Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2246-1

Опубликовано: 29 июн. 2024
Источник: suse-cvrf

Описание

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

This update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container fixes the following issues:

  • Collect component Role rules under operator Role instead of ClusterRole (bsc#1223965, CVE-2024-33394)
  • Ensure procps is installed (provides ps for tests)

This update also rebuilds it against current go releases.

Список пакетов

SUSE Linux Enterprise Micro 5.5
kubevirt-manifests-1.1.1-150500.8.18.1
kubevirt-virtctl-1.1.1-150500.8.18.1
SUSE Linux Enterprise Module for Containers 15 SP5
kubevirt-manifests-1.1.1-150500.8.18.1
kubevirt-virtctl-1.1.1-150500.8.18.1
openSUSE Leap 15.5
kubevirt-container-disk-1.1.1-150500.8.18.1
kubevirt-manifests-1.1.1-150500.8.18.1
kubevirt-tests-1.1.1-150500.8.18.1
kubevirt-virt-api-1.1.1-150500.8.18.1
kubevirt-virt-controller-1.1.1-150500.8.18.1
kubevirt-virt-exportproxy-1.1.1-150500.8.18.1
kubevirt-virt-exportserver-1.1.1-150500.8.18.1
kubevirt-virt-handler-1.1.1-150500.8.18.1
kubevirt-virt-launcher-1.1.1-150500.8.18.1
kubevirt-virt-operator-1.1.1-150500.8.18.1
kubevirt-virtctl-1.1.1-150500.8.18.1
obs-service-kubevirt_containers_meta-1.1.1-150500.8.18.1

Описание

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.


Затронутые продукты
SUSE Linux Enterprise Micro 5.5:kubevirt-manifests-1.1.1-150500.8.18.1
SUSE Linux Enterprise Micro 5.5:kubevirt-virtctl-1.1.1-150500.8.18.1
SUSE Linux Enterprise Module for Containers 15 SP5:kubevirt-manifests-1.1.1-150500.8.18.1
SUSE Linux Enterprise Module for Containers 15 SP5:kubevirt-virtctl-1.1.1-150500.8.18.1

Ссылки