{"schema_version":"1.7.3","id":"SUSE-SU-2022:4635-1","published":"2022-12-29T11:31:23Z","modified":"2026-02-04T03:24:03.505666Z","related":["CVE-2022-1708"],"upstream":["CVE-2022-1708"],"summary":"Security update for conmon","details":"This update for conmon fixes the following issues:\n\nconmon was updated to version 2.1.5:\n\n* don't leak syslog_identifier\n* logging: do not read more that the buf size\n* logging: fix error handling\n* Makefile: Fix install for FreeBSD\n* signal: Track changes to get_signal_descriptor in the FreeBSD version\n* Packit: initial enablement\n\nUpdate to version 2.1.4:\n\n* Fix a bug where conmon crashed when it got a SIGCHLD\n\nupdate to 2.1.3:\n\n* Stop using g_unix_signal_add() to avoid threads\n* Rename CLI optionlog-size-global-max to log-global-size-max \n\nUpdate to version 2.1.2:\n\n* add log-global-size-max option to limit the total output conmon processes (CVE-2022-1708 bsc#1200285)\n* journald: print tag and name if both are specified\n* drop some logs to debug level\n\nUpdate to version 2.1.0\n\n* logging: buffer partial messages to journald\n* exit: close all fds >= 3\n* fix: cgroup: Free memory_cgroup_file_path if open fails.\n\nUpdate to version 2.0.32\n\n* Fix: Avoid mainfd_std{in,out} sharing the same file descriptor.\n* exit_command: Fix: unset subreaper attribute before running exit command\n\nUpdate to version 2.0.31\n* logging: new mode -l passthrough\n* ctr_logs: use container name or ID as SYSLOG_IDENTIFIER for journald\n* conmon: Fix: free userdata files before exec cleanup\n","affected":[{"package":{"name":"conmon","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.5-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"conmon":"2.1.5-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4635-1.json"}},{"package":{"name":"conmon","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP4","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.5-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"conmon":"2.1.5-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4635-1.json"}},{"package":{"name":"conmon","ecosystem":"openSUSE:Leap Micro 5.3","purl":"pkg:rpm/opensuse/conmon&distro=openSUSE%20Leap%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.5-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"conmon":"2.1.5-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4635-1.json"}},{"package":{"name":"conmon","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/conmon&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.5-150400.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"conmon":"2.1.5-150400.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:4635-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20224635-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1708"}]}