Container summary for ses/7.1/ceph/haproxy


SUSE-CU-2023:3072-1

Container Advisory IDSUSE-CU-2023:3072-1
Container Tagsses/7.1/ceph/haproxy:2.0.31 , ses/7.1/ceph/haproxy:2.0.31.3.5.503 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.503
The following patches have been included in this update:
Advisory IDSUSE-RU-2023:2497-1
ReleasedTue Jun 13 15:37:25 2023
SummaryRecommended update for libzypp
Typerecommended
Severityimportant
References1211661,1212187
Description:

This update for libzypp fixes the following issues:


Advisory IDSUSE-RU-2023:2625-1
ReleasedFri Jun 23 17:16:11 2023
SummaryRecommended update for gcc12
Typerecommended
Severitymoderate
References
Description:

This update for gcc12 fixes the following issues:


* includes regression and other bug fixes


Advisory IDSUSE-SU-2023:2640-1
ReleasedMon Jun 26 15:09:10 2023
SummarySecurity update for vim
Typesecurity
Severitymoderate
References1210996,1211256,1211257,CVE-2023-2426,CVE-2023-2609,CVE-2023-2610
Description:

This update for vim fixes the following issues:


Advisory IDSUSE-RU-2023:2742-1
ReleasedFri Jun 30 11:40:56 2023
SummaryRecommended update for autoyast2, libzypp, yast2-pkg-bindings, yast2-update, zypper
Typerecommended
Severitymoderate
References1202234,1209565,1211261,1212187,1212222
Description:

This update for yast2-pkg-bindings fixes the following issues:
libzypp was updated to version 17.31.14 (22):


zypper was updated to version 1.14.61:

yast2-pkg-bindings, autoyast:

yast2-update:


Advisory IDSUSE-RU-2023:2855-1
ReleasedMon Jul 17 16:35:21 2023
SummaryRecommended update for openldap2
Typerecommended
Severitymoderate
References1212260
Description:

This update for openldap2 fixes the following issues:


Advisory IDSUSE-SU-2023:2879-1
ReleasedWed Jul 19 09:45:34 2023
SummarySecurity update for dbus-1
Typesecurity
Severitymoderate
References1212126,CVE-2023-34969
Description:

This update for dbus-1 fixes the following issues:


Advisory IDSUSE-SU-2023:2882-1
ReleasedWed Jul 19 11:49:39 2023
SummarySecurity update for perl
Typesecurity
Severityimportant
References1210999,CVE-2023-31484
Description:

This update for perl fixes the following issues:

- CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).


Advisory IDSUSE-RU-2023:2885-1
ReleasedWed Jul 19 16:58:43 2023
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1208721,1209229,1211828
Description:

This update for glibc fixes the following issues:


Advisory IDSUSE-RU-2023:2918-1
ReleasedThu Jul 20 12:00:17 2023
SummaryRecommended update for gpgme
Typerecommended
Severitymoderate
References1089497
Description:

This update for gpgme fixes the following issues:
gpgme:

libassuan:


Advisory IDSUSE-SU-2023:2956-1
ReleasedTue Jul 25 08:33:38 2023
SummarySecurity update for libcap
Typesecurity
Severitymoderate
References1211419,CVE-2023-2603
Description:

This update for libcap fixes the following issues:


Advisory IDSUSE-SU-2023:3179-1
ReleasedThu Aug 3 13:59:38 2023
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1201627,1207534,1213487,CVE-2022-4304,CVE-2023-3446
Description:

This update for openssl-1_1 fixes the following issues:



Advisory IDSUSE-SU-2023:3210-1
ReleasedMon Aug 7 15:20:04 2023
SummarySecurity update for pcre2
Typesecurity
Severitymoderate
References1213514,CVE-2022-41409
Description:

This update for pcre2 fixes the following issues:
- CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514).


Advisory IDSUSE-RU-2023:3218-1
ReleasedMon Aug 7 16:52:13 2023
SummaryRecommended update for cryptsetup
Typerecommended
Severitymoderate
References1211079
Description:

This update for cryptsetup fixes the following issues:


Advisory IDSUSE-RU-2023:3270-1
ReleasedThu Aug 10 19:34:35 2023
SummaryRecommended update for vim
Typerecommended
Severitymoderate
References1211461
Description:

This update for vim fixes the following issues:


Advisory IDSUSE-RU-2023:3284-1
ReleasedFri Aug 11 10:29:50 2023
SummaryRecommended update for shadow
Typerecommended
Severitymoderate
References1206627,1213189
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-SU-2023:3291-1
ReleasedFri Aug 11 12:51:21 2023
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1213517,1213853,CVE-2023-3817
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-SU-2023:3365-1
ReleasedFri Aug 18 20:35:01 2023
SummarySecurity update for krb5
Typesecurity
Severityimportant
References1214054,CVE-2023-36054
Description:

This update for krb5 fixes the following issues:


Advisory IDSUSE-SU-2023:3472-1
ReleasedTue Aug 29 10:55:16 2023
SummarySecurity update for procps
Typesecurity
Severitylow
References1214290,CVE-2023-4016
Description:

This update for procps fixes the following issues:
- CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290).


Advisory IDSUSE-RU-2023:3487-1
ReleasedTue Aug 29 14:28:35 2023
SummaryRecommended update for lvm2
Typerecommended
Severitymoderate
References1214071
Description:

This update for lvm2 fixes the following issues:


Advisory IDSUSE-SU-2023:3490-1
ReleasedWed Aug 30 13:58:47 2023
SummarySecurity update for haproxy
Typesecurity
Severitymoderate
References1214102,CVE-2023-40225
Description:

This update for haproxy fixes the following issues:


Advisory IDSUSE-RU-2023:3515-1
ReleasedFri Sep 1 15:54:25 2023
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitymoderate
References1158763,1210740,1213231,1213557,1213673
Description:

This update for libzypp, zypper fixes the following issues:


Advisory IDSUSE-SU-2023:3639-1
ReleasedMon Sep 18 13:33:16 2023
SummarySecurity update for libeconf
Typesecurity
Severitymoderate
References1198165,1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181
Description:

This update for libeconf fixes the following issues:
Update to version 0.5.2.


The following non-security bug was fixed:


Advisory IDSUSE-SU-2023:3661-1
ReleasedMon Sep 18 21:44:09 2023
SummarySecurity update for gcc12
Typesecurity
Severityimportant
References1214052,CVE-2023-4039
Description:

This update for gcc12 fixes the following issues:


Advisory IDSUSE-SU-2023:3698-1
ReleasedWed Sep 20 11:01:15 2023
SummarySecurity update for libxml2
Typesecurity
Severityimportant
References1214768,CVE-2023-39615
Description:

This update for libxml2 fixes the following issues:


SUSE-CU-2023:1837-1

Container Advisory IDSUSE-CU-2023:1837-1
Container Tagsses/7.1/ceph/haproxy:2.0.31 , ses/7.1/ceph/haproxy:2.0.31.3.5.422 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.422
The following patches have been included in this update:
Advisory IDSUSE-RU-2023:2133-1
ReleasedTue May 9 13:37:10 2023
SummaryRecommended update for zlib
Typerecommended
Severitymoderate
References1206513
Description:

This update for zlib fixes the following issues:


Advisory IDSUSE-SU-2023:2227-1
ReleasedWed May 17 09:57:41 2023
SummarySecurity update for curl
Typesecurity
Severityimportant
References1211231,1211232,1211233,1211339,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-RU-2023:2237-1
ReleasedWed May 17 17:10:07 2023
SummaryRecommended update for vim
Typerecommended
Severitymoderate
References1211144
Description:

This update for vim fixes the following issues:


Advisory IDSUSE-RU-2023:2247-1
ReleasedThu May 18 17:04:38 2023
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitymoderate
References1127591,1195633,1208329,1209406,1210870
Description:

This update for libzypp, zypper fixes the following issues:


Advisory IDSUSE-RU-2023:2333-1
ReleasedWed May 31 09:01:28 2023
SummaryRecommended update for zlib
Typerecommended
Severitymoderate
References1210593
Description:

This update for zlib fixes the following issue:


Advisory IDSUSE-SU-2023:2343-1
ReleasedThu Jun 1 11:35:28 2023
SummarySecurity update for openssl-1_1
Typesecurity
Severityimportant
References1211430,CVE-2023-2650
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-RU-2023:2365-1
ReleasedMon Jun 5 09:22:46 2023
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1210164
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-SU-2023:2484-1
ReleasedMon Jun 12 08:49:58 2023
SummarySecurity update for openldap2
Typesecurity
Severitymoderate
References1211795,CVE-2023-2953
Description:

This update for openldap2 fixes the following issues:


SUSE-CU-2023:1459-1

Container Advisory IDSUSE-CU-2023:1459-1
Container Tagsses/7.1/ceph/haproxy:2.0.31 , ses/7.1/ceph/haproxy:2.0.31.3.5.391 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.391
The following patches have been included in this update:
Advisory IDSUSE-RU-2023:714-1
ReleasedMon Mar 13 10:53:25 2023
SummaryRecommended update for rpm
Typerecommended
Severityimportant
References1207294
Description:

This update for rpm fixes the following issues:


Advisory IDSUSE-RU-2023:776-1
ReleasedThu Mar 16 17:29:23 2023
SummaryRecommended update for gcc12
Typerecommended
Severitymoderate
References
Description:

This update for gcc12 fixes the following issues:
This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes

This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided in the SUSE Linux Enterprise Module for Development Tools.
To use gcc12 compilers use:


For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html


Advisory IDSUSE-SU-2023:781-1
ReleasedThu Mar 16 19:07:00 2023
SummarySecurity update for vim
Typesecurity
Severityimportant
References1207780,1208828,1208957,1208959,CVE-2023-0512,CVE-2023-1127,CVE-2023-1170,CVE-2023-1175
Description:

This update for vim fixes the following issues:


Updated to version 9.0 with patch level 1386.


Advisory IDSUSE-RU-2023:786-1
ReleasedThu Mar 16 19:36:09 2023
SummaryRecommended update for libsolv, libzypp, zypper
Typerecommended
Severityimportant
References1178233,1203248,1203249,1203715,1204548,1204956,1205570,1205636,1206949
Description:

This update for libsolv, libzypp, zypper fixes the following issues:
libsolv:


libzypp:

zypper:


Advisory IDSUSE-SU-2023:1711-1
ReleasedFri Mar 31 13:33:04 2023
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1207992,1209209,1209210,1209211,1209212,1209214,CVE-2023-23916,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-SU-2023:1718-1
ReleasedFri Mar 31 15:47:34 2023
SummarySecurity update for glibc
Typesecurity
Severitymoderate
References1207571,1207957,1207975,1208358,CVE-2023-0687
Description:

This update for glibc fixes the following issues:
Security issue fixed:


Other issues fixed:


Advisory IDSUSE-RU-2023:1753-1
ReleasedTue Apr 4 11:55:00 2023
SummaryRecommended update for systemd-presets-common-SUSE
Typerecommended
Severitymoderate
References
Description:

This update for systemd-presets-common-SUSE fixes the following issue:


Advisory IDSUSE-SU-2023:1790-1
ReleasedThu Apr 6 15:36:15 2023
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1209624,1209873,1209878,CVE-2023-0464,CVE-2023-0465,CVE-2023-0466
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-RU-2023:1805-1
ReleasedTue Apr 11 10:12:41 2023
SummaryRecommended update for timezone
Typerecommended
Severityimportant
References
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2023:1945-1
ReleasedFri Apr 21 14:13:27 2023
SummaryRecommended update for elfutils
Typerecommended
Severitymoderate
References1203599
Description:

This update for elfutils fixes the following issues:


Advisory IDSUSE-SU-2023:2048-1
ReleasedWed Apr 26 21:05:45 2023
SummarySecurity update for libxml2
Typesecurity
Severityimportant
References1065270,1199132,1204585,1210411,1210412,CVE-2021-3541,CVE-2022-29824,CVE-2023-28484,CVE-2023-29469
Description:

This update for libxml2 fixes the following issues:



Advisory IDSUSE-SU-2023:2070-1
ReleasedFri Apr 28 13:56:33 2023
SummarySecurity update for shadow
Typesecurity
Severitymoderate
References1210507,CVE-2023-29383
Description:

This update for shadow fixes the following issues:


Advisory IDSUSE-SU-2023:2074-1
ReleasedFri Apr 28 17:02:25 2023
SummarySecurity update for zstd
Typesecurity
Severitymoderate
References1209533,CVE-2022-4899
Description:

This update for zstd fixes the following issues:


Advisory IDSUSE-SU-2023:2076-1
ReleasedFri Apr 28 17:35:05 2023
SummarySecurity update for glib2
Typesecurity
Severitymoderate
References1209713,1209714,1210135,CVE-2023-24593,CVE-2023-25180
Description:

This update for glib2 fixes the following issues:


The following non-security bug was fixed:


Advisory IDSUSE-SU-2023:2103-1
ReleasedThu May 4 20:05:44 2023
SummarySecurity update for vim
Typesecurity
Severitymoderate
References1208828,1209042,1209187,CVE-2023-1127,CVE-2023-1264,CVE-2023-1355
Description:

This update for vim fixes the following issues:
Updated to version 9.0 with patch level 1443, fixes the following security problems


Advisory IDSUSE-RU-2023:2104-1
ReleasedThu May 4 21:05:30 2023
SummaryRecommended update for procps
Typerecommended
Severitymoderate
References1209122
Description:

This update for procps fixes the following issue:


Advisory IDSUSE-SU-2023:2111-1
ReleasedFri May 5 14:34:00 2023
SummarySecurity update for ncurses
Typesecurity
Severitymoderate
References1210434,CVE-2023-29491
Description:

This update for ncurses fixes the following issues:


Advisory IDSUSE-feature-2023:2119-1
ReleasedFri May 5 22:28:54 2023
SummaryFeature update for haproxy
Typefeature
Severitymoderate
References1207181,1208132,CVE-2023-0056,CVE-2023-25725
Description:

This update for haproxy fixes the following issues:
Update to version 2.0.31 (jsc#PED-3821):


SUSE-CU-2023:628-1

Container Advisory IDSUSE-CU-2023:628-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.338 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.338
The following patches have been included in this update:
Advisory IDSUSE-RU-2023:676-1
ReleasedWed Mar 8 14:33:23 2023
SummaryRecommended update for libxml2
Typerecommended
Severitymoderate
References1204585
Description:

This update for libxml2 fixes the following issues:


SUSE-CU-2023:499-1

Container Advisory IDSUSE-CU-2023:499-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.330 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.330
The following patches have been included in this update:
Advisory IDSUSE-SU-2022:3766-1
ReleasedWed Oct 26 11:38:01 2022
SummarySecurity update for buildah
Typesecurity
Severityimportant
References1167864,1181961,1202812,CVE-2020-10696,CVE-2021-20206,CVE-2022-2990
Description:

This update for buildah fixes the following issues:


Buildah was updated to version 1.27.1:



Update to version 1.27.0:


Update to version 1.26.4:

Update to version 1.26.3:

Drop requires on apparmor pattern, should be moved elsewhere for systems which want AppArmor instead of SELinux.

Update to version 1.26.2:

Update to version 1.26.1:


Advisory IDSUSE-SU-2022:3773-1
ReleasedWed Oct 26 12:19:29 2022
SummarySecurity update for curl
Typesecurity
Severityimportant
References1204383,CVE-2022-32221
Description:

This update for curl fixes the following issues:
- CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383).


Advisory IDSUSE-RU-2022:3776-1
ReleasedWed Oct 26 14:06:43 2022
SummaryRecommended update for permissions
Typerecommended
Severityimportant
References1203911,1204137
Description:

This update for permissions fixes the following issues:


Advisory IDSUSE-SU-2022:3805-1
ReleasedThu Oct 27 17:19:46 2022
SummarySecurity update for dbus-1
Typesecurity
Severityimportant
References1087072,1204111,1204112,1204113,CVE-2022-42010,CVE-2022-42011,CVE-2022-42012
Description:

This update for dbus-1 fixes the following issues:
- CVE-2022-42010: Fixed potential crash that could be triggered by an invalid signature (bsc#1204111). - CVE-2022-42011: Fixed an out of bounds read caused by a fixed length array (bsc#1204112). - CVE-2022-42012: Fixed a use-after-free that could be trigged by a message in non-native endianness with out-of-band Unix file descriptor (bsc#1204113).
Bugfixes:
- Disable asserts (bsc#1087072).


Advisory IDSUSE-SU-2022:3871-1
ReleasedFri Nov 4 13:26:29 2022
SummarySecurity update for libxml2
Typesecurity
Severityimportant
References1201978,1204366,1204367,CVE-2016-3709,CVE-2022-40303,CVE-2022-40304
Description:

This update for libxml2 fixes the following issues:
- CVE-2016-3709: Fixed possible XSS vulnerability (bsc#1201978). - CVE-2022-40303: Fixed integer overflows with XML_PARSE_HUGE (bsc#1204366). - CVE-2022-40304: Fixed dict corruption caused by entity reference cycles (bsc#1204367).


Advisory IDSUSE-RU-2022:3901-1
ReleasedTue Nov 8 10:50:06 2022
SummaryRecommended update for openssl-1_1
Typerecommended
Severitymoderate
References1180995,1203046
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-RU-2022:3910-1
ReleasedTue Nov 8 13:05:04 2022
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References
Description:

This update for pam fixes the following issue:


Advisory IDSUSE-SU-2022:3912-1
ReleasedTue Nov 8 13:38:11 2022
SummarySecurity update for expat
Typesecurity
Severityimportant
References1204708,CVE-2022-43680
Description:

This update for expat fixes the following issues:
- CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).


Advisory IDSUSE-SU-2022:3922-1
ReleasedWed Nov 9 09:03:33 2022
SummarySecurity update for protobuf
Typesecurity
Severityimportant
References1194530,1203681,1204256,CVE-2021-22569,CVE-2022-1941,CVE-2022-3171
Description:

This update for protobuf fixes the following issues:


Advisory IDSUSE-RU-2022:3961-1
ReleasedMon Nov 14 07:33:50 2022
SummaryRecommended update for zlib
Typerecommended
Severityimportant
References1203652
Description:

This update for zlib fixes the following issues:


Advisory IDSUSE-RU-2022:3973-1
ReleasedMon Nov 14 15:38:25 2022
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1201959,1204211
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-SU-2022:4056-1
ReleasedThu Nov 17 15:38:08 2022
SummarySecurity update for systemd
Typesecurity
Severitymoderate
References1204179,1204968,CVE-2022-3821
Description:

This update for systemd fixes the following issues:




Advisory IDSUSE-RU-2022:4066-1
ReleasedFri Nov 18 10:43:00 2022
SummaryRecommended update for timezone
Typerecommended
Severityimportant
References1177460,1202324,1204649,1205156
Description:

This update for timezone fixes the following issues:
Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156):


Advisory IDSUSE-SU-2022:4081-1
ReleasedFri Nov 18 15:40:46 2022
SummarySecurity update for dpkg
Typesecurity
Severitylow
References1199944,CVE-2022-1664
Description:

This update for dpkg fixes the following issues:


Advisory IDSUSE-RU-2022:4198-1
ReleasedWed Nov 23 13:15:04 2022
SummaryRecommended update for rpm
Typerecommended
Severitymoderate
References1202750
Description:

This update for rpm fixes the following issues:


Advisory IDSUSE-RU-2022:4256-1
ReleasedMon Nov 28 12:36:32 2022
SummaryRecommended update for gcc12
Typerecommended
Severitymoderate
References
Description:

This update for gcc12 fixes the following issues:
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
The Go, D and Ada language compiler parts are available unsupported via the PackageHub repositories.
To use gcc12 compilers use:


For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html


Advisory IDSUSE-RU-2022:4270-1
ReleasedTue Nov 29 13:20:45 2022
SummaryRecommended update for lvm2
Typerecommended
Severitymoderate
References1198523,1199074,1203216
Description:

This update for lvm2 fixes the following issues:


Advisory IDSUSE-SU-2022:4282-1
ReleasedTue Nov 29 15:50:15 2022
SummarySecurity update for vim
Typesecurity
Severityimportant
References1192478,1202962,1203110,1203152,1203155,1203194,1203272,1203508,1203509,1203796,1203797,1203799,1203820,1203924,1204779,CVE-2021-3928,CVE-2022-2980,CVE-2022-2982,CVE-2022-3037,CVE-2022-3099,CVE-2022-3134,CVE-2022-3153,CVE-2022-3234,CVE-2022-3235,CVE-2022-3278,CVE-2022-3296,CVE-2022-3297,CVE-2022-3324,CVE-2022-3352,CVE-2022-3705
Description:

This update for vim fixes the following issues:
Updated to version 9.0 with patch level 0814:


Advisory IDSUSE-SU-2022:4628-1
ReleasedWed Dec 28 09:23:13 2022
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1206337,CVE-2022-46908
Description:

This update for sqlite3 fixes the following issues:


Advisory IDSUSE-SU-2022:4630-1
ReleasedWed Dec 28 09:25:18 2022
SummarySecurity update for systemd
Typesecurity
Severityimportant
References1200723,1203857,1204423,1205000,CVE-2022-4415
Description:

This update for systemd fixes the following issues:


Bug fixes:


Advisory IDSUSE-SU-2022:4631-1
ReleasedWed Dec 28 09:29:15 2022
SummarySecurity update for vim
Typesecurity
Severityimportant
References1204779,1205797,1206028,1206071,1206072,1206075,1206077,CVE-2022-3491,CVE-2022-3520,CVE-2022-3591,CVE-2022-3705,CVE-2022-4141,CVE-2022-4292,CVE-2022-4293
Description:

This update for vim fixes the following issues:
Updated to version 9.0.1040:


Advisory IDSUSE-SU-2022:4633-1
ReleasedWed Dec 28 09:32:15 2022
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1206309,CVE-2022-43552
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-RU-2023:25-1
ReleasedThu Jan 5 09:51:41 2023
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:
Version update from 2022f to 2022g (bsc#1177460):


Advisory IDSUSE-RU-2023:48-1
ReleasedMon Jan 9 10:37:54 2023
SummaryRecommended update for libtirpc
Typerecommended
Severitymoderate
References1199467
Description:

This update for libtirpc fixes the following issues:


Advisory IDSUSE-SU-2023:56-1
ReleasedMon Jan 9 11:13:43 2023
SummarySecurity update for libksba
Typesecurity
Severitymoderate
References1206579,CVE-2022-47629
Description:

This update for libksba fixes the following issues:


Advisory IDSUSE-RU-2023:157-1
ReleasedThu Jan 26 15:54:43 2023
SummaryRecommended update for util-linux
Typerecommended
Severitymoderate
References1194038,1205646
Description:

This update for util-linux fixes the following issues:


Advisory IDSUSE-SU-2023:174-1
ReleasedThu Jan 26 20:52:38 2023
SummarySecurity update for glib2
Typesecurity
Severitylow
References1183533,CVE-2021-28153
Description:

This update for glib2 fixes the following issues:


Advisory IDSUSE-RU-2023:176-1
ReleasedThu Jan 26 20:56:20 2023
SummaryRecommended update for permissions
Typerecommended
Severitymoderate
References1206738
Description:

This update for permissions fixes the following issues:
Update to version 20181225:


Advisory IDSUSE-RU-2023:181-1
ReleasedThu Jan 26 21:55:43 2023
SummaryRecommended update for procps
Typerecommended
Severitylow
References1206412
Description:

This update for procps fixes the following issues:


Advisory IDSUSE-RU-2023:188-1
ReleasedFri Jan 27 12:07:19 2023
SummaryRecommended update for zlib
Typerecommended
Severityimportant
References1203652
Description:

This update for zlib fixes the following issues:


Advisory IDSUSE-SU-2023:198-1
ReleasedFri Jan 27 14:26:54 2023
SummarySecurity update for krb5
Typesecurity
Severityimportant
References1205126,CVE-2022-42898
Description:

This update for krb5 fixes the following issues:


Advisory IDSUSE-SU-2023:211-1
ReleasedMon Jan 30 17:26:10 2023
SummarySecurity update for vim
Typesecurity
Severitymoderate
References1206866,1206867,1206868,1207162,1207396,CVE-2023-0049,CVE-2023-0051,CVE-2023-0054,CVE-2023-0288,CVE-2023-0433
Description:

This update for vim fixes the following issues:


Advisory IDSUSE-SU-2023:310-1
ReleasedTue Feb 7 17:35:34 2023
SummarySecurity update for openssl-1_1
Typesecurity
Severityimportant
References1121365,1198472,1207533,1207534,1207536,1207538,CVE-2022-4304,CVE-2022-4450,CVE-2023-0215,CVE-2023-0286
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-SU-2023:413-1
ReleasedTue Feb 14 17:07:23 2023
SummarySecurity update for haproxy
Typesecurity
Severitycritical
References1207181,1208132,CVE-2023-0056,CVE-2023-25725
Description:

This update for haproxy fixes the following issues:


SUSE-CU-2022:2686-1

Container Advisory IDSUSE-CU-2022:2686-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.208 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.208
The following patches have been included in this update:

SUSE-CU-2022:2685-1

Container Advisory IDSUSE-CU-2022:2685-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.208 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.208
The following patches have been included in this update:

SUSE-CU-2022:2660-1

Container Advisory IDSUSE-CU-2022:2660-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.205 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.205
The following patches have been included in this update:
Advisory IDSUSE-RU-2022:3215-1
ReleasedThu Sep 8 15:58:27 2022
SummaryRecommended update for rpm
Typerecommended
Severitymoderate
References
Description:

This update for rpm fixes the following issues:


Advisory IDSUSE-RU-2022:3223-1
ReleasedFri Sep 9 04:33:35 2022
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitymoderate
References1199895,1200993,1201092,1201576,1201638
Description:

This update for libzypp, zypper fixes the following issues:
libzypp:


zypper:


Advisory IDSUSE-SU-2022:3229-1
ReleasedFri Sep 9 14:46:01 2022
SummarySecurity update for vim
Typesecurity
Severityimportant
References1200270,1200697,1200698,1200700,1200701,1200732,1200884,1200902,1200903,1200904,1201132,1201133,1201134,1201135,1201136,1201150,1201151,1201152,1201153,1201154,1201155,1201249,1201356,1201359,1201363,1201620,1201863,1202046,1202049,1202050,1202051,1202414,1202420,1202421,1202511,1202512,1202515,1202552,1202599,1202687,1202689,1202862,CVE-2022-1720,CVE-2022-1968,CVE-2022-2124,CVE-2022-2125,CVE-2022-2126,CVE-2022-2129,CVE-2022-2175,CVE-2022-2182,CVE-2022-2183,CVE-2022-2206,CVE-2022-2207,CVE-2022-2208,CVE-2022-2210,CVE-2022-2231,CVE-2022-2257,CVE-2022-2264,CVE-2022-2284,CVE-2022-2285,CVE-2022-2286,CVE-2022-2287,CVE-2022-2304,CVE-2022-2343,CVE-2022-2344,CVE-2022-2345,CVE-2022-2522,CVE-2022-2571,CVE-2022-2580,CVE-2022-2581,CVE-2022-2598,CVE-2022-2816,CVE-2022-2817,CVE-2022-2819,CVE-2022-2845,CVE-2022-2849,CVE-2022-2862,CVE-2022-2874,CVE-2022-2889,CVE-2022-2923,CVE-2022-2946,CVE-2022-3016
Description:

This update for vim fixes the following issues:
Updated to version 9.0 with patch level 0313:

Bugfixes:


Advisory IDSUSE-RU-2022:3262-1
ReleasedTue Sep 13 15:34:29 2022
SummaryRecommended update for gcc11
Typerecommended
Severitymoderate
References1199140
Description:


This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)


Advisory IDSUSE-SU-2022:3271-1
ReleasedWed Sep 14 06:45:39 2022
SummarySecurity update for perl
Typesecurity
Severitymoderate
References1047178,CVE-2017-6512
Description:

This update for perl fixes the following issues:


Advisory IDSUSE-RU-2022:3276-1
ReleasedThu Sep 15 06:15:29 2022
SummaryThis update fixes the following issues:
Typerecommended
Severitymoderate
References
Description:

Implement ECO jsc#SLE-20950 to fix the channel configuration for libeconf-devel having L3 support (instead of unsupported).


Advisory IDSUSE-RU-2022:3304-1
ReleasedMon Sep 19 11:43:25 2022
SummaryRecommended update for libassuan
Typerecommended
Severitymoderate
References
Description:

This update for libassuan fixes the following issues:


Advisory IDSUSE-SU-2022:3305-1
ReleasedMon Sep 19 11:45:57 2022
SummarySecurity update for libtirpc
Typesecurity
Severityimportant
References1201680,CVE-2021-46828
Description:

This update for libtirpc fixes the following issues:


Advisory IDSUSE-SU-2022:3307-1
ReleasedMon Sep 19 13:26:51 2022
SummarySecurity update for sqlite3
Typesecurity
Severitymoderate
References1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
Description:

This update for sqlite3 fixes the following issues:


Advisory IDSUSE-SU-2022:3394-1
ReleasedMon Sep 26 16:05:19 2022
SummarySecurity update for permissions
Typesecurity
Severitymoderate
References1203018,CVE-2022-31252
Description:

This update for permissions fixes the following issues:


Advisory IDSUSE-RU-2022:3452-1
ReleasedWed Sep 28 12:13:43 2022
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1201942
Description:

This update for glibc fixes the following issues:


Advisory IDSUSE-RU-2022:3555-1
ReleasedMon Oct 10 14:05:12 2022
SummaryRecommended update for aaa_base
Typerecommended
Severityimportant
References1199492
Description:

This update for aaa_base fixes the following issues:


Advisory IDSUSE-RU-2022:3565-1
ReleasedTue Oct 11 16:17:38 2022
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitycritical
References1189282,1201972,1203649
Description:

This update for libzypp, zypper fixes the following issues:
libzypp:


zypper:


Advisory IDSUSE-SU-2022:3597-1
ReleasedMon Oct 17 13:13:16 2022
SummarySecurity update for expat
Typesecurity
Severityimportant
References1203438,CVE-2022-40674
Description:

This update for expat fixes the following issues:


Advisory IDSUSE-SU-2022:3683-1
ReleasedFri Oct 21 11:48:39 2022
SummarySecurity update for libksba
Typesecurity
Severitycritical
References1204357,CVE-2022-3515
Description:

This update for libksba fixes the following issues:
- CVE-2022-3515: Fixed a possible overflow in the TLV parser (bsc#1204357).


SUSE-CU-2022:2084-1

Container Advisory IDSUSE-CU-2022:2084-1
Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.153 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
Container Release3.5.153
The following patches have been included in this update:
Advisory IDSUSE-RU-2018:1332-1
ReleasedTue Jul 17 09:01:19 2018
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1073299,1093392
Description:

This update for timezone provides the following fixes:


Advisory IDSUSE-RU-2018:2463-1
ReleasedThu Oct 25 14:48:34 2018
SummaryRecommended update for timezone, timezone-java
Typerecommended
Severitymoderate
References1104700,1112310
Description:


This update for timezone, timezone-java fixes the following issues:
The timezone database was updated to 2018f:


Other bugfixes:


Advisory IDSUSE-RU-2018:2550-1
ReleasedWed Oct 31 16:16:56 2018
SummaryRecommended update for timezone, timezone-java
Typerecommended
Severitymoderate
References1113554
Description:

This update provides the latest time zone definitions (2018g), including the following change:


Advisory IDSUSE-RU-2019:102-1
ReleasedTue Jan 15 18:02:58 2019
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1120402
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2019:790-1
ReleasedThu Mar 28 12:06:17 2019
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1130557
Description:

This update for timezone fixes the following issues:
timezone was updated 2019a:


Advisory IDSUSE-RU-2019:1815-1
ReleasedThu Jul 11 07:47:55 2019
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1140016
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2019:2762-1
ReleasedThu Oct 24 07:08:44 2019
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1150451
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2020:1303-1
ReleasedMon May 18 09:40:36 2020
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1169582
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2020:1542-1
ReleasedThu Jun 4 13:24:37 2020
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1172055
Description:

This update for timezone fixes the following issue:


Advisory IDSUSE-RU-2020:3099-1
ReleasedThu Oct 29 19:33:41 2020
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2020:3123-1
ReleasedTue Nov 3 09:48:13 2020
SummaryRecommended update for timezone
Typerecommended
Severityimportant
References1177460,1178346,1178350,1178353
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-RU-2021:179-1
ReleasedWed Jan 20 13:38:51 2021
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:





Advisory IDSUSE-RU-2021:301-1
ReleasedThu Feb 4 08:46:27 2021
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:



Advisory IDSUSE-RU-2021:2573-1
ReleasedThu Jul 29 14:21:52 2021
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1188127
Description:

This update for timezone fixes the following issue:

the IANA time zone database package, in addition to 'zone1970.tab', as before. This makes sure time zone aliases are now correctly supported. This update adds the 'tzdata.zi' file (bsc#1188127).


Advisory IDSUSE-RU-2021:3883-1
ReleasedThu Dec 2 11:47:07 2021
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:
Update timezone to 2021e (bsc#1177460)


Advisory IDSUSE-RU-2022:1118-1
ReleasedTue Apr 5 18:34:06 2022
SummaryRecommended update for timezone
Typerecommended
Severitymoderate
References1177460
Description:

This update for timezone fixes the following issues:


Advisory IDSUSE-SU-2022:1617-1
ReleasedTue May 10 14:40:12 2022
SummarySecurity update for gzip
Typesecurity
Severityimportant
References1198062,1198922,CVE-2022-1271
Description:

This update for gzip fixes the following issues:


Advisory IDSUSE-RU-2022:1626-1
ReleasedTue May 10 15:55:13 2022
SummaryRecommended update for systemd
Typerecommended
Severitymoderate
References1198090,1198114
Description:

This update for systemd fixes the following issues:


Advisory IDSUSE-RU-2022:1655-1
ReleasedFri May 13 15:36:10 2022
SummaryRecommended update for pam
Typerecommended
Severitymoderate
References1197794
Description:

This update for pam fixes the following issue:


Advisory IDSUSE-SU-2022:1657-1
ReleasedFri May 13 15:39:07 2022
SummarySecurity update for curl
Typesecurity
Severitymoderate
References1198614,1198723,1198766,CVE-2022-22576,CVE-2022-27775,CVE-2022-27776
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-RU-2022:1658-1
ReleasedFri May 13 15:40:20 2022
SummaryRecommended update for libpsl
Typerecommended
Severityimportant
References1197771
Description:

This update for libpsl fixes the following issues:


Advisory IDSUSE-SU-2022:1670-1
ReleasedMon May 16 10:06:30 2022
SummarySecurity update for openldap2
Typesecurity
Severityimportant
References1199240,CVE-2022-29155
Description:

This update for openldap2 fixes the following issues:


Advisory IDSUSE-SU-2022:1688-1
ReleasedMon May 16 14:02:49 2022
SummarySecurity update for e2fsprogs
Typesecurity
Severityimportant
References1198446,CVE-2022-1304
Description:

This update for e2fsprogs fixes the following issues:


Advisory IDSUSE-RU-2022:1691-1
ReleasedMon May 16 15:13:39 2022
SummaryRecommended update for augeas
Typerecommended
Severitymoderate
References1197443
Description:

This update for augeas fixes the following issue:


Advisory IDSUSE-SU-2022:1750-1
ReleasedThu May 19 15:28:20 2022
SummarySecurity update for libxml2
Typesecurity
Severityimportant
References1196490,1199132,CVE-2022-23308,CVE-2022-29824
Description:

This update for libxml2 fixes the following issues:


Advisory IDSUSE-SU-2022:1870-1
ReleasedFri May 27 10:03:40 2022
SummarySecurity update for curl
Typesecurity
Severityimportant
References1199223,1199224,CVE-2022-27781,CVE-2022-27782
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-SU-2022:1883-1
ReleasedMon May 30 12:41:35 2022
SummarySecurity update for pcre2
Typesecurity
Severityimportant
References1199232,CVE-2022-1586
Description:

This update for pcre2 fixes the following issues:


Advisory IDSUSE-RU-2022:1887-1
ReleasedTue May 31 09:24:18 2022
SummaryRecommended update for grep
Typerecommended
Severitymoderate
References1040589
Description:

This update for grep fixes the following issues:


Advisory IDSUSE-RU-2022:1899-1
ReleasedWed Jun 1 10:43:22 2022
SummaryRecommended update for libtirpc
Typerecommended
Severityimportant
References1198176
Description:

This update for libtirpc fixes the following issues:


Advisory IDSUSE-RU-2022:1909-1
ReleasedWed Jun 1 16:25:35 2022
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1198751
Description:

This update for glibc fixes the following issues:


Advisory IDSUSE-RU-2022:2019-1
ReleasedWed Jun 8 16:50:07 2022
SummaryRecommended update for gcc11
Typerecommended
Severitymoderate
References1192951,1193659,1195283,1196861,1197065
Description:

This update for gcc11 fixes the following issues:
Update to the GCC 11.3.0 release.


Advisory IDSUSE-SU-2022:2102-1
ReleasedThu Jun 16 15:18:23 2022
SummarySecurity update for vim
Typesecurity
Severityimportant
References1070955,1191770,1192167,1192902,1192903,1192904,1193466,1193905,1194093,1194216,1194217,1194388,1194872,1194885,1195004,1195203,1195332,1195354,1196361,1198596,1198748,1199331,1199333,1199334,1199651,1199655,1199693,1199745,1199747,1199936,1200010,1200011,1200012,CVE-2017-17087,CVE-2021-3778,CVE-2021-3796,CVE-2021-3872,CVE-2021-3875,CVE-2021-3903,CVE-2021-3927,CVE-2021-3928,CVE-2021-3968,CVE-2021-3973,CVE-2021-3974,CVE-2021-3984,CVE-2021-4019,CVE-2021-4069,CVE-2021-4136,CVE-2021-4166,CVE-2021-4192,CVE-2021-4193,CVE-2021-46059,CVE-2022-0128,CVE-2022-0213,CVE-2022-0261,CVE-2022-0318,CVE-2022-0319,CVE-2022-0351,CVE-2022-0359,CVE-2022-0361,CVE-2022-0392,CVE-2022-0407,CVE-2022-0413,CVE-2022-0696,CVE-2022-1381,CVE-2022-1420,CVE-2022-1616,CVE-2022-1619,CVE-2022-1620,CVE-2022-1733,CVE-2022-1735,CVE-2022-1771,CVE-2022-1785,CVE-2022-1796,CVE-2022-1851,CVE-2022-1897,CVE-2022-1898,CVE-2022-1927
Description:

This update for vim fixes the following issues:


Advisory IDSUSE-SU-2022:2251-1
ReleasedMon Jul 4 09:52:25 2022
SummarySecurity update for openssl-1_1
Typesecurity
Severitymoderate
References1185637,1199166,1200550,CVE-2022-1292,CVE-2022-2068
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-RU-2022:2323-1
ReleasedThu Jul 7 12:16:58 2022
SummaryRecommended update for systemd-presets-branding-SLE
Typerecommended
Severitylow
References
Description:

This update for systemd-presets-branding-SLE fixes the following issues:


Advisory IDSUSE-SU-2022:2327-1
ReleasedThu Jul 7 15:06:13 2022
SummarySecurity update for curl
Typesecurity
Severityimportant
References1200735,1200737,CVE-2022-32206,CVE-2022-32208
Description:

This update for curl fixes the following issues:


Advisory IDSUSE-SU-2022:2328-1
ReleasedThu Jul 7 15:07:35 2022
SummarySecurity update for openssl-1_1
Typesecurity
Severityimportant
References1201099,CVE-2022-2097
Description:

This update for openssl-1_1 fixes the following issues:


Advisory IDSUSE-SU-2022:2361-1
ReleasedTue Jul 12 12:05:01 2022
SummarySecurity update for pcre
Typesecurity
Severityimportant
References1199232,CVE-2022-1586
Description:

This update for pcre fixes the following issues:


Advisory IDSUSE-RU-2022:2406-1
ReleasedFri Jul 15 11:49:01 2022
SummaryRecommended update for glibc
Typerecommended
Severitymoderate
References1197718,1199140,1200334,1200855
Description:

This update for glibc fixes the following issues:


This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).


Advisory IDSUSE-RU-2022:2470-1
ReleasedThu Jul 21 04:40:14 2022
SummaryRecommended update for systemd
Typerecommended
Severityimportant
References1137373,1181658,1194708,1195157,1197570,1198507,1198732,1200170
Description:

This update for systemd fixes the following issues:


Advisory IDSUSE-RU-2022:2494-1
ReleasedThu Jul 21 15:16:42 2022
SummaryRecommended update for glibc
Typerecommended
Severityimportant
References1200855,1201560,1201640
Description:

This update for glibc fixes the following issues:


Advisory IDSUSE-SU-2022:2546-1
ReleasedMon Jul 25 14:43:22 2022
SummarySecurity update for gpg2
Typesecurity
Severityimportant
References1196125,1201225,CVE-2022-34903
Description:

This update for gpg2 fixes the following issues:


Advisory IDSUSE-RU-2022:2572-1
ReleasedThu Jul 28 04:22:33 2022
SummaryRecommended update for libzypp, zypper
Typerecommended
Severitymoderate
References1194550,1197684,1199042
Description:

This update for libzypp, zypper fixes the following issues:
libzypp:


zypper:


Advisory IDSUSE-SU-2022:2614-1
ReleasedMon Aug 1 10:41:04 2022
SummarySecurity update for dwarves and elfutils
Typesecurity
Severitymoderate
References1033084,1033085,1033086,1033087,1033088,1033089,1033090,1082318,1104264,1106390,1107066,1107067,1111973,1112723,1112726,1123685,1125007,CVE-2017-7607,CVE-2017-7608,CVE-2017-7609,CVE-2017-7610,CVE-2017-7611,CVE-2017-7612,CVE-2017-7613,CVE-2018-16062,CVE-2018-16402,CVE-2018-16403,CVE-2018-18310,CVE-2018-18520,CVE-2018-18521,CVE-2019-7146,CVE-2019-7148,CVE-2019-7149,CVE-2019-7150,CVE-2019-7664,CVE-2019-7665
Description:

This update for dwarves and elfutils fixes the following issues:
elfutils was updated to version 0.177 (jsc#SLE-24501):

Update to version 0.176:
Update to version 0.175:
  • readelf: Handle mutliple .debug_macro sections. Recognize and parse GNU Property, NT_VERSION and GNU Build Attribute ELF Notes.
  • strip: Handle SHT_GROUP correctly. Add strip --reloc-debug-sections-only option. Handle relocations against GNU compressed sections.
  • libdwelf: New function dwelf_elf_begin.
  • libcpu: Recognize bpf jump variants BPF_JLT, BPF_JLE, BPF_JSLT and BPF_JSLE. backends: RISCV handles ADD/SUB relocations. Handle SHT_X86_64_UNWIND. - CVE-2018-18521: arlib: Divide-by-zero vulnerabilities in the function arlib_add_symbols() used by eu-ranlib (bsc#1112723) - CVE-2018-18310: Invalid Address Read problem in dwfl_segment_report_module.c (bsc#1111973) - CVE-2018-18520: eu-size: Bad handling of ar files inside are files (bsc#1112726)
  • Update to version 0.174:
  • libelf, libdw and all tools now handle extended shnum and shstrndx correctly.
  • elfcompress: Don't rewrite input file if no section data needs updating. Try harder to keep same file mode bits (suid) on rewrite.
  • strip: Handle mixed (out of order) allocated/non-allocated sections.
  • unstrip: Handle SHT_GROUP sections.
  • backends: RISCV and M68K now have backend implementations to generate CFI based backtraces.
  • Fixes: - CVE-2018-16402: libelf: denial of service/double free on an attempt to decompress the same section twice (bsc#1107066) Double-free crash in nm and readelf - CVE-2018-16403: heap buffer overflow in readelf (bsc#1107067) - CVE-2018-16062: heap-buffer-overflow in /elfutils/libdw/dwarf_getaranges.c:156 (bsc#1106390)
  • Update to version 0.173:
  • More fixes for crashes and hangs found by afl-fuzz. In particular various functions now detect and break infinite loops caused by bad DIE tree cycles.
  • readelf: Will now lookup the size and signedness of constant value types to display them correctly (and not just how they were encoded).
  • libdw: New function dwarf_next_lines to read CU-less .debug_line data. dwarf_begin_elf now accepts ELF files containing just .debug_line or .debug_frame sections (which can be read without needing a DIE tree from the .debug_info section). Removed dwarf_getscn_info, which was never implemented.
  • backends: Handle BPF simple relocations. The RISCV backends now handles ABI specific CFI and knows about RISCV register types and names.
  • Update to version 0.172:
  • Various bug fixes in libdw and eu-readelf dealing with bad DWARF5 data. Thanks to running the afl fuzzer on eu-readelf and various testcases.
  • Update to version 0.171:
  • DWARF5 and split dwarf, including GNU DebugFission, are supported now. Data can be read from the new DWARF sections .debug_addr, .debug_line_str, .debug_loclists, .debug_str_offsets and .debug_rnglists. Plus the new DWARF5 and GNU DebugFission encodings of the existing .debug sections. Also in split DWARF .dwo (DWARF object) files. This support is mostly handled by existing functions (dwarf_getlocation*, dwarf_getsrclines, dwarf_ranges, dwarf_form*, etc.) now returning the data from the new sections and data formats. But some new functions have been added to more easily get information about skeleton and split compile units (dwarf_get_units and dwarf_cu_info), handle new attribute data (dwarf_getabbrevattr_data) and to keep references to Dwarf_Dies that might come from different sections or files (dwarf_die_addr_die).
  • Not yet supported are .dwp (Dwarf Package) and .sup (Dwarf Supplementary) files, the .debug_names index, the .debug_cu_index and .debug_tu_index sections. Only a single .debug_info (and .debug_types) section are currently handled.
  • readelf: Handle all new DWARF5 sections. --debug-dump=info+ will show split unit DIEs when found. --dwarf-skeleton can be used when inspecting a .dwo file. Recognizes GNU locviews with --debug-dump=loc.
  • libdw: New functions dwarf_die_addr_die, dwarf_get_units, dwarf_getabbrevattr_data and dwarf_cu_info. libdw will now try to resolve the alt file on first use of an alt attribute FORM when not set yet with dwarf_set_alt. dwarf_aggregate_size() now works with multi-dimensional arrays.
  • libdwfl: Use process_vm_readv when available instead of ptrace. backends: Add a RISC-V backend. There were various improvements to build on Windows. The sha1 and md5 implementations have been removed, they weren't used.

  • Update to version 0.170:
    New functions dwarf_default_lower_bound and dwarf_line_file. dwarf_peel_type now handles DWARF5 immutable, packed and shared tags. dwarf_getmacros now handles DWARF5 .debug_macro sections.
  • strip: Add -R, --remove-section=SECTION and --keep-section=SECTION.
  • backends: The bpf disassembler is now always build on all platforms.

  • Update to version 0.169:

    dwarves is shipped new in version 1.22 to provide tooling for use by the Linux Kernel BTF verification framework.


    Advisory IDSUSE-RU-2022:2628-1
    ReleasedTue Aug 2 12:21:23 2022
    SummaryRecommended update for apparmor
    Typerecommended
    Severityimportant
    References1195463,1196850
    Description:

    This update for apparmor fixes the following issues:


    Advisory IDSUSE-SU-2022:2649-1
    ReleasedWed Aug 3 15:06:21 2022
    SummarySecurity update for pcre2
    Typesecurity
    Severityimportant
    References1164384,1199235,CVE-2019-20454,CVE-2022-1587
    Description:

    This update for pcre2 fixes the following issues:


    Advisory IDSUSE-SU-2022:2717-1
    ReleasedTue Aug 9 12:54:16 2022
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1198627,CVE-2022-29458
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-SU-2022:2866-1
    ReleasedMon Aug 22 15:36:30 2022
    SummarySecurity update for systemd-presets-common-SUSE
    Typesecurity
    Severitymoderate
    References1199524,1200485,CVE-2022-1706
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:


    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2022:2904-1
    ReleasedFri Aug 26 05:28:34 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1198341
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2022:2921-1
    ReleasedFri Aug 26 15:17:43 2022
    SummaryRecommended update for systemd
    Typerecommended
    Severityimportant
    References1195059
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:2929-1
    ReleasedMon Aug 29 11:21:47 2022
    SummaryRecommended update for timezone
    Typerecommended
    Severityimportant
    References1202310
    Description:

    This update for timezone fixes the following issue:


    Advisory IDSUSE-RU-2022:2944-1
    ReleasedWed Aug 31 05:39:14 2022
    SummaryRecommended update for procps
    Typerecommended
    Severityimportant
    References1181475
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-SU-2022:2947-1
    ReleasedWed Aug 31 09:16:21 2022
    SummarySecurity update for zlib
    Typesecurity
    Severityimportant
    References1202175,CVE-2022-37434
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2022:2982-1
    ReleasedThu Sep 1 12:33:47 2022
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1197178,1198731,1200842
    Description:

    This update for util-linux fixes the following issues:


    Advisory IDSUSE-RU-2022:2994-1
    ReleasedFri Sep 2 10:44:54 2022
    SummaryRecommended update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame
    Typerecommended
    Severitymoderate
    References1198925
    Description:


    This update for lame, libass, libcdio-paranoia, libdc1394, libgsm, libva, libvdpau, libvorbis, libvpx, libwebp, openjpeg, opus, speex, twolame adds some missing 32bit libraries to some products. (bsc#1198925)
    No codechanges were done in this update.


    Advisory IDSUSE-SU-2022:3004-1
    ReleasedFri Sep 2 15:02:14 2022
    SummarySecurity update for curl
    Typesecurity
    Severitylow
    References1202593,CVE-2022-35252
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2022:3127-1
    ReleasedWed Sep 7 04:36:10 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1198752,1200800
    Description:

    This update for libtirpc fixes the following issues:


    SUSE-CU-2022:880-1

    Container Advisory IDSUSE-CU-2022:880-1
    Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.3.5.1 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
    Container Release3.5.1
    The following patches have been included in this update:
    Advisory IDSUSE-SU-2022:1040-1
    ReleasedWed Mar 30 09:40:58 2022
    SummarySecurity update for protobuf
    Typesecurity
    Severitymoderate
    References1195258,CVE-2021-22570
    Description:

    This update for protobuf fixes the following issues:


    Advisory IDSUSE-RU-2022:1047-1
    ReleasedWed Mar 30 16:20:56 2022
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1196093,1197024
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2022:1061-1
    ReleasedWed Mar 30 18:27:06 2022
    SummarySecurity update for zlib
    Typesecurity
    Severityimportant
    References1197459,CVE-2018-25032
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-SU-2022:1073-1
    ReleasedFri Apr 1 11:45:01 2022
    SummarySecurity update for yaml-cpp
    Typesecurity
    Severitymoderate
    References1121227,1121230,1122004,1122021,CVE-2018-20573,CVE-2018-20574,CVE-2019-6285,CVE-2019-6292
    Description:

    This update for yaml-cpp fixes the following issues:


    Advisory IDSUSE-RU-2022:1099-1
    ReleasedMon Apr 4 12:53:05 2022
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1194883
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2022:1107-1
    ReleasedMon Apr 4 17:49:17 2022
    SummaryRecommended update for util-linux
    Typerecommended
    Severitymoderate
    References1194642
    Description:

    This update for util-linux fixes the following issue:


    Advisory IDSUSE-SU-2022:1157-1
    ReleasedTue Apr 12 13:26:19 2022
    SummarySecurity update for libsolv, libzypp, zypper
    Typesecurity
    Severityimportant
    References1184501,1194848,1195999,1196061,1196317,1196368,1196514,1196925,1197134
    Description:

    This update for libsolv, libzypp, zypper fixes the following issues:
    Security relevant fix:


    libsolv update to 0.7.22:

    libzypp update to 17.30.0:

    zypper update to 1.14.52:


    Advisory IDSUSE-SU-2022:1158-1
    ReleasedTue Apr 12 14:44:43 2022
    SummarySecurity update for xz
    Typesecurity
    Severityimportant
    References1198062,CVE-2022-1271
    Description:

    This update for xz fixes the following issues:


    Advisory IDSUSE-RU-2022:1170-1
    ReleasedTue Apr 12 18:20:07 2022
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1191502,1193086,1195247,1195529,1195899,1196567
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:1203-1
    ReleasedThu Apr 14 11:43:28 2022
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1195231
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2022:1281-1
    ReleasedWed Apr 20 12:26:38 2022
    SummaryRecommended update for libtirpc
    Typerecommended
    Severitymoderate
    References1196647
    Description:

    This update for libtirpc fixes the following issues:


    Advisory IDSUSE-RU-2022:1302-1
    ReleasedFri Apr 22 10:04:46 2022
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1196939
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-RU-2022:1374-1
    ReleasedMon Apr 25 15:02:13 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1191157,1197004
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2022:1409-1
    ReleasedTue Apr 26 12:54:57 2022
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1195628,1196107
    Description:

    This update for gcc11 fixes the following issues:


    Advisory IDSUSE-RU-2022:1438-1
    ReleasedWed Apr 27 15:27:19 2022
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitylow
    References1195251
    Description:

    This update for systemd-presets-common-SUSE fixes the following issue:


    Advisory IDSUSE-RU-2022:1451-1
    ReleasedThu Apr 28 10:47:22 2022
    SummaryRecommended update for perl
    Typerecommended
    Severitymoderate
    References1193489
    Description:

    This update for perl fixes the following issues:


    SUSE-CU-2022:326-1

    Container Advisory IDSUSE-CU-2022:326-1
    Container Tagsses/7.1/ceph/haproxy:2.0.14 , ses/7.1/ceph/haproxy:2.0.14.2.2.10 , ses/7.1/ceph/haproxy:latest , ses/7.1/ceph/haproxy:sle15.3.pacific
    Container Release2.2.10
    The following patches have been included in this update:
    Advisory IDSUSE-SU-2018:1353-1
    ReleasedThu Jul 19 09:50:32 2018
    SummarySecurity update for e2fsprogs
    Typesecurity
    Severitymoderate
    References1009532,1038194,915402,918346,960273,CVE-2015-0247,CVE-2015-1572
    Description:

    This update for e2fsprogs fixes the following issues:
    Security issues fixed:


    Bug fixes:


    Advisory IDSUSE-RU-2018:1999-1
    ReleasedTue Sep 25 08:20:35 2018
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1071321
    Description:

    This update for zlib provides the following fixes:


    Advisory IDSUSE-RU-2018:2055-1
    ReleasedThu Sep 27 14:30:14 2018
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1089640
    Description:

    This update for openldap2 provides the following fix:


    Advisory IDSUSE-SU-2018:2182-1
    ReleasedTue Oct 9 11:08:36 2018
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1088279,1102046,1105166,CVE-2018-14404,CVE-2018-14567,CVE-2018-9251
    Description:

    This update for libxml2 fixes the following security issues:


    Advisory IDSUSE-RU-2018:2370-1
    ReleasedMon Oct 22 14:02:01 2018
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1102310,1104531
    Description:

    This update for aaa_base provides the following fixes:


    Advisory IDSUSE-RU-2018:2569-1
    ReleasedFri Nov 2 19:00:18 2018
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1110700
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2018:2607-1
    ReleasedWed Nov 7 15:42:48 2018
    SummaryOptional update for gcc8
    Typerecommended
    Severitylow
    References1084812,1084842,1087550,1094222,1102564
    Description:


    The GNU Compiler GCC 8 is being added to the Development Tools Module by this update.
    The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
    Various optimizers have been improved in GCC 8, several of bugs fixed, quite some new warnings added and the error pin-pointing and fix-suggestions have been greatly improved.
    The GNU Compiler page for GCC 8 contains a summary of all the changes that have happened:
    https://gcc.gnu.org/gcc-8/changes.html
    Also changes needed or common pitfalls when porting software are described on:
    https://gcc.gnu.org/gcc-8/porting_to.html


    Advisory IDSUSE-SU-2018:2825-1
    ReleasedMon Dec 3 15:35:02 2018
    SummarySecurity update for pam
    Typesecurity
    Severityimportant
    References1115640,CVE-2018-17953
    Description:

    This update for pam fixes the following issue:
    Security issue fixed:


    Advisory IDSUSE-SU-2018:2861-1
    ReleasedThu Dec 6 14:32:01 2018
    SummarySecurity update for ncurses
    Typesecurity
    Severityimportant
    References1103320,1115929,CVE-2018-19211
    Description:

    This update for ncurses fixes the following issues:
    Security issue fixed:


    Non-security issue fixed:


    Advisory IDSUSE-RU-2019:44-1
    ReleasedTue Jan 8 13:07:32 2019
    SummaryRecommended update for acl
    Typerecommended
    Severitylow
    References953659
    Description:

    This update for acl fixes the following issues:


    Advisory IDSUSE-SU-2019:247-1
    ReleasedWed Feb 6 07:18:45 2019
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1123043,CVE-2019-6706
    Description:

    This update for lua53 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:369-1
    ReleasedWed Feb 13 14:01:42 2019
    SummaryRecommended update for itstool
    Typerecommended
    Severitymoderate
    References1065270,1111019
    Description:

    This update for itstool and python-libxml2-python fixes the following issues:
    Package: itstool - Updated version to support Python3. (bnc#1111019)
    Package: python-libxml2-python - Fix segfault when parsing invalid data. (bsc#1065270)


    Advisory IDSUSE-SU-2019:571-1
    ReleasedThu Mar 7 18:13:46 2019
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907
    Description:

    This update for file fixes the following issues:
    The following security vulnerabilities were addressed:


    Advisory IDSUSE-RU-2019:732-1
    ReleasedMon Mar 25 14:10:04 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1088524,1118364,1128246
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2019:788-1
    ReleasedThu Mar 28 11:55:06 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1119687,CVE-2018-20346
    Description:

    This update for sqlite3 to version 3.27.2 fixes the following issue:
    Security issue fixed:


    Release notes: https://www.sqlite.org/releaselog/3_27_2.html


    Advisory IDSUSE-RU-2019:1002-1
    ReleasedWed Apr 24 10:13:34 2019
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1110304,1129576
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-SU-2019:1127-1
    ReleasedThu May 2 09:39:24 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1130325,1130326,CVE-2019-9936,CVE-2019-9937
    Description:

    This update for sqlite3 to version 3.28.0 fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:1206-1
    ReleasedFri May 10 14:01:55 2019
    SummarySecurity update for bzip2
    Typesecurity
    Severitylow
    References985657,CVE-2016-3189
    Description:

    This update for bzip2 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:1312-1
    ReleasedWed May 22 12:19:12 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1096191
    Description:

    This update for aaa_base fixes the following issue:
    * Shell detection in /etc/profile and /etc/bash.bashrc was broken within AppArmor-confined containers (bsc#1096191)


    Advisory IDSUSE-SU-2019:1368-1
    ReleasedTue May 28 13:15:38 2019
    SummaryRecommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root
    Typesecurity
    Severityimportant
    References1134524,CVE-2019-5021
    Description:

    This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:


    Advisory IDSUSE-SU-2019:1457-1
    ReleasedTue Jun 11 10:09:14 2019
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1137443,CVE-2019-12735
    Description:

    This update for vim fixes the following issue:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:1484-1
    ReleasedThu Jun 13 07:46:46 2019
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1128383
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-SU-2019:1486-1
    ReleasedThu Jun 13 09:40:24 2019
    SummarySecurity update for elfutils
    Typesecurity
    Severitymoderate
    References1033084,1033085,1033086,1033087,1033088,1033089,1033090,1106390,1107066,1107067,1111973,1112723,1112726,1123685,1125007,CVE-2017-7607,CVE-2017-7608,CVE-2017-7609,CVE-2017-7610,CVE-2017-7611,CVE-2017-7612,CVE-2017-7613,CVE-2018-16062,CVE-2018-16402,CVE-2018-16403,CVE-2018-18310,CVE-2018-18520,CVE-2018-18521,CVE-2019-7150,CVE-2019-7665
    Description:

    This update for elfutils fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:1595-1
    ReleasedFri Jun 21 10:17:44 2019
    SummarySecurity update for dbus-1
    Typesecurity
    Severityimportant
    References1137832,CVE-2019-12749
    Description:

    This update for dbus-1 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:1631-1
    ReleasedFri Jun 21 11:17:21 2019
    SummaryRecommended update for xz
    Typerecommended
    Severitylow
    References1135709
    Description:

    This update for xz fixes the following issues:
    Add SUSE-Public-Domain licence as some parts of xz utils (liblzma, xz, xzdec, lzmadec, documentation, translated messages, tests, debug, extra directory) are in public domain licence [bsc#1135709]


    Advisory IDSUSE-RU-2019:1700-1
    ReleasedTue Jun 25 13:19:21 2019
    SummarySecurity update for libssh
    Typerecommended
    Severitymoderate
    References1134193
    Description:

    This update for libssh fixes the following issue:
    Issue addressed:


    Advisory IDSUSE-RU-2019:1808-1
    ReleasedWed Jul 10 13:16:29 2019
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1133808
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-SU-2019:1835-1
    ReleasedFri Jul 12 18:06:31 2019
    SummarySecurity update for expat
    Typesecurity
    Severitymoderate
    References1139937,CVE-2018-20843
    Description:

    This update for expat fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:1846-1
    ReleasedMon Jul 15 11:36:33 2019
    SummarySecurity update for bzip2
    Typesecurity
    Severityimportant
    References1139083,CVE-2019-12900
    Description:

    This update for bzip2 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-SU-2019:1971-1
    ReleasedThu Jul 25 14:58:52 2019
    SummarySecurity update for libgcrypt
    Typesecurity
    Severitymoderate
    References1138939,CVE-2019-12904
    Description:

    This update for libgcrypt fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:1994-1
    ReleasedFri Jul 26 16:12:05 2019
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References1135123
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2019:2004-1
    ReleasedMon Jul 29 13:01:59 2019
    SummarySecurity update for bzip2
    Typesecurity
    Severityimportant
    References1139083,CVE-2019-12900
    Description:

    This update for bzip2 fixes the following issues:


    Advisory IDSUSE-RU-2019:2097-1
    ReleasedFri Aug 9 09:31:17 2019
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severityimportant
    References1097073
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2019:2134-1
    ReleasedWed Aug 14 11:54:56 2019
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1136717,1137624,1141059,SLE-5807
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2019:2188-1
    ReleasedWed Aug 21 10:10:29 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1140647
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2019:2218-1
    ReleasedMon Aug 26 11:29:57 2019
    SummaryRecommended update for pinentry
    Typerecommended
    Severitymoderate
    References1141883
    Description:

    This update for pinentry fixes the following issues:


    Advisory IDSUSE-SU-2019:2395-1
    ReleasedWed Sep 18 08:31:38 2019
    SummarySecurity update for openldap2
    Typesecurity
    Severitymoderate
    References1073313,1111388,1114845,1143194,1143273,CVE-2017-17740,CVE-2019-13057,CVE-2019-13565
    Description:

    This update for openldap2 fixes the following issues:
    Security issue fixed:


    Non-security issues fixed:


    Advisory IDSUSE-RU-2019:2423-1
    ReleasedFri Sep 20 16:41:45 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1146866,SLE-9132
    Description:

    This update for aaa_base fixes the following issues:
    Added sysctl.d/51-network.conf to tighten network security (bsc#1146866) (jira#SLE-9132)
    Following settings have been tightened (and set to 0):


    Advisory IDSUSE-SU-2019:2429-1
    ReleasedMon Sep 23 09:28:40 2019
    SummarySecurity update for expat
    Typesecurity
    Severitymoderate
    References1149429,CVE-2019-15903
    Description:

    This update for expat fixes the following issues:
    Security issues fixed:


    Advisory IDSUSE-SU-2019:2533-1
    ReleasedThu Oct 3 15:02:50 2019
    SummarySecurity update for sqlite3
    Typesecurity
    Severitymoderate
    References1150137,CVE-2019-16168
    Description:

    This update for sqlite3 fixes the following issues:
    Security issue fixed:


    Advisory IDSUSE-RU-2019:2676-1
    ReleasedTue Oct 15 21:06:54 2019
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1145716,1152101,CVE-2019-5094
    Description:

    This update for e2fsprogs fixes the following issues:
    Security issue fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2019:2730-1
    ReleasedMon Oct 21 16:04:57 2019
    SummarySecurity update for procps
    Typesecurity
    Severityimportant
    References1092100,1121753,CVE-2018-1122,CVE-2018-1123,CVE-2018-1124,CVE-2018-1125,CVE-2018-1126
    Description:

    This update for procps fixes the following issues:
    procps was updated to 3.3.15. (bsc#1092100)
    Following security issues were fixed:



    Also this non-security issue was fixed:

    The update to 3.3.15 contains the following fixes:


    Advisory IDSUSE-RU-2019:2870-1
    ReleasedThu Oct 31 08:09:14 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1051143,1138869,1151023
    Description:

    This update for aaa_base provides the following fixes:


    Advisory IDSUSE-SU-2019:2997-1
    ReleasedMon Nov 18 15:16:38 2019
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
    Description:

    This update for ncurses fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2019:3059-1
    ReleasedMon Nov 25 17:33:07 2019
    SummarySecurity update for cpio
    Typesecurity
    Severitymoderate
    References1155199,CVE-2019-14866
    Description:

    This update for cpio fixes the following issues:


    Advisory IDSUSE-SU-2019:3061-1
    ReleasedMon Nov 25 17:34:22 2019
    SummarySecurity update for gcc9
    Typesecurity
    Severitymoderate
    References1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
    Description:



    This update includes the GNU Compiler Collection 9.
    A full changelog is provided by the GCC team on:
    https://www.gnu.org/software/gcc/gcc-9/changes.html

    The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages.
    To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it.

    Security issues fixed:


    Non-security issues fixed:


    Advisory IDSUSE-SU-2019:3086-1
    ReleasedThu Nov 28 10:02:24 2019
    SummarySecurity update for libidn2
    Typesecurity
    Severitymoderate
    References1154884,1154887,CVE-2019-12290,CVE-2019-18224
    Description:

    This update for libidn2 to version 2.2.0 fixes the following issues:


    Advisory IDSUSE-SU-2019:3087-1
    ReleasedThu Nov 28 10:03:00 2019
    SummarySecurity update for libxml2
    Typesecurity
    Severitylow
    References1123919
    Description:

    This update for libxml2 doesn't fix any additional security issues, but correct its rpm changelog to reflect all CVEs that have been fixed over the past.


    Advisory IDSUSE-RU-2019:3118-1
    ReleasedFri Nov 29 14:41:35 2019
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1154295
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-RU-2019:3166-1
    ReleasedWed Dec 4 11:24:42 2019
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1007715,1084934,1157278
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2019:3267-1
    ReleasedWed Dec 11 11:19:53 2019
    SummarySecurity update for libssh
    Typesecurity
    Severityimportant
    References1158095,CVE-2019-14889
    Description:

    This update for libssh fixes the following issues:


    Advisory IDSUSE-SU-2019:3392-1
    ReleasedFri Dec 27 13:33:29 2019
    SummarySecurity update for libgcrypt
    Typesecurity
    Severitymoderate
    References1148987,1155338,1155339,CVE-2019-13627
    Description:

    This update for libgcrypt fixes the following issues:
    Security issues fixed:


    Bug fixes:


    Advisory IDSUSE-SU-2020:129-1
    ReleasedMon Jan 20 09:21:13 2020
    SummarySecurity update for libssh
    Typesecurity
    Severityimportant
    References1158095,CVE-2019-14889
    Description:

    This update for libssh fixes the following issues:


    Advisory IDSUSE-RU-2020:225-1
    ReleasedFri Jan 24 06:49:07 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:256-1
    ReleasedWed Jan 29 09:39:17 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1157794,1160970
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2020:265-1
    ReleasedThu Jan 30 14:05:34 2020
    SummarySecurity update for e2fsprogs
    Typesecurity
    Severitymoderate
    References1160571,CVE-2019-5188
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-RU-2020:339-1
    ReleasedThu Feb 6 13:03:22 2020
    SummaryRecommended update for openldap2
    Typerecommended
    Severitylow
    References1158921
    Description:

    This update for openldap2 provides the following fix:


    Advisory IDSUSE-RU-2020:451-1
    ReleasedTue Feb 25 10:50:35 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1155337,1161215,1161216,1161218,1161219,1161220
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2020:480-1
    ReleasedTue Feb 25 17:38:22 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1160735
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2020:525-1
    ReleasedFri Feb 28 11:49:36 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1164562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:597-1
    ReleasedThu Mar 5 15:24:09 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1164950
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2020:633-1
    ReleasedTue Mar 10 16:23:08 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1139939,1151023
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2020:689-1
    ReleasedFri Mar 13 17:09:01 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:


    This update for PAM fixes the following issue:


    Advisory IDSUSE-RU-2020:846-1
    ReleasedThu Apr 2 07:24:07 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1164950,1166748,1167674
    Description:

    This update for libgcrypt fixes the following issues:


    * Set up global_init as the constructor function: * Relax the entropy requirements on selftest. This is especially important for virtual machines to boot properly before the RNG is available:


    Advisory IDSUSE-RU-2020:917-1
    ReleasedFri Apr 3 15:02:25 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1166510
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2020:948-1
    ReleasedWed Apr 8 07:44:21 2020
    SummarySecurity update for gmp, gnutls, libnettle
    Typesecurity
    Severitymoderate
    References1152692,1155327,1166881,1168345,CVE-2020-11501
    Description:

    This update for gmp, gnutls, libnettle fixes the following issues:
    Security issue fixed:


    FIPS related bugfixes:


    Advisory IDSUSE-RU-2020:961-1
    ReleasedWed Apr 8 13:34:06 2020
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitymoderate
    References1160979
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-SU-2020:967-1
    ReleasedThu Apr 9 11:41:53 2020
    SummarySecurity update for libssh
    Typesecurity
    Severitymoderate
    References1168699,CVE-2020-1730
    Description:

    This update for libssh fixes the following issues:


    Advisory IDSUSE-RU-2020:1063-1
    ReleasedWed Apr 22 10:46:50 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1165539,1169569
    Description:

    This update for libgcrypt fixes the following issues:
    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2020:1214-1
    ReleasedThu May 7 11:20:34 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1169944
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-SU-2020:1219-1
    ReleasedThu May 7 17:10:42 2020
    SummarySecurity update for openldap2
    Typesecurity
    Severityimportant
    References1170771,CVE-2020-12243
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2020:1226-1
    ReleasedFri May 8 10:51:05 2020
    SummaryRecommended update for gcc9
    Typerecommended
    Severitymoderate
    References1149995,1152590,1167898
    Description:

    This update for gcc9 fixes the following issues:
    This update ships the GCC 9.3 release.


    Advisory IDSUSE-SU-2020:1294-1
    ReleasedMon May 18 07:38:36 2020
    SummarySecurity update for file
    Typesecurity
    Severitymoderate
    References1154661,1169512,CVE-2019-18218
    Description:

    This update for file fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-SU-2020:1299-1
    ReleasedMon May 18 07:43:21 2020
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1159928,1161517,1161521,CVE-2019-19956,CVE-2019-20388,CVE-2020-7595
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2020:1328-1
    ReleasedMon May 18 17:16:04 2020
    SummaryRecommended update for grep
    Typerecommended
    Severitymoderate
    References1155271
    Description:

    This update for grep fixes the following issues:


    Advisory IDSUSE-RU-2020:1361-1
    ReleasedThu May 21 09:31:18 2020
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1171872
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2020:1370-1
    ReleasedThu May 21 19:06:00 2020
    SummaryRecommended update for systemd-presets-branding-SLE
    Typerecommended
    Severitymoderate
    References1171656
    Description:

    This update for systemd-presets-branding-SLE fixes the following issues:
    Cleanup of outdated autostart services (bsc#1171656):


    Advisory IDSUSE-RU-2020:1404-1
    ReleasedMon May 25 15:32:34 2020
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1138793,1166260
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2020:1506-1
    ReleasedFri May 29 17:22:11 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1087982,1170527
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2020:1532-1
    ReleasedThu Jun 4 10:16:12 2020
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1172021,CVE-2019-19956
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2020:1551-1
    ReleasedMon Jun 8 09:31:41 2020
    SummarySecurity update for vim
    Typesecurity
    Severitymoderate
    References1172225,CVE-2019-20807
    Description:

    This update for vim fixes the following issues:


    Advisory IDSUSE-SU-2020:1733-1
    ReleasedWed Jun 24 09:43:36 2020
    SummarySecurity update for curl
    Typesecurity
    Severityimportant
    References1173026,1173027,CVE-2020-8169,CVE-2020-8177
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2020:1795-1
    ReleasedMon Jun 29 11:22:45 2020
    SummaryRecommended update for lvm2
    Typerecommended
    Severityimportant
    References1172566
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-SU-2020:1396-1
    ReleasedFri Jul 3 12:33:05 2020
    SummarySecurity update for zstd
    Typesecurity
    Severitymoderate
    References1082318,1133297
    Description:

    This update for zstd fixes the following issues:


    Advisory IDSUSE-SU-2020:1856-1
    ReleasedMon Jul 6 17:05:51 2020
    SummarySecurity update for openldap2
    Typesecurity
    Severityimportant
    References1172698,1172704,CVE-2020-8023
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2020:1938-1
    ReleasedThu Jul 16 14:43:32 2020
    SummaryRecommended update for libsolv, libzypp, zypper
    Typerecommended
    Severitymoderate
    References1169947,1170801,1172925,1173106
    Description:

    This update for libsolv, libzypp, zypper fixes the following issues:
    libsolv was updated to:


    zypper was updated to version 1.14.37:

    libzypp was updated to 17.24.0


    Advisory IDSUSE-RU-2020:1954-1
    ReleasedSat Jul 18 03:07:15 2020
    SummaryRecommended update for cracklib
    Typerecommended
    Severitymoderate
    References1172396
    Description:

    This update for cracklib fixes the following issues:


    Advisory IDSUSE-RU-2020:1987-1
    ReleasedTue Jul 21 17:02:15 2020
    SummaryRecommended update for libsolv, libzypp, yast2-packager, yast2-pkg-bindings
    Typerecommended
    Severityimportant
    References1172477,1173336,1174011
    Description:

    This update for libsolv, libzypp, yast2-packager, yast2-pkg-bindings fixes the following issues:
    libsolv:


    libzypp:

    yast2-packager:

    yast2-pkg-bindings:


    Advisory IDSUSE-RU-2020:2083-1
    ReleasedThu Jul 30 10:27:59 2020
    SummaryRecommended update for diffutils
    Typerecommended
    Severitymoderate
    References1156913
    Description:

    This update for diffutils fixes the following issue:


    Advisory IDSUSE-RU-2020:2384-1
    ReleasedSat Aug 29 00:57:13 2020
    SummaryRecommended update for e2fsprogs
    Typerecommended
    Severitylow
    References1170964
    Description:

    This update for e2fsprogs fixes the following issues:


    Advisory IDSUSE-RU-2020:2420-1
    ReleasedTue Sep 1 13:48:35 2020
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1174551,1174736
    Description:

    This update for zlib provides the following fixes:


    Advisory IDSUSE-SU-2020:2445-1
    ReleasedWed Sep 2 09:33:02 2020
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1175109,CVE-2020-8231
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2020:2581-1
    ReleasedWed Sep 9 13:07:07 2020
    SummarySecurity update for openldap2
    Typesecurity
    Severitymoderate
    References1174154,CVE-2020-15719
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-SU-2020:2612-1
    ReleasedFri Sep 11 11:18:01 2020
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1176179,CVE-2020-24977
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2020:2651-1
    ReleasedWed Sep 16 14:42:55 2020
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1175811,1175830,1175831
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-SU-2020:2712-1
    ReleasedTue Sep 22 17:08:03 2020
    SummarySecurity update for openldap2
    Typesecurity
    Severitymoderate
    References1175568,CVE-2020-8027
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2020:2819-1
    ReleasedThu Oct 1 10:39:16 2020
    SummaryRecommended update for libzypp, zypper
    Typerecommended
    Severitymoderate
    References1165424,1173273,1173529,1174240,1174561,1174918,1175342,1175592
    Description:

    This update for libzypp, zypper provides the following fixes:
    Changes in libzypp:


    Changes in zypper:


    Advisory IDSUSE-RU-2020:2850-1
    ReleasedFri Oct 2 12:26:03 2020
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1175110
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2020:2852-1
    ReleasedFri Oct 2 16:55:39 2020
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1173470,1175844
    Description:

    This update for openssl-1_1 fixes the following issues:
    FIPS:


    Advisory IDSUSE-RU-2020:2869-1
    ReleasedTue Oct 6 16:13:20 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1011548,1153943,1153946,1161239,1171762
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-RU-2020:2893-1
    ReleasedMon Oct 12 14:14:55 2020
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1177479
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2020:2914-1
    ReleasedTue Oct 13 17:25:20 2020
    SummarySecurity update for bind
    Typesecurity
    Severitymoderate
    References1100369,1109160,1118367,1118368,1128220,1156205,1157051,1161168,1170667,1170713,1171313,1171740,1172958,1173307,1173311,1173983,1175443,1176092,1176674,906079,CVE-2017-3136,CVE-2018-5741,CVE-2019-6477,CVE-2020-8616,CVE-2020-8617,CVE-2020-8618,CVE-2020-8619,CVE-2020-8620,CVE-2020-8621,CVE-2020-8622,CVE-2020-8623,CVE-2020-8624
    Description:

    This update for bind fixes the following issues:
    BIND was upgraded to version 9.16.6:
    Note:


    Fixing security issues:

    Other issues fixed:


    Advisory IDSUSE-SU-2020:2947-1
    ReleasedFri Oct 16 15:23:07 2020
    SummarySecurity update for gcc10, nvptx-tools
    Typesecurity
    Severitymoderate
    References1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844
    Description:

    This update for gcc10, nvptx-tools fixes the following issues:
    This update provides the GCC10 compiler suite and runtime libraries.
    The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by the gcc10 variants.
    The new compiler variants are available with '-10' suffix, you can specify them via:
    CC=gcc-10 CXX=g++-10
    or similar commands.
    For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
    Changes in nvptx-tools:


    Advisory IDSUSE-RU-2020:2958-1
    ReleasedTue Oct 20 12:24:55 2020
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1158830
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2020:2983-1
    ReleasedWed Oct 21 15:03:03 2020
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1176123
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-OU-2020:3026-1
    ReleasedFri Oct 23 15:35:51 2020
    SummaryOptional update for the Public Cloud Module
    Typeoptional
    Severitymoderate
    References
    Description:


    This update adds the Google Cloud Storage packages to the Public Cloud module (jsc#ECO-2398). The following packages were included:


    Advisory IDSUSE-RU-2020:3048-1
    ReleasedTue Oct 27 16:05:17 2020
    SummaryRecommended update for libsolv, libzypp, yaml-cpp, zypper
    Typerecommended
    Severitymoderate
    References1174918,1176192,1176435,1176712,1176740,1176902,1177238,935885
    Description:

    This update for libsolv, libzypp, yaml-cpp, zypper fixes the following issues:
    libzypp was updated to 17.25.1:


    yaml-cpp:

    No source changes were done to yaml-cpp.
    zypper was updated to 1.14.40:

    libsolv was updated to 0.7.15 to fix:


    Advisory IDSUSE-RU-2020:3259-1
    ReleasedMon Nov 9 14:28:19 2020
    SummaryRecommended update for haproxy
    Typerecommended
    Severitymoderate
    References1178277
    Description:

    This update for haproxy fixes the following issues:


    Advisory IDSUSE-SU-2020:3313-1
    ReleasedThu Nov 12 16:07:37 2020
    SummarySecurity update for openldap2
    Typesecurity
    Severityimportant
    References1178387,CVE-2020-25692
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2020:3462-1
    ReleasedFri Nov 20 13:14:35 2020
    SummaryRecommended update for pam and sudo
    Typerecommended
    Severitymoderate
    References1174593,1177858,1178727
    Description:

    This update for pam and sudo fixes the following issue:
    pam:


    sudo:


    Advisory IDSUSE-OU-2020:3481-1
    ReleasedMon Nov 23 11:17:09 2020
    SummaryOptional update for vim
    Typeoptional
    Severitylow
    References1166602,1173256,1174564,1176549
    Description:

    This update for vim doesn't fix any user visible issues and it is optional to install.


    Advisory IDSUSE-RU-2020:3581-1
    ReleasedTue Dec 1 14:40:22 2020
    SummaryRecommended update for libusb-1_0
    Typerecommended
    Severitymoderate
    References1178376
    Description:

    This update for libusb-1_0 fixes the following issues:


    Advisory IDSUSE-RU-2020:3620-1
    ReleasedThu Dec 3 17:03:55 2020
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2020:3703-1
    ReleasedMon Dec 7 20:17:32 2020
    SummaryRecommended update for aaa_base
    Typerecommended
    Severitymoderate
    References1179431
    Description:

    This update for aaa_base fixes the following issue:


    Advisory IDSUSE-SU-2020:3721-1
    ReleasedWed Dec 9 13:36:46 2020
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1179491,CVE-2020-1971
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2020:3735-1
    ReleasedWed Dec 9 18:19:24 2020
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1179398,1179399,1179593,CVE-2020-8284,CVE-2020-8285,CVE-2020-8286
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2020:3791-1
    ReleasedMon Dec 14 17:39:19 2020
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for gzip fixes the following issue:


    Advisory IDSUSE-RU-2020:3809-1
    ReleasedTue Dec 15 13:46:05 2020
    SummaryRecommended update for glib2
    Typerecommended
    Severitymoderate
    References1178346
    Description:

    This update for glib2 fixes the following issues:
    Update from version 2.62.5 to version 2.62.6:


    Advisory IDSUSE-RU-2020:3942-1
    ReleasedTue Dec 29 12:22:01 2020
    SummaryRecommended update for libidn2
    Typerecommended
    Severitymoderate
    References1180138
    Description:

    This update for libidn2 fixes the following issues:


    Advisory IDSUSE-RU-2020:3943-1
    ReleasedTue Dec 29 12:24:45 2020
    SummaryRecommended update for libxml2
    Typerecommended
    Severitymoderate
    References1178823
    Description:

    This update for libxml2 fixes the following issues:
    Avoid quadratic checking of identity-constraints, speeding up XML validation (bsc#1178823)


    Advisory IDSUSE-RU-2021:6-1
    ReleasedMon Jan 4 07:05:06 2021
    SummaryRecommended update for libdlm
    Typerecommended
    Severitymoderate
    References1098449,1144793,1168771,1177533,1177658
    Description:

    This update for libdlm fixes the following issues:


    Advisory IDSUSE-SU-2021:109-1
    ReleasedWed Jan 13 10:13:24 2021
    SummarySecurity update for libzypp, zypper
    Typesecurity
    Severitymoderate
    References1050625,1174016,1177238,1177275,1177427,1177583,1178910,1178966,1179083,1179222,1179415,1179909,CVE-2017-9271
    Description:

    This update for libzypp, zypper fixes the following issues:
    Update zypper to version 1.14.41
    Update libzypp to 17.25.4


    yast-installation was updated to 4.2.48:


    Advisory IDSUSE-SU-2021:129-1
    ReleasedThu Jan 14 12:26:15 2021
    SummarySecurity update for openldap2
    Typesecurity
    Severitymoderate
    References1178909,1179503,CVE-2020-25709,CVE-2020-25710
    Description:

    This update for openldap2 fixes the following issues:
    Security issues fixed:


    Non-security issue fixed:


    Advisory IDSUSE-RU-2021:152-1
    ReleasedFri Jan 15 17:04:47 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1179691,1179738
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2021:169-1
    ReleasedTue Jan 19 16:18:46 2021
    SummaryRecommended update for libsolv, libzypp, zypper
    Typerecommended
    Severitymoderate
    References1179816,1180077,1180663,1180721
    Description:

    This update for libsolv, libzypp, zypper fixes the following issues:
    libzypp was updated to 17.25.6:


    zypper was updated to 1.14.42:

    libsolv was updated to 0.7.16;


    Advisory IDSUSE-SU-2021:197-1
    ReleasedFri Jan 22 15:17:42 2021
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1171883,CVE-2020-8025
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2021:220-1
    ReleasedTue Jan 26 14:00:51 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for keyutils fixes the following issues:


    Advisory IDSUSE-RU-2021:278-1
    ReleasedTue Feb 2 09:43:08 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1181319
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2021:293-1
    ReleasedWed Feb 3 12:52:34 2021
    SummaryRecommended update for gmp
    Typerecommended
    Severitymoderate
    References1180603
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-RU-2021:294-1
    ReleasedWed Feb 3 12:54:28 2021
    SummaryRecommended update for libprotobuf
    Typerecommended
    Severitymoderate
    References
    Description:


    libprotobuf was updated to fix:


    Advisory IDSUSE-RU-2021:302-1
    ReleasedThu Feb 4 13:18:35 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severityimportant
    References1179691
    Description:

    This update for lvm2 fixes the following issues:


    If this behavior is still wanted, please change this manually in the lvm.conf


    Advisory IDSUSE-OU-2021:339-1
    ReleasedMon Feb 8 13:16:07 2021
    SummaryOptional update for pam
    Typeoptional
    Severitylow
    References
    Description:

    This update for pam fixes the following issues:


    This patch is optional to be installed - it doesn't fix any bugs.


    Advisory IDSUSE-RU-2021:656-1
    ReleasedMon Mar 1 09:34:21 2021
    SummaryRecommended update for protobuf
    Typerecommended
    Severitymoderate
    References1177127
    Description:

    This update for protobuf fixes the following issues:


    Advisory IDSUSE-SU-2021:723-1
    ReleasedMon Mar 8 16:45:27 2021
    SummarySecurity update for openldap2
    Typesecurity
    Severityimportant
    References1182279,1182408,1182411,1182412,1182413,1182415,1182416,1182417,1182418,1182419,1182420,CVE-2020-36221,CVE-2020-36222,CVE-2020-36223,CVE-2020-36224,CVE-2020-36225,CVE-2020-36226,CVE-2020-36227,CVE-2020-36228,CVE-2020-36229,CVE-2020-36230,CVE-2021-27212
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-SU-2021:754-1
    ReleasedTue Mar 9 17:10:49 2021
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitymoderate
    References1182331,1182333,1182959,CVE-2021-23840,CVE-2021-23841
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2021:778-1
    ReleasedFri Mar 12 17:42:25 2021
    SummarySecurity update for glib2
    Typesecurity
    Severityimportant
    References1182328,1182362,CVE-2021-27218,CVE-2021-27219
    Description:

    This update for glib2 fixes the following issues:


    Advisory IDSUSE-RU-2021:786-1
    ReleasedMon Mar 15 11:19:23 2021
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1176201
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-RU-2021:874-1
    ReleasedThu Mar 18 09:41:54 2021
    SummaryRecommended update for libsolv, libzypp, zypper
    Typerecommended
    Severitymoderate
    References1179847,1181328,1181622,1182629
    Description:

    This update for libsolv, libzypp, zypper fixes the following issues:


    Advisory IDSUSE-RU-2021:924-1
    ReleasedTue Mar 23 10:00:49 2021
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094
    Description:

    This update for filesystem the following issues:


    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2021:926-1
    ReleasedTue Mar 23 13:20:24 2021
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitymoderate
    References1083473,1112500,1115408,1165780,1183012
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:


    Advisory IDSUSE-SU-2021:930-1
    ReleasedWed Mar 24 12:09:23 2021
    SummarySecurity update for nghttp2
    Typesecurity
    Severityimportant
    References1172442,1181358,CVE-2020-11080
    Description:

    This update for nghttp2 fixes the following issues:


    Advisory IDSUSE-SU-2021:948-1
    ReleasedWed Mar 24 14:31:34 2021
    SummarySecurity update for zstd
    Typesecurity
    Severitymoderate
    References1183370,1183371,CVE-2021-24031,CVE-2021-24032
    Description:

    This update for zstd fixes the following issues:


    Advisory IDSUSE-SU-2021:955-1
    ReleasedThu Mar 25 16:11:48 2021
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1183852,CVE-2021-3449
    Description:

    This update for openssl-1_1 fixes the security issue:


    Advisory IDSUSE-RU-2021:991-1
    ReleasedWed Mar 31 13:28:37 2021
    SummaryRecommended update for vim
    Typerecommended
    Severitymoderate
    References1182324
    Description:

    This update for vim provides the following fixes:


    Advisory IDSUSE-RU-2021:1004-1
    ReleasedThu Apr 1 15:07:09 2021
    SummaryRecommended update for libcap
    Typerecommended
    Severitymoderate
    References1180073
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-SU-2021:1006-1
    ReleasedThu Apr 1 17:44:57 2021
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1183933,1183934,CVE-2021-22876,CVE-2021-22890
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2021:1018-1
    ReleasedTue Apr 6 14:29:13 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1180713
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1141-1
    ReleasedMon Apr 12 13:13:36 2021
    SummaryRecommended update for openldap2
    Typerecommended
    Severitylow
    References1182791
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2021:1169-1
    ReleasedTue Apr 13 15:01:42 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitylow
    References1181976
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1289-1
    ReleasedWed Apr 21 14:02:46 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1177047
    Description:

    This update for gzip fixes the following issues:


    Advisory IDSUSE-RU-2021:1295-1
    ReleasedWed Apr 21 14:08:19 2021
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitymoderate
    References1184136
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:


    Advisory IDSUSE-OU-2021:1296-1
    ReleasedWed Apr 21 14:09:28 2021
    SummaryOptional update for e2fsprogs
    Typeoptional
    Severitylow
    References1183791
    Description:

    This update for e2fsprogs fixes the following issues:


    This patch does not fix any user visible issues and is therefore optional to install.


    Advisory IDSUSE-OU-2021:1299-1
    ReleasedWed Apr 21 14:11:41 2021
    SummaryOptional update for gpgme
    Typeoptional
    Severitylow
    References1183801
    Description:

    This update for gpgme fixes the following issues:


    This patch is optional to install and does not provide any user visible bug fixes.


    Advisory IDSUSE-RU-2021:1407-1
    ReleasedWed Apr 28 15:49:02 2021
    SummaryRecommended update for libcap
    Typerecommended
    Severityimportant
    References1184690
    Description:

    This update for libcap fixes the following issues:


    Advisory IDSUSE-RU-2021:1426-1
    ReleasedThu Apr 29 06:23:13 2021
    SummaryRecommended update for libsolv
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for libsolv fixes the following issues:


    Advisory IDSUSE-RU-2021:1449-1
    ReleasedFri Apr 30 08:08:25 2021
    SummaryRecommended update for systemd-presets-branding-SLE
    Typerecommended
    Severitymoderate
    References1165780
    Description:

    This update for systemd-presets-branding-SLE fixes the following issues:


    Advisory IDSUSE-SU-2021:1466-1
    ReleasedTue May 4 08:30:57 2021
    SummarySecurity update for permissions
    Typesecurity
    Severityimportant
    References1182899
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2021:1481-1
    ReleasedTue May 4 14:18:32 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1178680
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-SU-2021:1523-1
    ReleasedWed May 5 18:24:20 2021
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1185408,1185409,1185410,CVE-2021-3516,CVE-2021-3517,CVE-2021-3518
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2021:1526-1
    ReleasedThu May 6 08:57:30 2021
    SummaryRecommended update for bash
    Typerecommended
    Severityimportant
    References1183064
    Description:

    This update for bash fixes the following issues:


    Advisory IDSUSE-RU-2021:1528-1
    ReleasedThu May 6 15:31:23 2021
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1161276
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2021:1543-1
    ReleasedFri May 7 15:16:33 2021
    SummaryRecommended update for patterns-microos
    Typerecommended
    Severitymoderate
    References1184435
    Description:

    This update for patterns-microos provides the following fix:


    Advisory IDSUSE-RU-2021:1544-1
    ReleasedFri May 7 16:34:41 2021
    SummaryRecommended update for libzypp
    Typerecommended
    Severitymoderate
    References1180851,1181874,1182936,1183628,1184997,1185239
    Description:

    This update for libzypp fixes the following issues:
    Upgrade from version 17.25.8 to version 17.25.10


    Advisory IDSUSE-RU-2021:1549-1
    ReleasedMon May 10 13:48:00 2021
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1185417
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-RU-2021:1582-1
    ReleasedWed May 12 13:40:03 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1184687,1185190
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2021:1612-1
    ReleasedFri May 14 17:09:39 2021
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1184614
    Description:

    This update for openldap2 fixes the following issue:


    Advisory IDSUSE-RU-2021:1643-1
    ReleasedWed May 19 13:51:48 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1181443,1184358,1185562
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:1654-1
    ReleasedWed May 19 16:43:36 2021
    SummarySecurity update for libxml2
    Typesecurity
    Severityimportant
    References1185408,1185409,1185410,1185698,CVE-2021-3516,CVE-2021-3517,CVE-2021-3518,CVE-2021-3537
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-SU-2021:1762-1
    ReleasedWed May 26 12:30:01 2021
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1186114,CVE-2021-22898
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-SU-2021:1825-1
    ReleasedTue Jun 1 16:24:01 2021
    SummarySecurity update for lz4
    Typesecurity
    Severityimportant
    References1185438,CVE-2021-3520
    Description:

    This update for lz4 fixes the following issues:


    Advisory IDSUSE-RU-2021:1833-1
    ReleasedWed Jun 2 15:32:28 2021
    SummaryRecommended update for zypper
    Typerecommended
    Severitymoderate
    References1153687,1180851,1181874,1182372,1182936,1183268,1183589,1183628,1184997,1185239
    Description:

    This update for zypper fixes the following issues:
    zypper was upgraded to 1.14.44:


    libzypp was upgraded from version 17.25.8 to version 17.25.10


    Advisory IDSUSE-RU-2021:1861-1
    ReleasedFri Jun 4 09:59:40 2021
    SummaryRecommended update for gcc10
    Typerecommended
    Severitymoderate
    References1029961,1106014,1178577,1178624,1178675,1182016
    Description:

    This update for gcc10 fixes the following issues:


    Advisory IDSUSE-RU-2021:1879-1
    ReleasedTue Jun 8 09:16:09 2021
    SummaryRecommended update for libzypp, zypper
    Typerecommended
    Severityimportant
    References1184326,1184399,1184997,1185325
    Description:

    This update for libzypp, zypper fixes the following issues:
    libzypp was updated to 17.26.0:


    zypper was updated to 1.14.45:


    Advisory IDSUSE-SU-2021:1917-1
    ReleasedWed Jun 9 14:48:05 2021
    SummarySecurity update for libxml2
    Typesecurity
    Severitymoderate
    References1186015,CVE-2021-3541
    Description:

    This update for libxml2 fixes the following issues:


    Advisory IDSUSE-RU-2021:1935-1
    ReleasedThu Jun 10 10:45:09 2021
    SummaryRecommended update for gzip
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for gzip fixes the following issue:


    Advisory IDSUSE-RU-2021:1937-1
    ReleasedThu Jun 10 10:47:09 2021
    SummaryRecommended update for nghttp2
    Typerecommended
    Severitymoderate
    References1186642
    Description:


    This update for nghttp2 fixes the following issue:


    Advisory IDSUSE-SU-2021:2157-1
    ReleasedThu Jun 24 15:40:14 2021
    SummarySecurity update for libgcrypt
    Typesecurity
    Severityimportant
    References1187212,CVE-2021-33560
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-RU-2021:2173-1
    ReleasedMon Jun 28 14:59:45 2021
    SummaryRecommended update for automake
    Typerecommended
    Severitymoderate
    References1040589,1047218,1182604,1185540,1186049
    Description:

    This update for automake fixes the following issues:


    This update for pcre fixes the following issues:

    This update for brp-check-suse fixes the following issues:


    Advisory IDSUSE-RU-2021:2178-1
    ReleasedMon Jun 28 15:56:15 2021
    SummaryRecommended update for systemd-presets-common-SUSE
    Typerecommended
    Severitymoderate
    References1186561
    Description:

    This update for systemd-presets-common-SUSE fixes the following issues:
    When installing the systemd-presets-common-SUSE package for the first time in a new system, it might happen that some services are installed before systemd so the %systemd_pre/post macros would not work. This is handled by enabling all preset services in this package's %posttrans section but it wasn't enabling user services, just system services. Now it enables also the user services installed before this package (bsc#1186561)


    Advisory IDSUSE-SU-2021:2196-1
    ReleasedTue Jun 29 09:41:39 2021
    SummarySecurity update for lua53
    Typesecurity
    Severitymoderate
    References1175448,1175449,CVE-2020-24370,CVE-2020-24371
    Description:

    This update for lua53 fixes the following issues:
    Update to version 5.3.6:


    Advisory IDSUSE-RU-2021:2205-1
    ReleasedWed Jun 30 09:17:41 2021
    SummaryRecommended update for openldap2
    Typerecommended
    Severityimportant
    References1187210
    Description:

    This update for openldap2 fixes the following issues:


    Advisory IDSUSE-RU-2021:2210-1
    ReleasedWed Jun 30 13:00:09 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1184124
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2021:2273-1
    ReleasedThu Jul 8 09:48:48 2021
    SummaryRecommended update for libzypp, zypper
    Typerecommended
    Severitymoderate
    References1186447,1186503
    Description:

    This update for libzypp, zypper fixes the following issues:


    Advisory IDSUSE-SU-2021:2292-1
    ReleasedMon Jul 12 08:25:20 2021
    SummarySecurity update for dbus-1
    Typesecurity
    Severityimportant
    References1187105,CVE-2020-35512
    Description:

    This update for dbus-1 fixes the following issues:


    Advisory IDSUSE-RU-2021:2316-1
    ReleasedWed Jul 14 13:49:55 2021
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1185807,1185828,1185958,1186411,1187154,1187292
    Description:

    This update for systemd fixes the following issues:




    Advisory IDSUSE-SU-2021:2320-1
    ReleasedWed Jul 14 17:01:06 2021
    SummarySecurity update for sqlite3
    Typesecurity
    Severityimportant
    References1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
    Description:

    This update for sqlite3 fixes the following issues:


    Advisory IDSUSE-RU-2021:2394-1
    ReleasedMon Jul 19 12:06:53 2021
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1177695,1187093
    Description:

    This update for suse-module-tools provides the following fixes:


    Advisory IDSUSE-RU-2021:2399-1
    ReleasedMon Jul 19 19:06:22 2021
    SummaryRecommended update for release packages
    Typerecommended
    Severitymoderate
    References1099521
    Description:

    This update for the release packages provides the following fix:


    Advisory IDSUSE-SU-2021:2410-1
    ReleasedTue Jul 20 14:41:26 2021
    SummarySecurity update for systemd
    Typesecurity
    Severityimportant
    References1188063,CVE-2021-33910
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-SU-2021:2439-1
    ReleasedWed Jul 21 13:46:48 2021
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1188217,1188218,1188219,1188220,CVE-2021-22922,CVE-2021-22923,CVE-2021-22924,CVE-2021-22925
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2021:2456-1
    ReleasedThu Jul 22 15:28:39 2021
    SummaryRecommended update for pam-config
    Typerecommended
    Severitymoderate
    References1187091
    Description:

    This update for pam-config fixes the following issues:


    Advisory IDSUSE-RU-2021:2626-1
    ReleasedThu Aug 5 12:10:35 2021
    SummaryRecommended maintenance update for libeconf
    Typerecommended
    Severitymoderate
    References1188348
    Description:

    This update for libeconf fixes the following issue:


    Advisory IDSUSE-RU-2021:2627-1
    ReleasedThu Aug 5 12:10:46 2021
    SummaryRecommended maintenance update for systemd-default-settings
    Typerecommended
    Severitymoderate
    References1188348
    Description:

    This update for systemd-default-settings fixes the following issue:


    Advisory IDSUSE-SU-2021:2682-1
    ReleasedThu Aug 12 20:06:19 2021
    SummarySecurity update for rpm
    Typesecurity
    Severityimportant
    References1179416,1181805,1183543,1183545,CVE-2021-20266,CVE-2021-20271,CVE-2021-3421
    Description:

    This update for rpm fixes the following issues:


    Security fixes:



    Advisory IDSUSE-SU-2021:2689-1
    ReleasedMon Aug 16 10:54:52 2021
    SummarySecurity update for cpio
    Typesecurity
    Severityimportant
    References1189206,CVE-2021-38185
    Description:

    This update for cpio fixes the following issues:
    It was possible to trigger Remote code execution due to a integer overflow (CVE-2021-38185, bsc#1189206)


    Advisory IDSUSE-RU-2021:2763-1
    ReleasedTue Aug 17 17:16:22 2021
    SummaryRecommended update for cpio
    Typerecommended
    Severitycritical
    References1189465
    Description:

    This update for cpio fixes the following issues:


    Advisory IDSUSE-SU-2021:2773-1
    ReleasedWed Aug 18 16:05:09 2021
    SummarySecurity update for haproxy
    Typesecurity
    Severityimportant
    References1189366
    Description:

    This update for haproxy fixes the following issues:


    Advisory IDSUSE-RU-2021:2780-1
    ReleasedThu Aug 19 16:09:15 2021
    SummaryRecommended update for cpio
    Typerecommended
    Severitycritical
    References1189465,CVE-2021-38185
    Description:

    This update for cpio fixes the following issues:


    Advisory IDSUSE-RU-2021:2786-1
    ReleasedFri Aug 20 02:02:23 2021
    SummaryRecommended update for bash
    Typerecommended
    Severityimportant
    References1057452,1188287
    Description:

    This update for bash fixes the following issues:


    Advisory IDSUSE-SU-2021:2809-1
    ReleasedMon Aug 23 12:12:31 2021
    SummarySecurity update for systemd
    Typesecurity
    Severitymoderate
    References1166028,1171962,1184994,1185972,1188063,CVE-2020-13529,CVE-2021-33910
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-SU-2021:2810-1
    ReleasedMon Aug 23 12:14:30 2021
    SummarySecurity update for dbus-1
    Typesecurity
    Severitymoderate
    References1172505,CVE-2020-12049
    Description:

    This update for dbus-1 fixes the following issues:


    Advisory IDSUSE-SU-2021:2830-1
    ReleasedTue Aug 24 16:20:18 2021
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severityimportant
    References1189520,1189521,CVE-2021-3711,CVE-2021-3712
    Description:

    This update for openssl-1_1 fixes the following security issues:



    Advisory IDSUSE-RU-2021:2938-1
    ReleasedFri Sep 3 09:19:36 2021
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1184614
    Description:


    This update for openldap2 fixes the following issue:


    Advisory IDSUSE-RU-2021:2950-1
    ReleasedFri Sep 3 11:59:19 2021
    SummaryRecommended update for pcre2
    Typerecommended
    Severitymoderate
    References1187937
    Description:

    This update for pcre2 fixes the following issue:

    PHP versions.


    Advisory IDSUSE-SU-2021:2966-1
    ReleasedTue Sep 7 09:49:14 2021
    SummarySecurity update for openssl-1_1
    Typesecurity
    Severitylow
    References1189521,CVE-2021-3712
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-SU-2021:2975-1
    ReleasedTue Sep 7 21:08:34 2021
    SummarySecurity update for haproxy
    Typesecurity
    Severitymoderate
    References1189877,CVE-2021-40346
    Description:

    This update for haproxy fixes the following issues:


    Advisory IDSUSE-RU-2021:3001-1
    ReleasedThu Sep 9 15:08:13 2021
    SummaryRecommended update for netcfg
    Typerecommended
    Severitymoderate
    References1189683
    Description:

    This update for netcfg fixes the following issues:


    Advisory IDSUSE-RU-2021:3013-1
    ReleasedThu Sep 9 16:55:40 2021
    SummaryRecommended update for patterns-base, patterns-server-enterprise, sles15-image
    Typerecommended
    Severitymoderate
    References1183154,1189550
    Description:

    This update for patterns-base, patterns-server-enterprise, sles15-image fixes the following issues:


    Advisory IDSUSE-RU-2021:3182-1
    ReleasedTue Sep 21 17:04:26 2021
    SummaryRecommended update for file
    Typerecommended
    Severitymoderate
    References1189996
    Description:

    This update for file fixes the following issues:


    Advisory IDSUSE-RU-2021:3203-1
    ReleasedThu Sep 23 14:41:35 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1189537,1190190
    Description:

    This update for kmod fixes the following issues:



    Advisory IDSUSE-SU-2021:3291-1
    ReleasedWed Oct 6 16:45:36 2021
    SummarySecurity update for glibc
    Typesecurity
    Severitymoderate
    References1186489,1187911,CVE-2021-33574,CVE-2021-35942
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-SU-2021:3298-1
    ReleasedWed Oct 6 16:54:52 2021
    SummarySecurity update for curl
    Typesecurity
    Severitymoderate
    References1190373,1190374,CVE-2021-22946,CVE-2021-22947
    Description:

    This update for curl fixes the following issues:


    Advisory IDSUSE-RU-2021:3310-1
    ReleasedWed Oct 6 18:12:41 2021
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1134353,1184994,1188291,1188588,1188713,1189446,1189480
    Description:

    This update for systemd fixes the following issues:




    Additional fixes:


    Advisory IDSUSE-OU-2021:3327-1
    ReleasedMon Oct 11 11:44:50 2021
    SummaryOptional update for coreutils
    Typeoptional
    Severitylow
    References1189454
    Description:

    This optional update for coreutils fixes the following issue:


    Advisory IDSUSE-RU-2021:3411-1
    ReleasedWed Oct 13 10:42:25 2021
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1191019
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2021:3413-1
    ReleasedWed Oct 13 10:50:45 2021
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severityimportant
    References1189441,1189841,1190598
    Description:

    This update for suse-module-tools fixes the following issues:


    Advisory IDSUSE-SU-2021:3445-1
    ReleasedFri Oct 15 09:03:39 2021
    SummarySecurity update for rpm
    Typesecurity
    Severityimportant
    References1183659,1185299,1187670,1188548
    Description:

    This update for rpm fixes the following issues:
    Security issues fixed:


    Maintaince issues fixed:


    Advisory IDSUSE-SU-2021:3474-1
    ReleasedWed Oct 20 08:41:31 2021
    SummarySecurity update for util-linux
    Typesecurity
    Severitymoderate
    References1178236,1188921,CVE-2021-37600
    Description:

    This update for util-linux fixes the following issues:


    Advisory IDSUSE-RU-2021:3480-1
    ReleasedWed Oct 20 11:24:10 2021
    SummaryRecommended update for yast2-network
    Typerecommended
    Severitymoderate
    References1185016,1185524,1186910,1187270,1187512,1188344,1190645,1190739,1190915,1190933
    Description:

    This update for yast2-network fixes the following issues:


    Advisory IDSUSE-SU-2021:3490-1
    ReleasedWed Oct 20 16:31:55 2021
    SummarySecurity update for ncurses
    Typesecurity
    Severitymoderate
    References1190793,CVE-2021-39537
    Description:

    This update for ncurses fixes the following issues:


    Advisory IDSUSE-RU-2021:3494-1
    ReleasedWed Oct 20 16:48:46 2021
    SummaryRecommended update for pam
    Typerecommended
    Severitymoderate
    References1190052
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-RU-2021:3501-1
    ReleasedFri Oct 22 10:42:46 2021
    SummaryRecommended update for libzypp, zypper, libsolv, protobuf
    Typerecommended
    Severitymoderate
    References1186503,1186602,1187224,1187425,1187466,1187738,1187760,1188156,1188435,1189031,1190059,1190199,1190465,1190712,1190815
    Description:

    This update for libzypp, zypper, libsolv and protobuf fixes the following issues:


    Advisory IDSUSE-RU-2021:3509-1
    ReleasedTue Oct 26 09:47:40 2021
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severityimportant
    References1191200,1191260,1191480,1191804,1191922
    Description:

    This update for suse-module-tools fixes the following issues:
    Update to version 15.3.13:


    Advisory IDSUSE-RU-2021:3510-1
    ReleasedTue Oct 26 11:22:15 2021
    SummaryRecommended update for pam
    Typerecommended
    Severityimportant
    References1191987
    Description:

    This update for pam fixes the following issues:


    Advisory IDSUSE-SU-2021:3529-1
    ReleasedWed Oct 27 09:23:32 2021
    SummarySecurity update for pcre
    Typesecurity
    Severitymoderate
    References1172973,1172974,CVE-2019-20838,CVE-2020-14155
    Description:

    This update for pcre fixes the following issues:
    Update pcre to version 8.45:


    Advisory IDSUSE-RU-2021:3564-1
    ReleasedWed Oct 27 16:12:08 2021
    SummaryRecommended update for rpm-config-SUSE
    Typerecommended
    Severitymoderate
    References1190850
    Description:

    This update for rpm-config-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2021:3589-1
    ReleasedMon Nov 1 19:27:52 2021
    SummaryRecommended update for apparmor
    Typerecommended
    Severitymoderate
    References1191690
    Description:

    This update for apparmor fixes the following issues:


    Advisory IDSUSE-RU-2021:3663-1
    ReleasedMon Nov 15 19:14:32 2021
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1191804
    Description:

    This update for suse-module-tools fixes the following issues:


    Advisory IDSUSE-RU-2021:3786-1
    ReleasedWed Nov 24 05:59:13 2021
    SummaryRecommended update for rpm-config-SUSE
    Typerecommended
    Severityimportant
    References1192160
    Description:

    This update for rpm-config-SUSE fixes the following issues:


    Advisory IDSUSE-RU-2021:3792-1
    ReleasedWed Nov 24 06:12:09 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1192104
    Description:

    This update for kmod fixes the following issues:


    Advisory IDSUSE-RU-2021:3799-1
    ReleasedWed Nov 24 18:07:54 2021
    SummaryRecommended update for gcc11
    Typerecommended
    Severitymoderate
    References1187153,1187273,1188623
    Description:

    This update for gcc11 fixes the following issues:
    The additional GNU compiler collection GCC 11 is provided:
    To select these compilers install the packages:


    to select them for building:

    The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.


    Advisory IDSUSE-RU-2021:3808-1
    ReleasedFri Nov 26 00:30:54 2021
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1186071,1190440,1190984,1192161
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2021:3870-1
    ReleasedThu Dec 2 07:11:50 2021
    SummaryRecommended update for libzypp, zypper
    Typerecommended
    Severitymoderate
    References1190356,1191286,1191324,1191370,1191609,1192337,1192436
    Description:

    This update for libzypp, zypper fixes the following issues:
    libzypp:


    zypper:


    Advisory IDSUSE-RU-2021:3872-1
    ReleasedThu Dec 2 07:25:55 2021
    SummaryRecommended update for cracklib
    Typerecommended
    Severitymoderate
    References1191736
    Description:

    This update for cracklib fixes the following issues:


    Advisory IDSUSE-RU-2021:3891-1
    ReleasedFri Dec 3 10:21:49 2021
    SummaryRecommended update for keyutils
    Typerecommended
    Severitymoderate
    References1029961,1113013,1187654
    Description:

    This update for keyutils fixes the following issues:


    keyutils was updated to 1.6.3 (jsc#SLE-20016):

    Updated to 1.6:

    Updated to 1.5.11 (bsc#1113013)


    Advisory IDSUSE-SU-2021:3899-1
    ReleasedFri Dec 3 11:27:41 2021
    SummarySecurity update for aaa_base
    Typesecurity
    Severitymoderate
    References1162581,1174504,1191563,1192248
    Description:

    This update for aaa_base fixes the following issues:


    Advisory IDSUSE-SU-2021:3946-1
    ReleasedMon Dec 6 14:57:42 2021
    SummarySecurity update for gmp
    Typesecurity
    Severitymoderate
    References1192717,CVE-2021-43618
    Description:

    This update for gmp fixes the following issues:


    Advisory IDSUSE-RU-2021:3963-1
    ReleasedMon Dec 6 19:57:39 2021
    SummaryRecommended update for system-users
    Typerecommended
    Severitymoderate
    References1190401
    Description:

    This update for system-users fixes the following issues:


    Advisory IDSUSE-RU-2021:3980-1
    ReleasedThu Dec 9 16:42:19 2021
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References1191592
    Description:


    glibc was updated to fix the following issue:


    Advisory IDSUSE-RU-2021:3985-1
    ReleasedFri Dec 10 06:08:24 2021
    SummaryRecommended update for suse-module-tools
    Typerecommended
    Severitymoderate
    References1187196
    Description:

    This update for suse-module-tools fixes the following issues:


    Advisory IDSUSE-RU-2021:4014-1
    ReleasedMon Dec 13 13:57:39 2021
    SummaryRecommended update for apparmor
    Typerecommended
    Severitymoderate
    References1191532,1191690
    Description:

    This update for apparmor fixes the following issues:
    Changes in apparmor:


    Advisory IDSUSE-RU-2021:4145-1
    ReleasedWed Dec 22 05:27:48 2021
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1161276
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2021:4165-1
    ReleasedWed Dec 22 22:52:11 2021
    SummaryRecommended update for kmod
    Typerecommended
    Severitymoderate
    References1193430
    Description:

    This update for kmod fixes the following issues:


    Advisory IDSUSE-RU-2021:4175-1
    ReleasedThu Dec 23 11:22:33 2021
    SummaryRecommended update for systemd
    Typerecommended
    Severityimportant
    References1192423,1192858,1193759
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2021:4182-1
    ReleasedThu Dec 23 11:51:51 2021
    SummaryRecommended update for zlib
    Typerecommended
    Severitymoderate
    References1192688
    Description:

    This update for zlib fixes the following issues:


    Advisory IDSUSE-SU-2021:4192-1
    ReleasedTue Dec 28 10:39:50 2021
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1174504
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-RU-2022:2-1
    ReleasedMon Jan 3 08:27:18 2022
    SummaryRecommended update for lvm2
    Typerecommended
    Severitymoderate
    References1183905,1193181
    Description:

    This update for lvm2 fixes the following issues:


    Advisory IDSUSE-RU-2022:4-1
    ReleasedMon Jan 3 08:28:54 2022
    SummaryRecommended update for libgcrypt
    Typerecommended
    Severitymoderate
    References1193480
    Description:

    This update for libgcrypt fixes the following issues:


    Advisory IDSUSE-SU-2022:43-1
    ReleasedTue Jan 11 08:50:13 2022
    SummarySecurity update for systemd
    Typesecurity
    Severitymoderate
    References1178561,1190515,1194178,CVE-2021-3997
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:93-1
    ReleasedTue Jan 18 05:11:58 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severityimportant
    References1192489
    Description:

    This update for openssl-1_1 fixes the following issues:


    Advisory IDSUSE-RU-2022:96-1
    ReleasedTue Jan 18 05:14:44 2022
    SummaryRecommended update for rpm
    Typerecommended
    Severityimportant
    References1180125,1190824,1193711
    Description:

    This update for rpm fixes the following issues:


    Advisory IDSUSE-SU-2022:141-1
    ReleasedThu Jan 20 13:47:16 2022
    SummarySecurity update for permissions
    Typesecurity
    Severitymoderate
    References1169614
    Description:

    This update for permissions fixes the following issues:


    Advisory IDSUSE-SU-2022:144-1
    ReleasedThu Jan 20 16:38:23 2022
    SummarySecurity update for cryptsetup
    Typesecurity
    Severitymoderate
    References1194469,CVE-2021-4122
    Description:

    This update for cryptsetup fixes the following issues:


    Advisory IDSUSE-SU-2022:178-1
    ReleasedTue Jan 25 14:16:23 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1194251,1194362,1194474,1194476,1194477,1194478,1194479,1194480,CVE-2021-45960,CVE-2021-46143,CVE-2022-22822,CVE-2022-22823,CVE-2022-22824,CVE-2022-22825,CVE-2022-22826,CVE-2022-22827
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:184-1
    ReleasedTue Jan 25 18:20:56 2022
    SummarySecurity update for json-c
    Typesecurity
    Severityimportant
    References1171479,CVE-2020-12762
    Description:

    This update for json-c fixes the following issues:


    Advisory IDSUSE-RU-2022:207-1
    ReleasedThu Jan 27 09:24:49 2022
    SummaryRecommended update for glibc
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for glibc fixes the following issues:


    Advisory IDSUSE-RU-2022:228-1
    ReleasedMon Jan 31 06:07:52 2022
    SummaryRecommended update for boost
    Typerecommended
    Severitymoderate
    References1194522
    Description:

    This update for boost fixes the following issues:


    Advisory IDSUSE-SU-2022:330-1
    ReleasedFri Feb 4 09:29:08 2022
    SummarySecurity update for glibc
    Typesecurity
    Severityimportant
    References1194640,1194768,1194770,1194785,CVE-2021-3999,CVE-2022-23218,CVE-2022-23219
    Description:


    This update for glibc fixes the following issues:


    Features added:


    Advisory IDSUSE-RU-2022:335-1
    ReleasedFri Feb 4 10:24:02 2022
    SummaryRecommended update for coreutils
    Typerecommended
    Severitymoderate
    References1189152
    Description:

    This update for coreutils fixes the following issues:


    Advisory IDSUSE-RU-2022:343-1
    ReleasedMon Feb 7 15:16:58 2022
    SummaryRecommended update for systemd
    Typerecommended
    Severitymoderate
    References1193086
    Description:

    This update for systemd fixes the following issues:


    Advisory IDSUSE-RU-2022:348-1
    ReleasedTue Feb 8 13:02:20 2022
    SummaryRecommended update for libzypp
    Typerecommended
    Severityimportant
    References1193007,1193488,1194597,1194898,954813
    Description:

    This update for libzypp fixes the following issues:


    Advisory IDSUSE-SU-2022:283-1
    ReleasedTue Feb 8 16:10:39 2022
    SummarySecurity update for samba
    Typesecurity
    Severitycritical
    References1139519,1183572,1183574,1188571,1191227,1191532,1192684,1193690,1194859,1195048,CVE-2020-27840,CVE-2021-20277,CVE-2021-20316,CVE-2021-36222,CVE-2021-43566,CVE-2021-44141,CVE-2021-44142,CVE-2022-0336
    Description:




    samba was updated to 4.15.4 (jsc#SLE-23329);

    Samba was updated to version 4.15.3

    krb5 was updated to 1.16.3 to 1.19.2

    Changes from 1.19.1:

    Changes from 1.19
    Administrator experience * When a client keytab is present, the GSSAPI krb5 mech will refresh credentials even if the current credentials were acquired manually. * It is now harder to accidentally delete the K/M entry from a KDB. Developer experience * gss_acquire_cred_from() now supports the 'password' and 'verify' options, allowing credentials to be acquired via password and verified using a keytab key. * When an application accepts a GSS security context, the new GSS_C_CHANNEL_BOUND_FLAG will be set if the initiator and acceptor both provided matching channel bindings. * Added the GSS_KRB5_NT_X509_CERT name type, allowing S4U2Self requests to identify the desired client principal by certificate. * PKINIT certauth modules can now cause the hw-authent flag to be set in issued tickets. * The krb5_init_creds_step() API will now issue the same password expiration warnings as krb5_get_init_creds_password(). Protocol evolution * Added client and KDC support for Microsoft's Resource-Based Constrained Delegation, which allows cross-realm S4U2Proxy requests. A third-party database module is required for KDC support. * kadmin/admin is now the preferred server principal name for kadmin connections, and the host-based form is no longer created by default. The client will still try the host-based form as a fallback. * Added client and server support for Microsoft's KERB_AP_OPTIONS_CBT extension, which causes channel bindings to be required for the initiator if the acceptor provided them. The client will send this option if the client_aware_gss_bindings profile option is set. User experience * kinit will now issue a warning if the des3-cbc-sha1 encryption type is used in the reply. This encryption type will be deprecated and removed in future releases. * Added kvno flags --out-cache, --no-store, and --cached-only (inspired by Heimdal's kgetcred).
    Changes from 1.18.3
    Changes from 1.18.2
    Changes from 1.18.1
    Changes from 1.18 Administrator experience: * Remove support for single-DES encryption types. * Change the replay cache format to be more efficient and robust. Replay cache filenames using the new format end with '.rcache2' by default. * setuid programs will automatically ignore environment variables that normally affect krb5 API functions, even if the caller does not use krb5_init_secure_context(). * Add an 'enforce_ok_as_delegate' krb5.conf relation to disable credential forwarding during GSSAPI authentication unless the KDC sets the ok-as-delegate bit in the service ticket. * Use the permitted_enctypes krb5.conf setting as the default value for default_tkt_enctypes and default_tgs_enctypes. Developer experience: * Implement krb5_cc_remove_cred() for all credential cache types. * Add the krb5_pac_get_client_info() API to get the client account name from a PAC. Protocol evolution: * Add KDC support for S4U2Self requests where the user is identified by X.509 certificate. (Requires support for certificate lookup from a third-party KDB module.) * Remove support for an old ('draft 9') variant of PKINIT. * Add support for Microsoft NegoEx. (Requires one or more third-party GSS modules implementing NegoEx mechanisms.) User experience: * Add support for 'dns_canonicalize_hostname=fallback', causing host-based principal names to be tried first without DNS canonicalization, and again with DNS canonicalization if the un-canonicalized server is not found. * Expand single-component hostnames in host-based principal names when DNS canonicalization is not used, adding the system's first DNS search path as a suffix. Add a 'qualify_shortname' krb5.conf relation to override this suffix or disable expansion. * Honor the transited-policy-checked ticket flag on application servers, eliminating the requirement to configure capaths on servers in some scenarios. Code quality: * The libkrb5 serialization code (used to export and import krb5 GSS security contexts) has been simplified and made type-safe. * The libkrb5 code for creating KRB-PRIV, KRB-SAFE, and KRB-CRED messages has been revised to conform to current coding practices. * The test suite has been modified to work with macOS System Integrity Protection enabled. * The test suite incorporates soft-pkcs11 so that PKINIT PKCS11 support can always be tested.
    Changes from 1.17.1
    Changes from 1.17: Administrator experience: Developer experience:
  • The new krb5_get_etype_info() API can be used to retrieve enctype, salt, and string-to-key parameters from the KDC for a client principal.
  • The new GSS_KRB5_NT_ENTERPRISE_NAME name type allows enterprise principal names to be used with GSS-API functions.
  • KDC and kadmind modules which call com_err() will now write to the log file in a format more consistent with other log messages.
  • Programs which use large numbers of memory credential caches should perform better.
  • Protocol evolution:
  • The SPAKE pre-authentication mechanism is now supported. This mechanism protects against password dictionary attacks without requiring any additional infrastructure such as certificates. SPAKE is enabled by default on clients, but must be manually enabled on the KDC for this release.
  • PKINIT freshness tokens are now supported. Freshness tokens can protect against scenarios where an attacker uses temporary access to a smart card to generate authentication requests for the future.
  • Password change operations now prefer TCP over UDP, to avoid spurious error messages about replays when a response packet is dropped.
  • The KDC now supports cross-realm S4U2Self requests when used with a third-party KDB module such as Samba's. The client code for cross-realm S4U2Self requests is also now more robust.
  • User experience:
  • The new ktutil addent -f flag can be used to fetch salt information from the KDC for password-based keys.
  • The new kdestroy -p option can be used to destroy a credential cache within a collection by client principal name.
  • The Kerberos man page has been restored, and documents the environment variables that affect programs using the Kerberos library.
  • Code quality:
  • Python test scripts now use Python 3.
  • Python test scripts now display markers in verbose output, making it easier to find where a failure occurred within the scripts.
  • The Windows build system has been simplified and updated to work with more recent versions of Visual Studio. A large volume of unused Windows-specific code has been removed. Visual Studio 2013 or later is now required.

  • ldb was updated to version 2.4.1 (jsc#SLE-23329);

    + Corrected python behaviour for 'in' for LDAP attributes contained as part of ldb.Message; (bso#14845); + Fix memory handling in ldb.msg_diff; (bso#14836);

    + pyldb: Fix Message.items() for a message containing elements + pyldb: Add test for Message.items() + tests: Use ldbsearch '--scope instead of '-s' + Change page size of guidindexpackv1.ldb + Use a 1MiB lmdb so the test also passes on aarch64 CentOS stream + attrib_handler casefold: simplify space dropping + fix ldb_comparison_fold off-by-one overrun + CVE-2020-27840: pytests: move Dn.validate test to ldb + CVE-2020-27840 ldb_dn: avoid head corruption in ldb_dn_explode + CVE-2021-20277 ldb/attrib_handlers casefold: stay in bounds + CVE-2021-20277 ldb tests: ldb_match tests with extra spaces + improve comments for ldb_module_connect_backend() + test/ldb_tdb: correct introductory comments + ldb.h: remove undefined async_ctx function signatures + correct comments in attrib_handers val_to_int64 + dn tests use cmocka print functions + ldb_match: remove redundant check + add tests for ldb_wildcard_compare + ldb_match: trailing chunk must match end of string + pyldb: catch potential overflow error in py_timestring + ldb: remove some 'if PY3's in tests
    talloc was updated to 2.3.3:

    tdb was updated to version 1.4.4:

    tevent was updated to version 0.11.0:

    sssd was updated to:

    apparmor was updated to:


    Advisory IDSUSE-RU-2022:383-1
    ReleasedTue Feb 15 17:47:36 2022
    SummaryRecommended update for cyrus-sasl
    Typerecommended
    Severitymoderate
    References1194265
    Description:

    This update for cyrus-sasl fixes the following issues:


    Advisory IDSUSE-SU-2022:498-1
    ReleasedFri Feb 18 10:46:56 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1195054,1195217,CVE-2022-23852,CVE-2022-23990
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-RU-2022:520-1
    ReleasedFri Feb 18 12:45:19 2022
    SummaryRecommended update for rpm
    Typerecommended
    Severitymoderate
    References1194968
    Description:

    This update for rpm fixes the following issues:


    Advisory IDSUSE-SU-2022:539-1
    ReleasedMon Feb 21 13:47:51 2022
    SummarySecurity update for systemd
    Typesecurity
    Severitymoderate
    References1191826,1192637,1194178,CVE-2021-3997
    Description:

    This update for systemd fixes the following issues:


    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2022:674-1
    ReleasedWed Mar 2 13:24:38 2022
    SummaryRecommended update for yast2-network
    Typerecommended
    Severitymoderate
    References1187512
    Description:

    This update for yast2-network fixes the following issues:


    Advisory IDSUSE-RU-2022:692-1
    ReleasedThu Mar 3 15:46:47 2022
    SummaryRecommended update for filesystem
    Typerecommended
    Severitymoderate
    References1190447
    Description:

    This update for filesystem fixes the following issues:


    Advisory ID23018
    ReleasedFri Mar 4 08:31:54 2022
    SummarySecurity update for conmon, libcontainers-common, libseccomp, podman
    Typesecurity
    Severitymoderate
    References1176804,1177598,1181640,1182998,1188520,1188914,1193166,1193273,CVE-2020-14370,CVE-2020-15157,CVE-2021-20199,CVE-2021-20291,CVE-2021-3602,CVE-2021-4024,CVE-2021-41190
    Description:

    This update for conmon, libcontainers-common, libseccomp, podman fixes the following issues:
    podman was updated to 3.4.4.
    Security issues fixed:



    Update to version 3.4.4:
    * Bugfixes
    - Fixed a bug where the podman exec command would, under some circumstances, print a warning message about failing to move conmon to the appropriate cgroup (#12535). - Fixed a bug where named volumes created as part of container creation (e.g. podman run --volume avolume:/a/mountpoint or similar) would be mounted with incorrect permissions (#12523). - Fixed a bug where the podman-remote create and podman-remote run commands did not properly handle the --entrypoint='' option (to clear the container's entrypoint) (#12521).

    * Security
    - This release addresses CVE-2021-4024, where the podman machine command opened the gvproxy API (used to forward ports to podman machine VMs) to the public internet on port 7777. - This release addresses CVE-2021-41190, where incomplete specification of behavior regarding image manifests could lead to inconsistent decoding on different clients.
    * Features
    - The --secret type=mount option to podman create and podman run supports a new option, target=, which specifies where in the container the secret will be mounted (#12287).
    * Bugfixes
    - Fixed a bug where rootless Podman would occasionally print warning messages about failing to move the pause process to a new cgroup (#12065). - Fixed a bug where the podman run and podman create commands would, when pulling images, still require TLS even with registries set to Insecure via config file (#11933). - Fixed a bug where the podman generate systemd command generated units that depended on multi-user.target, which has been removed from some distributions (#12438). - Fixed a bug where Podman could not run containers with images that had /etc/ as a symlink (#12189). - Fixed a bug where the podman logs -f command would, when using the journald logs backend, exit immediately if the container had previously been restarted (#12263). - Fixed a bug where, in containers on VMs created by podman machine, the host.containers.internal name pointed to the VM, not the host system (#11642). - Fixed a bug where containers and pods created by the podman play kube command in VMs managed by podman machine would not automatically forward ports from the host machine (#12248). - Fixed a bug where podman machine init would fail on OS X when GNU Coreutils was installed (#12329). - Fixed a bug where podman machine start would exit before SSH on the started VM was accepting connections (#11532). - Fixed a bug where the podman run command with signal proxying (--sig-proxy) enabled could print an error if it attempted to send a signal to a container that had just exited (#8086). - Fixed a bug where the podman stats command would not return correct information for containers running Systemd as PID1 (#12400). - Fixed a bug where the podman image save command would fail on OS X when writing the image to STDOUT (#12402). - Fixed a bug where the podman ps command did not properly handle PS arguments which contained whitespace (#12452). - Fixed a bug where the podman-remote wait command could fail to detect that the container exited and return an error under some circumstances (#12457). - Fixed a bug where the Windows MSI installer for podman-remote would break the PATH environment variable by adding an extra ' (#11416).
    * API
    - The Libpod Play Kube endpoint now also accepts ConfigMap YAML as part of its payload, and will use provided any ConfigMap to configure provided pods and services. - Fixed a bug where the Compat Create endpoint for Containers would not always create the container's working directory if it did not exist (#11842). - Fixed a bug where the Compat Create endpoint for Containers returned an incorrect error message with 404 errors when the requested image was not found (#12315). - Fixed a bug where the Compat Create endpoint for Containers did not properly handle the HostConfig.Mounts field (#12419). - Fixed a bug where the Compat Archive endpoint for Containers did not properly report errors when the operation failed (#12420). - Fixed a bug where the Compat Build endpoint for Images ignored the layers query parameter (for caching intermediate layers from the build) (#12378). - Fixed a bug where the Compat Build endpoint for Images did not report errors in a manner compatible with Docker (#12392). - Fixed a bug where the Compat Build endpoint for Images would fail to build if the context directory was a symlink (#12409). - Fixed a bug where the Compat List endpoint for Images included manifest lists (and not just images) in returned results (#12453).

    * Fixed a bug where podman tag could not tag manifest lists (#12046). * Fixed a bug where built-in volumes specified by images would not be created correctly under some circumstances. * Fixed a bug where, when using Podman Machine on OS X, containers in pods did not have working port forwarding from the host (#12207). * Fixed a bug where the podman network reload command command on containers using the slirp4netns network mode and the rootlessport port forwarding driver would make an unnecessary attempt to restart rootlessport on containers that did not forward ports. * Fixed a bug where the podman generate kube command would generate YAML including some unnecessary (set to default) fields (e.g. empty SELinux and DNS configuration blocks, and the privileged flag when set to false) (#11995). * Fixed a bug where the podman pod rm command could, if interrupted at the right moment, leave a reference to an already-removed infra container behind (#12034). * Fixed a bug where the podman pod rm command would not remove pods with more than one container if all containers save for the infra container were stopped unless --force was specified (#11713). * Fixed a bug where the --memory flag to podman run and podman create did not accept a limit of 0 (which should specify unlimited memory) (#12002). * Fixed a bug where the remote Podman client's podman build command could attempt to build a Dockerfile in the working directory of the podman system service instance instead of the Dockerfile specified by the user (#12054). * Fixed a bug where the podman logs --tail command could function improperly (printing more output than requested) when the journald log driver was used. * Fixed a bug where containers run using the slirp4netns network mode with IPv6 enabled would not have IPv6 connectivity until several seconds after they started (#11062). * Fixed a bug where some Podman commands could cause an extra dbus-daemon process to be created (#9727). * Fixed a bug where rootless Podman would sometimes print warnings about a failure to move the pause process into a given CGroup (#12065). * Fixed a bug where the checkpointed field in podman inspect on a container was not set to false after a container was restored. * Fixed a bug where the podman system service command would print overly-verbose logs about request IDs (#12181). * Fixed a bug where Podman could, when creating a new container without a name explicitly specified by the user, sometimes use an auto-generated name already in use by another container if multiple containers were being created in parallel (#11735).
    Update to version 3.4.1:
    * Bugfixes
    - Fixed a bug where podman machine init could, under some circumstances, create invalid machine configurations which could not be started (#11824). - Fixed a bug where the podman machine list command would not properly populate some output fields. - Fixed a bug where podman machine rm could leave dangling sockets from the removed machine (#11393). - Fixed a bug where podman run --pids-limit=-1 was not supported (it now sets the PID limit in the container to unlimited) (#11782). - Fixed a bug where podman run and podman attach could throw errors about a closed network connection when STDIN was closed by the client (#11856). - Fixed a bug where the podman stop command could fail when run on a container that had another podman stop command run on it previously. - Fixed a bug where the --sync flag to podman ps was nonfunctional. - Fixed a bug where the Windows and OS X remote clients' podman stats command would fail (#11909). - Fixed a bug where the podman play kube command did not properly handle environment variables whose values contained an = (#11891). - Fixed a bug where the podman generate kube command could generate invalid annotations when run on containers with volumes that use SELinux relabelling (:z or :Z) (#11929). - Fixed a bug where the podman generate kube command would generate YAML including some unnecessary (set to default) fields (e.g. user and group, entrypoint, default protocol for forwarded ports) (#11914, #11915, and #11965). - Fixed a bug where the podman generate kube command could, under some circumstances, generate YAML including an invalid targetPort field for forwarded ports (#11930). - Fixed a bug where rootless Podman's podman info command could, under some circumstances, not read available CGroup controllers (#11931). - Fixed a bug where podman container checkpoint --export would fail to checkpoint any container created with --log-driver=none (#11974).
    * API
    - Fixed a bug where the Compat Create endpoint for Containers could panic when no options were passed to a bind mount of tmpfs (#11961).
    Update to version 3.4.0:
    * Features
    - Pods now support init containers! Init containers are containers which run before the rest of the pod starts. There are two types of init containers: 'always', which always run before the pod is started, and 'once', which only run the first time the pod starts and are subsequently removed. They can be added using the podman create command's --init-ctr option. - Support for init containers has also been added to podman play kube and podman generate kube - init containers contained in Kubernetes YAML will be created as Podman init containers, and YAML generated by Podman will include any init containers created. - The podman play kube command now supports building images. If the --build option is given and a directory with the name of the specified image exists in the current working directory and contains a valid Containerfile or Dockerfile, the image will be built and used for the container. - The podman play kube command now supports a new option, --teardown, which removes any pods and containers created by the given Kubernetes YAML. - The podman generate kube command now generates annotations for SELinux mount options on volume (:z and :Z) that are respected by the podman play kube command. - A new command has been added, podman pod logs, to return logs for all containers in a pod at the same time. - Two new commands have been added, podman volume export (to export a volume to a tar file) and podman volume import) (to populate a volume from a given tar file). - The podman auto-update command now supports simple rollbacks. If a container fails to start after an automatic update, it will be rolled back to the previous image and restarted again. - Pods now share their user namespace by default, and the podman pod create command now supports the --userns option. This allows rootless pods to be created with the --userns=keep-id option. - The podman pod ps command now supports a new filter with its --filter option, until, which returns pods created before a given timestamp. - The podman image scp command has been added. This command allows images to be transferred between different hosts. - The podman stats command supports a new option, --interval, to specify the amount of time before the information is refreshed. - The podman inspect command now includes ports exposed (but not published) by containers (e.g. ports from --expose when --publish-all is not specified). - The podman inspect command now has a new boolean value, Checkpointed, which indicates that a container was stopped as a result of a podman container checkpoint operation. - Volumes created by podman volume create now support setting quotas when run atop XFS. The size and inode options allow the maximum size and maximum number of inodes consumed by a volume to be limited. - The podman info command now outputs information on what log drivers, network drivers, and volume plugins are available for use (#11265). - The podman info command now outputs the current log driver in use, and the variant and codename of the distribution in use. - The parameters of the VM created by podman machine init (amount of disk space, memory, CPUs) can now be set in containers.conf. - The podman machine ls command now shows additional information (CPUs, memory, disk size) about VMs managed by podman machine. - The podman ps command now includes healthcheck status in container state for containers that have healthchecks (#11527).
    * Changes
    - The podman build command has a new alias, podman buildx, to improve compatibility with Docker. We have already added support for many docker buildx flags to podman build and aim to continue to do so. - Cases where Podman is run without a user session or a writable temporary files directory will now produce better error messages. - The default log driver has been changed from file to journald. The file driver did not properly support log rotation, so this should lead to a better experience. If journald is not available on the system, Podman will automatically revert to the file. - Podman no longer depends on ip for removing networks (#11403). - The deprecated --macvlan flag to podman network create now warns when it is used. It will be removed entirely in the Podman 4.0 release. - The podman machine start command now prints a message when the VM is successfully started. - The podman stats command can now be used on containers that are paused. - The podman unshare command will now return the exit code of the command that was run in the user namespace (assuming the command was successfully run). - Successful healthchecks will no longer add a healthy line to the system log to reduce log spam. - As a temporary workaround for a lack of shortname prompts in the Podman remote client, VMs created by podman machine now default to only using the docker.io registry.
    * Bugfixes
    - Fixed a bug where whitespace in the definition of sysctls (particularly default sysctls specified in containers.conf) would cause them to be parsed incorrectly. - Fixed a bug where the Windows remote client improperly validated volume paths (#10900). - Fixed a bug where the first line of logs from a container run with the journald log driver could be skipped. - Fixed a bug where images created by podman commit did not include ports exposed by the container. - Fixed a bug where the podman auto-update command would ignore the io.containers.autoupdate.authfile label when pulling images (#11171). - Fixed a bug where the --workdir option to podman create and podman run could not be set to a directory where a volume was mounted (#11352). - Fixed a bug where systemd socket-activation did not properly work with systemd-managed Podman containers (#10443). - Fixed a bug where environment variable secrets added to a container were not available to exec sessions launched in the container. - Fixed a bug where rootless containers could fail to start the rootlessport port-forwarding service when XDG_RUNTIME_DIR was set to a long path. - Fixed a bug where arguments to the --systemd option to podman create and podman run were case-sensitive (#11387). - Fixed a bug where the podman manifest rm command would also remove images referenced by the manifest, not just the manifest itself (#11344). - Fixed a bug where the Podman remote client on OS X would not function properly if the TMPDIR environment variable was not set (#11418). - Fixed a bug where the /etc/hosts file was not guaranteed to contain an entry for localhost (this is still not guaranteed if --net=host is used; such containers will exactly match the host's /etc/hosts) (#11411). - Fixed a bug where the podman machine start command could print warnings about unsupported CPU features (#11421). - Fixed a bug where the podman info command could segfault when accessing cgroup information. - Fixed a bug where the podman logs -f command could hang when a container exited (#11461). - Fixed a bug where the podman generate systemd command could not be used on containers that specified a restart policy (#11438). - Fixed a bug where the remote Podman client's podman build command would fail to build containers if the UID and GID on the client were higher than 65536 (#11474). - Fixed a bug where the remote Podman client's podman build command would fail to build containers if the context directory was a symlink (#11732). - Fixed a bug where the --network flag to podman play kube was not properly parsed when a non-bridge network configuration was specified. - Fixed a bug where the podman inspect command could error when the container being inspected was removed as it was being inspected (#11392). - Fixed a bug where the podman play kube command ignored the default pod infra image specified in containers.conf. - Fixed a bug where the --format option to podman inspect was nonfunctional under some circumstances (#8785). - Fixed a bug where the remote Podman client's podman run and podman exec commands could skip a byte of output every 8192 bytes (#11496). - Fixed a bug where the podman stats command would print nonsensical results if the container restarted while it was running (#11469). - Fixed a bug where the remote Podman client would error when STDOUT was redirected on a Windows client (#11444). - Fixed a bug where the podman run command could return 0 when the application in the container exited with 125 (#11540). - Fixed a bug where containers with --restart=always set using the rootlessport port-forwarding service could not be restarted automatically. - Fixed a bug where the --cgroups=split option to podman create and podman run was silently discarded if the container was part of a pod. - Fixed a bug where the podman container runlabel command could fail if the image name given included a tag. - Fixed a bug where Podman could add an extra 127.0.0.1 entry to /etc/hosts under some circumstances (#11596). - Fixed a bug where the remote Podman client's podman untag command did not properly handle tags including a digest (#11557). - Fixed a bug where the --format option to podman ps did not properly support the table argument for tabular output. - Fixed a bug where the --filter option to podman ps did not properly handle filtering by healthcheck status (#11687). - Fixed a bug where the podman run and podman start --attach commands could race when retrieving the exit code of a container that had already been removed resulting in an error (e.g. by an external podman rm -f) (#11633). - Fixed a bug where the podman generate kube command would add default environment variables to generated YAML. - Fixed a bug where the podman generate kube command would add the default CMD from the image to generated YAML (#11672). - Fixed a bug where the podman rm --storage command could fail to remove containers under some circumstances (#11207). - Fixed a bug where the podman machine ssh command could fail when run on Linux (#11731). - Fixed a bug where the podman stop command would error when used on a container that was already stopped (#11740). - Fixed a bug where renaming a container in a pod using the podman rename command, then removing the pod using podman pod rm, could cause Podman to believe the new name of the container was permanently in use, despite the container being removed (#11750).
    * API
    - The Libpod Pull endpoint for Images now has a new query parameter, quiet, which (when set to true) suppresses image pull progress reports (#10612). - The Compat Events endpoint now includes several deprecated fields from the Docker v1.21 API for improved compatibility with older clients. - The Compat List and Inspect endpoints for Images now prefix image IDs with sha256: for improved Docker compatibility (#11623). - The Compat Create endpoint for Containers now properly sets defaults for healthcheck-related fields (#11225). - The Compat Create endpoint for Containers now supports volume options provided by the Mounts field (#10831). - The Compat List endpoint for Secrets now supports a new query parameter, filter, which allows returned results to be filtered. - The Compat Auth endpoint now returns the correct response code (500 instead of 400) when logging into a registry fails. - The Version endpoint now includes information about the OCI runtime and Conmon in use (#11227). - Fixed a bug where the X-Registry-Config header was not properly handled, leading to errors when pulling images (#11235). - Fixed a bug where invalid query parameters could cause a null pointer dereference when creating error messages. - Logging of API requests and responses at trace level has been greatly improved, including the addition of an X-Reference-Id header to correlate requests and responses (#10053).
    Update to version 3.3.1:
    * Bugfixes
    - Fixed a bug where unit files created by podman generate systemd could not cleanup shut down containers when stopped by systemctl stop (#11304). - Fixed a bug where podman machine commands would not properly locate the gvproxy binary in some circumstances. - Fixed a bug where containers created as part of a pod using the --pod-id-file option would not join the pod's network namespace (#11303). - Fixed a bug where Podman, when using the systemd cgroups driver, could sometimes leak dbus sessions. - Fixed a bug where the until filter to podman logs and podman events was improperly handled, requiring input to be negated (#11158). - Fixed a bug where rootless containers using CNI networking run on systems using systemd-resolved for DNS would fail to start if resolved symlinked /etc/resolv.conf to an absolute path (#11358).
    * API
    - A large number of potential file descriptor leaks from improperly closing client connections have been fixed.
    Update to version 3.3.0:
    * Fix network aliases with network id * machine: compute sha256 as we read the image file * machine: check for file exists instead of listing directory * pkg/bindings/images.nTar(): slashify hdr.Name values * Volumes: Only remove from DB if plugin removal succeeds * For compatibility, ignore Content-Type * [v3.3] Bump c/image 5.15.2, buildah v1.22.3 * Implement SD-NOTIFY proxy in conmon * Fix rootless cni dns without systemd stub resolver * fix rootlessport flake * Skip stats test in CGv1 container environments * Fix AVC denials in tests of volume mounts * Restore buildah-bud test requiring new images * Revert '.cirrus.yml: use fresh images for all VMs' * Fix device tests using ls test files * Enhance priv. dev. check * Workaround host availability of /dev/kvm * Skip cgroup-parent test due to frequent flakes * Cirrus: Fix not uploading logformatter html
    Switch to crun (bsc#1188914)
    Update to version 3.2.3:
    * Bump to v3.2.3 * Update release notes for v3.2.3 * vendor containers/common@v0.38.16 * vendor containers/buildah@v1.21.3 * Fix race conditions in rootless cni setup * CNI-in-slirp4netns: fix bind-mount for /run/systemd/resolve/stub-resolv.conf * Make rootless-cni setup more robust * Support uid,gid,mode options for secrets * vendor containers/common@v0.38.15 * [CI:DOCS] podman search: clarify that results depend on implementation * vendor containers/common@v0.38.14 * vendor containers/common@v0.38.13 * [3.2] vendor containers/common@v0.38.12 * Bump README to v3.2.2 * Bump to v3.2.3-dev







    Bugfixes - Fixed a bug where the Created field of podman ps --format=json was formatted as a string instead of an Unix timestamp (integer) (#9315). - Fixed a bug where failing lookups of individual layers during the podman images command would cause the whole command to fail without printing output. - Fixed a bug where --cgroups=split did not function properly on cgroups v1 systems. - Fixed a bug where mounting a volume over an directory in the container that existed, but was empty, could fail (#9393). - Fixed a bug where mounting a volume over a directory in the container that existed could copy the entirety of the container's rootfs, instead of just the directory mounted over, into the volume (#9415). - Fixed a bug where Podman would treat the --entrypoint=[''] option to podman run and podman create as a literal empty string in the entrypoint, when instead it should have been ignored (#9377). - Fixed a bug where Podman would set the HOME environment variable to '' when the container ran as a user without an assigned home directory (#9378). - Fixed a bug where specifying a pod infra image that had no tags (by using its ID) would cause podman pod create to panic (#9374). - Fixed a bug where the --runtime option was not properly handled by the podman build command (#9365). - Fixed a bug where Podman would incorrectly print an error message related to the remote API when the remote API was not in use and starting Podman failed. - Fixed a bug where Podman would change ownership of a container's working directory, even if it already existed (#9387). - Fixed a bug where the podman generate systemd --new command would incorrectly escape %t when generating the path for the PID file (#9373). - Fixed a bug where Podman could, when run inside a Podman container with the host's containers/storage directory mounted into the container, erroneously detect a reboot and reset container state if the temporary directory was not also mounted in (#9191). - Fixed a bug where some options of the podman build command (including but not limited to --jobs) were nonfunctional (#9247). * API - Fixed a breaking change to the Libpod Wait API for Containers where the Conditions parameter changed type in Podman v3.0 (#9351). - Fixed a bug where the Compat Create endpoint for Containers did not properly handle forwarded ports that did not specify a host port. - Fixed a bug where the Libpod Wait endpoint for Containers could write duplicate headers after an error occurred. - Fixed a bug where the Compat Create endpoint for Images would not pull images that already had a matching tag present locally, even if a more recent version was available at the registry (#9232). - The Compat Create endpoint for Images has had its compatibility with Docker improved, allowing its use with the docker-java library. * Misc - Updated Buildah to v1.19.4 - Updated the containers/storage library to v1.24.6
  • Changes from v3.0.0 * Features - Podman now features initial support for Docker Compose. - Added the podman rename command, which allows containers to be renamed after they are created (#1925). - The Podman remote client now supports the podman copy command. - A new command, podman network reload, has been added. This command will re-configure the network of all running containers, and can be used to recreate firewall rules lost when the system firewall was reloaded (e.g. via firewall-cmd --reload). - Podman networks now have IDs. They can be seen in podman network ls and can be used when removing and inspecting networks. Existing networks receive IDs automatically. - Podman networks now also support labels. They can be added via the --label option to network create, and podman network ls can filter labels based on them. - The podman network create command now supports setting bridge MTU and VLAN through the --opt option (#8454). - The podman container checkpoint and podman container restore commands can now checkpoint and restore containers that include volumes. - The podman container checkpoint command now supports the --with-previous and --pre-checkpoint options, and the podman container restore command now support the --import-previous option. These add support for two-step checkpointing with lowered dump times. - The podman push command can now push manifest lists. Podman will first attempt to push as an image, then fall back to pushing as a manifest list if that fails. - The podman generate kube command can now be run on multiple containers at once, and will generate a single pod containing all of them. - The podman generate kube and podman play kube commands now support Kubernetes DNS configuration, and will preserve custom DNS configuration when exporting or importing YAML (#9132). - The podman generate kube command now properly supports generating YAML for containers and pods creating using host networking (--net=host) (#9077). - The podman kill command now supports a --cidfile option to kill containers given a file containing the container's ID (#8443). - The podman pod create command now supports the --net=none option (#9165). - The podman volume create command can now specify volume UID and GID as options with the UID and GID fields passed to the the --opt option. - Initial support has been added for Docker Volume Plugins. Podman can now define available plugins in containers.conf and use them to create volumes with podman volume create --driver. - The podman run and podman create commands now support a new option, --platform, to specify the platform of the image to be used when creating the container. - The --security-opt option to podman run and podman create now supports the systempaths=unconfined option to unrestrict access to all paths in the container, as well as mask and unmask options to allow more granular restriction of container paths. - The podman stats --format command now supports a new format specified, MemUsageBytes, which prints the raw bytes of memory consumed by a container without human-readable formatting #8945. - The podman ps command can now filter containers based on what pod they are joined to via the pod filter (#8512). - The podman pod ps command can now filter pods based on what networks they are joined to via the network filter. The podman pod ps command can now print information on what networks a pod is joined to via the .Networks specifier to the --format option. - The podman system prune command now supports filtering what containers, pods, images, and volumes will be pruned. - The podman volume prune commands now supports filtering what volumes will be pruned. - The podman system prune command now includes information on space reclaimed (#8658). - The podman info command will now properly print information about packages in use on Gentoo and Arch systems. - The containers.conf file now contains an option for disabling creation of a new kernel keyring on container creation (#8384). - The podman image sign command can now sign multi-arch images by producing a signature for each image in a given manifest list. - The podman image sign command, when run as rootless, now supports per-user registry configuration files in $HOME/.config/containers/registries.d. - Configuration options for slirp4netns can now be set system-wide via the NetworkCmdOptions configuration option in containers.conf. - The MTU of slirp4netns can now be configured via the mtu= network command option (e.g. podman run --net slirp4netns:mtu=9000). * Security - A fix for CVE-2021-20199 is included. Podman between v1.8.0 and v2.2.1 used 127.0.0.1 as the source address for all traffic forwarded into rootless containers by a forwarded port; this has been changed to address the issue. * Changes - Shortname aliasing support has now been turned on by default. All Podman commands that must pull an image will, if a TTY is available, prompt the user about what image to pull. - The podman load command no longer accepts a NAME[:TAG] argument. The presence of this argument broke CLI compatibility with Docker by making docker load commands unusable with Podman (#7387). - The Go bindings for the HTTP API have been rewritten with a focus on limiting dependency footprint and improving extensibility. Read more here. - The legacy Varlink API has been completely removed from Podman. - The default log level for Podman has been changed from Error to Warn. - The podman network create command can now create macvlan networks using the --driver macvlan option for Docker compatibility. The existing --macvlan flag has been deprecated and will be removed in Podman 4.0 some time next year. - The podman inspect command has had the LogPath and LogTag fields moved into the LogConfig structure (from the root of the Inspect structure). The maximum size of the log file is also included. - The podman generate systemd command no longer generates unit files using the deprecated KillMode=none option (#8615). - The podman stop command now releases the container lock while waiting for it to stop - as such, commands like podman ps will no longer block until podman stop completes (#8501). - Networks created with podman network create --internal no longer use the dnsname plugin. This configuration never functioned as expected. - Error messages for the remote Podman client have been improved when it cannot connect to a Podman service. - Error messages for podman run when an invalid SELinux is specified have been improved. - Rootless Podman features improved support for containers with a single user mapped into the rootless user namespace. - Pod infra containers now respect default sysctls specified in containers.conf allowing for advanced configuration of the namespaces they will share. - SSH public key handling for remote Podman has been improved. * Bugfixes - Fixed a bug where the podman history --no-trunc command would truncate the Created By field (#9120). - Fixed a bug where root containers that did not explicitly specify a CNI network to join did not generate an entry for the network in use in the Networks field of the output of podman inspect (#6618). - Fixed a bug where, under some circumstances, container working directories specified by the image (via the WORKDIR instruction) but not present in the image, would not be created (#9040). - Fixed a bug where the podman generate systemd command would generate invalid unit files if the container was creating using a command line that included doubled braces ({{ and }}), e.g. --log-opt-tag={{.Name}} (#9034). - Fixed a bug where the podman generate systemd --new command could generate unit files including invalid Podman commands if the container was created using merged short options (e.g. podman run -dt) (#8847). - Fixed a bug where the podman generate systemd --new command could generate unit files that did not handle Podman commands including some special characters (e.g. $) (#9176 - Fixed a bug where rootless containers joining CNI networks could not set a static IP address (#7842). - Fixed a bug where rootless containers joining CNI networks could not set network aliases (#8567). - Fixed a bug where the remote client could, under some circumstances, not include the Containerfile when sending build context to the server (#8374). - Fixed a bug where rootless Podman did not mount /sys as a new sysfs in some circumstances where it was acceptable. - Fixed a bug where rootless containers that both joined a user namespace and a CNI networks would cause a segfault. These options are incompatible and now return an error. - Fixed a bug where the podman play kube command did not properly handle CMD and ARGS from images (#8803). - Fixed a bug where the podman play kube command did not properly handle environment variables from images (#8608). - Fixed a bug where the podman play kube command did not properly print errors that occurred when starting containers. - Fixed a bug where the podman play kube command errored when hostNetwork was used (#8790). - Fixed a bug where the podman play kube command would always pull images when the :latest tag was specified, even if the image was available locally (#7838). - Fixed a bug where the podman play kube command did not properly handle SELinux configuration, rending YAML with custom SELinux configuration unusable (#8710). - Fixed a bug where the podman generate kube command incorrectly populated the args and command fields of generated YAML (#9211). - Fixed a bug where containers in a pod would create a duplicate entry in the pod's shared /etc/hosts file every time the container restarted (#8921). - Fixed a bug where the podman search --list-tags command did not support the --format option (#8740). - Fixed a bug where the http_proxy option in containers.conf was not being respected, and instead was set unconditionally to true (#8843). - Fixed a bug where rootless Podman could, on systems with a recent Conmon and users with a long username, fail to attach to containers (#8798). - Fixed a bug where the podman images command would break and fail to display any images if an empty manifest list was present in storage (#8931). - Fixed a bug where locale environment variables were not properly passed on to Conmon. - Fixed a bug where Podman would not build on the MIPS architecture (#8782). - Fixed a bug where rootless Podman could fail to properly configure user namespaces for rootless containers when the user specified a --uidmap option that included a mapping beginning with UID 0. - Fixed a bug where the podman logs command using the k8s-file backend did not properly handle partial log lines with a length of 1 (#8879). - Fixed a bug where the podman logs command with the --follow option did not properly handle log rotation (#8733). - Fixed a bug where user-specified HOSTNAME environment variables were overwritten by Podman (#8886). - Fixed a bug where Podman would applied default sysctls from containers.conf in too many situations (e.g. applying network sysctls when the container shared its network with a pod). - Fixed a bug where Podman did not properly handle cases where a secondary image store was in use and an image was present in both the secondary and primary stores (#8176). - Fixed a bug where systemd-managed rootless Podman containers where the user in the container was not root could fail as the container's PID file was not accessible to systemd on the host (#8506). - Fixed a bug where the --privileged option to podman run and podman create would, under some circumstances, not disable Seccomp (#8849). - Fixed a bug where the podman exec command did not properly add capabilities when the container or exec session were run with --privileged. - Fixed a bug where rootless Podman would use the --enable-sandbox option to slirp4netns unconditionally, even when pivot_root was disabled, rendering slirp4netns unusable when pivot_root was disabled (#8846). - Fixed a bug where podman build --logfile did not actually write the build's log to the logfile. - Fixed a bug where the podman system service command did not close STDIN, and could display user-interactive prompts (#8700). - Fixed a bug where the podman system reset command could, under some circumstances, remove all the contents of the XDG_RUNTIME_DIR directory (#8680). - Fixed a bug where the podman network create command created CNI configurations that did not include a default gateway (#8748). - Fixed a bug where the podman.service systemd unit provided by default used the wrong service type, and would cause systemd to not correctly register the service as started (#8751). - Fixed a bug where, if the TMPDIR environment variable was set for the container engine in containers.conf, it was being ignored. - Fixed a bug where the podman events command did not properly handle future times given to the --until option (#8694). - Fixed a bug where the podman logs command wrote container STDERR logs to STDOUT instead of STDERR (#8683). - Fixed a bug where containers created from an image with multiple tags would report that they were created from the wrong tag (#8547). - Fixed a bug where container capabilities were not set properly when the --cap-add=all and --user options to podman create and podman run were combined. - Fixed a bug where the --layers option to podman build was nonfunctional (#8643). - Fixed a bug where the podman system prune command did not act recursively, and thus would leave images, containers, pods, and volumes present that would be removed by a subsequent call to podman system prune (#7990). - Fixed a bug where the --publish option to podman run and podman create did not properly handle ports specified as a range of ports with no host port specified (#8650). - Fixed a bug where --format did not support JSON output for individual fields (#8444). - Fixed a bug where the podman stats command would fail when run on root containers using the slirp4netns network mode (#7883). - Fixed a bug where the Podman remote client would ask for a password even if the server's SSH daemon did not support password authentication (#8498). - Fixed a bug where the podman stats command would fail if the system did not support one or more of the cgroup controllers Podman supports (#8588). - Fixed a bug where the --mount option to podman create and podman run did not ignore the consistency mount option. - Fixed a bug where failures during the resizing of a container's TTY would print the wrong error. - Fixed a bug where the podman network disconnect command could cause the podman inspect command to fail for a container until it was restarted (#9234). - Fixed a bug where containers created from a read-only rootfs (using the --rootfs option to podman create and podman run) would fail (#9230). - Fixed a bug where specifying Go templates to the --format option to multiple Podman commands did not support the join function (#8773). - Fixed a bug where the podman rmi command could, when run in parallel on multiple images, return layer not known errors (#6510). - Fixed a bug where the podman inspect command on containers displayed unlimited ulimits incorrectly (#9303). - Fixed a bug where Podman would fail to start when a volume was mounted over a directory in a container that contained symlinks that terminated outside the directory and its subdirectories (#6003).
  • API - Libpod API version has been bumped to v3.0.0. - All Libpod Pod APIs have been modified to properly report errors with individual containers. Cases where the operation as a whole succeeded but individual containers failed now report an HTTP 409 error (#8865). - The Compat API for Containers now supports the Rename and Copy APIs. - Fixed a bug where the Compat Prune APIs (for volumes, containers, and images) did not return the amount of space reclaimed in their responses. - Fixed a bug where the Compat and Libpod Exec APIs for Containers would drop errors that occurred prior to the exec session successfully starting (e.g. a 'no such file' error if an invalid executable was passed) (#8281) - Fixed a bug where the Volumes field in the Compat Create API for Containers was being ignored (#8649). - Fixed a bug where the NetworkMode field in the Compat Create API for Containers was not handling some values, e.g. container:, correctly. - Fixed a bug where the Compat Create API for Containers did not set container name properly. - Fixed a bug where containers created using the Compat Create API unconditionally used Kubernetes file logging (the default specified in containers.conf is now used). - Fixed a bug where the Compat Inspect API for Containers could include container states not recognized by Docker. - Fixed a bug where Podman did not properly clean up after calls to the Events API when the journald backend was in use, resulting in a leak of file descriptors (#8864). - Fixed a bug where the Libpod Pull endpoint for Images could fail with an index out of range error under certain circumstances (#8870). - Fixed a bug where the Libpod Exists endpoint for Images could panic. - Fixed a bug where the Compat List API for Containers did not support all filters (#8860). - Fixed a bug where the Compat List API for Containers did not properly populate the Status field. - Fixed a bug where the Compat and Libpod Resize APIs for Containers ignored the height and width parameters (#7102). - Fixed a bug where the Compat Search API for Images returned an incorrectly-formatted JSON response (#8758). - Fixed a bug where the Compat Load API for Images did not properly clean up temporary files. - Fixed a bug where the Compat Create API for Networks could panic when an empty IPAM configuration was specified. - Fixed a bug where the Compat Inspect and List APIs for Networks did not include Scope. - Fixed a bug where the Compat Wait endpoint for Containers did not support the same wait conditions that Docker did. * Misc - Updated Buildah to v1.19.2 - Updated the containers/storage library to v1.24.5 - Updated the containers/image library to v5.10.2 - Updated the containers/common library to v0.33.4


    SELinux support [jsc#SMO-15]

    libseccomp was updated to release 2.5.3:

    Update to release 2.5.2

    update to 2.5.1:

    Update to release 2.5.0

    Update to release 2.4.3

    Update to release 2.4.2


    conmon was updated to version 2.0.30:
    * Remove unreachable code path * exit: report if the exit command was killed * exit: fix race zombie reaper * conn_sock: allow watchdog messages through the notify socket proxy * seccomp: add support for seccomp notify
    Update to version 2.0.29:
    * Reset OOM score back to 0 for container runtime * call functions registered with atexit on SIGTERM * conn_sock: fix potential segfault
    Update to version 2.0.27:
    * Add CRI-O integration test GitHub action * exec: don't fail on EBADFD * close_fds: fix close of external fds * Add arm64 static build binary
    Update to version 2.0.26:
    * conn_sock: do not fail on EAGAIN * fix segfault from a double freed pointer * Fix a bug where conmon could never spawn a container, because a disagreement between the caller and itself on where the attach socket was. * improve --full-attach to ignore the socket-dir directly. that means callers don't need to specify a socket dir at all (and can remove it) * add full-attach option to allow callers to not truncate a very long path for the attach socket * close only opened FDs * set locale to inherit environment
    Update to version 2.0.22:
    * added man page * attach: always chdir * conn_sock: Explicitly free a heap-allocated string * refactor I/O and add SD_NOTIFY proxy support
    Update to version 2.0.21:
    * protect against kill(-1) * Makefile: enable debuginfo generation * Remove go.sum file and add go.mod * Fail if conmon config could not be written * nix: remove double definition for e2fsprogs * Speedup static build by utilizing CI cache on `/nix` folder * Fix nix build for failing e2fsprogs tests * test: fix CI * Use Podman for building
    libcontainers-common was updated to include:
    (changes too long to list)
    CVEs fixed: CVE-2020-14370,CVE-2020-15157,CVE-2021-20199,CVE-2021-20291,CVE-2021-3602


    Advisory IDSUSE-SU-2022:713-1
    ReleasedFri Mar 4 09:34:17 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196026,1196168,1196169,1196171,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:727-1
    ReleasedFri Mar 4 10:39:21 2022
    SummarySecurity update for libeconf, shadow and util-linux
    Typesecurity
    Severitymoderate
    References1188507,1192954,1193632,1194976,CVE-2021-3995,CVE-2021-3996
    Description:

    This security update for libeconf, shadow and util-linux fix the following issues:
    libeconf:


    Issues fixed in libeconf:
    shadow:

    util-linux:


    Advisory IDSUSE-SU-2022:736-1
    ReleasedFri Mar 4 14:51:57 2022
    SummarySecurity update for vim
    Typesecurity
    Severityimportant
    References1190533,1190570,1191893,1192478,1192481,1193294,1193298,1194216,1194556,1195004,1195066,1195126,1195202,1195356,CVE-2021-3778,CVE-2021-3796,CVE-2021-3872,CVE-2021-3927,CVE-2021-3928,CVE-2021-3984,CVE-2021-4019,CVE-2021-4193,CVE-2021-46059,CVE-2022-0318,CVE-2022-0319,CVE-2022-0351,CVE-2022-0361,CVE-2022-0413
    Description:

    This update for vim fixes the following issues:


    Advisory IDSUSE-SU-2022:743-1
    ReleasedMon Mar 7 22:08:12 2022
    SummarySecurity update for cyrus-sasl
    Typesecurity
    Severityimportant
    References1194265,1196036,CVE-2022-24407
    Description:

    This update for cyrus-sasl fixes the following issues:


    The following non-security bugs were fixed:


    Advisory IDSUSE-RU-2022:771-1
    ReleasedWed Mar 9 09:27:07 2022
    SummaryRecommended update for libseccomp
    Typerecommended
    Severitymoderate
    References1196825
    Description:

    This update for libseccomp fixes the following issues:


    Advisory IDSUSE-RU-2022:787-1
    ReleasedThu Mar 10 11:20:13 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References
    Description:

    This update for openldap2 fixes the following issue:


    Advisory IDSUSE-RU-2022:788-1
    ReleasedThu Mar 10 11:21:04 2022
    SummaryRecommended update for libzypp, zypper
    Typerecommended
    Severitymoderate
    References1195326
    Description:

    This update for libzypp, zypper fixes the following issues:


    Advisory IDSUSE-RU-2022:789-1
    ReleasedThu Mar 10 11:22:05 2022
    SummaryRecommended update for update-alternatives
    Typerecommended
    Severitymoderate
    References1195654
    Description:

    This update for update-alternatives fixes the following issues:


    Advisory IDSUSE-RU-2022:808-1
    ReleasedFri Mar 11 06:07:58 2022
    SummaryRecommended update for procps
    Typerecommended
    Severitymoderate
    References1195468
    Description:

    This update for procps fixes the following issues:


    Advisory IDSUSE-SU-2022:844-1
    ReleasedTue Mar 15 11:33:57 2022
    SummarySecurity update for expat
    Typesecurity
    Severityimportant
    References1196025,1196784,CVE-2022-25236
    Description:

    This update for expat fixes the following issues:


    Advisory IDSUSE-SU-2022:845-1
    ReleasedTue Mar 15 11:40:52 2022
    SummarySecurity update for chrony
    Typesecurity
    Severitymoderate
    References1099272,1115529,1128846,1162964,1172113,1173277,1174075,1174911,1180689,1181826,1187906,1190926,1194229,CVE-2020-14367
    Description:

    This update for chrony fixes the following issues:
    Chrony was updated to 4.1, bringing features and bugfixes.
    Update to 4.1
    * Add support for NTS servers specified by IP address (matching Subject Alternative Name in server certificate) * Add source-specific configuration of trusted certificates * Allow multiple files and directories with trusted certificates * Allow multiple pairs of server keys and certificates * Add copy option to server/pool directive * Increase PPS lock limit to 40% of pulse interval * Perform source selection immediately after loading dump files * Reload dump files for addresses negotiated by NTS-KE server * Update seccomp filter and add less restrictive level * Restart ongoing name resolution on online command * Fix dump files to not include uncorrected offset * Fix initstepslew to accept time from own NTP clients * Reset NTP address and port when no longer negotiated by NTS-KE server



    Update to 4.0
    - Enhancements
    - Add support for Network Time Security (NTS) authentication - Add support for AES-CMAC keys (AES128, AES256) with Nettle - Add authselectmode directive to control selection of unauthenticated sources - Add binddevice, bindacqdevice, bindcmddevice directives - Add confdir directive to better support fragmented configuration - Add sourcedir directive and 'reload sources' command to support dynamic NTP sources specified in files - Add clockprecision directive - Add dscp directive to set Differentiated Services Code Point (DSCP) - Add -L option to limit log messages by severity - Add -p option to print whole configuration with included files - Add -U option to allow start under non-root user - Allow maxsamples to be set to 1 for faster update with -q/-Q option - Avoid replacing NTP sources with sources that have unreachable address - Improve pools to repeat name resolution to get 'maxsources' sources - Improve source selection with trusted sources - Improve NTP loop test to prevent synchronisation to itself - Repeat iburst when NTP source is switched from offline state to online - Update clock synchronisation status and leap status more frequently - Update seccomp filter - Add 'add pool' command - Add 'reset sources' command to drop all measurements - Add authdata command to print details about NTP authentication - Add selectdata command to print details about source selection - Add -N option and sourcename command to print original names of sources - Add -a option to some commands to print also unresolved sources - Add -k, -p, -r options to clients command to select, limit, reset data
    - Bug fixes
    - Don’t set interface for NTP responses to allow asymmetric routing - Handle RTCs that don’t support interrupts - Respond to command requests with correct address on multihomed hosts - Removed features - Drop support for RIPEMD keys (RMD128, RMD160, RMD256, RMD320) - Drop support for long (non-standard) MACs in NTPv4 packets (chrony 2.x clients using non-MD5/SHA1 keys need to use option 'version 3') - Drop support for line editing with GNU Readline


    Update to 3.5.1:
    * Create new file when writing pidfile (CVE-2020-14367, bsc#1174911)





    Update to 3.5:




    Update to version 3.4
    * Enhancements
    + Add filter option to server/pool/peer directive + Add minsamples and maxsamples options to hwtimestamp directive + Add support for faster frequency adjustments in Linux 4.19 + Change default pidfile to /var/run/chrony/chronyd.pid to allow chronyd without root privileges to remove it on exit + Disable sub-second polling intervals for distant NTP sources + Extend range of supported sub-second polling intervals + Get/set IPv4 destination/source address of NTP packets on FreeBSD + Make burst options and command useful with short polling intervals + Modify auto_offline option to activate when sending request failed + Respond from interface that received NTP request if possible + Add onoffline command to switch between online and offline state according to current system network configuration + Improve example NetworkManager dispatcher script
    * Bug fixes
    + Avoid waiting in Linux getrandom system call + Fix PPS support on FreeBSD and NetBSD
    Update to version 3.3
    * Enhancements:
    + Add burst option to server/pool directive + Add stratum and tai options to refclock directive + Add support for Nettle crypto library + Add workaround for missing kernel receive timestamps on Linux + Wait for late hardware transmit timestamps + Improve source selection with unreachable sources + Improve protection against replay attacks on symmetric mode + Allow PHC refclock to use socket in /var/run/chrony + Add shutdown command to stop chronyd + Simplify format of response to manual list command + Improve handling of unknown responses in chronyc
    * Bug fixes:
    + Respond to NTPv1 client requests with zero mode + Fix -x option to not require CAP_SYS_TIME under non-root user + Fix acquisitionport directive to work with privilege separation + Fix handling of socket errors on Linux to avoid high CPU usage + Fix chronyc to not get stuck in infinite loop after clock step


    Advisory IDSUSE-RU-2022:861-1
    ReleasedTue Mar 15 23:30:48 2022
    SummaryRecommended update for openssl-1_1
    Typerecommended
    Severitymoderate
    References1182959,1195149,1195792,1195856
    Description:

    This update for openssl-1_1 fixes the following issues:
    openssl-1_1:

    glibc:
    linux-glibc-devel:

    libxcrypt:

    zlib:


    Advisory IDSUSE-RU-2022:874-1
    ReleasedWed Mar 16 10:40:52 2022
    SummaryRecommended update for openldap2
    Typerecommended
    Severitymoderate
    References1197004
    Description:

    This update for openldap2 fixes the following issue:


    Advisory IDSUSE-RU-2022:905-1
    ReleasedMon Mar 21 08:46:09 2022
    SummaryRecommended update for util-linux
    Typerecommended
    Severityimportant
    References1172427,1194642
    Description:

    This update for util-linux fixes the following issues:


    Advisory IDSUSE-RU-2022:936-1
    ReleasedTue Mar 22 18:10:17 2022
    SummaryRecommended update for filesystem and systemd-rpm-macros
    Typerecommended
    Severitymoderate
    References1196275,1196406
    Description:

    This update for filesystem and systemd-rpm-macros fixes the following issues:
    filesystem:


    systemd-rpm-macros:


    Advisory IDSUSE-SU-2022:4167-1
    ReleasedTue Nov 22 12:18:49 2022
    SummarySecurity update for krb5
    Typesecurity
    Severityimportant
    References1205126,CVE-2022-42898
    Description:

    This update for krb5 fixes the following issues: