File _patchinfo of Package patchinfo.36514
<patchinfo incident="36514">
<issue tracker="bnc" id="1228324">VUL-0: CVE-2024-41110: docker: Authz zero length regression</issue>
<issue tracker="bnc" id="1214855">umarshalling volume options for volume: unexpected end of JSON input</issue>
<issue tracker="bnc" id="1230331">docker: add Requires for docker-buildx</issue>
<issue tracker="bnc" id="1230333">docker-buildx: move to be a subpackage of Docker</issue>
<issue tracker="bnc" id="1231348">Issues on remount of tmpfs mount/secrets</issue>
<issue tracker="bnc" id="1221916">SLES15-SP4: Docker buildx build fails to COPY from build stage using nested links</issue>
<issue tracker="cve" id="2024-41110"/>
<packager>cyphar</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for docker-stable</summary>
<description>This update for docker-stable fixes the following issues:
- CVE-2024-41110: Fixed Authz zero length regression (bsc#1228324).
Bug fixes:
- Allow users to disable SUSE secrets support by setting DOCKER_SUSE_SECRETS_ENABLE=0 in /etc/sysconfig/docker (bsc#1231348).
- Import specfile changes for docker-buildx as well as the changes to help reduce specfile differences between docker-stable and docker (bsc#1230331, bsc#1230333).
- Fix BuildKit's symlink resolution logic to correctly handle non-lexical symlinks (bsc#1221916).
- Write volume options atomically so sudden system crashes won't result in future Docker starts failing due to empty files (bsc#1214855).
</description>
</patchinfo>