=========================================================================== ZMCIRT Vulnerability Bulletin ZMC-2021.10.11.0800 kubernetes: Multiple vulnerabilities 11th October 2021 =========================================================================== Product: kubernetes Publisher: SUSE Operating System: SUSE Impact/Access: Access Confidential Data -- Existing Account Reduced Security -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2021-25741 Reference: ESB-2021.3246 ESB-2021.3228 Original Bulletin: https://www.suse.com/support/update/announcement/2021/suse-su-20213323-1 - --------------------------BEGIN INCLUDED TEXT-------------------- SUSE Security Update: Includes a kubernetes update to 1.17.17 including a back ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3323-1 Rating: low References: #1189416 Cross-References: CVE-2021-25741 Affected Products: SUSE CaaS Platform 4.0 ______________________________________________________________________________ port for CVE-2021-25741 An update that fixes one vulnerability is now available. Description: == Kubernetes bsc#1189416 kubernetes issue is a backport of the upstream security fix (CVE-2021-25741): https://github.com/kubernetes/kubernetes/pull/ 104253 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: o SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. I will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: o SUSE CaaS Platform 4.0 (noarch): release-notes-caasp-4.2.20210929-4.71.2 skuba-update-1.4.13-3.56.2 o SUSE CaaS Platform 4.0 (x86_64): caasp-release-4.2.6-24.43.2 kubernetes-client-1.17.17-4.25.2 kubernetes-common-1.17.17-4.25.2 kubernetes-kubeadm-1.17.17-4.25.2 kubernetes-kubelet-1.17.17-4.25.2 skuba-1.4.13-3.56.2 References: o https://www.suse.com/security/cve/CVE-2021-25741.html o https://bugzilla.suse.com/1189416 - --------------------------END INCLUDED TEXT-------------------- ZMCIRT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. ZMCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Internet Email: report@cirt.zm Telephone: 7070 ZMCIRT personnel answer during Zambian business hours which are 8am to 5pm. On call after hours for member emergencies only. ===========================================================================
Copyright @2023 ZAMBIA CIRT