Security update for docker
This update for docker fixes the following issues: Update to docker-buildx v0.22.0: - CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239765). - CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). Bug fixes: - Fix unconditional container-selinux pull (bsc#1237367).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for docker fixes the following issues: Update to docker-buildx v0.22.0: - CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239765). - CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185). - CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322). Bug fixes: - Fix unconditional container-selinux pull (bsc#1237367).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1237367
- https://bugzilla.suse.com/1239185
- https://bugzilla.suse.com/1239322
- https://bugzilla.suse.com/1239765
- https://www.suse.com/security/cve/CVE-2025-0495
- https://www.suse.com/security/cve/CVE-2025-22868
- https://www.suse.com/security/cve/CVE-2025-22869
- https://www.suse.com/support/update/announcement/2025/suse-su-202520360-1/