Описание
Security update for docker
This update for docker fixes the following issues:
- CVE-2025-58181: Fixed a bug in crypto/ssh where invalidated number of mechanisms can cause unbounded memory consumption. (bsc#1253904)
Список пакетов
Image SLES15-SP7-GCE-3P
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
Image SLES15-SP7-SAP-GCE-3P
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.2
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.3
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.4
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Micro 5.5
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Module for Basesystem 15 SP7
docker-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
SUSE Linux Enterprise Module for Containers 15 SP7
docker-bash-completion-28.5.1_ce-150000.241.2
docker-rootless-extras-28.5.1_ce-150000.241.2
docker-zsh-completion-28.5.1_ce-150000.241.2
openSUSE Leap 15.6
docker-28.5.1_ce-150000.241.2
docker-bash-completion-28.5.1_ce-150000.241.2
docker-buildx-0.29.0-150000.241.2
docker-fish-completion-28.5.1_ce-150000.241.2
docker-rootless-extras-28.5.1_ce-150000.241.2
docker-zsh-completion-28.5.1_ce-150000.241.2
Ссылки
- Link for SUSE-SU-2026:0666-1
- E-Mail link for SUSE-SU-2026:0666-1
- SUSE Security Ratings
- SUSE Bug 1253904
- SUSE CVE CVE-2025-58181 page
Описание
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Затронутые продукты
Image SLES15-SP7-GCE-3P:docker-28.5.1_ce-150000.241.2
Image SLES15-SP7-GCE-3P:docker-buildx-0.29.0-150000.241.2
Image SLES15-SP7-SAP-GCE-3P:docker-28.5.1_ce-150000.241.2
Image SLES15-SP7-SAP-GCE-3P:docker-buildx-0.29.0-150000.241.2
Ссылки
- CVE-2025-58181
- SUSE Bug 1253784