FlawAtlas
Search the atlas
SUSE-SU-2023:4936-1 Not scored

Security update for docker, rootlesskit

This update for docker, rootlesskit fixes the following issues: docker: - Update to Docker 24.0.7-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2407>. bsc#1217513 * Deny containers access to /sys/devices/virtual/powercap by default. - CVE-2020-8694 bsc#1170415 - CVE-2020-8695 bsc#1170446 - CVE-2020-12912 bsc#1178760 - Update to Docker 24.0.6-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2406 . bsc#1215323 - Add a docker.socket unit file, but with socket activation effectively disabled to ensure that Docker will always run even if you start the socket individually. Users should probably just ignore this unit file. bsc#1210141 - Update to Docker 24.0.5-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2405 . bsc#1213229 This update ships docker-rootless support in the docker-rootless-extra package. (jsc#PED-6180) rootlesskit: - new package, for docker rootless support. (jsc#PED-6180)

Exploit probability Not scored
Published December 20, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 docker
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS docker
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS docker
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS docker
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS docker
SUSE:Linux Enterprise Micro 5.1 docker
SUSE:Linux Enterprise Micro 5.2 docker
SUSE:Linux Enterprise Micro 5.3 docker
SUSE:Linux Enterprise Micro 5.4 docker
SUSE:Linux Enterprise Micro 5.5 docker
SUSE:Linux Enterprise Module for Containers 15 SP4 docker
SUSE:Linux Enterprise Module for Containers 15 SP4 rootlesskit
SUSE:Linux Enterprise Module for Containers 15 SP5 docker
SUSE:Linux Enterprise Module for Containers 15 SP5 rootlesskit
SUSE:Linux Enterprise Server 15 SP1-LTSS docker
SUSE:Linux Enterprise Server 15 SP2-LTSS docker
SUSE:Linux Enterprise Server 15 SP3-LTSS docker
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 docker
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 docker
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 docker
openSUSE:Leap 15.4 docker
openSUSE:Leap 15.4 rootlesskit
openSUSE:Leap 15.5 docker
openSUSE:Leap 15.5 rootlesskit
openSUSE:Leap Micro 5.3 docker
openSUSE:Leap Micro 5.4 docker

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:4936-1

This update for docker, rootlesskit fixes the following issues: docker: - Update to Docker 24.0.7-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2407>. bsc#1217513 * Deny containers access to /sys/devices/virtual/powercap by default. - CVE-2020-8694 bsc#1170415 - CVE-2020-8695 bsc#1170446 - CVE-2020-12912 bsc#1178760 - Update to Docker 24.0.6-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2406 . bsc#1215323 - Add a docker.socket unit file, but with socket activation effectively disabled to ensure that Docker will always run even if you start the socket individually. Users should probably just ignore this unit file. bsc#1210141 - Update to Docker 24.0.5-ce. See upstream changelong online at https://docs.docker.com/engine/release-notes/24.0/#2405 . bsc#1213229 This update ships docker-rootless support in the docker-rootless-extra package. (jsc#PED-6180) rootlesskit: - new package, for docker rootless support. (jsc#PED-6180)

View original source

05 / REFERENCES

Further evidence