Container summary for bci/golang
SUSE-CU-2023:768-1
Container Advisory ID | SUSE-CU-2023:768-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-20.6 |
Container Release | 20.6 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:869-1
|
Released | Wed Mar 22 09:43:30 2023 |
Summary | Security update for go1.18 |
Type | security |
Severity | important |
References | 1208270,1208271,1208272,1208491,CVE-2022-41723,CVE-2022-41724,CVE-2022-41725 |
Description:
This update for go1.18 fixes the following issues:
- CVE-2022-41723: Fixed a quadratic complexity in HPACK decoding in net/http (bsc#1208270).
- CVE-2022-41724: Fixed a denial of service from excessive resource consumption in net/http and mime/multipart (bsc#1208271).
- CVE-2022-41725: Fixed a panic with large handshake records in crypto/tls (bsc#1208272).
The following non-security bug was fixed:
- Fixed PTF ref:_00D1igLOd._5005qM0AP4:ref SG#65262 (bsc#1208491).
SUSE-CU-2023:707-1
Container Advisory ID | SUSE-CU-2023:707-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-20.4 |
Container Release | 20.4 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:776-1
|
Released | Thu Mar 16 17:29:23 2023 |
Summary | Recommended update for gcc12 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for gcc12 fixes the following issues:
This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided in the SUSE Linux
Enterprise Module for Development Tools.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
Advisory ID | SUSE-RU-2023:782-1
|
Released | Thu Mar 16 19:08:34 2023 |
Summary | Recommended update for libgcrypt |
Type | recommended |
Severity | moderate |
References | 1208924,1208925,1208926 |
Description:
This update for libgcrypt fixes the following issues:
- FIPS: ECC: Transition to error-state if PCT fail [bsc#1208925]
- FIPS: ECDSA: Avoid no-keytest in ECDSA keygen [bsc#1208924]
- FIPS: PBKDF2: Added additional checks for the minimum key length,
salt length, iteration count and passphrase length to the kdf
FIPS indicator in _gcry_fips_indicator_kdf() [bsc#1208926]
Advisory ID | SUSE-RU-2023:783-1
|
Released | Thu Mar 16 19:09:03 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1208998 |
Description:
This update for openssl-1_1 fixes the following issues:
FIPS: Service-level indicator changes [bsc#1208998]
- Add additional checks required by FIPS 140-3. Minimum values for
PBKDF2 are: 112 bits for key, 128 bits for salt, 1000 for
iteration count and 20 characters for password.
SUSE-CU-2023:660-1
Container Advisory ID | SUSE-CU-2023:660-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.48 |
Container Release | 19.48 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:734-1
|
Released | Tue Mar 14 18:07:33 2023 |
Summary | Recommended update for go1.18 |
Type | recommended |
Severity | moderate |
References | 1193742 |
Description:
This update for go1.18 fixes the following issues:
go1.18.10 (released 2023-01-10) includes fixes to cgo, the
compiler, the linker, and the crypto/x509, net/http, and syscall
packages. (bsc#1193742)
- misc/cgo: backport needed for dlltool fix
- crypto/x509: Verify on macOS does not return typed errors
- cmd/compile: the loong64 intrinsic for CompareAndSwapUint32 function needs to sign extend its 'old' argument.
- syscall, internal/poll: accept4-to-accept fallback removal broke Go code on Synology DSM 6.2 ARM devices
- os: TestLstat failure on Linux Aarch64
- reflect: sort.SliceStable sorts incorrectly on arm64 with less function created with reflect.MakeFunc and slice of sufficient length
- cmd/go: remove test dependency on gopkg.in service
- cmd/go: TestScript/version_buildvcs_git_gpg (if enabled) fails on linux longtest builders
- cgo: malformed DWARF TagVariable entry
- cmd/cgo: Wrong types in compiler errors with clang 14
- cmd/link/internal/ppc64: too-far trampoline is reused
- net: reenable TestLookupDotsWithRemoteSource and TestLookupGoogleSRV with a different target
- net/http: bad handling of HEAD requests with a body
SUSE-CU-2023:651-1
Container Advisory ID | SUSE-CU-2023:651-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.47 |
Container Release | 19.47 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:714-1
|
Released | Mon Mar 13 10:53:25 2023 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | important |
References | 1207294 |
Description:
This update for rpm fixes the following issues:
- Fix missing python(abi) for 3.XX versions (bsc#1207294)
SUSE-CU-2023:550-1
Container Advisory ID | SUSE-CU-2023:550-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.43 |
Container Release | 19.43 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:617-1
|
Released | Fri Mar 3 16:49:06 2023 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | 1207789 |
Description:
This update for jitterentropy fixes the following issues:
- build jitterentropy library with debuginfo (bsc#1207789)
SUSE-CU-2023:519-1
Container Advisory ID | SUSE-CU-2023:519-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.41 |
Container Release | 19.41 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:563-1
|
Released | Tue Feb 28 10:51:46 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1207994 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Serialize jitterentropy calls to avoid thread safety issues [bsc#1207994]
SUSE-CU-2023:434-1
Container Advisory ID | SUSE-CU-2023:434-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.37 |
Container Release | 19.37 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:464-1
|
Released | Mon Feb 20 18:11:37 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for systemd fixes the following issues:
- Merge of v249.15
- Drop workaround related to systemd-timesyncd that addressed a Factory issue.
- Conditionalize the use of /lib/modprobe.d only on systems with split usr
support enabled (i.e. SLE).
- Make use of the %systemd_* rpm macros consistently. Using the upstream
variants will ease the backports of Factory changes to SLE since Factory
systemd uses the upstream variants exclusively.
- machines.target belongs to systemd-container, do its init/cleanup steps from
the scriptlets of this sub-package.
- Make sure we apply the presets on units shipped by systemd package.
- systemd-testsuite: move the integration tests in a dedicated sub directory.
- Move systemd-cryptenroll into udev package.
SUSE-CU-2023:360-1
Container Advisory ID | SUSE-CU-2023:360-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.31 |
Container Release | 19.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:429-1
|
Released | Wed Feb 15 17:41:22 2023 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1207990,1207991,1207992,CVE-2023-23914,CVE-2023-23915,CVE-2023-23916 |
Description:
This update for curl fixes the following issues:
- CVE-2023-23914: Fixed HSTS ignored on multiple requests (bsc#1207990).
- CVE-2023-23915: Fixed HSTS amnesia with --parallel (bsc#1207991).
- CVE-2023-23916: Fixed HTTP multi-header compression denial of service (bsc#1207992).
Advisory ID | SUSE-SU-2023:430-1
|
Released | Wed Feb 15 17:42:25 2023 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1208027,1208028,CVE-2023-22490,CVE-2023-23946 |
Description:
This update for git fixes the following issues:
- CVE-2023-22490: Fixed incorrectly usable local clone optimization even when using a non-local transport (bsc#1208027).
- CVE-2023-23946: Fixed issue where a path outside the working tree can be overwritten as the user who is running 'git apply' (bsc#1208028).
SUSE-CU-2023:359-1
Container Advisory ID | SUSE-CU-2023:359-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.30 |
Container Release | 19.30 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:348-1
|
Released | Fri Feb 10 15:08:41 2023 |
Summary | Security update for less |
Type | security |
Severity | moderate |
References | 1207815,CVE-2022-46663 |
Description:
This update for less fixes the following issues:
- CVE-2022-46663: Fixed denial-of-service by printing specially crafted escape sequences to the terminal (bsc#1207815).
SUSE-CU-2023:309-1
Container Advisory ID | SUSE-CU-2023:309-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.28 |
Container Release | 19.28 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:311-1
|
Released | Tue Feb 7 17:36:32 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1207533,1207534,1207536,1207538,CVE-2022-4304,CVE-2022-4450,CVE-2023-0215,CVE-2023-0286 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-0286: Fixed X.400 address type confusion in X.509 GENERAL_NAME_cmp for x400Address (bsc#1207533).
- CVE-2023-0215: Fixed use-after-free following BIO_new_NDEF() (bsc#1207536).
- CVE-2022-4450: Fixed double free after calling PEM_read_bio_ex() (bsc#1207538).
- CVE-2022-4304: Fixed timing Oracle in RSA Decryption (bsc#1207534).
SUSE-CU-2023:273-1
Container Advisory ID | SUSE-CU-2023:273-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.25 |
Container Release | 19.25 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:188-1
|
Released | Fri Jan 27 12:07:19 2023 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | important |
References | 1203652 |
Description:
This update for zlib fixes the following issues:
- Follow up fix for bug bsc#1203652 due to libxml2 issues
Advisory ID | SUSE-SU-2023:201-1
|
Released | Fri Jan 27 15:24:15 2023 |
Summary | Security update for systemd |
Type | security |
Severity | moderate |
References | 1204944,1205000,1207264,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed an issue where users could access coredumps
with changed uid, gid or capabilities (bsc#1205000).
Non-security fixes:
- Enabled the pstore service (jsc#PED-2663).
- Fixed an issue accessing TPM when secure boot is enabled (bsc#1204944).
- Fixed an issue where a pamd file could get accidentally overwritten
after an update (bsc#1207264).
SUSE-CU-2023:244-1
Container Advisory ID | SUSE-CU-2023:244-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.21 |
Container Release | 19.21 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:177-1
|
Released | Thu Jan 26 20:57:35 2023 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1194038,1205646 |
Description:
This update for util-linux fixes the following issues:
- Fix tests not passing when '@' character is in build path:
Fixes rpmbuild %checks fail when @ in the directory path (bsc#1194038).
- libuuid continuous clock handling for time based UUIDs:
Prevent use of the new libuuid ABI by uuidd %post before update
of libuuid1 (bsc#1205646).
Advisory ID | SUSE-RU-2023:178-1
|
Released | Thu Jan 26 20:58:21 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1207182 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Add Pair-wise Consistency Test when generating DH key [bsc#1207182]
SUSE-CU-2023:179-1
Container Advisory ID | SUSE-CU-2023:179-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.18 |
Container Release | 19.18 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:110-1
|
Released | Fri Jan 20 10:18:16 2023 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1207032,1207033,CVE-2022-23521,CVE-2022-41903 |
Description:
This update for git fixes the following issues:
- CVE-2022-41903: Fixed a heap overflow in the 'git archive' and
'git log --format' commands (bsc#1207033).
- CVE-2022-23521: Fixed an integer overflow that could be triggered
when parsing a gitattributes file (bsc#1207032).
SUSE-CU-2023:112-1
Container Advisory ID | SUSE-CU-2023:112-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.15 |
Container Release | 19.15 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:45-1
|
Released | Mon Jan 9 10:32:26 2023 |
Summary | Recommended update for libxml2 |
Type | recommended |
Severity | moderate |
References | 1204585 |
Description:
This update for libxml2 fixes the following issues:
- Add W3C conformance tests to the testsuite (bsc#1204585):
* Added file xmlts20080827.tar.gz
Advisory ID | SUSE-RU-2023:48-1
|
Released | Mon Jan 9 10:37:54 2023 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1199467 |
Description:
This update for libtirpc fixes the following issues:
- Consider /proc/sys/net/ipv4/ip_local_reserved_ports, before binding to a random port (bsc#1199467)
Advisory ID | SUSE-RU-2023:50-1
|
Released | Mon Jan 9 10:42:21 2023 |
Summary | Recommended update for shadow |
Type | recommended |
Severity | moderate |
References | 1205502 |
Description:
This update for shadow fixes the following issues:
- Fix issue with user id field that cannot be interpreted (bsc#1205502)
SUSE-CU-2023:60-1
Container Advisory ID | SUSE-CU-2023:60-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.13 |
Container Release | 19.13 |
The following patches have been included in this update:
SUSE-CU-2023:36-1
Container Advisory ID | SUSE-CU-2023:36-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.12 |
Container Release | 19.12 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:25-1
|
Released | Thu Jan 5 09:51:41 2023 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
Version update from 2022f to 2022g (bsc#1177460):
- In the Mexican state of Chihuahua:
* The border strip near the US will change to agree with nearby US locations on 2022-11-30.
* The strip's western part, represented by Ciudad Juarez, switches from -06 all year to -07/-06 with US DST rules,
like El Paso, TX.
* The eastern part, represented by Ojinaga, will observe US DST next year, like Presidio, TX.
* A new Zone America/Ciudad_Juarez splits from America/Ojinaga.
- Much of Greenland, represented by America/Nuuk, stops observing winter time after March 2023, so its daylight saving
time becomes standard time.
- Changes for pre-1996 northern Canada
- Update to past DST transition in Colombia (1993), Singapore (1981)
- 'timegm' is now supported by default
SUSE-CU-2022:3491-1
Container Advisory ID | SUSE-CU-2022:3491-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.9 |
Container Release | 19.9 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:4629-1
|
Released | Wed Dec 28 09:24:07 2022 |
Summary | Security update for systemd |
Type | security |
Severity | important |
References | 1200723,1205000,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).
Bug fixes:
- Support by-path devlink for multipath nvme block devices (bsc#1200723).
SUSE-CU-2022:3438-1
Container Advisory ID | SUSE-CU-2022:3438-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.7 |
Container Release | 19.7 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:4597-1
|
Released | Wed Dec 21 10:13:11 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1206308,1206309,CVE-2022-43551,CVE-2022-43552 |
Description:
This update for curl fixes the following issues:
- CVE-2022-43552: HTTP Proxy deny use-after-free (bsc#1206309).
- CVE-2022-43551: Fixed HSTS bypass via IDN (bsc#1206308).
SUSE-CU-2022:3407-1
Container Advisory ID | SUSE-CU-2022:3407-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-19.2 |
Container Release | 19.2 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4499-1
|
Released | Thu Dec 15 10:48:49 2022 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1179465 |
Description:
This update for openssh fixes the following issues:
- Make ssh connections update their dbus environment (bsc#1179465):
* Add openssh-dbus.sh, openssh-dbus.csh, openssh-dbus.fish
SUSE-CU-2022:3385-1
Container Advisory ID | SUSE-CU-2022:3385-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.52 |
Container Release | 18.52 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:4398-1
|
Released | Fri Dec 9 15:59:41 2022 |
Summary | Security update for go1.18 |
Type | security |
Severity | moderate |
References | 1193742,1206134,1206135,CVE-2022-41717,CVE-2022-41720 |
Description:
This update for go1.18 fixes the following issues:
Update to version 1.18.9, includes the following security fixes:
- CVE-2022-41717: net/http: limit canonical header cache by bytes, not entries (bsc#1206135)
- CVE-2022-41720: os, net/http: avoid escapes from os.DirFS and http.Dir on Windows (bsc#1206134)
SUSE-CU-2022:3286-1
Container Advisory ID | SUSE-CU-2022:3286-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.47 |
Container Release | 18.47 |
The following patches have been included in this update:
SUSE-CU-2022:3216-1
Container Advisory ID | SUSE-CU-2022:3216-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.46 |
Container Release | 18.46 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4256-1
|
Released | Mon Nov 28 12:36:32 2022 |
Summary | Recommended update for gcc12 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for gcc12 fixes the following issues:
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
The Go, D and Ada language compiler parts are available unsupported via the
PackageHub repositories.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your Makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
SUSE-CU-2022:3169-1
Container Advisory ID | SUSE-CU-2022:3169-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.44 |
Container Release | 18.44 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4236-1
|
Released | Fri Nov 25 18:20:32 2022 |
Summary | Recommended update for linux-glibc-devel |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for linux-glibc-devel fixes the following issues:
- Add the rest of 1.0 IAA operation definitions to the user header (jsc#PED-813).
SUSE-CU-2022:3147-1
Container Advisory ID | SUSE-CU-2022:3147-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.43 |
Container Release | 18.43 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4212-1
|
Released | Thu Nov 24 15:53:48 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1190651 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Mark PBKDF2 with key shorter than 112 bits as non-approved (bsc#1190651)
- FIPS: Consider RSA siggen/sigver with PKCS1 padding also approved (bsc#1190651)
- FIPS: Return the correct indicator for a given EC group order bits (bsc#1190651)
SUSE-CU-2022:3146-1
Container Advisory ID | SUSE-CU-2022:3146-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.42 |
Container Release | 18.42 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4198-1
|
Released | Wed Nov 23 13:15:04 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | moderate |
References | 1202750 |
Description:
This update for rpm fixes the following issues:
- Strip critical bit in signature subpackage parsing
- No longer deadlock DNF after pubkey import (bsc#1202750)
SUSE-CU-2022:3145-1
Container Advisory ID | SUSE-CU-2022:3145-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.40 |
Container Release | 18.40 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4066-1
|
Released | Fri Nov 18 10:43:00 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1177460,1202324,1204649,1205156 |
Description:
This update for timezone fixes the following issues:
Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156):
- Mexico will no longer observe DST except near the US border
- Chihuahua moves to year-round -06 on 2022-10-30
- Fiji no longer observes DST
- In vanguard form, GMT is now a Zone and Etc/GMT a link
- zic now supports links to links, and vanguard form uses this
- Simplify four Ontario zones
- Fix a Y2438 bug when reading TZif data
- Enable 64-bit time_t on 32-bit glibc platforms
- Omit large-file support when no longer needed
- Jordan and Syria switch from +02/+03 with DST to year-round +03
- Palestine transitions are now Saturdays at 02:00
- Simplify three Ukraine zones into one
- Improve tzselect on intercontinental Zones
- Chile's DST is delayed by a week in September 2022 (bsc#1202324)
- Iran no longer observes DST after 2022
- Rename Europe/Kiev to Europe/Kyiv
- New `zic -R` command option
- Vanguard form now uses %z
Advisory ID | SUSE-SU-2022:4081-1
|
Released | Fri Nov 18 15:40:46 2022 |
Summary | Security update for dpkg |
Type | security |
Severity | low |
References | 1199944,CVE-2022-1664 |
Description:
This update for dpkg fixes the following issues:
- CVE-2022-1664: Fixed a directory traversal vulnerability in Dpkg::Source::Archive (bsc#1199944).
Advisory ID | SUSE-RU-2022:4135-1
|
Released | Mon Nov 21 00:13:40 2022 |
Summary | Recommended update for libeconf |
Type | recommended |
Severity | moderate |
References | 1198165 |
Description:
This update for libeconf fixes the following issues:
- Update to version 0.4.6+git
- econftool:
Parsing error: Reporting file and line nr. --delimeters=spaces accepting all kind of spaces for delimiter.
- libeconf:
Parse files correctly on space characters (1198165)
- Update to version 0.4.5+git
- econftool:
New call 'syntax' for checking the configuration files only. Returns an error string with line number if error.
New options '--comment' and '--delimeters'
Advisory ID | SUSE-SU-2022:4146-1
|
Released | Mon Nov 21 09:56:12 2022 |
Summary | Security update for binutils |
Type | security |
Severity | moderate |
References | 1142579,1185597,1185712,1188374,1191473,1193929,1194783,1197592,1198237,1202816,1202966,1202967,1202969,CVE-2019-1010204,CVE-2021-3530,CVE-2021-3648,CVE-2021-3826,CVE-2021-45078,CVE-2021-46195,CVE-2022-27943,CVE-2022-38126,CVE-2022-38127,CVE-2022-38533 |
Description:
This update for binutils fixes the following issues:
The following security bugs were fixed:
- CVE-2019-1010204: Fixed out-of-bounds read in elfcpp/elfcpp_file.h (bsc#1142579).
- CVE-2021-3530: Fixed stack-based buffer overflow in demangle_path() in rust-demangle.c (bsc#1185597).
- CVE-2021-3648: Fixed infinite loop while demangling rust symbols (bsc#1188374).
- CVE-2021-3826: Fixed heap/stack buffer overflow in the dlang_lname function in d-demangle.c (bsc#1202969).
- CVE-2021-45078: Fixed out-of-bounds write in stab_xcoff_builtin_type() in stabs.c (bsc#1193929).
- CVE-2021-46195: Fixed uncontrolled recursion in libiberty/rust-demangle.c (bsc#1194783).
- CVE-2022-27943: Fixed stack exhaustion in demangle_const in (bsc#1197592).
- CVE-2022-38126: Fixed assertion fail in the display_debug_names() function in binutils/dwarf.c (bsc#1202966).
- CVE-2022-38127: Fixed NULL pointer dereference in the read_and_display_attr_value() function in binutils/dwarf.c (bsc#1202967).
- CVE-2022-38533: Fixed heap out-of-bounds read in bfd_getl32 (bsc#1202816).
The following non-security bugs were fixed:
- SLE toolchain update of binutils, update to 2.39 from 2.37.
- Update to 2.39:
* The ELF linker will now generate a warning message if the stack is made
executable. Similarly it will warn if the output binary contains a
segment with all three of the read, write and execute permission
bits set. These warnings are intended to help developers identify
programs which might be vulnerable to attack via these executable
memory regions.
The warnings are enabled by default but can be disabled via a command
line option. It is also possible to build a linker with the warnings
disabled, should that be necessary.
* The ELF linker now supports a --package-metadata option that allows
embedding a JSON payload in accordance to the Package Metadata
specification.
* In linker scripts it is now possible to use TYPE= in an output
section description to set the section type value.
* The objdump program now supports coloured/colored syntax
highlighting of its disassembler output for some architectures.
(Currently: AVR, RiscV, s390, x86, x86_64).
* The nm program now supports a --no-weak/-W option to make it ignore
weak symbols.
* The readelf and objdump programs now support a -wE option to prevent
them from attempting to access debuginfod servers when following
links.
* The objcopy program's --weaken, --weaken-symbol, and
--weaken-symbols options now works with unique symbols as well.
- Update to 2.38:
* elfedit: Add --output-abiversion option to update ABIVERSION.
* Add support for the LoongArch instruction set.
* Tools which display symbols or strings (readelf, strings, nm, objdump)
have a new command line option which controls how unicode characters are
handled. By default they are treated as normal for the tool. Using
--unicode=locale will display them according to the current locale.
Using --unicode=hex will display them as hex byte values, whilst
--unicode=escape will display them as escape sequences. In addition
using --unicode=highlight will display them as unicode escape sequences
highlighted in red (if supported by the output device).
* readelf -r dumps RELR relative relocations now.
* Support for efi-app-aarch64, efi-rtdrv-aarch64 and efi-bsdrv-aarch64 has been
added to objcopy in order to enable UEFI development using binutils.
* ar: Add --thin for creating thin archives. -T is a deprecated alias without
diagnostics. In many ar implementations -T has a different meaning, as
specified by X/Open System Interface.
* Add support for AArch64 system registers that were missing in previous
releases.
* Add support for the LoongArch instruction set.
* Add a command-line option, -muse-unaligned-vector-move, for x86 target
to encode aligned vector move as unaligned vector move.
* Add support for Cortex-R52+ for Arm.
* Add support for Cortex-A510, Cortex-A710, Cortex-X2 for AArch64.
* Add support for Cortex-A710 for Arm.
* Add support for Scalable Matrix Extension (SME) for AArch64.
* The --multibyte-handling=[allow|warn|warn-sym-only] option tells the
assembler what to when it encoutners multibyte characters in the input. The
default is to allow them. Setting the option to 'warn' will generate a
warning message whenever any multibyte character is encountered. Using the
option to 'warn-sym-only' will make the assembler generate a warning whenever a
symbol is defined containing multibyte characters. (References to undefined
symbols will not generate warnings).
* Outputs of .ds.x directive and .tfloat directive with hex input from
x86 assembler have been reduced from 12 bytes to 10 bytes to match the
output of .tfloat directive.
* Add support for 'armv8.8-a', 'armv9-a', 'armv9.1-a', 'armv9.2-a' and
'armv9.3-a' for -march in AArch64 GAS.
* Add support for 'armv8.7-a', 'armv8.8-a', 'armv9-a', 'armv9.1-a',
'armv9.2-a' and 'armv9.3-a' for -march in Arm GAS.
* Add support for Intel AVX512_FP16 instructions.
* Add -z pack-relative-relocs/-z no pack-relative-relocs to x86 ELF
linker to pack relative relocations in the DT_RELR section.
* Add support for the LoongArch architecture.
* Add -z indirect-extern-access/-z noindirect-extern-access to x86 ELF
linker to control canonical function pointers and copy relocation.
* Add --max-cache-size=SIZE to set the the maximum cache size to SIZE
bytes.
- Explicitly enable --enable-warn-execstack=yes and --enable-warn-rwx-segments=yes.
- Add gprofng subpackage.
- Include recognition of 'z16' name for 'arch14' on s390. (bsc#1198237).
- Add back fix for bsc#1191473, which got lost in the update to 2.38.
- Install symlinks for all target specific tools on arm-eabi-none (bsc#1185712).
- Enable PRU architecture for AM335x CPU (Beagle Bone Black board)
Advisory ID | SUSE-SU-2022:4153-1
|
Released | Mon Nov 21 14:34:09 2022 |
Summary | Security update for krb5 |
Type | security |
Severity | important |
References | 1205126,CVE-2022-42898 |
Description:
This update for krb5 fixes the following issues:
- CVE-2022-42898: Fixed integer overflow in PAC parsing (bsc#1205126).
SUSE-CU-2022:3024-1
Container Advisory ID | SUSE-CU-2022:3024-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.31 |
Container Release | 18.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3999-1
|
Released | Tue Nov 15 17:08:04 2022 |
Summary | Security update for systemd |
Type | security |
Severity | moderate |
References | 1204179,1204968,CVE-2022-3821 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).
- Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428
* 0469b9f2bc pstore: do not try to load all known pstore modules
* ad05f54439 pstore: Run after modules are loaded
* ccad817445 core: Add trigger limit for path units
* 281d818fe3 core/mount: also add default before dependency for automount mount units
* ffe5b4afa8 logind: fix crash in logind on user-specified message string
- Document udev naming scheme (bsc#1204179)
- Make 'sle15-sp3' net naming scheme still available for backward compatibility
reason
Advisory ID | SUSE-SU-2022:4055-1
|
Released | Thu Nov 17 15:37:24 2022 |
Summary | Security update for go1.18 |
Type | security |
Severity | low |
References | 1193742,1204941,CVE-2022-41716 |
Description:
This update for go1.18 fixes the following issues:
Update to go 1.18.8 (released 2022-11-01) (bsc#1193742):
Security fixes:
- CVE-2022-41716: Fixed unsanitized NUL in environment variables in syscalls, os/exec (go#56327) (bsc#1204941).
Bugfixes:
- runtime: lock count' fatal error when cgo is enabled (go#56308).
SUSE-CU-2022:2986-1
Container Advisory ID | SUSE-CU-2022:2986-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.27 |
Container Release | 18.27 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3961-1
|
Released | Mon Nov 14 07:33:50 2022 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | important |
References | 1203652 |
Description:
This update for zlib fixes the following issues:
- Fix updating strm.adler with inflate() if DFLTCC is used (bsc#1203652)
Advisory ID | SUSE-RU-2022:3974-1
|
Released | Mon Nov 14 15:39:20 2022 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1201959,1204211 |
Description:
This update for util-linux fixes the following issues:
- Fix file conflict during upgrade (bsc#1204211)
- libuuid improvements (bsc#1201959, PED-1150):
libuuid: Fix range when parsing UUIDs.
Improve cache handling for short running applications-increment the cache size over runtime.
Implement continuous clock handling for time based UUIDs.
Check clock value from clock file to provide seamless libuuid.
SUSE-CU-2022:2943-1
Container Advisory ID | SUSE-CU-2022:2943-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.23 |
Container Release | 18.23 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3931-1
|
Released | Thu Nov 10 11:26:01 2022 |
Summary | Security update for git |
Type | security |
Severity | moderate |
References | 1204455,1204456,CVE-2022-39253,CVE-2022-39260 |
Description:
This update for git fixes the following issues:
- CVE-2022-39260: Fixed overflow in split_cmdline() (bsc#1204456).
- CVE-2022-39253: Fixed dereference issue with symbolic links via the `--local` clone mechanism (bsc#1204455).
SUSE-CU-2022:2912-1
Container Advisory ID | SUSE-CU-2022:2912-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.22 |
Container Release | 18.22 |
The following patches have been included in this update:
SUSE-CU-2022:2893-1
Container Advisory ID | SUSE-CU-2022:2893-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.21 |
Container Release | 18.21 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3904-1
|
Released | Tue Nov 8 10:52:13 2022 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1192439 |
Description:
This update for openssh fixes the following issue:
- Prevent empty messages from being sent. (bsc#1192439)
Advisory ID | SUSE-RU-2022:3910-1
|
Released | Tue Nov 8 13:05:04 2022 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for pam fixes the following issue:
- Update pam_motd to the most current version. (PED-1712)
SUSE-CU-2022:2859-1
Container Advisory ID | SUSE-CU-2022:2859-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.18 |
Container Release | 18.18 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3884-1
|
Released | Mon Nov 7 10:59:26 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1204708,CVE-2022-43680 |
Description:
This update for expat fixes the following issues:
- CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).
SUSE-CU-2022:2821-1
Container Advisory ID | SUSE-CU-2022:2821-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.16 |
Container Release | 18.16 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3870-1
|
Released | Fri Nov 4 11:12:08 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1190651,1202148 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Add a missing dependency on jitterentropy-devel for libopenssl-1_1-devel (bsc#1202148)
- FIPS: OpenSSL service-level indicator: Allow AES XTS 256 (bsc#1190651)
SUSE-CU-2022:2756-1
Container Advisory ID | SUSE-CU-2022:2756-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.13 |
Container Release | 18.13 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3785-1
|
Released | Wed Oct 26 20:20:19 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1204383,1204386,CVE-2022-32221,CVE-2022-42916 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383).
- CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386).
Advisory ID | SUSE-RU-2022:3787-1
|
Released | Thu Oct 27 04:41:09 2022 |
Summary | Recommended update for permissions |
Type | recommended |
Severity | important |
References | 1194047,1203911 |
Description:
This update for permissions fixes the following issues:
- Fix regression introduced by backport of security fix (bsc#1203911)
- Add permissions for enlightenment helper on 32bit arches (bsc#1194047)
SUSE-CU-2022:2715-1
Container Advisory ID | SUSE-CU-2022:2715-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-18.7 |
Container Release | 18.7 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2796-1
|
Released | Fri Aug 12 14:34:31 2022 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for jitterentropy fixes the following issues:
jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library,
used by other FIPS libraries.
Advisory ID | SUSE-RU-2022:3328-1
|
Released | Wed Sep 21 12:48:56 2022 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | 1202870 |
Description:
This update for jitterentropy fixes the following issues:
- Hide the non-GNUC constructs that are library internal from the
exported header, to make it usable in builds with strict C99
compliance. (bsc#1202870)
Advisory ID | SUSE-RU-2022:3551-1
|
Released | Fri Oct 7 17:03:55 2022 |
Summary | Recommended update for libgcrypt |
Type | recommended |
Severity | moderate |
References | 1182983,1190700,1191020,1202117 |
Description:
This update for libgcrypt fixes the following issues:
- FIPS: Fixed gpg/gpg2 gets out of core handler in FIPS mode while
typing Tab key to Auto-Completion. [bsc#1182983]
- FIPS: Ported libgcrypt to use jitterentropy [bsc#1202117, jsc#SLE-24941]
* Enable the jitter based entropy generator by default in random.conf
* Update the internal jitterentropy to version 3.4.0
- FIPS: Get most of the entropy from rndjent_poll [bsc#1202117]
- FIPS: Check keylength in gcry_fips_indicator_kdf() [bsc#1190700]
* Consider approved keylength greater or equal to 112 bits.
- FIPS: Zeroize buffer and digest in check_binary_integrity() [bsc#1191020]
Advisory ID | SUSE-RU-2022:3555-1
|
Released | Mon Oct 10 14:05:12 2022 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | important |
References | 1199492 |
Description:
This update for aaa_base fixes the following issues:
- The wrapper rootsh is not a restricted shell. (bsc#1199492)
Advisory ID | SUSE-RU-2022:3663-1
|
Released | Wed Oct 19 19:05:21 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1121365,1180995,1190651,1190653,1190888,1193859,1198471,1198472,1201293,1202148,1203046,1203069 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Default to RFC-7919 groups for genparam and dhparam
- FIPS: list only FIPS approved digest and public key algorithms
[bsc#1121365, bsc#1190888, bsc#1193859, bsc#1198471, bsc#1198472]
- FIPS: Add KAT for the RAND_DRBG implementation [bsc#1203069]
- FIPS: openssl: RAND api should call into FIPS DRBG [bsc#1201293]
* The FIPS_drbg implementation is not FIPS validated anymore. To
provide backwards compatibility for applications that need FIPS
compliant RNG number generation and use FIPS_drbg_generate,
this function was re-wired to call the FIPS validated DRBG
instance instead through the RAND_bytes() call.
- FIPS: Fix minor memory leaks by FIPS patch [bsc#1203046]
- FIPS: OpenSSL: Port openssl to use jitterentropy [bsc#1202148, jsc#SLE-24941]
libcrypto.so now requires libjitterentropy3 library.
- FIPS: OpenSSL Provide a service-level indicator [bsc#1190651]
- FIPS: Add zeroization of temporary variables to the hmac integrity
function FIPSCHECK_verify(). [bsc#1190653]
Advisory ID | SUSE-SU-2022:3668-1
|
Released | Wed Oct 19 21:34:58 2022 |
Summary | Security update for go1.18 |
Type | security |
Severity | important |
References | 1193742,1204023,1204024,1204025,CVE-2022-2879,CVE-2022-2880,CVE-2022-41715 |
Description:
This update for go1.18 fixes the following issues:
Updated to version 1.18.7 (bsc#1193742):
- CVE-2022-41715: Fixed memory exhaustion in regexp/syntax (bsc#1204023).
- CVE-2022-2879: Fixed unbounded memory consumption when reading headers in archive/tar (bsc#1204024).
- CVE-2022-2880: Fixed ReverseProxy forwarding unparseable query parameters (bsc#1204025).
Advisory ID | SUSE-SU-2022:3692-1
|
Released | Fri Oct 21 16:15:07 2022 |
Summary | Security update for libxml2 |
Type | security |
Severity | important |
References | 1204366,1204367,CVE-2022-40303,CVE-2022-40304 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2022-40303: Fixed integer overflows with XML_PARSE_HUGE (bsc#1204366).
- CVE-2022-40304: Fixed dict corruption caused by entity reference cycles (bsc#1204367).
SUSE-CU-2022:2582-1
Container Advisory ID | SUSE-CU-2022:2582-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-17.8 |
Container Release | 17.8 |
The following patches have been included in this update:
SUSE-CU-2022:2534-1
Container Advisory ID | SUSE-CU-2022:2534-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-17.7 |
Container Release | 17.7 |
The following patches have been included in this update:
SUSE-CU-2022:2489-1
Container Advisory ID | SUSE-CU-2022:2489-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-17.4 |
Container Release | 17.4 |
The following patches have been included in this update:
SUSE-CU-2022:2436-1
Container Advisory ID | SUSE-CU-2022:2436-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.43 |
Container Release | 16.43 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3489-1
|
Released | Sat Oct 1 13:35:24 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1203438,CVE-2022-40674 |
Description:
This update for expat fixes the following issues:
- CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438).
SUSE-CU-2022:2416-1
Container Advisory ID | SUSE-CU-2022:2416-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.42 |
Container Release | 16.42 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3452-1
|
Released | Wed Sep 28 12:13:43 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1201942 |
Description:
This update for glibc fixes the following issues:
- Reversing calculation of __x86_shared_non_temporal_threshold (bsc#1201942)
- powerpc: Optimized memcmp for power10 (jsc#PED-987)
SUSE-CU-2022:2367-1
Container Advisory ID | SUSE-CU-2022:2367-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.40 |
Container Release | 16.40 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3353-1
|
Released | Fri Sep 23 15:23:40 2022 |
Summary | Security update for permissions |
Type | security |
Severity | moderate |
References | 1203018,CVE-2022-31252 |
Description:
This update for permissions fixes the following issues:
- CVE-2022-31252: Fixed chkstat group controlled paths (bsc#1203018).
SUSE-CU-2022:2328-1
Container Advisory ID | SUSE-CU-2022:2328-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.34 |
Container Release | 16.34 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3305-1
|
Released | Mon Sep 19 11:45:57 2022 |
Summary | Security update for libtirpc |
Type | security |
Severity | important |
References | 1201680,CVE-2021-46828 |
Description:
This update for libtirpc fixes the following issues:
- CVE-2021-46828: Fixed denial of service vulnerability with lots of connections (bsc#1201680).
Advisory ID | SUSE-SU-2022:3325-1
|
Released | Wed Sep 21 12:28:17 2022 |
Summary | Security update for go1.18 |
Type | security |
Severity | important |
References | 1193742,1203185,CVE-2022-27664 |
Description:
This update for go1.18 fixes the following issues:
Update to go version 1.18.6 (bsc#1193742):
- CVE-2022-27664: Fixed DoS in net/http caused by mishandled server errors after sending GOAWAY (bsc#1203185).
SUSE-CU-2022:2248-1
Container Advisory ID | SUSE-CU-2022:2248-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.29 |
Container Release | 16.29 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3262-1
|
Released | Tue Sep 13 15:34:29 2022 |
Summary | Recommended update for gcc11 |
Type | recommended |
Severity | moderate |
References | 1199140 |
Description:
This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)
Advisory ID | SUSE-SU-2022:3271-1
|
Released | Wed Sep 14 06:45:39 2022 |
Summary | Security update for perl |
Type | security |
Severity | moderate |
References | 1047178,CVE-2017-6512 |
Description:
This update for perl fixes the following issues:
- CVE-2017-6512: Fixed File::Path rmtree/remove_tree race condition (bsc#1047178).
SUSE-CU-2022:2170-1
Container Advisory ID | SUSE-CU-2022:2170-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.24 |
Container Release | 16.24 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3157-1
|
Released | Wed Sep 7 14:32:50 2022 |
Summary | Recommended update for go1.18 |
Type | recommended |
Severity | moderate |
References | 1193742 |
Description:
This update for go1.18 fixes the following issues:
- Bootstrap using go1.16 on SUSE Linux Enterprise 15 and newer (bsc#1193742)
- Simplify conditional gcc_go_version 12 on Tumbleweed, 11 elsewhere
Advisory ID | SUSE-RU-2022:3215-1
|
Released | Thu Sep 8 15:58:27 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for rpm fixes the following issues:
- Support Ed25519 RPM signatures [jsc#SLE-24714]
SUSE-CU-2022:2072-1
Container Advisory ID | SUSE-CU-2022:2072-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.18 |
Container Release | 16.18 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3127-1
|
Released | Wed Sep 7 04:36:10 2022 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1198752,1200800 |
Description:
This update for libtirpc fixes the following issues:
- Exclude ipv6 addresses in client protocol version 2 code (bsc#1200800)
- Fix memory leak in params.r_addr assignement (bsc#1198752)
SUSE-CU-2022:2058-1
Container Advisory ID | SUSE-CU-2022:2058-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.17 |
Container Release | 16.17 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2947-1
|
Released | Wed Aug 31 09:16:21 2022 |
Summary | Security update for zlib |
Type | security |
Severity | important |
References | 1202175,CVE-2022-37434 |
Description:
This update for zlib fixes the following issues:
- CVE-2022-37434: Fixed heap-based buffer over-read or buffer overflow via large gzip header extra field (bsc#1202175).
Advisory ID | SUSE-RU-2022:2977-1
|
Released | Thu Sep 1 12:30:19 2022 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1197178,1198731 |
Description:
This update for util-linux fixes the following issues:
- agetty: Resolve tty name even if stdin is specified (bsc#1197178)
- libmount: When moving a mount point, update all sub mount entries in utab (bsc#1198731)
Advisory ID | SUSE-SU-2022:3003-1
|
Released | Fri Sep 2 15:01:44 2022 |
Summary | Security update for curl |
Type | security |
Severity | low |
References | 1202593,CVE-2022-35252 |
Description:
This update for curl fixes the following issues:
- CVE-2022-35252: Fixed a potential injection of control characters
into cookies, which could be exploited by sister sites to cause a
denial of service (bsc#1202593).
SUSE-CU-2022:1976-1
Container Advisory ID | SUSE-CU-2022:1976-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.11 |
Container Release | 16.11 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2929-1
|
Released | Mon Aug 29 11:21:47 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1202310 |
Description:
This update for timezone fixes the following issue:
- Reflect new Chile DST change (bsc#1202310)
SUSE-CU-2022:1931-1
Container Advisory ID | SUSE-CU-2022:1931-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-16.9 |
Container Release | 16.9 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2901-1
|
Released | Fri Aug 26 03:34:23 2022 |
Summary | Recommended update for elfutils |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for elfutils fixes the following issues:
- Fix runtime dependency for devel package
Advisory ID | SUSE-RU-2022:2904-1
|
Released | Fri Aug 26 05:28:34 2022 |
Summary | Recommended update for openldap2 |
Type | recommended |
Severity | moderate |
References | 1198341 |
Description:
This update for openldap2 fixes the following issues:
- Prevent memory reuse which may lead to instability (bsc#1198341)
Advisory ID | SUSE-RU-2022:2920-1
|
Released | Fri Aug 26 15:17:02 2022 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | important |
References | 1195059,1201795 |
Description:
This update for systemd fixes the following issues:
- Don't replace /etc/systemd/system/tmp.mount symlink with a dangling one pointing to /usr/lib/systemd/ (bsc#1201795)
- Drop or soften some of the deprecation warnings (jsc#PED-944)
- Ensure root user can login even if systemd-user-sessions.service is not activated yet (bsc#1195059)
- Avoid applying presets to any services shipped by the experimental sub-package, as they aren't enabled by default
- analyze: Fix offline check for syscal filter
- calendarspec: Fix timer skipping the next elapse
- core: Allow command argument to be longer
- hwdb: Add AV production controllers to hwdb and add uaccess
- hwdb: Allow console users access to rfkill
- hwdb: Allow end-users root-less access to TL866 EPROM readers
- hwdb: Permit unsetting power/persist for USB devices
- hwdb: Tag IR cameras as such
- hwdb: Fix parsing issue
- hwdb: Make usb match patterns uppercase
- hwdb: Update the hardware database
- journal-file: Stop using the event loop if it's already shutting down
- journal-remote: Disable `--trust` option when gnutls is disabled and check_permission() should not be called
- journald: Ensure resources are properly allocated for SIGTERM handling
- kernel-install: Ensure modules.builtin.alias.bin is removed when no longer needed
- macro: Account for negative values in DECIMAL_STR_WIDTH()
- manager: Disallow clone3() function call in seccomp filters
- missing-syscall: Define MOVE_MOUNT_T_EMPTY_PATH if missing
- pid1,cgroup-show: Prevent failure if cgroup.procs in some subcgroups is not readable
- resolve: Fix typo in dns_class_is_pseudo()
- sd-event: Improve handling of process events and termination of processes
- sd-ipv4acd: Fix ARP packet conflicts occurring when sender hardware is one of the host's interfaces
- stdio-bridge: Improve the meaning of the error message
- tmpfiles: Check for the correct directory
SUSE-CU-2022:1802-1
Container Advisory ID | SUSE-CU-2022:1802-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-15.1 , bci/golang:latest |
Container Release | 15.1 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2717-1
|
Released | Tue Aug 9 12:54:16 2022 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1198627,CVE-2022-29458 |
Description:
This update for ncurses fixes the following issues:
- CVE-2022-29458: Fixed segfaulting out-of-bounds read in convert_strings in tinfo/read_entry.c (bsc#1198627).
SUSE-CU-2022:1767-1
Container Advisory ID | SUSE-CU-2022:1767-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.30 , bci/golang:latest |
Container Release | 7.30 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2632-1
|
Released | Wed Aug 3 09:51:00 2022 |
Summary | Security update for permissions |
Type | security |
Severity | important |
References | 1198720,1200747,1201385 |
Description:
This update for permissions fixes the following issues:
- apptainer: fix starter-suid location (bsc#1198720)
- static permissions: remove deprecated bind / named chroot entries (bsc#1200747)
- postfix: add postlog setgid for maildrop binary (bsc#1201385)
Advisory ID | SUSE-SU-2022:2672-1
|
Released | Thu Aug 4 14:06:24 2022 |
Summary | Security update for go1.18 |
Type | security |
Severity | important |
References | 1193742,1201434,1201436,1201437,1201440,1201443,1201444,1201445,1201447,1201448,1202035,CVE-2022-1705,CVE-2022-1962,CVE-2022-28131,CVE-2022-30630,CVE-2022-30631,CVE-2022-30632,CVE-2022-30633,CVE-2022-30635,CVE-2022-32148,CVE-2022-32189 |
Description:
This update for go1.18 fixes the following issues:
Update to go version 1.18.5 (bsc#1193742):
- CVE-2022-32189: encoding/gob, math/big: decoding big.Float and big.Rat can panic (bsc#1202035).
- CVE-2022-1705: net/http: improper sanitization of Transfer-Encoding header (bsc#1201434)
- CVE-2022-32148: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (bsc#1201436)
- CVE-2022-30631: compress/gzip: stack exhaustion in Reader.Read (bsc#1201437).
- CVE-2022-30633: encoding/xml: stack exhaustion in Unmarshal (bsc#1201440).
- CVE-2022-28131: encoding/xml: stack exhaustion in Decoder.Skip (bsc#1201443).
- CVE-2022-30635: encoding/gob: stack exhaustion in Decoder.Decode (bsc#1201444).
- CVE-2022-30632: path/filepath: stack exhaustion in Glob (bsc#1201445).
- CVE-2022-30630: io/fs: stack exhaustion in Glob (bsc#1201447).
- CVE-2022-1962: go/parser: stack exhaustion in all Parse* functions (bsc#1201448).
SUSE-CU-2022:1726-1
Container Advisory ID | SUSE-CU-2022:1726-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.26 , bci/golang:latest |
Container Release | 7.26 |
The following patches have been included in this update:
SUSE-CU-2022:1682-1
Container Advisory ID | SUSE-CU-2022:1682-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.24 , bci/golang:latest |
Container Release | 7.24 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2566-1
|
Released | Wed Jul 27 15:04:49 2022 |
Summary | Security update for pcre2 |
Type | security |
Severity | important |
References | 1199235,CVE-2022-1587 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1587: Fixed out-of-bounds read due to bug in recursions (bsc#1199235).
SUSE-CU-2022:1663-1
Container Advisory ID | SUSE-CU-2022:1663-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.23 , bci/golang:latest |
Container Release | 7.23 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2018:1332-1
|
Released | Tue Jul 17 09:01:19 2018 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1073299,1093392 |
Description:
This update for timezone provides the following fixes:
- North Korea switches back from +0830 to +09 on 2018-05-05.
- Ireland's standard time is in the summer, with negative DST offset to standard time used
in Winter. (bsc#1073299)
- yast2-country is no longer setting TIMEZONE in /etc/sysconfig/clock and is calling systemd
timedatectl instead. Do not set /etc/localtime on timezone package updates to avoid
setting an incorrect timezone. (bsc#1093392)
Advisory ID | SUSE-RU-2018:2463-1
|
Released | Thu Oct 25 14:48:34 2018 |
Summary | Recommended update for timezone, timezone-java |
Type | recommended |
Severity | moderate |
References | 1104700,1112310 |
Description:
This update for timezone, timezone-java fixes the following issues:
The timezone database was updated to 2018f:
- Volgograd moves from +03 to +04 on 2018-10-28.
- Fiji ends DST 2019-01-13, not 2019-01-20.
- Most of Chile changes DST dates, effective 2019-04-06 (bsc#1104700)
- Corrections to past timestamps of DST transitions
- Use 'PST' and 'PDT' for Philippine time
- minor code changes to zic handling of the TZif format
- documentation updates
Other bugfixes:
- Fixed a zic problem with the 1948-1951 DST transition in Japan (bsc#1112310)
Advisory ID | SUSE-RU-2018:2550-1
|
Released | Wed Oct 31 16:16:56 2018 |
Summary | Recommended update for timezone, timezone-java |
Type | recommended |
Severity | moderate |
References | 1113554 |
Description:
This update provides the latest time zone definitions (2018g), including the following change:
- Morocco switched from +00/+01 to permanent +01 effective 2018-10-28 (bsc#1113554)
Advisory ID | SUSE-RU-2019:102-1
|
Released | Tue Jan 15 18:02:58 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1120402 |
Description:
This update for timezone fixes the following issues:
- Update 2018i:
São Tomé and Príncipe switches from +01 to +00 on 2019-01-01. (bsc#1120402)
- Update 2018h:
Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21
New zone Asia/Qostanay because Qostanay, Kazakhstan didn't move
Metlakatla, Alaska observes PST this winter only
Guess Morocco will continue to adjust clocks around Ramadan
Add predictions for Iran from 2038 through 2090
Advisory ID | SUSE-RU-2019:790-1
|
Released | Thu Mar 28 12:06:17 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1130557 |
Description:
This update for timezone fixes the following issues:
timezone was updated 2019a:
- Palestine 'springs forward' on 2019-03-30 instead of 2019-03-23
- Metlakatla 'fell back' to rejoin Alaska Time on 2019-01-20 at 02:00
- Israel observed DST in 1980 (08-02/09-13) and 1984 (05-05/08-25)
- zic now has an -r option to limit the time range of output data
Advisory ID | SUSE-RU-2019:1815-1
|
Released | Thu Jul 11 07:47:55 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1140016 |
Description:
This update for timezone fixes the following issues:
- Timezone update 2019b. (bsc#1140016):
- Brazil no longer observes DST.
- 'zic -b slim' outputs smaller TZif files.
- Palestine's 2019 spring-forward transition was on 03-29, not 03-30.
- Add info about the Crimea situation.
Advisory ID | SUSE-RU-2019:2762-1
|
Released | Thu Oct 24 07:08:44 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1150451 |
Description:
This update for timezone fixes the following issues:
- Fiji observes DST from 2019-11-10 to 2020-01-12.
- Norfolk Island starts observing Australian-style DST.
Advisory ID | SUSE-RU-2020:1303-1
|
Released | Mon May 18 09:40:36 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1169582 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020a. (bsc#1169582)
* Morocco springs forward on 2020-05-31, not 2020-05-24.
* Canada's Yukon advanced to -07 year-round on 2020-03-08.
* America/Nuuk renamed from America/Godthab.
* zic now supports expiration dates for leap second lists.
Advisory ID | SUSE-RU-2020:1542-1
|
Released | Thu Jun 4 13:24:37 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1172055 |
Description:
This update for timezone fixes the following issue:
- zdump --version reported 'unknown' (bsc#1172055)
Advisory ID | SUSE-RU-2020:3099-1
|
Released | Thu Oct 29 19:33:41 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020b (bsc#1177460)
* Revised predictions for Morocco's changes starting in 2023.
* Canada's Yukon changes to -07 on 2020-11-01, not 2020-03-08.
* Macquarie Island has stayed in sync with Tasmania since 2011.
* Casey, Antarctica is at +08 in winter and +11 in summer.
* zic no longer supports -y, nor the TYPE field of Rules.
Advisory ID | SUSE-RU-2020:3123-1
|
Released | Tue Nov 3 09:48:13 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1177460,1178346,1178350,1178353 |
Description:
This update for timezone fixes the following issues:
- Generate 'fat' timezone files (was default before 2020b). (bsc#1178346, bsc#1178350, bsc#1178353)
- Palestine ends DST earlier than predicted, on 2020-10-24. (bsc#1177460)
- Fiji starts DST later than usual, on 2020-12-20. (bsc#1177460)
Advisory ID | SUSE-RU-2021:179-1
|
Released | Wed Jan 20 13:38:51 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
Advisory ID | SUSE-RU-2021:301-1
|
Released | Thu Feb 4 08:46:27 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
Advisory ID | SUSE-RU-2021:2573-1
|
Released | Thu Jul 29 14:21:52 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1188127 |
Description:
This update for timezone fixes the following issue:
- From systemd v249: when enumerating time zones the timedatectl tool will now consult the 'tzdata.zi' file shipped by
the IANA time zone database package, in addition to 'zone1970.tab', as before. This makes sure time zone aliases are
now correctly supported. This update adds the 'tzdata.zi' file (bsc#1188127).
Advisory ID | SUSE-RU-2021:3883-1
|
Released | Thu Dec 2 11:47:07 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
Update timezone to 2021e (bsc#1177460)
- Palestine will fall back 10-29 (not 10-30) at 01:00
- Fiji suspends DST for the 2021/2022 season
- 'zic -r' marks unspecified timestamps with '-00'
- Fix a bug in 'zic -b fat' that caused old timestamps to be mishandled in 32-bit-only readers
- Refresh timezone info for china
Advisory ID | SUSE-RU-2022:1118-1
|
Released | Tue Apr 5 18:34:06 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2022a (bsc#1177460):
* Palestine will spring forward on 2022-03-27, not on 03-26
* `zdump -v` now outputs better failure indications
* Bug fixes for code that reads corrupted TZif data
Advisory ID | SUSE-SU-2022:2360-1
|
Released | Tue Jul 12 12:01:39 2022 |
Summary | Security update for pcre2 |
Type | security |
Severity | important |
References | 1199232,CVE-2022-1586 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
Advisory ID | SUSE-SU-2022:2361-1
|
Released | Tue Jul 12 12:05:01 2022 |
Summary | Security update for pcre |
Type | security |
Severity | important |
References | 1199232,CVE-2022-1586 |
Description:
This update for pcre fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
Advisory ID | SUSE-RU-2022:2406-1
|
Released | Fri Jul 15 11:49:01 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1197718,1199140,1200334,1200855 |
Description:
This update for glibc fixes the following issues:
- powerpc: Fix VSX register number on __strncpy_power9 (bsc#1200334)
- Disable warnings due to deprecated libselinux symbols used by nss and nscd (bsc#1197718)
- i386: Remove broken CAN_USE_REGISTER_ASM_EBP (bsc#1197718)
- rtld: Avoid using up static TLS surplus for optimizations (bsc#1200855, BZ #25051)
This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).
Advisory ID | SUSE-RU-2022:2469-1
|
Released | Thu Jul 21 04:38:31 2022 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | important |
References | 1137373,1181658,1194708,1195157,1197570,1198732,1200170,1201276 |
Description:
This update for systemd fixes the following issues:
- Make {/etc,/usr/lib}/systemd/network owned by both udev and systemd-network. The configuration files put in these
directories are read by both udevd and systemd-networkd (bsc#1201276)
- Allow control characters in environment variable values (bsc#1200170)
- Fix issues with multipath setup (bsc#1137373, bsc#1181658, bsc#1194708, bsc#1195157, bsc#1197570)
- Fix parsing error in s390 udev rules conversion script (bsc#1198732)
- core/device: device_coldplug(): don't set DEVICE_DEAD
- core/device: do not downgrade device state if it is already enumerated
- core/device: drop unnecessary condition
Advisory ID | SUSE-RU-2022:2493-1
|
Released | Thu Jul 21 14:35:08 2022 |
Summary | Recommended update for rpm-config-SUSE |
Type | recommended |
Severity | moderate |
References | 1193282 |
Description:
This update for rpm-config-SUSE fixes the following issues:
- Add SBAT values macros for other packages (bsc#1193282)
Advisory ID | SUSE-RU-2022:2494-1
|
Released | Thu Jul 21 15:16:42 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | important |
References | 1200855,1201560,1201640 |
Description:
This update for glibc fixes the following issues:
- Remove tunables from static tls surplus patch which caused crashes (bsc#1200855)
- i386: Disable check_consistency for GCC 5 and above (bsc#1201640, BZ #25788)
Advisory ID | SUSE-SU-2022:2550-1
|
Released | Tue Jul 26 14:00:21 2022 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1201431,CVE-2022-29187 |
Description:
This update for git fixes the following issues:
- CVE-2022-29187: Incomplete fix for CVE-2022-24765: potential command injection via git worktree (bsc#1201431).
Advisory ID | SUSE-SU-2022:2552-1
|
Released | Tue Jul 26 14:55:40 2022 |
Summary | Security update for libxml2 |
Type | security |
Severity | important |
References | 1196490,1199132,CVE-2022-23308,CVE-2022-29824 |
Description:
This update for libxml2 fixes the following issues:
Update to 2.9.14:
- CVE-2022-29824: Fixed integer overflow that could have led to an out-of-bounds write in buf.c (xmlBuf*) and tree.c (xmlBuffer*) (bsc#1199132).
Update to version 2.9.13:
- CVE-2022-23308: Fixed a use-after-free of ID and IDREF attributes. (bsc#1196490)
SUSE-CU-2022:1490-1
Container Advisory ID | SUSE-CU-2022:1490-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.11 , bci/golang:latest |
Container Release | 7.11 |
The following patches have been included in this update:
SUSE-CU-2022:1428-1
Container Advisory ID | SUSE-CU-2022:1428-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.9 , bci/golang:latest |
Container Release | 7.9 |
The following patches have been included in this update:
SUSE-CU-2022:1427-1
Container Advisory ID | SUSE-CU-2022:1427-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.9 , bci/golang:latest |
Container Release | 7.9 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2294-1
|
Released | Wed Jul 6 13:34:15 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315 |
Description:
This update for expat fixes the following issues:
- CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025).
- Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784).
- CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026).
- CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168).
- CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169).
- CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).
Advisory ID | SUSE-SU-2022:2305-1
|
Released | Wed Jul 6 13:38:42 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1200734,1200735,1200736,1200737,CVE-2022-32205,CVE-2022-32206,CVE-2022-32207,CVE-2022-32208 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32205: Set-Cookie denial of service (bsc#1200734)
- CVE-2022-32206: HTTP compression denial of service (bsc#1200735)
- CVE-2022-32207: Unpreserved file permissions (bsc#1200736)
- CVE-2022-32208: FTP-KRB bad message verification (bsc#1200737)
Advisory ID | SUSE-SU-2022:2308-1
|
Released | Wed Jul 6 14:15:13 2022 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1185637,1199166,1200550,1201099,CVE-2022-1292,CVE-2022-2068,CVE-2022-2097 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2022-1292: Fixed command injection in c_rehash (bsc#1199166).
- CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550)
- CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099).
SUSE-CU-2022:1381-1
Container Advisory ID | SUSE-CU-2022:1381-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.4 , bci/golang:latest |
Container Release | 7.4 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2157-1
|
Released | Wed Jun 22 17:11:26 2022 |
Summary | Recommended update for binutils |
Type | recommended |
Severity | moderate |
References | 1198458 |
Description:
This update for binutils fixes the following issues:
- For building the shim 15.6~rc1 and later versions aarch64 image, objcopy
needs to support efi-app-aarch64 target. (bsc#1198458)
SUSE-CU-2022:1353-1
Container Advisory ID | SUSE-CU-2022:1353-1 |
Container Tags | bci/golang:1.18 , bci/golang:1.18-7.3 , bci/golang:latest |
Container Release | 7.3 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2018:1999-1
|
Released | Tue Sep 25 08:20:35 2018 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1071321 |
Description:
This update for zlib provides the following fixes:
- Speedup zlib on power8. (fate#325307)
- Add safeguard against negative values in uInt. (bsc#1071321)
Advisory ID | SUSE-RU-2018:2370-1
|
Released | Mon Oct 22 14:02:01 2018 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1102310,1104531 |
Description:
This update for aaa_base provides the following fixes:
- Let bash.bashrc work even for (m)ksh. (bsc#1104531)
- Fix an error at login if java system directory is empty. (bsc#1102310)
Advisory ID | SUSE-RU-2018:2569-1
|
Released | Fri Nov 2 19:00:18 2018 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1110700 |
Description:
This update for pam fixes the following issues:
- Remove limits for nproc from /etc/security/limits.conf (bsc#1110700)
Advisory ID | SUSE-RU-2018:2607-1
|
Released | Wed Nov 7 15:42:48 2018 |
Summary | Optional update for gcc8 |
Type | recommended |
Severity | low |
References | 1084812,1084842,1087550,1094222,1102564 |
Description:
The GNU Compiler GCC 8 is being added to the Development Tools Module by this
update.
The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other
gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
Various optimizers have been improved in GCC 8, several of bugs fixed,
quite some new warnings added and the error pin-pointing and
fix-suggestions have been greatly improved.
The GNU Compiler page for GCC 8 contains a summary of all the changes that
have happened:
https://gcc.gnu.org/gcc-8/changes.html
Also changes needed or common pitfalls when porting software are described on:
https://gcc.gnu.org/gcc-8/porting_to.html
Advisory ID | SUSE-RU-2018:2798-1
|
Released | Wed Nov 28 07:48:35 2018 |
Summary | Recommended update for make |
Type | recommended |
Severity | moderate |
References | 1100504 |
Description:
This update for make fixes the following issues:
- Use a non-blocking read with pselect to avoid hangs (bsc#1100504)
Advisory ID | SUSE-SU-2018:2825-1
|
Released | Mon Dec 3 15:35:02 2018 |
Summary | Security update for pam |
Type | security |
Severity | important |
References | 1115640,CVE-2018-17953 |
Description:
This update for pam fixes the following issue:
Security issue fixed:
- CVE-2018-17953: Fixed IP address and subnet handling of pam_access.so that was not honoured correctly when a single host was specified (bsc#1115640).
Advisory ID | SUSE-SU-2018:2861-1
|
Released | Thu Dec 6 14:32:01 2018 |
Summary | Security update for ncurses |
Type | security |
Severity | important |
References | 1103320,1115929,CVE-2018-19211 |
Description:
This update for ncurses fixes the following issues:
Security issue fixed:
- CVE-2018-19211: Fixed denial of service issue that was triggered by a NULL pointer dereference at function _nc_parse_entry (bsc#1115929).
Non-security issue fixed:
- Remove scree.xterm from terminfo data base as with this screen uses fallback TERM=screen (bsc#1103320).
Advisory ID | SUSE-RU-2019:6-1
|
Released | Wed Jan 2 20:25:25 2019 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1099119,1099192 |
Description:
GCC 7 was updated to the GCC 7.4 release.
- Fix AVR configuration to not use __cxa_atexit or libstdc++ headers.
Point to /usr/avr/sys-root/include as system header include directory.
- Includes fix for build with ISL 0.20.
- Pulls fix for libcpp lexing bug on ppc64le manifesting during
build with gcc8. [bsc#1099119]
- Pulls fix for forcing compile-time tuning even when building
with -march=z13 on s390x. [bsc#1099192]
- Fixes support for 32bit ASAN with glibc 2.27+
Advisory ID | SUSE-RU-2019:44-1
|
Released | Tue Jan 8 13:07:32 2019 |
Summary | Recommended update for acl |
Type | recommended |
Severity | low |
References | 953659 |
Description:
This update for acl fixes the following issues:
- test: Add helper library to fake passwd/group files.
- quote: Escape literal backslashes. (bsc#953659)
Advisory ID | SUSE-SU-2019:247-1
|
Released | Wed Feb 6 07:18:45 2019 |
Summary | Security update for lua53 |
Type | security |
Severity | moderate |
References | 1123043,CVE-2019-6706 |
Description:
This update for lua53 fixes the following issues:
Security issue fixed:
- CVE-2019-6706: Fixed a use-after-free bug in the lua_upvaluejoin function of lapi.c (bsc#1123043)
Advisory ID | SUSE-SU-2019:571-1
|
Released | Thu Mar 7 18:13:46 2019 |
Summary | Security update for file |
Type | security |
Severity | moderate |
References | 1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907 |
Description:
This update for file fixes the following issues:
The following security vulnerabilities were addressed:
- CVE-2018-10360: Fixed an out-of-bounds read in the function do_core_note in
readelf.c, which allowed remote attackers to cause a denial of service
(application crash) via a crafted ELF file (bsc#1096974)
- CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c
(bsc#1126118)
- CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c
(bsc#1126119)
- CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c
(bsc#1126117)
Advisory ID | SUSE-RU-2019:732-1
|
Released | Mon Mar 25 14:10:04 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1088524,1118364,1128246 |
Description:
This update for aaa_base fixes the following issues:
- Restore old position of ssh/sudo source of profile (bsc#1118364).
- Update logic for JRE_HOME env variable (bsc#1128246)
Advisory ID | SUSE-RU-2019:905-1
|
Released | Mon Apr 8 16:48:02 2019 |
Summary | Recommended update for gcc |
Type | recommended |
Severity | moderate |
References | 1096008 |
Description:
This update for gcc fixes the following issues:
- Fix gcc-PIE spec to properly honor -no-pie at link time. (bsc#1096008)
Advisory ID | SUSE-RU-2019:1002-1
|
Released | Wed Apr 24 10:13:34 2019 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1110304,1129576 |
Description:
This update for zlib fixes the following issues:
- Fixes a segmentation fault error (bsc#1110304, bsc#1129576)
Advisory ID | SUSE-RU-2019:1105-1
|
Released | Tue Apr 30 12:10:58 2019 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1084842,1114592,1124644,1128794,1129389,1131264,SLE-6738 |
Description:
This update for gcc7 fixes the following issues:
Update to gcc-7-branch head (r270528).
- Disables switch jump-tables when retpolines are used. This restores
some lost performance for kernel builds with retpolines. (bsc#1131264,
jsc#SLE-6738)
- Fix ICE compiling tensorflow on aarch64. (bsc#1129389)
- Fix for aarch64 FMA steering pass use-after-free. (bsc#1128794)
- Fix for s390x FP load-and-test issue. (bsc#1124644)
- Improve build reproducability by disabling address-space randomization
during build.
- Adjust gnat manual entries in the info directory. (bsc#1114592)
- Includes fix to no longer try linking -lieee with -mieee-fp. (bsc#1084842)
Advisory ID | SUSE-RU-2019:1312-1
|
Released | Wed May 22 12:19:12 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1096191 |
Description:
This update for aaa_base fixes the following issue:
* Shell detection in /etc/profile and /etc/bash.bashrc was broken within AppArmor-confined containers
(bsc#1096191)
Advisory ID | SUSE-SU-2019:1368-1
|
Released | Tue May 28 13:15:38 2019 |
Summary | Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root |
Type | security |
Severity | important |
References | 1134524,CVE-2019-5021 |
Description:
This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:
- CVE-2019-5021: Include an invalidated root password by default, not an empty one (bsc#1134524)
Advisory ID | SUSE-RU-2019:1631-1
|
Released | Fri Jun 21 11:17:21 2019 |
Summary | Recommended update for xz |
Type | recommended |
Severity | low |
References | 1135709 |
Description:
This update for xz fixes the following issues:
Add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
Advisory ID | SUSE-RU-2019:2134-1
|
Released | Wed Aug 14 11:54:56 2019 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1136717,1137624,1141059,SLE-5807 |
Description:
This update for zlib fixes the following issues:
- Update the s390 patchset. (bsc#1137624)
- Tweak zlib-power8 to have type of crc32_vpmsum conform to usage. (bsc#1141059)
- Use FAT LTO objects in order to provide proper static library.
- Do not enable the previous patchset on s390 but just s390x. (bsc#1137624)
- Add patchset for s390 improvements. (jsc#SLE-5807, bsc#1136717)
Advisory ID | SUSE-RU-2019:2188-1
|
Released | Wed Aug 21 10:10:29 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1140647 |
Description:
This update for aaa_base fixes the following issues:
- Make systemd detection cgroup oblivious. (bsc#1140647)
Advisory ID | SUSE-RU-2019:2423-1
|
Released | Fri Sep 20 16:41:45 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1146866,SLE-9132 |
Description:
This update for aaa_base fixes the following issues:
Added sysctl.d/51-network.conf to tighten network security (bsc#1146866) (jira#SLE-9132)
Following settings have been tightened (and set to 0):
- net.ipv4.conf.all.accept_redirects
- net.ipv4.conf.default.accept_redirects
- net.ipv4.conf.default.accept_source_route
- net.ipv6.conf.all.accept_redirects
- net.ipv6.conf.default.accept_redirects
Advisory ID | SUSE-SU-2019:2702-1
|
Released | Wed Oct 16 18:41:30 2019 |
Summary | Security update for gcc7 |
Type | security |
Severity | moderate |
References | 1071995,1141897,1142649,1148517,1149145,CVE-2019-14250,CVE-2019-15847 |
Description:
This update for gcc7 to r275405 fixes the following issues:
Security issues fixed:
- CVE-2019-14250: Fixed an integer overflow in binutils (bsc#1142649).
- CVE-2019-15847: Fixed an optimization in the POWER9 backend of gcc that could reduce the entropy of the random number generator (bsc#1149145).
Non-security issue fixed:
- Move Live Patching technology stack from kGraft to upstream klp (bsc#1071995, fate#323487).
Advisory ID | SUSE-SU-2019:2779-1
|
Released | Thu Oct 24 16:57:42 2019 |
Summary | Security update for binutils |
Type | security |
Severity | moderate |
References | 1109412,1109413,1109414,1111996,1112534,1112535,1113247,1113252,1113255,1116827,1118644,1118830,1118831,1120640,1121034,1121035,1121056,1133131,1133232,1141913,1142772,1152590,1154016,1154025,CVE-2018-1000876,CVE-2018-17358,CVE-2018-17359,CVE-2018-17360,CVE-2018-17985,CVE-2018-18309,CVE-2018-18483,CVE-2018-18484,CVE-2018-18605,CVE-2018-18606,CVE-2018-18607,CVE-2018-19931,CVE-2018-19932,CVE-2018-20623,CVE-2018-20651,CVE-2018-20671,CVE-2018-6323,CVE-2018-6543,CVE-2018-6759,CVE-2018-6872,CVE-2018-7208,CVE-2018-7568,CVE-2018-7569,CVE-2018-7570,CVE-2018-7642,CVE-2018-7643,CVE-2018-8945,CVE-2019-1010180,ECO-368,SLE-6206 |
Description:
This update for binutils fixes the following issues:
binutils was updated to current 2.32 branch [jsc#ECO-368].
Includes following security fixes:
- CVE-2018-17358: Fixed invalid memory access in _bfd_stab_section_find_nearest_line in syms.c (bsc#1109412)
- CVE-2018-17359: Fixed invalid memory access exists in bfd_zalloc in opncls.c (bsc#1109413)
- CVE-2018-17360: Fixed heap-based buffer over-read in bfd_getl32 in libbfd.c (bsc#1109414)
- CVE-2018-17985: Fixed a stack consumption problem caused by the cplus_demangle_type (bsc#1116827)
- CVE-2018-18309: Fixed an invalid memory address dereference was discovered in read_reloc in reloc.c (bsc#1111996)
- CVE-2018-18483: Fixed get_count function provided by libiberty that allowed attackers to cause a denial of service or other unspecified impact (bsc#1112535)
- CVE-2018-18484: Fixed stack exhaustion in the C++ demangling functions provided by libiberty, caused by recursive stack frames (bsc#1112534)
- CVE-2018-18605: Fixed a heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup causing a denial of service (bsc#1113255)
- CVE-2018-18606: Fixed a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments, causing denial of service (bsc#1113252)
- CVE-2018-18607: Fixed a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section, causing denial of service (bsc#1113247)
- CVE-2018-19931: Fixed a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h (bsc#1118831)
- CVE-2018-19932: Fixed an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA (bsc#1118830)
- CVE-2018-20623: Fixed a use-after-free in the error function in elfcomm.c (bsc#1121035)
- CVE-2018-20651: Fixed a denial of service via a NULL pointer dereference in elf_link_add_object_symbols in elflink.c (bsc#1121034)
- CVE-2018-20671: Fixed an integer overflow that can trigger a heap-based buffer overflow in load_specific_debug_section in objdump.c (bsc#1121056)
- CVE-2018-1000876: Fixed integer overflow in bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc in objdump (bsc#1120640)
- CVE-2019-1010180: Fixed an out of bound memory access that could lead to crashes (bsc#1142772)
- enable xtensa architecture (Tensilica lc6 and related)
- Use -ffat-lto-objects in order to provide assembly for static libs
(bsc#1141913).
- Fixed some LTO build issues (bsc#1133131 bsc#1133232).
- riscv: Don't check ABI flags if no code section
- Fixed a segfault in ld when building some versions of pacemaker (bsc#1154025, bsc#1154016).
- Add avr, epiphany and rx to target_list so that the common binutils can handle all objects we can create with crosses (bsc#1152590).
Update to binutils 2.32:
- The binutils now support for the C-SKY processor series.
- The x86 assembler now supports a -mvexwig=[0|1] option to control
encoding of VEX.W-ignored (WIG) VEX instructions.
It also has a new -mx86-used-note=[yes|no] option to generate (or
not) x86 GNU property notes.
- The MIPS assembler now supports the Loongson EXTensions R2 (EXT2),
the Loongson EXTensions (EXT) instructions, the Loongson Content
Address Memory (CAM) ASE and the Loongson MultiMedia extensions
Instructions (MMI) ASE.
- The addr2line, c++filt, nm and objdump tools now have a default
limit on the maximum amount of recursion that is allowed whilst
demangling strings. This limit can be disabled if necessary.
- Objdump's --disassemble option can now take a parameter,
specifying the starting symbol for disassembly. Disassembly will
continue from this symbol up to the next symbol or the end of the
function.
- The BFD linker will now report property change in linker map file
when merging GNU properties.
- The BFD linker's -t option now doesn't report members within
archives, unless -t is given twice. This makes it more useful
when generating a list of files that should be packaged for a
linker bug report.
- The GOLD linker has improved warning messages for relocations that
refer to discarded sections.
- Improve relro support on s390 [fate#326356]
- Fix broken debug symbols (bsc#1118644)
- Handle ELF compressed header alignment correctly.
Advisory ID | SUSE-RU-2019:2870-1
|
Released | Thu Oct 31 08:09:14 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1051143,1138869,1151023 |
Description:
This update for aaa_base provides the following fixes:
- Check if variables can be set before modifying them to avoid warnings on login with a
restricted shell. (bsc#1138869)
- Add s390x compressed kernel support. (bsc#1151023)
- service: Check if there is a second argument before using it. (bsc#1051143)
Advisory ID | SUSE-SU-2019:2997-1
|
Released | Mon Nov 18 15:16:38 2019 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595 |
Description:
This update for ncurses fixes the following issues:
Security issues fixed:
- CVE-2019-17594: Fixed a heap-based buffer over-read in the _nc_find_entry function (bsc#1154036).
- CVE-2019-17595: Fixed a heap-based buffer over-read in the fmt_entry function (bsc#1154037).
Non-security issue fixed:
- Removed screen.xterm from terminfo database (bsc#1103320).
Advisory ID | SUSE-SU-2019:3061-1
|
Released | Mon Nov 25 17:34:22 2019 |
Summary | Security update for gcc9 |
Type | security |
Severity | moderate |
References | 1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536 |
Description:
This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html
The base system compiler libraries libgcc_s1, libstdc++6 and others are
now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 /
CXX=g++-9 during configuration for using it.
Security issues fixed:
- CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145)
- CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649)
Non-security issues fixed:
- Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254)
- Fixed miscompilation for vector shift on s390. (bsc#1141897)
Advisory ID | SUSE-SU-2019:3086-1
|
Released | Thu Nov 28 10:02:24 2019 |
Summary | Security update for libidn2 |
Type | security |
Severity | moderate |
References | 1154884,1154887,CVE-2019-12290,CVE-2019-18224 |
Description:
This update for libidn2 to version 2.2.0 fixes the following issues:
- CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884).
- CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887).
Advisory ID | SUSE-RU-2019:3166-1
|
Released | Wed Dec 4 11:24:42 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1007715,1084934,1157278 |
Description:
This update for aaa_base fixes the following issues:
- Use official key binding functions in inputrc that is replace up-history with previous-history, down-history with next-history and backward-delete-word with backward-kill-word. (bsc#1084934)
- Add some missed key escape sequences for urxvt-unicode terminal as well. (bsc#1007715)
- Clear broken ghost entry in patch which breaks 'readline'. (bsc#1157278)
Advisory ID | SUSE-RU-2020:10-1
|
Released | Thu Jan 2 12:35:06 2020 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1146475 |
Description:
This update for gcc7 fixes the following issues:
- Fix miscompilation with thread-safe localstatic initialization (gcc#85887).
- Fix debug info created for array definitions that complete an earlier declaration (bsc#1146475).
Advisory ID | SUSE-RU-2020:256-1
|
Released | Wed Jan 29 09:39:17 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1157794,1160970 |
Description:
This update for aaa_base fixes the following issues:
- Improves the way how the Java path is created to fix an issue with sapjvm. (bsc#1157794)
- Drop 'dev.cdrom.autoclose' = 0 from sysctl config. (bsc#1160970)
Advisory ID | SUSE-RU-2020:395-1
|
Released | Tue Feb 18 14:16:48 2020 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1160086 |
Description:
This update for gcc7 fixes the following issue:
- Fixed a miscompilation in zSeries code (bsc#1160086)
Advisory ID | SUSE-RU-2020:453-1
|
Released | Tue Feb 25 10:51:53 2020 |
Summary | Recommended update for binutils |
Type | recommended |
Severity | moderate |
References | 1160590 |
Description:
This update for binutils fixes the following issues:
- Recognize the official name of s390 arch13: 'z15'. (bsc#1160590, jsc#SLE-7903 aka jsc#SLE-7464)
Advisory ID | SUSE-RU-2020:480-1
|
Released | Tue Feb 25 17:38:22 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1160735 |
Description:
This update for aaa_base fixes the following issues:
- Change 'rp_filter' to increase the default priority to ethernet over the wifi. (bsc#1160735)
Advisory ID | SUSE-RU-2020:525-1
|
Released | Fri Feb 28 11:49:36 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1164562 |
Description:
This update for pam fixes the following issues:
- Add libdb as build-time dependency to enable pam_userdb module.
Enable pam_userdb.so (jsc#sle-7258, bsc#1164562)
Advisory ID | SUSE-RU-2020:633-1
|
Released | Tue Mar 10 16:23:08 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1139939,1151023 |
Description:
This update for aaa_base fixes the following issues:
- get_kernel_version: fix for current kernel on s390x (bsc#1151023, bsc#1139939)
- added '-h'/'--help' to the command old
- change feedback url from http://www.suse.de/feedback to https://github.com/openSUSE/aaa_base/issues
Advisory ID | SUSE-RU-2020:689-1
|
Released | Fri Mar 13 17:09:01 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1166510 |
Description:
This update for PAM fixes the following issue:
- The license of libdb linked against pam_userdb is not always wanted,
so we temporary disabled pam_userdb again. It will be published
in a different package at a later time. (bsc#1166510)
Advisory ID | SUSE-RU-2020:917-1
|
Released | Fri Apr 3 15:02:25 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1166510 |
Description:
This update for pam fixes the following issues:
- Moved pam_userdb into a separate package pam-extra. (bsc#1166510)
Advisory ID | SUSE-SU-2020:948-1
|
Released | Wed Apr 8 07:44:21 2020 |
Summary | Security update for gmp, gnutls, libnettle |
Type | security |
Severity | moderate |
References | 1152692,1155327,1166881,1168345,CVE-2020-11501 |
Description:
This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:
- CVE-2020-11501: Fixed zero random value in DTLS client hello (bsc#1168345)
FIPS related bugfixes:
- FIPS: Install checksums for binary integrity verification which are
required when running in FIPS mode (bsc#1152692, jsc#SLE-9518)
- FIPS: Fixed a cfb8 decryption issue, no longer truncate output IV if
input is shorter than block size. (bsc#1166881)
- FIPS: Added Diffie Hellman public key verification test. (bsc#1155327)
Advisory ID | SUSE-RU-2020:1226-1
|
Released | Fri May 8 10:51:05 2020 |
Summary | Recommended update for gcc9 |
Type | recommended |
Severity | moderate |
References | 1149995,1152590,1167898 |
Description:
This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.
- Includes a fix for Internal compiler error when building HepMC (bsc#1167898)
- Includes fix for binutils version parsing
- Add libstdc++6-pp provides and conflicts to avoid file conflicts
with same minor version of libstdc++6-pp from gcc10.
- Add gcc9 autodetect -g at lto link (bsc#1149995)
- Install go tool buildid for bootstrapping go
Advisory ID | SUSE-SU-2020:1294-1
|
Released | Mon May 18 07:38:36 2020 |
Summary | Security update for file |
Type | security |
Severity | moderate |
References | 1154661,1169512,CVE-2019-18218 |
Description:
This update for file fixes the following issues:
Security issues fixed:
- CVE-2019-18218: Fixed a heap-based buffer overflow in cdf_read_property_info() (bsc#1154661).
Non-security issue fixed:
- Fixed broken '--help' output (bsc#1169512).
Advisory ID | SUSE-RU-2020:1328-1
|
Released | Mon May 18 17:16:04 2020 |
Summary | Recommended update for grep |
Type | recommended |
Severity | moderate |
References | 1155271 |
Description:
This update for grep fixes the following issues:
- Update testsuite expectations, no functional changes (bsc#1155271)
Advisory ID | SUSE-RU-2020:1404-1
|
Released | Mon May 25 15:32:34 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1138793,1166260 |
Description:
This update for zlib fixes the following issues:
- Including the latest fixes from IBM (bsc#1166260)
IBM Z mainframes starting from version z15 provide DFLTCC instruction, which implements
deflate algorithm in hardware with estimated compression and decompression performance
orders of magnitude faster than the current zlib and ratio comparable with that of level 1.
- Add SUSE specific fix to solve bsc#1138793.
The fix will avoid to test if the app was linked with exactly same version of zlib
like the one that is present on the runtime.
Advisory ID | SUSE-RU-2020:1506-1
|
Released | Fri May 29 17:22:11 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1087982,1170527 |
Description:
This update for aaa_base fixes the following issues:
- Not all XTerm based emulators do have a terminfo entry. (bsc#1087982)
- Better support of Midnight Commander. (bsc#1170527)
Advisory ID | SUSE-RU-2020:1954-1
|
Released | Sat Jul 18 03:07:15 2020 |
Summary | Recommended update for cracklib |
Type | recommended |
Severity | moderate |
References | 1172396 |
Description:
This update for cracklib fixes the following issues:
- Fixed a buffer overflow when processing long words.
Advisory ID | SUSE-RU-2020:2083-1
|
Released | Thu Jul 30 10:27:59 2020 |
Summary | Recommended update for diffutils |
Type | recommended |
Severity | moderate |
References | 1156913 |
Description:
This update for diffutils fixes the following issue:
- Disable a sporadically failing test for ppc64 and ppc64le builds. (bsc#1156913)
Advisory ID | SUSE-RU-2020:2420-1
|
Released | Tue Sep 1 13:48:35 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1174551,1174736 |
Description:
This update for zlib provides the following fixes:
- Permit a deflateParams() parameter change as soon as possible. (bsc#1174736)
- Fix DFLTCC not flushing EOBS when creating raw streams. (bsc#1174551)
Advisory ID | SUSE-RU-2020:2651-1
|
Released | Wed Sep 16 14:42:55 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1175811,1175830,1175831 |
Description:
This update for zlib fixes the following issues:
- Fix compression level switching (bsc#1175811, bsc#1175830, bsc#1175831)
- Enable hardware compression on s390/s390x (jsc#SLE-13776)
Advisory ID | SUSE-RU-2020:2869-1
|
Released | Tue Oct 6 16:13:20 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1011548,1153943,1153946,1161239,1171762 |
Description:
This update for aaa_base fixes the following issues:
- DIR_COLORS (bug#1006973):
- add screen.xterm-256color
- add TERM rxvt-unicode-256color
- sort and merge TERM entries in etc/DIR_COLORS
- check for Packages.db and use this instead of Packages. (bsc#1171762)
- Rename path() to _path() to avoid using a general name.
- refresh_initrd call modprobe as /sbin/modprobe (bsc#1011548)
- etc/profile add some missing ;; in case esac statements
- profile and csh.login: on s390x set TERM to dumb on dumb terminal (bsc#1153946)
- backup-rpmdb: exit if zypper is running (bsc#1161239)
- Add color alias for ip command (jsc#sle-9880, jsc#SLE-7679, bsc#1153943)
Advisory ID | SUSE-SU-2020:2947-1
|
Released | Fri Oct 16 15:23:07 2020 |
Summary | Security update for gcc10, nvptx-tools |
Type | security |
Severity | moderate |
References | 1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844 |
Description:
This update for gcc10, nvptx-tools fixes the following issues:
This update provides the GCC10 compiler suite and runtime libraries.
The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by
the gcc10 variants.
The new compiler variants are available with '-10' suffix, you can specify them
via:
CC=gcc-10
CXX=g++-10
or similar commands.
For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
Changes in nvptx-tools:
Advisory ID | SUSE-RU-2020:2983-1
|
Released | Wed Oct 21 15:03:03 2020 |
Summary | Recommended update for file |
Type | recommended |
Severity | moderate |
References | 1176123 |
Description:
This update for file fixes the following issues:
- Fixes an issue when file displays broken 'ELF' interpreter. (bsc#1176123)
Advisory ID | SUSE-SU-2020:3060-1
|
Released | Wed Oct 28 08:09:21 2020 |
Summary | Security update for binutils |
Type | security |
Severity | moderate |
References | 1126826,1126829,1126831,1140126,1142649,1143609,1153768,1153770,1157755,1160254,1160590,1163333,1163744,CVE-2019-12972,CVE-2019-14250,CVE-2019-14444,CVE-2019-17450,CVE-2019-17451,CVE-2019-9074,CVE-2019-9075,CVE-2019-9077 |
Description:
This update for binutils fixes the following issues:
binutils was updated to version 2.35. (jsc#ECO-2373)
Update to binutils 2.35:
- The assembler can now produce DWARF-5 format line number tables.
- Readelf now has a 'lint' mode to enable extra checks of the files it is processing.
- Readelf will now display '[...]' when it has to truncate a symbol name.
The old behaviour - of displaying as many characters as possible, up to
the 80 column limit - can be restored by the use of the --silent-truncation
option.
- The linker can now produce a dependency file listing the inputs that it
has processed, much like the -M -MP option supported by the compiler.
- fix DT_NEEDED order with -flto [bsc#1163744]
Update to binutils 2.34:
- The disassembler (objdump --disassemble) now has an option to
generate ascii art thats show the arcs between that start and end
points of control flow instructions.
- The binutils tools now have support for debuginfod. Debuginfod is a
HTTP service for distributing ELF/DWARF debugging information as
well as source code. The tools can now connect to debuginfod
servers in order to download debug information about the files that
they are processing.
- The assembler and linker now support the generation of ELF format
files for the Z80 architecture.
- Add new subpackages for libctf and libctf-nobfd.
- Disable LTO due to bsc#1163333.
- Includes fixes for these CVEs:
bsc#1153768 aka CVE-2019-17451 aka PR25070
bsc#1153770 aka CVE-2019-17450 aka PR25078
- fix various build fails on aarch64 (PR25210, bsc#1157755).
Update to binutils 2.33.1:
- Adds support for the Arm Scalable Vector Extension version 2
(SVE2) instructions, the Arm Transactional Memory Extension (TME)
instructions and the Armv8.1-M Mainline and M-profile Vector
Extension (MVE) instructions.
- Adds support for the Arm Cortex-A76AE, Cortex-A77 and Cortex-M35P
processors and the AArch64 Cortex-A34, Cortex-A65, Cortex-A65AE,
Cortex-A76AE, and Cortex-A77 processors.
- Adds a .float16 directive for both Arm and AArch64 to allow
encoding of 16-bit floating point literals.
- For MIPS, Add -m[no-]fix-loongson3-llsc option to fix (or not)
Loongson3 LLSC Errata. Add a --enable-mips-fix-loongson3-llsc=[yes|no]
configure time option to set the default behavior. Set the default
if the configure option is not used to 'no'.
- The Cortex-A53 Erratum 843419 workaround now supports a choice of
which workaround to use. The option --fix-cortex-a53-843419 now
takes an optional argument --fix-cortex-a53-843419[=full|adr|adrp]
which can be used to force a particular workaround to be used.
See --help for AArch64 for more details.
- Add support for GNU_PROPERTY_AARCH64_FEATURE_1_BTI and
GNU_PROPERTY_AARCH64_FEATURE_1_PAC in ELF GNU program properties
in the AArch64 ELF linker.
- Add -z force-bti for AArch64 to enable GNU_PROPERTY_AARCH64_FEATURE_1_BTI
on output while warning about missing GNU_PROPERTY_AARCH64_FEATURE_1_BTI
on inputs and use PLTs protected with BTI.
- Add -z pac-plt for AArch64 to pick PAC enabled PLTs.
- Add --source-comment[=] option to objdump which if present,
provides a prefix to source code lines displayed in a disassembly.
- Add --set-section-alignment =
option to objcopy to allow the changing of section alignments.
- Add --verilog-data-width option to objcopy for verilog targets to
control width of data elements in verilog hex format.
- The separate debug info file options of readelf (--debug-dump=links
and --debug-dump=follow) and objdump (--dwarf=links and
--dwarf=follow-links) will now display and/or follow multiple
links if more than one are present in a file. (This usually
happens when gcc's -gsplit-dwarf option is used).
In addition objdump's --dwarf=follow-links now also affects its
other display options, so that for example, when combined with
--syms it will cause the symbol tables in any linked debug info
files to also be displayed. In addition when combined with
--disassemble the --dwarf= follow-links option will ensure that
any symbol tables in the linked files are read and used when
disassembling code in the main file.
- Add support for dumping types encoded in the Compact Type Format
to objdump and readelf.
- Includes fixes for these CVEs:
bsc#1126826 aka CVE-2019-9077 aka PR1126826
bsc#1126829 aka CVE-2019-9075 aka PR1126829
bsc#1126831 aka CVE-2019-9074 aka PR24235
bsc#1140126 aka CVE-2019-12972 aka PR23405
bsc#1143609 aka CVE-2019-14444 aka PR24829
bsc#1142649 aka CVE-2019-14250 aka PR90924
- Add xBPF target
- Fix various problems with DWARF 5 support in gas
- fix nm -B for objects compiled with -flto and -fcommon.
Advisory ID | SUSE-RU-2020:3462-1
|
Released | Fri Nov 20 13:14:35 2020 |
Summary | Recommended update for pam and sudo |
Type | recommended |
Severity | moderate |
References | 1174593,1177858,1178727 |
Description:
This update for pam and sudo fixes the following issue:
pam:
- pam_xauth: do not *free* a string which has been successfully passed to *putenv*. (bsc#1177858)
- Initialize the local variable *daysleft* to avoid a misleading warning for password expire days. (bsc#1178727)
- Run /usr/bin/xauth using the old user's and group's identifiers. (bsc#1174593)
sudo:
- Fix a problem with pam_xauth which checks effective and real uids to get the real identity of the user. (bsc#1174593)
Advisory ID | SUSE-RU-2020:3620-1
|
Released | Thu Dec 3 17:03:55 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for pam fixes the following issues:
- Check if the password is part of the username. (jsc#SLE-16719, jsc#SLE-16720)
- Check whether the password contains a substring of of the user's name of at least `` characters length in
some form. This is enabled by the new parameter `usersubstr=`
Advisory ID | SUSE-RU-2020:3640-1
|
Released | Mon Dec 7 13:24:41 2020 |
Summary | Recommended update for binutils |
Type | recommended |
Severity | important |
References | 1179036,1179341 |
Description:
This update for binutils fixes the following issues:
Update binutils 2.35 branch to commit 1c5243df:
- Fixes PR26520, aka [bsc#1179036], a problem in addr2line with
certain DWARF variable descriptions.
- Also fixes PR26711, PR26656, PR26655, PR26929, PR26808, PR25878,
PR26740, PR26778, PR26763, PR26685, PR26699, PR26902, PR26869,
PR26711
- The above includes fixes for dwo files produced by modern dwp,
fixing several problems in the DWARF reader.
Update binutils to 2.35.1 and rebased branch diff:
- This is a point release over the previous 2.35 version, containing bug
fixes, and as an exception to the usual rule, one new feature. The
new feature is the support for a new directive in the assembler:
'.nop'. This directive creates a single no-op instruction in whatever
encoding is correct for the target architecture. Unlike the .space or
.fill this is a real instruction, and it does affect the generation of
DWARF line number tables, should they be enabled. This fixes an
incompatibility introduced in the latest update that broke the install
scripts of the Oracle server. [bsc#1179341]
Advisory ID | SUSE-RU-2020:3703-1
|
Released | Mon Dec 7 20:17:32 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1179431 |
Description:
This update for aaa_base fixes the following issue:
- Avoid semicolon within (t)csh login script on S/390. (bsc#1179431)
Advisory ID | SUSE-SU-2020:3749-1
|
Released | Thu Dec 10 14:39:28 2020 |
Summary | Security update for gcc7 |
Type | security |
Severity | moderate |
References | 1150164,1161913,1167939,1172798,1178577,1178614,1178624,1178675,CVE-2020-13844 |
Description:
This update for gcc7 fixes the following issues:
- CVE-2020-13844: Added mitigation for aarch64 Straight Line Speculation issue (bsc#1172798)
- Enable fortran for the nvptx offload compiler.
- Update README.First-for.SuSE.packagers
- avoid assembler errors with AVX512 gather and scatter instructions when using -masm=intel.
- Backport the aarch64 -moutline-atomics feature and accumulated fixes but not its
default enabling. [jsc#SLE-12209, bsc#1167939]
- Fixed 32bit libgnat.so link. [bsc#1178675]
- Fixed memcpy miscompilation on aarch64. [bsc#1178624, bsc#1178577]
- Fixed debug line info for try/catch. [bsc#1178614]
- Remove -mbranch-protection=standard (aarch64 flag) when gcc7 is used to build gcc7 (ie when ada is enabled)
- Fixed corruption of pass private ->aux via DF. [gcc#94148]
- Fixed debug information issue with inlined functions and passed by reference arguments. [gcc#93888]
- Fixed binutils release date detection issue.
- Fixed register allocation issue with exception handling code on s390x. [bsc#1161913]
- Fixed miscompilation of some atomic code on aarch64. [bsc#1150164]
Advisory ID | SUSE-RU-2020:3942-1
|
Released | Tue Dec 29 12:22:01 2020 |
Summary | Recommended update for libidn2 |
Type | recommended |
Severity | moderate |
References | 1180138 |
Description:
This update for libidn2 fixes the following issues:
- The library is actually dual licensed, GPL-2.0-or-later or LGPL-3.0-or-later,
adjusted the RPM license tags (bsc#1180138)
Advisory ID | SUSE-RU-2021:79-1
|
Released | Tue Jan 12 10:49:34 2021 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1167939 |
Description:
This update for gcc7 fixes the following issues:
- Amend the gcc7 aarch64 atomics for glibc namespace violation with getauxval. [bsc#1167939]
Advisory ID | SUSE-RU-2021:220-1
|
Released | Tue Jan 26 14:00:51 2021 |
Summary | Recommended update for keyutils |
Type | recommended |
Severity | moderate |
References | 1180603 |
Description:
This update for keyutils fixes the following issues:
- Adjust the library license to be LPGL-2.1+ only (the tools are GPL2+, the library is just LGPL-2.1+) (bsc#1180603)
Advisory ID | SUSE-RU-2021:293-1
|
Released | Wed Feb 3 12:52:34 2021 |
Summary | Recommended update for gmp |
Type | recommended |
Severity | moderate |
References | 1180603 |
Description:
This update for gmp fixes the following issues:
- correct license statements of packages (library itself is no GPL-3.0) (bsc#1180603)
Advisory ID | SUSE-OU-2021:339-1
|
Released | Mon Feb 8 13:16:07 2021 |
Summary | Optional update for pam |
Type | optional |
Severity | low |
References | |
Description:
This update for pam fixes the following issues:
- Added rpm macros for this package, so that other packages can make use of it
This patch is optional to be installed - it doesn't fix any bugs.
Advisory ID | SUSE-RU-2021:596-1
|
Released | Thu Feb 25 10:26:30 2021 |
Summary | Recommended update for gcc7 |
Type | recommended |
Severity | moderate |
References | 1181618 |
Description:
This update for gcc7 fixes the following issues:
- Fixed webkit2gtk3 build (bsc#1181618)
- Change GCC exception licenses to SPDX format
- Remove include-fixed/pthread.h
Advisory ID | SUSE-RU-2021:786-1
|
Released | Mon Mar 15 11:19:23 2021 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1176201 |
Description:
This update for zlib fixes the following issues:
- Fixed hw compression on z15 (bsc#1176201)
Advisory ID | SUSE-RU-2021:924-1
|
Released | Tue Mar 23 10:00:49 2021 |
Summary | Recommended update for filesystem |
Type | recommended |
Severity | moderate |
References | 1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094 |
Description:
This update for filesystem the following issues:
- Remove duplicate line due to merge error
- Add fix for 'mesa' creating cache with perm 0700. (bsc#1181011)
- Fixed an issue causing failure during installation/upgrade a failure. (rh#1548403) (bsc#1146705)
- Allows to override config to add cleanup options of '/var/tmp'. (bsc#1078466)
- Create config to cleanup '/tmp' regular required with 'tmpfs'. (bsc#1175519)
This update for systemd fixes the following issues:
- Fix for a possible memory leak. (bsc#1180020)
- Fix for a case when to a bind mounted directory results inactive mount units. (#7811) (bsc#1180596)
- Fixed an issue when starting a container conflicts with another one. (bsc#1178775)
- Drop most of the tmpfiles that deal with generic paths and avoid warnings. (bsc#1078466, bsc#1181831)
- Don't use shell redirections when calling a rpm macro. (bsc#1183094)
- 'systemd' requires 'aaa_base' >= 13.2. (bsc#1180083)
Advisory ID | SUSE-SU-2021:930-1
|
Released | Wed Mar 24 12:09:23 2021 |
Summary | Security update for nghttp2 |
Type | security |
Severity | important |
References | 1172442,1181358,CVE-2020-11080 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358)
Advisory ID | SUSE-RU-2021:1291-1
|
Released | Wed Apr 21 14:04:06 2021 |
Summary | Recommended update for mpfr |
Type | recommended |
Severity | moderate |
References | 1141190 |
Description:
This update for mpfr fixes the following issues:
- Fixed an issue when building for ppc64le (bsc#1141190)
Technical library fixes:
- A subtraction of two numbers of the same sign or addition of two numbers of different signs
can be rounded incorrectly (and the ternary value can be incorrect) when one of the two
inputs is reused as the output (destination) and all these MPFR numbers have exactly
GMP_NUMB_BITS bits of precision (typically, 32 bits on 32-bit machines, 64 bits on 64-bit
machines).
- The mpfr_fma and mpfr_fms functions can behave incorrectly in case of internal overflow or
underflow.
- The result of the mpfr_sqr function can be rounded incorrectly in a rare case near underflow
when the destination has exactly GMP_NUMB_BITS bits of precision (typically, 32 bits on
32-bit machines, 64 bits on 64-bit machines) and the input has at most GMP_NUMB_BITS bits
of precision.
- The behavior and documentation of the mpfr_get_str function are inconsistent concerning the
minimum precision (this is related to the change of the minimum precision from 2 to 1 in
MPFR 4.0.0). The get_str patch fixes this issue in the following way: the value 1 can now be
provided for n (4th argument of mpfr_get_str); if n = 0, then the number of significant digits
in the output string can now be 1, as already implied by the documentation (but the code was
increasing it to 2).
- The mpfr_cmp_q function can behave incorrectly when the rational (mpq_t) number has a null
denominator.
- The mpfr_inp_str and mpfr_out_str functions might behave incorrectly when the stream is a
null pointer: the stream is replaced by stdin and stdout, respectively. This behavior is
useless, not documented (thus incorrect in case a null pointer would have a special meaning),
and not consistent with other input/output functions.
Advisory ID | SUSE-RU-2021:1643-1
|
Released | Wed May 19 13:51:48 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | important |
References | 1181443,1184358,1185562 |
Description:
This update for pam fixes the following issues:
- Fixed a bug, where the 'unlimited'/'-1' value was not interpreted correctly (bsc#1181443)
- Fixed a bug, where pam_access interpreted the keyword 'LOCAL' incorrectly, leading to
an attempt to resolve it as a hostname (bsc#1184358)
- In the 32-bit compatibility package for 64-bit architectures, require 'systemd-32bit' to be also installed as it contains pam_systemd.so for 32 bit applications. (bsc#1185562)
Advisory ID | SUSE-RU-2021:1861-1
|
Released | Fri Jun 4 09:59:40 2021 |
Summary | Recommended update for gcc10 |
Type | recommended |
Severity | moderate |
References | 1029961,1106014,1178577,1178624,1178675,1182016 |
Description:
This update for gcc10 fixes the following issues:
- Disable nvptx offloading for aarch64 again since it doesn't work
- Fixed a build failure issue. (bsc#1182016)
- Fix for memory miscompilation on 'aarch64'. (bsc#1178624, bsc#1178577)
- Fix 32bit 'libgnat.so' link. (bsc#1178675)
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it stays /%lib. (bsc#1029961)
- Build complete set of multilibs for arm-none target. (bsc#1106014)
Advisory ID | SUSE-RU-2021:1926-1
|
Released | Thu Jun 10 08:38:14 2021 |
Summary | Recommended update for gcc |
Type | recommended |
Severity | moderate |
References | 1096677 |
Description:
This update for gcc fixes the following issues:
- Added gccgo symlink and go and gofmt as alternatives to support parallel installation
of golang (bsc#1096677)
Advisory ID | SUSE-RU-2021:1937-1
|
Released | Thu Jun 10 10:47:09 2021 |
Summary | Recommended update for nghttp2 |
Type | recommended |
Severity | moderate |
References | 1186642 |
Description:
This update for nghttp2 fixes the following issue:
- The (lib)nghttp2 packages had a lower release number in SUSE Linux Enterprise 15 sp2 and sp3 than in 15 sp1, which could lead
to migration issues. (bsc#1186642)
Advisory ID | SUSE-RU-2021:2146-1
|
Released | Wed Jun 23 17:55:14 2021 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1115550,1174162 |
Description:
This update for openssh fixes the following issues:
- Fixed a race condition leading to a sshd termination of multichannel sessions with non-root users (bsc#1115550, bsc#1174162).
Advisory ID | SUSE-RU-2021:2173-1
|
Released | Mon Jun 28 14:59:45 2021 |
Summary | Recommended update for automake |
Type | recommended |
Severity | moderate |
References | 1040589,1047218,1182604,1185540,1186049 |
Description:
This update for automake fixes the following issues:
- Implement generated autoconf makefiles reproducible (bsc#1182604)
- Add fix to avoid date variations in docs. (bsc#1047218, jsc#SLE-17848)
- Avoid bashisms in test-driver script. (bsc#1185540)
This update for pcre fixes the following issues:
- Do not run profiling 'check' in parallel to make package build reproducible. (bsc#1040589)
This update for brp-check-suse fixes the following issues:
- Add fixes to support reproducible builds. (bsc#1186049)
Advisory ID | SUSE-SU-2021:2196-1
|
Released | Tue Jun 29 09:41:39 2021 |
Summary | Security update for lua53 |
Type | security |
Severity | moderate |
References | 1175448,1175449,CVE-2020-24370,CVE-2020-24371 |
Description:
This update for lua53 fixes the following issues:
Update to version 5.3.6:
- CVE-2020-24371: lgc.c mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage (bsc#1175449)
- CVE-2020-24370: ldebug.c allows a negation overflow and segmentation fault in getlocal and setlocal (bsc#1175448)
- Long brackets with a huge number of '=' overflow some internal buffer arithmetic.
Advisory ID | SUSE-SU-2021:2555-1
|
Released | Thu Jul 29 08:29:55 2021 |
Summary | Security update for git |
Type | security |
Severity | moderate |
References | 1168930,1183026,1183580,CVE-2021-21300 |
Description:
This update for git fixes the following issues:
Update from version 2.26.2 to version 2.31.1 (jsc#SLE-18152)
Security fixes:
- CVE-2021-21300: On case-insensitive file systems with support for symbolic links, if Git is configured globally
to apply delay-capable clean/smudge filters (such as Git LFS), Git could run remote code during a clone. (bsc#1183026)
Non security changes:
- Add `sysusers` file to create `git-daemon` user.
- Remove `perl-base` and `openssh-server` dependency on `git-core`and provide a `perl-Git` package. (jsc#SLE-17838)
- `fsmonitor` bug fixes
- Fix `git bisect` to take an annotated tag as a good/bad endpoint
- Fix a corner case in `git mv` on case insensitive systems
- Require only `openssh-clients` where possible (like Tumbleweed or SUSE Linux Enterprise >= 15 SP3). (bsc#1183580)
- Drop `rsync` requirement, not necessary anymore.
- Use of `pack-redundant` command is discouraged and will trigger a warning. The replacement is `repack -d`.
- The `--format=%(trailers)` mechanism gets enhanced to make it easier to design output for machine consumption.
- No longer give message to choose between rebase or merge upon pull if the history `fast-forwards`.
- The configuration variable `core.abbrev` can be set to `no` to force no abbreviation regardless of the hash algorithm
- `git rev-parse` can be explicitly told to give output as absolute or relative path with the
`--path-format=(absolute|relative)` option.
- Bash completion update to make it easier for end-users to add completion for their custom `git` subcommands.
- `git maintenance` learned to drive scheduled maintenance on platforms whose native scheduling methods are not 'cron'.
- After expiring a reflog and making a single commit, the reflog for the branch would record a single entry that
knows both `@{0}` and `@{1}`, but we failed to answer 'what commit were we on?', i.e. `@{1}`
- `git bundle` learns `--stdin` option to read its refs from the standard input.
Also, it now does not lose refs when they point at the same object.
- `git log` learned a new `--diff-merges=` option.
- `git ls-files` can and does show multiple entries when the index is unmerged, which is a source for confusion
unless `-s/-u` option is in use. A new option `--deduplicate` has been introduced.
- `git worktree list` now annotates worktrees as prunable, shows locked and prunable attributes
in `--porcelain mode`, and gained a `--verbose` option.
- `git clone` tries to locally check out the branch pointed at by HEAD of the remote repository after it
is done, but the protocol did not convey the information necessary to do so when copying an empty repository.
The protocol v2 learned how to do so.
- There are other ways than `..` for a single token to denote a `commit range', namely `^!`
and `^-`, but `git range-diff` did not understand them.
- The `git range-diff` command learned `--(left|right)-only` option to show only one side of the compared range.
- `git mergetool` feeds three versions (base, local and remote) of a conflicted path unmodified.
The command learned to optionally prepare these files with unconflicted parts already resolved.
- The `.mailmap` is documented to be read only from the root level of a working tree, but a stray file
in a bare repository also was read by accident, which has been corrected.
- `git maintenance` tool learned a new `pack-refs` maintenance task.
- Improved error message given when a configuration variable that is expected to have a boolean value.
- Signed commits and tags now allow verification of objects, whose two object names
(one in SHA-1, the other in SHA-256) are both signed.
- `git rev-list` command learned `--disk-usage` option.
- `git diff`, `git log` `--{skip,rotate}-to=` allows the user to discard diff output for early
paths or move them to the end of the output.
- `git difftool` learned `--skip-to=` option to restart an interrupted session from an arbitrary path.
- `git grep` has been tweaked to be limited to the sparse checkout paths.
- `git rebase --[no-]fork-point` gained a configuration variable `rebase.forkPoint` so that users do not have
to keep specifying a non-default setting.
- `git stash` did not work well in a sparsely checked out working tree.
- Newline characters in the host and path part of `git://` URL are now forbidden.
- `Userdiff` updates for PHP, Rust, CSS
- Avoid administrator error leading to data loss with `git push --force-with-lease[=
[]` by
introducing `--force-if-includes`
]
- only pull `asciidoctor` for the default ruby version
- The `--committer-date-is-author-date` option of `rebase` and `am` subcommands lost the e-mail address by
mistake in 2.29
- The transport protocol v2 has become the default again
- `git worktree` gained a `repair` subcommand, `git init --separate-git-dir` no longer corrupts administrative data
related to linked worktrees
- `git maintenance` introduced for repository maintenance tasks
- `fetch.writeCommitGraph` is deemed to be still a bit too risky and is no longer part of the
`feature.experimental` set.
- The commands in the `diff` family honors the `diff.relative` configuration variable.
- `git diff-files` has been taught to say paths that are marked as `intent-to-add` are new files,
not modified from an empty blob.
- `git gui` now allows opening work trees from the start-up dialog.
- `git bugreport` reports what shell is in use.
- Some repositories have commits that record wrong committer timezone; `git fast-import` has an option to pass
these timestamps intact to allow recreating existing repositories as-is.
- `git describe` will always use the `long` version when giving its output based misplaced tags
- `git pull` issues a warning message until the `pull.rebase` configuration variable is explicitly given
Advisory ID | SUSE-RU-2021:2606-1
|
Released | Wed Aug 4 13:16:09 2021 |
Summary | Recommended update for libcbor |
Type | recommended |
Severity | moderate |
References | 1102408 |
Description:
This update for libcbor fixes the following issues:
- Implement a fix to avoid building shared library twice. (bsc#1102408)
Advisory ID | SUSE-SU-2021:2682-1
|
Released | Thu Aug 12 20:06:19 2021 |
Summary | Security update for rpm |
Type | security |
Severity | important |
References | 1179416,1181805,1183543,1183545,CVE-2021-20266,CVE-2021-20271,CVE-2021-3421 |
Description:
This update for rpm fixes the following issues:
- Changed default package verification level to 'none' to be compatible to rpm-4.14.1
- Made illegal obsoletes a warning
- Fixed a potential access of freed mem in ndb's glue code (bsc#1179416)
- Added support for enforcing signature policy and payload verification step to
transactions (jsc#SLE-17817)
- Added :humansi and :hmaniec query formatters for human readable output
- Added query selectors for whatobsoletes and whatconflicts
- Added support for sorting caret higher than base version
- rpm does no longer require the signature header to be in a contiguous
region when signing (bsc#1181805)
Security fixes:
- CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an
attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM
repository, to cause RPM database corruption. The highest threat from this vulnerability is to
data integrity (bsc#1183543)
- CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file.
This flaw allows an attacker who can convince a victim to install a seemingly verifiable package,
whose signature header was modified, to cause RPM database corruption and execute code. The highest
threat from this vulnerability is to data integrity, confidentiality, and system availability (bsc#1183545)
- CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker
who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability
is to system availability.
Advisory ID | SUSE-RU-2021:2993-1
|
Released | Thu Sep 9 14:31:33 2021 |
Summary | Recommended update for gcc |
Type | recommended |
Severity | moderate |
References | 1185348 |
Description:
This update for gcc fixes the following issues:
- With gcc-PIE add -pie even when -fPIC is specified but we are
not linking a shared library. [bsc#1185348]
- Fix postun of gcc-go alternative.
Advisory ID | SUSE-RU-2021:3182-1
|
Released | Tue Sep 21 17:04:26 2021 |
Summary | Recommended update for file |
Type | recommended |
Severity | moderate |
References | 1189996 |
Description:
This update for file fixes the following issues:
- Fixes exception thrown by memory allocation problem (bsc#1189996)
Advisory ID | SUSE-SU-2021:3291-1
|
Released | Wed Oct 6 16:45:36 2021 |
Summary | Security update for glibc |
Type | security |
Severity | moderate |
References | 1186489,1187911,CVE-2021-33574,CVE-2021-35942 |
Description:
This update for glibc fixes the following issues:
- CVE-2021-33574: Fixed use __pthread_attr_copy in mq_notify (bsc#1186489).
- CVE-2021-35942: Fixed wordexp handle overflow in positional parameter number (bsc#1187911).
Advisory ID | SUSE-SU-2021:3445-1
|
Released | Fri Oct 15 09:03:39 2021 |
Summary | Security update for rpm |
Type | security |
Severity | important |
References | 1183659,1185299,1187670,1188548 |
Description:
This update for rpm fixes the following issues:
Security issues fixed:
- PGP hardening changes (bsc#1185299)
Maintaince issues fixed:
- Fixed zstd detection (bsc#1187670)
- Added ndb rofs support (bsc#1188548)
- Fixed deadlock when multiple rpm processes try tp acquire the database lock (bsc#1183659)
Advisory ID | SUSE-SU-2021:3490-1
|
Released | Wed Oct 20 16:31:55 2021 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1190793,CVE-2021-39537 |
Description:
This update for ncurses fixes the following issues:
- CVE-2021-39537: Fixed an heap-based buffer overflow in _nc_captoinfo. (bsc#1190793)
Advisory ID | SUSE-RU-2021:3494-1
|
Released | Wed Oct 20 16:48:46 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1190052 |
Description:
This update for pam fixes the following issues:
- Added pam_faillock to the set of available PAM modules. (jsc#SLE-20638)
- Added new file macros.pam on request of systemd. (bsc#1190052)
Advisory ID | SUSE-RU-2021:3510-1
|
Released | Tue Oct 26 11:22:15 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | important |
References | 1191987 |
Description:
This update for pam fixes the following issues:
- Fixed a bad directive file which resulted in
the 'securetty' file to be installed as 'macros.pam'.
(bsc#1191987)
Advisory ID | SUSE-SU-2021:3529-1
|
Released | Wed Oct 27 09:23:32 2021 |
Summary | Security update for pcre |
Type | security |
Severity | moderate |
References | 1172973,1172974,CVE-2019-20838,CVE-2020-14155 |
Description:
This update for pcre fixes the following issues:
Update pcre to version 8.45:
- CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974).
- CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973)
Advisory ID | SUSE-SU-2021:3616-1
|
Released | Thu Nov 4 12:29:16 2021 |
Summary | Security update for binutils |
Type | security |
Severity | moderate |
References | 1179898,1179899,1179900,1179901,1179902,1179903,1180451,1180454,1180461,1181452,1182252,1183511,1184620,1184794,CVE-2020-16590,CVE-2020-16591,CVE-2020-16592,CVE-2020-16593,CVE-2020-16598,CVE-2020-16599,CVE-2020-35448,CVE-2020-35493,CVE-2020-35496,CVE-2020-35507,CVE-2021-20197,CVE-2021-20284,CVE-2021-3487 |
Description:
This update for binutils fixes the following issues:
Update to binutils 2.37:
- The GNU Binutils sources now requires a C99 compiler and library to
build.
- Support for Realm Management Extension (RME) for AArch64 has been
added.
- A new linker option '-z report-relative-reloc' for x86 ELF targets
has been added to report dynamic relative relocations.
- A new linker option '-z start-stop-gc' has been added to disable
special treatment of __start_*/__stop_* references when
--gc-sections.
- A new linker options '-Bno-symbolic' has been added which will
cancel the '-Bsymbolic' and '-Bsymbolic-functions' options.
- The readelf tool has a new command line option which can be used to
specify how the numeric values of symbols are reported.
--sym-base=0|8|10|16 tells readelf to display the values in base 8,
base 10 or base 16. A sym base of 0 represents the default action
of displaying values under 10000 in base 10 and values above that in
base 16.
- A new format has been added to the nm program. Specifying
'--format=just-symbols' (or just using -j) will tell the program to
only display symbol names and nothing else.
- A new command line option '--keep-section-symbols' has been added to
objcopy and strip. This stops the removal of unused section symbols
when the file is copied. Removing these symbols saves space, but
sometimes they are needed by other tools.
- The '--weaken', '--weaken-symbol' and '--weaken-symbols' options
supported by objcopy now make undefined symbols weak on targets that
support weak symbols.
- Readelf and objdump can now display and use the contents of .debug_sup
sections.
- Readelf and objdump will now follow links to separate debug info
files by default. This behaviour can be stopped via the use of the
new '-wN' or '--debug-dump=no-follow-links' options for readelf and
the '-WN' or '--dwarf=no-follow-links' options for objdump. Also
the old behaviour can be restored by the use of the
'--enable-follow-debug-links=no' configure time option.
The semantics of the =follow-links option have also been slightly
changed. When enabled, the option allows for the loading of symbol
tables and string tables from the separate files which can be used
to enhance the information displayed when dumping other sections,
but it does not automatically imply that information from the
separate files should be displayed.
If other debug section display options are also enabled (eg
'--debug-dump=info') then the contents of matching sections in both
the main file and the separate debuginfo file *will* be displayed.
This is because in most cases the debug section will only be present
in one of the files.
If however non-debug section display options are enabled (eg
'--sections') then the contents of matching parts of the separate
debuginfo file will *not* be displayed. This is because in most
cases the user probably only wanted to load the symbol information
from the separate debuginfo file. In order to change this behaviour
a new command line option --process-links can be used. This will
allow di0pslay options to applied to both the main file and any
separate debuginfo files.
- Nm has a new command line option: '--quiet'. This suppresses 'no
symbols' diagnostic.
Update to binutils 2.36:
New features in the Assembler:
* When setting the link order attribute of ELF sections, it is now
possible to use a numeric section index instead of symbol name.
* Added a .nop directive to generate a single no-op instruction in
a target neutral manner. This instruction does have an effect on
DWARF line number generation, if that is active.
* Removed --reduce-memory-overheads and --hash-size as gas now
uses hash tables that can be expand and shrink automatically.
* Add support for AVX VNNI, HRESET, UINTR, TDX, AMX and Key
Locker instructions.
* Support non-absolute segment values for lcall and ljmp.
* Add {disp16} pseudo prefix to x86 assembler.
* Configure with --enable-x86-used-note by default for Linux/x86.
* Add support for Cortex-A78, Cortex-A78AE and Cortex-X1,
Cortex-R82, Neoverse V1, and Neoverse N2 cores.
* Add support for ETMv4 (Embedded Trace Macrocell), ETE (Embedded
Trace Extension), TRBE (Trace Buffer Extension), CSRE (Call
Stack Recorder Extension) and BRBE (Branch Record Buffer
Extension) system registers.
* Add support for Armv8-R and Armv8.7-A ISA extensions.
* Add support for DSB memory nXS barrier, WFET and WFIT
instruction for Armv8.7.
* Add support for +csre feature for -march. Add CSR PDEC
instruction for CSRE feature in AArch64.
* Add support for +flagm feature for -march in Armv8.4 AArch64.
* Add support for +ls64 feature for -march in Armv8.7
AArch64. Add atomic 64-byte load/store instructions for this
feature.
* Add support for +pauth (Pointer Authentication) feature for
-march in AArch64.
New features in the Linker:
* Add --error-handling-script= command line option to allow
a helper script to be invoked when an undefined symbol or a
missing library is encountered. This option can be suppressed
via the configure time switch: --enable-error-handling-script=no.
* Add -z x86-64-{baseline|v[234]} to the x86 ELF linker to mark
x86-64-{baseline|v[234]} ISA level as needed.
* Add -z unique-symbol to avoid duplicated local symbol names.
* The creation of PE format DLLs now defaults to using a more
secure set of DLL characteristics.
* The linker now deduplicates the types in .ctf sections. The new
command-line option --ctf-share-types describes how to do this:
its default value, share-unconflicted, produces the most compact
output.
* The linker now omits the 'variable section' from .ctf sections
by default, saving space. This is almost certainly what you
want unless you are working on a project that has its own
analogue of symbol tables that are not reflected in the ELF
symtabs.
New features in other binary tools:
* The ar tool's previously unused l modifier is now used for
specifying dependencies of a static library. The arguments of
this option (or --record-libdeps long form option) will be
stored verbatim in the __.LIBDEP member of the archive, which
the linker may read at link time.
* Readelf can now display the contents of LTO symbol table
sections when asked to do so via the --lto-syms command line
option.
* Readelf now accepts the -C command line option to enable the
demangling of symbol names. In addition the --demangle=