File _patchinfo of Package patchinfo.38055

<patchinfo incident="38055">
  <issue tracker="bnc" id="1219437">VUL-0: CVE-2024-23650: buildkit: BuildKit daemon could crash via malicious BuildKit client or frontend request</issue>
  <issue tracker="bnc" id="1239185">VUL-0: CVE-2025-22868: TRACKERBUG: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2</issue>
  <issue tracker="bnc" id="1239322">VUL-0: CVE-2025-22869: TRACKERBUG: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh</issue>
  <issue tracker="bnc" id="1237367">docker pulls in container-selinux unconditionally</issue>
  <issue tracker="bnc" id="1234089">VUL-0: CVE-2024-29018: docker: moby: external DNS requests from 'internal' networks could lead to data exfiltration</issue>
  <issue tracker="cve" id="2024-23653"/>
  <issue tracker="cve" id="2024-23650"/>
  <issue tracker="cve" id="2024-2365"/>
  <issue tracker="cve" id="2024-41110"/>
  <issue tracker="cve" id="2024-29018"/>
  <issue tracker="cve" id="2025-22868"/>
  <issue tracker="cve" id="2025-22869"/>
  <packager>cyphar</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for docker, docker-stable</summary>
  <description>This update for docker, docker-stable fixes the following issues:

- CVE-2025-22868: Fixed unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239185).
- CVE-2025-22869: Fixed Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239322).
- CVE-2024-29018: Fixed external DNS requests from 'internal' networks leading to data exfiltration (bsc#1234089).
- CVE-2024-23650: Fixed BuildKit daemon crash via malicious BuildKit client or frontend request (bsc#1219437).

Other fixes:
- Make container-selinux requirement conditional on selinux-policy (bsc#1237367).
- Updated docker-buildx to 0.19.3.
</description>
</patchinfo>
openSUSE Build Service is sponsored by