FlawAtlas
Search the atlas
SUSE-SU-2023:4727-1 Not scored

Security update for catatonit, containerd, runc

This update of runc and containerd fixes the following issues: containerd: - Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8 * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528) catatonit: - Update to catatonit v0.2.0. * Change license to GPL-2.0-or-later. - Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done). - Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors). runc: - Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10

Exploit probability Not scored
Published December 12, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP2-LTSS runc
openSUSE:Leap 15.4 containerd
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 runc
openSUSE:Leap 15.4 runc
SUSE:Linux Enterprise Micro 5.3 runc
SUSE:Linux Enterprise Server 15 SP1-LTSS containerd
openSUSE:Leap Micro 5.3 containerd
SUSE:Linux Enterprise Micro 5.4 containerd
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 containerd
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS runc
openSUSE:Leap Micro 5.4 runc
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 catatonit
SUSE:Linux Enterprise Module for Containers 15 SP4 containerd
SUSE:Linux Enterprise Micro 5.1 runc
SUSE:Linux Enterprise Server 15 SP1-LTSS runc
SUSE:Linux Enterprise Server 15 SP2-LTSS containerd
SUSE:Linux Enterprise Module for Containers 15 SP5 runc
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS runc
SUSE:Linux Enterprise Module for Containers 15 SP4 runc
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS containerd
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS catatonit
SUSE:Linux Enterprise Server 15 SP2-LTSS catatonit
SUSE:Linux Enterprise Server 15 SP3-LTSS containerd
SUSE:Enterprise Storage 7.1 runc
SUSE:Linux Enterprise Micro 5.2 containerd
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS containerd
openSUSE:Leap 15.5 runc
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS runc
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 containerd
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS containerd
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 runc
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS runc
SUSE:Linux Enterprise Server 15 SP1-LTSS catatonit
SUSE:Linux Enterprise Micro 5.5 containerd
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS catatonit
openSUSE:Leap Micro 5.3 runc
SUSE:Linux Enterprise Micro 5.2 runc
SUSE:Enterprise Storage 7.1 containerd
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 containerd
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 catatonit
SUSE:Linux Enterprise Module for Containers 15 SP5 containerd
SUSE:Linux Enterprise Micro 5.5 runc
openSUSE:Leap 15.5 containerd
SUSE:Linux Enterprise Micro 5.3 containerd
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS containerd
SUSE:Linux Enterprise Micro 5.1 containerd
SUSE:Linux Enterprise Micro 5.4 runc
SUSE:Linux Enterprise Server 15 SP3-LTSS runc
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 runc
openSUSE:Leap Micro 5.4 containerd

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:4727-1

This update of runc and containerd fixes the following issues: containerd: - Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8 * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528) catatonit: - Update to catatonit v0.2.0. * Change license to GPL-2.0-or-later. - Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done). - Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors). runc: - Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10

View original source

05 / REFERENCES

Further evidence