Описание
Security update for containerd, docker, runc
This update for containerd, docker, runc fixes the following issues:
containerd:
-Update to containerd v1.7.8. Upstream release notes:
https://github.com/containerd/containerd/releases/tag/v1.7.8
docker:
- Update to Docker 24.0.7-ce. See upstream changelong online at
https://docs.docker.com/engine/release-notes/24.0/#2407 (bsc#1217513)
- Deny containers access to /sys/devices/virtual/powercap by default.
- CVE-2020-8694 bsc#1170415
- CVE-2020-8695 bsc#1170446
- CVE-2020-12912 bsc#1178760
- Deny containers access to /sys/devices/virtual/powercap by default.
runc:
- Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10
Список пакетов
Image SLES12-SP5-Azure-Basic-On-Demand
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-GCE-On-Demand
SUSE Linux Enterprise Module for Containers 12
Ссылки
- Link for SUSE-SU-2023:4625-1
- E-Mail link for SUSE-SU-2023:4625-1
- SUSE Security Ratings
- SUSE Bug 1170415
- SUSE Bug 1170446
- SUSE Bug 1178760
- SUSE Bug 1217513
- SUSE CVE CVE-2020-12912 page
- SUSE CVE CVE-2020-8694 page
- SUSE CVE CVE-2020-8695 page
Описание
A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access.
Затронутые продукты
Ссылки
- CVE-2020-12912
- SUSE Bug 1178760
Описание
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Затронутые продукты
Ссылки
- CVE-2020-8694
- SUSE Bug 1170415
- SUSE Bug 1170446
- SUSE Bug 1178591
- SUSE Bug 1178700
- SUSE Bug 1179661
Описание
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Затронутые продукты
Ссылки
- CVE-2020-8695
- SUSE Bug 1170415
- SUSE Bug 1170446
- SUSE Bug 1178591