{"schema_version":"1.7.3","id":"SUSE-SU-2023:4625-1","published":"2023-12-01T08:26:08Z","modified":"2025-05-02T04:30:27.774982Z","related":["CVE-2020-12912","CVE-2020-8694","CVE-2020-8695"],"upstream":["CVE-2020-12912","CVE-2020-8694","CVE-2020-8695"],"summary":"Security update for containerd, docker, runc","details":"This update for containerd, docker, runc fixes the following issues:\n\ncontainerd:\n\n-Update to containerd v1.7.8. Upstream release notes:\n\n  https://github.com/containerd/containerd/releases/tag/v1.7.8\n\ndocker:\n\n- Update to Docker 24.0.7-ce. See upstream changelong online at\n  https://docs.docker.com/engine/release-notes/24.0/#2407 (bsc#1217513)\n  * Deny containers access to /sys/devices/virtual/powercap by default.\n    - CVE-2020-8694 bsc#1170415\n    - CVE-2020-8695 bsc#1170446\n    - CVE-2020-12912 bsc#1178760\n\nrunc:\n\n- Update to runc v1.1.10. Upstream changelog is available from\n  https://github.com/opencontainers/runc/releases/tag/v1.1.10\n","affected":[{"package":{"name":"containerd","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.8-16.88.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.7.8-16.88.1","docker":"24.0.7_ce-98.103.1","runc":"1.1.10-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4625-1.json"}},{"package":{"name":"docker","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.0.7_ce-98.103.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.7.8-16.88.1","docker":"24.0.7_ce-98.103.1","runc":"1.1.10-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4625-1.json"}},{"package":{"name":"runc","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.10-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.7.8-16.88.1","docker":"24.0.7_ce-98.103.1","runc":"1.1.10-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4625-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234625-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170415"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170446"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178760"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217513"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12912"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8695"}]}