{"affected":[{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 15 SP1-BCL","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCL"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 15 SP1-LTSS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 15 SP2-BCL","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCL"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP1","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Manager Proxy 4.1","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Manager%20Proxy%204.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Manager Retail Branch Server 4.1","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Manager Server 4.1","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Manager%20Server%204.1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Enterprise Storage 6","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Enterprise%20Storage%206"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"conmon":"2.1.3-150100.3.9.1"}]},"package":{"ecosystem":"SUSE:Enterprise Storage 7","name":"conmon","purl":"pkg:rpm/suse/conmon&distro=SUSE%20Enterprise%20Storage%207"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.3-150100.3.9.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for conmon fixes the following issues:\n\nconmon was updated to 2.1.3:\n\n* Stop using g_unix_signal_add() to avoid threads\n* Rename CLI optionlog-size-global-max to log-global-size-max \n\nUpdate to version 2.1.2:\n\n* add log-global-size-max option to limit the total output conmon processes (CVE-2022-1708 bsc#1200285)\n* journald: print tag and name if both are specified\n* drop some logs to debug level\n\nUpdate to version 2.1.0\n\n* logging: buffer partial messages to journald\n* exit: close all fds >= 3\n* fix: cgroup: Free memory_cgroup_file_path if open fails.\n  Call g_free instead of free.\n\nUpdate to version 2.0.32\n\n* Fix: Avoid mainfd_std{in,out} sharing the same file descriptor.\n* exit_command: Fix: unset subreaper attribute before running exit command\n\nUpdate to version 2.0.31\n \n* logging: new mode -l passthrough\n* ctr_logs: use container name or ID as SYSLOG_IDENTIFIER for journald\n* conmon: Fix: free userdata files before exec cleanup\n\nUpdate to version 2.0.30:\n\n* Remove unreachable code path\n* exit: report if the exit command was killed\n* exit: fix race zombie reaper\n* conn_sock: allow watchdog messages through the notify socket proxy\n* seccomp: add support for seccomp notify\n\nUpdate to version 2.0.29:\n\n* Reset OOM score back to 0 for container runtime\n* call functions registered with atexit on SIGTERM\n* conn_sock: fix potential segfault\n\nUpdate to version 2.0.27:\n\n* Add CRI-O integration test GitHub action\n* exec: don't fail on EBADFD\n* close_fds: fix close of external fds\n* Add arm64 static build binary\n\nUpdate to version 2.0.26:\n\n* conn_sock: do not fail on EAGAIN\n* fix segfault from a double freed pointer\n* Fix a bug where conmon could never spawn a container, because\n  a disagreement between the caller and itself on where the attach\n  socket was.\n* improve --full-attach to ignore the socket-dir directly. that\n  means callers don't need to specify a socket dir at all (and\n  can remove it)\n* add full-attach option to allow callers to not truncate a very\n  long path for the attach socket\n* close only opened FDs\n* set locale to inherit environment\n\nUpdate to version 2.0.22:\n\n* added man page\n* attach: always chdir\n* conn_sock: Explicitly free a heap-allocated string\n* refactor I/O and add SD_NOTIFY proxy support\n\nUpdate to version 2.0.21:\n\n* protect against kill(-1)\n* Makefile: enable debuginfo generation\n* Remove go.sum file and add go.mod\n* Fail if conmon config could not be written\n* nix: remove double definition for e2fsprogs\n* Speedup static build by utilizing CI cache on `/nix` folder\n* Fix nix build for failing e2fsprogs tests\n* test: fix CI\n* Use Podman for building\n","id":"SUSE-SU-2022:3896-1","modified":"2022-11-08T09:17:04Z","published":"2022-11-08T09:17:04Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223896-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200285"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1708"}],"related":["CVE-2022-1708"],"summary":"Security update for conmon","upstream":["CVE-2022-1708"]}