SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:1017-1 Container Tags : bci/python:3 , bci/python:3-18.28 , bci/python:3.6 , bci/python:3.6-18.28 Container Release : 18.28 Severity : important Type : security References : 1214691 1217445 1217589 1218866 1219666 CVE-2022-48566 CVE-2023-6597 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:870-1 Released: Wed Mar 13 13:05:14 2024 Summary: Security update for glibc Type: security Severity: moderate References: 1217445,1217589,1218866 This update for glibc fixes the following issues: Security issues fixed: - qsort: harden handling of degenerated / non transient compare function (bsc#1218866) Other issues fixed: - getaddrinfo: translate ENOMEM to EAI_MEMORY (bsc#1217589, BZ #31163) - aarch64: correct CFI in rawmemchr (bsc#1217445, BZ #31113) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:901-1 Released: Thu Mar 14 17:49:10 2024 Summary: Security update for python3 Type: security Severity: important References: 1214691,1219666,CVE-2022-48566,CVE-2023-6597 This update for python3 fixes the following issues: - CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666). - CVE-2022-48566: Make compare_digest more constant-time (bsc#1214691). The following package changes have been done: - glibc-2.31-150300.68.1 updated - libpython3_6m1_0-3.6.15-150300.10.57.1 updated - python3-base-3.6.15-150300.10.57.1 updated - python3-3.6.15-150300.10.57.1 updated - python3-devel-3.6.15-150300.10.57.1 updated - container:sles15-image-15.0.0-36.11.13 updated