<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">SUSE-IU-2024:21-1</DocumentTitle>
  <DocumentType>SUSE Image</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE Image SUSE-IU-2024:21-1</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2026-03-19T08:53:56Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-01-11T01:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-01-11T01:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-publiccloud.pl</Engine>
      <Date>2021-02-18T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Image update for SUSE-IU-2024:21-1 / google/sles-15-sp5-chost-byos-v20240111-x86-64</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This image update for google/sles-15-sp5-chost-byos-v20240111-x86-64 contains the following changes:
Package curl was updated:

- Fix: libssh: Implement SFTP packet size limit (bsc#1216987)  * Add curl-libssh_Implement_SFTP_packet_size_limit.patch

Package docker was updated:

- Update to Docker 24.0.7-ce. See upstream changelong online at  &amp;lt;https://docs.docker.com/engine/release-notes/24.0/#2407&amp;gt;. bsc#1217513
  * Deny containers access to /sys/devices/virtual/powercap by default.
  - CVE-2020-8694 bsc#1170415
  - CVE-2020-8695 bsc#1170446
  - CVE-2020-12912 bsc#1178760
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  * cli-0001-docs-include-required-tools-in-source-tree.patch

- Add a patch to fix apparmor on SLE-12, reverting the upstream removal of
  version-specific templating for the default apparmor profile. bsc#1213500
  + 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch

- Update to Docker 24.0.6-ce. See upstream changelong online at
  &amp;lt;https://docs.docker.com/engine/release-notes/24.0/#2406&amp;gt;. bsc#1215323
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * cli-0001-docs-include-required-tools-in-source-tree.patch
- Switch from disabledrun to manualrun in _service.
- Add a docker.socket unit file, but with socket activation effectively
  disabled to ensure that Docker will always run even if you start the socket
  individually. Users should probably just ignore this unit file. bsc#1210141

Package google-guest-agent was updated:

- Update to version 20231031.01 (bsc#1216547, bsc#1216751)  * Add prefix to scheduler logs (#325)
- from version 20231030.00
  * Test configuration files are loaded in the documented
    order. Fix initial integration test. (#324)
  * Enable mTLS by default (#323)
- from version 20231026.00
  * Rotate MDS root certificate (#322)
- from version 20231020.00
  * Update response struct, add tests (#315)
  * Don't try to schedule mTLS job twice (#317)
- from version 20231019.00
  * snapshot: Add context cancellation handling (#318)

- Bump the golang compiler version to 1.21 (bsc#1216546)

- Update to version 20231016.00
  * instance setup: trust/rely on metadata package's retry (#316)
- from version 20231013.01
  * Update known cert dirs for updaters (#314)
- from version 20231011.00
  * Verify cert refresher is enabled before running (#312)
- from version 20231009.00
  * Add support for the SSH key options (#296)
- from version 20231006.01
  * Events interface improvement (#290)
- from version 20231006.00
  * Refactor script runner to use common metadata package (#311)
  * Schedule MTLS job before notifying systemd (#310)
  * Refactor authorized keys to use metadata package (#300)
- from version 20231005.00
  * docs update: add configuration and event manager's docs. (#309)
- from version 20231004.01
  * Fix license header (#301)
  * packaging(deb): add epoch to oslogin dep declaration (#308)
- from version 20231004.00
  * packaging(deb): ignore suffix of version (#306)
  * packaging: force epoch and ignore suffix of version (#305)
- from version 20231003.01
  * oslogin: declare explicitly dependency (#304)
  * oslogin: remove Unstable.pamless_auth_stack feature flag (#303)
- from version 20231003.00
  * oslogin: resort ssh configuration keys (#299)
- from version 20230925.00
  * oslogin: introduce a feature flag to cert auth (#298)
- from version 20230923.00
  * gitignore: unify ignore in the root dir (#297)
- from version 20230921.01
  * managers: we accidentally disabled addressMgr, bring it back (#295)
  * cfg: fix typos (#294)
  * cfg: config typos (#293)
  * cfg: introduce a configuration management package (#288)
- from version 20230921.00
  * mtls: bring it back (#292)
- from version 20230920.01
  * Fix permissions on file created by SaferWriteFile() (#291)
- from version 20230920.00
  * sshca: re-enable the event watcher &amp;amp; handler (#289)
- from version 20230919.01
  * oslogin: add PAMless Authorization Stack configuration (#285)
- from version 20230919.00
  * Preparing it for review (#287)
  * sshca: make sure to restore SELinux context of the pipe (#286)
  * remove deprecated usage, fix warnings (#282)
  * Update system store (#278)
  * Update workload certificate endpoints, use metadata package (#275)
  * metadata: use url package to form metadata URLs (#284)
- from version 20230913.00
  * release prep: disable ssh trusted ca module (#281)
- from version 20230912.00
  * New Guest Agent Release (#280)
- from version 20230909.00
  * Revert &amp;quot;service: remove the use of the service library (#273)&amp;quot; (#276)
  * service: remove the use of the service library (#273)
- from version 20230906.01
  * Store keys to machine keyset (#272)
- from version 20230905.00
  * restorecon: first try to determine if it's installed (#271)
  * run: change all commands to use CommandContext (#268)
  * Notify systemd after scheduling required jobs (#270)
  * Store certs in ProgramData instead of Program Files (#269)
  * metadata watcher: remove local retry &amp;amp; implement unit tests (#267)
  * run: split command running utilities into its own package (#265)

- Update to version 20230828.00
  * snapshot: Use main context rather than create its own (#266)
- from version 20230825.01
  * Verify if cert was successfully added to certpool (#264)
- from version 20230825.00
  * Find previous cert for cleanup using one stored on disk (#263)
- from version 20230823.00
  * Revert &amp;quot;sshtrustedca: configure selinux context
    for sshtrustedca pipe (#256)&amp;quot; (#262)
  * Update credentials directory on Linux (#260)
- from version 20230821.00
  * Update owners (#261)
- from version 20230819.00
  * Revert &amp;quot;guest-agent: prepare for public release (#258)&amp;quot; (#259)
- from version 20230817.00
  * guest-agent: prepare for public release (#258)
- from version 20230816.01
  * Enable telemetry collection by default (#253)
- from version 20230816.00
  * Add pkcs12 license and update retry logic (#257)
  * sshtrustedca: Configure selinux context for sshtrustedca pipe (#256)
  * Store windows certs in certstore (#255)
  * events: Multiplex event watchers (#250)
  * Scheduler fixes (#254)
  * Update license files (#251)
  * Run telemetry every 24 hours, record pretty name on linux (#248)

- Update to version 20230811.00
  * sshca: move the event handler to its own package (#247)
- from version 20230809.02
  * Move scheduler package to google_guest_agent (#249)
- from version 20230809.01
  * Add scheduler utility to run jobs at interval (#244)
- from version 20230809.00
  * sshca: transform the format from json to openssh (#246)
- from version 20230803.00
  * Add support for reading UEFI variables on windows (#243)
- from version 20230801.03
  * sshtrustedca watcher: fix concurrency error (#242)
- from version 20230801.02
  * metadata: add a delta between http client timeout and hang (#241)
- from version 20230801.00
  * metadata: properly set request config (#240)
  * main: bring back the mds client initialization (#239)
  * metadata: don't try to use metadata before agentInit() is done (#238)
  * Add (disabled) telemetry logic to GuestAgent (#219)
  * metadata event handler: updates and bug fixes (#235)
  * Verify client credentials are signed by root CA before writing on disk (#236)
  * metadata: properly handle context cancelation (#234)
  * metadata: fix context cancelation error check (#233)
  * metadata: remove the sleep around metadata in instance setup (#232)
  * metadata: implement backoff strategy (#231)
  * Decrypt and store client credentials on disk (#230)
  * Upgrade Go version 1.20 (#228)
  * Fetch guest credentials and add MDS response proto (#226)
  * metadata: pass main context to WriteGuestAttributes() (#227)
  * Support for reading &amp;amp; writing Root CA cert from UEFI variable (#225)
  * ssh_trusted_ca: enable the feature (#224)
  * sshTrustedCA: add pipe event handler (#222)
  * events: start using events layer (#223)
- from version 20230726.00
  * events: introducing a events handling subsystem (#221)
- from version 20230725.00
  * metadata: add metadata client interface (#220)
- from version 20230711.00
  * metadata: moving to its own package (#218)
- from version 20230707.00
  * snapshot: fix request handling error (#217)
- Bump Go API version to 1.20

Package google-guest-oslogin was updated:

- Update to version 20231101.00 (bsc#1216548, bsc#1216750)  * Fix HTTP calls retry logic (#117)

- Update to version 20231004
  * packaging: Make the dependency explicit (#120)

- update to 20230926.00:
  * fix suse build
  * selinux: fix selinux build (#114)
  * test: align CXX Flags
  * sshca: Make the implementation more C++ like
  * sshca: Add a SysLog wrapper
  * oslogin_utils: introduce AuthorizeUser() API
  * sshca: move it out of pam dir
  * pam: start disabling the use of oslogin_sshca
  * sshca: consider sshca API to assume a cert only
  * authorized principals: introduce the new command
  * authorize keys: update to use new APIs
  * pam modules: remove pam_*_admin and update pam_*_login
  * cache_refresh: should be catching by reference.

- Update to version 20230823.00
  * selinux: Add sshd_key_t type enforcement to trusted user ca (#113)
- from version 20230822.00
  * sshca: Add tests with fingerprint and multiple extensions (#111)
- from version 20230821.01
  * sshca: Support method token and handle multi line (#109)
- from version 20230821.00
  * Update owners (#110)

- Update to version 20230808.00
  * byoid: extract and apply the ca fingerprint to policy call (#106)

- Update to version 20230502.00
  * Improve the URL in 2fa prompt (#104)
- from version 20230406.02
  * Check open files (#101)
- from version 20230406.01
  * Initialize variables (#100)
  * Fix formatting (#102)
- from version 20230406.00
  * PAM cleanup: remove duplicates (#97)
- from version 20230405.00
  * NSS cleanup (#98)
- from version 20230403.01
  * Cleanup Makefiles (#95)
- from version 20230403.00
  * Add anandadalton to the owners list (#96)

- Update to version 20230217.00
  * Update OWNERS (#91)
- from version 20230202.00
  * Update owners file (#89)

Package avahi was updated:

- Add avahi-CVE-2023-38472.patch: Fix reachable assertion in  avahi_rdata_parse (bsc#1216853, CVE-2023-38472).

Package libxcrypt was updated:

- fix variable name for datamember in 'struct crypt_data' [bsc#1215496]- added patches
  fix https://github.com/besser82/libxcrypt/commit/b212d601549a0fc84cbbcaf21b931f903787d7e2
  + libxcrypt-man-fix-variable-name.patch

Package gnutls was updated:

- Security fix: [bsc#1217277, CVE-2023-5981]  * Fix timing side-channel inside RSA-PSK key exchange.
  * auth/rsa_psk: side-step potential side-channel
  * Add curl-CVE-2023-5981.patch

Package ncurses was updated:

- Add patch bsc1218014-cve-2023-50495.patch  * Fix CVE-2023-50495: segmentation fault via _nc_wrap_entry()

- Add patch boo1201384.patch
  * Do not fully reset serial lines

Package procps was updated:

- Submit latest procps 3.3.17 to SLE-15 tree for jira#PED-3244  and jira#PED-6369
- The patches now upstream had been dropped meanwhile
  * procps-vmstat-1b9ea611.patch (bsc#1185417)
  - For support up to 2048 CPU as well
  * bsc1209122-a6c0795d.patch (bnc#1209122)
  - allow `-Â´ as leading character to ignore possible errors
    on systctl entries
  * patch procps-ng-3.3.9-bsc1121753-Cpus.patch (bsc#1121753)
  - was a backport of an upstream fix to get the first CPU
    summary correct
- Enable pidof for SLE-15 as this is provided by sysvinit-tools
- Use a check on syscall __NR_pidfd_open to decide if
  the pwait tool and its manual page will be build

- Modify patches
  * procps-ng-3.3.9-w-notruncate.diff
  * procps-ng-3.3.17-logind.patch
  to real to not truncate output of w with option -n

- procps-ng-3.3.17-logind.patch: Backport from 4.x git, prefer
  logind over utmp (jsc#PED-3144)

Package libsolv was updated:

- add zstd support for the installcheck tool- add putinowndirpool cache to make file list handling in
  repo_write much faster
- bump version to 0.7.27

- fix evr roundtrip in testcases
- do not use deprecated headerUnload with newer rpm versions
- bump version to 0.7.26

- support complex deps in SOLVABLE_PREREQ_IGNOREINST
- fix minimization not prefering installed packages in some cases
- reduce memory usage in repo_updateinfoxml
- fix lock-step interfering with architecture selection
- fix choice rule handing for package downgrades
- fix complex dependencies with an &amp;quot;else&amp;quot; part sometimes leading
  to unsolved dependencies
- bump version to 0.7.25

Package libzypp was updated:

- CheckAccessDeleted: fix 'running in container' filter  (bsc#1218291)
- version 17.31.27 (22)

- Call zypp commit plugins during transactional update (fixes #506)
- Add support for loongarch64 (fixes #504)
- Teach MediaMultiCurl to download HTTP Multibyte ranges.
- Teach zsync downloads to MultiCurl.
- Expand RepoVars in URLs downloading a .repo file (bsc#1212160)
  Convenient and helps documentation as it may refer to a single
  command for a bunch of distributions. Like e.g. &amp;quot;zypper ar
  'https://server.my/$releasever/my.repo'&amp;quot;.
- version 17.31.26 (22)

- Fix build issue with zchunk build flags (fixes #500)
- version 17.31.25 (22)

- Open rpmdb just once during execution of %posttrans scripts
  (bsc#1216412)
- Avoid using select() since it does not support fd numbers &amp;gt;
  1024 (fixes #447)
- tools/DownloadFiles: use standard zypp progress bar (fixes #489)
- Revert &amp;quot;Color download progress bar&amp;quot; (fixes #475)
  Cyan is already used for the output of RPM scriptlets. Avoid this
  colorific collision between download progress bar and scriptlet
  output.
- Fix ProgressBar's calculation of the printed tag position (fixes #494)
- Switch zypp::Digest to Openssl 3.0 Provider API (fixes #144)
- Fix usage of deprecated CURL features (fixes #486)
- version 17.31.24 (22)

- Stop using boost version 1 timer library (fixes #489,
  bsc#1215294)
- version 17.31.23 (22)

Package openssh was updated:

- Added openssh-cve-2023-48795.patch (bsc#1217950, CVE-2023-48795).  This mitigates a prefix truncation attack that could be used to
  undermine channel security.

- Enhanced SELinux functionality. Added
  * openssh-7.8p1-role-mls.patch
    Proper handling of MLS systems and basis for other SELinux
    improvements
  * openssh-6.6p1-privsep-selinux.patch
    Properly set contexts during privilege separation
  * openssh-6.6p1-keycat.patch
    Add ssh-keycat command to allow retrival of authorized_keys
    on MLS setups with polyinstantiation
  * openssh-6.6.1p1-selinux-contexts.patch
    Additional changes to set the proper context during privilege
    separation
  * openssh-7.6p1-cleanup-selinux.patch
    Various changes and putting the pieces together
  For now we don't ship the ssh-keycat command, but we need the patch
  for the other SELinux infrastructure
  This change fixes issues like bsc#1214788, where the ssh daemon
  needs to act on behalf of a user and needs a proper context for this

Package python-instance-billing-flavor-check was updated:

- Version 0.0.4  Run the command as sudo only (bsc#1217696, bsc#1217695)

- Version 0.0.3
  Handle exception for Python 3.4

Package python3-cryptography was updated:

- Add CVE-2023-49083.patch to fix A null-pointer-dereference and  segfault could occur when loading certificates from a PKCS#7 bundle.
  bsc#1217592

Package rsyslog was updated:

- restart daemon after modules packages have been updated  (bsc#1217292)

Package samba was updated:

- Add new idmap_nss option 'use_upn' for those NSS modules able to  handle UPNs or DOMAIN/user name format; (bsc#1215369);
- Avoid unnecessary locking in idmap parent setup; (bsc#1215369);

- Add &amp;quot;net offlinejoin composeodj&amp;quot; command; (bsc#1214076);

Package 000release-packages:sle-module-basesystem-release was updated:

Package 000release-packages:sle-module-containers-release was updated:

Package 000release-packages:sle-module-public-cloud-release was updated:

Package 000release-packages:sle-module-server-applications-release was updated:

Package 000release-packages:SLES-release was updated:

Package tar was updated:

- Fix CVE-2023-39804, Incorrectly handled extension attributes in  PAX archives can lead to a crash, bsc#1217969
  * fix-CVE-2023-39804.patch

Package xen was updated:

- Update to Xen 4.17.3 bug fix release (bsc#1027519)  xen-4.17.3-testing-src.tar.bz2
  * No upstream changelog found in sources or webpage
- Dropped patches contained in new tarball
  64763137-x86-AutoIBRS-definitions.patch
  64e5b4ac-x86-AMD-extend-Zenbleed-check.patch
  64e6459b-revert-VMX-sanitize-rIP-before-reentering.patch
  64eef7e9-x86-reporting-spurious-i8259-interrupts.patch
  64f71f50-Arm-handle-cache-flush-at-top.patch
  65084ba5-x86-AMD-dont-expose-TscFreqSel.patch
  65087000-x86-spec-ctrl-SPEC_CTRL_EXIT_TO_XEN-confusion.patch
  65087001-x86-spec-ctrl-fold-DO_SPEC_CTRL_EXIT_TO_XEN.patch
  65087002-x86-spec-ctrl-SPEC_CTRL-ENTRY-EXIT-asm-macros.patch
  65087003-x86-spec-ctrl-SPEC_CTRL-ENTER-EXIT-comments.patch
  65087004-x86-entry-restore_all_xen-stack_end.patch
  65087005-x86-entry-track-IST-ness-of-entry.patch
  65087006-x86-spec-ctrl-VERW-on-IST-exit-to-Xen.patch
  65087007-x86-AMD-Zen-1-2-predicates.patch
  65087008-x86-spec-ctrl-Zen1-DIV-leakage.patch
  650abbfe-x86-shadow-defer-PV-top-level-release.patch
  65263470-AMD-IOMMU-flush-TLB-when-flushing-DTE.patch
  65263471-libfsimage-xfs-remove-dead-code.patch
  65263472-libfsimage-xfs-amend-mask32lo.patch
  65263473-libfsimage-xfs-sanity-check-superblock.patch
  65263474-libfsimage-xfs-compile-time-check.patch
  65263475-pygrub-remove-unnecessary-hypercall.patch
  65263476-pygrub-small-refactors.patch
  65263477-pygrub-open-output-files-earlier.patch
  65263478-libfsimage-function-to-preload-plugins.patch
  65263479-pygrub-deprivilege.patch
  6526347a-libxl-allow-bootloader-restricted-mode.patch
  6526347b-libxl-limit-bootloader-when-restricted.patch
  6526347c-SVM-fix-AMD-DR-MASK-context-switch-asymmetry.patch
  6526347d-x86-PV-auditing-of-guest-breakpoints.patch
  652fef4f-x86-AMD-erratum-1485.patch
  65319724-VT-d-SAGAW-parsing.patch
  6532858d-x86-DOITM.patch
  654370e2-x86-x2APIC-remove-ACPI_FADT_APIC_CLUSTER-use.patch
  65437103-x86-i8259-dont-assume-IRQs-always-target-CPU0.patch
  65536847-AMD-IOMMU-correct-level-for-quarantine-pt.patch
  65536848-x86-spec-ctrl-remove-conditional-IRQs-on-ness.patch
  655b2ba9-fix-sched_move_domain.patch
  xsa440.patch

- Upstream bug fixes (bsc#1027519)
  64763137-x86-AutoIBRS-definitions.patch
  652fef4f-x86-AMD-erratum-1485.patch
  65319724-VT-d-SAGAW-parsing.patch
  6532858d-x86-DOITM.patch
  654370e2-x86-x2APIC-remove-ACPI_FADT_APIC_CLUSTER-use.patch
  65437103-x86-i8259-dont-assume-IRQs-always-target-CPU0.patch
  655b2ba9-fix-sched_move_domain.patch
- bsc#1216654 - VUL-0: CVE-2023-46835: xen: x86/AMD: mismatch in
  IOMMU quarantine page table levels (XSA-445)
  65536847-AMD-IOMMU-correct-level-for-quarantine-pt.patch
- bsc#1216807 - VUL-0: CVE-2023-46836: xen: x86: BTC/SRSO fixes not
  fully effective (XSA-446)
  65536848-x86-spec-ctrl-remove-conditional-IRQs-on-ness.patch
- Patches replaced by newer upstream versions
  xsa445.patch
  xsa446.patch

Package zypper was updated:

- Fix search/info commands ignoring --ignore-unknown (bsc#1217593)  The switch makes search commands return 0 rather than 104 for
  empty search results.
- version 1.14.68

- patch: Make sure reboot-needed is remembered until next boot
  (bsc#1217873)
- version 1.14.67

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp5-chost-byos-v20240111-x86-64/</URL>
      <Description>Public Cloud Image Info</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <Branch Type="Product Name" Name="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
        <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="curl-8.0.1-150400.5.41.1">
      <FullProductName ProductID="curl-8.0.1-150400.5.41.1">curl-8.0.1-150400.5.41.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="docker-24.0.7_ce-150000.190.4">
      <FullProductName ProductID="docker-24.0.7_ce-150000.190.4">docker-24.0.7_ce-150000.190.4</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="google-guest-agent-20231031.01-150000.1.40.1">
      <FullProductName ProductID="google-guest-agent-20231031.01-150000.1.40.1">google-guest-agent-20231031.01-150000.1.40.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="google-guest-oslogin-20231101.00-150000.1.35.1">
      <FullProductName ProductID="google-guest-oslogin-20231101.00-150000.1.35.1">google-guest-oslogin-20231101.00-150000.1.35.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavahi-client3-0.8-150400.7.13.1">
      <FullProductName ProductID="libavahi-client3-0.8-150400.7.13.1">libavahi-client3-0.8-150400.7.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libavahi-common3-0.8-150400.7.13.1">
      <FullProductName ProductID="libavahi-common3-0.8-150400.7.13.1">libavahi-common3-0.8-150400.7.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcrypt1-4.4.15-150300.4.7.1">
      <FullProductName ProductID="libcrypt1-4.4.15-150300.4.7.1">libcrypt1-4.4.15-150300.4.7.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-8.0.1-150400.5.41.1">
      <FullProductName ProductID="libcurl4-8.0.1-150400.5.41.1">libcurl4-8.0.1-150400.5.41.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgnutls30-3.7.3-150400.4.38.1">
      <FullProductName ProductID="libgnutls30-3.7.3-150400.4.38.1">libgnutls30-3.7.3-150400.4.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libncurses6-6.1-150000.5.20.1">
      <FullProductName ProductID="libncurses6-6.1-150000.5.20.1">libncurses6-6.1-150000.5.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsolv-tools-0.7.27-150400.3.11.2">
      <FullProductName ProductID="libsolv-tools-0.7.27-150400.3.11.2">libsolv-tools-0.7.27-150400.3.11.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libzypp-17.31.27-150400.3.49.1">
      <FullProductName ProductID="libzypp-17.31.27-150400.3.49.1">libzypp-17.31.27-150400.3.49.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ncurses-utils-6.1-150000.5.20.1">
      <FullProductName ProductID="ncurses-utils-6.1-150000.5.20.1">ncurses-utils-6.1-150000.5.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssh-8.4p1-150300.3.27.1">
      <FullProductName ProductID="openssh-8.4p1-150300.3.27.1">openssh-8.4p1-150300.3.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssh-clients-8.4p1-150300.3.27.1">
      <FullProductName ProductID="openssh-clients-8.4p1-150300.3.27.1">openssh-clients-8.4p1-150300.3.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssh-common-8.4p1-150300.3.27.1">
      <FullProductName ProductID="openssh-common-8.4p1-150300.3.27.1">openssh-common-8.4p1-150300.3.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssh-server-8.4p1-150300.3.27.1">
      <FullProductName ProductID="openssh-server-8.4p1-150300.3.27.1">openssh-server-8.4p1-150300.3.27.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="procps-3.3.17-150000.7.37.1">
      <FullProductName ProductID="procps-3.3.17-150000.7.37.1">procps-3.3.17-150000.7.37.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-instance-billing-flavor-check-0.0.4-150000.1.6.1">
      <FullProductName ProductID="python-instance-billing-flavor-check-0.0.4-150000.1.6.1">python-instance-billing-flavor-check-0.0.4-150000.1.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-cryptography-3.3.2-150400.23.1">
      <FullProductName ProductID="python3-cryptography-3.3.2-150400.23.1">python3-cryptography-3.3.2-150400.23.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-cssselect-1.0.3-150000.3.5.1">
      <FullProductName ProductID="python3-cssselect-1.0.3-150000.3.5.1">python3-cssselect-1.0.3-150000.3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rsyslog-8.2306.0-150400.5.24.1">
      <FullProductName ProductID="rsyslog-8.2306.0-150400.5.24.1">rsyslog-8.2306.0-150400.5.24.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rsyslog-module-relp-8.2306.0-150400.5.24.1">
      <FullProductName ProductID="rsyslog-module-relp-8.2306.0-150400.5.24.1">rsyslog-module-relp-8.2306.0-150400.5.24.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1">
      <FullProductName ProductID="samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1">samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tar-1.34-150000.3.34.1">
      <FullProductName ProductID="tar-1.34-150000.3.34.1">tar-1.34-150000.3.34.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="terminfo-6.1-150000.5.20.1">
      <FullProductName ProductID="terminfo-6.1-150000.5.20.1">terminfo-6.1-150000.5.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="terminfo-base-6.1-150000.5.20.1">
      <FullProductName ProductID="terminfo-base-6.1-150000.5.20.1">terminfo-base-6.1-150000.5.20.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-libs-4.17.3_02-150500.3.18.1">
      <FullProductName ProductID="xen-libs-4.17.3_02-150500.3.18.1">xen-libs-4.17.3_02-150500.3.18.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="zypper-1.14.68-150400.3.40.2">
      <FullProductName ProductID="zypper-1.14.68-150400.3.40.2">zypper-1.14.68-150400.3.40.2</FullProductName>
    </Branch>
    <Relationship ProductReference="curl-8.0.1-150400.5.41.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:curl-8.0.1-150400.5.41.1">curl-8.0.1-150400.5.41.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="docker-24.0.7_ce-150000.190.4" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:docker-24.0.7_ce-150000.190.4">docker-24.0.7_ce-150000.190.4 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="google-guest-agent-20231031.01-150000.1.40.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:google-guest-agent-20231031.01-150000.1.40.1">google-guest-agent-20231031.01-150000.1.40.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="google-guest-oslogin-20231101.00-150000.1.35.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:google-guest-oslogin-20231101.00-150000.1.35.1">google-guest-oslogin-20231101.00-150000.1.35.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavahi-client3-0.8-150400.7.13.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libavahi-client3-0.8-150400.7.13.1">libavahi-client3-0.8-150400.7.13.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libavahi-common3-0.8-150400.7.13.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libavahi-common3-0.8-150400.7.13.1">libavahi-common3-0.8-150400.7.13.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcrypt1-4.4.15-150300.4.7.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libcrypt1-4.4.15-150300.4.7.1">libcrypt1-4.4.15-150300.4.7.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.0.1-150400.5.41.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libcurl4-8.0.1-150400.5.41.1">libcurl4-8.0.1-150400.5.41.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgnutls30-3.7.3-150400.4.38.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libgnutls30-3.7.3-150400.4.38.1">libgnutls30-3.7.3-150400.4.38.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libncurses6-6.1-150000.5.20.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libncurses6-6.1-150000.5.20.1">libncurses6-6.1-150000.5.20.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsolv-tools-0.7.27-150400.3.11.2" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libsolv-tools-0.7.27-150400.3.11.2">libsolv-tools-0.7.27-150400.3.11.2 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libzypp-17.31.27-150400.3.49.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libzypp-17.31.27-150400.3.49.1">libzypp-17.31.27-150400.3.49.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="ncurses-utils-6.1-150000.5.20.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:ncurses-utils-6.1-150000.5.20.1">ncurses-utils-6.1-150000.5.20.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssh-8.4p1-150300.3.27.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-8.4p1-150300.3.27.1">openssh-8.4p1-150300.3.27.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssh-clients-8.4p1-150300.3.27.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-clients-8.4p1-150300.3.27.1">openssh-clients-8.4p1-150300.3.27.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssh-common-8.4p1-150300.3.27.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-common-8.4p1-150300.3.27.1">openssh-common-8.4p1-150300.3.27.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssh-server-8.4p1-150300.3.27.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-server-8.4p1-150300.3.27.1">openssh-server-8.4p1-150300.3.27.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="procps-3.3.17-150000.7.37.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:procps-3.3.17-150000.7.37.1">procps-3.3.17-150000.7.37.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-instance-billing-flavor-check-0.0.4-150000.1.6.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:python-instance-billing-flavor-check-0.0.4-150000.1.6.1">python-instance-billing-flavor-check-0.0.4-150000.1.6.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-cryptography-3.3.2-150400.23.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:python3-cryptography-3.3.2-150400.23.1">python3-cryptography-3.3.2-150400.23.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-cssselect-1.0.3-150000.3.5.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:python3-cssselect-1.0.3-150000.3.5.1">python3-cssselect-1.0.3-150000.3.5.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="rsyslog-8.2306.0-150400.5.24.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:rsyslog-8.2306.0-150400.5.24.1">rsyslog-8.2306.0-150400.5.24.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="rsyslog-module-relp-8.2306.0-150400.5.24.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:rsyslog-module-relp-8.2306.0-150400.5.24.1">rsyslog-module-relp-8.2306.0-150400.5.24.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1">samba-client-libs-4.17.12+git.455.b299ac1e60-150500.3.20.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="tar-1.34-150000.3.34.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:tar-1.34-150000.3.34.1">tar-1.34-150000.3.34.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="terminfo-6.1-150000.5.20.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:terminfo-6.1-150000.5.20.1">terminfo-6.1-150000.5.20.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="terminfo-base-6.1-150000.5.20.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:terminfo-base-6.1-150000.5.20.1">terminfo-base-6.1-150000.5.20.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.17.3_02-150500.3.18.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:xen-libs-4.17.3_02-150500.3.18.1">xen-libs-4.17.3_02-150500.3.18.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
    <Relationship ProductReference="zypper-1.14.68-150400.3.40.2" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:zypper-1.14.68-150400.3.40.2">zypper-1.14.68-150400.3.40.2 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access.</Note>
    </Notes>
    <CVE>CVE-2020-12912</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:docker-24.0.7_ce-150000.190.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.</Note>
    </Notes>
    <CVE>CVE-2020-8694</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:docker-24.0.7_ce-150000.190.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.</Note>
    </Notes>
    <CVE>CVE-2020-8695</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:docker-24.0.7_ce-150000.190.4</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.</Note>
    </Notes>
    <CVE>CVE-2023-38472</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libavahi-client3-0.8-150400.7.13.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libavahi-common3-0.8-150400.7.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.</Note>
    </Notes>
    <CVE>CVE-2023-39804</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:tar-1.34-150000.3.34.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The current setup of the quarantine page tables assumes that the
quarantine domain (dom_io) has been initialized with an address width
of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and hence 4 page table levels.

However dom_io being a PV domain gets the AMD-Vi IOMMU page tables
levels based on the maximum (hot pluggable) RAM address, and hence on
systems with no RAM above the 512GB mark only 3 page-table levels are
configured in the IOMMU.

On systems without RAM above the 512GB boundary
amd_iommu_quarantine_init() will setup page tables for the scratch
page with 4 levels, while the IOMMU will be configured to use 3 levels
only, resulting in the last page table directory (PDE) effectively
becoming a page table entry (PTE), and hence a device in quarantine
mode gaining write access to the page destined to be a PDE.

Due to this page table level mismatch, the sink page the device gets
read/write access to is no longer cleared between device assignment,
possibly leading to data leaks.
</Note>
    </Notes>
    <CVE>CVE-2023-46835</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:xen-libs-4.17.3_02-150500.3.18.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative
Return Stack Overflow) are not IRQ-safe.  It was believed that the
mitigations always operated in contexts with IRQs disabled.

However, the original XSA-254 fix for Meltdown (XPTI) deliberately left
interrupts enabled on two entry paths; one unconditionally, and one
conditionally on whether XPTI was active.

As BTC/SRSO and Meltdown affect different CPU vendors, the mitigations
are not active together by default.  Therefore, there is a race
condition whereby a malicious PV guest can bypass BTC/SRSO protections
and launch a BTC/SRSO attack against Xen.
</Note>
    </Notes>
    <CVE>CVE-2023-46836</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:xen-libs-4.17.3_02-150500.3.18.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.</Note>
    </Notes>
    <CVE>CVE-2023-48795</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-8.4p1-150300.3.27.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-clients-8.4p1-150300.3.27.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-common-8.4p1-150300.3.27.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:openssh-server-8.4p1-150300.3.27.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.</Note>
    </Notes>
    <CVE>CVE-2023-49083</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:python3-cryptography-3.3.2-150400.23.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().</Note>
    </Notes>
    <CVE>CVE-2023-50495</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libncurses6-6.1-150000.5.20.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:ncurses-utils-6.1-150000.5.20.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:terminfo-6.1-150000.5.20.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:terminfo-base-6.1-150000.5.20.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.</Note>
    </Notes>
    <CVE>CVE-2023-5981</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20240111-x86-64:libgnutls30-3.7.3-150400.4.38.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
</cvrfdoc>
