--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2024-c95d3199c5
2024-06-12 01:31:25.500988
--------------------------------------------------------------------------------
Name : singularity-ce
Product : Fedora 39
Version : 3.11.5^20240603gbd4675f
Release : 1.fc39
URL :
https://www.sylabs.io/singularity/
Summary : Application and environment virtualization
Description :
SingularityCE is the Community Edition of Singularity, an open source
container platform designed to be simple, fast, and secure.
--------------------------------------------------------------------------------
Update Information:
Bulk update of bundled Go dependencies.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jun 3 2024 David Trudgian <dtrudg(a)sylabs.io> - 3.11.5^20240603gbd4675f-1
- Bulk update of bundled Go dependencies.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2268897 - CVE-2024-28180 singularity-ce: jose-go: improper handling of highly
compressed data [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2268897
[ 2 ] Bug #2284383 - TRIAGE CVE-2024-3727 singularity-ce: containers/image: digest type
does not guarantee valid type [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2284383
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2024-c95d3199c5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------