Vulnerability Scan Report for registry.suse.com/bci/bci-init:15.5.18.4
Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: July 02, 2025 20:10

Systemd environment for containers based on the SLE Base Container Image. This container is only supported with podman.
Last scanned on: July 02, 2025 20:10
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
openssl-1_1 | MEDIUM | fixed |
Security update for openssl-1_1 Vulnerability ID: SUSE-SU-2025:0345-1 Installed Version: 1.1.1l-150500.17.25.1 Fixed Version: 1.1.1l-150500.17.40.1 This update for openssl-1_1 fixes the following issues: - CVE-2024-13176: Fixed timing side-channel in the ECDSA signature computation (bsc#1236136) |
||
pam | HIGH | fixed |
Security update for pam Vulnerability ID: SUSE-SU-2025:02013-1 Installed Version: 1.3.0-150000.6.66.1 Fixed Version: 1.3.0-150000.6.83.1 This update for pam fixes the following issues: - CVE-2025-6018: pam_env: Change the default to not read the user .pam_environment file (bsc#1243226). - CVE-2025-6020: pam_namespace: convert functions that may operate on a user-controlled path to operate on file descriptors instead of absolute path (bsc#1244509). |
||
pam-config | HIGH | fixed |
Security update for pam-config Vulnerability ID: SUSE-SU-2025:02082-1 Installed Version: 1.1-150200.3.6.1 Fixed Version: 1.1-150200.3.14.1 This update for pam-config fixes the following issues: - CVE-2025-6018: Stop adding pam_env in AUTH stack, and be sure to put this module at the really end of the SESSION stack (bsc#1243226). |
||
procps | LOW | fixed |
Security update for procps Vulnerability ID: SUSE-SU-2025:0741-1 Installed Version: 3.3.17-150000.7.37.1 Fixed Version: 3.3.17-150000.7.42.1 This update for procps fixes the following issues: - Integer overflow due to incomplete fix for CVE-2023-4016 can lead to segmentation fault in ps command when pid argument has a leading space (bsc#1236842, bsc#1214290). |
||
shadow | MEDIUM | fixed |
Security update for shadow Vulnerability ID: SUSE-SU-2024:2658-1 Installed Version: 4.8.1-150400.10.15.1 Fixed Version: 4.8.1-150400.10.18.1 This update for shadow fixes the following issues: - CVE-2013-4235: Fixed a race condition when copying and removing directory trees (bsc#916845). |