shield
Security update for cosign
SUSE-SLE-Module-Basesystem-15-SP5-2024-1486
This update for cosign fixes the following issues: - CVE-2024-29902: Fixed denial of service on host machine via remote image with a malicious attachments (bsc#1222835) - CVE-2024-29903: Fixed denial of service on host machine via malicious software artifacts (bsc#1222837) Other fixes: - Updated to 2.2.4 (jsc#SLE-23879) * Fixes for GHSA-88jx-383q-w4qc and GHSA-95pr-fxf5-86gv (#3661) * ErrNoSignaturesFound should be used when there is no signature attached to an image. (#3526) * fix semgrep issues for dgryski.semgrep-go ruleset (#3541) * Honor creation timestamp for signatures again (#3549) * Features * Adds Support for Fulcio Client Credentials Flow, and Argument to Set Flow Explicitly (#3578)
-
Release DateMay 2 2024
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
Basesystem Module 15.5 aarch64
-
Packagescosign
Container Signing, Verification and Storage in an OCI registry2.2.4-150400.3.20.1 lock rpm lock src
Basesystem Module 15.5 ppc64le
-
Packagescosign
Container Signing, Verification and Storage in an OCI registry2.2.4-150400.3.20.1 lock rpm lock src
Basesystem Module 15.5 x86_64
-
Packagescosign
Container Signing, Verification and Storage in an OCI registry2.2.4-150400.3.20.1 lock rpm lock src
Basesystem Module 15.5 s390x
-
Packagescosign
Container Signing, Verification and Storage in an OCI registry2.2.4-150400.3.20.1 lock rpm lock src