critical
Security update for docker
SUSE-SLE-Micro-6.0-64
This update for docker fixes the following issues: Security fixes: - CVE-2024-23651: Fixed arbitrary files write due to race condition on mounts (bsc#1219267) - CVE-2024-23652: Fixed insufficient validation of parent directory on mount (bsc#1219268) - CVE-2024-23653: Fixed insufficient validation on entitlement on container creation via buildkit (bsc#1219438) - CVE-2024-41110: A Authz zero length regression that could lead to authentication bypass was fixed (bsc#1228324) Other changes: - Update to Docker 25.0.6-ce. - Fix BuildKit's symlink resolution logic to correctly handle non-lexical symlinks. (bsc#1221916) - Write volume options atomically so sudden system crashes won't result in future Docker starts failing due to empty files. (bsc#1214855) - Fixed world writable docker overlay files (bsc#1220339)
-
Release DateFeb 3 2025
-
ReferencesBugzilla: 1210141, 1214855, 1215323, 1217513, 1219267, 1219268, 1219438, 1220339, 1221916, 1223409, 1228324
CVEs: CVE-2024-23651, CVE-2024-23652, CVE-2024-23653, CVE-2024-41110 -
Typesecurity
-
Severitycritical
cloud_download Downloads
SUSE Linux Micro 6.0 s390x
-
Packages
SUSE Linux Micro 6.0 aarch64
-
Packages
SUSE Linux Micro 6.0 x86_64
-
Packages