-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c95d3199c5 2024-06-12 01:31:25.500988 --------------------------------------------------------------------------------
Name : singularity-ce Product : Fedora 39 Version : 3.11.5^20240603gbd4675f Release : 1.fc39 URL : https://www.sylabs.io/singularity/ Summary : Application and environment virtualization Description : SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure.
-------------------------------------------------------------------------------- Update Information:
Bulk update of bundled Go dependencies. -------------------------------------------------------------------------------- ChangeLog:
* Mon Jun 3 2024 David Trudgian dtrudg@sylabs.io - 3.11.5^20240603gbd4675f-1 - Bulk update of bundled Go dependencies. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2268897 - CVE-2024-28180 singularity-ce: jose-go: improper handling of highly compressed data [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2268897 [ 2 ] Bug #2284383 - TRIAGE CVE-2024-3727 singularity-ce: containers/image: digest type does not guarantee valid type [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2284383 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c95d3199c5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org