SUSE-SU-2024:4204-1

Source
https://www.suse.com/support/update/announcement/2024/suse-su-20244204-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4204-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2024:4204-1
Related
Published
2024-12-05T14:57:37Z
Modified
2024-12-05T14:57:37Z
Summary
Security update for docker-stable
Details

This update for docker-stable fixes the following issues:

  • CVE-2024-41110: Fixed Authz zero length regression (bsc#1228324).

Bug fixes:

  • Allow users to disable SUSE secrets support by setting DOCKERSUSESECRETS_ENABLE=0 in /etc/sysconfig/docker (bsc#1231348).
  • Import specfile changes for docker-buildx as well as the changes to help reduce specfile differences between docker-stable and docker (bsc#1230331, bsc#1230333).
  • Fix BuildKit's symlink resolution logic to correctly handle non-lexical symlinks (bsc#1221916).
  • Write volume options atomically so sudden system crashes won't result in future Docker starts failing due to empty files (bsc#1214855).
References

Affected packages

SUSE:Linux Enterprise Module for Containers 15 SP5 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise Module for Containers 15 SP6 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise Server 15 SP3-LTSS / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise Server 15 SP4-LTSS / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 15 SP3 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 15 SP4 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

SUSE:Enterprise Storage 7.1 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/suse/docker-stable&distro=SUSE%20Enterprise%20Storage%207.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

openSUSE:Leap 15.5 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/opensuse/docker-stable&distro=openSUSE%20Leap%2015.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-fish-completion": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1",
            "docker-stable-rootless-extras": "24.0.9_ce-150000.1.5.1",
            "docker-stable-zsh-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}

openSUSE:Leap 15.6 / docker-stable

Package

Name
docker-stable
Purl
pkg:rpm/opensuse/docker-stable&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
24.0.9_ce-150000.1.5.1

Ecosystem specific

{
    "binaries": [
        {
            "docker-stable": "24.0.9_ce-150000.1.5.1",
            "docker-stable-fish-completion": "24.0.9_ce-150000.1.5.1",
            "docker-stable-bash-completion": "24.0.9_ce-150000.1.5.1",
            "docker-stable-rootless-extras": "24.0.9_ce-150000.1.5.1",
            "docker-stable-zsh-completion": "24.0.9_ce-150000.1.5.1"
        }
    ]
}