[openSUSE-SU-2021:1525-1] Security update for singularity
Severity
Moderate
Affected Packages
8
CVEs
1
Security update for singularity
This update for singularity fixes the following issues:
Update to 3.8.5:
- CVE-2021-41190: Fixed OCI manifest and index parsing confusion (boo#1193273).
- Building Singularity from source requires go greater or equal 1.16. We now aim to support the two most recent stable versions of Go. This corresponds to the Go Release Maintenance Policy
- Sourcing a script based on PATH is now permitted, fixing a regression introduced in 3.6.0.
- Environment variables in container definition files are properly scoped, fixing a regression introduced in 3.8.0.
- Fix the oras contexts to avoid hangs upon failed pushes to Harbor registry.
Package | Affected Version |
---|---|
pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-leap-15.3 | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-15&repo=suse-package-hub | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-leap-15.3 | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-15&repo=suse-package-hub | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-leap-15.3 | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-15&repo=suse-package-hub | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-leap-15.3 | < 3.8.5-bp153.2.10.1 |
pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-15&repo=suse-package-hub | < 3.8.5-bp153.2.10.1 |
- ID
- openSUSE-SU-2021:1525-1
- Severity
- moderate
- URL
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L3AGIEOXZIUUEYYMWKJCJCQI7V235UTR/
- Published
-
2021-12-04T13:06:13
(2 years ago) - Modified
-
2021-12-04T13:06:13
(2 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALAS-2021-1551
- ALPINE:CVE-2021-41190
- ELSA-2022-7457
- FEDORA-2021-3dda301691
- FEDORA-2021-62352983b4
- FEDORA-2021-6789ed60f2
- FEDORA-2021-6dc68dbe4d
- FEDORA-2021-79ba5abef6
- FEDORA-2021-aacef7fa15
- FEDORA-2021-d250fc2622
- FEDORA-2021-eb2742b148
- openSUSE-SU-2022:0334-1
- RHSA-2022:7457
- RLSA-2022:7457
- SUSE-SU-2022:0213-1
- SUSE-SU-2022:0334-1
- SUSE-SU-2022:1507-1
- SUSE-SU-2023:0187-1
- SUSE-SU-2023:0326-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1525-1.json | |
Suse | URL for openSUSE-SU-2021:1525-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L3AGIEOXZIUUEYYMWKJCJCQI7V235UTR/ | |
Suse | E-Mail link for openSUSE-SU-2021:1525-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/L3AGIEOXZIUUEYYMWKJCJCQI7V235UTR/ | |
Bugzilla | SUSE Bug 1193273 | https://bugzilla.suse.com/1193273 | |
CVE | SUSE CVE CVE-2021-41190 page | https://www.suse.com/security/cve/CVE-2021-41190/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-leap-15.3 | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-leap-15.3 | x86_64 | |
Affected | pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-15&repo=suse-package-hub | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-15 | x86_64 | |
Affected | pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-leap-15.3 | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-leap-15.3 | s390x | |
Affected | pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-15&repo=suse-package-hub | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-15 | s390x | |
Affected | pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-leap-15.3 | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-leap-15.3 | i586 | |
Affected | pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-15&repo=suse-package-hub | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-15 | i586 | |
Affected | pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-leap-15.3 | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-leap-15.3 | aarch64 | |
Affected | pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-15&repo=suse-package-hub | opensuse | singularity | < 3.8.5-bp153.2.10.1 | opensuse-15 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |