Bug 1172377 (CVE-2020-13401) - VUL-0: CVE-2020-13401: docker: [trackerbug] Docker 19.03.11 update
Summary: VUL-0: CVE-2020-13401: docker: [trackerbug] Docker 19.03.11 update
Status: RESOLVED FIXED
Alias: CVE-2020-13401
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv3.1:SUSE:CVE-2020-13401:6.0:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-02 08:41 UTC by Aleksa Sarai
Modified: 2025-10-13 08:36 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksa Sarai 2020-06-02 08:41:36 UTC
- Update to Docker 19.03.11-ce. See upstream changelog in the packaged
  /usr/share/doc/packages/docker/CHANGELOG.md. CVE-2020-13401
Comment 1 OBSbugzilla Bot 2020-06-03 12:10:06 UTC
This is an autogenerated message for OBS integration:
This bug (1172377) was mentioned in
https://build.opensuse.org/request/show/811117 Factory / containerd
https://build.opensuse.org/request/show/811118 Factory / docker
https://build.opensuse.org/request/show/811119 Factory / docker-runc
https://build.opensuse.org/request/show/811120 Factory / golang-github-docker-libnetwork
Comment 3 Swamp Workflow Management 2020-06-18 13:14:47 UTC
SUSE-SU-2020:1664-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172377
CVE References: CVE-2020-13401
Sources used:
SUSE Linux Enterprise Module for Containers 12 (src):    containerd-1.2.13-16.29.1, docker-19.03.11_ce-98.54.1, docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-1.46.1, golang-github-docker-libnetwork-0.7.0.1+gitr2902_153d0769a118-31.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 4 Swamp Workflow Management 2020-06-18 13:37:14 UTC
SUSE-SU-2020:1657-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172377
CVE References: CVE-2020-13401
Sources used:
SUSE Linux Enterprise Module for Containers 15-SP1 (src):    containerd-1.2.13-5.22.2, docker-19.03.11_ce-6.34.2, docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.38.2, golang-github-docker-libnetwork-0.7.0.1+gitr2902_153d0769a118-4.21.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2020-06-22 22:12:39 UTC
openSUSE-SU-2020:0846-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172377
CVE References: CVE-2020-13401
Sources used:
openSUSE Leap 15.1 (src):    containerd-1.2.13-lp151.2.12.1, docker-19.03.11_ce-lp151.2.18.1, docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-lp151.3.21.1, golang-github-docker-libnetwork-0.7.0.1+gitr2902_153d0769a118-lp151.2.12.1
Comment 6 Swamp Workflow Management 2020-07-15 16:32:39 UTC
SUSE-SU-2020:1657-2: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1172377
CVE References: CVE-2020-13401
Sources used:
SUSE Linux Enterprise Module for Containers 15-SP2 (src):    containerd-1.2.13-5.22.2, docker-19.03.11_ce-6.34.2, docker-runc-1.0.0rc10+gitr3981_dc9208a3303f-6.38.2, golang-github-docker-libnetwork-0.7.0.1+gitr2902_153d0769a118-4.21.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Dirk Mueller 2020-08-10 20:05:21 UTC
Looks all fixed?
Comment 8 Aleksa Sarai 2020-08-11 08:46:53 UTC
(In reply to Dirk Mueller from comment #7)
> Looks all fixed?

Yeah this package has been updated everywhere as far as I know.
Comment 9 Marcus Meissner 2020-12-09 09:32:19 UTC
released
Comment 11 Maintenance Automation 2025-10-10 20:31:18 UTC
SUSE-SU-2025:03540-1: An update that solves 53 vulnerabilities, contains one feature and has 137 security fixes can now be installed.

URL: https://www.suse.com/support/update/announcement/2025/suse-su-202503540-1
Category: security (important)
Bug References: 1001161, 1004490, 1007249, 1009961, 1012568, 1015661, 1016307, 1016992, 1019251, 1020806, 1021227, 1026827, 1028638, 1028639, 1029320, 1029630, 1030702, 1032287, 1032644, 1034053, 1034063, 1037436, 1037607, 1038476, 1038493, 1045628, 1046024, 1047218, 1048046, 1051429, 1055676, 1057743, 1058173, 1059011, 1064781, 1065609, 1066210, 1066801, 1069468, 1069758, 1072798, 1073877, 1074971, 1080978, 1084533, 1085117, 1085380, 1086185, 1089732, 1095817, 1096726, 1099277, 1100331, 1100727, 1102522, 1104821, 1105000, 1108038, 1112980, 1113313, 1114832, 1115464, 1118897, 1118898, 1118899, 1118990, 1119634, 1121412, 1121768, 1122469, 1124308, 1128376, 1128746, 1134068, 1138920, 1139649, 1142160, 1142413, 1143349, 1150397, 1153367, 1157330, 1158590, 1170415, 1170446, 1172377, 1174075, 1175081, 1176708, 1178760, 1178801, 1180243, 1180401, 1181594, 1181641, 1181677, 1181730, 1181732, 1182168, 1182476, 1182947, 1183855, 1184768, 1188447, 1190670, 1191015, 1191121, 1191334, 1191355, 1191434, 1192814, 1193273, 1193930, 1197284, 1197517, 1200022, 1200145, 1205375, 1206065, 1208074, 1210141, 1210797, 1211578, 1212368, 1213120, 1213229, 1213500, 1214107, 1214108, 1214109, 1215323, 1217513, 1219267, 1219268, 1219438, 1240150, 1247362, 1250508, 1250596, 885209, 907012, 907014, 908033, 909709, 909710, 909712, 913211, 913213, 920645, 930235, 931301, 935570, 938156, 942369, 942370, 946653, 949660, 950931, 953182, 954737, 954797, 954812, 956434, 958255, 959405, 963142, 964468, 964673, 965600, 965918, 968933, 968972, 970637, 974208, 976777, 977394, 978260, 980555, 983015, 984942, 987198, 988408, 988707, 989566, 993847, 995058, 995102, 995620, 996015, 999582
CVE References: CVE-2014-3499, CVE-2014-5277, CVE-2014-6407, CVE-2014-6408, CVE-2014-8178, CVE-2014-8179, CVE-2014-9356, CVE-2014-9357, CVE-2014-9358, CVE-2015-3627, CVE-2015-3629, CVE-2015-3630, CVE-2015-3631, CVE-2016-3697, CVE-2016-8867, CVE-2016-9962, CVE-2017-14992, CVE-2017-16539, CVE-2018-10892, CVE-2018-15664, CVE-2018-16873, CVE-2018-16874, CVE-2018-16875, CVE-2018-20699, CVE-2019-13509, CVE-2019-14271, CVE-2020-12912, CVE-2020-13401, CVE-2020-15257, CVE-2020-8694, CVE-2020-8695, CVE-2021-21284, CVE-2021-21285, CVE-2021-41089, CVE-2021-41091, CVE-2021-41092, CVE-2021-41103, CVE-2021-41190, CVE-2021-43565, CVE-2022-24769, CVE-2022-27191, CVE-2022-36109, CVE-2023-28840, CVE-2023-28841, CVE-2023-28842, CVE-2024-2365, CVE-2024-23651, CVE-2024-23652, CVE-2024-23653, CVE-2024-29018, CVE-2024-41110, CVE-2025-22868, CVE-2025-22869
Jira References: SLE-16460
Maintenance Incident: [SUSE:Maintenance:40905](https://smelt.suse.de/incident/40905/)
Sources used:
SUSE Linux Enterprise Server 12 SP5 LTSS (src):
 docker-stable-24.0.9_ce-1.20.1
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (src):
 docker-stable-24.0.9_ce-1.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Maintenance Automation 2025-10-13 08:36:43 UTC
SUSE-SU-2025:03545-1: An update that solves 53 vulnerabilities, contains one feature and has 137 security fixes can now be installed.

URL: https://www.suse.com/support/update/announcement/2025/suse-su-202503545-1
Category: security (important)
Bug References: 1001161, 1004490, 1007249, 1009961, 1012568, 1015661, 1016307, 1016992, 1019251, 1020806, 1021227, 1026827, 1028638, 1028639, 1029320, 1029630, 1030702, 1032287, 1032644, 1034053, 1034063, 1037436, 1037607, 1038476, 1038493, 1045628, 1046024, 1047218, 1048046, 1051429, 1055676, 1057743, 1058173, 1059011, 1064781, 1065609, 1066210, 1066801, 1069468, 1069758, 1072798, 1073877, 1074971, 1080978, 1084533, 1085117, 1085380, 1086185, 1089732, 1095817, 1096726, 1099277, 1100331, 1100727, 1102522, 1104821, 1105000, 1108038, 1112980, 1113313, 1114832, 1115464, 1118897, 1118898, 1118899, 1118990, 1119634, 1121412, 1121768, 1122469, 1124308, 1128376, 1128746, 1134068, 1138920, 1139649, 1142160, 1142413, 1143349, 1150397, 1153367, 1157330, 1158590, 1170415, 1170446, 1172377, 1174075, 1175081, 1176708, 1178760, 1178801, 1180243, 1180401, 1181594, 1181641, 1181677, 1181730, 1181732, 1182168, 1182476, 1182947, 1183855, 1184768, 1188447, 1190670, 1191015, 1191121, 1191334, 1191355, 1191434, 1192814, 1193273, 1193930, 1197284, 1197517, 1200022, 1200145, 1205375, 1206065, 1208074, 1210141, 1210797, 1211578, 1212368, 1213120, 1213229, 1213500, 1214107, 1214108, 1214109, 1215323, 1217513, 1219267, 1219268, 1219438, 1240150, 1247362, 1250508, 1250596, 885209, 907012, 907014, 908033, 909709, 909710, 909712, 913211, 913213, 920645, 930235, 931301, 935570, 938156, 942369, 942370, 946653, 949660, 950931, 953182, 954737, 954797, 954812, 956434, 958255, 959405, 963142, 964468, 964673, 965600, 965918, 968933, 968972, 970637, 974208, 976777, 977394, 978260, 980555, 983015, 984942, 987198, 988408, 988707, 989566, 993847, 995058, 995102, 995620, 996015, 999582
CVE References: CVE-2014-3499, CVE-2014-5277, CVE-2014-6407, CVE-2014-6408, CVE-2014-8178, CVE-2014-8179, CVE-2014-9356, CVE-2014-9357, CVE-2014-9358, CVE-2015-3627, CVE-2015-3629, CVE-2015-3630, CVE-2015-3631, CVE-2016-3697, CVE-2016-8867, CVE-2016-9962, CVE-2017-14992, CVE-2017-16539, CVE-2018-10892, CVE-2018-15664, CVE-2018-16873, CVE-2018-16874, CVE-2018-16875, CVE-2018-20699, CVE-2019-13509, CVE-2019-14271, CVE-2020-12912, CVE-2020-13401, CVE-2020-15257, CVE-2020-8694, CVE-2020-8695, CVE-2021-21284, CVE-2021-21285, CVE-2021-41089, CVE-2021-41091, CVE-2021-41092, CVE-2021-41103, CVE-2021-41190, CVE-2021-43565, CVE-2022-24769, CVE-2022-27191, CVE-2022-36109, CVE-2023-28840, CVE-2023-28841, CVE-2023-28842, CVE-2024-2365, CVE-2024-23651, CVE-2024-23652, CVE-2024-23653, CVE-2024-29018, CVE-2024-41110, CVE-2025-22868, CVE-2025-22869
Jira References: SLE-16460
Maintenance Incident: [SUSE:Maintenance:40904](https://smelt.suse.de/incident/40904/)
Sources used:
openSUSE Leap 15.6 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
Containers Module 15-SP6 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
Containers Module 15-SP7 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server 15 SP3 LTSS (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server 15 SP4 LTSS (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server 15 SP5 LTSS (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (src):
 docker-stable-24.0.9_ce-150000.1.25.1
SUSE Enterprise Storage 7.1 (src):
 docker-stable-24.0.9_ce-150000.1.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.