openSUSE-SU-2024:0194-2
Dashboard / Vulnerabilities / openSUSE-SU-2024:0194-2
openSUSE-SU-2024:0194-2
Summary: Security update for keybase-client
Details: This update for keybase-client fixes the following issues: Update to version 6.2.8 * Update client CA * Fix incomplete locking in config file handling. - Update the Image dependency to address CVE-2023-29408 / boo#1213928. This is done via the new update-image-tiff.patch. - Limit parallel test execution as that seems to cause failing builds on OBS that don't occur locally. - Integrate KBFS packages previously build via own source package * Upstream integrated these into the same source. * Also includes adding kbfs-related patches ensure-mount-dir-exists.patch and ensure-service-stop-unmounts-filesystem.patch. - Upgrade Go version used for compilation to 1.19. - Use Systemd unit file from upstream source.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/PKFUM343ZIFFU5562L2AAJWE2OVIJBOH/, https://bugzilla.suse.com/1213928, https://www.suse.com/security/cve/CVE-2023-29408
Affected packages
Package
Name: keybase-client
Purl: pkg:rpm/suse/keybase-client&distro=SUSE%20Package%20Hub%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
