FlawAtlas
Search the atlas
SUSE-SU-2025:1102-1 Not scored

Security update for docker, docker-stable

This update for docker, docker-stable fixes the following issues: - CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). - CVE-2024-29018: Fixed external DNS requests from 'internal' networks leading to data exfiltration (bsc#1234089). - CVE-2024-23650: Fixed BuildKit daemon crash via malicious BuildKit client or frontend request (bsc#1219437). Other fixes: - Make container-selinux requirement conditional on selinux-policy (bsc#1237367). - Updated docker-buildx to 0.19.3.

Exploit probability Not scored
Published April 2, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS docker
SUSE:Linux Enterprise Server 12 SP5-LTSS docker-stable
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 docker
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 docker-stable

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:1102-1

This update for docker, docker-stable fixes the following issues: - CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). - CVE-2024-29018: Fixed external DNS requests from 'internal' networks leading to data exfiltration (bsc#1234089). - CVE-2024-23650: Fixed BuildKit daemon crash via malicious BuildKit client or frontend request (bsc#1219437). Other fixes: - Make container-selinux requirement conditional on selinux-policy (bsc#1237367). - Updated docker-buildx to 0.19.3.

View original source

05 / REFERENCES

Further evidence