SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2420-1 Container Tags : bci/python:3 , bci/python:3-10.20 , bci/python:3.6 , bci/python:3.6-10.20 Container Release : 10.20 Severity : important Type : security References : 1186673 1209536 1213004 1213008 1213504 CVE-2023-38408 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2945-1 Released: Mon Jul 24 09:37:30 2023 Summary: Security update for openssh Type: security Severity: important References: 1186673,1209536,1213004,1213008,1213504,CVE-2023-38408 This update for openssh fixes the following issues: - CVE-2023-38408: Fixed a condition where specific libaries loaded via ssh-agent(1)'s PKCS#11 support could be abused to achieve remote code execution via a forwarded agent socket if those libraries were present on the victim's system and if the agent was forwarded to an attacker-controlled system. [bsc#1213504, CVE-2023-38408] - Close the right filedescriptor and also close fdh in read_hmac to avoid file descriptor leaks. [bsc#1209536] - Attempts to mitigate instances of secrets lingering in memory after a session exits. [bsc#1186673, bsc#1213004, bsc#1213008] The following package changes have been done: - openssh-common-8.4p1-150300.3.22.1 updated - openssh-fips-8.4p1-150300.3.22.1 updated - openssh-clients-8.4p1-150300.3.22.1 updated