openSUSE-SU-2021:1525-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1525-1
openSUSE-SU-2021:1525-1
Summary: Security update for singularity
Details: This update for singularity fixes the following issues: Update to 3.8.5: - CVE-2021-41190: Fixed OCI manifest and index parsing confusion (boo#1193273). - Building Singularity from source requires go greater or equal 1.16. We now aim to support the two most recent stable versions of Go. This corresponds to the Go Release Maintenance Policy - Sourcing a script based on PATH is now permitted, fixing a regression introduced in 3.6.0. - Environment variables in container definition files are properly scoped, fixing a regression introduced in 3.8.0. - Fix the oras contexts to avoid hangs upon failed pushes to Harbor registry.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/L3AGIEOXZIUUEYYMWKJCJCQI7V235UTR/, https://bugzilla.suse.com/1193273, https://www.suse.com/security/cve/CVE-2021-41190
Affected packages
Package
Name: singularity
Purl: pkg:rpm/suse/singularity&distro=SUSE%20Package%20Hub%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
