|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2023-50711: aws-nitro-enclaves-cli: vmm-sys-util: out of bounds memory accesses | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Thomas Leroy <thomas.leroy> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | camila.matos |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/389863/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1218499 | ||
|
Description
Thomas Leroy
2024-01-03 10:22:37 UTC
SUSE:SLE-15-SP4:Update/aws-nitro-enclaves-cli uses an affected version of the vmm-sys-util crate. Ok, Olaf, you're the bugowner of that package, as far as I can see, therefore I'm giving this to you. Let me know if you don't think you should be dealing with it and we'll figure things out... Rudi, do you remember why aws-nitro-enclaves-cli was forked intp SLE15-SP6? The SR lacks details. If possible, remove the forked pkg, and use the pkgs from the existing Update channels. this was requested by Eugenio on 2024/2/21 to enforce recompilation against openssl-3 I see. In 15.6 the pkg requires "libssl.so.3(OPENSSL_3.0.0)(64bit)", in 15.5 "libssl.so.1.1(OPENSSL_1_1_1)(64bit)". In other words, the fork is required. update submitted. SUSE-SU-2024:1966-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1218501 CVE References: CVE-2023-50711 Maintenance Incident: [SUSE:Maintenance:34162](https://smelt.suse.de/incident/34162/) Sources used: Public Cloud Module 15-SP6 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150600.10.3.1 openSUSE Leap 15.6 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150600.10.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2024:1984-1: An update that solves one vulnerability can now be installed. Category: security (moderate) Bug References: 1218501 CVE References: CVE-2023-50711 Maintenance Incident: [SUSE:Maintenance:34157](https://smelt.suse.de/incident/34157/) Sources used: openSUSE Leap 15.4 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 openSUSE Leap 15.5 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 Public Cloud Module 15-SP4 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 Public Cloud Module 15-SP5 (src): aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |