[openSUSE-SU-2021:1525-1] Security update for singularity

Severity Moderate
Affected Packages 8
CVEs 1

Security update for singularity

This update for singularity fixes the following issues:

Update to 3.8.5:

  • CVE-2021-41190: Fixed OCI manifest and index parsing confusion (boo#1193273).
  • Building Singularity from source requires go greater or equal 1.16. We now aim to support the two most recent stable versions of Go. This corresponds to the Go Release Maintenance Policy
  • Sourcing a script based on PATH is now permitted, fixing a regression introduced in 3.6.0.
  • Environment variables in container definition files are properly scoped, fixing a regression introduced in 3.8.0.
  • Fix the oras contexts to avoid hangs upon failed pushes to Harbor registry.
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-leap-15.3 opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-leap-15.3 x86_64
Affected pkg:rpm/opensuse/singularity?arch=x86_64&distro=opensuse-15&repo=suse-package-hub opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-15 x86_64
Affected pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-leap-15.3 opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-leap-15.3 s390x
Affected pkg:rpm/opensuse/singularity?arch=s390x&distro=opensuse-15&repo=suse-package-hub opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-15 s390x
Affected pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-leap-15.3 opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-leap-15.3 i586
Affected pkg:rpm/opensuse/singularity?arch=i586&distro=opensuse-15&repo=suse-package-hub opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-15 i586
Affected pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-leap-15.3 opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-leap-15.3 aarch64
Affected pkg:rpm/opensuse/singularity?arch=aarch64&distro=opensuse-15&repo=suse-package-hub opensuse singularity < 3.8.5-bp153.2.10.1 opensuse-15 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...