Vulnerability Scan Report for registry.suse.com/bci/golang:1.20-2.18
Go 1.21 development container based on the SLE Base Container Image.
Last scanned on: May 19, 2025 05:56

Go 1.21 development container based on the SLE Base Container Image.
Last scanned on: May 19, 2025 05:56
Package Name | Severity | Status | Description | Reference links | |
---|---|---|---|---|---|
libxml2-2 | HIGH | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2025:0341-1 Installed Version: 2.9.14-150400.5.13.1 Fixed Version: 2.9.14-150400.5.35.1 This update for libxml2 fixes the following issues: - CVE-2022-49043: Fixed a use-after-free in xmlXIncludeAddNode. (bsc#1236460) |
||
libxml2-2 | HIGH | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2025:0748-1 Installed Version: 2.9.14-150400.5.13.1 Fixed Version: 2.9.14-150400.5.38.1 This update for libxml2 fixes the following issues: - CVE-2024-56171: use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c (bsc#1237363). - CVE-2025-24928: stack-based buffer overflow in xmlSnprintfElements in valid.c (bsc#1237370). - CVE-2025-27113: NULL pointer dereference in xmlPatMatch in pattern.c (bsc#1237418). |
||
libxml2-2 | MEDIUM | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2023:2053-1 Installed Version: 2.9.14-150400.5.13.1 Fixed Version: 2.9.14-150400.5.16.1 This update for libxml2 fixes the following issues: - CVE-2023-29469: Fixed inconsistent result when hashing empty strings (bsc#1210412). - CVE-2023-28484: Fixed NULL pointer dereference in xmlSchemaFixupComplexType (bsc#1210411). The following non-security bug was fixed: - Remove unneeded dependency (bsc#1209918). |
||
libxml2-2 | MEDIUM | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2023:3699-1 Installed Version: 2.9.14-150400.5.13.1 Fixed Version: 2.9.14-150400.5.22.1 This update for libxml2 fixes the following issues: - CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768). |
||
libxml2-2 | MEDIUM | fixed |
Security update for libxml2 Vulnerability ID: SUSE-SU-2023:4537-1 Installed Version: 2.9.14-150400.5.13.1 Fixed Version: 2.9.14-150400.5.25.1 This update for libxml2 fixes the following issues: - CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129). |