critical Security update for docker
SUSE-SLE-Micro-5.3-2024-2801


RETRACTED: This update for docker fixes the following issues: - CVE-2024-23651: Fixed arbitrary files write due to race condition on mounts (bsc#1219267) - CVE-2024-23652: Fixed insufficient validation of parent directory on mount (bsc#1219268) - CVE-2024-23653: Fixed insufficient validation on entitlement on container creation via buildkit (bsc#1219438) - CVE-2024-41110: A Authz zero length regression that could lead to authentication bypass was fixed (bsc#1228324) Other fixes: - Update to Docker 25.0.6-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/25.0/#2506> - Update to Docker 25.0.5-ce (bsc#1223409) - Fix BuildKit's symlink resolution logic to correctly handle non-lexical symlinks. (bsc#1221916) - Write volume options atomically so sudden system crashes won't result in future Docker starts failing due to empty files. (bsc#1214855)


cloud_download Downloads

SUSE Linux Enterprise Micro 5.3 aarch64
  • Packages
    docker
    The Moby-project Linux container runtime
    25.0.6_ce-150000.203.1 lock rpm lock src
SUSE Linux Enterprise Micro 5.3 s390x
  • Packages
    docker
    The Moby-project Linux container runtime
    25.0.6_ce-150000.203.1 lock rpm lock src
SUSE Linux Enterprise Micro 5.3 x86_64
  • Packages
    docker
    The Moby-project Linux container runtime
    25.0.6_ce-150000.203.1 lock rpm lock src