Vulnerability Scan Report for registry.suse.com/bci/bci-init:15.5.14.30
Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: July 07, 2025 22:50

Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: July 07, 2025 22:50
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:2891-1 Installed Version: 1.1.1l-150500.17.25.1 Fixed Version: 1.1.1l-150500.17.34.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138) Other fixes: - Build with no-afalgeng (bsc#1226463) |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2024:3765-1 Installed Version: 1.1.1l-150500.17.25.1 Fixed Version: 1.1.1l-150500.17.37.1 This update for openssl-1_1 fixes the following issues: - CVE-2023-50782: Implicit rejection in PKCS#1 v1.5 (bsc#1220262) |
||
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2025:0345-1 Installed Version: 1.1.1l-150500.17.25.1 Fixed Version: 1.1.1l-150500.17.40.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-13176: Fixed timing side-channel in the ECDSA signature computation (bsc#1236136) |
||
pam | HIGH | fixed |
Security update for pam Vulnerability ID: SUSE-SU-2025:02013-1 Installed Version: 1.3.0-150000.6.66.1 Fixed Version: 1.3.0-150000.6.83.1 This update for pam fixes the following issues: - CVE-2025-6018: pam_env: Change the default to not read the user .pam_environment file (bsc#1243226). - CVE-2025-6020: pam_namespace: convert functions that may operate on a user-controlled path to operate on file descriptors instead of absolute path (bsc#1244509). |
||
pam-config | HIGH | fixed |
Security update for pam-config Vulnerability ID: SUSE-SU-2025:02082-1 Installed Version: 1.1-3.3.1 Fixed Version: 1.1-150200.3.14.1 This update for pam-config fixes the following issues: - CVE-2025-6018: Stop adding pam_env in AUTH stack, and be sure to put this module at the really end of the SESSION stack (bsc#1243226). |