED-5041) - Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby and add a note for transactional systems - Ship the man pages for fips-mode-setup and fips-finish-install - Make the supported versions change in the update-crypto-policies(8) man page persistent (bsc#1209998)


    Advisory IDSUSE-RU-2023:4456-1
    ReleasedThu Nov 16 08:40:57 2023
    SummaryRecommended update for selinux-policy
    Typerecommended
    Severitymoderate
    References1216060
    Description:

    This update for selinux-policy fixes the following issues:


    Advisory IDSUSE-SU-2023:4458-1
    ReleasedThu Nov 16 14:38:48 2023
    SummarySecurity update for gcc13
    Typesecurity
    Severityimportant
    References1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039
    Description:

    This update for gcc13 fixes the following issues:
    This update ship the GCC 13.2 compiler suite and its base libraries.
    The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones.
    The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
    The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories.
    To use gcc13 compilers use:


    For a full changelog with all new GCC13 features, check out
    https://gcc.gnu.org/gcc-13/changes.html

    Detailed changes:




    Advisory IDSUSE-SU-2023:4503-1
    ReleasedTue Nov 21 13:25:12 2023
    SummarySecurity update for avahi
    Typesecurity
    Severitymoderate
    References1215947,1216419,CVE-2023-38470,CVE-2023-38473
    Description:

    This update for avahi fixes the following issues:


    Advisory IDSUSE-SU-2023:4504-1
    ReleasedTue Nov 21 13:27:50 2023
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1216129,CVE-2023-45322
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2023:4518-1
    ReleasedTue Nov 21 17:35:30 2023
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1216922,CVE-2023-5678
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2023:4557-1
    ReleasedFri Nov 24 17:04:36 2023
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1214922,1214924,1214925,1215004,1215006,1215033,1215940,1216001,1216167,1216696,CVE-2023-46246,CVE-2023-4733,CVE-2023-4734,CVE-2023-4735,CVE-2023-4738,CVE-2023-4752,CVE-2023-4781,CVE-2023-5344,CVE-2023-5441,CVE-2023-5535
    Description:

    This update for vim fixes the following issues:
    Updated to version 9.0 with patch level 2103, fixes the following security problems


    Advisory IDSUSE-RU-2023:4603-1
    ReleasedWed Nov 29 08:41:39 2023
    SummaryRecommended update for selinux-policy
    Typerecommended
    Severitymoderate
    References1215405
    Description:

    This update for selinux-policy fixes the following issues:


    Advisory IDSUSE-SU-2023:4619-1
    ReleasedThu Nov 30 10:13:52 2023
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1210660,CVE-2023-2137
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-SU-2023:4623-1
    ReleasedThu Nov 30 19:22:32 2023
    SummarySecurity update for traceroute
    Typesecurity
    Severitymoderate
    References1216591,CVE-2023-46316
    Description:

    This update for traceroute fixes the following issues:


    Advisory IDSUSE-RU-2023:4628-1
    ReleasedFri Dec 1 09:27:15 2023
    SummaryRecommended update for podman
    Typerecommended
    Severitymoderate
    References1210299,1215807,1215926
    Description:

    This update for podman fixes the following issues:
    This update ships podman version 4.7.2:
    * WSL: Fixed podman compose command. * Fixed a bug in podman compose to try all configured providers before throwing an error (#20502). * Mask /sys/devices/virtual/powercap ( GHSA-jq35-85cj-fj4p)



    * Bugfixes
    * Fixed a bug involving non-English locales of Windows where machine installs using user-mode networking were rejected due to erroneous version detection (#20209). * Fixed a regression in --env-file handling (#19565). * Fixed a bug where podman inspect would fail when stat'ing a device failed.
    * API
    * The network list compat API endpoint is now much faster (#20035).



    * Security
    * Now the io.containers.capabilities LABEL in an image can be an empty string.
    * Features
    * New command set: podman farm [create,list,remove,update] has been created to 'farm' out builds to machines running Podman for different architectures. * New command: podman compose as a thin wrapper around an external compose provider such as docker-compose or podman-compose. * FreeBSD: podman run --device is now supported. * Linux: Add a new --module flag for Podman. * Podmansh: Timeout is now configurable using the podmansh_timeout option in containers.conf. * SELinux: Add support for confined users to create containers but restrict them from creating privileged containers. * WSL: Registers shared socket bindings on Windows, to allow other WSL distributions easy remote access (#15190). * WSL: Enabling user-mode-networking on older WSL2 generations will now detect an error with upgrade guidance. * The podman build command now supports two new options: --layer-label and --cw. * The podman kube generate command now supports generation of k8s DaemonSet kind (#18899). * The podman kube generate and podman kube play commands now support the k8s TerminationGracePeriodSeconds field (RH BZ#2218061). * The podman kube generate and podman kube play commands now support securityContext.procMount: Unmasked (#19881). * The podman generate kube command now supports a --podman-only flag to allow podman-only reserved annotations to be used in the generated YAML file. These annotations cannot be used by Kubernetes. * The podman kube generate now supports a --no-trunc flag that supports YAML files with annotations longer than 63 characters. Warning: if an annotation is longer than 63 chars, then the generated yaml file is not Kubernetes compatible. * An infra name annotation io.podman.annotations.infra.name is added in the generated yaml when the pod create command has --infra-name set. This annotation can also be used with kube play when wanting to customize the infra container name (#18312). * The syntax of --uidmap and --gidmap has been extended to lookup the parent user namespace and to extend default mappings (#18333). * The podman kube commands now support the List kind (#19052). * The podman kube play command now supports environment variables in kube.yaml (#15983). * The podman push and podman manifest push commands now support the --force-compression optionto prevent reusing other blobs (#18860). * The podman manifest push command now supports --add-compression to push with compressed variants. * The podman manifest push command now honors the add_compression field from containers.conf if --add-compression is not set. * The podman run and podman create --mount commands now support the ramfs type (#19659). * When running under systemd (e.g., via Quadlet), Podman will extend the start timeout in 30 second steps up to a maximum of 5 minutes when pulling an image. * The --add-host option now accepts the special string host-gateway instead of an IP Address, which will be mapped to the host IP address. * The podman generate systemd command is deprecated. Use Quadlet for running containers and pods under systemd. * The podman secret rm command now supports an --ignore option. * The --env-file option now supports multiline variables (#18724). * The --read-only-tmpfs flag now affects /dev and /dev/shm as well as /run, /tmp, /var/tmp (#12937). * The Podman --mount option now supports bind mounts passed as globs. * The --mount option can now be specified in containers.conf using the mounts field. * The podman stats now has an --all option to get all containers stats (#19252). * There is now a new --sdnotify=healthy policy where Podman sends the READY message once the container turns healthy (#6160). * Temporary files created when dealing with images in /var/tmp will automatically be cleaned up on reboot. * There is now a new filter option since for podman volume ls and podman volume prune (#19228). * The podman inspect command now has tab-completion support (#18672). * The podman kube play command now has support for the use of reserved annotations in the generated YAML. * The progress bar is now displayed when decompressing a Podman machine image (#19240). * The podman secret inspect command supports a new option --showsecret which will output the actual secret. * The podman secret create now supports a --replace option, which allows you to modify secrets without replacing containers. * The podman login command can now read the secret for a registry from its secret database created with podman secret create (#18667). * The remote Podman client’s podman play kube command now works with the --userns option (#17392).
    * Changes
    * The /tmp and /var/tmp inside of a podman kube play will no longer be noexec. * The limit of inotify instances has been bumped from 128 to 524288 for podman machine (#19848). * The podman kube play has been improved to only pull a newer image for the 'latest' tag (#19801). * Pulling from an oci transport will use the optional name for naming the image. * The podman info command will always display the existence of the Podman socket. * The echo server example in socket_activation.md has been rewritten to use quadlet instead of podman generate systemd. * Kubernetes support table documentation correctly show volumes support. * The podman auto-update manpage and documentation has been updated and now includes references to Quadlet.
    * Quadlet
    * Quadlet now supports setting Ulimit values. * Quadlet now supports setting the PidsLimit option in a container. * Quadlet unit files allow DNS field in Network group and DNS, DNSSearch, and DNSOption field in Container group (#19884). * Quadlet now supports ShmSize option in unit files. * Quadlet now recursively calls in user directories for unit files. * Quadlet now allows the user to set the service working directory relative to the YAML or Unit files (17177). * Quadlet now allows setting user-defined names for Volume and Network units via the VolumeName and NetworkName directives, respectively. * Kube quadlets can now support autoupdate.
    * Bugfixes
    * Fixed an issue where containers were being restarted after a podman kill. * Fixed a bug where events could report incorrect healthcheck results (#19237). * Fixed a bug where running a container in a pod didn't fail if volumes or mounts were specified in the containers.conf file. * Fixed a bug where pod cgroup limits were not being honored after a reboot (#19175). * Fixed a bug where podman rm -af could fail to remove containers under some circumstances (#18874). * Fixed a bug in rootless to clamp oom_score_adj to current value if it is too low (#19829). * Fixed a bug where --hostuser was being parsed in base 8 instead of base 10 (#19800). * Fixed a bug where kube down would error when an object did not exist (#19711). * Fixed a bug where containers created via DOCKER API without specifying StopTimeout had StopTimeout defaulting to 0 seconds (#19139). * Fixed a bug in podman exec to set umask to match the container it's execing into (#19713). * Fixed a bug where podman kube play failed to set a container's Umask to the default 0022. * Fixed a bug to automatically reassign Podman's machine ssh port on Windows when it conflicts with in-use system ports (#19554). * Fixed a bug where locales weren't passed to conmon correctly, resulting in a crash if some characters were specified over CLI (containers/common/#272). * Fixed a bug where podman top would sometimes not print the full output (#19504). * Fixed a bug were podman logs --tail could return incorrect lines when the k8s-file logger is used (#19545). * Fixed a bug where podman stop did not ignore cidfile not existing when user specified --ignore flag (#19546). * Fixed a bug where a container with an image volume and an inheri...


    * Changes
    * Fixed a performance issue when calculating diff sizes in overlay. The podman system df command should see a significant performance improvement (#19467).
    * Bugfixes
    * Fixed a bug where containers in a pod would use the pod restart policy over the set container restart policy (#19671).
    * API
    * Fixed a bug in the Compat Build endpoint where the pull query parameter did not parse 0/1 as a boolean (#17778).
    * Misc
    * Updated the containers/storage library to v1.48.1


    * Quadlet
    * Quadlet now selects the first Quadlet file found when multiple Quadlets exist with the same name.
    * API
    * Fixed a bug in the container kill endpoint to correctly return 409 when a container is not running (#19368).
    * Misc
    * Updated Buildah to v1.31.2 * Updated the containers/common library to v0.55.3



    * Features
    * The podman manifest inspect command now supports the --authfile option, for authentication purposes. * The podman wait command now supports --condition={healthy,unhealthy}, allowing waits on successful health checks. * The podman push command now supports a new option, --compression-level, which specifies the compression level to use (#18939). * The podman machine start command, when run with --log-level=debug, now creates a console window to display the virtual machine while booting. * Podman now supports a new option, --imagestore, which allows images to be stored in a different directory than the graphroot. * The --ip-range option to the podman network create command now accepts a new syntax, -, which allows more flexibility when limiting the ip range that Podman assigns. * [Tech Preview] A new command, podmansh, has been added, which executes a user shell within a container when the user logs into the system. The container that the users get added to can be defined via a Podman Quadlet file. This feature is currently a Tech Preview which means it's ready for users to try out but changes can be expected in upcoming versions. * The podman network create command supports a new --option, bclim, for the macvlan driver. * The podman network create command now supports adding static routes using the --route option. * The podman network create command supports a new --option, no_default_route for all drivers. * The podman info command now prints network information about the binary path, package version, program version and DNS information (#18443). * The podman info command now displays the number of free locks available, helping to debug lock exhaustion scenarios. * The podman info command now outputs information about pasta, if it exists in helper_binaries_dir or $PATH. * The remote Podman client’s podman build command now accepts Containerfiles that are not in the context directory (#18239). * The remote Podman client’s podman play kube command now supports the --configmap option (#17513). * The podman kube play command now supports multi-doc YAML files for configmap arguments. (#18537). * The podman pod create command now supports a new flag, --restart, which sets the restart policy for all the containers in a pod. * The --format={{.Restarts}} option to the podman ps command now shows the number of times a container has been restarted based on its restart policy. * The --format={{.Restarts}} option to the podman pod ps command now shows the total number of container restarts in a pod. * The podman machine provider can now be specified via the CONTAINERS_MACHINE_PROVIDER environment variable, as well as via the provider field in containers.conf (#17116). * A default list of pasta arguments can now be set in containers.conf via pasta_options. * The podman machine init and podman machine set commands now support a new option, --user-mode-networking, which improves interops with VPN configs that drop traffic from WSL networking, on Windows. * The remote Podman client’s podman push command now supports the --digestfile option (#18216). * Podman now supports a new option, --out, that allows redirection or suppression of STDOUT (#18120).
    * Changes
    * When looking up an image by digest, the entire repository of the specified value is now considered. This aligns with Docker's behavior since v20.10.20. Previously, both the repository and the tag was ignored and Podman looked for an image with only a matching digest. Ignoring the name, repository, and tag of the specified value can lead to security issues and is considered harmful. * The podman system service command now emits a warning when binding to a TCP socket. This is not a secure configuration and the Podman team recommends against using it. * The podman top command no longer depends on ps(1) being present in the container image and now uses the one from the host (#19001). * The --filter id=xxx option will now treat xxx as a CID prefix, and not as a regular expression (#18471). * The --filter option now requires multiple --filter flags to specify multiple filters. It will no longer support the comma syntax (--filter label=a,label=b). * The slirp4netns binary for will now be searched for in paths specified by the helper_binaries_dir option in containers.conf (#18239). * Podman machine now updates /run/docker.sock within the guest to be consistent with its rootless/rootful setting (#18480). * The podman system df command now counts files which podman generates for use with specific containers as part of the disk space used by those containers, and which can be reclaimed by removing those containers. It also counts space used by files it associates with specific images and volumes as being used by those images and volumes. * The podman build command now returns a clearer error message when the Containerfile cannot be found. (#16354). * Containers created with --pid=host will no longer print errors on podman stop (#18460). * The podman manifest push command no longer requires a destination to be specified. If a destination is not provided, the source is used as the destination (#18360). * The podman system reset command now warns the user that the graphroot and runroot directories will be deleted (#18349), (#18295). * The package and package-install targets in Makefile have now been fixed and also renamed to rpm and rpm-install respectively for clarity (#18817).
    * Quadlet
    * Quadlet now exits with a non-zero exit code when errors are found (#18778). * Rootless podman quadlet files can now be installed in /etc/containers/systemd/users directory. * Quadlet now supports the AutoUpdate option. * Quadlet now supports the Mask and Unmask options. * Quadlet now supports the WorkingDir option, which specifies the default working dir in a container. * Quadlet now supports the Sysctl option, which sets namespaced kernel parameters for containers (#18727). * Quadlet now supports the SecurityLabelNetsted=true option, which allows nested SELinux containers. * Quadlet now supports the Pull option in .container files (#18779). * Quadlet now supports the ExitCode field in .kube files, which reflects the exit codes of failed containers. * Quadlet now supports PodmanArgs field. * Quadlet now supports the HostName field, which sets the container's host name, in .container files (#18486).
    * Bugfixes
    * Fixed a bug where the podman machine start command would fail with a 255 exit code. It now waits for systemd-user sessions to be up, and for SSH to be ready, addressing the flaky machine starts (#17403). * Fixed a bug where the podman auto update command did not correctly use authentication files when contacting container registries. * Fixed a bug where --label option to the podman volume ls command would return volumes that matched any of the filters, not all of them (#19219). * Fixed a bug where the podman kube play command did not recognize containerPort names inside Kubernetes liveness probes. Now, liveness probes support both containerPort names as well as port numbers (#18645). * Fixed a bug where the --dns option to the podman run command was ignored for macvlan networks (#19169). * Fixed a bug in the podman system service command where setting LISTEN_FDS when listening on TCP would misbehave. * Fixed a bug where hostnames were not recognized as a network alias. Containers can now resolve other hostnames, in addition to their names (#17370). * Fixed a bug where the podman pod run command would error after a reboot on a non-systemd system (#19175). * Fixed a bug where the --syslog option returned a fatal error when no syslog server was found (#19075). * Fixed a bug where the --mount option would parse the readonly option incorrectly (#18995). * Fixed a bug where hook executables invoked by the podman run command set an incorrect working directory. It now sets the correct working directory pointing to the container bundle directory (#18907). * Fixed a bug where the -device-cgroup-rule option was silently ignored in rootless mode ([#18698](https://github.com/containers/podman/issu...
    • Don't unconditionally Obsolete podman-cni-config, ensure clean upgrade path.

    • Prefer Podman's new network stack (netavark) exclusively on ALP
    • Remove unused podman-cni-config subpackage, add systemd

    • Update to version 4.5.1:

    * Security
    * Do not include image annotations when building spec. These annotations can have security implications - crun, for example, allows rootless containers to preserve the user's groups through an annotation.
    * Quadlet
    * Fixed a bug in quadlet to recognize the systemd optional prefix '-'.
    * Bugfixes
    * Fixed a bug where fully resolving symlink paths included the version number, breaking the path to homebrew-installed qemu files (#18111). * Fixed a bug where Podman was splitting the filter map slightly differently compared to Docker (#18092). * Fixed a bug where running make package did not work on RHEL 8 environments (#18421). * Fixed a bug to allow comma separated dns server IP addresses in podman network create --dns and podman network update --dns-add/--dns-drop (#18663). * Fixed a bug to correctly stop containers created with --restart=always in all cases (#18259). * Fixed a bug in podman-remote logs to correctly display errors reported by the server. * Fixed a bug to correctly tear down the network stack again when an error happened during the setup. * Fixed a bug in the remote API exec inspect call to correctly display updated information, e.g. when the exec process died (#18424). * Fixed a bug so that podman save on windows can now write to stdout by default (#18147). * Fixed a bug where podman machine rm with the qemu backend now correctly removes the machine connection after the confirmation message not before (#18330). * Fixed a problem where podman machine connections would try to connect to the ipv6 localhost ipv6 (::1) (#16470).
    * API
    * Fixed a bug in the compat container create endpoint which could result in a 'duplicate mount destination' error when the volume path was not 'clean', e.g. included a final slash at the end. (#18454). * The compat API now correctly accepts a tag in the images/create?fromSrc endpoint (#18597).

    • Update to version 4.5.0:

    * Features
    * The podman kube play command now supports the hostIPC field (#17157). * The podman kube play command now supports a new flag, --wait, that keeps the workload running in foreground until killed with a sigkill or sigterm. The workloads are cleaned up and removed when killed (#14522). * The podman kube generate and podman kube play commands now support SELinux filetype labels. * The podman kube play command now supports sysctl options (#16711). * The podman kube generate command now supports generating the Deployments (#17712). * The podman machine inspect command now shows information about named pipe addresses on Windows (#16860). * The --userns=keep-id option for podman create, run, and kube play now works for root containers by copying the current mapping into a new user namespace (#17337). * A new command has been added, podman secret exists, to verify if a secret with the given name exists. * The podman kube generate and podman kube play commands now support ulimit annotations (#16404). * The podman create, run, pod create, and pod clone commands now support a new option, --shm-size-systemd, that allows limiting tmpfs sizes for systemd-specific mounts (#17037). * The podman create and run commands now support a new option, --group-entry which customizes the entry that is written to the /etc/group file within the container when the --user option is used (#14965). * The podman create and podman run commands now support a new option, --security-opt label=nested, which allows SELinux labeling within a confined container. * A new command, podman machine os apply has been added, which applies OS changes to a Podman machine, from an OCI image. * The podman search command now supports two new options: --cert-dir and --creds. * Defaults for the --cgroup-config option for podman create and podman run can now be set in containers.conf. * Podman now supports auto updates for containers running inside a pod (#17181). * Podman can now use a SQLite database as a backend for increased stability. The default remains the old database, BoltDB. The database to use is selected through the database_backend field in containers.conf. * Netavark plugin support has been added. The netavark network backend now allows users to create custom network drivers. podman network create -d can be used to create a network config for your plugin and then Podman will use it like any other config and takes care of setup/teardown on container start/stop. This requires at least Netavark version 1.6. * DHCP with macvlan and the netavark backend is now supported.
    * Changes
    * Remote builds using the podman build command no longer allows .containerignore or .dockerignore files to be symlinks outside the build context. * The podman system reset command now clears build caches. * The podman play kube command now adds ctrName as an alias to the pod network (#16544). * The podman kube generate command no longer adds hostPort to the pod spec when generating service kinds. * Using a private cgroup namespace with systemd containers on a cgroups v1 system will explicitly error (this configuration has never worked) (#17727). * The SYS_CHROOT capability has been re-added to the default set of capabilities. * Listing large quantities of images with the podman images command has seen a significant performance improvement (#17828).
    * Quadlet
    * Quadlet now supports the Rootfs= option, allowing containers to be based on rootfs in addition to image. * Quadlet now supports the Secret key in the Container group. * Quadlet now supports the Logdriver key in .container and .kube units. * Quadlet now supports the Mount key in .container files (#17632). * Quadlet now supports specifying static IPv4 and IPv6 addresses in .container files via the IP= and IP6= options. * Quadlet now supports health check configuration in .container files. * Quadlet now supports relative paths in the Volume key in .container files (#17418). * Quadlet now supports setting the UID and GID options for --userns=keep-id (#17908). * Quadlet now supports adding tmpfs filesystems through the Tmpfs key in .container files (#17907). * Quadlet now supports the UserNS option in .container files, which will replace the existing RemapGid, RemapUid, RemapUidSize and RemapUsers options in a future release (#17984). * Quadlet now includes a --version option. * Quadlet now forbids specifying SELinux label types, including disabling selinux separation. * Quadlet now does not set log-driver by default. * Fixed a bug where Quadlet did not recognize paths starting with systemd specifiers as absolute (#17906).
    * Bugfixes
    * Fixed a bug in the network list API where a race condition would cause the list to fail if a container had just been removed (#17341). * Fixed a bug in the podman image scp command to correctly use identity settings. * Fixed a bug in the remote Podman client's podman build command where building from stdin would fail. podman --remote build -f - now works correctly (#17495). * Fixed a bug in the podman volume prune command where exclusive (!=) filters would fail (#17051). * Fixed a bug in the --volume option in the podman create, run, pod create, and pod clone commands where specifying relative mappings or idmapped mounts would fail (#17517). * Fixed a bug in the podman kube play command where a secret would be created, but nothing would be printed on the terminal (#17071). * Fixed a bug in the podman kube down command where secrets were not removed. * Fixed a bug where cleaning up after an exited container could segfault on non-Linux operating systems. * Fixed a bug where the podman inspect command did not properly list the network configuration of containers created with --net=none or --net=host (#17385). * Fixed a bug where containers created with user-specified SELinux labels that created anonymous or named volumes would create those volumes with incorrect labels. * Fixed a bug where the podman checkpoint restore command could panic. * Fixed a bug in the podman events command where events could be returned more than once after a log file rotation (#17665). * Fixed a bug where errors from systemd when restarting units during a podman auto-update command were not reported. * Fixed a bug where containers created with the --health-on-failure=restart option were not restarting when the health state turned unhealthy (#17777). * Fixed a bug where containers using the slirp4netns network mode with the cidr option and a custom user namespace did not set proper DNS IPs in resolv.conf. * Fixed a bug where the podman auto-update command could fail to restart systemd units (#17607). * Fixed a bug where the podman play kube command did not properly handle secret.items in volumes (#17829). * Fixed a bug where the podman generate kube command could generate pods with invalid names and hostnames (#18054). * Fixed a bug where names of limits (such as RLIMIT_NOFILE) passed to the --ulimit option to podman create and podman run were case-sensitive (#18077). * Fixed a possible corruption issue with the configuration state of podman machine during system failures on Mac, Linux, and Windows.
    * API
    * The Compat Stats endpoint for Containers now returns the Id key as lowercase id to match Docker (#17869). * Fixed a bug where the Compat top endpoint incorrectly returned titles as a string instead of a list (#17524).
    * Misc
    * The podman version command no longer joins the rootless user namespace (#17657). * The podman-events --stream option is no longer hidden and is now documented. * Updated Buildah to v1.30.0 * Updated the containers/storage library to v1.46.1 * Updated the containers/image library to v5.25.0 * Updated the containers/common library to v0.52.0
    • Don't build against EoL go versions, fixes bsc#1210299


    Advisory IDSUSE-RU-2023:4644-1
    ReleasedTue Dec 5 13:46:14 2023
    SummaryRecommended update for psmisc
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for psmisc fixes the following issues:

    • Fix version number when building the package


    Advisory IDSUSE-SU-2023:4659-1
    ReleasedWed Dec 6 13:04:57 2023
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1217573,1217574,CVE-2023-46218,CVE-2023-46219
    Description:

    This update for curl fixes the following issues:

    • CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).
    • CVE-2023-46219: HSTS long file name clears contents (bsc#1217574).


    Advisory IDSUSE-SU-2023:4660-1
    ReleasedWed Dec 6 13:06:12 2023
    SummarySecurity update for kernel-firmware
    Typesecurity
    Severityimportant
    References1215823,1215831,CVE-2021-26345,CVE-2021-46766,CVE-2021-46774,CVE-2022-23820,CVE-2022-23830,CVE-2023-20519,CVE-2023-20521,CVE-2023-20526,CVE-2023-20533,CVE-2023-20566,CVE-2023-20592
    Description:

    This update for kernel-firmware fixes the following issues:
    Update AMD ucode to 20231030 (bsc#1215831):

    • CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
    • CVE-2021-46774: Insufficient input validation in ABL may enable a privileged attacker to perform arbitrary DRAM writes, potentially resulting in code execution and privilege escalation.
    • CVE-2023-20533: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker using DMA to read/write from/to invalid DRAM address potentially resulting in denial-of-service.
    0 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
  • CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
  • CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
  • CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
  • CVE-2022-23830: SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
  • CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
  • CVE-2021-26345: Failure to validate the value in APCB may allow an attacker with physical access to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
  • CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack (bsc#1215823).

  • Advisory IDSUSE-RU-2023:4671-1
    ReleasedWed Dec 6 14:33:41 2023
    SummaryRecommended update for man
    Typerecommended
    Severitymoderate
    References
    Description:


    This update of man fixes the following problem:

    • The 'man' commands is delivered to SUSE Linux Enterprise Micro to allow browsing man pages.


    Advisory IDSUSE-feature-2023:4678-1
    ReleasedThu Dec 7 01:53:29 2023
    SummaryFeature update for lvm2
    Typefeature
    Severityimportant
    References1216938
    Description:

    This update for lvm2 fixes the following issues:
    Updated lvm2 from LVM2.2.03.16 to LVM2.2.03.22 (jsc#PED-6753,jsc#PED-6754):

    • Version 2.03.22: * Fixed issues with LVM filters no longer working with SUSE Linux Enterprise 15 Service Pack 5 (bsc#1216938) * Fixed pv_major/pv_minor report field types so they are integers, not strings. * Added `lvmdevices --delnotfound` to delete entries for missing devices. * Always use cachepool name for metadata backup LV for `lvconvert --repair`. * Make metadata backup LVs read-only after pool's `lvconvert --repair`. * Improve VDO and Thin support with lvmlockd. * Handle `lvextend --usepolicies` for pools for all activation variants. * Fixed memleak in vgchange autoactivation setup. * Update py-compile building script. * Support conversion from thick to fully provisioned thin LV. * Cache/Thin-pool can use error and zero volumes for testing. * Individual thin volume can be cached, but cannot take snapshot. * Better internal support for handling error and zero target (for testing). * Resize COW above trimmed maximal size is does not return error. * Support parsing of vdo geometry format version 4. * Added lvm.conf thin_restore and cache_restore settings. * Handle multiple mounts while resizing volume with a FS. * Handle leading/trailing spaces in sys_wwid and sys_serial used by deivce_id. * Enhance lvm_import_vdo and use snapshot when converting VDO volume. * Fixed parsing of VDO metadata. * Fixed failing `-S|--select` for non-reporting cmds if using LV info/status fields. * Allow snapshots of raid+integrity LV. * Fixed multisegment RAID1 allocator to prevent using single disk for more legs.

    • Version 2.03.21: * Fixed activation of vdo-pool for with 0 length headers (converted pools). * Avoid printing internal init messages when creation integration devices. * Allow (write)cache over raid+integrity LV.

    • Version 2.03.20: * Fixed segfault if using `-S|--select` with log/report_command_log=1 setting. * Configure now fails when requested lvmlockd dependencies are missing. * Added some configure Gentoo enhancements for static builds.

    • Version 2.03.19: * Configure supports `--with-systemd-run` executed from udev rules. * Enhancement for build with MuslC systemd and non-bash system shells (dash). * Do not reset SYSTEMD_READY variable in udev for PVs on MD and loop devices. * Ensure udev is processing origin LV before its thick snapshots LVs. * Fixed and improve runtime memory size detection for VDO volumes.

    • Version 2.03.18: * Fixed issues reported by coverity scan. * Fixed warning for thin pool overprovisioning on lvextend (2.03.17). * Added support for writecache metadata_only and pause_writeback settings. * Fixed missing error messages in lvmdbusd.

    • Version 2.03.17: * Added new options (`--fs, --fsmode`) for FS handling when resizing LVs. * Fixed `lvremove -S|--select LV` to not also remove its historical LV right away. * Fixed lv_active field type to binary so --select and --binary applies properly. * Switch to use mallinfo2 and use it only with glibc. * Error out in lvm shell if using a cmd argument not supported in the shell. * Fixed lvm shell's lastlog command to report previous pre-command failures. * Extend VDO and VDOPOOL without flushing and locking fs. * Added `--valuesonly` option to lvmconfig to print only values without keys. * Updates configure with recent autoconf tooling. * Fixed `lvconvert --test --type vdo-pool` execution. * Added json_std output format for more JSON standard compliant version of output. * Fixed vdo_slab_size_mb value for converted VDO volume. * Fixed many corner cases in device_id, including handling of S/N duplicates. * Fixed various issues in lvmdbusd.


    Advisory IDSUSE-RU-2023:4680-1
    ReleasedThu Dec 7 07:34:12 2023
    SummaryRecommended update for selinux-policy
    Typerecommended
    Severitymoderate
    References1216747
    Description:

    This update for selinux-policy fixes the following issues:

    • Trigger rebuild of the policy when pcre2 gets updated to avoid regex version mismatch errors (bsc#1216747)


    Advisory IDSUSE-RU-2023:4699-1
    ReleasedMon Dec 11 07:02:10 2023
    SummaryRecommended update for gpg2
    Typerecommended
    Severitymoderate
    References1217212
    Description:

    This update for gpg2 fixes the following issues:

    • `dirmngr-client --validate` is broken for DER-encoded files (bsc#1217212)


    Advisory IDSUSE-RU-2023:4700-1
    ReleasedMon Dec 11 07:03:27 2023
    SummaryRecommended update for p11-kit
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for p11-kit fixes the following issues:

    • Ensure that programs using can be compiled with CRYPTOKI_GNU. Fixes GnuTLS builds (jsc#PED-6705).


    Advisory IDSUSE-RU-2023:4703-1
    ReleasedMon Dec 11 07:19:53 2023
    SummaryRecommended update for dracut
    Typerecommended
    Severitymoderate
    References1192986,1217031
    Description:

    This update for dracut fixes the following issues:

    • Update to version 055+suse.375.g1167ed75
    • Fix network device naming in udev-rules (bsc#1192986)


    Advisory IDSUSE-RU-2023:4723-1
    ReleasedTue Dec 12 09:57:51 2023
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1216862
    Description:

    This update for libtirpc fixes the following issue:

    • fix sed parsing in specfile (bsc#1216862)


    Advisory IDSUSE-SU-2023:4727-1
    ReleasedTue Dec 12 12:27:39 2023
    SummarySecurity update for catatonit, containerd, runc
    Typesecurity
    Severityimportant
    References1200528,CVE-2022-1996
    Description:


    This update of runc and containerd fixes the following issues:
    containerd:

    • Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8

    * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528)
    catatonit:
    • Update to catatonit v0.2.0. * Change license to GPL-2.0-or-later.

    • Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done).

    • Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors).

    runc:
    • Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10


    Advisory IDSUSE-RU-2023:4759-1
    ReleasedWed Dec 13 10:54:58 2023
    SummaryRecommended update for open-iscsi
    Typerecommended
    Severitymoderate
    References1210514
    Description:

    This update for open-iscsi fixes the following issue:

    • Upgrade to upstream version 2.1.9 (bsc#1210514) with tag '2.1.9-suse' (bsc#1210514) * replacing open-iscsi-2.1.8-suse.tar.bz2 with open-iscsi-2.1.9-suse.tar.bz2 * several fixes to harden iscsiuio (v0.7.8.8), including: - logging now uses syslog - shutdown now waits for helper threads to complete - netlink socket cleanup * some minor bug fixes, some helping builds on musl


    Advisory IDSUSE-SU-2023:4891-1
    ReleasedMon Dec 18 16:31:49 2023
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1201384,1218014,CVE-2023-50495
    Description:

    This update for ncurses fixes the following issues:

    • CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014)
    • Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384)


    Advisory IDSUSE-RU-2023:4897-1
    ReleasedTue Dec 19 08:22:36 2023
    SummaryOptional update for openslp
    Typerecommended
    Severitylow
    References
    Description:

    This update for openslp bumps the version number to ensure a clean upgrade path from SLE-12 to SLE-15.
    This is a no-change rebuild of the packages already available in SLE-15.


    Advisory IDSUSE-SU-2023:4901-1
    ReleasedTue Dec 19 11:25:47 2023
    SummarySecurity update for avahi
    Typesecurity
    Severitymoderate
    References1216853,CVE-2023-38472
    Description:

    This update for avahi fixes the following issues:

    • CVE-2023-38472: Fixed reachable assertion in avahi_rdata_parse (bsc#1216853).


    Advisory IDSUSE-SU-2023:4902-1
    ReleasedTue Dec 19 13:09:42 2023
    SummarySecurity update for openssh
    Typesecurity
    Severityimportant
    References1214788,1217950,CVE-2023-48795
    Description:

    This update for openssh fixes the following issues:

    • CVE-2023-48795: Fixed prefix truncation breaking ssh channel integrity (bsc#1217950).

    the following non-security bug was fixed:
    • Fix the 'no route to host' error when connecting via ProxyJump


    Advisory IDSUSE-RU-2023:4937-1
    ReleasedWed Dec 20 17:54:20 2023
    SummaryRecommended update for sg3_utils
    Typerecommended
    Severitymoderate
    References1215720,1215772,1216355
    Description:

    This update for sg3_utils fixes the following issues:

    • Update to version 1.47+15.b6898b8
    • L3-Question: rescan-scsi-bus.sh resize not detected (bsc#1215720).
    • Packman Discord package upgrade lockout defeat inoperative (bsc#1216355).
    • sg3_utils package doesn't rebuild initrd (bsc#1215772).
    • rescan-scsi-bus.sh: improve cleanup on exit (gh#doug-gilbert/sg3_utils#44)


    Advisory IDSUSE-RU-2023:4962-1
    ReleasedFri Dec 22 13:45:06 2023
    SummaryRecommended update for curl
    Typerecommended
    Severityimportant
    References1216987
    Description:

    This update for curl fixes the following issues:

    • libssh: Implement SFTP packet size limit (bsc#1216987)

    This update also ships curl to the INSTALLER channel.


    Advisory IDSUSE-RU-2023:4973-1
    ReleasedTue Dec 26 04:44:10 2023
    SummaryRecommended update for duktape
    Typerecommended
    Severitymoderate
    References1216296
    Description:


    This update of duktape fixes the following issue:

    • duktape-devel is shipped to Basesystem module (bsc#1216296).


    Advisory IDSUSE-RU-2024:11-1
    ReleasedTue Jan 2 13:24:52 2024
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1029961,1158830,1206798,1209122
    Description:

    This update for procps fixes the following issues:

    • Update procps to 3.3.17 (jsc#PED-3244 jsc#PED-6369)

    • For support up to 2048 CPU as well (bsc#1185417)
    • Allow `-´ as leading character to ignore possible errors on systctl entries (bsc#1209122)
    • Get the first CPU summary correct (bsc#1121753)
    • Enable pidof for SLE-15 as this is provided by sysvinit-tools
    • Use a check on syscall __NR_pidfd_open to decide if the pwait tool and its manual page will be build
    • Do not truncate output of w with option -n
    • Prefer logind over utmp (jsc#PED-3144)
    • Don't install translated man pages for non-installed binaries (uptime, kill).
    • Fix directory for Ukrainian man pages translations.
    • Move localized man pages to lang package.

    • Update to procps-ng-3.3.17

    * library: Incremented to 8:3:0 (no removals or additions, internal changes only) * all: properly handle utf8 cmdline translations * kill: Pass int to signalled process * pgrep: Pass int to signalled process * pgrep: Check sanity of SG_ARG_MAX * pgrep: Add older than selection * pidof: Quiet mode * pidof: show worker threads * ps.1: Mention stime alias * ps: check also match on truncated 16 char comm names * ps: Add exe output option * ps: A lot more sorting available * pwait: New command waits for a process * sysctl: Match systemd directory order * sysctl: Document directory order * top: ensure config file backward compatibility * top: add command line 'e' for symmetry with 'E' * top: add '4' toggle for two abreast cpu display * top: add '!' toggle for combining multiple cpus * top: fix potential SEGV involving -p switch * vmstat: Wide mode gives wider proc columns * watch: Add environment variable for interval * watch: Add no linewrap option * watch: Support more colors * free,uptime,slabtop: complain about extra ops
    • Package translations in procps-lang.

    • Fix pgrep: cannot allocate 4611686018427387903 bytes when ulimit -s is unlimited.

    • Enable pidof by default

    • Update to procps-ng-3.3.16

    * library: Increment to 8:2:0
    No removals or functions Internal changes only, so revision is incremented. Previous version should have been 8:1:0 not 8:0:1
    * docs: Use correct symbols for -h option in free.1 * docs: ps.1 now warns about command name length * docs: install translated man pages * pgrep: Match on runstate * snice: Fix matching on pid * top: can now exploit 256-color terminals * top: preserves 'other filters' in configuration file * top: can now collapse/expand forest view children * top: parent %CPU time includes collapsed children * top: improve xterm support for vim navigation keys * top: avoid segmentation fault at program termination * 'ps -C' does not allow anymore an argument longer than 15 characters (bsc#1158830)


    Advisory IDSUSE-RU-2024:26-1
    ReleasedThu Jan 4 11:15:24 2024
    SummaryRecommended update for mozilla-nss
    Typerecommended
    Severitymoderate
    References1214980
    Description:

    This update for mozilla-nss fixes the following issues:
    Mozilla NSS was updated to NSS 3.90.1

    • regenerate NameConstraints test certificates.
    • add OSXSAVE and XCR0 tests to AVX2 detection.


    Advisory IDSUSE-RU-2024:54-1
    ReleasedMon Jan 8 07:08:14 2024
    SummaryRecommended update for NetworkManager
    Typerecommended
    Severityimportant
    References1218248
    Description:

    This recommended update for NetworkManager fixes the following issues:

    • No-change rebuild to include NetworkManager-wwan in the SLE-Module-Desktop-Applications_15-SP5 channels (bsc#1218248)


    Advisory IDSUSE-RU-2024:62-1
    ReleasedMon Jan 8 11:44:47 2024
    SummaryRecommended update for libxcrypt
    Typerecommended
    Severitymoderate
    References1215496
    Description:

    This update for libxcrypt fixes the following issues:

    • fix variable name for datamember [bsc#1215496]
    • added patches fix https://github.com/besser82/libxcrypt/commit/b212d601549a0fc84cbbcaf21b931f903787d7e2


    Advisory IDSUSE-SU-2024:70-1
    ReleasedTue Jan 9 18:29:39 2024
    SummarySecurity update for tar
    Typesecurity
    Severitylow
    References1217969,CVE-2023-39804
    Description:

    This update for tar fixes the following issues:

    • CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969).


    Advisory IDSUSE-SU-2024:136-1
    ReleasedThu Jan 18 09:53:47 2024
    SummarySecurity update for pam
    Typesecurity
    Severitymoderate
    References1217000,1218475,CVE-2024-22365
    Description:

    This update for pam fixes the following issues:

    • CVE-2024-22365: Fixed a local denial of service during PAM login due to a missing check during path manipulation (bsc#1218475).
    • Check localtime_r() return value to fix crashing (bsc#1217000)


    Advisory IDSUSE-SU-2024:140-1
    ReleasedThu Jan 18 11:34:58 2024
    SummarySecurity update for libssh
    Typesecurity
    Severityimportant
    References1211188,1211190,1218126,1218186,1218209,CVE-2023-1667,CVE-2023-2283,CVE-2023-48795,CVE-2023-6004,CVE-2023-6918
    Description:

    This update for libssh fixes the following issues:
    Security fixes:
    - CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209) - CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126) - CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186) - CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188) - CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190)
    Other fixes:

    • Update to version 0.9.8 - Allow @ in usernames when parsing from URI composes

    • Update to version 0.9.7 - Fix several memory leaks in GSSAPI handling code


    Advisory IDSUSE-RU-2024:149-1
    ReleasedThu Jan 18 14:23:58 2024
    SummaryRecommended update for selinux-policy
    Typerecommended
    Severitymoderate
    References1205931,1216060
    Description:

    This update for selinux-policy fixes the following issues:

    • Allow rebootmgr to read the system state (bsc#1205931)
    • Allow keepalived_t read+write kernel_t pipes (bsc#1216060)


    Advisory IDSUSE-RU-2024:214-1
    ReleasedWed Jan 24 16:01:31 2024
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1214668,1215241,1217460
    Description:

    This update for systemd fixes the following issues:

    • resolved: actually check authenticated flag of SOA transaction
    • core/mount: Make device deps from /proc/self/mountinfo and .mount unit file exclusive
    • core: Add trace logging to mount_add_device_dependencies()
    • core/mount: Remove default deps from /proc/self/mountinfo when it is updated (bsc#1217460)
    • core/mount: Set Mount.from_proc_self_mountinfo flag before adding default dependencies
    • core: wrap some long comment
    • utmp-wtmp: Handle EINTR gracefully when waiting to write to tty
    • utmp-wtmp: Fix error in case isatty() fails
    • homed: Handle EINTR gracefully when waiting for device node
    • resolved: Handle EINTR returned from fd_wait_for_event() better
    • sd-netlink: Handle EINTR from poll() gracefully, as success
    • varlink: Handle EINTR gracefully when waiting for EIO via ppoll()
    • stdio-bridge: Don't be bothered with EINTR
    • sd-bus: Handle EINTR return from bus_poll() (bsc#1215241)
    • core: Replace slice dependencies as they get added (bsc#1214668)


    Advisory IDSUSE-RU-2024:231-1
    ReleasedThu Jan 25 11:57:37 2024
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1217775
    Description:

    This update for suse-module-tools fixes the following issues:

    • Update to version 15.5.4
    • Add symlink /boot/.vmlinuz.hmac (bsc#1217775)


    Advisory IDSUSE-SU-2024:238-1
    ReleasedFri Jan 26 10:56:41 2024
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1218571,CVE-2023-7207
    Description:

    This update for cpio fixes the following issues:

    • CVE-2023-7207: Fixed a path traversal issue that could lead to an arbitrary file write during archive extraction (bsc#1218571).


    Advisory IDSUSE-RU-2024:244-1
    ReleasedFri Jan 26 13:01:27 2024
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1207987
    Description:

    This update for util-linux fixes the following issues:

    • Fix performance degradation (bsc#1207987)


    Advisory IDSUSE-RU-2024:255-1
    ReleasedMon Jan 29 01:52:49 2024
    SummaryRecommended update for multipath-tools
    Typerecommended
    Severitymoderate
    References1218326
    Description:

    This update for multipath-tools fixes the following issues:

    • Fixed ANA prioritizer enablement logic (bsc#1218326)