Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2318-1

Опубликовано: 08 июл. 2024
Источник: suse-cvrf

Описание

Security update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container

This update for kubevirt, virt-api-container, virt-controller-container, virt-exportproxy-container, virt-exportserver-container, virt-handler-container, virt-launcher-container, virt-libguestfs-tools-container, virt-operator-container, virt-pr-helper-container fixes the following issues:

  • Collect component Role rules under operator Role instead of ClusterRole (bsc#1223965, CVE-2024-33394)
  • Ensure procps is installed (provides ps for tests)

Containers were rebuilt against current go and maintenance updates.

Список пакетов

SUSE Linux Enterprise Module for Containers 15 SP6
kubevirt-manifests-1.1.1-150600.5.3.2
kubevirt-virtctl-1.1.1-150600.5.3.2
openSUSE Leap 15.6
kubevirt-container-disk-1.1.1-150600.5.3.2
kubevirt-manifests-1.1.1-150600.5.3.2
kubevirt-pr-helper-conf-1.1.1-150600.5.3.2
kubevirt-tests-1.1.1-150600.5.3.2
kubevirt-virt-api-1.1.1-150600.5.3.2
kubevirt-virt-controller-1.1.1-150600.5.3.2
kubevirt-virt-exportproxy-1.1.1-150600.5.3.2
kubevirt-virt-exportserver-1.1.1-150600.5.3.2
kubevirt-virt-handler-1.1.1-150600.5.3.2
kubevirt-virt-launcher-1.1.1-150600.5.3.2
kubevirt-virt-operator-1.1.1-150600.5.3.2
kubevirt-virtctl-1.1.1-150600.5.3.2
obs-service-kubevirt_containers_meta-1.1.1-150600.5.3.2

Описание

An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.


Затронутые продукты
SUSE Linux Enterprise Module for Containers 15 SP6:kubevirt-manifests-1.1.1-150600.5.3.2
SUSE Linux Enterprise Module for Containers 15 SP6:kubevirt-virtctl-1.1.1-150600.5.3.2
openSUSE Leap 15.6:kubevirt-container-disk-1.1.1-150600.5.3.2
openSUSE Leap 15.6:kubevirt-manifests-1.1.1-150600.5.3.2

Ссылки