Security update for docker, docker-stable
This update for docker, docker-stable fixes the following issues: - CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). - CVE-2024-29018: Fixed external DNS requests from 'internal' networks leading to data exfiltration (bsc#1234089). - CVE-2024-23650: Fixed BuildKit daemon crash via malicious BuildKit client or frontend request (bsc#1219437). Other fixes: - Make container-selinux requirement conditional on selinux-policy (bsc#1237367). - Updated docker-buildx to 0.19.3.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for docker, docker-stable fixes the following issues: - CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). - CVE-2024-29018: Fixed external DNS requests from 'internal' networks leading to data exfiltration (bsc#1234089). - CVE-2024-23650: Fixed BuildKit daemon crash via malicious BuildKit client or frontend request (bsc#1219437). Other fixes: - Make container-selinux requirement conditional on selinux-policy (bsc#1237367). - Updated docker-buildx to 0.19.3.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1219437
- https://bugzilla.suse.com/1234089
- https://bugzilla.suse.com/1237367
- https://bugzilla.suse.com/1239185
- https://bugzilla.suse.com/1239322
- https://www.suse.com/security/cve/CVE-2024-23650
- https://www.suse.com/security/cve/CVE-2024-23653
- https://www.suse.com/security/cve/CVE-2024-29018
- https://www.suse.com/security/cve/CVE-2024-41110
- https://www.suse.com/security/cve/CVE-2025-22868
- https://www.suse.com/security/cve/CVE-2025-22869
- https://www.suse.com/support/update/announcement/2025/suse-su-20251102-1/