Описание
Security update for docker
This update for docker fixes the following issues:
- CVE-2025-58181: not validating the number of mechanisms can cause unlimited memory consumption (bsc#1253904).
Список пакетов
openSUSE Leap 16.0
docker-28.5.1_ce-160000.5.1
docker-bash-completion-28.5.1_ce-160000.5.1
docker-buildx-0.29.0-160000.5.1
docker-fish-completion-28.5.1_ce-160000.5.1
docker-rootless-extras-28.5.1_ce-160000.5.1
docker-zsh-completion-28.5.1_ce-160000.5.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1253904
- SUSE CVE CVE-2025-58181 page
Описание
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Затронутые продукты
openSUSE Leap 16.0:docker-28.5.1_ce-160000.5.1
openSUSE Leap 16.0:docker-bash-completion-28.5.1_ce-160000.5.1
openSUSE Leap 16.0:docker-buildx-0.29.0-160000.5.1
openSUSE Leap 16.0:docker-fish-completion-28.5.1_ce-160000.5.1
Ссылки
- CVE-2025-58181
- SUSE Bug 1253784