critical
Security update for apptainer
SUSE-SLE-Module-HPC-15-SP6-2025-980
This update for apptainer fixes the following issues: - CVE-2025-27144: Fixed Denial of Service in Go JOSE's Parsing (bsc#1237679). - CVE-2024-45338: Fixed denial of service due to non-linear parsing of case-insensitive content (bsc#1234794). - CVE-2024-45337: Fixed Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234595). - CVE-2025-22870: Fixed proxy bypass using IPv6 zone IDs (bsc#1238611). - CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239341). - CVE-2024-41110: Fixed Authz zero length regression (bsc#1228324).
-
Release DateMar 21 2025
-
ReferencesBugzilla: 1237679, 1234794, 1234595, 1238611, 1239341, 1228324
CVEs: CVE-2025-22870, CVE-2024-45338, CVE-2024-41110, CVE-2024-45337, CVE-2025-27144, CVE-2025-22869 -
Typesecurity
-
Severitycritical
cloud_download Downloads
HPC Module 15.6 aarch64
-
Packagesapptainer
Application and environment virtualizationapptainer-sle15_61.3.6-150600.4.9.1 lock rpm lock src
Apptainer Definition File Templates for SLE 15 SP61.3.6-150600.4.9.1 lock rpm
HPC Module 15.6 x86_64
-
Packagesapptainer
Application and environment virtualizationapptainer-sle15_61.3.6-150600.4.9.1 lock rpm lock src
Apptainer Definition File Templates for SLE 15 SP61.3.6-150600.4.9.1 lock rpm