{"schema_version":"1.7.3","id":"SUSE-SU-2023:2292-1","published":"2023-05-25T07:21:44Z","modified":"2025-05-02T04:31:15.424968Z","related":["CVE-2021-25749","CVE-2022-3162","CVE-2022-3294"],"upstream":["CVE-2021-25749","CVE-2022-3162","CVE-2022-3294"],"summary":"Security update for kubernetes1.23","details":"This update for kubernetes1.23 fixes the following issues:\n\n- add kubernetes1.18-client-common as conflicts with kubernetes-client-bash-completion \n\n- Split individual completions into separate packages\n\nUpdate to version 1.23.17:\n\n  * releng: Update images, dependencies and version to Go 1.19.6\n  * Update golang.org/x/net to v0.7.0\n  * Pin golang.org/x/net to v0.4.0\n  * add scale test for probes\n  * use custom dialer for http probes\n  * use custom dialer for tcp probes\n  * add custom dialer optimized for probes\n  * egress_selector: prevent goroutines leak on connect() step.\n  * tls.Dial() validates hostname, no need to do that manually\n  * Fix issue that Audit Server could not correctly encode DeleteOption\n  * Do not include scheduler name in the preemption event message\n  * Do not leak cross namespace pod metadata in preemption events\n  * pkg/controller/job: re-honor exponential backoff\n  * releng: Update images, dependencies and version to Go 1.19.5\n  * Bump Konnectivity to v0.0.35\n  * Improve vendor verification works for each staging repo\n  * Update to go1.19\n  * Adjust for os/exec changes in 1.19\n  * Update golangci-lint to 1.46.2 and fix errors\n  * Match go1.17 defaults for SHA-1 and GC\n  * update golangci-lint to 1.45.0\n  * kubelet: make the image pull time more accurate in event\n  * change k8s.gcr.io/pause to registry.k8s.io/pause\n  * use etcd 3.5.6-0 after promotion\n  * changelog: CVE-2022-3294 and CVE-2022-3162 were fixed in v1.23.14\n  * Add CVE-2021-25749 to CHANGELOG-1.23.md\n  * Add CVE-2022-3294 to CHANGELOG-1.23.md\n  * kubeadm: use registry.k8s.io instead of k8s.gcr.io\n  * etcd: Updated to v3.5.5\n  * Bump konnectivity network proxy to v0.0.33. Includes a couple bug fixes for better handling of dial failures. [Agent & Server](https://github.com/kubernetes-sigs/apiserver-network-proxy/commits/v0.0.33) include numerous other fixes.\n  * kubeadm: allow RSA and ECDSA format keys in preflight check\n  * Fixes kubelet log compression on Windows\n  * Reduce default gzip compression level from 4 to 1 in apiserver\n  * exec auth: support TLS config caching\n  * Marshal MicroTime to json and proto at the same precision\n  * Windows: ensure runAsNonRoot does case-insensitive comparison on user name\n  * update structured-merge-diff to 4.2.3\n  * Add rate limiting when calling STS assume role API\n  * Fixing issue in generatePodSandboxWindowsConfig for hostProcess containers by where pod sandbox won't have HostProcess bit set if pod does not have a security context but containers specify HostProcess.\n","affected":[{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Linux Enterprise Module for Containers 15 SP4","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}},{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}},{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}},{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Linux Enterprise Server 15 SP3-LTSS","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}},{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP3","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}},{"package":{"name":"kubernetes1.23","ecosystem":"SUSE:Enterprise Storage 7.1","purl":"pkg:rpm/suse/kubernetes1.23&distro=SUSE%20Enterprise%20Storage%207.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.17-150300.7.6.1"}]}],"ecosystem_specific":{"binaries":[{"kubernetes1.23-client":"1.23.17-150300.7.6.1","kubernetes1.23-client-common":"1.23.17-150300.7.6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2292-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232292-1/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-25749"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3162"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3294"}]}