Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0666-1

Опубликовано: 26 фев. 2026
Источник: suse-cvrf

Описание

Security update for docker

This update for docker fixes the following issues:

  • CVE-2025-58181: Fixed a bug in crypto/ssh where invalidated number of mechanisms can cause unbounded memory consumption. (bsc#1253904)

Список пакетов

Image SLES15-SP7-GCE-3P
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
Image SLES15-SP7-SAP-GCE-3P
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.2
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.3
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.4
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.5
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Module for Basesystem 15 SP7
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Module for Containers 15 SP7
docker-bash-completion-28.5.1_ce-150000.241.2
docker-rootless-extras-28.5.1_ce-150000.241.2
docker-zsh-completion-28.5.1_ce-150000.241.2
openSUSE Leap 15.6
docker-28.5.1_ce-150000.241.2
docker-bash-completion-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
docker-fish-completion-28.5.1_ce-150000.241.2
docker-rootless-extras-28.5.1_ce-150000.241.2
docker-zsh-completion-28.5.1_ce-150000.241.2

Описание

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.


Затронутые продукты
Image SLES15-SP7-GCE-3P:docker-28.5.1_ce-150000.241.2
Image SLES15-SP7-GCE-3P:docker-buildx-0.29.0-150000.241.2
Image SLES15-SP7-SAP-GCE-3P:docker-28.5.1_ce-150000.241.2
Image SLES15-SP7-SAP-GCE-3P:docker-buildx-0.29.0-150000.241.2

Ссылки
Уязвимость SUSE-SU-2026:0666-1