<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">SUSE-IU-2024:1753-1</DocumentTitle>
  <DocumentType>SUSE Image</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE Image SUSE-IU-2024:1753-1</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2026-03-19T08:53:52Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-11-12T01:00:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-11-12T01:00:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-publiccloud.pl</Engine>
      <Date>2021-02-18T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Image update for SUSE-IU-2024:1753-1 / google/sles-15-sp5-chost-byos-v20241112-arm64</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This image update for google/sles-15-sp5-chost-byos-v20241112-arm64 contains the following changes:
Package curl was updated:

- Security fix: [bsc#1232528, CVE-2024-9681]  * HSTS subdomain overwrites parent cache entry
  * Add curl-CVE-2024-9681.patch

Package lvm2 was updated:

- LVM2 mirror attached to another node couldn't be converted into linear LV (bsc#1231796)  + bug-1231796_lvconvert-fix-lvconvert-m-0-for-in-sync-legs.patch

Package openssl-1_1 was updated:

- Security fix: [bsc#1220262, CVE-2023-50782]  * Implicit rejection in PKCS#1 v1.5
  * Add openssl-CVE-2023-50782.patch

Package python3 was updated:

- Add CVE-2024-9287-venv_path_unquoted.patch to properly quote  path names provided when creating a virtual environment
  (bsc#1232241, CVE-2024-9287)

- Drop .pyc files from docdir for reproducible builds
  (bsc#1230906).

Package libzypp was updated:

- PluginFrame: Send unescaped colons in header values  (bsc#1231043)
  According to the STOMP protocol it would be correct to escape a
  colon in a header-value, but it breaks plugin receivers which do
  not expect this. The first colon separates header-name from
  header-value, so escaping in the header-value is not needed
  anyway.
  Escaping in the header-value affects especially the urlresolver
  plugins. The input URL is passed in a header, but sent back as
  raw data in the frames body. If the plugin receiver does not
  correctly unescape the URL we may get back a &amp;quot;https\c//&amp;quot; which is
  not usable.
- Do not ignore return value of std::remove_if in MediaSyncFacade
  (fixes #579)
- Fix hang in curl code with no network connection (bsc#1230912)
- version 17.35.12 (35)

Package shadow was updated:

- bsc#1230972: Add useradd warnings when requested UID is outside  the default range
- add shadow-bsc1230972-useradd-warning.patch

- bsc#1228337: chage -d date vs passwd -S output is off by one
  Remove shadow-bsc1176006-chage-date.patch

Package 000release-packages:sle-module-basesystem-release was updated:

Package 000release-packages:sle-module-containers-release was updated:

Package 000release-packages:sle-module-public-cloud-release was updated:

Package 000release-packages:sle-module-server-applications-release was updated:

Package wget was updated:

- Update 0001-possibly-truncate-pathname-components.patch  * Take the patch from savannah repository where the checking of the file
    length doesn't include path length.
  * [bsc#1204720, bsc#1231661]

Package wicked was updated:

- Update to version 0.6.77  - compat-suse: use iftype in sysctl handling (bsc#1230911, gh#openSUSE/wicked#1043)
  - Always generate the ipv4/ipv6 &amp;lt;enabled&amp;gt;true|false&amp;lt;/enabled&amp;gt; node
  - Inherit all, default and interface sysctl settings also for loopback,
    except for use_tempaddr and accept_dad.
  - Consider only interface specific accept_redirects sysctl settings.
  - Adopt ifsysctl(5) manual page with wicked specific behavior.
  - route: fix family and destination processing (bsc#1231060)
  - man: improve wicked-config(5) file description (gh#openSUSE/wicked#1039)
  - dhcp4: add ignore-rfc3927-1-6 wicked-config(5) option (jsc#PED-10855, gh#openSUSE/wicked#1038)
  - team: set arp link watcher interval default to 1s (gh#openSUSE/wicked#1037)
  - systemd: use `BindsTo=dbus.service` in favor of `Requisite=` (bsc#1229745)
  - compat-suse: fix use of deprecated `INTERFACETYPE=dummy` (boo#1229555)
  - arp: don't set target broadcast hardware address (gh#openSUSE/wicked#1036)
  - dbus: don't memcpy empty/NULL array value (gh#openSUSE/wicked#1035)
  - ethtool: fix leak and free pause data in ethtool_free (gh#openSUSE/wicked#1030)
- Removed patches included in the source archive:
  [- 0001-compat-suse-repair-dummy-interfaces-boo-1229555.patch]

</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp5-chost-byos-v20241112-arm64/</URL>
      <Description>Public Cloud Image Info</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <Branch Type="Product Name" Name="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
        <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="curl-8.0.1-150400.5.56.1">
      <FullProductName ProductID="curl-8.0.1-150400.5.56.1">curl-8.0.1-150400.5.56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcurl4-8.0.1-150400.5.56.1">
      <FullProductName ProductID="libcurl4-8.0.1-150400.5.56.1">libcurl4-8.0.1-150400.5.56.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2">
      <FullProductName ProductID="libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2">libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgcc_s1-14.2.0+git10526-150000.1.6.1">
      <FullProductName ProductID="libgcc_s1-14.2.0+git10526-150000.1.6.1">libgcc_s1-14.2.0+git10526-150000.1.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libopenssl1_1-1.1.1l-150500.17.37.1">
      <FullProductName ProductID="libopenssl1_1-1.1.1l-150500.17.37.1">libopenssl1_1-1.1.1l-150500.17.37.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_6m1_0-3.6.15-150300.10.75.1">
      <FullProductName ProductID="libpython3_6m1_0-3.6.15-150300.10.75.1">libpython3_6m1_0-3.6.15-150300.10.75.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-14.2.0+git10526-150000.1.6.1">
      <FullProductName ProductID="libstdc++6-14.2.0+git10526-150000.1.6.1">libstdc++6-14.2.0+git10526-150000.1.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libzypp-17.35.12-150500.6.21.1">
      <FullProductName ProductID="libzypp-17.35.12-150500.6.21.1">libzypp-17.35.12-150500.6.21.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="login_defs-4.8.1-150400.10.24.1">
      <FullProductName ProductID="login_defs-4.8.1-150400.10.24.1">login_defs-4.8.1-150400.10.24.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="openssl-1_1-1.1.1l-150500.17.37.1">
      <FullProductName ProductID="openssl-1_1-1.1.1l-150500.17.37.1">openssl-1_1-1.1.1l-150500.17.37.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-3.6.15-150300.10.75.1">
      <FullProductName ProductID="python3-3.6.15-150300.10.75.1">python3-3.6.15-150300.10.75.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-base-3.6.15-150300.10.75.1">
      <FullProductName ProductID="python3-base-3.6.15-150300.10.75.1">python3-base-3.6.15-150300.10.75.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="shadow-4.8.1-150400.10.24.1">
      <FullProductName ProductID="shadow-4.8.1-150400.10.24.1">shadow-4.8.1-150400.10.24.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="suse-build-key-12.0-150000.8.55.1">
      <FullProductName ProductID="suse-build-key-12.0-150000.8.55.1">suse-build-key-12.0-150000.8.55.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="wget-1.20.3-150000.3.23.2">
      <FullProductName ProductID="wget-1.20.3-150000.3.23.2">wget-1.20.3-150000.3.23.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="wicked-0.6.77-150500.3.39.1">
      <FullProductName ProductID="wicked-0.6.77-150500.3.39.1">wicked-0.6.77-150500.3.39.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="wicked-service-0.6.77-150500.3.39.1">
      <FullProductName ProductID="wicked-service-0.6.77-150500.3.39.1">wicked-service-0.6.77-150500.3.39.1</FullProductName>
    </Branch>
    <Relationship ProductReference="curl-8.0.1-150400.5.56.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:curl-8.0.1-150400.5.56.1">curl-8.0.1-150400.5.56.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcurl4-8.0.1-150400.5.56.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libcurl4-8.0.1-150400.5.56.1">libcurl4-8.0.1-150400.5.56.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2">libdevmapper1_03-2.03.22_1.02.196-150500.7.12.2 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgcc_s1-14.2.0+git10526-150000.1.6.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libgcc_s1-14.2.0+git10526-150000.1.6.1">libgcc_s1-14.2.0+git10526-150000.1.6.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libopenssl1_1-1.1.1l-150500.17.37.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libopenssl1_1-1.1.1l-150500.17.37.1">libopenssl1_1-1.1.1l-150500.17.37.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_6m1_0-3.6.15-150300.10.75.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libpython3_6m1_0-3.6.15-150300.10.75.1">libpython3_6m1_0-3.6.15-150300.10.75.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libstdc++6-14.2.0+git10526-150000.1.6.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libstdc++6-14.2.0+git10526-150000.1.6.1">libstdc++6-14.2.0+git10526-150000.1.6.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="libzypp-17.35.12-150500.6.21.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libzypp-17.35.12-150500.6.21.1">libzypp-17.35.12-150500.6.21.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="login_defs-4.8.1-150400.10.24.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:login_defs-4.8.1-150400.10.24.1">login_defs-4.8.1-150400.10.24.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="openssl-1_1-1.1.1l-150500.17.37.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:openssl-1_1-1.1.1l-150500.17.37.1">openssl-1_1-1.1.1l-150500.17.37.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-3.6.15-150300.10.75.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:python3-3.6.15-150300.10.75.1">python3-3.6.15-150300.10.75.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-base-3.6.15-150300.10.75.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:python3-base-3.6.15-150300.10.75.1">python3-base-3.6.15-150300.10.75.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="shadow-4.8.1-150400.10.24.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:shadow-4.8.1-150400.10.24.1">shadow-4.8.1-150400.10.24.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="suse-build-key-12.0-150000.8.55.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:suse-build-key-12.0-150000.8.55.1">suse-build-key-12.0-150000.8.55.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="wget-1.20.3-150000.3.23.2" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:wget-1.20.3-150000.3.23.2">wget-1.20.3-150000.3.23.2 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="wicked-0.6.77-150500.3.39.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:wicked-0.6.77-150500.3.39.1">wicked-0.6.77-150500.3.39.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
    <Relationship ProductReference="wicked-service-0.6.77-150500.3.39.1" RelationType="Default Component Of" RelatesToProductReference="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64">
      <FullProductName ProductID="Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:wicked-service-0.6.77-150500.3.39.1">wicked-service-0.6.77-150500.3.39.1 as a component of Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.</Note>
    </Notes>
    <CVE>CVE-2023-50782</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libopenssl1_1-1.1.1l-150500.17.37.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:openssl-1_1-1.1.1l-150500.17.37.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.</Note>
    </Notes>
    <CVE>CVE-2024-9287</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:python3-3.6.15-150300.10.75.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.

This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.

(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)

When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *bleed over* and get set for the
parent domain `example.com` in curl's HSTS cache.

The result of a triggered bug is that HTTP accesses to `example.com` get
converted to HTTPS for a different period of time than what was asked for by
the origin server. If `example.com` for example stops supporting HTTPS at its
expiry time, curl might then fail to access `http://example.com` until the
(wrongly set) timeout expires. This bug can also expire the parent's entry
*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier
than otherwise intended.</Note>
    </Notes>
    <CVE>CVE-2024-9681</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:curl-8.0.1-150400.5.56.1</ProductID>
        <ProductID>Public Cloud Image google/sles-15-sp5-chost-byos-v20241112-arm64:libcurl4-8.0.1-150400.5.56.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
  </Vulnerability>
</cvrfdoc>
