Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02289-2

Опубликовано: 16 июл. 2025
Источник: suse-cvrf

Описание

Security update for docker

This update for docker fixes the following issues:

Update to Docker 28.2.2-ce (bsc#1243833, bsc#1242114):

  • CVE-2025-0495: Fixed credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration.(bsc#1239765)
  • CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241830).

Other fixes:

  • Update to docker-buildx v0.22.0.
  • Always clear SUSEConnect suse_* secrets when starting containers (bsc#1244035).
  • Disable transparent SUSEConnect support for SLE-16. (jsc#PED-12534)
  • Now that the only blocker for docker-buildx support was removed for SLE-16, enable docker-buildx for SLE-16 as well. (jsc#PED-8905)
  • SUSEConnect secrets fails in SLES rootless docker containers (bsc#1240150).

Список пакетов

Image SLES15-SP4-BYOS
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-Hardened-BYOS
docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-Hardened-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-HPC-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-Hardened-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-Manager-Server-5-0
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-Manager-Server-5-0-EC2-llc
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-Manager-Server-5-0-EC2-ltd
docker-28.2.2_ce-150000.227.1
Image SLES15-SP5-SAPCAL-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-Azure-Basic
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-Aliyun
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-Azure
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-GCE
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-GDC
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-CHOST-BYOS-SAP-CCloud
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-EC2
docker-28.2.2_ce-150000.227.1
Image SLES15-SP6-EC2-ECS-HVM
docker-28.2.2_ce-150000.227.1
SUSE Enterprise Storage 7.1
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-fish-completion-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-fish-completion-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server 15 SP3-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-fish-completion-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server 15 SP4-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server 15 SP5-LTSS
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-fish-completion-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
docker-28.2.2_ce-150000.227.1
docker-bash-completion-28.2.2_ce-150000.227.1
docker-rootless-extras-28.2.2_ce-150000.227.1
docker-stable-24.0.9_ce-150000.1.22.1
docker-stable-bash-completion-24.0.9_ce-150000.1.22.1

Описание

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.


Затронутые продукты
Image SLES15-SP4-BYOS-EC2:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-BYOS:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS-EC2:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS:docker-28.2.2_ce-150000.227.1

Ссылки

Описание

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).


Затронутые продукты
Image SLES15-SP4-BYOS-EC2:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-BYOS:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS-EC2:docker-28.2.2_ce-150000.227.1
Image SLES15-SP4-HPC-BYOS:docker-28.2.2_ce-150000.227.1

Ссылки
Уязвимость SUSE-SU-2025:02289-2