Vulnerability Scan Report for registry.suse.com/bci/php-fpm:8.2.20
PHP-FPM 8 container based on the SLE Base Container Image.
Last scanned on: July 05, 2025 15:34

PHP-FPM 8 container based on the SLE Base Container Image.
Last scanned on: July 05, 2025 15:34
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libxml2-2 | MEDIUM | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2025:1438-1 Installed Version: 2.10.3-150500.5.17.1 Fixed Version: 2.10.3-150500.5.26.1 This update for libxml2 fixes the following issues: - CVE-2025-32414: Fixed an out-of-bounds read when parsing text via the Python API. (bsc#1241551) - CVE-2025-32415: Fixed a crafted XML document may lead to a heap-based buffer under-read. (bsc#1241453) |
||
openssl-3 | HIGH | fixed |
Security update for openssl-3 Vulnerability ID: SUSE-SU-2025:1550-1 Installed Version: 3.1.4-150600.5.18.1 Fixed Version: 3.1.4-150600.5.27.1 This update for openssl-3 fixes the following issues: Security: - CVE-2025-27587: Timing side channel vulnerability in the P-384 implementation when used with ECDSA in the PPC architecture (bsc#1240366). - Missing null pointer check before accessing handshake_func in ssl_lib.c (bsc#1240607). FIPS: - Disabling EMS in OpenSSL configuration prevents sshd from starting (bsc#1230959, bsc#1232326, bsc#1231748). |
||
openssl-3 | MEDIUM | fixed |
Security update for openssl-3 Vulnerability ID: SUSE-SU-2024:3943-1 Installed Version: 3.1.4-150600.5.18.1 Fixed Version: 3.1.4-150600.5.21.1 This update for openssl-3 fixes the following issues: - CVE-2023-50782: Implicit rejection in PKCS#1 v1.5 (bsc#1220262) |
||
openssl-3 | MEDIUM | fixed |
Security update for openssl-3 Vulnerability ID: SUSE-SU-2025:0430-1 Installed Version: 3.1.4-150600.5.18.1 Fixed Version: 3.1.4-150600.5.24.1 This update for openssl-3 fixes the following issues: - CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation (bsc#1236136). |
||
pam | HIGH | fixed |
Security update for pam Vulnerability ID: SUSE-SU-2025:02013-1 Installed Version: 1.3.0-150000.6.71.2 Fixed Version: 1.3.0-150000.6.83.1 This update for pam fixes the following issues: - CVE-2025-6018: pam_env: Change the default to not read the user .pam_environment file (bsc#1243226). - CVE-2025-6020: pam_namespace: convert functions that may operate on a user-controlled path to operate on file descriptors instead of absolute path (bsc#1244509). |