Container summary for bci/nodejs
SUSE-CU-2024:5204-1
| Container Advisory ID | SUSE-CU-2024:5204-1 |
| Container Tags | bci/node:18 , bci/node:18-36.3 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-36.3 , bci/nodejs:18.20.4 |
| Container Release | 36.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3659-1
|
| Released | Wed Oct 16 15:12:47 2024 |
| Summary | Recommended update for gcc14 |
| Type | recommended |
| Severity | moderate |
| References | 1188441,1210959,1214915,1219031,1220724,1221601 |
Description:
This update for gcc14 fixes the following issues:
This update ships the GNU Compiler Collection GCC 14.2. (jsc#PED-10474)
The compiler runtime libraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 13 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP5 and SP6, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available
unsupported via the PackageHub repositories.
To use gcc14 compilers use:
- install 'gcc14' or 'gcc14-c++' or one of the other 'gcc14-COMPILER' frontend packages.
- override your Makefile to use CC=gcc14, CXX=g++14 and similar overrides for the other languages.
For a full changelog with all new GCC14 features, check out
https://gcc.gnu.org/gcc-14/changes.html
- Add libquadmath0-devel-gcc14 sub-package to allow installing
quadmath.h and SO link without installing the fortran frontend
- Avoid combine spending too much compile-time and memory doing nothing on s390x. [bsc#1188441]
- Remove timezone Recommends from the libstdc++6 package. [bsc#1221601]
- Revert libgccjit dependency change. [bsc#1220724]
- Fix libgccjit-devel dependency, a newer shared library is OK.
- Fix libgccjit dependency, the corresponding compiler isn't required.
- Add cross-X-newlib-devel requires to newlib cross compilers.
[bsc#1219031]
- Re-enable AutoReqProv for cross packages but filter files processed
via __requires_exclude_from and __provides_exclude_from.
[bsc#1219031]
- Package m2rte.so plugin in the gcc14-m2 sub-package rather than
in gcc13-devel. [bsc#1210959]
- Require libstdc++6-devel-gcc14 from gcc14-m2 as m2 programs
are linked against libstdc++6.
SUSE-CU-2024:5079-1
| Container Advisory ID | SUSE-CU-2024:5079-1 |
| Container Tags | bci/node:18 , bci/node:18-36.1 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-36.1 , bci/nodejs:18.20.4 |
| Container Release | 36.1 |
The following patches have been included in this update:
SUSE-CU-2024:5007-1
| Container Advisory ID | SUSE-CU-2024:5007-1 |
| Container Tags | bci/node:18 , bci/node:18-35.9 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-35.9 , bci/nodejs:18.20.4 |
| Container Release | 35.9 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3597-1
|
| Released | Fri Oct 11 10:39:52 2024 |
| Summary | Recommended update for bash |
| Type | recommended |
| Severity | moderate |
| References | 1227807 |
Description:
This update for bash fixes the following issues:
- Load completion file eveh if a brace expansion is in the
command line included (bsc#1227807).
SUSE-CU-2024:4974-1
| Container Advisory ID | SUSE-CU-2024:4974-1 |
| Container Tags | bci/node:18 , bci/node:18-35.8 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-35.8 , bci/nodejs:18.20.4 |
| Container Release | 35.8 |
The following patches have been included in this update:
SUSE-CU-2024:4852-1
| Container Advisory ID | SUSE-CU-2024:4852-1 |
| Container Tags | bci/node:18 , bci/node:18-35.7 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-35.7 , bci/nodejs:18.20.4 |
| Container Release | 35.7 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3527-1
|
| Released | Fri Oct 4 15:27:07 2024 |
| Summary | Recommended update for e2fsprogs |
| Type | recommended |
| Severity | moderate |
| References | 1230145 |
Description:
This update for e2fsprogs fixes the following issue:
- resize2fs: Check number of group descriptors only if meta_bg is disabled
(bsc#1230145).
SUSE-CU-2024:4744-1
| Container Advisory ID | SUSE-CU-2024:4744-1 |
| Container Tags | bci/node:18 , bci/node:18-35.4 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-35.4 , bci/nodejs:18.20.4 |
| Container Release | 35.4 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3503-1
|
| Released | Tue Oct 1 16:13:07 2024 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1228661 |
Description:
This update for glibc fixes the following issue:
- fix memory malloc problem: Initiate tcache shutdown even
without allocations (bsc#1228661).
SUSE-CU-2024:4645-1
| Container Advisory ID | SUSE-CU-2024:4645-1 |
| Container Tags | bci/node:18 , bci/node:18-34.2 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-34.2 , bci/nodejs:18.20.4 |
| Container Release | 34.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3477-1
|
| Released | Fri Sep 27 15:22:22 2024 |
| Summary | Recommended update for curl |
| Type | recommended |
| Severity | moderate |
| References | 1230516 |
Description:
This update for curl fixes the following issue:
- Make special characters in URL work with aws-sigv4 (bsc#1230516).
SUSE-CU-2024:4580-1
| Container Advisory ID | SUSE-CU-2024:4580-1 |
| Container Tags | bci/node:18 , bci/node:18-34.1 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-34.1 , bci/nodejs:18.20.4 |
| Container Release | 34.1 |
The following patches have been included in this update:
SUSE-CU-2024:4524-1
| Container Advisory ID | SUSE-CU-2024:4524-1 |
| Container Tags | bci/node:18 , bci/node:18-32.1 , bci/node:18.20.4 , bci/nodejs:18 , bci/nodejs:18-32.1 , bci/nodejs:18.20.4 |
| Container Release | 32.1 |
The following patches have been included in this update:
SUSE-CU-2024:4465-1
| Container Advisory ID | SUSE-CU-2024:4465-1 |
| Container Tags | bci/node:18 , bci/node:18-31.5 , bci/node:18.20.4 , bci/node:18.20.4-31.5 , bci/nodejs:18 , bci/nodejs:18-31.5 , bci/nodejs:18.20.4 , bci/nodejs:18.20.4-31.5 |
| Container Release | 31.5 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3300-1
|
| Released | Wed Sep 18 14:27:53 2024 |
| Summary | Recommended update for ncurses |
| Type | recommended |
| Severity | moderate |
| References | 1229028 |
Description:
This update for ncurses fixes the following issues:
- Allow the terminal description based on static fallback entries to be freed (bsc#1229028)
SUSE-CU-2024:4269-1
| Container Advisory ID | SUSE-CU-2024:4269-1 |
| Container Tags | bci/node:18 , bci/node:18-31.2 , bci/node:18.20.4 , bci/node:18.20.4-31.2 , bci/nodejs:18 , bci/nodejs:18-31.2 , bci/nodejs:18.20.4 , bci/nodejs:18.20.4-31.2 |
| Container Release | 31.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:3216-1
|
| Released | Thu Sep 12 13:05:20 2024 |
| Summary | Security update for expat |
| Type | security |
| Severity | moderate |
| References | 1229930,1229931,1229932,CVE-2024-45490,CVE-2024-45491,CVE-2024-45492 |
Description:
This update for expat fixes the following issues:
- CVE-2024-45492: integer overflow in function nextScaffoldPart. (bsc#1229932)
- CVE-2024-45491: integer overflow in dtdCopy. (bsc#1229931)
- CVE-2024-45490: negative length for XML_ParseBuffer not rejected. (bsc#1229930)
SUSE-CU-2024:4234-1
| Container Advisory ID | SUSE-CU-2024:4234-1 |
| Container Tags | bci/node:18 , bci/node:18-30.4 , bci/node:18.20.4 , bci/node:18.20.4-30.4 , bci/nodejs:18 , bci/nodejs:18-30.4 , bci/nodejs:18.20.4 , bci/nodejs:18.20.4-30.4 |
| Container Release | 30.4 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:3211-1
|
| Released | Wed Sep 11 17:40:13 2024 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1230093,CVE-2024-8096 |
Description:
This update for curl fixes the following issues:
- CVE-2024-8096: OCSP stapling bypass with GnuTLS. (bsc#1230093)
SUSE-CU-2024:4121-1
| Container Advisory ID | SUSE-CU-2024:4121-1 |
| Container Tags | bci/node:18 , bci/node:18-30.3 , bci/node:18.20.4 , bci/node:18.20.4-30.3 , bci/nodejs:18 , bci/nodejs:18-30.3 , bci/nodejs:18.20.4 , bci/nodejs:18.20.4-30.3 |
| Container Release | 30.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3167-1
|
| Released | Mon Sep 9 12:31:59 2024 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1228043 |
Description:
This update for glibc fixes the following issue:
- s390x: Fix segfault in wcsncmp (bsc#1228043).
SUSE-CU-2024:4081-1
| Container Advisory ID | SUSE-CU-2024:4081-1 |
| Container Tags | bci/node:18 , bci/node:18-29.9 , bci/nodejs:18 , bci/nodejs:18-29.9 |
| Container Release | 29.9 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:3149-1
|
| Released | Thu Sep 5 17:05:36 2024 |
| Summary | Security update for systemd |
| Type | security |
| Severity | moderate |
| References | 1218297,1221479,1226414,1228091,CVE-2023-7008 |
Description:
This update for systemd fixes the following issues:
- CVE-2023-7008: Fixed man-in-the-middle due to unsigned name response in signed zone not refused when DNSSEC=yes (bsc#1218297)
Other fixes:
- Unit: drop ProtectClock=yes from systemd-udevd.service (bsc#1226414)
- Don't mention any rpm macros inside comments, even if escaped (bsc#1228091)
- Skip redundant dependencies specified the LSB description that references the file name of the service itself for early boot scripts (bsc#1221479).
SUSE-CU-2024:4026-1
| Container Advisory ID | SUSE-CU-2024:4026-1 |
| Container Tags | bci/node:18 , bci/node:18-29.7 , bci/nodejs:18 , bci/nodejs:18-29.7 |
| Container Release | 29.7 |
The following patches have been included in this update:
SUSE-CU-2024:3988-1
| Container Advisory ID | SUSE-CU-2024:3988-1 |
| Container Tags | bci/node:18 , bci/node:18-29.6 , bci/nodejs:18 , bci/nodejs:18-29.6 |
| Container Release | 29.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:3080-1
|
| Released | Mon Sep 2 16:43:54 2024 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1228535,CVE-2024-7264 |
Description:
This update for curl fixes the following issues:
- CVE-2024-7264: Fixed out-of-bounds read in ASN.1 date parser GTime2str() (bsc#1228535)
SUSE-CU-2024:3882-1
| Container Advisory ID | SUSE-CU-2024:3882-1 |
| Container Tags | bci/node:18 , bci/node:18-29.3 , bci/nodejs:18 , bci/nodejs:18-29.3 |
| Container Release | 29.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:3009-1
|
| Released | Mon Aug 26 11:43:26 2024 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1229029 |
Description:
This update for git fixes the following issue:
- Fix syntax error with old apparmor versions (bsc#1229029)
SUSE-CU-2024:3836-1
| Container Advisory ID | SUSE-CU-2024:3836-1 |
| Container Tags | bci/node:18 , bci/node:18-29.2 , bci/nodejs:18 , bci/nodejs:18-29.2 |
| Container Release | 29.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:2967-1
|
| Released | Mon Aug 19 15:41:29 2024 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1194818 |
Description:
This update for pam fixes the following issue:
- Prevent cursor escape from the login prompt (bsc#1194818).
SUSE-CU-2024:3749-1
| Container Advisory ID | SUSE-CU-2024:3749-1 |
| Container Tags | bci/node:18 , bci/node:18-29.1 , bci/nodejs:18 , bci/nodejs:18-29.1 |
| Container Release | 29.1 |
The following patches have been included in this update:
SUSE-CU-2024:3653-1
| Container Advisory ID | SUSE-CU-2024:3653-1 |
| Container Tags | bci/node:18 , bci/node:18-28.6 , bci/nodejs:18 , bci/nodejs:18-28.6 |
| Container Release | 28.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2891-1
|
| Released | Tue Aug 13 11:39:53 2024 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | moderate |
| References | 1226463,1227138,CVE-2024-5535 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2024-5535: Fixed a buffer overread in function SSL_select_next_proto() with an empty supported client protocols buffer (bsc#1227138)
Other fixes:
- Build with no-afalgeng (bsc#1226463)
SUSE-CU-2024:3584-1
| Container Advisory ID | SUSE-CU-2024:3584-1 |
| Container Tags | bci/node:18 , bci/node:18-28.2 , bci/nodejs:18 , bci/nodejs:18-28.2 |
| Container Release | 28.2 |
The following patches have been included in this update:
SUSE-CU-2024:3495-1
| Container Advisory ID | SUSE-CU-2024:3495-1 |
| Container Tags | bci/node:18 , bci/node:18-27.3 , bci/nodejs:18 , bci/nodejs:18-27.3 |
| Container Release | 27.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2804-1
|
| Released | Wed Aug 7 09:48:29 2024 |
| Summary | Security update for shadow |
| Type | security |
| Severity | moderate |
| References | 1228770,CVE-2013-4235 |
Description:
This update for shadow fixes the following issues:
- Fixed not copying of skel files (bsc#1228770)
SUSE-CU-2024:3429-1
| Container Advisory ID | SUSE-CU-2024:3429-1 |
| Container Tags | bci/node:18 , bci/node:18-27.2 , bci/nodejs:18 , bci/nodejs:18-27.2 |
| Container Release | 27.2 |
The following patches have been included in this update:
SUSE-CU-2024:3428-1
| Container Advisory ID | SUSE-CU-2024:3428-1 |
| Container Tags | bci/node:18 , bci/node:18-27.1 , bci/nodejs:18 , bci/nodejs:18-27.1 |
| Container Release | 27.1 |
The following patches have been included in this update:
SUSE-CU-2024:3331-1
| Container Advisory ID | SUSE-CU-2024:3331-1 |
| Container Tags | bci/node:18 , bci/node:18-26.14 , bci/nodejs:18 , bci/nodejs:18-26.14 |
| Container Release | 26.14 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2656-1
|
| Released | Tue Jul 30 15:36:08 2024 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1219660,CVE-2024-24577 |
Description:
This update for git fixes the following issues:
- CVE-2024-24577: Fixed arbitrary code execution due to heap corruption in git_index_add (bsc#1219660)
| Advisory ID | SUSE-SU-2024:2658-1
|
| Released | Tue Jul 30 15:37:26 2024 |
| Summary | Security update for shadow |
| Type | security |
| Severity | important |
| References | 916845,CVE-2013-4235 |
Description:
This update for shadow fixes the following issues:
- CVE-2013-4235: Fixed a race condition when copying and removing directory trees (bsc#916845).
| Advisory ID | SUSE-RU-2024:2679-1
|
| Released | Wed Jul 31 09:47:44 2024 |
| Summary | Recommended update for patterns-base |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for patterns-base fixes the following issues:
Added a fips-certified pattern matching the exact certified FIPS
versions of the Linux Kernel, openssl 1.1.1, gnutls/nettle, mozilla-nss
and libgcrypt.
Note that applying this pattern might cause downgrade of various packages
and so deinstall security and bugfix updates released after the certified
binaries.
SUSE-CU-2024:3265-1
| Container Advisory ID | SUSE-CU-2024:3265-1 |
| Container Tags | bci/node:18 , bci/node:18-26.10 , bci/nodejs:18 , bci/nodejs:18-26.10 |
| Container Release | 26.10 |
The following patches have been included in this update:
SUSE-CU-2024:3194-1
| Container Advisory ID | SUSE-CU-2024:3194-1 |
| Container Tags | bci/node:18 , bci/node:18-26.9 , bci/nodejs:18 , bci/nodejs:18-26.9 |
| Container Release | 26.9 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2542-1
|
| Released | Wed Jul 17 09:51:35 2024 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | moderate |
| References | 1222665,1227554,1227560,CVE-2024-22020,CVE-2024-27980,CVE-2024-36138 |
Description:
This update for nodejs18 fixes the following issues:
Update to 18.20.4:
- CVE-2024-36138: Fixed CVE-2024-27980 fix bypass (bsc#1227560)
- CVE-2024-22020: Fixed a bypass of network import restriction via data URL (bsc#1227554)
Changes in 18.20.3:
- This release fixes a regression introduced in Node.js 18.19.0 where http.server.close() was incorrectly closing idle connections.
deps:
- acorn updated to 8.11.3.
- acorn-walk updated to 8.3.2.
- ada updated to 2.7.8.
- c-ares updated to 1.28.1.
- corepack updated to 0.28.0.
- nghttp2 updated to 1.61.0.
- ngtcp2 updated to 1.3.0.
- npm updated to 10.7.0. Includes a fix from npm@10.5.1 to limit the number of open connections npm/cli#7324.
- simdutf updated to 5.2.4.
Changes in 18.20.2:
- CVE-2024-27980: Fixed command injection via args parameter of child_process.spawn without shell option enabled on Windows (bsc#1222665)
SUSE-CU-2024:3111-1
| Container Advisory ID | SUSE-CU-2024:3111-1 |
| Container Tags | bci/node:18 , bci/node:18-26.8 , bci/nodejs:18 , bci/nodejs:18-26.8 |
| Container Release | 26.8 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2302-1
|
| Released | Thu Jul 4 16:21:10 2024 |
| Summary | Security update for krb5 |
| Type | security |
| Severity | important |
| References | 1227186,1227187,CVE-2024-37370,CVE-2024-37371 |
Description:
This update for krb5 fixes the following issues:
- CVE-2024-37370: Fixed confidential GSS krb5 wrap tokens with invalid fields were errouneously accepted (bsc#1227186).
- CVE-2024-37371: Fixed invalid memory read when processing message tokens with invalid length fields (bsc#1227187).
SUSE-CU-2024:3009-1
| Container Advisory ID | SUSE-CU-2024:3009-1 |
| Container Tags | bci/node:18 , bci/node:18-26.4 , bci/nodejs:18 , bci/nodejs:18-26.4 |
| Container Release | 26.4 |
The following patches have been included in this update:
SUSE-CU-2024:2980-1
| Container Advisory ID | SUSE-CU-2024:2980-1 |
| Container Tags | bci/node:18 , bci/node:18-26.3 , bci/nodejs:18 , bci/nodejs:18-26.3 |
| Container Release | 26.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2019:2730-1
|
| Released | Mon Oct 21 16:04:57 2019 |
| Summary | Security update for procps |
| Type | security |
| Severity | important |
| References | 1092100,1121753,CVE-2018-1122,CVE-2018-1123,CVE-2018-1124,CVE-2018-1125,CVE-2018-1126 |
Description:
This update for procps fixes the following issues:
procps was updated to 3.3.15. (bsc#1092100)
Following security issues were fixed:
- CVE-2018-1122: Prevent local privilege escalation in top. If a user ran top
with HOME unset in an attacker-controlled directory, the attacker could have
achieved privilege escalation by exploiting one of several vulnerabilities in
the config_file() function (bsc#1092100).
- CVE-2018-1123: Prevent denial of service in ps via mmap buffer overflow.
Inbuilt protection in ps maped a guard page at the end of the overflowed
buffer, ensuring that the impact of this flaw is limited to a crash (temporary
denial of service) (bsc#1092100).
- CVE-2018-1124: Prevent multiple integer overflows leading to a heap
corruption in file2strvec function. This allowed a privilege escalation for a
local attacker who can create entries in procfs by starting processes, which
could result in crashes or arbitrary code execution in proc utilities run by
other users (bsc#1092100).
- CVE-2018-1125: Prevent stack buffer overflow in pgrep. This vulnerability was
mitigated by FORTIFY limiting the impact to a crash (bsc#1092100).
- CVE-2018-1126: Ensure correct integer size in proc/alloc.* to prevent
truncation/integer overflow issues (bsc#1092100).
Also this non-security issue was fixed:
- Fix CPU summary showing old data. (bsc#1121753)
The update to 3.3.15 contains the following fixes:
- library: Increment to 8:0:1
No removals, no new functions
Changes: slab and pid structures
- library: Just check for SIGLOST and don't delete it
- library: Fix integer overflow and LPE in file2strvec CVE-2018-1124
- library: Use size_t for alloc functions CVE-2018-1126
- library: Increase comm size to 64
- pgrep: Fix stack-based buffer overflow CVE-2018-1125
- pgrep: Remove >15 warning as comm can be longer
- ps: Fix buffer overflow in output buffer, causing DOS CVE-2018-1123
- ps: Increase command name selection field to 64
- top: Don't use cwd for location of config CVE-2018-1122
- update translations
- library: build on non-glibc systems
- free: fix scaling on 32-bit systems
- Revert 'Support running with child namespaces'
- library: Increment to 7:0:1
No changes, no removals
New fuctions: numa_init, numa_max_node, numa_node_of_cpu, numa_uninit, xalloc_err_handler
- doc: Document I idle state in ps.1 and top.1
- free: fix some of the SI multiples
- kill: -l space between name parses correctly
- library: dont use vm_min_free on non Linux
- library: don't strip off wchan prefixes (ps & top)
- pgrep: warn about 15+ char name only if -f not used
- pgrep/pkill: only match in same namespace by default
- pidof: specify separator between pids
- pkill: Return 0 only if we can kill process
- pmap: fix duplicate output line under '-x' option
- ps: avoid eip/esp address truncations
- ps: recognizes SCHED_DEADLINE as valid CPU scheduler
- ps: display NUMA node under which a thread ran
- ps: Add seconds display for cputime and time
- ps: Add LUID field
- sysctl: Permit empty string for value
- sysctl: Don't segv when file not available
- sysctl: Read and write large buffers
- top: add config file support for XDG specification
- top: eliminated minor libnuma memory leak
- top: show fewer memory decimal places (configurable)
- top: provide command line switch for memory scaling
- top: provide command line switch for CPU States
- top: provides more accurate cpu usage at startup
- top: display NUMA node under which a thread ran
- top: fix argument parsing quirk resulting in SEGV
- top: delay interval accepts non-locale radix point
- top: address a wishlist man page NLS suggestion
- top: fix potential distortion in 'Mem' graph display
- top: provide proper multi-byte string handling
- top: startup defaults are fully customizable
- watch: define HOST_NAME_MAX where not defined
- vmstat: Fix alignment for disk partition format
- watch: Support ANSI 39,49 reset sequences
| Advisory ID | SUSE-RU-2020:225-1
|
| Released | Fri Jan 24 06:49:07 2020 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1158830 |
Description:
This update for procps fixes the following issues:
- Fix for 'ps -C' allowing to accept any arguments longer than 15 characters anymore. (bsc#1158830)
| Advisory ID | SUSE-RU-2020:2958-1
|
| Released | Tue Oct 20 12:24:55 2020 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1158830 |
Description:
This update for procps fixes the following issues:
- Fixes an issue when command 'ps -C' does not allow anymore an argument longer than 15 characters. (bsc#1158830)
| Advisory ID | SUSE-RU-2021:1169-1
|
| Released | Tue Apr 13 15:01:42 2021 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | low |
| References | 1181976 |
Description:
This update for procps fixes the following issues:
- Corrected a statement in the man page about processor pinning via taskset (bsc#1181976)
| Advisory ID | SUSE-RU-2021:1549-1
|
| Released | Mon May 10 13:48:00 2021 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1185417 |
Description:
This update for procps fixes the following issues:
- Support up to 2048 CPU as well. (bsc#1185417)
| Advisory ID | SUSE-RU-2022:808-1
|
| Released | Fri Mar 11 06:07:58 2022 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1195468 |
Description:
This update for procps fixes the following issues:
- Stop registering signal handler for SIGURG, to avoid `ps` failure if
someone sends such signal. Without the signal handler, SIGURG will
just be ignored. (bsc#1195468)
| Advisory ID | SUSE-RU-2022:2944-1
|
| Released | Wed Aug 31 05:39:14 2022 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | important |
| References | 1181475 |
Description:
This update for procps fixes the following issues:
- Fix 'free' command reporting misleading 'used' value (bsc#1181475)
| Advisory ID | SUSE-RU-2023:181-1
|
| Released | Thu Jan 26 21:55:43 2023 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | low |
| References | 1206412 |
Description:
This update for procps fixes the following issues:
- Improve memory handling/usage (bsc#1206412)
- Make sure that correct library version is installed (bsc#1206412)
| Advisory ID | SUSE-RU-2023:2104-1
|
| Released | Thu May 4 21:05:30 2023 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1209122 |
Description:
This update for procps fixes the following issue:
- Allow - as leading character to ignore possible errors on systctl entries (bsc#1209122)
| Advisory ID | SUSE-SU-2023:3440-1
|
| Released | Mon Aug 28 08:57:10 2023 |
| Summary | Security update for gawk |
| Type | security |
| Severity | low |
| References | 1214025,CVE-2023-4156 |
Description:
This update for gawk fixes the following issues:
- CVE-2023-4156: Fix a heap out of bound read by validating the index into argument list. (bsc#1214025)
| Advisory ID | SUSE-SU-2023:3472-1
|
| Released | Tue Aug 29 10:55:16 2023 |
| Summary | Security update for procps |
| Type | security |
| Severity | low |
| References | 1214290,CVE-2023-4016 |
Description:
This update for procps fixes the following issues:
- CVE-2023-4016: Fixed ps buffer overflow (bsc#1214290).
| Advisory ID | SUSE-RU-2024:11-1
|
| Released | Tue Jan 2 13:24:52 2024 |
| Summary | Recommended update for procps |
| Type | recommended |
| Severity | moderate |
| References | 1029961,1158830,1206798,1209122 |
Description:
This update for procps fixes the following issues:
- Update procps to 3.3.17 (jsc#PED-3244 jsc#PED-6369)
- For support up to 2048 CPU as well (bsc#1185417)
- Allow `-´ as leading character to ignore possible errors on systctl entries (bsc#1209122)
- Get the first CPU summary correct (bsc#1121753)
- Enable pidof for SLE-15 as this is provided by sysvinit-tools
- Use a check on syscall __NR_pidfd_open to decide if
the pwait tool and its manual page will be build
- Do not truncate output of w with option -n
- Prefer logind over utmp (jsc#PED-3144)
- Don't install translated man pages for non-installed binaries
(uptime, kill).
- Fix directory for Ukrainian man pages translations.
- Move localized man pages to lang package.
- Update to procps-ng-3.3.17
* library: Incremented to 8:3:0
(no removals or additions, internal changes only)
* all: properly handle utf8 cmdline translations
* kill: Pass int to signalled process
* pgrep: Pass int to signalled process
* pgrep: Check sanity of SG_ARG_MAX
* pgrep: Add older than selection
* pidof: Quiet mode
* pidof: show worker threads
* ps.1: Mention stime alias
* ps: check also match on truncated 16 char comm names
* ps: Add exe output option
* ps: A lot more sorting available
* pwait: New command waits for a process
* sysctl: Match systemd directory order
* sysctl: Document directory order
* top: ensure config file backward compatibility
* top: add command line 'e' for symmetry with 'E'
* top: add '4' toggle for two abreast cpu display
* top: add '!' toggle for combining multiple cpus
* top: fix potential SEGV involving -p switch
* vmstat: Wide mode gives wider proc columns
* watch: Add environment variable for interval
* watch: Add no linewrap option
* watch: Support more colors
* free,uptime,slabtop: complain about extra ops
- Package translations in procps-lang.
- Fix pgrep: cannot allocate 4611686018427387903 bytes when ulimit -s is unlimited.
- Update to procps-ng-3.3.16
* library: Increment to 8:2:0
No removals or functions
Internal changes only, so revision is incremented.
Previous version should have been 8:1:0 not 8:0:1
* docs: Use correct symbols for -h option in free.1
* docs: ps.1 now warns about command name length
* docs: install translated man pages
* pgrep: Match on runstate
* snice: Fix matching on pid
* top: can now exploit 256-color terminals
* top: preserves 'other filters' in configuration file
* top: can now collapse/expand forest view children
* top: parent %CPU time includes collapsed children
* top: improve xterm support for vim navigation keys
* top: avoid segmentation fault at program termination
* 'ps -C' does not allow anymore an argument longer than 15 characters (bsc#1158830)
| Advisory ID | SUSE-OU-2024:2282-1
|
| Released | Tue Jul 2 22:41:28 2024 |
| Summary | Optional update for openscap, scap-security-guide |
| Type | optional |
| Severity | moderate |
| References | |
Description:
This update for scap-security-guide and openscap provides the SCAP tooling
for SLE Micro 5.3, 5.4, 5.5.
This includes shipping openscap dependencies libxmlsec1-1 and libxmlsec1-openssl for SLE Micro.
SUSE-CU-2024:2888-1
| Container Advisory ID | SUSE-CU-2024:2888-1 |
| Container Tags | bci/node:18 , bci/node:18-25.9 , bci/nodejs:18 , bci/nodejs:18-25.9 |
| Container Release | 25.9 |
The following patches have been included in this update:
SUSE-CU-2024:2866-1
| Container Advisory ID | SUSE-CU-2024:2866-1 |
| Container Tags | bci/node:18 , bci/node:18-25.8 , bci/nodejs:18 , bci/nodejs:18-25.8 |
| Container Release | 25.8 |
The following patches have been included in this update:
SUSE-CU-2024:2834-1
| Container Advisory ID | SUSE-CU-2024:2834-1 |
| Container Tags | bci/node:18 , bci/node:18-25.6 , bci/nodejs:18 , bci/nodejs:18-25.6 |
| Container Release | 25.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:2086-1
|
| Released | Wed Jun 19 11:48:24 2024 |
| Summary | Recommended update for gcc13 |
| Type | recommended |
| Severity | moderate |
| References | 1188441 |
Description:
This update for gcc13 fixes the following issues:
Update to GCC 13.3 release
- Removed Fiji support from the GCN offload compiler as that is requiring
Code Object version 3 which is no longer supported by llvm18.
- Avoid combine spending too much compile-time and memory doing nothing
on s390x. [bsc#1188441]
- Make requirement to lld version specific to avoid requiring the
meta-package.
SUSE-CU-2024:2779-1
| Container Advisory ID | SUSE-CU-2024:2779-1 |
| Container Tags | bci/node:18 , bci/node:18-25.3 , bci/nodejs:18 , bci/nodejs:18-25.3 |
| Container Release | 25.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:2051-1
|
| Released | Tue Jun 18 09:16:01 2024 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | important |
| References | 1225551,CVE-2024-4741 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551)
SUSE-CU-2024:2731-1
| Container Advisory ID | SUSE-CU-2024:2731-1 |
| Container Tags | bci/node:18 , bci/node:18-25.1 , bci/nodejs:18 , bci/nodejs:18-25.1 |
| Container Release | 25.1 |
The following patches have been included in this update:
SUSE-CU-2024:2701-1
| Container Advisory ID | SUSE-CU-2024:2701-1 |
| Container Tags | bci/node:18 , bci/node:18-24.3 , bci/nodejs:18 , bci/nodejs:18-24.3 |
| Container Release | 24.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:2024-1
|
| Released | Thu Jun 13 16:15:18 2024 |
| Summary | Recommended update for jitterentropy |
| Type | recommended |
| Severity | moderate |
| References | 1209627 |
Description:
This update for jitterentropy fixes the following issues:
- Fixed a stack corruption on s390x: [bsc#1209627]
* Output size of the STCKE command on s390x is 16 bytes, compared
to 8 bytes of the STCK command. Fix a stack corruption in the
s390x version of jent_get_nstime(). Add some more detailed
information on the STCKE command.
Updated to 3.4.1
- add FIPS 140 hints to man page
- simplify the test tool to search for optimal configurations
- fix: jent_loop_shuffle: re-add setting the time that was lost with 3.4.0
- enhancement: add ARM64 assembler code to read high-res timer
SUSE-CU-2024:2635-1
| Container Advisory ID | SUSE-CU-2024:2635-1 |
| Container Tags | bci/node:18 , bci/node:18-24.1 , bci/nodejs:18 , bci/nodejs:18-24.1 |
| Container Release | 24.1 |
The following patches have been included in this update:
SUSE-CU-2024:2604-1
| Container Advisory ID | SUSE-CU-2024:2604-1 |
| Container Tags | bci/node:18 , bci/node:18-23.1 , bci/nodejs:18 , bci/nodejs:18-23.1 |
| Container Release | 23.1 |
The following patches have been included in this update:
SUSE-CU-2024:2513-1
| Container Advisory ID | SUSE-CU-2024:2513-1 |
| Container Tags | bci/node:18 , bci/node:18-22.1 , bci/nodejs:18 , bci/nodejs:18-22.1 |
| Container Release | 22.1 |
The following patches have been included in this update:
SUSE-CU-2024:2463-1
| Container Advisory ID | SUSE-CU-2024:2463-1 |
| Container Tags | bci/node:18 , bci/node:18-21.14 , bci/nodejs:18 , bci/nodejs:18-21.14 |
| Container Release | 21.14 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1895-1
|
| Released | Mon Jun 3 09:00:20 2024 |
| Summary | Security update for glibc |
| Type | security |
| Severity | important |
| References | 1221940,1223423,1223424,1223425,CVE-2024-33599,CVE-2024-33600,CVE-2024-33601,CVE-2024-33602 |
Description:
This update for glibc fixes the following issues:
- CVE-2024-33599: Fixed a stack-based buffer overflow in netgroup cache in nscd (bsc#1223423)
- CVE-2024-33600: Avoid null pointer crashes after notfound response in nscd (bsc#1223424)
- CVE-2024-33600: Do not send missing not-found response in addgetnetgrentX in nscd (bsc#1223424)
- CVE-2024-33601, CVE-2024-33602: Fixed use of two buffers in addgetnetgrentX ( bsc#1223425)
- CVE-2024-33602: Use time_t for return type of addgetnetgrentX (bsc#1223425)
- Avoid creating userspace live patching prologue for _start routine (bsc#1221940)
SUSE-CU-2024:2414-1
| Container Advisory ID | SUSE-CU-2024:2414-1 |
| Container Tags | bci/node:18 , bci/node:18-21.12 , bci/nodejs:18 , bci/nodejs:18-21.12 |
| Container Release | 21.12 |
The following patches have been included in this update:
SUSE-CU-2024:2359-1
| Container Advisory ID | SUSE-CU-2024:2359-1 |
| Container Tags | bci/node:18 , bci/node:18-21.10 , bci/nodejs:18 , bci/nodejs:18-21.10 |
| Container Release | 21.10 |
The following patches have been included in this update:
SUSE-CU-2024:2320-1
| Container Advisory ID | SUSE-CU-2024:2320-1 |
| Container Tags | bci/node:18 , bci/node:18-21.9 , bci/nodejs:18 , bci/nodejs:18-21.9 |
| Container Release | 21.9 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:1802-1
|
| Released | Tue May 28 16:20:18 2024 |
| Summary | Recommended update for e2fsprogs |
| Type | recommended |
| Severity | moderate |
| References | 1223596 |
Description:
This update for e2fsprogs fixes the following issues:
EA Inode handling fixes:
- ext2fs: avoid re-reading inode multiple times (bsc#1223596)
- e2fsck: fix potential out-of-bounds read in inc_ea_inode_refs() (bsc#1223596)
- e2fsck: add more checks for ea inode consistency (bsc#1223596)
- e2fsck: fix golden output of several tests (bsc#1223596)
| Advisory ID | SUSE-SU-2024:1807-1
|
| Released | Tue May 28 22:11:31 2024 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1224168,1224170,1224171,1224172,1224173,CVE-2024-32002,CVE-2024-32004,CVE-2024-32020,CVE-2024-32021,CVE-2024-32465 |
Description:
This update for git fixes the following issues:
- CVE-2024-32002: Fixed recursive clones on case-insensitive filesystems that support symbolic links are susceptible to case confusion (bsc#1224168).
- CVE-2024-32004: Fixed arbitrary code execution during local clones (bsc#1224170).
- CVE-2024-32020: Fixed file overwriting vulnerability during local clones (bsc#1224171).
- CVE-2024-32021: Fixed git may create hardlinks to arbitrary user-readable files (bsc#1224172).
- CVE-2024-32465: Fixed arbitrary code execution during clone operations (bsc#1224173).
| Advisory ID | SUSE-SU-2024:1808-1
|
| Released | Tue May 28 22:12:38 2024 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | moderate |
| References | 1222548,CVE-2024-2511 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2024-2511: Fixed unconstrained session cache growth in TLSv1.3 (bsc#1222548).
SUSE-CU-2024:2213-1
| Container Advisory ID | SUSE-CU-2024:2213-1 |
| Container Tags | bci/node:18 , bci/node:18-21.2 , bci/nodejs:18 , bci/nodejs:18-21.2 |
| Container Release | 21.2 |
The following patches have been included in this update:
SUSE-CU-2024:2185-1
| Container Advisory ID | SUSE-CU-2024:2185-1 |
| Container Tags | bci/node:18 , bci/node:18-21.1 , bci/nodejs:18 , bci/nodejs:18-21.1 |
| Container Release | 21.1 |
The following patches have been included in this update:
SUSE-CU-2024:2131-1
| Container Advisory ID | SUSE-CU-2024:2131-1 |
| Container Tags | bci/node:18 , bci/node:18-20.1 , bci/nodejs:18 , bci/nodejs:18-20.1 |
| Container Release | 20.1 |
The following patches have been included in this update:
SUSE-CU-2024:2130-1
| Container Advisory ID | SUSE-CU-2024:2130-1 |
| Container Tags | bci/node:18 , bci/node:18-19.1 , bci/nodejs:18 , bci/nodejs:18-19.1 |
| Container Release | 19.1 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:1665-1
|
| Released | Thu May 16 08:00:09 2024 |
| Summary | Recommended update for coreutils |
| Type | recommended |
| Severity | moderate |
| References | 1221632 |
Description:
This update for coreutils fixes the following issues:
- ls: avoid triggering automounts (bsc#1221632)
SUSE-CU-2024:2069-1
| Container Advisory ID | SUSE-CU-2024:2069-1 |
| Container Tags | bci/node:18 , bci/node:18-18.3 , bci/nodejs:18 , bci/nodejs:18-18.3 |
| Container Release | 18.3 |
The following patches have been included in this update:
SUSE-CU-2024:1999-1
| Container Advisory ID | SUSE-CU-2024:1999-1 |
| Container Tags | bci/node:18 , bci/node:18-18.2 , bci/nodejs:18 , bci/nodejs:18-18.2 |
| Container Release | 18.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1598-1
|
| Released | Fri May 10 11:50:36 2024 |
| Summary | Security update for less |
| Type | security |
| Severity | important |
| References | 1222849,CVE-2024-32487 |
Description:
This update for less fixes the following issues:
- CVE-2024-32487: Fixed mishandling of \n character in paths when LESSOPEN is set leads to OS command execution. (bsc#1222849)
SUSE-CU-2024:1962-1
| Container Advisory ID | SUSE-CU-2024:1962-1 |
| Container Tags | bci/node:18 , bci/node:18-17.14 , bci/nodejs:18 , bci/nodejs:18-17.14 |
| Container Release | 17.14 |
The following patches have been included in this update:
SUSE-CU-2024:1865-1
| Container Advisory ID | SUSE-CU-2024:1865-1 |
| Container Tags | bci/node:18 , bci/node:18-17.13 , bci/nodejs:18 , bci/nodejs:18-17.13 |
| Container Release | 17.13 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:1485-1
|
| Released | Thu May 2 05:33:36 2024 |
| Summary | Recommended update for python39 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for python39 fixes the following issues:
- Build python package for python311 (jsc#PED-5851) and python39 (jsc#PED-7886)
SUSE-CU-2024:1813-1
| Container Advisory ID | SUSE-CU-2024:1813-1 |
| Container Tags | bci/node:18 , bci/node:18-17.9 , bci/nodejs:18 , bci/nodejs:18-17.9 |
| Container Release | 17.9 |
The following patches have been included in this update:
SUSE-CU-2024:1776-1
| Container Advisory ID | SUSE-CU-2024:1776-1 |
| Container Tags | bci/node:18 , bci/node:18-17.7 , bci/nodejs:18 , bci/nodejs:18-17.7 |
| Container Release | 17.7 |
The following patches have been included in this update:
SUSE-CU-2024:1653-1
| Container Advisory ID | SUSE-CU-2024:1653-1 |
| Container Tags | bci/node:18 , bci/node:18-17.6 , bci/nodejs:18 , bci/nodejs:18-17.6 |
| Container Release | 17.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1375-1
|
| Released | Mon Apr 22 14:56:13 2024 |
| Summary | Security update for glibc |
| Type | security |
| Severity | important |
| References | 1222992,CVE-2024-2961 |
Description:
This update for glibc fixes the following issues:
- iconv: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence (CVE-2024-2961, bsc#1222992)
SUSE-CU-2024:1590-1
| Container Advisory ID | SUSE-CU-2024:1590-1 |
| Container Tags | bci/node:18 , bci/node:18-17.4 , bci/nodejs:18 , bci/nodejs:18-17.4 |
| Container Release | 17.4 |
The following patches have been included in this update:
SUSE-CU-2024:1536-1
| Container Advisory ID | SUSE-CU-2024:1536-1 |
| Container Tags | bci/node:18 , bci/node:18-17.2 , bci/nodejs:18 , bci/nodejs:18-17.2 |
| Container Release | 17.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1309-1
|
| Released | Tue Apr 16 11:32:57 2024 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1220053,1222244,1222384,1222530,1222603,CVE-2024-24806,CVE-2024-27982,CVE-2024-27983,CVE-2024-30260,CVE-2024-30261 |
Description:
This update for nodejs18 fixes the following issues:
Update to 18.20.1
Security fixes:
- CVE-2024-27983: Fixed failed assertion in node::http2::Http2Session::~Http2Session() that could lead to HTTP/2 server crash (bsc#1222244)
- CVE-2024-27982: Fixed HTTP Request Smuggling via Content Length Obfuscation (bsc#1222384)
- CVE-2024-30260: Fixed proxy-authorization header not cleared on cross-origin redirect in undici (bsc#1222530)
- CVE-2024-30261: Fixed fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect in undici (bsc#1222603)
- CVE-2024-24806: Fixed improper domain lookup that potentially leads to SSRF attacks in libuv (bsc#1220053)
SUSE-CU-2024:1496-1
| Container Advisory ID | SUSE-CU-2024:1496-1 |
| Container Tags | bci/node:18 , bci/node:18-17.1 , bci/nodejs:18 , bci/nodejs:18-17.1 |
| Container Release | 17.1 |
The following patches have been included in this update:
SUSE-CU-2024:1429-1
| Container Advisory ID | SUSE-CU-2024:1429-1 |
| Container Tags | bci/node:18 , bci/node:18-16.51 , bci/nodejs:18 , bci/nodejs:18-16.51 |
| Container Release | 16.51 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:1253-1
|
| Released | Fri Apr 12 08:15:18 2024 |
| Summary | Recommended update for gcc13 |
| Type | recommended |
| Severity | moderate |
| References | 1210959,1214934,1217450,1217667,1218492,1219031,1219520,1220724,1221239 |
Description:
This update for gcc13 fixes the following issues:
- Fix unwinding for JIT code. [bsc#1221239]
- Revert libgccjit dependency change. [bsc#1220724]
- Remove crypt and crypt_r interceptors. The crypt API change in SLE15 SP3
breaks them. [bsc#1219520]
- Add support for -fmin-function-alignment. [bsc#1214934]
- Use %{_target_cpu} to determine host and build.
- Fix for building TVM. [bsc#1218492]
- Add cross-X-newlib-devel requires to newlib cross compilers.
[bsc#1219031]
- Package m2rte.so plugin in the gcc13-m2 sub-package rather than in gcc13-devel. [bsc#1210959]
- Require libstdc++6-devel-gcc13 from gcc13-m2 as m2 programs are linked against libstdc++6.
- Fixed building mariadb on i686. [bsc#1217667]
- Avoid update-alternatives dependency for accelerator crosses.
- Package tool links to llvm in cross-amdgcn-gcc13 rather than in
cross-amdgcn-newlib13-devel since that also has the dependence.
- Depend on llvmVER instead of llvm with VER equal to
%product_libs_llvm_ver where available and adjust tool discovery
accordingly. This should also properly trigger re-builds when
the patchlevel version of llvmVER changes, possibly changing
the binary names we link to. [bsc#1217450]
SUSE-CU-2024:1410-1
| Container Advisory ID | SUSE-CU-2024:1410-1 |
| Container Tags | bci/node:18 , bci/node:18-16.49 , bci/nodejs:18 , bci/nodejs:18-16.49 |
| Container Release | 16.49 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:1231-1
|
| Released | Thu Apr 11 15:20:40 2024 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1220441 |
Description:
This update for glibc fixes the following issues:
- duplocale: protect use of global locale (bsc#1220441, BZ #23970)
SUSE-CU-2024:1380-1
| Container Advisory ID | SUSE-CU-2024:1380-1 |
| Container Tags | bci/node:18 , bci/node:18-16.45 , bci/nodejs:18 , bci/nodejs:18-16.45 |
| Container Release | 16.45 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1192-1
|
| Released | Wed Apr 10 09:14:37 2024 |
| Summary | Security update for less |
| Type | security |
| Severity | important |
| References | 1219901,CVE-2022-48624 |
Description:
This update for less fixes the following issues:
- CVE-2022-48624: Fixed LESSCLOSE handling in less that does not quote shell metacharacters (bsc#1219901).
SUSE-CU-2024:1323-1
| Container Advisory ID | SUSE-CU-2024:1323-1 |
| Container Tags | bci/node:18 , bci/node:18-16.44 , bci/nodejs:18 , bci/nodejs:18-16.44 |
| Container Release | 16.44 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:1129-1
|
| Released | Mon Apr 8 09:12:08 2024 |
| Summary | Security update for expat |
| Type | security |
| Severity | important |
| References | 1219559,1221289,CVE-2023-52425,CVE-2024-28757 |
Description:
This update for expat fixes the following issues:
- CVE-2023-52425: Fixed a DoS caused by processing large tokens. (bsc#1219559)
- CVE-2024-28757: Fixed an XML Entity Expansion. (bsc#1221289)
| Advisory ID | SUSE-SU-2024:1133-1
|
| Released | Mon Apr 8 11:29:02 2024 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1220061,CVE-2023-45918 |
Description:
This update for ncurses fixes the following issues:
- CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061).
| Advisory ID | SUSE-SU-2024:1136-1
|
| Released | Mon Apr 8 11:30:15 2024 |
| Summary | Security update for c-ares |
| Type | security |
| Severity | moderate |
| References | 1220279,CVE-2024-25629 |
Description:
This update for c-ares fixes the following issues:
- CVE-2024-25629: Fixed out of bounds read in ares__read_line() (bsc#1220279).
| Advisory ID | SUSE-SU-2024:1151-1
|
| Released | Mon Apr 8 11:36:23 2024 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1221665,1221667,CVE-2024-2004,CVE-2024-2398 |
Description:
This update for curl fixes the following issues:
- CVE-2024-2004: Fix the uUsage of disabled protocol logic. (bsc#1221665)
- CVE-2024-2398: Fix HTTP/2 push headers memory-leak. (bsc#1221667)
| Advisory ID | SUSE-SU-2024:1167-1
|
| Released | Mon Apr 8 15:11:11 2024 |
| Summary | Security update for nghttp2 |
| Type | security |
| Severity | important |
| References | 1221399,CVE-2024-28182 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2024-28182: Fixed denial of service via http/2 continuation frames (bsc#1221399)
SUSE-CU-2024:1247-1
| Container Advisory ID | SUSE-CU-2024:1247-1 |
| Container Tags | bci/node:18 , bci/node:18-16.39 , bci/nodejs:18 , bci/nodejs:18-16.39 |
| Container Release | 16.39 |
The following patches have been included in this update:
SUSE-CU-2024:1246-1
| Container Advisory ID | SUSE-CU-2024:1246-1 |
| Container Tags | bci/node:18 , bci/node:18-16.38 , bci/nodejs:18 , bci/nodejs:18-16.38 |
| Container Release | 16.38 |
The following patches have been included in this update:
SUSE-CU-2024:1128-1
| Container Advisory ID | SUSE-CU-2024:1128-1 |
| Container Tags | bci/node:18 , bci/node:18-16.36 , bci/nodejs:18 , bci/nodejs:18-16.36 |
| Container Release | 16.36 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:997-1
|
| Released | Tue Mar 26 11:03:37 2024 |
| Summary | Security update for krb5 |
| Type | security |
| Severity | important |
| References | 1220770,1220771,1220772,CVE-2024-26458,CVE-2024-26461,CVE-2024-26462 |
Description:
This update for krb5 fixes the following issues:
- CVE-2024-26458: Fixed memory leak at /krb5/src/lib/rpc/pmap_rmt.c (bsc#1220770).
- CVE-2024-26461: Fixed memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c (bsc#1220771).
- CVE-2024-26462: Fixed memory leak at /krb5/src/kdc/ndr.c (bsc#1220772).
SUSE-CU-2024:1077-1
| Container Advisory ID | SUSE-CU-2024:1077-1 |
| Container Tags | bci/node:18 , bci/node:18-16.34 , bci/nodejs:18 , bci/nodejs:18-16.34 |
| Container Release | 16.34 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:960-1
|
| Released | Thu Mar 21 09:35:14 2024 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1216545 |
Description:
This update for git fixes the following issues:
- Do not replace apparmor configuration (bsc#1216545)
SUSE-CU-2024:1051-1
| Container Advisory ID | SUSE-CU-2024:1051-1 |
| Container Tags | bci/node:18 , bci/node:18-16.33 , bci/nodejs:18 , bci/nodejs:18-16.33 |
| Container Release | 16.33 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:914-1
|
| Released | Mon Mar 18 06:39:03 2024 |
| Summary | Recommended update for shadow |
| Type | recommended |
| Severity | important |
| References | 1176006,1188307,1203823 |
Description:
This update for shadow fixes the following issues:
- Fix chage date miscalculation (bsc#1176006)
- Fix passwd segfault when nsswitch.conf defines 'files compat' (bsc#1188307
- Remove pam_keyinit from PAM config files (bsc#1203823)
| Advisory ID | SUSE-RU-2024:929-1
|
| Released | Tue Mar 19 06:36:24 2024 |
| Summary | Recommended update for coreutils |
| Type | recommended |
| Severity | moderate |
| References | 1219321 |
Description:
This update for coreutils fixes the following issues:
- tail: fix tailing sysfs files where PAGE_SIZE > BUFSIZ (bsc#1219321)
SUSE-CU-2024:991-1
| Container Advisory ID | SUSE-CU-2024:991-1 |
| Container Tags | bci/node:18 , bci/node:18-16.29 , bci/nodejs:18 , bci/nodejs:18-16.29 |
| Container Release | 16.29 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:870-1
|
| Released | Wed Mar 13 13:05:14 2024 |
| Summary | Security update for glibc |
| Type | security |
| Severity | moderate |
| References | 1217445,1217589,1218866 |
Description:
This update for glibc fixes the following issues:
Security issues fixed:
- qsort: harden handling of degenerated / non transient compare function (bsc#1218866)
Other issues fixed:
- getaddrinfo: translate ENOMEM to EAI_MEMORY (bsc#1217589, BZ #31163)
- aarch64: correct CFI in rawmemchr (bsc#1217445, BZ #31113)
| Advisory ID | SUSE-RU-2024:907-1
|
| Released | Fri Mar 15 08:57:38 2024 |
| Summary | Recommended update for audit |
| Type | recommended |
| Severity | moderate |
| References | 1215377 |
Description:
This update for audit fixes the following issue:
- Fix plugin termination when using systemd service units (bsc#1215377)
SUSE-CU-2024:896-1
| Container Advisory ID | SUSE-CU-2024:896-1 |
| Container Tags | bci/node:18 , bci/node:18-16.24 , bci/nodejs:18 , bci/nodejs:18-16.24 |
| Container Release | 16.24 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:792-1
|
| Released | Thu Mar 7 09:55:23 2024 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for timezone fixes the following issues:
- Update to version 2024a
- Kazakhstan unifies on UTC+5
- Palestine springs forward a week later than previously predicted in 2024 and 2025
- Asia/Ho_Chi_Minh's 1955-07-01 transition occurred at 01:00 not 00:00
- From 1947 through 1949, Toronto's transitions occurred at 02:00 not 00:00
- In 1911 Miquelon adopted standard time on June 15, not May 15
- The FROM and TO columns of Rule lines can no longer be 'minimum'
- localtime no longer mishandle some timestamps
- strftime %s now uses tm_gmtoff if available
- Ittoqqortoormiit, Greenland changes time zones on 2024-03-31
- Vostok, Antarctica changed time zones on 2023-12-18
- Casey, Antarctica changed time zones five times since 2020
- Code and data fixes for Palestine timestamps starting in 2072
- A new data file zonenow.tab for timestamps starting now
- Much of Greenland changed its standard time from -03 to -02 on 2023-03-25
- localtime.c no longer mishandles TZif files that contain a single transition into a DST regime
- tzselect no longer creates temporary files
- tzselect no longer mishandles the following:
* Spaces and most other special characters in BUGEMAIL, PACKAGE, TZDIR, and VERSION.
* TZ strings when using mawk 1.4.3, which mishandles regular expressions of the form /X{2,}/
* ISO 6709 coordinates when using an awk that lacks the GNU extension of newlines in -v option-arguments
* Non UTF-8 locales when using an iconv command that lacks the GNU //TRANSLIT extension
* zic no longer mishandles data for Palestine after the year 2075
SUSE-CU-2024:839-1
| Container Advisory ID | SUSE-CU-2024:839-1 |
| Container Tags | bci/node:18 , bci/node:18-16.22 , bci/nodejs:18 , bci/nodejs:18-16.22 |
| Container Release | 16.22 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:766-1
|
| Released | Tue Mar 5 13:50:28 2024 |
| Summary | Recommended update for libssh |
| Type | recommended |
| Severity | important |
| References | 1220385 |
Description:
This update for libssh fixes the following issues:
- Fix regression parsing IPv6 addresses provided as hostname (bsc#1220385)
SUSE-CU-2024:796-1
| Container Advisory ID | SUSE-CU-2024:796-1 |
| Container Tags | bci/node:18 , bci/node:18-16.19 , bci/nodejs:18 , bci/nodejs:18-16.19 |
| Container Release | 16.19 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:730-1
|
| Released | Thu Feb 29 13:00:43 2024 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1219724,1219992,1219993,1219997,1220014,1220017,CVE-2023-46809,CVE-2024-21892,CVE-2024-22019,CVE-2024-22025,CVE-2024-24758,CVE-2024-24806 |
Description:
This update for nodejs18 fixes the following issues:
Update to 18.19.1: (security updates)
- CVE-2024-21892: Code injection and privilege escalation through Linux capabilities (bsc#1219992).
- CVE-2024-22019: http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks (bsc#1219993).
- CVE-2023-46809: Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) (bsc#1219997).
- CVE-2024-22025: Denial of Service by resource exhaustion in fetch() brotli decoding (bsc#1220014).
- CVE-2024-24758: undici version 5.28.3 (bsc#1220017).
- CVE-2024-24806: libuv version 1.48.0 (bsc#1219724).
Update to LTS version 18.19.0
- deps: npm updates to 10.x
- esm:
+ Leverage loaders when resolving subsequent loaders
+ import.meta.resolve unflagged
+ --experimental-default-type flag to flip module defaults
SUSE-CU-2024:703-1
| Container Advisory ID | SUSE-CU-2024:703-1 |
| Container Tags | bci/node:18 , bci/node:18-16.11 , bci/nodejs:18 , bci/nodejs:18-16.11 |
| Container Release | 16.11 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:614-1
|
| Released | Mon Feb 26 11:31:18 2024 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | important |
| References | 1216752 |
Description:
This update for rpm fixes the following issues:
- backport lua support for rpm.execute to ease migrating from SLE Micro 5.5 to 6.0 (bsc#1216752)
| Advisory ID | SUSE-RU-2024:615-1
|
| Released | Mon Feb 26 11:32:32 2024 |
| Summary | Recommended update for netcfg |
| Type | recommended |
| Severity | moderate |
| References | 1211886 |
Description:
This update for netcfg fixes the following issues:
- Add krb-prop entry (bsc#1211886)
SUSE-CU-2024:654-1
| Container Advisory ID | SUSE-CU-2024:654-1 |
| Container Tags | bci/node:18 , bci/node:18-16.9 , bci/nodejs:18 , bci/nodejs:18-16.9 |
| Container Release | 16.9 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:549-1
|
| Released | Tue Feb 20 17:05:52 2024 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | moderate |
| References | 1219243,CVE-2024-0727 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2024-0727: Denial of service when processing a maliciously formatted PKCS12 file (bsc#1219243).
| Advisory ID | SUSE-SU-2024:555-1
|
| Released | Tue Feb 20 17:22:17 2024 |
| Summary | Security update for libxml2 |
| Type | security |
| Severity | moderate |
| References | 1219576,CVE-2024-25062 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2024-25062: Fixed use-after-free in XMLReader (bsc#1219576).
SUSE-CU-2024:625-1
| Container Advisory ID | SUSE-CU-2024:625-1 |
| Container Tags | bci/node:18 , bci/node:18-16.7 , bci/nodejs:18 , bci/nodejs:18-16.7 |
| Container Release | 16.7 |
The following patches have been included in this update:
SUSE-CU-2024:544-1
| Container Advisory ID | SUSE-CU-2024:544-1 |
| Container Tags | bci/node:18 , bci/node:18-16.4 , bci/nodejs:18 , bci/nodejs:18-16.4 |
| Container Release | 16.4 |
The following patches have been included in this update:
SUSE-CU-2024:481-1
| Container Advisory ID | SUSE-CU-2024:481-1 |
| Container Tags | bci/node:18 , bci/node:18-15.20 , bci/nodejs:18 , bci/nodejs:18-15.20 |
| Container Release | 15.20 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:322-1
|
| Released | Fri Feb 2 15:13:26 2024 |
| Summary | Recommended update for aaa_base |
| Type | recommended |
| Severity | moderate |
| References | 1107342,1215434 |
Description:
This update for aaa_base fixes the following issues:
- Set JAVA_HOME correctly (bsc#1107342, bsc#1215434)
| Advisory ID | SUSE-SU-2024:305-1
|
| Released | Mon Mar 11 14:15:37 2024 |
| Summary | Security update for cpio |
| Type | security |
| Severity | moderate |
| References | 1218571,1219238,CVE-2023-7207 |
Description:
This update for cpio fixes the following issues:
- Fixed cpio not extracting correctly when using --no-absolute-filenames option the security fix for CVE-2023-7207 (bsc#1218571, bsc#1219238)
SUSE-CU-2024:415-1
| Container Advisory ID | SUSE-CU-2024:415-1 |
| Container Tags | bci/node:18 , bci/node:18-15.11 , bci/nodejs:18 , bci/nodejs:18-15.11 |
| Container Release | 15.11 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:238-1
|
| Released | Fri Jan 26 10:56:41 2024 |
| Summary | Security update for cpio |
| Type | security |
| Severity | moderate |
| References | 1218571,CVE-2023-7207 |
Description:
This update for cpio fixes the following issues:
- CVE-2023-7207: Fixed a path traversal issue that could lead to an
arbitrary file write during archive extraction (bsc#1218571).
| Advisory ID | SUSE-RU-2024:244-1
|
| Released | Fri Jan 26 13:01:27 2024 |
| Summary | Recommended update for util-linux |
| Type | recommended |
| Severity | moderate |
| References | 1207987 |
Description:
This update for util-linux fixes the following issues:
- Fix performance degradation (bsc#1207987)
SUSE-CU-2024:352-1
| Container Advisory ID | SUSE-CU-2024:352-1 |
| Container Tags | bci/node:18 , bci/node:18-15.7 , bci/nodejs:18 , bci/nodejs:18-15.7 |
| Container Release | 15.7 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:214-1
|
| Released | Wed Jan 24 16:01:31 2024 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | 1214668,1215241,1217460 |
Description:
This update for systemd fixes the following issues:
- resolved: actually check authenticated flag of SOA transaction
- core/mount: Make device deps from /proc/self/mountinfo and .mount unit file exclusive
- core: Add trace logging to mount_add_device_dependencies()
- core/mount: Remove default deps from /proc/self/mountinfo when it is updated (bsc#1217460)
- core/mount: Set Mount.from_proc_self_mountinfo flag before adding default dependencies
- core: wrap some long comment
- utmp-wtmp: Handle EINTR gracefully when waiting to write to tty
- utmp-wtmp: Fix error in case isatty() fails
- homed: Handle EINTR gracefully when waiting for device node
- resolved: Handle EINTR returned from fd_wait_for_event() better
- sd-netlink: Handle EINTR from poll() gracefully, as success
- varlink: Handle EINTR gracefully when waiting for EIO via ppoll()
- stdio-bridge: Don't be bothered with EINTR
- sd-bus: Handle EINTR return from bus_poll() (bsc#1215241)
- core: Replace slice dependencies as they get added (bsc#1214668)
SUSE-CU-2024:272-1
| Container Advisory ID | SUSE-CU-2024:272-1 |
| Container Tags | bci/node:18 , bci/node:18-15.4 , bci/nodejs:18 , bci/nodejs:18-15.4 |
| Container Release | 15.4 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:136-1
|
| Released | Thu Jan 18 09:53:47 2024 |
| Summary | Security update for pam |
| Type | security |
| Severity | moderate |
| References | 1217000,1218475,CVE-2024-22365 |
Description:
This update for pam fixes the following issues:
- CVE-2024-22365: Fixed a local denial of service during PAM login
due to a missing check during path manipulation (bsc#1218475).
- Check localtime_r() return value to fix crashing (bsc#1217000)
| Advisory ID | SUSE-SU-2024:140-1
|
| Released | Thu Jan 18 11:34:58 2024 |
| Summary | Security update for libssh |
| Type | security |
| Severity | important |
| References | 1211188,1211190,1218126,1218186,1218209,CVE-2023-1667,CVE-2023-2283,CVE-2023-48795,CVE-2023-6004,CVE-2023-6918 |
Description:
This update for libssh fixes the following issues:
Security fixes:
- CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209)
- CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126)
- CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186)
- CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188)
- CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190)
Other fixes:
- Update to version 0.9.8
- Allow @ in usernames when parsing from URI composes
- Update to version 0.9.7
- Fix several memory leaks in GSSAPI handling code
SUSE-CU-2024:200-1
| Container Advisory ID | SUSE-CU-2024:200-1 |
| Container Tags | bci/node:18 , bci/node:18-14.1 , bci/nodejs:18 , bci/nodejs:18-14.1 |
| Container Release | 14.1 |
The following patches have been included in this update:
SUSE-CU-2024:176-1
| Container Advisory ID | SUSE-CU-2024:176-1 |
| Container Tags | bci/node:18 , bci/node:18-13.8 , bci/nodejs:18 , bci/nodejs:18-13.8 |
| Container Release | 13.8 |
The following patches have been included in this update:
SUSE-CU-2024:111-1
| Container Advisory ID | SUSE-CU-2024:111-1 |
| Container Tags | bci/node:18 , bci/node:18-13.6 , bci/nodejs:18 , bci/nodejs:18-13.6 |
| Container Release | 13.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2024:70-1
|
| Released | Tue Jan 9 18:29:39 2024 |
| Summary | Security update for tar |
| Type | security |
| Severity | low |
| References | 1217969,CVE-2023-39804 |
Description:
This update for tar fixes the following issues:
- CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969).
SUSE-CU-2024:110-1
| Container Advisory ID | SUSE-CU-2024:110-1 |
| Container Tags | bci/node:18 , bci/node:18-13.4 , bci/nodejs:18 , bci/nodejs:18-13.4 |
| Container Release | 13.4 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2024:62-1
|
| Released | Mon Jan 8 11:44:47 2024 |
| Summary | Recommended update for libxcrypt |
| Type | recommended |
| Severity | moderate |
| References | 1215496 |
Description:
This update for libxcrypt fixes the following issues:
- fix variable name for datamember [bsc#1215496]
- added patches fix https://github.com/besser82/libxcrypt/commit/b212d601549a0fc84cbbcaf21b931f903787d7e2
SUSE-CU-2024:50-1
| Container Advisory ID | SUSE-CU-2024:50-1 |
| Container Tags | bci/node:18 , bci/node:18-13.1 , bci/nodejs:18 , bci/nodejs:18-13.1 |
| Container Release | 13.1 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:4962-1
|
| Released | Fri Dec 22 13:45:06 2023 |
| Summary | Recommended update for curl |
| Type | recommended |
| Severity | important |
| References | 1216987 |
Description:
This update for curl fixes the following issues:
- libssh: Implement SFTP packet size limit (bsc#1216987)
This update also ships curl to the INSTALLER channel.
| Advisory ID | SUSE-RU-2023:4970-1
|
| Released | Mon Dec 25 09:48:21 2023 |
| Summary | Recommended update for icu73_2 |
| Type | recommended |
| Severity | moderate |
| References | 1217354,1217479 |
Description:
This update for icu73_2 fixes the following issue:
- ships 32bit icu library on SLES 15 SP3 to complement the ICU 69 32bit libraries.
SUSE-CU-2023:4251-1
| Container Advisory ID | SUSE-CU-2023:4251-1 |
| Container Tags | bci/node:18 , bci/node:18-12.27 , bci/nodejs:18 , bci/nodejs:18-12.27 |
| Container Release | 12.27 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4891-1
|
| Released | Mon Dec 18 16:31:49 2023 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1201384,1218014,CVE-2023-50495 |
Description:
This update for ncurses fixes the following issues:
- CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014)
- Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384)
SUSE-CU-2023:4152-1
| Container Advisory ID | SUSE-CU-2023:4152-1 |
| Container Tags | bci/node:18 , bci/node:18-12.26 , bci/nodejs:18 , bci/nodejs:18-12.26 |
| Container Release | 12.26 |
The following patches have been included in this update:
SUSE-CU-2023:4090-1
| Container Advisory ID | SUSE-CU-2023:4090-1 |
| Container Tags | bci/node:18 , bci/node:18-12.19 , bci/nodejs:18 , bci/nodejs:18-12.19 |
| Container Release | 12.19 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:4716-1
|
| Released | Mon Dec 11 18:38:23 2023 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1216501 |
Description:
This update for git fixes the following issues:
- Add rule for /etc/gitconfig in gitweb.cgi apparmor profile (bsc#1216501).
- gitweb.cgi AppArmor profile
- make the profile a named profile
- add local/include to make custom additions easier
| Advisory ID | SUSE-RU-2023:4723-1
|
| Released | Tue Dec 12 09:57:51 2023 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | moderate |
| References | 1216862 |
Description:
This update for libtirpc fixes the following issue:
- fix sed parsing in specfile (bsc#1216862)
SUSE-CU-2023:4012-1
| Container Advisory ID | SUSE-CU-2023:4012-1 |
| Container Tags | bci/node:18 , bci/node:18-12.15 , bci/nodejs:18 , bci/nodejs:18-12.15 |
| Container Release | 12.15 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4659-1
|
| Released | Wed Dec 6 13:04:57 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1217573,1217574,CVE-2023-46218,CVE-2023-46219 |
Description:
This update for curl fixes the following issues:
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).
- CVE-2023-46219: HSTS long file name clears contents (bsc#1217574).
| Advisory ID | SUSE-RU-2023:4671-1
|
| Released | Wed Dec 6 14:33:41 2023 |
| Summary | Recommended update for man |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update of man fixes the following problem:
- The 'man' commands is delivered to SUSE Linux Enterprise Micro
to allow browsing man pages.
SUSE-CU-2023:3958-1
| Container Advisory ID | SUSE-CU-2023:3958-1 |
| Container Tags | bci/node:18 , bci/node:18-12.11 , bci/nodejs:18 , bci/nodejs:18-12.11 |
| Container Release | 12.11 |
The following patches have been included in this update:
SUSE-CU-2023:3870-1
| Container Advisory ID | SUSE-CU-2023:3870-1 |
| Container Tags | bci/node:18 , bci/node:18-12.8 , bci/nodejs:18 , bci/nodejs:18-12.8 |
| Container Release | 12.8 |
The following patches have been included in this update:
SUSE-CU-2023:3818-1
| Container Advisory ID | SUSE-CU-2023:3818-1 |
| Container Tags | bci/node:18 , bci/node:18-12.7 , bci/nodejs:18 , bci/nodejs:18-12.7 |
| Container Release | 12.7 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4504-1
|
| Released | Tue Nov 21 13:27:50 2023 |
| Summary | Security update for libxml2 |
| Type | security |
| Severity | moderate |
| References | 1216129,CVE-2023-45322 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129).
| Advisory ID | SUSE-SU-2023:4518-1
|
| Released | Tue Nov 21 17:35:30 2023 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | important |
| References | 1216922,CVE-2023-5678 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922).
SUSE-CU-2023:3745-1
| Container Advisory ID | SUSE-CU-2023:3745-1 |
| Container Tags | bci/node:18 , bci/node:18-11.35 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.35 , bci/nodejs:latest |
| Container Release | 11.35 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4458-1
|
| Released | Thu Nov 16 14:38:48 2023 |
| Summary | Security update for gcc13 |
| Type | security |
| Severity | important |
| References | 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 |
Description:
This update for gcc13 fixes the following issues:
This update ship the GCC 13.2 compiler suite and its base libraries.
The compiler base libraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 12 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available
unsupported via the PackageHub repositories.
To use gcc13 compilers use:
- install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
- override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages.
For a full changelog with all new GCC13 features, check out
https://gcc.gnu.org/gcc-13/changes.html
Detailed changes:
- CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable
length stack allocations. (bsc#1214052)
- Work around third party app crash during C++ standard library initialization. [bsc#1216664]
- Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427)
- Bump included newlib to version 4.3.0.
- Update to GCC trunk head (r13-5254-g05b9868b182bb9)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Turn cross compiler to s390x to a glibc cross. [bsc#1214460]
- Also handle -static-pie in the default-PIE specs
- Fixed missed optimization in Skia resulting in Firefox crashes when
building with LTO. [bsc#1212101]
- Make libstdc++6-devel packages own their directories since they
can be installed standalone. [bsc#1211427]
- Add new x86-related intrinsics (amxcomplexintrin.h).
- RISC-V: Add support for inlining subword atomic operations
- Use --enable-link-serialization rather that --enable-link-mutex,
the benefit of the former one is that the linker jobs are not
holding tokens of the make's jobserver.
- Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd
for the general state of BPF with GCC.
- Add bootstrap conditional to allow --without=bootstrap to be
specified to speed up local builds for testing.
- Bump included newlib to version 4.3.0.
- Also package libhwasan_preinit.o on aarch64.
- Configure external timezone database provided by the timezone
package. Make libstdc++6 recommend timezone to get a fully
working std::chrono. Install timezone when running the testsuite.
- Package libhwasan_preinit.o on x86_64.
- Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
- Enable PRU flavour for gcc13
- update floatn fixinclude pickup to check each header separately (bsc#1206480)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Bump libgo SONAME to libgo22.
- Do not package libhwasan for biarch (32-bit architecture)
as the extension depends on 64-bit pointers.
- Adjust floatn fixincludes guard to work with SLE12 and earlier
SLE15.
- Depend on at least LLVM 13 for GCN cross compiler.
- Update embedded newlib to version 4.2.0
- Allow cross-pru-gcc12-bootstrap for armv7l architecture.
PRU architecture is used for real-time MCUs embedded into TI
armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for
armv7l in order to build both host applications and PRU firmware
during the same build.
SUSE-CU-2023:3663-1
| Container Advisory ID | SUSE-CU-2023:3663-1 |
| Container Tags | bci/node:18 , bci/node:18-11.30 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.30 , bci/nodejs:latest |
| Container Release | 11.30 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:4310-1
|
| Released | Tue Oct 31 14:10:47 2023 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | moderate |
| References | 1196647 |
Description:
This Update for libtirpc to 1.3.4, fixing the following issues:
Update to 1.3.4 (bsc#1199467)
* binddynport.c honor ip_local_reserved_ports
- replaces: binddynport-honor-ip_local_reserved_ports.patch
* gss-api: expose gss major/minor error in authgss_refresh()
* rpcb_clnt.c: Eliminate double frees in delete_cache()
* rpcb_clnt.c: memory leak in destroy_addr
* portmapper: allow TCP-only portmapper
* getnetconfigent: avoid potential DoS issue by removing unnecessary sleep
* clnt_raw.c: fix a possible null pointer dereference
* bindresvport.c: fix a potential resource leakage
Update to 1.3.3:
- Fix DoS vulnerability in libtirpc
- replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch
- _rpc_dtablesize: use portable system call
- libtirpc: Fix use-after-free accessing the error number
- Fix potential memory leak of parms.r_addr
- replaces 0001-fix-parms.r_addr-memory-leak.patch
- rpcb_clnt.c add mechanism to try v2 protocol first
- preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch
- Eliminate deadlocks in connects with an MT environment
- clnt_dg_freeres() uncleared set active state may deadlock
- thread safe clnt destruction
- SUNRPC: mutexed access blacklist_read state variable
- SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c
Update to 1.3.2:
- Replace the final SunRPC licenses with BSD licenses
- blacklist: Add a few more well known ports
- libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS
Update to 1.3.1:
- Remove AUTH_DES interfaces from auth_des.h
The unsupported AUTH_DES authentication has be
compiled out since commit d918e41d889 (Wed Oct 9 2019)
replaced by API routines that return errors.
- svc_dg: Free xp_netid during destroy
- Fix memory management issues of fd locks
- libtirpc: replace array with list for per-fd locks
- __svc_vc_dodestroy: fix double free of xp_ltaddr.buf
- __rpc_dtbsize: rlim_cur instead of rlim_max
- pkg-config: use the correct replacements for libdir/includedir
SUSE-CU-2023:3565-1
| Container Advisory ID | SUSE-CU-2023:3565-1 |
| Container Tags | bci/node:18 , bci/node:18-11.25 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.25 , bci/nodejs:latest |
| Container Release | 11.25 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4200-1
|
| Released | Wed Oct 25 12:04:29 2023 |
| Summary | Security update for nghttp2 |
| Type | security |
| Severity | important |
| References | 1216123,1216174,CVE-2023-44487 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2023-44487: Fixed HTTP/2 Rapid Reset attack. (bsc#1216174)
| Advisory ID | SUSE-SU-2023:4215-1
|
| Released | Thu Oct 26 12:19:25 2023 |
| Summary | Security update for zlib |
| Type | security |
| Severity | moderate |
| References | 1216378,CVE-2023-45853 |
Description:
This update for zlib fixes the following issues:
- CVE-2023-45853: Fixed an integer overflow that would lead to a
buffer overflow in the minizip subcomponent (bsc#1216378).
SUSE-CU-2023:3548-1
| Container Advisory ID | SUSE-CU-2023:3548-1 |
| Container Tags | bci/node:18 , bci/node:18-11.22 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.22 , bci/nodejs:latest |
| Container Release | 11.22 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4162-1
|
| Released | Mon Oct 23 15:33:03 2023 |
| Summary | Security update for gcc13 |
| Type | security |
| Severity | important |
| References | 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039 |
Description:
This update for gcc13 fixes the following issues:
This update ship the GCC 13.2 compiler suite and its base libraries.
The compiler base libraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 12 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available
unsupported via the PackageHub repositories.
To use gcc13 compilers use:
- install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
- override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages.
For a full changelog with all new GCC13 features, check out
https://gcc.gnu.org/gcc-13/changes.html
Detailed changes:
- CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable
length stack allocations. (bsc#1214052)
- Turn cross compiler to s390x to a glibc cross. [bsc#1214460]
- Also handle -static-pie in the default-PIE specs
- Fixed missed optimization in Skia resulting in Firefox crashes when
building with LTO. [bsc#1212101]
- Make libstdc++6-devel packages own their directories since they
can be installed standalone. [bsc#1211427]
- Add new x86-related intrinsics (amxcomplexintrin.h).
- RISC-V: Add support for inlining subword atomic operations
- Use --enable-link-serialization rather that --enable-link-mutex,
the benefit of the former one is that the linker jobs are not
holding tokens of the make's jobserver.
- Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd
for the general state of BPF with GCC.
- Add bootstrap conditional to allow --without=bootstrap to be
specified to speed up local builds for testing.
- Bump included newlib to version 4.3.0.
- Also package libhwasan_preinit.o on aarch64.
- Configure external timezone database provided by the timezone
package. Make libstdc++6 recommend timezone to get a fully
working std::chrono. Install timezone when running the testsuite.
- Package libhwasan_preinit.o on x86_64.
- Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
- Enable PRU flavour for gcc13
- update floatn fixinclude pickup to check each header separately (bsc#1206480)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Bump libgo SONAME to libgo22.
- Do not package libhwasan for biarch (32-bit architecture)
as the extension depends on 64-bit pointers.
- Adjust floatn fixincludes guard to work with SLE12 and earlier
SLE15.
- Depend on at least LLVM 13 for GCN cross compiler.
- Update embedded newlib to version 4.2.0
- Allow cross-pru-gcc12-bootstrap for armv7l architecture.
PRU architecture is used for real-time MCUs embedded into TI
armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for
armv7l in order to build both host applications and PRU firmware
during the same build.
SUSE-CU-2023:3513-1
| Container Advisory ID | SUSE-CU-2023:3513-1 |
| Container Tags | bci/node:18 , bci/node:18-11.20 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.20 , bci/nodejs:latest |
| Container Release | 11.20 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3563-1
|
| Released | Fri Sep 8 15:28:17 2023 |
| Summary | Security update for icu73_2 |
| Type | security |
| Severity | moderate |
| References | 1030253,1095425,1103893,1112183,1146907,1158955,1159131,1161007,1162882,1166844,1167603,1182252,1182645,1192935,1193951,354372,437293,824262,CVE-2020-10531,CVE-2020-21913 |
Description:
This update for icu73_2 fixes the following issues:
* CLDR extends the support for “short†Chinese sort orders to
cover some additional, required characters for Level 2. This
is carried over into ICU collation.
* ICU has a modified character conversion table, mapping some
GB18030 characters to Unicode characters that were encoded
after GB18030-2005.
- fixes builds where UCHAR_TYPE is re-defined such as libqt5-qtwebengine
* Improved Japanese and Korean short-text line breaking
* Reduction of C++ memory use in date formatting
* Support for Unicode 15, including new characters, scripts,
emoji, and corresponding API constants.
* Support for CLDR 42 locale data with various additions and
corrections.
* Shift to tzdb 2022e. Pre-1970 data for a number of timezones
has been removed.
- bump library packagename to libicu71 to match the version.
* updates to CLDR 41 locale data with various additions and corrections.
* phrase-based line breaking for Japanese. Existing line breaking methods
follow standards and conventions for body text but do not work well for
short Japanese text, such as in titles and headings. This new feature is
optimized for these use cases.
* support for Hindi written in Latin letters (hi_Latn). The CLDR data for
this increasingly popular locale has been significantly revised and
expanded. Note that based on user expectations, hi_Latn incorporates a
large amount of English, and can also be referred to as “Hinglishâ€.
* time zone data updated to version 2022a. Note that pre-1970 data for a
number of time zones has been removed, as has been the case in the upstream
tzdata release since 2021b.
- ICU-21793 Fix ucptrietest golden diff [bsc#1192935]
* Unicode 14 (new characters, scripts, emoji, and API constants)
* CLDR 40 (many additions and corrections)
* Fixes for measurement unit formatting
* Can now be built with up to C++20 compilers
- ICU-21613 Fix undefined behaviour in ComplexUnitsConverter::applyRounder
* CLDR 39
* For Norwegian, 'no' is back to being the canonical code, with
'nb' treated as equivalent. This aligns handling of Norwegian
with other macro language codes.
* Binary prefixes in measurement units (KiB, MiB, etc.)
* Time zone offsets from local time: New APIs
BasicTimeZone::getOffsetFromLocal() (C++) and
ucal_getTimeZoneOffsetFromLocal()
- Backport ICU-21366 (bsc#1182645)
* Fix memory problem in FormattedStringBuilder
* Fix assertion when setKeywordValue w/ long value.
* Fix UBSan breakage on 8bit of rbbi
* fix int32_t overflow in listFormat
* Fix memory handling in MemoryPool::operator=()
* Fix memory leak in AliasReplacer
- Add back icu.keyring, see https://unicode-org.atlassian.net/browse/ICU-21361
* CLDR 38
* Measurement unit preferences
* PluralRules selection for ranges of numbers
* Locale ID canonicalization now conforms to the CLDR spec
including edge cases
* DateIntervalFormat supports output options such as capitalization
* Measurement units are normalized in skeleton string output
* Time zone data (tzdata) version 2020d
- Add the provides for libicu to Make .Net core can install
successfully. (bsc#1167603, bsc#1161007)
* Unicode 13 (ICU-20893, same as in ICU 66)
+ Total of 5930 new characters
+ 4 new scripts
+ 55 new emoji characters, plus additional new sequences
+ New CJK extension, first characters in plane 3: U+30000..U+3134A
* CLDR 37
+ New language at Modern coverage: Nigerian Pidgin
+ New languages at Basic coverage: Fulah (Adlam), Maithili,
Manipuri, Santali, Sindhi (Devanagari), Sundanese
+ Region containment: EU no longer includes GB
+ Unicode 13 root collation data and Chinese data for collation and transliteration
* DateTimePatternGenerator now obeys the 'hc' preference in the locale identifier (ICU-20442)
* Various other improvements for ECMA-402 conformance
* Number skeletons have a new 'concise' form that can be used in MessageFormat strings (ICU-20418)
* Currency formatting options for formal and other currency display name variants (ICU-20854)
* ListFormatter: new public API to select the style & type (ICU-12863)
* ListFormatter now selects the proper “andâ€/“or†form for Spanish & Hebrew (ICU-21016)
* Locale ID canonicalization upgraded to implement the complete CLDR spec (ICU-20834, ICU-20272)
* LocaleMatcher: New option to ignore one-way matches (ICU-20936),
and other tweaks to the code (ICU-20916, ICU-20917) and data (from CLDR)
* acceptLanguage() reimplemented via LocaleMatcher (ICU-20700)
* Data build tool: tzdbNames.res moved from the 'zone_tree' category to the 'zone_supplemental' category (ICU-21073)
* Fixed uses of u8'literals' broken by the C++20 introduction of the incompatible char8_t type (ICU-20972),
* and added a few API overloads to reduce the need for reinterpret_cast (ICU-20984).
* Support for manipulating CLDR 37 unit identifiers in MeasureUnit.
* Fix potential integer overflow in UnicodeString:doAppend (bsc#1166844, CVE-2020-10531).
* Unicode 13 support
* Fix uses of u8'literals' broken by C++20 introduction of
incompatible char8_t type. (ICU-20972)
* use LocalMemory for cmd to prevent use after free
(bsc#1193951 CVE-2020-21913).
- Remove /usr/lib(64)/icu/current [bsc#1158955].
- Update to release 65.1 (jsc#SLE-11118).
* Updated to CLDR 36 locale data with many additions and
corrections, and some new measurement units.
* The Java LocaleMatcher API is improved, and ported to C++.
| Advisory ID | SUSE-RU-2023:4073-1
|
| Released | Fri Oct 13 11:40:26 2023 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | low |
| References | |
Description:
This update for rpm fixes the following issue:
- Enables build for all python modules (jsc#PED-68, jsc#PED-1988)
| Advisory ID | SUSE-RU-2023:4105-1
|
| Released | Wed Oct 18 08:15:40 2023 |
| Summary | Recommended update for openssl-1_1 |
| Type | recommended |
| Severity | moderate |
| References | 1215215 |
Description:
This update for openssl-1_1 fixes the following issues:
- Displays 'fips' in the version string (bsc#1215215)
| Advisory ID | SUSE-SU-2023:4110-1
|
| Released | Wed Oct 18 12:35:26 2023 |
| Summary | Security update for glibc |
| Type | security |
| Severity | important |
| References | 1215286,1215891,CVE-2023-4813 |
Description:
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-4813: Fixed a potential use-after-free in gaih_inet() (bsc#1215286, BZ #28931)
Also a regression from a previous update was fixed:
- elf: Align argument of __munmap to page size (bsc#1215891, BZ #28676)
| Advisory ID | SUSE-SU-2023:4133-1
|
| Released | Thu Oct 19 12:03:10 2023 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1216190,1216205,1216272,1216273,CVE-2023-38552,CVE-2023-39333,CVE-2023-44487,CVE-2023-45143 |
Description:
This update for nodejs18 fixes the following issues:
- Update to version 18.18.2
- CVE-2023-44487: Fixed the Rapid Reset attack in nghttp2. (bsc#1216190)
- CVE-2023-45143: Fixed a cookie leakage in undici. (bsc#1216205)
- CVE-2023-38552: Fixed an integrity checks according to policies that could be circumvented. (bsc#1216272)
- CVE-2023-39333: Fixed a code injection via WebAssembly export names. (bsc#1216273)
| Advisory ID | SUSE-RU-2023:4153-1
|
| Released | Fri Oct 20 19:27:58 2023 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | 1215313 |
Description:
This update for systemd fixes the following issues:
- Fix mismatch of nss-resolve version in Package Hub (no source code changes)
| Advisory ID | SUSE-RU-2023:4154-1
|
| Released | Fri Oct 20 19:33:25 2023 |
| Summary | Recommended update for aaa_base |
| Type | recommended |
| Severity | moderate |
| References | 1107342,1215434 |
Description:
This update for aaa_base fixes the following issues:
- Respect /etc/update-alternatives/java when setting JAVA_HOME (bsc#1215434,bsc#1107342)
SUSE-CU-2023:3382-1
| Container Advisory ID | SUSE-CU-2023:3382-1 |
| Container Tags | bci/node:18 , bci/node:18-11.10 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.10 , bci/nodejs:latest |
| Container Release | 11.10 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:4024-1
|
| Released | Tue Oct 10 13:24:40 2023 |
| Summary | Security update for shadow |
| Type | security |
| Severity | low |
| References | 1214806,CVE-2023-4641 |
Description:
This update for shadow fixes the following issues:
- CVE-2023-4641: Fixed potential password leak (bsc#1214806).
| Advisory ID | SUSE-SU-2023:4044-1
|
| Released | Wed Oct 11 09:01:14 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1215888,1215889,CVE-2023-38545,CVE-2023-38546 |
Description:
This update for curl fixes the following issues:
- CVE-2023-38545: Fixed a heap buffer overflow in SOCKS5. (bsc#1215888)
- CVE-2023-38546: Fixed a cookie injection with none file. (bsc#1215889)
SUSE-CU-2023:3341-1
| Container Advisory ID | SUSE-CU-2023:3341-1 |
| Container Tags | bci/node:18 , bci/node:18-11.7 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.7 , bci/nodejs:latest |
| Container Release | 11.7 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3994-1
|
| Released | Fri Oct 6 13:44:15 2023 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1215533 |
Description:
This update for git fixes the following issues:
- Downgrade openssh dependency to recommends (bsc#1215533)
| Advisory ID | SUSE-SU-2023:3997-1
|
| Released | Fri Oct 6 14:13:56 2023 |
| Summary | Security update for nghttp2 |
| Type | security |
| Severity | important |
| References | 1215713,CVE-2023-35945 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713).
SUSE-CU-2023:3290-1
| Container Advisory ID | SUSE-CU-2023:3290-1 |
| Container Tags | bci/node:18 , bci/node:18-11.5 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.5 , bci/nodejs:latest |
| Container Release | 11.5 |
The following patches have been included in this update:
SUSE-CU-2023:3252-1
| Container Advisory ID | SUSE-CU-2023:3252-1 |
| Container Tags | bci/node:18 , bci/node:18-11.3 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-11.3 , bci/nodejs:latest |
| Container Release | 11.3 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3954-1
|
| Released | Tue Oct 3 20:09:47 2023 |
| Summary | Security update for libeconf |
| Type | security |
| Severity | important |
| References | 1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 |
Description:
This update for libeconf fixes the following issues:
Update to version 0.5.2.
- CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078).
- CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078)
SUSE-CU-2023:3167-1
| Container Advisory ID | SUSE-CU-2023:3167-1 |
| Container Tags | bci/node:18 , bci/node:18-10.5 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-10.5 , bci/nodejs:latest |
| Container Release | 10.5 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3814-1
|
| Released | Wed Sep 27 18:08:17 2023 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1211829,1212819,1212910 |
Description:
This update for glibc fixes the following issues:
- nscd: Fix netlink cache invalidation if epoll is used (bsc#1212910, BZ #29415)
- Restore lookup of IPv4 mapped addresses in files database (bsc#1212819, BZ #25457)
- elf: Remove excessive p_align check on PT_LOAD segments (bsc#1211829, BZ #28688)
- elf: Properly align PT_LOAD segments (bsc#1211829, BZ #28676)
- ld.so: Always use MAP_COPY to map the first segment (BZ #30452)
- add GB18030-2022 charmap (jsc#PED-4908, BZ #30243)
| Advisory ID | SUSE-SU-2023:3823-1
|
| Released | Wed Sep 27 18:42:38 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1215026,CVE-2023-38039 |
Description:
This update for curl fixes the following issues:
- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)
SUSE-CU-2023:3142-1
| Container Advisory ID | SUSE-CU-2023:3142-1 |
| Container Tags | bci/node:18 , bci/node:18-10.2 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-10.2 , bci/nodejs:latest |
| Container Release | 10.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3780-1
|
| Released | Tue Sep 26 10:58:21 2023 |
| Summary | Recommended update hidapi |
| Type | recommended |
| Severity | moderate |
| References | 1214535 |
Description:
This update for hidapi ships the missing libhidapi-raw0 library to SLE and Leap Micro 5.3 and 5.4.
SUSE-CU-2023:3120-1
| Container Advisory ID | SUSE-CU-2023:3120-1 |
| Container Tags | bci/node:18 , bci/node:18-10.1 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-10.1 , bci/nodejs:latest |
| Container Release | 10.1 |
The following patches have been included in this update:
SUSE-CU-2023:3046-1
| Container Advisory ID | SUSE-CU-2023:3046-1 |
| Container Tags | bci/node:18 , bci/node:18-9.33 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.33 , bci/nodejs:latest |
| Container Release | 9.33 |
The following patches have been included in this update:
SUSE-CU-2023:3032-1
| Container Advisory ID | SUSE-CU-2023:3032-1 |
| Container Tags | bci/node:18 , bci/node:18-9.32 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.32 , bci/nodejs:latest |
| Container Release | 9.32 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3661-1
|
| Released | Mon Sep 18 21:44:09 2023 |
| Summary | Security update for gcc12 |
| Type | security |
| Severity | important |
| References | 1214052,CVE-2023-4039 |
Description:
This update for gcc12 fixes the following issues:
- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).
| Advisory ID | SUSE-SU-2023:3666-1
|
| Released | Mon Sep 18 21:52:18 2023 |
| Summary | Security update for libxml2 |
| Type | security |
| Severity | important |
| References | 1214768,CVE-2023-39615 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).
SUSE-CU-2023:2988-1
| Container Advisory ID | SUSE-CU-2023:2988-1 |
| Container Tags | bci/node:18 , bci/node:18-9.30 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.30 , bci/nodejs:latest |
| Container Release | 9.30 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3611-1
|
| Released | Fri Sep 15 09:28:36 2023 |
| Summary | Recommended update for sysuser-tools |
| Type | recommended |
| Severity | moderate |
| References | 1195391,1205161,1207778,1213240,1214140 |
Description:
This update for sysuser-tools fixes the following issues:
- Update to version 3.2
- Always create a system group of the same name as the system user (bsc#1205161, bsc#1207778, bsc#1213240)
- Add 'quilt setup' friendly hint to %sysusers_requires usage
- Use append so if a pre file already exists it isn't overridden
- Invoke bash for bash scripts (bsc#1195391)
- Remove all systemd requires not supported on SLE15 (bsc#1214140)
SUSE-CU-2023:2926-1
| Container Advisory ID | SUSE-CU-2023:2926-1 |
| Container Tags | bci/node:18 , bci/node:18-9.28 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.28 , bci/nodejs:latest |
| Container Release | 9.28 |
The following patches have been included in this update:
SUSE-CU-2023:2890-1
| Container Advisory ID | SUSE-CU-2023:2890-1 |
| Container Tags | bci/node:18 , bci/node:18-9.27 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.27 , bci/nodejs:latest |
| Container Release | 9.27 |
The following patches have been included in this update:
SUSE-CU-2023:2855-1
| Container Advisory ID | SUSE-CU-2023:2855-1 |
| Container Tags | bci/node:18 , bci/node:18-9.24 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.24 , bci/nodejs:latest |
| Container Release | 9.24 |
The following patches have been included in this update:
SUSE-CU-2023:2784-1
| Container Advisory ID | SUSE-CU-2023:2784-1 |
| Container Tags | bci/node:18 , bci/node:18-9.23 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.23 , bci/nodejs:latest |
| Container Release | 9.23 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3410-1
|
| Released | Thu Aug 24 06:56:32 2023 |
| Summary | Recommended update for audit |
| Type | recommended |
| Severity | moderate |
| References | 1201519,1204844 |
Description:
This update for audit fixes the following issues:
- Create symbolic link from /sbin/audisp-syslog to /usr/sbin/audisp-syslog (bsc#1201519)
- Fix rules not loaded when restarting auditd.service (bsc#1204844)
| Advisory ID | SUSE-RU-2023:3451-1
|
| Released | Mon Aug 28 12:15:22 2023 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | 1186606,1194609,1208194,1209741,1210702,1211576,1212434,1213185,1213575,1213873 |
Description:
This update for systemd fixes the following issues:
- Fix reboot and shutdown issues by getting only active MD arrays (bsc#1211576, bsc#1212434, bsc#1213575)
- Decrease devlink priority for iso disks (bsc#1213185)
- Do not ignore mount point paths longer than 255 characters (bsc#1208194)
- Refuse hibernation if there's no possible way to resume (bsc#1186606)
- Update 'korean' and 'arabic' keyboard layouts (bsc#1210702)
- Drop some entries no longer needed by YaST (bsc#1194609)
- The 'systemd --user' instances get their own session keyring instead of the user default one (bsc#1209741)
- Dynamically allocate receive buffer to handle large amount of mounts (bsc#1213873)
SUSE-CU-2023:2749-1
| Container Advisory ID | SUSE-CU-2023:2749-1 |
| Container Tags | bci/node:18 , bci/node:18-9.15 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.15 , bci/nodejs:latest |
| Container Release | 9.15 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3378-1
|
| Released | Tue Aug 22 18:35:14 2023 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1214150,1214154,1214156,CVE-2023-32002,CVE-2023-32006,CVE-2023-32559 |
Description:
This update for nodejs18 fixes the following issues:
Update to LTS version 18.17.1.
- CVE-2023-32002: Fixed permissions policies bypass via Module._load (bsc#1214150).
- CVE-2023-32006: Fixed permissions policies impersonation using module.constructor.createRequire() (bsc#1214156).
- CVE-2023-32559: Fixed permissions policies bypass via process.binding (bsc#1214154).
SUSE-CU-2023:2696-1
| Container Advisory ID | SUSE-CU-2023:2696-1 |
| Container Tags | bci/node:18 , bci/node:18-9.13 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.13 , bci/nodejs:latest |
| Container Release | 9.13 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3325-1
|
| Released | Wed Aug 16 08:26:08 2023 |
| Summary | Security update for krb5 |
| Type | security |
| Severity | important |
| References | 1214054,CVE-2023-36054 |
Description:
This update for krb5 fixes the following issues:
- CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054)
| Advisory ID | SUSE-SU-2023:3327-1
|
| Released | Wed Aug 16 08:45:25 2023 |
| Summary | Security update for pcre2 |
| Type | security |
| Severity | moderate |
| References | 1213514,CVE-2022-41409 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514).
SUSE-CU-2023:2640-1
| Container Advisory ID | SUSE-CU-2023:2640-1 |
| Container Tags | bci/node:18 , bci/node:18-9.11 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.11 , bci/nodejs:latest |
| Container Release | 9.11 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3285-1
|
| Released | Fri Aug 11 10:30:38 2023 |
| Summary | Recommended update for shadow |
| Type | recommended |
| Severity | moderate |
| References | 1206627,1213189 |
Description:
This update for shadow fixes the following issues:
- Prevent lock files from remaining after power interruptions (bsc#1213189)
- Add --prefix support to passwd, chpasswd and chage (bsc#1206627)
SUSE-CU-2023:2605-1
| Container Advisory ID | SUSE-CU-2023:2605-1 |
| Container Tags | bci/node:18 , bci/node:18-9.9 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.9 , bci/nodejs:latest |
| Container Release | 9.9 |
The following patches have been included in this update:
SUSE-CU-2023:2556-1
| Container Advisory ID | SUSE-CU-2023:2556-1 |
| Container Tags | bci/node:18 , bci/node:18-9.8 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.8 , bci/nodejs:latest |
| Container Release | 9.8 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:3242-1
|
| Released | Tue Aug 8 18:19:40 2023 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | moderate |
| References | 1213853,CVE-2023-3817 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853)
SUSE-CU-2023:2502-1
| Container Advisory ID | SUSE-CU-2023:2502-1 |
| Container Tags | bci/node:18 , bci/node:18-9.5 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.5 , bci/nodejs:latest |
| Container Release | 9.5 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:3102-1
|
| Released | Tue Aug 1 14:11:53 2023 |
| Summary | Recommended update for openssl-1_1 |
| Type | recommended |
| Severity | moderate |
| References | 1213517 |
Description:
This update for openssl-1_1 fixes the following issues:
- Dont pass zero length input to EVP_Cipher (bsc#1213517)
SUSE-CU-2023:2479-1
| Container Advisory ID | SUSE-CU-2023:2479-1 |
| Container Tags | bci/node:18 , bci/node:18-9.1 , bci/node:latest , bci/nodejs:18 , bci/nodejs:18-9.1 , bci/nodejs:latest |
| Container Release | 9.1 |
The following patches have been included in this update:
SUSE-CU-2023:2444-1
| Container Advisory ID | SUSE-CU-2023:2444-1 |
| Container Tags | bci/node:18 , bci/node:18-8.18 , bci/nodejs:18 , bci/nodejs:18-8.18 |
| Container Release | 8.18 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2965-1
|
| Released | Tue Jul 25 12:30:22 2023 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | moderate |
| References | 1213487,CVE-2023-3446 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487).
| Advisory ID | SUSE-RU-2023:2966-1
|
| Released | Tue Jul 25 14:26:14 2023 |
| Summary | Recommended update for libxml2 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for libxml2 fixes the following issues:
- Build also for modern python version (jsc#PED-68)
SUSE-CU-2023:2415-1
| Container Advisory ID | SUSE-CU-2023:2415-1 |
| Container Tags | bci/node:18 , bci/node:18-8.14 , bci/nodejs:18 , bci/nodejs:18-8.14 |
| Container Release | 8.14 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2945-1
|
| Released | Mon Jul 24 09:37:30 2023 |
| Summary | Security update for openssh |
| Type | security |
| Severity | important |
| References | 1186673,1209536,1213004,1213008,1213504,CVE-2023-38408 |
Description:
This update for openssh fixes the following issues:
- CVE-2023-38408: Fixed a condition where specific libaries loaded via
ssh-agent(1)'s PKCS#11 support could be abused to achieve remote code
execution via a forwarded agent socket if those libraries were present on the
victim's system and if the agent was forwarded to an attacker-controlled
system. [bsc#1213504, CVE-2023-38408]
- Close the right filedescriptor and also close fdh in read_hmac to avoid file
descriptor leaks. [bsc#1209536]
- Attempts to mitigate instances of secrets lingering in memory after a session
exits. [bsc#1186673, bsc#1213004, bsc#1213008]
SUSE-CU-2023:2371-1
| Container Advisory ID | SUSE-CU-2023:2371-1 |
| Container Tags | bci/node:18 , bci/node:18-8.13 , bci/nodejs:18 , bci/nodejs:18-8.13 |
| Container Release | 8.13 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2882-1
|
| Released | Wed Jul 19 11:49:39 2023 |
| Summary | Security update for perl |
| Type | security |
| Severity | important |
| References | 1210999,CVE-2023-31484 |
Description:
This update for perl fixes the following issues:
- CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).
| Advisory ID | SUSE-RU-2023:2885-1
|
| Released | Wed Jul 19 16:58:43 2023 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1208721,1209229,1211828 |
Description:
This update for glibc fixes the following issues:
- getlogin_r: fix missing fallback if loginuid is unset (bsc#1209229, BZ #30235)
- Exclude static archives from preparation for live patching (bsc#1208721)
- resolv_conf: release lock on allocation failure (bsc#1211828, BZ #30527)
| Advisory ID | SUSE-SU-2023:2891-1
|
| Released | Wed Jul 19 21:14:33 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1213237,CVE-2023-32001 |
Description:
This update for curl fixes the following issues:
- CVE-2023-32001: Fixed TOCTOU race condition (bsc#1213237).
| Advisory ID | SUSE-RU-2023:2922-1
|
| Released | Thu Jul 20 18:34:03 2023 |
| Summary | Recommended update for libfido2 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for libfido2 fixes the following issues:
- Use openssl 1.1 still on SUSE Linux Enterprise 15 to avoid pulling unneeded
openssl-3 dependency. (jsc#PED-4521)
SUSE-CU-2023:2324-1
| Container Advisory ID | SUSE-CU-2023:2324-1 |
| Container Tags | bci/node:18 , bci/node:18-8.6 , bci/nodejs:18 , bci/nodejs:18-8.6 |
| Container Release | 8.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2023:2827-1
|
| Released | Fri Jul 14 11:27:47 2023 |
| Summary | Recommended update for libxml2 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for libxml2 fixes the following issues:
- Build also for modern python version (jsc#PED-68)
| Advisory ID | SUSE-RU-2023:2847-1
|
| Released | Mon Jul 17 08:40:42 2023 |
| Summary | Recommended update for audit |
| Type | recommended |
| Severity | moderate |
| References | 1210004 |
Description:
This update for audit fixes the following issues:
- Check for AF_UNIX unnamed sockets (bsc#1210004)
- Enable livepatching on main library on x86_64
| Advisory ID | SUSE-RU-2023:2855-1
|
| Released | Mon Jul 17 16:35:21 2023 |
| Summary | Recommended update for openldap2 |
| Type | recommended |
| Severity | moderate |
| References | 1212260 |
Description:
This update for openldap2 fixes the following issues:
- libldap2 crashes on ldap_sasl_bind_s (bsc#1212260)
SUSE-CU-2023:2278-1
| Container Advisory ID | SUSE-CU-2023:2278-1 |
| Container Tags | bci/node:18 , bci/node:18-8.1 , bci/nodejs:18 , bci/nodejs:18-8.1 |
| Container Release | 8.1 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2620-1
|
| Released | Fri Jun 23 13:41:36 2023 |
| Summary | Security update for openssl-3 |
| Type | security |
| Severity | moderate |
| References | 1210714,1211430,CVE-2023-1255,CVE-2023-2650 |
Description:
This update for openssl-3 fixes the following issues:
- CVE-2023-1255: Fixed input buffer over-read in AES-XTS implementation on 64 bit ARM (bsc#1210714).
- CVE-2023-2650: Fixed possible DoS translating ASN.1 object identifiers (bsc#1211430).
| Advisory ID | SUSE-RU-2023:2811-1
|
| Released | Wed Jul 12 11:56:18 2023 |
| Summary | Recommended update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt fixes the following issues:
This update provides a feature update to the FIDO2 stack.
Changes in libfido2:
- Version 1.13.0 (2023-02-20)
* New API calls:
+ fido_assert_empty_allow_list;
+ fido_cred_empty_exclude_list.
* fido2-token: fix issue when listing large blobs.
- Version 1.12.0 (2022-09-22)
* Support for COSE_ES384.
* Improved support for FIDO 2.1 authenticators.
* New API calls:
+ es384_pk_free;
+ es384_pk_from_EC_KEY;
+ es384_pk_from_EVP_PKEY;
+ es384_pk_from_ptr;
+ es384_pk_new;
+ es384_pk_to_EVP_PKEY;
+ fido_cbor_info_certs_len;
+ fido_cbor_info_certs_name_ptr;
+ fido_cbor_info_certs_value_ptr;
+ fido_cbor_info_maxrpid_minpinlen;
+ fido_cbor_info_minpinlen;
+ fido_cbor_info_new_pin_required;
+ fido_cbor_info_rk_remaining;
+ fido_cbor_info_uv_attempts;
+ fido_cbor_info_uv_modality.
* Documentation and reliability fixes.
- Version 1.11.0 (2022-05-03)
* Experimental PCSC support; enable with -DUSE_PCSC.
* Improved OpenSSL 3.0 compatibility.
* Use RFC1951 raw deflate to compress CTAP 2.1 largeBlobs.
* winhello: advertise 'uv' instead of 'clientPin'.
* winhello: support hmac-secret in fido_dev_get_assert().
* New API calls:
+ fido_cbor_info_maxlargeblob.
* Documentation and reliability fixes.
* Separate build and regress targets.
- Version 1.10.0 (2022-01-17)
* bio: fix CTAP2 canonical CBOR encoding in fido_bio_dev_enroll_*(); gh#480.
* New API calls:
- fido_dev_info_set;
- fido_dev_io_handle;
- fido_dev_new_with_info;
- fido_dev_open_with_info.
* Cygwin and NetBSD build fixes.
* Documentation and reliability fixes.
* Support for TPM 2.0 attestation of COSE_ES256 credentials.
- Version 1.9.0 (2021-10-27)
* Enabled NFC support on Linux.
* Support for FIDO 2.1 'minPinLength' extension.
* Support for COSE_EDDSA, COSE_ES256, and COSE_RS1 attestation.
* Support for TPM 2.0 attestation.
* Support for device timeouts; see fido_dev_set_timeout().
* New API calls:
- es256_pk_from_EVP_PKEY;
- fido_cred_attstmt_len;
- fido_cred_attstmt_ptr;
- fido_cred_pin_minlen;
- fido_cred_set_attstmt;
- fido_cred_set_pin_minlen;
- fido_dev_set_pin_minlen_rpid;
- fido_dev_set_timeout;
- rs256_pk_from_EVP_PKEY.
* Reliability and portability fixes.
* Better handling of HID devices without identification strings; gh#381.
* Better support for FIDO 2.1 authenticators.
* Support for attestation format 'none'.
* New API calls:
- fido_assert_set_clientdata;
- fido_cbor_info_algorithm_cose;
- fido_cbor_info_algorithm_count;
- fido_cbor_info_algorithm_type;
- fido_cbor_info_transports_len;
- fido_cbor_info_transports_ptr;
- fido_cred_set_clientdata;
- fido_cred_set_id;
- fido_credman_set_dev_rk;
- fido_dev_is_winhello.
* fido2-token: new -Sc option to update a resident credential.
* Documentation and reliability fixes.
* HID access serialisation on Linux.
* hid_win: detect devices with vendor or product IDs > 0x7fff
* Support for FIDO 2.1 authenticator configuration.
* Support for FIDO 2.1 UV token permissions.
* Support for FIDO 2.1 'credBlobs' and 'largeBlobs' extensions.
* New API calls
* New fido_init flag to disable fido_dev_open’s U2F fallback
* Experimental NFC support on Linux.
- Enabled hidapi again, issues related to hidapi are fixed upstream
* Documentation and reliability fixes.
* New API calls:
+ fido_cred_authdata_raw_len;
+ fido_cred_authdata_raw_ptr;
+ fido_cred_sigcount;
+ fido_dev_get_uv_retry_count;
+ fido_dev_supports_credman.
* Hardened Windows build.
* Native FreeBSD and NetBSD support.
* Use CTAP2 canonical CBOR when combining hmac-secret and credProtect.
- Create a udev subpackage and ship the udev rule.
Changes in python-fido2:
* Don't fail device discovery when hidraw doesn't support HIDIOCGRAWUNIQ
* Support the latest Windows webauthn.h API (included in Windows 11).
* Add product name and serial number to HidDescriptors.
* Remove the need for the uhid-freebsd dependency on FreeBSD.
* Add new CTAP error codes and improve handling of unknown codes.
* Client: API changes to better support extensions.
* Client.make_credential now returns a AuthenticatorAttestationResponse,
which holds the AttestationObject and ClientData, as well as any
client extension results for the credential.
* Client.get_assertion now returns an AssertionSelection object,
which is used to select between multiple assertions
* Renames: The CTAP1 and CTAP2 classes have been renamed to
Ctap1 and Ctap2, respectively.
* ClientPin: The ClientPin API has been restructured to support
multiple PIN protocols, UV tokens, and token permissions.
* CTAP 2.1 PRE: Several new features have been added for CTAP 2.1
* HID: The platform specific HID code has been revamped
- Version 0.8.1 (released 2019-11-25)
* Bugfix: WindowsClient.make_credential error when resident key requirement is unspecified.
- Version 0.8.0 (released 2019-11-25)
* New fido2.webauthn classes modeled after the W3C WebAuthn spec introduced.
* CTAP2 send_cbor/make_credential/get_assertion and U2fClient request/authenticate timeout arguments replaced with event used to cancel a request.
* Fido2Client:
- make_credential/get_assertion now take WebAuthn options objects.
- timeout is now provided in ms in WebAuthn options objects. Event based cancelation also available by passing an Event.
* Fido2Server:
- ATTESTATION, USER_VERIFICATION, and AUTHENTICATOR_ATTACHMENT enums have been replaced with fido2.webauthn classes.
- RelyingParty has been replaced with PublicKeyCredentialRpEntity, and name is no longer optional.
- Options returned by register_begin/authenticate_begin now omit unspecified values if they are optional, instead of filling in default values.
- Fido2Server.allowed_algorithms now contains a list of PublicKeyCredentialParameters instead of algorithm identifiers.
- Fido2Server.timeout is now in ms and of type int.
* Support native WebAuthn API on Windows through WindowsClient.
- Version 0.7.2 (released 2019-10-24)
* Support for the TPM attestation format.
* Allow passing custom challenges to register/authenticate in Fido2Server.
* Bugfix: CTAP2 CANCEL command response handling fixed.
* Bugfix: Fido2Client fix handling of empty allow_list.
* Bugfix: Fix typo in CTAP2.get_assertions() causing it to fail.
- Version 0.7.1 (released 2019-09-20)
* Enforce canonical CBOR on Authenticator responses by default.
* PCSC: Support extended APDUs.
* Server: Verify that UP flag is set.
* U2FFido2Server: Implement AppID exclusion extension.
* U2FFido2Server: Allow custom U2F facet verification.
* Bugfix: U2FFido2Server.authenticate_complete now returns the result.
- Version 0.7.0 (released 2019-06-17)
* Add support for NFC devices using PCSC.
* Add support for the hmac-secret Authenticator extension.
* Honor max credential ID length and number of credentials to Authenticator.
* Add close() method to CTAP devices to explicitly release their resources.
- Version 0.6.0 (released 2019-05-10)
* Don't fail if CTAP2 Info contains unknown fields.
* Replace cbor loads/dumps functions with encode/decode/decode_from.
* Server: Add support for AuthenticatorAttachment.
* Server: Add support for more key algorithms.
* Client: Expose CTAP2 Info object as Fido2Client.info.
Changes in yubikey-manager:
- Update to version 4.0.9 (released 2022-06-17)
* Dependency: Add support for python-fido2 1.x
* Fix: Drop stated support for Click 6 as features from 7 are being used.
- Update to version 4.0.8 (released 2022-01-31)
* Bugfix: Fix error message for invalid modhex when programing a YubiOTP credential.
* Bugfix: Fix issue with displaying a Steam credential when it is the only account.
* Bugfix: Prevent installation of files in site-packages root.
* Bugfix: Fix cleanup logic in PIV for protected management key.
* Add support for token identifier when programming slot-based HOTP.
* Add support for programming NDEF in text mode.
* Dependency: Add support for Cryptography ⇠38.
** Bugfix release: Fix broken naming for 'YubiKey 4', and a small OATH issue with
touch Steam credentials.
- version 4.0.6 (released 2021-09-08)
** Improve handling of YubiKey device reboots.
** More consistently mask PIN/password input in prompts.
** Support switching mode over CCID for YubiKey Edge.
** Run pkill from PATH instead of fixed location.
- version 4.0.5 (released 2021-07-16)
** Bugfix: Fix PIV feature detection for some YubiKey NEO versions.
** Bugfix: Fix argument short form for --period when adding TOTP credentials.
** Bugfix: More strict validation for some arguments, resulting in better error messages.
** Bugfix: Correctly handle TOTP credentials using period != 30 AND touch_required.
** Bugfix: Fix prompting for access code in the otp settings command (now uses '-A -').
* Add support for fido reset over NFC.
* Bugfix: The --touch argument to piv change-management-key was
ignored.
* Bugfix: Don’t prompt for password when importing PIV key/cert
if file is invalid.
* Bugfix: Fix setting touch-eject/auto-eject for YubiKey 4 and NEO.
* Bugfix: Detect PKCS#12 format when outer sequence uses
indefinite length.
* Dependency: Add support for Click 8.
* Update device names
* Add read_info output to the --diagnose command, and show
exception types.
* Bugfix: Fix read_info for YubiKey Plus.
* Add support for YK5-based FIPS YubiKeys.
* Bugfix: Fix OTP device enumeration on Win32.
* Drop reliance on libusb and libykpersonalize.
* Support the 'fido' and 'otp' subcommands over NFC
* New 'ykman --diagnose' command to aid in troubleshooting.
* New 'ykman apdu' command for sending raw APDUs over the smart
card interface.
* New 'yubikit' package added for custom development and advanced
scripting.
* OpenPGP: Add support for KDF enabled YubiKeys.
* Static password: Add support for FR, IT, UK and BEPO keyboard
layouts.
* Add support for YubiKey 5C NFC
* OpenPGP: set-touch now performs compatibility checks before prompting for PIN
* OpenPGP: Improve error messages and documentation for set-touch
* PIV: read-object command no longer adds a trailing newline
* CLI: Hint at missing permissions when opening a device fails
* Linux: Improve error handling when pcscd is not running
* Windows: Improve how .DLL files are loaded, thanks to Marius Gabriel Mihai for reporting this!
* Bugfix: set-touch now accepts the cached-fixed option
* Bugfix: Fix crash in OtpController.prepare_upload_key() error parsing
* Bugfix: Fix crash in piv info command when a certificate slot contains an invalid certificate
* Library: PivController.read_certificate(slot) now wraps certificate parsing exceptions in new exception type InvalidCertificate
* Library: PivController.list_certificates() now returns None for slots containing invalid certificate, instead of raising an exception
- Version 3.1.0 (released 2019-08-20)
* Add support for YubiKey 5Ci
* OpenPGP: the info command now prints OpenPGP specification version as well
* OpenPGP: Update support for attestation to match OpenPGP v3.4
* PIV: Use UTC time for self-signed certificates
* OTP: Static password now supports the Norman keyboard layout
- Version 3.0.0 (released 2019-06-24)
* Add support for new YubiKey Preview and lightning form factor
* FIDO: Support for credential management
* OpenPGP: Support for OpenPGP attestation, cardholder certificates and
cached touch policies
* OTP: Add flag for using numeric keypad when sending digits
- Version 2.1.1 (released 2019-05-28)
* OTP: Add initial support for uploading Yubico OTP credentials to YubiCloud
* Don’t automatically select the U2F applet on YubiKey NEO, it might be
blocked by the OS
* ChalResp: Always pad challenge correctly
* Bugfix: Don’t crash with older versions of cryptography
* Bugfix: Password was always prompted in OATH command, even if sent as
argument
Changes in yubikey-manager-qt:
* Compatibility update for ykman 5.0.1.
* Update to Python 3.11.
* Update product images.
- Update to version 1.2.4 (released 2021-10-26)
* Update device names and images.
* PIV: Fix import of certificate.
* Improved error handling when using Security Key Series devices.
* PIV: Fix generation of certificate in slot 9c.
* Fix detection of YubiKey Plus
* Compatibility update for yubikey-manager 4.0
* Bugfix: Device caching with multiple devices
* Drop dependencies on libusb and libykpers.
* Add additional product names and images
* Add support for YubiKey 5C NFC
* OTP: Add option to upload YubiOTP credential to YubiCloud
* Linux: Show hint about pcscd service if opening device fails
* Bugfix: Signal handling now compatible with Python 3.8
- Version 1.1.3 (released 2019-08-20)
* Add suppport for YubiKey 5Ci
* PIV: Use UTC time for self-signed certificates
- Version 1.1.2 (released 2019-06-24)
* Add support for new YubiKey Preview
* PIV: The popup for the management key now have a 'Use default' option
* Windows: Fix issue with importing PIV certificates
* Bugfix: generate static password now works correctly
SUSE-CU-2023:2229-1
| Container Advisory ID | SUSE-CU-2023:2229-1 |
| Container Tags | bci/node:18 , bci/node:18-7.6 , bci/nodejs:18 , bci/nodejs:18-7.6 |
| Container Release | 7.6 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2765-1
|
| Released | Mon Jul 3 20:28:14 2023 |
| Summary | Security update for libcap |
| Type | security |
| Severity | moderate |
| References | 1211418,1211419,CVE-2023-2602,CVE-2023-2603 |
Description:
This update for libcap fixes the following issues:
- CVE-2023-2602: Fixed improper memory release in libcap/psx/psx.c:__wrap_pthread_create() (bsc#1211418).
- CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419).
SUSE-CU-2023:2197-1
| Container Advisory ID | SUSE-CU-2023:2197-1 |
| Container Tags | bci/node:18 , bci/node:18-7.2 , bci/nodejs:18 , bci/nodejs:18-7.2 |
| Container Release | 7.2 |
The following patches have been included in this update:
| Advisory ID | SUSE-SU-2023:2669-1
|
| Released | Wed Jun 28 09:24:41 2023 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1208744,1211407,1211604,1211605,1211606,1211607,1212574,1212579,1212581,1212582,1212583,CVE-2022-25881,CVE-2023-30581,CVE-2023-30585,CVE-2023-30588,CVE-2023-30589,CVE-2023-30590,CVE-2023-31124,CVE-2023-31130,CVE-2023-31147,CVE-2023-32067 |
Description:
This update for nodejs18 fixes the following issues:
Update to version 18.16.1:
- CVE-2023-30581: Fixed mainModule.__proto__ Bypass Experimental Policy Mechanism (bsc#1212574).
- CVE-2023-30585: Fixed privilege escalation via Malicious Registry Key manipulation during Node.js installer repair process (bsc#1212579).
- CVE-2023-30588: Fixed process interuption due to invalid Public Key information in x509 certificates (bsc#1212581).
- CVE-2023-30589: Fixed HTTP Request Smuggling via empty headers separated by CR (bsc#1212582).
- CVE-2023-30590: Fixed DiffieHellman key generation after setting a private key (bsc#1212583).
- CVE-2023-31124: Fixed cross compilation issue with AutoTools that does not set CARES_RANDOM_FILE (bsc#1211607).
- CVE-2023-31130: Fixed buffer underwrite problem in ares_inet_net_pton() (bsc#1211606).
- CVE-2023-31147: Fixed insufficient randomness in generation of DNS query IDs (bsc#1211605).
- CVE-2023-32067: Fixed denial-of-service via 0-byte UDP payload (bsc#1211604).
- CVE-2022-25881: Fixed a Regular Expression Denial of Service (bsc#1208744).
Bug fixes:
- Increased the default timeout on unit tests from 2 to 20 minutes. This seems to have lead to build failures on some platforms, like s390x in Factory. (bsc#1211407)
SUSE-CU-2023:2174-1
| Container Advisory ID | SUSE-CU-2023:2174-1 |
| Container Tags | bci/node:18 , bci/node:18-7.1 , bci/nodejs:18 , bci/nodejs:18-7.1 |
| Container Release | 7.1 |
The following patches have been included in this update:
SUSE-CU-2023:2126-1
| Container Advisory ID | SUSE-CU-2023:2126-1 |
| Container Tags | bci/node:18 , bci/node:18-6.7 , bci/nodejs:18 , bci/nodejs:18-6.7 |
| Container Release | 6.7 |
The following patches have been included in this update:
| Advisory ID | 29171
|
| Released | Tue Jun 20 12:29:00 2023 |
| Summary | Security update for openssl-1_1 |
| Type | security |
| Severity | important |
| References | 1201627,1207534,1211430,CVE-2022-4304,CVE-2023-2650 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430).
- CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption.
The previous fix for this timing side channel turned out to cause a
severe 2-3x performance regression in the typical use case (bsc#1207534).
- Update further expiring certificates that affect tests (bsc#1201627)
| Advisory ID | SUSE-RU-2023:2625-1
|
| Released | Fri Jun 23 17:16:11 2023 |
| Summary | Recommended update for gcc12 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for gcc12 fixes the following issues:
- Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204
* includes regression and other bug fixes
- Speed up builds with --enable-link-serialization.
- Update embedded newlib to version 4.2.0
SUSE-CU-2023:2072-1
| Container Advisory ID | SUSE-CU-2023:2072-1 |
| Container Tags | bci/node:18 , bci/node:18-6.5 , bci/nodejs:18 , bci/nodejs:18-6.5 |
| Container Release | 6.5 |
The following patches have been included in this update:
SUSE-CU-2023:2023-1
| Container Advisory ID | SUSE-CU-2023:2023-1 |
| Container Tags | bci/node:18 , bci/node:18-6.3 , bci/nodejs:18 , bci/nodejs:18-6.3 |
| Container Release | 6.3 |
The following patches have been included in this update:
SUSE-CU-2023:1975-1
| Container Advisory ID | SUSE-CU-2023:1975-1 |
| Container Tags | bci/node:18 , bci/node:18-6.1 , bci/nodejs:18 , bci/nodejs:18-6.1 |
| Container Release | 6.1 |
The following patches have been included in this update:
| Advisory ID | SUSE-RU-2018:1332-1
|
| Released | Tue Jul 17 09:01:19 2018 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1073299,1093392 |
Description:
This update for timezone provides the following fixes:
- North Korea switches back from +0830 to +09 on 2018-05-05.
- Ireland's standard time is in the summer, with negative DST offset to standard time used
in Winter. (bsc#1073299)
- yast2-country is no longer setting TIMEZONE in /etc/sysconfig/clock and is calling systemd
timedatectl instead. Do not set /etc/localtime on timezone package updates to avoid
setting an incorrect timezone. (bsc#1093392)
| Advisory ID | SUSE-RU-2018:2463-1
|
| Released | Thu Oct 25 14:48:34 2018 |
| Summary | Recommended update for timezone, timezone-java |
| Type | recommended |
| Severity | moderate |
| References | 1104700,1112310 |
Description:
This update for timezone, timezone-java fixes the following issues:
The timezone database was updated to 2018f:
- Volgograd moves from +03 to +04 on 2018-10-28.
- Fiji ends DST 2019-01-13, not 2019-01-20.
- Most of Chile changes DST dates, effective 2019-04-06 (bsc#1104700)
- Corrections to past timestamps of DST transitions
- Use 'PST' and 'PDT' for Philippine time
- minor code changes to zic handling of the TZif format
- documentation updates
Other bugfixes:
- Fixed a zic problem with the 1948-1951 DST transition in Japan (bsc#1112310)
| Advisory ID | SUSE-RU-2018:2550-1
|
| Released | Wed Oct 31 16:16:56 2018 |
| Summary | Recommended update for timezone, timezone-java |
| Type | recommended |
| Severity | moderate |
| References | 1113554 |
Description:
This update provides the latest time zone definitions (2018g), including the following change:
- Morocco switched from +00/+01 to permanent +01 effective 2018-10-28 (bsc#1113554)
| Advisory ID | SUSE-RU-2018:2569-1
|
| Released | Fri Nov 2 19:00:18 2018 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1110700 |
Description:
This update for pam fixes the following issues:
- Remove limits for nproc from /etc/security/limits.conf (bsc#1110700)
| Advisory ID | SUSE-RU-2018:2607-1
|
| Released | Wed Nov 7 15:42:48 2018 |
| Summary | Optional update for gcc8 |
| Type | recommended |
| Severity | low |
| References | 1084812,1084842,1087550,1094222,1102564 |
Description:
The GNU Compiler GCC 8 is being added to the Development Tools Module by this
update.
The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other
gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
Various optimizers have been improved in GCC 8, several of bugs fixed,
quite some new warnings added and the error pin-pointing and
fix-suggestions have been greatly improved.
The GNU Compiler page for GCC 8 contains a summary of all the changes that
have happened:
https://gcc.gnu.org/gcc-8/changes.html
Also changes needed or common pitfalls when porting software are described on:
https://gcc.gnu.org/gcc-8/porting_to.html
| Advisory ID | SUSE-SU-2018:2825-1
|
| Released | Mon Dec 3 15:35:02 2018 |
| Summary | Security update for pam |
| Type | security |
| Severity | important |
| References | 1115640,CVE-2018-17953 |
Description:
This update for pam fixes the following issue:
Security issue fixed:
- CVE-2018-17953: Fixed IP address and subnet handling of pam_access.so that was not honoured correctly when a single host was specified (bsc#1115640).
| Advisory ID | SUSE-SU-2018:2861-1
|
| Released | Thu Dec 6 14:32:01 2018 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | important |
| References | 1103320,1115929,CVE-2018-19211 |
Description:
This update for ncurses fixes the following issues:
Security issue fixed:
- CVE-2018-19211: Fixed denial of service issue that was triggered by a NULL pointer dereference at function _nc_parse_entry (bsc#1115929).
Non-security issue fixed:
- Remove scree.xterm from terminfo data base as with this screen uses fallback TERM=screen (bsc#1103320).
| Advisory ID | SUSE-RU-2019:44-1
|
| Released | Tue Jan 8 13:07:32 2019 |
| Summary | Recommended update for acl |
| Type | recommended |
| Severity | low |
| References | 953659 |
Description:
This update for acl fixes the following issues:
- test: Add helper library to fake passwd/group files.
- quote: Escape literal backslashes. (bsc#953659)
| Advisory ID | SUSE-RU-2019:102-1
|
| Released | Tue Jan 15 18:02:58 2019 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1120402 |
Description:
This update for timezone fixes the following issues:
- Update 2018i:
São Tomé and PrÃncipe switches from +01 to +00 on 2019-01-01. (bsc#1120402)
- Update 2018h:
Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21
New zone Asia/Qostanay because Qostanay, Kazakhstan didn't move
Metlakatla, Alaska observes PST this winter only
Guess Morocco will continue to adjust clocks around Ramadan
Add predictions for Iran from 2038 through 2090
| Advisory ID | SUSE-SU-2019:247-1
|
| Released | Wed Feb 6 07:18:45 2019 |
| Summary | Security update for lua53 |
| Type | security |
| Severity | moderate |
| References | 1123043,CVE-2019-6706 |
Description:
This update for lua53 fixes the following issues:
Security issue fixed:
- CVE-2019-6706: Fixed a use-after-free bug in the lua_upvaluejoin function of lapi.c (bsc#1123043)
| Advisory ID | SUSE-SU-2019:571-1
|
| Released | Thu Mar 7 18:13:46 2019 |
| Summary | Security update for file |
| Type | security |
| Severity | moderate |
| References | 1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907 |
Description:
This update for file fixes the following issues:
The following security vulnerabilities were addressed:
- CVE-2018-10360: Fixed an out-of-bounds read in the function do_core_note in
readelf.c, which allowed remote attackers to cause a denial of service
(application crash) via a crafted ELF file (bsc#1096974)
- CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c
(bsc#1126118)
- CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c
(bsc#1126119)
- CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c
(bsc#1126117)
| Advisory ID | SUSE-RU-2019:790-1
|
| Released | Thu Mar 28 12:06:17 2019 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1130557 |
Description:
This update for timezone fixes the following issues:
timezone was updated 2019a:
- Palestine 'springs forward' on 2019-03-30 instead of 2019-03-23
- Metlakatla 'fell back' to rejoin Alaska Time on 2019-01-20 at 02:00
- Israel observed DST in 1980 (08-02/09-13) and 1984 (05-05/08-25)
- zic now has an -r option to limit the time range of output data
| Advisory ID | SUSE-SU-2019:926-1
|
| Released | Wed Apr 10 16:33:12 2019 |
| Summary | Security update for tar |
| Type | security |
| Severity | moderate |
| References | 1120610,1130496,CVE-2018-20482,CVE-2019-9923 |
Description:
This update for tar fixes the following issues:
Security issues fixed:
- CVE-2019-9923: Fixed a denial of service while parsing certain archives with malformed extended headers in pax_decode_header() (bsc#1130496).
- CVE-2018-20482: Fixed a denial of service when the '--sparse' option mishandles file shrinkage during read access (bsc#1120610).
| Advisory ID | SUSE-SU-2019:1368-1
|
| Released | Tue May 28 13:15:38 2019 |
| Summary | Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root |
| Type | security |
| Severity | important |
| References | 1134524,CVE-2019-5021 |
Description:
This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:
- CVE-2019-5021: Include an invalidated root password by default, not an empty one (bsc#1134524)
| Advisory ID | SUSE-RU-2019:1631-1
|
| Released | Fri Jun 21 11:17:21 2019 |
| Summary | Recommended update for xz |
| Type | recommended |
| Severity | low |
| References | 1135709 |
Description:
This update for xz fixes the following issues:
Add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
| Advisory ID | SUSE-RU-2019:1815-1
|
| Released | Thu Jul 11 07:47:55 2019 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1140016 |
Description:
This update for timezone fixes the following issues:
- Timezone update 2019b. (bsc#1140016):
- Brazil no longer observes DST.
- 'zic -b slim' outputs smaller TZif files.
- Palestine's 2019 spring-forward transition was on 03-29, not 03-30.
- Add info about the Crimea situation.
| Advisory ID | SUSE-RU-2019:2762-1
|
| Released | Thu Oct 24 07:08:44 2019 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1150451 |
Description:
This update for timezone fixes the following issues:
- Fiji observes DST from 2019-11-10 to 2020-01-12.
- Norfolk Island starts observing Australian-style DST.
| Advisory ID | SUSE-SU-2019:2997-1
|
| Released | Mon Nov 18 15:16:38 2019 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595 |
Description:
This update for ncurses fixes the following issues:
Security issues fixed:
- CVE-2019-17594: Fixed a heap-based buffer over-read in the _nc_find_entry function (bsc#1154036).
- CVE-2019-17595: Fixed a heap-based buffer over-read in the fmt_entry function (bsc#1154037).
Non-security issue fixed:
- Removed screen.xterm from terminfo database (bsc#1103320).
| Advisory ID | SUSE-SU-2019:3061-1
|
| Released | Mon Nov 25 17:34:22 2019 |
| Summary | Security update for gcc9 |
| Type | security |
| Severity | moderate |
| References | 1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536 |
Description:
This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html
The base system compiler libraries libgcc_s1, libstdc++6 and others are
now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 /
CXX=g++-9 during configuration for using it.
Security issues fixed:
- CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145)
- CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649)
Non-security issues fixed:
- Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254)
- Fixed miscompilation for vector shift on s390. (bsc#1141897)
| Advisory ID | SUSE-SU-2019:3086-1
|
| Released | Thu Nov 28 10:02:24 2019 |
| Summary | Security update for libidn2 |
| Type | security |
| Severity | moderate |
| References | 1154884,1154887,CVE-2019-12290,CVE-2019-18224 |
Description:
This update for libidn2 to version 2.2.0 fixes the following issues:
- CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884).
- CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887).
| Advisory ID | SUSE-RU-2020:521-1
|
| Released | Thu Feb 27 18:08:56 2020 |
| Summary | Recommended update for c-ares |
| Type | recommended |
| Severity | moderate |
| References | 1125306,1159006 |
Description:
This update for c-ares fixes the following issues:
c-ares version update to 1.15.0:
- Add ares_init_options() configurability for path to resolv.conf file
- Ability to exclude building of tools (adig, ahost, acountry) in CMake
- Report ARES_ENOTFOUND for .onion domain names as per RFC7686
(bsc#1125306)
- Apply the IPv6 server blacklist to all nameserver sources
- Prevent changing name servers while queries are outstanding
- ares_set_servers_csv() on failure should not leave channel in a
bad state
- getaddrinfo - avoid infinite loop in case of NXDOMAIN
- ares_getenv - return NULL in all cases
- implement ares_getaddrinfo
- Fixed a regression in DNS results that contain both A and AAAA answers.
- Add netcfg as the build requirement and runtime requirement.
| Advisory ID | SUSE-RU-2020:525-1
|
| Released | Fri Feb 28 11:49:36 2020 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1164562 |
Description:
This update for pam fixes the following issues:
- Add libdb as build-time dependency to enable pam_userdb module.
Enable pam_userdb.so (jsc#sle-7258, bsc#1164562)
| Advisory ID | SUSE-RU-2020:689-1
|
| Released | Fri Mar 13 17:09:01 2020 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1166510 |
Description:
This update for PAM fixes the following issue:
- The license of libdb linked against pam_userdb is not always wanted,
so we temporary disabled pam_userdb again. It will be published
in a different package at a later time. (bsc#1166510)
| Advisory ID | SUSE-RU-2020:917-1
|
| Released | Fri Apr 3 15:02:25 2020 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1166510 |
Description:
This update for pam fixes the following issues:
- Moved pam_userdb into a separate package pam-extra. (bsc#1166510)
| Advisory ID | SUSE-SU-2020:948-1
|
| Released | Wed Apr 8 07:44:21 2020 |
| Summary | Security update for gmp, gnutls, libnettle |
| Type | security |
| Severity | moderate |
| References | 1152692,1155327,1166881,1168345,CVE-2020-11501 |
Description:
This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:
- CVE-2020-11501: Fixed zero random value in DTLS client hello (bsc#1168345)
FIPS related bugfixes:
- FIPS: Install checksums for binary integrity verification which are
required when running in FIPS mode (bsc#1152692, jsc#SLE-9518)
- FIPS: Fixed a cfb8 decryption issue, no longer truncate output IV if
input is shorter than block size. (bsc#1166881)
- FIPS: Added Diffie Hellman public key verification test. (bsc#1155327)
| Advisory ID | SUSE-RU-2020:1226-1
|
| Released | Fri May 8 10:51:05 2020 |
| Summary | Recommended update for gcc9 |
| Type | recommended |
| Severity | moderate |
| References | 1149995,1152590,1167898 |
Description:
This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.
- Includes a fix for Internal compiler error when building HepMC (bsc#1167898)
- Includes fix for binutils version parsing
- Add libstdc++6-pp provides and conflicts to avoid file conflicts
with same minor version of libstdc++6-pp from gcc10.
- Add gcc9 autodetect -g at lto link (bsc#1149995)
- Install go tool buildid for bootstrapping go
| Advisory ID | SUSE-SU-2020:1294-1
|
| Released | Mon May 18 07:38:36 2020 |
| Summary | Security update for file |
| Type | security |
| Severity | moderate |
| References | 1154661,1169512,CVE-2019-18218 |
Description:
This update for file fixes the following issues:
Security issues fixed:
- CVE-2019-18218: Fixed a heap-based buffer overflow in cdf_read_property_info() (bsc#1154661).
Non-security issue fixed:
- Fixed broken '--help' output (bsc#1169512).
| Advisory ID | SUSE-RU-2020:1303-1
|
| Released | Mon May 18 09:40:36 2020 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1169582 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020a. (bsc#1169582)
* Morocco springs forward on 2020-05-31, not 2020-05-24.
* Canada's Yukon advanced to -07 year-round on 2020-03-08.
* America/Nuuk renamed from America/Godthab.
* zic now supports expiration dates for leap second lists.
| Advisory ID | SUSE-RU-2020:1328-1
|
| Released | Mon May 18 17:16:04 2020 |
| Summary | Recommended update for grep |
| Type | recommended |
| Severity | moderate |
| References | 1155271 |
Description:
This update for grep fixes the following issues:
- Update testsuite expectations, no functional changes (bsc#1155271)
| Advisory ID | SUSE-RU-2020:1542-1
|
| Released | Thu Jun 4 13:24:37 2020 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1172055 |
Description:
This update for timezone fixes the following issue:
- zdump --version reported 'unknown' (bsc#1172055)
| Advisory ID | SUSE-RU-2020:1954-1
|
| Released | Sat Jul 18 03:07:15 2020 |
| Summary | Recommended update for cracklib |
| Type | recommended |
| Severity | moderate |
| References | 1172396 |
Description:
This update for cracklib fixes the following issues:
- Fixed a buffer overflow when processing long words.
| Advisory ID | SUSE-RU-2020:2083-1
|
| Released | Thu Jul 30 10:27:59 2020 |
| Summary | Recommended update for diffutils |
| Type | recommended |
| Severity | moderate |
| References | 1156913 |
Description:
This update for diffutils fixes the following issue:
- Disable a sporadically failing test for ppc64 and ppc64le builds. (bsc#1156913)
| Advisory ID | SUSE-SU-2020:2947-1
|
| Released | Fri Oct 16 15:23:07 2020 |
| Summary | Security update for gcc10, nvptx-tools |
| Type | security |
| Severity | moderate |
| References | 1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844 |
Description:
This update for gcc10, nvptx-tools fixes the following issues:
This update provides the GCC10 compiler suite and runtime libraries.
The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by
the gcc10 variants.
The new compiler variants are available with '-10' suffix, you can specify them
via:
CC=gcc-10
CXX=g++-10
or similar commands.
For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
Changes in nvptx-tools:
| Advisory ID | SUSE-RU-2020:2983-1
|
| Released | Wed Oct 21 15:03:03 2020 |
| Summary | Recommended update for file |
| Type | recommended |
| Severity | moderate |
| References | 1176123 |
Description:
This update for file fixes the following issues:
- Fixes an issue when file displays broken 'ELF' interpreter. (bsc#1176123)
| Advisory ID | SUSE-RU-2020:3099-1
|
| Released | Thu Oct 29 19:33:41 2020 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020b (bsc#1177460)
* Revised predictions for Morocco's changes starting in 2023.
* Canada's Yukon changes to -07 on 2020-11-01, not 2020-03-08.
* Macquarie Island has stayed in sync with Tasmania since 2011.
* Casey, Antarctica is at +08 in winter and +11 in summer.
* zic no longer supports -y, nor the TYPE field of Rules.
| Advisory ID | SUSE-RU-2020:3123-1
|
| Released | Tue Nov 3 09:48:13 2020 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | important |
| References | 1177460,1178346,1178350,1178353 |
Description:
This update for timezone fixes the following issues:
- Generate 'fat' timezone files (was default before 2020b). (bsc#1178346, bsc#1178350, bsc#1178353)
- Palestine ends DST earlier than predicted, on 2020-10-24. (bsc#1177460)
- Fiji starts DST later than usual, on 2020-12-20. (bsc#1177460)
| Advisory ID | SUSE-RU-2020:3462-1
|
| Released | Fri Nov 20 13:14:35 2020 |
| Summary | Recommended update for pam and sudo |
| Type | recommended |
| Severity | moderate |
| References | 1174593,1177858,1178727 |
Description:
This update for pam and sudo fixes the following issue:
pam:
- pam_xauth: do not *free* a string which has been successfully passed to *putenv*. (bsc#1177858)
- Initialize the local variable *daysleft* to avoid a misleading warning for password expire days. (bsc#1178727)
- Run /usr/bin/xauth using the old user's and group's identifiers. (bsc#1174593)
sudo:
- Fix a problem with pam_xauth which checks effective and real uids to get the real identity of the user. (bsc#1174593)
| Advisory ID | SUSE-SU-2020:3478-1
|
| Released | Mon Nov 23 09:33:17 2020 |
| Summary | Security update for c-ares |
| Type | security |
| Severity | moderate |
| References | 1178882,CVE-2020-8277 |
Description:
This update for c-ares fixes the following issues:
- Version update to 1.17.0
* CVE-2020-8277: Fixed a Denial of Service through DNS request (bsc#1178882)
* For further details see https://c-ares.haxx.se/changelog.html
| Advisory ID | SUSE-RU-2020:3616-1
|
| Released | Thu Dec 3 10:56:12 2020 |
| Summary | Recommended update for c-ares |
| Type | recommended |
| Severity | moderate |
| References | 1178882 |
Description:
- Fixed incomplete c-ares-devel dependencies introduced by the privous update (bsc#1178882).
| Advisory ID | SUSE-RU-2020:3620-1
|
| Released | Thu Dec 3 17:03:55 2020 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for pam fixes the following issues:
- Check if the password is part of the username. (jsc#SLE-16719, jsc#SLE-16720)
- Check whether the password contains a substring of of the user's name of at least `` characters length in
some form. This is enabled by the new parameter `usersubstr=`
| Advisory ID | SUSE-RU-2020:3791-1
|
| Released | Mon Dec 14 17:39:19 2020 |
| Summary | Recommended update for gzip |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for gzip fixes the following issue:
- Enable `DFLTCC` (Deflate Conversion Call) compression for s390x for levels 1-6 to `CFLAGS`. (jsc#SLE-13775)
Enable by adding `-DDFLTCC_LEVEL_MASK=0x7e` to `CFLAGS`.
| Advisory ID | SUSE-RU-2020:3942-1
|
| Released | Tue Dec 29 12:22:01 2020 |
| Summary | Recommended update for libidn2 |
| Type | recommended |
| Severity | moderate |
| References | 1180138 |
Description:
This update for libidn2 fixes the following issues:
- The library is actually dual licensed, GPL-2.0-or-later or LGPL-3.0-or-later,
adjusted the RPM license tags (bsc#1180138)
| Advisory ID | SUSE-RU-2021:179-1
|
| Released | Wed Jan 20 13:38:51 2021 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
| Advisory ID | SUSE-RU-2021:220-1
|
| Released | Tue Jan 26 14:00:51 2021 |
| Summary | Recommended update for keyutils |
| Type | recommended |
| Severity | moderate |
| References | 1180603 |
Description:
This update for keyutils fixes the following issues:
- Adjust the library license to be LPGL-2.1+ only (the tools are GPL2+, the library is just LGPL-2.1+) (bsc#1180603)
| Advisory ID | SUSE-RU-2021:293-1
|
| Released | Wed Feb 3 12:52:34 2021 |
| Summary | Recommended update for gmp |
| Type | recommended |
| Severity | moderate |
| References | 1180603 |
Description:
This update for gmp fixes the following issues:
- correct license statements of packages (library itself is no GPL-3.0) (bsc#1180603)
| Advisory ID | SUSE-RU-2021:301-1
|
| Released | Thu Feb 4 08:46:27 2021 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
| Advisory ID | SUSE-OU-2021:339-1
|
| Released | Mon Feb 8 13:16:07 2021 |
| Summary | Optional update for pam |
| Type | optional |
| Severity | low |
| References | |
Description:
This update for pam fixes the following issues:
- Added rpm macros for this package, so that other packages can make use of it
This patch is optional to be installed - it doesn't fix any bugs.
| Advisory ID | SUSE-RU-2021:924-1
|
| Released | Tue Mar 23 10:00:49 2021 |
| Summary | Recommended update for filesystem |
| Type | recommended |
| Severity | moderate |
| References | 1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094 |
Description:
This update for filesystem the following issues:
- Remove duplicate line due to merge error
- Add fix for 'mesa' creating cache with perm 0700. (bsc#1181011)
- Fixed an issue causing failure during installation/upgrade a failure. (rh#1548403) (bsc#1146705)
- Allows to override config to add cleanup options of '/var/tmp'. (bsc#1078466)
- Create config to cleanup '/tmp' regular required with 'tmpfs'. (bsc#1175519)
This update for systemd fixes the following issues:
- Fix for a possible memory leak. (bsc#1180020)
- Fix for a case when to a bind mounted directory results inactive mount units. (#7811) (bsc#1180596)
- Fixed an issue when starting a container conflicts with another one. (bsc#1178775)
- Drop most of the tmpfiles that deal with generic paths and avoid warnings. (bsc#1078466, bsc#1181831)
- Don't use shell redirections when calling a rpm macro. (bsc#1183094)
- 'systemd' requires 'aaa_base' >= 13.2. (bsc#1180083)
| Advisory ID | SUSE-SU-2021:930-1
|
| Released | Wed Mar 24 12:09:23 2021 |
| Summary | Security update for nghttp2 |
| Type | security |
| Severity | important |
| References | 1172442,1181358,CVE-2020-11080 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358)
| Advisory ID | SUSE-SU-2021:974-1
|
| Released | Mon Mar 29 19:31:27 2021 |
| Summary | Security update for tar |
| Type | security |
| Severity | low |
| References | 1181131,CVE-2021-20193 |
Description:
This update for tar fixes the following issues:
CVE-2021-20193: Memory leak in read_header() in list.c (bsc#1181131)
| Advisory ID | SUSE-RU-2021:1018-1
|
| Released | Tue Apr 6 14:29:13 2021 |
| Summary | Recommended update for gzip |
| Type | recommended |
| Severity | moderate |
| References | 1180713 |
Description:
This update for gzip fixes the following issues:
- Fixes an issue when 'gzexe' counts the lines to skip wrong. (bsc#1180713)
| Advisory ID | SUSE-RU-2021:1289-1
|
| Released | Wed Apr 21 14:02:46 2021 |
| Summary | Recommended update for gzip |
| Type | recommended |
| Severity | moderate |
| References | 1177047 |
Description:
This update for gzip fixes the following issues:
- Fixed a potential segfault when zlib acceleration is enabled (bsc#1177047)
| Advisory ID | SUSE-RU-2021:1643-1
|
| Released | Wed May 19 13:51:48 2021 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | important |
| References | 1181443,1184358,1185562 |
Description:
This update for pam fixes the following issues:
- Fixed a bug, where the 'unlimited'/'-1' value was not interpreted correctly (bsc#1181443)
- Fixed a bug, where pam_access interpreted the keyword 'LOCAL' incorrectly, leading to
an attempt to resolve it as a hostname (bsc#1184358)
- In the 32-bit compatibility package for 64-bit architectures, require 'systemd-32bit' to be also installed as it contains pam_systemd.so for 32 bit applications. (bsc#1185562)
| Advisory ID | SUSE-RU-2021:1861-1
|
| Released | Fri Jun 4 09:59:40 2021 |
| Summary | Recommended update for gcc10 |
| Type | recommended |
| Severity | moderate |
| References | 1029961,1106014,1178577,1178624,1178675,1182016 |
Description:
This update for gcc10 fixes the following issues:
- Disable nvptx offloading for aarch64 again since it doesn't work
- Fixed a build failure issue. (bsc#1182016)
- Fix for memory miscompilation on 'aarch64'. (bsc#1178624, bsc#1178577)
- Fix 32bit 'libgnat.so' link. (bsc#1178675)
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it stays /%lib. (bsc#1029961)
- Build complete set of multilibs for arm-none target. (bsc#1106014)
| Advisory ID | SUSE-RU-2021:1935-1
|
| Released | Thu Jun 10 10:45:09 2021 |
| Summary | Recommended update for gzip |
| Type | recommended |
| Severity | moderate |
| References | 1186642 |
Description:
This update for gzip fixes the following issue:
- gzip had a lower release number in 15 sp2 and sp3 than in 15 sp1, which could lead
to migration issues. (bsc#1186642)
| Advisory ID | SUSE-RU-2021:1937-1
|
| Released | Thu Jun 10 10:47:09 2021 |
| Summary | Recommended update for nghttp2 |
| Type | recommended |
| Severity | moderate |
| References | 1186642 |
Description:
This update for nghttp2 fixes the following issue:
- The (lib)nghttp2 packages had a lower release number in SUSE Linux Enterprise 15 sp2 and sp3 than in 15 sp1, which could lead
to migration issues. (bsc#1186642)
| Advisory ID | SUSE-RU-2021:2146-1
|
| Released | Wed Jun 23 17:55:14 2021 |
| Summary | Recommended update for openssh |
| Type | recommended |
| Severity | moderate |
| References | 1115550,1174162 |
Description:
This update for openssh fixes the following issues:
- Fixed a race condition leading to a sshd termination of multichannel sessions with non-root users (bsc#1115550, bsc#1174162).
| Advisory ID | SUSE-RU-2021:2173-1
|
| Released | Mon Jun 28 14:59:45 2021 |
| Summary | Recommended update for automake |
| Type | recommended |
| Severity | moderate |
| References | 1040589,1047218,1182604,1185540,1186049 |
Description:
This update for automake fixes the following issues:
- Implement generated autoconf makefiles reproducible (bsc#1182604)
- Add fix to avoid date variations in docs. (bsc#1047218, jsc#SLE-17848)
- Avoid bashisms in test-driver script. (bsc#1185540)
This update for pcre fixes the following issues:
- Do not run profiling 'check' in parallel to make package build reproducible. (bsc#1040589)
This update for brp-check-suse fixes the following issues:
- Add fixes to support reproducible builds. (bsc#1186049)
| Advisory ID | SUSE-RU-2021:2193-1
|
| Released | Mon Jun 28 18:38:43 2021 |
| Summary | Recommended update for tar |
| Type | recommended |
| Severity | moderate |
| References | 1184124 |
Description:
This update for tar fixes the following issues:
- Link '/var/lib/tests/tar/bin/genfile' as Position-Independent Executable (bsc#1184124)
| Advisory ID | SUSE-SU-2021:2196-1
|
| Released | Tue Jun 29 09:41:39 2021 |
| Summary | Security update for lua53 |
| Type | security |
| Severity | moderate |
| References | 1175448,1175449,CVE-2020-24370,CVE-2020-24371 |
Description:
This update for lua53 fixes the following issues:
Update to version 5.3.6:
- CVE-2020-24371: lgc.c mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage (bsc#1175449)
- CVE-2020-24370: ldebug.c allows a negation overflow and segmentation fault in getlocal and setlocal (bsc#1175448)
- Long brackets with a huge number of '=' overflow some internal buffer arithmetic.
| Advisory ID | SUSE-SU-2021:2555-1
|
| Released | Thu Jul 29 08:29:55 2021 |
| Summary | Security update for git |
| Type | security |
| Severity | moderate |
| References | 1168930,1183026,1183580,CVE-2021-21300 |
Description:
This update for git fixes the following issues:
Update from version 2.26.2 to version 2.31.1 (jsc#SLE-18152)
Security fixes:
- CVE-2021-21300: On case-insensitive file systems with support for symbolic links, if Git is configured globally
to apply delay-capable clean/smudge filters (such as Git LFS), Git could run remote code during a clone. (bsc#1183026)
Non security changes:
- Add `sysusers` file to create `git-daemon` user.
- Remove `perl-base` and `openssh-server` dependency on `git-core`and provide a `perl-Git` package. (jsc#SLE-17838)
- `fsmonitor` bug fixes
- Fix `git bisect` to take an annotated tag as a good/bad endpoint
- Fix a corner case in `git mv` on case insensitive systems
- Require only `openssh-clients` where possible (like Tumbleweed or SUSE Linux Enterprise >= 15 SP3). (bsc#1183580)
- Drop `rsync` requirement, not necessary anymore.
- Use of `pack-redundant` command is discouraged and will trigger a warning. The replacement is `repack -d`.
- The `--format=%(trailers)` mechanism gets enhanced to make it easier to design output for machine consumption.
- No longer give message to choose between rebase or merge upon pull if the history `fast-forwards`.
- The configuration variable `core.abbrev` can be set to `no` to force no abbreviation regardless of the hash algorithm
- `git rev-parse` can be explicitly told to give output as absolute or relative path with the
`--path-format=(absolute|relative)` option.
- Bash completion update to make it easier for end-users to add completion for their custom `git` subcommands.
- `git maintenance` learned to drive scheduled maintenance on platforms whose native scheduling methods are not 'cron'.
- After expiring a reflog and making a single commit, the reflog for the branch would record a single entry that
knows both `@{0}` and `@{1}`, but we failed to answer 'what commit were we on?', i.e. `@{1}`
- `git bundle` learns `--stdin` option to read its refs from the standard input.
Also, it now does not lose refs when they point at the same object.
- `git log` learned a new `--diff-merges=` option.
- `git ls-files` can and does show multiple entries when the index is unmerged, which is a source for confusion
unless `-s/-u` option is in use. A new option `--deduplicate` has been introduced.
- `git worktree list` now annotates worktrees as prunable, shows locked and prunable attributes
in `--porcelain mode`, and gained a `--verbose` option.
- `git clone` tries to locally check out the branch pointed at by HEAD of the remote repository after it
is done, but the protocol did not convey the information necessary to do so when copying an empty repository.
The protocol v2 learned how to do so.
- There are other ways than `..` for a single token to denote a `commit range', namely `^!`
and `^-`, but `git range-diff` did not understand them.
- The `git range-diff` command learned `--(left|right)-only` option to show only one side of the compared range.
- `git mergetool` feeds three versions (base, local and remote) of a conflicted path unmodified.
The command learned to optionally prepare these files with unconflicted parts already resolved.
- The `.mailmap` is documented to be read only from the root level of a working tree, but a stray file
in a bare repository also was read by accident, which has been corrected.
- `git maintenance` tool learned a new `pack-refs` maintenance task.
- Improved error message given when a configuration variable that is expected to have a boolean value.
- Signed commits and tags now allow verification of objects, whose two object names
(one in SHA-1, the other in SHA-256) are both signed.
- `git rev-list` command learned `--disk-usage` option.
- `git diff`, `git log` `--{skip,rotate}-to=` allows the user to discard diff output for early
paths or move them to the end of the output.
- `git difftool` learned `--skip-to=` option to restart an interrupted session from an arbitrary path.
- `git grep` has been tweaked to be limited to the sparse checkout paths.
- `git rebase --[no-]fork-point` gained a configuration variable `rebase.forkPoint` so that users do not have
to keep specifying a non-default setting.
- `git stash` did not work well in a sparsely checked out working tree.
- Newline characters in the host and path part of `git://` URL are now forbidden.
- `Userdiff` updates for PHP, Rust, CSS
- Avoid administrator error leading to data loss with `git push --force-with-lease[=
[]` by
introducing `--force-if-includes`
]
- only pull `asciidoctor` for the default ruby version
- The `--committer-date-is-author-date` option of `rebase` and `am` subcommands lost the e-mail address by
mistake in 2.29
- The transport protocol v2 has become the default again
- `git worktree` gained a `repair` subcommand, `git init --separate-git-dir` no longer corrupts administrative data
related to linked worktrees
- `git maintenance` introduced for repository maintenance tasks
- `fetch.writeCommitGraph` is deemed to be still a bit too risky and is no longer part of the
`feature.experimental` set.
- The commands in the `diff` family honors the `diff.relative` configuration variable.
- `git diff-files` has been taught to say paths that are marked as `intent-to-add` are new files,
not modified from an empty blob.
- `git gui` now allows opening work trees from the start-up dialog.
- `git bugreport` reports what shell is in use.
- Some repositories have commits that record wrong committer timezone; `git fast-import` has an option to pass
these timestamps intact to allow recreating existing repositories as-is.
- `git describe` will always use the `long` version when giving its output based misplaced tags
- `git pull` issues a warning message until the `pull.rebase` configuration variable is explicitly given
| Advisory ID | SUSE-RU-2021:2573-1
|
| Released | Thu Jul 29 14:21:52 2021 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1188127 |
Description:
This update for timezone fixes the following issue:
- From systemd v249: when enumerating time zones the timedatectl tool will now consult the 'tzdata.zi' file shipped by
the IANA time zone database package, in addition to 'zone1970.tab', as before. This makes sure time zone aliases are
now correctly supported. This update adds the 'tzdata.zi' file (bsc#1188127).
| Advisory ID | SUSE-RU-2021:2606-1
|
| Released | Wed Aug 4 13:16:09 2021 |
| Summary | Recommended update for libcbor |
| Type | recommended |
| Severity | moderate |
| References | 1102408 |
Description:
This update for libcbor fixes the following issues:
- Implement a fix to avoid building shared library twice. (bsc#1102408)
| Advisory ID | SUSE-SU-2021:2682-1
|
| Released | Thu Aug 12 20:06:19 2021 |
| Summary | Security update for rpm |
| Type | security |
| Severity | important |
| References | 1179416,1181805,1183543,1183545,CVE-2021-20266,CVE-2021-20271,CVE-2021-3421 |
Description:
This update for rpm fixes the following issues:
- Changed default package verification level to 'none' to be compatible to rpm-4.14.1
- Made illegal obsoletes a warning
- Fixed a potential access of freed mem in ndb's glue code (bsc#1179416)
- Added support for enforcing signature policy and payload verification step to
transactions (jsc#SLE-17817)
- Added :humansi and :hmaniec query formatters for human readable output
- Added query selectors for whatobsoletes and whatconflicts
- Added support for sorting caret higher than base version
- rpm does no longer require the signature header to be in a contiguous
region when signing (bsc#1181805)
Security fixes:
- CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an
attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM
repository, to cause RPM database corruption. The highest threat from this vulnerability is to
data integrity (bsc#1183543)
- CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file.
This flaw allows an attacker who can convince a victim to install a seemingly verifiable package,
whose signature header was modified, to cause RPM database corruption and execute code. The highest
threat from this vulnerability is to data integrity, confidentiality, and system availability (bsc#1183545)
- CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker
who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability
is to system availability.
| Advisory ID | SUSE-SU-2021:2760-1
|
| Released | Tue Aug 17 17:11:14 2021 |
| Summary | Security update for c-ares |
| Type | security |
| Severity | important |
| References | 1188881,CVE-2021-3672 |
Description:
This update for c-ares fixes the following issues:
Version update to git snapshot 1.17.1+20200724:
- CVE-2021-3672: fixed missing input validation on hostnames returned by DNS servers (bsc#1188881)
- If ares_getaddrinfo() was terminated by an ares_destroy(), it would cause crash
- Crash in sortaddrinfo() if the list size equals 0 due to an unexpected DNS response
- Expand number of escaped characters in DNS replies as per RFC1035 5.1 to prevent spoofing
- Use unbuffered /dev/urandom for random data to prevent early startup performance issues
| Advisory ID | SUSE-RU-2021:3001-1
|
| Released | Thu Sep 9 15:08:13 2021 |
| Summary | Recommended update for netcfg |
| Type | recommended |
| Severity | moderate |
| References | 1189683 |
Description:
This update for netcfg fixes the following issues:
- add submissions port/protocol to services file for message submission over TLS protocol [bsc#1189683]
| Advisory ID | SUSE-RU-2021:3022-1
|
| Released | Mon Sep 13 10:48:16 2021 |
| Summary | Recommended update for c-ares |
| Type | recommended |
| Severity | important |
| References | 1190225 |
Description:
This update for c-ares fixes the following issue:
- Allow '_' as part of DNS response. (bsc#1190225)
- 'c-ares' 1.17.2 introduced response validation to prevent a security issue, however it was not listing '_' as a
valid character for domain name responses which caused issues when a 'CNAME' referenced a 'SRV' record which
contained underscores.
| Advisory ID | SUSE-RU-2021:3182-1
|
| Released | Tue Sep 21 17:04:26 2021 |
| Summary | Recommended update for file |
| Type | recommended |
| Severity | moderate |
| References | 1189996 |
Description:
This update for file fixes the following issues:
- Fixes exception thrown by memory allocation problem (bsc#1189996)
| Advisory ID | SUSE-SU-2021:3291-1
|
| Released | Wed Oct 6 16:45:36 2021 |
| Summary | Security update for glibc |
| Type | security |
| Severity | moderate |
| References | 1186489,1187911,CVE-2021-33574,CVE-2021-35942 |
Description:
This update for glibc fixes the following issues:
- CVE-2021-33574: Fixed use __pthread_attr_copy in mq_notify (bsc#1186489).
- CVE-2021-35942: Fixed wordexp handle overflow in positional parameter number (bsc#1187911).
| Advisory ID | SUSE-SU-2021:3445-1
|
| Released | Fri Oct 15 09:03:39 2021 |
| Summary | Security update for rpm |
| Type | security |
| Severity | important |
| References | 1183659,1185299,1187670,1188548 |
Description:
This update for rpm fixes the following issues:
Security issues fixed:
- PGP hardening changes (bsc#1185299)
Maintaince issues fixed:
- Fixed zstd detection (bsc#1187670)
- Added ndb rofs support (bsc#1188548)
- Fixed deadlock when multiple rpm processes try tp acquire the database lock (bsc#1183659)
| Advisory ID | SUSE-SU-2021:3490-1
|
| Released | Wed Oct 20 16:31:55 2021 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1190793,CVE-2021-39537 |
Description:
This update for ncurses fixes the following issues:
- CVE-2021-39537: Fixed an heap-based buffer overflow in _nc_captoinfo. (bsc#1190793)
| Advisory ID | SUSE-RU-2021:3494-1
|
| Released | Wed Oct 20 16:48:46 2021 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1190052 |
Description:
This update for pam fixes the following issues:
- Added pam_faillock to the set of available PAM modules. (jsc#SLE-20638)
- Added new file macros.pam on request of systemd. (bsc#1190052)
| Advisory ID | SUSE-RU-2021:3510-1
|
| Released | Tue Oct 26 11:22:15 2021 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | important |
| References | 1191987 |
Description:
This update for pam fixes the following issues:
- Fixed a bad directive file which resulted in
the 'securetty' file to be installed as 'macros.pam'.
(bsc#1191987)
| Advisory ID | SUSE-SU-2021:3529-1
|
| Released | Wed Oct 27 09:23:32 2021 |
| Summary | Security update for pcre |
| Type | security |
| Severity | moderate |
| References | 1172973,1172974,CVE-2019-20838,CVE-2020-14155 |
Description:
This update for pcre fixes the following issues:
Update pcre to version 8.45:
- CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974).
- CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973)
| Advisory ID | SUSE-RU-2021:3766-1
|
| Released | Tue Nov 23 07:07:43 2021 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1192023 |
Description:
This update for git fixes the following issues:
- Installation of the 'git-daemon' package needs nogroup group dependency (bsc#1192023)
| Advisory ID | SUSE-RU-2021:3799-1
|
| Released | Wed Nov 24 18:07:54 2021 |
| Summary | Recommended update for gcc11 |
| Type | recommended |
| Severity | moderate |
| References | 1187153,1187273,1188623 |
Description:
This update for gcc11 fixes the following issues:
The additional GNU compiler collection GCC 11 is provided:
To select these compilers install the packages:
- gcc11
- gcc-c++11
- and others with 11 prefix.
to select them for building:
The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.
| Advisory ID | SUSE-RU-2021:3872-1
|
| Released | Thu Dec 2 07:25:55 2021 |
| Summary | Recommended update for cracklib |
| Type | recommended |
| Severity | moderate |
| References | 1191736 |
Description:
This update for cracklib fixes the following issues:
- Enable build time tests (bsc#1191736)
| Advisory ID | SUSE-RU-2021:3883-1
|
| Released | Thu Dec 2 11:47:07 2021 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
Update timezone to 2021e (bsc#1177460)
- Palestine will fall back 10-29 (not 10-30) at 01:00
- Fiji suspends DST for the 2021/2022 season
- 'zic -r' marks unspecified timestamps with '-00'
- Fix a bug in 'zic -b fat' that caused old timestamps to be mishandled in 32-bit-only readers
- Refresh timezone info for china
| Advisory ID | SUSE-RU-2021:3891-1
|
| Released | Fri Dec 3 10:21:49 2021 |
| Summary | Recommended update for keyutils |
| Type | recommended |
| Severity | moderate |
| References | 1029961,1113013,1187654 |
Description:
This update for keyutils fixes the following issues:
- Add /etc/keys/ and /usr/etc/keys/ directory (bsc#1187654)
keyutils was updated to 1.6.3 (jsc#SLE-20016):
- Revert the change notifications that were using /dev/watch_queue.
- Apply the change notifications that use pipe2(O_NOTIFICATION_PIPE).
- Allow 'keyctl supports' to retrieve raw capability data.
- Allow 'keyctl id' to turn a symbolic key ID into a numeric ID.
- Allow 'keyctl new_session' to name the keyring.
- Allow 'keyctl add/padd/etc.' to take hex-encoded data.
- Add 'keyctl watch*' to expose kernel change notifications on keys.
- Add caps for namespacing and notifications.
- Set a default TTL on keys that upcall for name resolution.
- Explicitly clear memory after it's held sensitive information.
- Various manual page fixes.
- Fix C++-related errors.
- Add support for keyctl_move().
- Add support for keyctl_capabilities().
- Make key=val list optional for various public-key ops.
- Fix system call signature for KEYCTL_PKEY_QUERY.
- Fix 'keyctl pkey_query' argument passing.
- Use keyctl_read_alloc() in dump_key_tree_aux().
- Various manual page fixes.
Updated to 1.6:
- Apply various specfile cleanups from Fedora.
- request-key: Provide a command line option to suppress helper execution.
- request-key: Find least-wildcard match rather than first match.
- Remove the dependency on MIT Kerberos.
- Fix some error messages
- keyctl_dh_compute.3: Suggest /proc/crypto for list of available hashes.
- Fix doc and comment typos.
- Add public key ops for encrypt, decrypt, sign and verify (needs linux-4.20).
- Add pkg-config support for finding libkeyutils.
- upstream isn't offering PGP signatures for the source tarballs anymore
Updated to 1.5.11 (bsc#1113013)
- Add keyring restriction support.
- Add KDF support to the Diffie-Helman function.
- DNS: Add support for AFS config files and SRV records
| Advisory ID | SUSE-SU-2021:3942-1
|
| Released | Mon Dec 6 14:46:05 2021 |
| Summary | Security update for brotli |
| Type | security |
| Severity | moderate |
| References | 1175825,CVE-2020-8927 |
Description:
This update for brotli fixes the following issues:
- CVE-2020-8927: Fixed integer overflow when input chunk is larger than 2GiB (bsc#1175825).
| Advisory ID | SUSE-SU-2021:3946-1
|
| Released | Mon Dec 6 14:57:42 2021 |
| Summary | Security update for gmp |
| Type | security |
| Severity | moderate |
| References | 1192717,CVE-2021-43618 |
Description:
This update for gmp fixes the following issues:
- CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717).
| Advisory ID | SUSE-SU-2021:3950-1
|
| Released | Mon Dec 6 14:59:37 2021 |
| Summary | Security update for openssh |
| Type | security |
| Severity | important |
| References | 1190975,CVE-2021-41617 |
Description:
This update for openssh fixes the following issues:
- CVE-2021-41617: Fixed privilege escalation when AuthorizedKeysCommand/AuthorizedPrincipalsCommand are configured (bsc#1190975).
| Advisory ID | SUSE-RU-2021:3980-1
|
| Released | Thu Dec 9 16:42:19 2021 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1191592 |
Description:
glibc was updated to fix the following issue:
- Support for new IBM Z Hardware (bsc#1191592, jsc#IBM-869)
| Advisory ID | SUSE-SU-2021:4063-1
|
| Released | Tue Dec 14 13:58:09 2021 |
| Summary | Security update for icu.691 |
| Type | security |
| Severity | important |
| References | 1158955,1159131,1161007,1162882,1167603,1182252,1182645 |
Description:
This update for icu.691 fixes the following issues:
- Renamed package from icu 69.1 for SUSE:SLE-15-SP3:Update. (jsc#SLE-17893)
- Fix undefined behaviour in 'ComplexUnitsConverter::applyRounder'
- Update to release 69.1
- For Norwegian, 'no' is back to being the canonical code, with
'nb' treated as equivalent. This aligns handling of Norwegian
with other macro language codes.
- Binary prefixes in measurement units (KiB, MiB, etc.)
- Time zone offsets from local time with new APIs.
- Don't disable testsuite under 'qemu-linux-user'
- Fixed an issue when ICU test on 'aarch64 fails. (bsc#1182645)
- Drop 'SUSE_ASNEEDED' as the issue was in binutils. (bsc#1182252)
- Fix 'pthread' dependency issue. (bsc#1182252)
- Update to release 68.2
- Fix memory problem in 'FormattedStringBuilder'
- Fix assertion when 'setKeywordValue w/' long value.
- Fix UBSan breakage on 8bit of rbbi
- fix int32_t overflow in listFormat
- Fix memory handling in MemoryPool::operator=()
- Fix memory leak in AliasReplacer
- Add back icu.keyring.
- Update to release 68.1
- PluralRules selection for ranges of numbers
- Locale ID canonicalization now conforms to the CLDR spec including edge cases
- DateIntervalFormat supports output options such as capitalization
- Measurement units are normalized in skeleton string output
- Time zone data (tzdata) version 2020d
- Add the provides for libicu to Make .Net core can install successfully. (bsc#1167603, bsc#1161007)
- Update to version 67.1
- Unicode 13 (ICU-20893, same as in ICU 66)
- Total of 5930 new characters
- 4 new scripts
- 55 new emoji characters, plus additional new sequences
- New CJK extension, first characters in plane 3: U+30000..U+3134A
- New language at Modern coverage: Nigerian Pidgin
- New languages at Basic coverage: Fulah (Adlam), Maithili,
Manipuri, Santali, Sindhi (Devanagari), Sundanese
- Region containment: EU no longer includes GB
- Unicode 13 root collation data and Chinese data for collation and transliteration
- DateTimePatternGenerator now obeys the 'hc' preference in the locale identifier
- Various other improvements for ECMA-402 conformance
- Number skeletons have a new 'concise' form that can be used in MessageFormat strings
- Currency formatting options for formal and other currency display name variants
- ListFormatter: new public API to select the style & type
- ListFormatter now selects the proper “andâ€/“or†form for Spanish & Hebrew.
- Locale ID canonicalization upgraded to implement the complete CLDR spec.
- LocaleMatcher: New option to ignore one-way matches
- acceptLanguage() reimplemented via LocaleMatcher
- Data build tool: tzdbNames.res moved from the 'zone_tree' category to the 'zone_supplemental' category
- Fixed uses of u8'literals' broken by the C++20 introduction of the incompatible char8_t type
- and added a few API overloads to reduce the need for reinterpret_cast.
- Support for manipulating CLDR 37 unit identifiers in MeasureUnit.
- Drop icu-versioning. (bsc#1159131)
- Update to version 66.1
- Unicode 13 support
- Fix uses of u8'literals' broken by C++20 introduction of incompatible char8_t type.
- Fixed an issue when Qt apps can't handle non-ASCII filesystem path. ([bsc#1162882)
- Remove '/usr/lib(64)/icu/current'. (bsc#1158955)
| Advisory ID | SUSE-SU-2021:4153-1
|
| Released | Wed Dec 22 11:00:48 2021 |
| Summary | Security update for openssh |
| Type | security |
| Severity | important |
| References | 1183137,CVE-2021-28041 |
Description:
This update for openssh fixes the following issues:
- CVE-2021-28041: Fixed double free in ssh-agent (bsc#1183137).
| Advisory ID | SUSE-RU-2022:96-1
|
| Released | Tue Jan 18 05:14:44 2022 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | important |
| References | 1180125,1190824,1193711 |
Description:
This update for rpm fixes the following issues:
- Fix header check so that old rpms no longer get rejected (bsc#1190824)
- Add explicit requirement on python-rpm-macros (bsc#1180125, bsc#1193711)
| Advisory ID | SUSE-RU-2022:207-1
|
| Released | Thu Jan 27 09:24:49 2022 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for glibc fixes the following issues:
- Add support for livepatches on x86_64 for SUSE Linux Enterprise 15 SP4 (jsc#SLE-20049).
| Advisory ID | SUSE-RU-2022:227-1
|
| Released | Mon Jan 31 06:05:25 2022 |
| Summary | Recommended update for git |
| Type | recommended |
| Severity | moderate |
| References | 1193722 |
Description:
This update for git fixes the following issues:
- update to 2.34.1 (bsc#1193722):
* 'git grep' looking in a blob that has non-UTF8 payload was
completely broken when linked with certain versions of PCREv2
library in the latest release.
* 'git pull' with any strategy when the other side is behind us
should succeed as it is a no-op, but doesn't.
* An earlier change in 2.34.0 caused JGit application (that abused
GIT_EDITOR mechanism when invoking 'git config') to get stuck with
a SIGTTOU signal; it has been reverted.
* An earlier change that broke .gitignore matching has been reverted.
* SubmittingPatches document gained a syntactically incorrect mark-up,
which has been corrected.
- git 2.33.0:
* 'git send-email' learned the '--sendmail-cmd' command line option
and the 'sendemail.sendmailCmd' configuration variable, which is a
more sensible approach than the current way of repurposing the
'smtp-server' that is meant to name the server to instead name the
command to talk to the server.
* The userdiff pattern for C# learned the token 'record'.
* 'git rev-list' learns to omit the 'commit ' header
lines from the output with the `--no-commit-header` option.
* 'git worktree add --lock' learned to record why the worktree is
locked with a custom message.
* internal improvements including performance optimizations
* a number of bug fixes
- git 2.32.0:
* '.gitattributes', '.gitignore', and '.mailmap' files that are
symbolic links are ignored
* 'git apply --3way' used to first attempt a straight
application, and only fell back to the 3-way merge algorithm
when the straight application failed. Starting with this
version, the command will first try the 3-way merge algorithm
and only when it fails (either resulting with conflict or the
base versions of blobs are missing), falls back to the usual
patch application.
* 'git stash show' can now show the untracked part of the stash
* Improved 'git repack' strategy
* http code can now unlock a certificate with a cached password
respectively.
* 'git clone --reject-shallow' option fails the clone as soon as
we notice that we are cloning from a shallow repository.
* 'gitweb' learned 'e-mail privacy' feature
* Multiple improvements to output and configuration options
* Bug fixes and developer visible fixes
| Advisory ID | SUSE-SU-2022:330-1
|
| Released | Fri Feb 4 09:29:08 2022 |
| Summary | Security update for glibc |
| Type | security |
| Severity | important |
| References | 1194640,1194768,1194770,1194785,CVE-2021-3999,CVE-2022-23218,CVE-2022-23219 |
Description:
This update for glibc fixes the following issues:
- CVE-2021-3999: Fixed incorrect errno in getcwd (bsc#1194640)
- CVE-2022-23219: Fixed buffer overflow in sunrpc clnt_create for 'unix' (bsc#1194768)
- CVE-2022-23218: Fixed buffer overflow in sunrpc svcunix_create (bsc#1194770)
Features added:
- IBM Power 10 string operation improvements (bsc#1194785, jsc#SLE-18195)
| Advisory ID | SUSE-RU-2022:520-1
|
| Released | Fri Feb 18 12:45:19 2022 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | moderate |
| References | 1194968 |
Description:
This update for rpm fixes the following issues:
- Revert unwanted /usr/bin/python to /usr/bin/python2 change we got with the update to 4.14.3 (bsc#1194968)
| Advisory ID | SUSE-RU-2022:692-1
|
| Released | Thu Mar 3 15:46:47 2022 |
| Summary | Recommended update for filesystem |
| Type | recommended |
| Severity | moderate |
| References | 1190447 |
Description:
This update for filesystem fixes the following issues:
- Release ported filesystem to LTSS channels (bsc#1190447).
| Advisory ID | SUSE-RU-2022:789-1
|
| Released | Thu Mar 10 11:22:05 2022 |
| Summary | Recommended update for update-alternatives |
| Type | recommended |
| Severity | moderate |
| References | 1195654 |
Description:
This update for update-alternatives fixes the following issues:
- Break bash - update-alternatives cycle rewrite of '%post' in 'lua'. (bsc#1195654)
| Advisory ID | SUSE-RU-2022:861-1
|
| Released | Tue Mar 15 23:31:21 2022 |
| Summary | Recommended update for openssl-1_1 |
| Type | recommended |
| Severity | moderate |
| References | 1182959,1195149,1195792,1195856 |
Description:
This update for openssl-1_1 fixes the following issues:
openssl-1_1:
- Fix PAC pointer authentication in ARM (bsc#1195856)
- Pull libopenssl-1_1 when updating openssl-1_1 with the same version (bsc#1195792)
- FIPS: Fix function and reason error codes (bsc#1182959)
- Enable zlib compression support (bsc#1195149)
glibc:
- Resolve installation issue of `glibc-devel` in SUSE Linux Enterprise Micro 5.1
linux-glibc-devel:
- Resolve installation issue of `linux-kernel-headers` in SUSE Linux Enterprise Micro 5.1
libxcrypt:
- Resolve installation issue of `libxcrypt-devel` in SUSE Linux Enterprise Micro 5.1
zlib:
- Resolve installation issue of `zlib-devel` in SUSE Linux Enterprise Micro 5.1
| Advisory ID | SUSE-RU-2022:936-1
|
| Released | Tue Mar 22 18:10:17 2022 |
| Summary | Recommended update for filesystem and systemd-rpm-macros |
| Type | recommended |
| Severity | moderate |
| References | 1196275,1196406 |
Description:
This update for filesystem and systemd-rpm-macros fixes the following issues:
filesystem:
- Add path /lib/modprobe.d (bsc#1196275, jsc#SLE-20639)
systemd-rpm-macros:
- Make %_modprobedir point to /lib/modprobe.d (bsc#1196275, bsc#1196406)
| Advisory ID | SUSE-RU-2022:1047-1
|
| Released | Wed Mar 30 16:20:56 2022 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1196093,1197024 |
Description:
This update for pam fixes the following issues:
- Define _pam_vendordir as the variable is needed by systemd and others. (bsc#1196093)
- Between allocating the variable 'ai' and free'ing them, there are two 'return NO' were we don't free this variable.
This patch inserts freaddrinfo() calls before the 'return NO;'s. (bsc#1197024)
| Advisory ID | SUSE-RU-2022:1118-1
|
| Released | Tue Apr 5 18:34:06 2022 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2022a (bsc#1177460):
* Palestine will spring forward on 2022-03-27, not on 03-26
* `zdump -v` now outputs better failure indications
* Bug fixes for code that reads corrupted TZif data
| Advisory ID | SUSE-SU-2022:1158-1
|
| Released | Tue Apr 12 14:44:43 2022 |
| Summary | Security update for xz |
| Type | security |
| Severity | important |
| References | 1198062,CVE-2022-1271 |
Description:
This update for xz fixes the following issues:
- CVE-2022-1271: Fixed an incorrect escaping of malicious filenames (ZDI-CAN-16587). (bsc#1198062)
| Advisory ID | SUSE-RU-2022:1281-1
|
| Released | Wed Apr 20 12:26:38 2022 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | moderate |
| References | 1196647 |
Description:
This update for libtirpc fixes the following issues:
- Add option to enforce connection via protocol version 2 first (bsc#1196647)
| Advisory ID | SUSE-RU-2022:1374-1
|
| Released | Mon Apr 25 15:02:13 2022 |
| Summary | Recommended update for openldap2 |
| Type | recommended |
| Severity | moderate |
| References | 1191157,1197004 |
Description:
This update for openldap2 fixes the following issues:
- allow specification of max/min TLS version with TLS1.3 (bsc#1191157)
- libldap was able to be out of step with openldap in some cases which could cause incorrect installations and symbol
resolution failures. openldap2 and libldap now are locked to their related release versions. (bsc#1197004)
- restore CLDAP functionality in CLI tools (jsc#PM-3288)
| Advisory ID | SUSE-RU-2022:1409-1
|
| Released | Tue Apr 26 12:54:57 2022 |
| Summary | Recommended update for gcc11 |
| Type | recommended |
| Severity | moderate |
| References | 1195628,1196107 |
Description:
This update for gcc11 fixes the following issues:
- Add a list of Obsoletes to libstdc++6-pp-gcc11 so updates from
packages provided by older GCC work. Add a requires from that
package to the corresponding libstc++6 package to keep those
at the same version. [bsc#1196107]
- Fixed memory corruption when creating dependences with the D language frontend.
- Add gcc11-PIE, similar to gcc-PIE but affecting gcc11 [bsc#1195628]
- Put libstdc++6-pp Requires on the shared library and drop
to Recommends.
| Advisory ID | SUSE-RU-2022:1451-1
|
| Released | Thu Apr 28 10:47:22 2022 |
| Summary | Recommended update for perl |
| Type | recommended |
| Severity | moderate |
| References | 1193489 |
Description:
This update for perl fixes the following issues:
- Fix Socket::VERSION evaluation and stabilize Socket:VERSION comparisons (bsc#1193489)
| Advisory ID | SUSE-SU-2022:1484-1
|
| Released | Mon May 2 16:47:10 2022 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1181400,1198234,CVE-2022-24765 |
Description:
This update for git fixes the following issues:
- Updated to version 2.35.3:
- CVE-2022-24765: Fixed a potential command injection via git worktree (bsc#1198234).
| Advisory ID | SUSE-SU-2022:1548-1
|
| Released | Thu May 5 16:45:28 2022 |
| Summary | Security update for tar |
| Type | security |
| Severity | moderate |
| References | 1029961,1120610,1130496,1181131,CVE-2018-20482,CVE-2019-9923,CVE-2021-20193 |
Description:
This update for tar fixes the following issues:
- CVE-2021-20193: Fixed a memory leak in read_header() in list.c (bsc#1181131).
- CVE-2019-9923: Fixed a null-pointer dereference in pax_decode_header in sparse.c (bsc#1130496).
- CVE-2018-20482: Fixed infinite read loop in sparse_dump_region in sparse.c (bsc#1120610).
- Update to GNU tar 1.34:
* Fix extraction over pipe
* Fix memory leak in read_header (CVE-2021-20193) (bsc#1181131)
* Fix extraction when . and .. are unreadable
* Gracefully handle duplicate symlinks when extracting
* Re-initialize supplementary groups when switching to user
privileges
- Update to GNU tar 1.33:
* POSIX extended format headers do not include PID by default
* --delay-directory-restore works for archives with reversed
member ordering
* Fix extraction of a symbolic link hardlinked to another
symbolic link
* Wildcards in exclude-vcs-ignore mode don't match slash
* Fix the --no-overwrite-dir option
* Fix handling of chained renames in incremental backups
* Link counting works for file names supplied with -T
* Accept only position-sensitive (file-selection) options in file
list files
- prepare usrmerge (bsc#1029961)
- Update to GNU 1.32
* Fix the use of --checkpoint without explicit --checkpoint-action
* Fix extraction with the -U option
* Fix iconv usage on BSD-based systems
* Fix possible NULL dereference (savannah bug #55369)
[bsc#1130496] [CVE-2019-9923]
* Improve the testsuite
- Update to GNU 1.31
* Fix heap-buffer-overrun with --one-top-level, bug introduced
with the addition of that option in 1.28
* Support for zstd compression
* New option '--zstd' instructs tar to use zstd as compression
program. When listing, extractng and comparing, zstd compressed
archives are recognized automatically. When '-a' option is in
effect, zstd compression is selected if the destination archive
name ends in '.zst' or '.tzst'.
* The -K option interacts properly with member names given in the
command line. Names of members to extract can be specified along
with the '-K NAME' option. In this case, tar will extract NAME
and those of named members that appear in the archive after it,
which is consistent with the semantics of the option. Previous
versions of tar extracted NAME, those of named members that
appeared before it, and everything after it.
* Fix CVE-2018-20482 - When creating archives with the --sparse
option, previous versions of tar would loop endlessly if a
sparse file had been truncated while being archived.
| Advisory ID | SUSE-SU-2022:1617-1
|
| Released | Tue May 10 14:40:12 2022 |
| Summary | Security update for gzip |
| Type | security |
| Severity | important |
| References | 1198062,1198922,CVE-2022-1271 |
Description:
This update for gzip fixes the following issues:
- CVE-2022-1271: Fix escaping of malicious filenames. (bsc#1198062)
| Advisory ID | SUSE-RU-2022:1655-1
|
| Released | Fri May 13 15:36:10 2022 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | 1197794 |
Description:
This update for pam fixes the following issue:
- Do not include obsolete header files (bsc#1197794)
| Advisory ID | SUSE-RU-2022:1658-1
|
| Released | Fri May 13 15:40:20 2022 |
| Summary | Recommended update for libpsl |
| Type | recommended |
| Severity | important |
| References | 1197771 |
Description:
This update for libpsl fixes the following issues:
- Fix libpsl compilation issues (bsc#1197771)
| Advisory ID | SUSE-SU-2022:1670-1
|
| Released | Mon May 16 10:06:30 2022 |
| Summary | Security update for openldap2 |
| Type | security |
| Severity | important |
| References | 1199240,CVE-2022-29155 |
Description:
This update for openldap2 fixes the following issues:
- CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240).
| Advisory ID | SUSE-RU-2022:1709-1
|
| Released | Tue May 17 17:35:47 2022 |
| Summary | Recommended update for libcbor |
| Type | recommended |
| Severity | important |
| References | 1197743 |
Description:
This update for libcbor fixes the following issues:
- Fix build errors occuring on SUSE Linux Enterprise 15 Service Pack 4
| Advisory ID | SUSE-SU-2022:1718-1
|
| Released | Tue May 17 17:44:43 2022 |
| Summary | Security update for e2fsprogs |
| Type | security |
| Severity | important |
| References | 1198446,CVE-2022-1304 |
Description:
This update for e2fsprogs fixes the following issues:
- CVE-2022-1304: Fixed out-of-bounds read/write leading to segmentation fault
and possibly arbitrary code execution. (bsc#1198446)
| Advisory ID | SUSE-RU-2022:1887-1
|
| Released | Tue May 31 09:24:18 2022 |
| Summary | Recommended update for grep |
| Type | recommended |
| Severity | moderate |
| References | 1040589 |
Description:
This update for grep fixes the following issues:
- Make profiling deterministic. (bsc#1040589, SLE-24115)
| Advisory ID | SUSE-RU-2022:1899-1
|
| Released | Wed Jun 1 10:43:22 2022 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | important |
| References | 1198176 |
Description:
This update for libtirpc fixes the following issues:
- Add a check for nullpointer in check_address to prevent client from crashing (bsc#1198176)
| Advisory ID | SUSE-RU-2022:1909-1
|
| Released | Wed Jun 1 16:25:35 2022 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1198751 |
Description:
This update for glibc fixes the following issues:
- Add the correct name for the IBM Z16 (bsc#1198751).
| Advisory ID | SUSE-RU-2022:2019-1
|
| Released | Wed Jun 8 16:50:07 2022 |
| Summary | Recommended update for gcc11 |
| Type | recommended |
| Severity | moderate |
| References | 1192951,1193659,1195283,1196861,1197065 |
Description:
This update for gcc11 fixes the following issues:
Update to the GCC 11.3.0 release.
- includes SLS hardening backport on x86_64. [bsc#1195283]
- includes change to adjust gnats idea of the target, fixing the build of gprbuild. [bsc#1196861]
- fixed miscompile of embedded premake in 0ad on i586. [bsc#1197065]
- use --with-cpu rather than specifying --with-arch/--with-tune
- Fix D memory corruption in -M output.
- Fix ICE in is_this_parameter with coroutines. [bsc#1193659]
- fixes issue with debug dumping together with -o /dev/null
- fixes libgccjit issue showing up in emacs build [bsc#1192951]
- Package mwaitintrin.h
| Advisory ID | SUSE-SU-2022:2294-1
|
| Released | Wed Jul 6 13:34:15 2022 |
| Summary | Security update for expat |
| Type | security |
| Severity | important |
| References | 1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315 |
Description:
This update for expat fixes the following issues:
- CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025).
- Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784).
- CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026).
- CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168).
- CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169).
- CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).
| Advisory ID | SUSE-SU-2022:2305-1
|
| Released | Wed Jul 6 13:38:42 2022 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1200734,1200735,1200736,1200737,CVE-2022-32205,CVE-2022-32206,CVE-2022-32207,CVE-2022-32208 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32205: Set-Cookie denial of service (bsc#1200734)
- CVE-2022-32206: HTTP compression denial of service (bsc#1200735)
- CVE-2022-32207: Unpreserved file permissions (bsc#1200736)
- CVE-2022-32208: FTP-KRB bad message verification (bsc#1200737)
| Advisory ID | SUSE-SU-2022:2360-1
|
| Released | Tue Jul 12 12:01:39 2022 |
| Summary | Security update for pcre2 |
| Type | security |
| Severity | important |
| References | 1199232,CVE-2022-1586 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
| Advisory ID | SUSE-SU-2022:2361-1
|
| Released | Tue Jul 12 12:05:01 2022 |
| Summary | Security update for pcre |
| Type | security |
| Severity | important |
| References | 1199232,CVE-2022-1586 |
Description:
This update for pcre fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
| Advisory ID | SUSE-RU-2022:2406-1
|
| Released | Fri Jul 15 11:49:01 2022 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1197718,1199140,1200334,1200855 |
Description:
This update for glibc fixes the following issues:
- powerpc: Fix VSX register number on __strncpy_power9 (bsc#1200334)
- Disable warnings due to deprecated libselinux symbols used by nss and nscd (bsc#1197718)
- i386: Remove broken CAN_USE_REGISTER_ASM_EBP (bsc#1197718)
- rtld: Avoid using up static TLS surplus for optimizations (bsc#1200855, BZ #25051)
This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).
| Advisory ID | SUSE-RU-2022:2469-1
|
| Released | Thu Jul 21 04:38:31 2022 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | important |
| References | 1137373,1181658,1194708,1195157,1197570,1198732,1200170,1201276 |
Description:
This update for systemd fixes the following issues:
- Make {/etc,/usr/lib}/systemd/network owned by both udev and systemd-network. The configuration files put in these
directories are read by both udevd and systemd-networkd (bsc#1201276)
- Allow control characters in environment variable values (bsc#1200170)
- Fix issues with multipath setup (bsc#1137373, bsc#1181658, bsc#1194708, bsc#1195157, bsc#1197570)
- Fix parsing error in s390 udev rules conversion script (bsc#1198732)
- core/device: device_coldplug(): don't set DEVICE_DEAD
- core/device: do not downgrade device state if it is already enumerated
- core/device: drop unnecessary condition
| Advisory ID | SUSE-RU-2022:2493-1
|
| Released | Thu Jul 21 14:35:08 2022 |
| Summary | Recommended update for rpm-config-SUSE |
| Type | recommended |
| Severity | moderate |
| References | 1193282 |
Description:
This update for rpm-config-SUSE fixes the following issues:
- Add SBAT values macros for other packages (bsc#1193282)
| Advisory ID | SUSE-RU-2022:2494-1
|
| Released | Thu Jul 21 15:16:42 2022 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | important |
| References | 1200855,1201560,1201640 |
Description:
This update for glibc fixes the following issues:
- Remove tunables from static tls surplus patch which caused crashes (bsc#1200855)
- i386: Disable check_consistency for GCC 5 and above (bsc#1201640, BZ #25788)
| Advisory ID | SUSE-SU-2022:2550-1
|
| Released | Tue Jul 26 14:00:21 2022 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1201431,CVE-2022-29187 |
Description:
This update for git fixes the following issues:
- CVE-2022-29187: Incomplete fix for CVE-2022-24765: potential command injection via git worktree (bsc#1201431).
| Advisory ID | SUSE-SU-2022:2566-1
|
| Released | Wed Jul 27 15:04:49 2022 |
| Summary | Security update for pcre2 |
| Type | security |
| Severity | important |
| References | 1199235,CVE-2022-1587 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1587: Fixed out-of-bounds read due to bug in recursions (bsc#1199235).
| Advisory ID | SUSE-SU-2022:2632-1
|
| Released | Wed Aug 3 09:51:00 2022 |
| Summary | Security update for permissions |
| Type | security |
| Severity | important |
| References | 1198720,1200747,1201385 |
Description:
This update for permissions fixes the following issues:
- apptainer: fix starter-suid location (bsc#1198720)
- static permissions: remove deprecated bind / named chroot entries (bsc#1200747)
- postfix: add postlog setgid for maildrop binary (bsc#1201385)
| Advisory ID | SUSE-SU-2022:2717-1
|
| Released | Tue Aug 9 12:54:16 2022 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1198627,CVE-2022-29458 |
Description:
This update for ncurses fixes the following issues:
- CVE-2022-29458: Fixed segfaulting out-of-bounds read in convert_strings in tinfo/read_entry.c (bsc#1198627).
| Advisory ID | SUSE-RU-2022:2735-1
|
| Released | Wed Aug 10 04:31:41 2022 |
| Summary | Recommended update for tar |
| Type | recommended |
| Severity | moderate |
| References | 1200657 |
Description:
This update for tar fixes the following issues:
- Fix race condition while creating intermediate subdirectories (bsc#1200657)
| Advisory ID | SUSE-RU-2022:2796-1
|
| Released | Fri Aug 12 14:34:31 2022 |
| Summary | Recommended update for jitterentropy |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for jitterentropy fixes the following issues:
jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library,
used by other FIPS libraries.
| Advisory ID | SUSE-RU-2022:2844-1
|
| Released | Thu Aug 18 14:41:25 2022 |
| Summary | Recommended update for tar |
| Type | recommended |
| Severity | important |
| References | 1202436 |
Description:
This update for tar fixes the following issues:
- A regression in a previous update lead to potential deadlocks when extracting an archive. (bsc#1202436)
| Advisory ID | SUSE-RU-2022:2901-1
|
| Released | Fri Aug 26 03:34:23 2022 |
| Summary | Recommended update for elfutils |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for elfutils fixes the following issues:
- Fix runtime dependency for devel package
| Advisory ID | SUSE-RU-2022:2904-1
|
| Released | Fri Aug 26 05:28:34 2022 |
| Summary | Recommended update for openldap2 |
| Type | recommended |
| Severity | moderate |
| References | 1198341 |
Description:
This update for openldap2 fixes the following issues:
- Prevent memory reuse which may lead to instability (bsc#1198341)
| Advisory ID | SUSE-RU-2022:2920-1
|
| Released | Fri Aug 26 15:17:02 2022 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | important |
| References | 1195059,1201795 |
Description:
This update for systemd fixes the following issues:
- Don't replace /etc/systemd/system/tmp.mount symlink with a dangling one pointing to /usr/lib/systemd/ (bsc#1201795)
- Drop or soften some of the deprecation warnings (jsc#PED-944)
- Ensure root user can login even if systemd-user-sessions.service is not activated yet (bsc#1195059)
- Avoid applying presets to any services shipped by the experimental sub-package, as they aren't enabled by default
- analyze: Fix offline check for syscal filter
- calendarspec: Fix timer skipping the next elapse
- core: Allow command argument to be longer
- hwdb: Add AV production controllers to hwdb and add uaccess
- hwdb: Allow console users access to rfkill
- hwdb: Allow end-users root-less access to TL866 EPROM readers
- hwdb: Permit unsetting power/persist for USB devices
- hwdb: Tag IR cameras as such
- hwdb: Fix parsing issue
- hwdb: Make usb match patterns uppercase
- hwdb: Update the hardware database
- journal-file: Stop using the event loop if it's already shutting down
- journal-remote: Disable `--trust` option when gnutls is disabled and check_permission() should not be called
- journald: Ensure resources are properly allocated for SIGTERM handling
- kernel-install: Ensure modules.builtin.alias.bin is removed when no longer needed
- macro: Account for negative values in DECIMAL_STR_WIDTH()
- manager: Disallow clone3() function call in seccomp filters
- missing-syscall: Define MOVE_MOUNT_T_EMPTY_PATH if missing
- pid1,cgroup-show: Prevent failure if cgroup.procs in some subcgroups is not readable
- resolve: Fix typo in dns_class_is_pseudo()
- sd-event: Improve handling of process events and termination of processes
- sd-ipv4acd: Fix ARP packet conflicts occurring when sender hardware is one of the host's interfaces
- stdio-bridge: Improve the meaning of the error message
- tmpfiles: Check for the correct directory
| Advisory ID | SUSE-RU-2022:2929-1
|
| Released | Mon Aug 29 11:21:47 2022 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | important |
| References | 1202310 |
Description:
This update for timezone fixes the following issue:
- Reflect new Chile DST change (bsc#1202310)
| Advisory ID | SUSE-SU-2022:3003-1
|
| Released | Fri Sep 2 15:01:44 2022 |
| Summary | Security update for curl |
| Type | security |
| Severity | low |
| References | 1202593,CVE-2022-35252 |
Description:
This update for curl fixes the following issues:
- CVE-2022-35252: Fixed a potential injection of control characters
into cookies, which could be exploited by sister sites to cause a
denial of service (bsc#1202593).
| Advisory ID | SUSE-RU-2022:3127-1
|
| Released | Wed Sep 7 04:36:10 2022 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | moderate |
| References | 1198752,1200800 |
Description:
This update for libtirpc fixes the following issues:
- Exclude ipv6 addresses in client protocol version 2 code (bsc#1200800)
- Fix memory leak in params.r_addr assignement (bsc#1198752)
| Advisory ID | SUSE-RU-2022:3215-1
|
| Released | Thu Sep 8 15:58:27 2022 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for rpm fixes the following issues:
- Support Ed25519 RPM signatures [jsc#SLE-24714]
| Advisory ID | SUSE-RU-2022:3262-1
|
| Released | Tue Sep 13 15:34:29 2022 |
| Summary | Recommended update for gcc11 |
| Type | recommended |
| Severity | moderate |
| References | 1199140 |
Description:
This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)
| Advisory ID | SUSE-SU-2022:3271-1
|
| Released | Wed Sep 14 06:45:39 2022 |
| Summary | Security update for perl |
| Type | security |
| Severity | moderate |
| References | 1047178,CVE-2017-6512 |
Description:
This update for perl fixes the following issues:
- CVE-2017-6512: Fixed File::Path rmtree/remove_tree race condition (bsc#1047178).
| Advisory ID | SUSE-SU-2022:3305-1
|
| Released | Mon Sep 19 11:45:57 2022 |
| Summary | Security update for libtirpc |
| Type | security |
| Severity | important |
| References | 1201680,CVE-2021-46828 |
Description:
This update for libtirpc fixes the following issues:
- CVE-2021-46828: Fixed denial of service vulnerability with lots of connections (bsc#1201680).
| Advisory ID | SUSE-RU-2022:3328-1
|
| Released | Wed Sep 21 12:48:56 2022 |
| Summary | Recommended update for jitterentropy |
| Type | recommended |
| Severity | moderate |
| References | 1202870 |
Description:
This update for jitterentropy fixes the following issues:
- Hide the non-GNUC constructs that are library internal from the
exported header, to make it usable in builds with strict C99
compliance. (bsc#1202870)
| Advisory ID | SUSE-SU-2022:3353-1
|
| Released | Fri Sep 23 15:23:40 2022 |
| Summary | Security update for permissions |
| Type | security |
| Severity | moderate |
| References | 1203018,CVE-2022-31252 |
Description:
This update for permissions fixes the following issues:
- CVE-2022-31252: Fixed chkstat group controlled paths (bsc#1203018).
| Advisory ID | SUSE-RU-2022:3452-1
|
| Released | Wed Sep 28 12:13:43 2022 |
| Summary | Recommended update for glibc |
| Type | recommended |
| Severity | moderate |
| References | 1201942 |
Description:
This update for glibc fixes the following issues:
- Reversing calculation of __x86_shared_non_temporal_threshold (bsc#1201942)
- powerpc: Optimized memcmp for power10 (jsc#PED-987)
| Advisory ID | SUSE-SU-2022:3489-1
|
| Released | Sat Oct 1 13:35:24 2022 |
| Summary | Security update for expat |
| Type | security |
| Severity | important |
| References | 1203438,CVE-2022-40674 |
Description:
This update for expat fixes the following issues:
- CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438).
| Advisory ID | SUSE-RU-2022:3555-1
|
| Released | Mon Oct 10 14:05:12 2022 |
| Summary | Recommended update for aaa_base |
| Type | recommended |
| Severity | important |
| References | 1199492 |
Description:
This update for aaa_base fixes the following issues:
- The wrapper rootsh is not a restricted shell. (bsc#1199492)
| Advisory ID | SUSE-SU-2022:3785-1
|
| Released | Wed Oct 26 20:20:19 2022 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1204383,1204386,CVE-2022-32221,CVE-2022-42916 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383).
- CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386).
| Advisory ID | SUSE-RU-2022:3787-1
|
| Released | Thu Oct 27 04:41:09 2022 |
| Summary | Recommended update for permissions |
| Type | recommended |
| Severity | important |
| References | 1194047,1203911 |
Description:
This update for permissions fixes the following issues:
- Fix regression introduced by backport of security fix (bsc#1203911)
- Add permissions for enlightenment helper on 32bit arches (bsc#1194047)
| Advisory ID | SUSE-SU-2022:3884-1
|
| Released | Mon Nov 7 10:59:26 2022 |
| Summary | Security update for expat |
| Type | security |
| Severity | important |
| References | 1204708,CVE-2022-43680 |
Description:
This update for expat fixes the following issues:
- CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).
| Advisory ID | SUSE-RU-2022:3904-1
|
| Released | Tue Nov 8 10:52:13 2022 |
| Summary | Recommended update for openssh |
| Type | recommended |
| Severity | moderate |
| References | 1192439 |
Description:
This update for openssh fixes the following issue:
- Prevent empty messages from being sent. (bsc#1192439)
| Advisory ID | SUSE-RU-2022:3910-1
|
| Released | Tue Nov 8 13:05:04 2022 |
| Summary | Recommended update for pam |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for pam fixes the following issue:
- Update pam_motd to the most current version. (PED-1712)
| Advisory ID | SUSE-SU-2022:3931-1
|
| Released | Thu Nov 10 11:26:01 2022 |
| Summary | Security update for git |
| Type | security |
| Severity | moderate |
| References | 1204455,1204456,CVE-2022-39253,CVE-2022-39260 |
Description:
This update for git fixes the following issues:
- CVE-2022-39260: Fixed overflow in split_cmdline() (bsc#1204456).
- CVE-2022-39253: Fixed dereference issue with symbolic links via the `--local` clone mechanism (bsc#1204455).
| Advisory ID | SUSE-SU-2022:3999-1
|
| Released | Tue Nov 15 17:08:04 2022 |
| Summary | Security update for systemd |
| Type | security |
| Severity | moderate |
| References | 1204179,1204968,CVE-2022-3821 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).
- Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428
* 0469b9f2bc pstore: do not try to load all known pstore modules
* ad05f54439 pstore: Run after modules are loaded
* ccad817445 core: Add trigger limit for path units
* 281d818fe3 core/mount: also add default before dependency for automount mount units
* ffe5b4afa8 logind: fix crash in logind on user-specified message string
- Document udev naming scheme (bsc#1204179)
- Make 'sle15-sp3' net naming scheme still available for backward compatibility
reason
| Advisory ID | SUSE-RU-2022:4066-1
|
| Released | Fri Nov 18 10:43:00 2022 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | important |
| References | 1177460,1202324,1204649,1205156 |
Description:
This update for timezone fixes the following issues:
Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156):
- Mexico will no longer observe DST except near the US border
- Chihuahua moves to year-round -06 on 2022-10-30
- Fiji no longer observes DST
- In vanguard form, GMT is now a Zone and Etc/GMT a link
- zic now supports links to links, and vanguard form uses this
- Simplify four Ontario zones
- Fix a Y2438 bug when reading TZif data
- Enable 64-bit time_t on 32-bit glibc platforms
- Omit large-file support when no longer needed
- Jordan and Syria switch from +02/+03 with DST to year-round +03
- Palestine transitions are now Saturdays at 02:00
- Simplify three Ukraine zones into one
- Improve tzselect on intercontinental Zones
- Chile's DST is delayed by a week in September 2022 (bsc#1202324)
- Iran no longer observes DST after 2022
- Rename Europe/Kiev to Europe/Kyiv
- New `zic -R` command option
- Vanguard form now uses %z
| Advisory ID | SUSE-SU-2022:4081-1
|
| Released | Fri Nov 18 15:40:46 2022 |
| Summary | Security update for dpkg |
| Type | security |
| Severity | low |
| References | 1199944,CVE-2022-1664 |
Description:
This update for dpkg fixes the following issues:
- CVE-2022-1664: Fixed a directory traversal vulnerability in Dpkg::Source::Archive (bsc#1199944).
| Advisory ID | SUSE-RU-2022:4135-1
|
| Released | Mon Nov 21 00:13:40 2022 |
| Summary | Recommended update for libeconf |
| Type | recommended |
| Severity | moderate |
| References | 1198165 |
Description:
This update for libeconf fixes the following issues:
- Update to version 0.4.6+git
- econftool:
Parsing error: Reporting file and line nr. --delimeters=spaces accepting all kind of spaces for delimiter.
- libeconf:
Parse files correctly on space characters (1198165)
- Update to version 0.4.5+git
- econftool:
New call 'syntax' for checking the configuration files only. Returns an error string with line number if error.
New options '--comment' and '--delimeters'
| Advisory ID | SUSE-RU-2022:4198-1
|
| Released | Wed Nov 23 13:15:04 2022 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | moderate |
| References | 1202750 |
Description:
This update for rpm fixes the following issues:
- Strip critical bit in signature subpackage parsing
- No longer deadlock DNF after pubkey import (bsc#1202750)
| Advisory ID | SUSE-RU-2022:4256-1
|
| Released | Mon Nov 28 12:36:32 2022 |
| Summary | Recommended update for gcc12 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for gcc12 fixes the following issues:
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
The Go, D and Ada language compiler parts are available unsupported via the
PackageHub repositories.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your Makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
| Advisory ID | SUSE-RU-2022:4312-1
|
| Released | Fri Dec 2 11:16:47 2022 |
| Summary | Recommended update for tar |
| Type | recommended |
| Severity | moderate |
| References | 1200657,1203600 |
Description:
This update for tar fixes the following issues:
- Fix unexpected inconsistency when making directory (bsc#1203600)
- Update race condition fix (bsc#1200657)
| Advisory ID | SUSE-RU-2022:4499-1
|
| Released | Thu Dec 15 10:48:49 2022 |
| Summary | Recommended update for openssh |
| Type | recommended |
| Severity | moderate |
| References | 1179465 |
Description:
This update for openssh fixes the following issues:
- Make ssh connections update their dbus environment (bsc#1179465):
* Add openssh-dbus.sh, openssh-dbus.csh, openssh-dbus.fish
| Advisory ID | SUSE-SU-2022:4597-1
|
| Released | Wed Dec 21 10:13:11 2022 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1206308,1206309,CVE-2022-43551,CVE-2022-43552 |
Description:
This update for curl fixes the following issues:
- CVE-2022-43552: HTTP Proxy deny use-after-free (bsc#1206309).
- CVE-2022-43551: Fixed HSTS bypass via IDN (bsc#1206308).
| Advisory ID | SUSE-SU-2022:4629-1
|
| Released | Wed Dec 28 09:24:07 2022 |
| Summary | Security update for systemd |
| Type | security |
| Severity | important |
| References | 1200723,1205000,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).
Bug fixes:
- Support by-path devlink for multipath nvme block devices (bsc#1200723).
| Advisory ID | SUSE-RU-2023:25-1
|
| Released | Thu Jan 5 09:51:41 2023 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | moderate |
| References | 1177460 |
Description:
This update for timezone fixes the following issues:
Version update from 2022f to 2022g (bsc#1177460):
- In the Mexican state of Chihuahua:
* The border strip near the US will change to agree with nearby US locations on 2022-11-30.
* The strip's western part, represented by Ciudad Juarez, switches from -06 all year to -07/-06 with US DST rules,
like El Paso, TX.
* The eastern part, represented by Ojinaga, will observe US DST next year, like Presidio, TX.
* A new Zone America/Ciudad_Juarez splits from America/Ojinaga.
- Much of Greenland, represented by America/Nuuk, stops observing winter time after March 2023, so its daylight saving
time becomes standard time.
- Changes for pre-1996 northern Canada
- Update to past DST transition in Colombia (1993), Singapore (1981)
- 'timegm' is now supported by default
| Advisory ID | SUSE-RU-2023:48-1
|
| Released | Mon Jan 9 10:37:54 2023 |
| Summary | Recommended update for libtirpc |
| Type | recommended |
| Severity | moderate |
| References | 1199467 |
Description:
This update for libtirpc fixes the following issues:
- Consider /proc/sys/net/ipv4/ip_local_reserved_ports, before binding to a random port (bsc#1199467)
| Advisory ID | SUSE-RU-2023:50-1
|
| Released | Mon Jan 9 10:42:21 2023 |
| Summary | Recommended update for shadow |
| Type | recommended |
| Severity | moderate |
| References | 1205502 |
Description:
This update for shadow fixes the following issues:
- Fix issue with user id field that cannot be interpreted (bsc#1205502)
| Advisory ID | SUSE-SU-2023:110-1
|
| Released | Fri Jan 20 10:18:16 2023 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1207032,1207033,CVE-2022-23521,CVE-2022-41903 |
Description:
This update for git fixes the following issues:
- CVE-2022-41903: Fixed a heap overflow in the 'git archive' and
'git log --format' commands (bsc#1207033).
- CVE-2022-23521: Fixed an integer overflow that could be triggered
when parsing a gitattributes file (bsc#1207032).
| Advisory ID | SUSE-RU-2023:179-1
|
| Released | Thu Jan 26 21:54:30 2023 |
| Summary | Recommended update for tar |
| Type | recommended |
| Severity | low |
| References | 1202436 |
Description:
This update for tar fixes the following issue:
- Fix hang when unpacking test tarball (bsc#1202436)
| Advisory ID | SUSE-SU-2023:201-1
|
| Released | Fri Jan 27 15:24:15 2023 |
| Summary | Security update for systemd |
| Type | security |
| Severity | moderate |
| References | 1204944,1205000,1207264,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed an issue where users could access coredumps
with changed uid, gid or capabilities (bsc#1205000).
Non-security fixes:
- Enabled the pstore service (jsc#PED-2663).
- Fixed an issue accessing TPM when secure boot is enabled (bsc#1204944).
- Fixed an issue where a pamd file could get accidentally overwritten
after an update (bsc#1207264).
| Advisory ID | SUSE-SU-2023:348-1
|
| Released | Fri Feb 10 15:08:41 2023 |
| Summary | Security update for less |
| Type | security |
| Severity | moderate |
| References | 1207815,CVE-2022-46663 |
Description:
This update for less fixes the following issues:
- CVE-2022-46663: Fixed denial-of-service by printing specially crafted escape sequences to the terminal (bsc#1207815).
| Advisory ID | SUSE-SU-2023:419-1
|
| Released | Wed Feb 15 11:45:51 2023 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | moderate |
| References | 1200303,1201325,1201326,1201327,1201328,1203831,1203832,1205042,1205119,1205236,CVE-2022-32212,CVE-2022-32213,CVE-2022-32214,CVE-2022-32215,CVE-2022-35255,CVE-2022-35256,CVE-2022-43548 |
Description:
This update for nodejs18 fixes the following issues:
This update ships nodejs18 (jsc#PED-2097)
Update to NodejJS 18.13.0 LTS:
- build: disable v8 snapshot compression by default
- crypto: update root certificates
- deps: update ICU to 72.1
- doc:
+ add doc-only deprecation for headers/trailers setters
+ add Rafael to the tsc
+ deprecate use of invalid ports in url.parse
+ deprecate url.parse()
- lib: drop fetch experimental warning
- net: add autoSelectFamily and autoSelectFamilyAttemptTimeout options
- src:
+ add uvwasi version
+ add initial shadow realm support
+ add t.after() hook
+ don't use a symbol for runHook()
+ add 'ca' property to certificate object
+ add fast path for utf8 encoding
+ improve textdecoder decode performance
+ add MIME utilities
- Fixes compatibility with ICU 72.1 (bsc#1205236)
- Fix migration to openssl-3 (bsc#1205042)
Update to NodeJS 18.12.1 LTS:
- inspector: DNS rebinding in --inspect via invalid octal IP
(bsc#1205119, CVE-2022-43548)
Update to NodeJS 18.12.0 LTS:
- Running in 'watch' mode using node --watch restarts the process
when an imported file is changed.
- fs: add FileHandle.prototype.readLines
- http: add writeEarlyHints function to ServerResponse
- http2: make early hints generic
- util: add default value option to parsearg
Update to NodeJS 18.11.0:
- added experimental watch mode -- running in 'watch' mode using
node --watch restarts the process when an imported file is changed
- fs: add FileHandle.prototype.readLines
- http: add writeEarlyHints function to ServerResponse
- http2: make early hints generic
- lib: refactor transferable AbortSignal
- src: add detailed embedder process initialization API
- util: add default value option to parsearg
Update to NodeJS 18.10.0:
- deps: upgrade npm to 8.19.2
- http: throw error on content-length mismatch
- stream: add ReadableByteStream.tee()
Update to Nodejs 18.9.1:
- deps: llhttp updated to 6.0.10
+ CVE-2022-32213 bypass via obs-fold mechanic (bsc#1201325)
+ Incorrect Parsing of Multi-line Transfer-Encoding
(CVE-2022-32215, bsc#1201327)
+ Incorrect Parsing of Header Fields (CVE-2022-35256, bsc#1203832)
- crypto: fix weak randomness in WebCrypto keygen
(CVE-2022-35255, bsc#1203831)
Update to Nodejs 18.9.0:
- lib - add diagnostics channel for process and worker
- os - add machine method
- report - expose report public native apis
- src - expose environment RequestInterrupt api
- vm - include vm context in the embedded snapshot
Changes in 18.8.0:
- bootstrap: implement run-time user-land snapshots via
--build-snapshot and --snapshot-blob. See
- crypto:
+ allow zero-length IKM in HKDF and in webcrypto PBKDF2
+ allow zero-length secret KeyObject
- deps: upgrade npm to 8.18.0
- http: make idle http parser count configurable
- net: add local family
- src: print source map error source on demand
- tls: pass a valid socket on tlsClientError
Update to Nodejs 18.7.0:
- events: add CustomEvent
- http: add drop request event for http server
- lib: improved diagnostics_channel subscribe/unsubscribe
- util: add tokens to parseArgs
- enable crypto policy ciphers for TW and SLE15 SP4+ (bsc#1200303)
Update to Nodejs 18.6.0:
- Experimental ESM Loader Hooks API. For details see,
https://nodejs.org/api/esm.html
- dns: export error code constants from dns/promises
- esm: add chaining to loaders
- http: add diagnostics channel for http client
- http: add perf_hooks detail for http request and client
- module: add isBuiltIn method
- net: add drop event for net server
- test_runner: expose describe and it
- v8: add v8.startupSnapshot utils
For details, see
https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.6.0
Update to Nodejs 18.5.0:
- http: stricter Transfer-Encoding and header separator parsing
(bsc#1201325, bsc#1201326, bsc#1201327,
CVE-2022-32213, CVE-2022-32214, CVE-2022-32215)
- src: fix IPv4 validation in inspector_socket
(bsc#1201328, CVE-2022-32212)
For details, see
https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.5.0
Update to Nodejs 18.4.0. For detailed changes see,
https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.4.0
Initial packaging of Nodejs 18.2.0. For detailed changes since previous versions, see
https://github.com/nodejs/node/blob/master/doc/changelogs/CHANGELOG_V18.md#18.2.0
| Advisory ID | SUSE-SU-2023:429-1
|
| Released | Wed Feb 15 17:41:22 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1207990,1207991,1207992,CVE-2023-23914,CVE-2023-23915,CVE-2023-23916 |
Description:
This update for curl fixes the following issues:
- CVE-2023-23914: Fixed HSTS ignored on multiple requests (bsc#1207990).
- CVE-2023-23915: Fixed HSTS amnesia with --parallel (bsc#1207991).
- CVE-2023-23916: Fixed HTTP multi-header compression denial of service (bsc#1207992).
| Advisory ID | SUSE-SU-2023:430-1
|
| Released | Wed Feb 15 17:42:25 2023 |
| Summary | Security update for git |
| Type | security |
| Severity | important |
| References | 1208027,1208028,CVE-2023-22490,CVE-2023-23946 |
Description:
This update for git fixes the following issues:
- CVE-2023-22490: Fixed incorrectly usable local clone optimization even when using a non-local transport (bsc#1208027).
- CVE-2023-23946: Fixed issue where a path outside the working tree can be overwritten as the user who is running 'git apply' (bsc#1208028).
| Advisory ID | SUSE-SU-2023:463-1
|
| Released | Mon Feb 20 16:33:39 2023 |
| Summary | Security update for tar |
| Type | security |
| Severity | moderate |
| References | 1202436,1207753,CVE-2022-48303 |
Description:
This update for tar fixes the following issues:
- CVE-2022-48303: Fixed a one-byte out-of-bounds read that resulted in use of uninitialized memory for a conditional jump (bsc#1207753).
Bug fixes:
- Fix hang when unpacking test tarball (bsc#1202436).
| Advisory ID | SUSE-RU-2023:464-1
|
| Released | Mon Feb 20 18:11:37 2023 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for systemd fixes the following issues:
- Merge of v249.15
- Drop workaround related to systemd-timesyncd that addressed a Factory issue.
- Conditionalize the use of /lib/modprobe.d only on systems with split usr
support enabled (i.e. SLE).
- Make use of the %systemd_* rpm macros consistently. Using the upstream
variants will ease the backports of Factory changes to SLE since Factory
systemd uses the upstream variants exclusively.
- machines.target belongs to systemd-container, do its init/cleanup steps from
the scriptlets of this sub-package.
- Make sure we apply the presets on units shipped by systemd package.
- systemd-testsuite: move the integration tests in a dedicated sub directory.
- Move systemd-cryptenroll into udev package.
| Advisory ID | SUSE-SU-2023:486-1
|
| Released | Thu Feb 23 10:38:13 2023 |
| Summary | Security update for c-ares |
| Type | security |
| Severity | important |
| References | 1208067,CVE-2022-4904 |
Description:
This update for c-ares fixes the following issues:
Updated to version 1.19.0:
- CVE-2022-4904: Fixed missing string length check in config_sortlist() (bsc#1208067).
| Advisory ID | SUSE-RU-2023:617-1
|
| Released | Fri Mar 3 16:49:06 2023 |
| Summary | Recommended update for jitterentropy |
| Type | recommended |
| Severity | moderate |
| References | 1207789 |
Description:
This update for jitterentropy fixes the following issues:
- build jitterentropy library with debuginfo (bsc#1207789)
| Advisory ID | SUSE-RU-2023:714-1
|
| Released | Mon Mar 13 10:53:25 2023 |
| Summary | Recommended update for rpm |
| Type | recommended |
| Severity | important |
| References | 1207294 |
Description:
This update for rpm fixes the following issues:
- Fix missing python(abi) for 3.XX versions (bsc#1207294)
| Advisory ID | SUSE-SU-2023:738-1
|
| Released | Wed Mar 15 08:17:45 2023 |
| Summary | Security update for nodejs18 |
| Type | security |
| Severity | important |
| References | 1208413,1208481,1208483,1208485,1208487,CVE-2023-23918,CVE-2023-23919,CVE-2023-23920,CVE-2023-23936,CVE-2023-24807 |
Description:
This update for nodejs18 fixes the following issues:
Update to NodeJS 18.14.2 LTS:
- CVE-2023-23918: Fixed permissions policies that could have been bypassed via process.mainModule (bsc#1208481).
- CVE-2023-23919: Fixed OpenSSL error handling issues in nodejs crypto library (bsc#1208483).
- CVE-2023-23920: Fixed insecure loading of ICU data through ICU_DATA environment (bsc#1208487).
- CVE-2023-23936: Fixed protection against CRLF injection in host headers inside fetch API (bsc#1208485).
- CVE-2023-24807: Fixed possible Regular Expression Denial of Service (ReDoS) via Headers.set() and Headers.append() methods (bsc#1208413).
| Advisory ID | SUSE-RU-2023:776-1
|
| Released | Thu Mar 16 17:29:23 2023 |
| Summary | Recommended update for gcc12 |
| Type | recommended |
| Severity | moderate |
| References | |
Description:
This update for gcc12 fixes the following issues:
This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided in the SUSE Linux
Enterprise Module for Development Tools.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
| Advisory ID | SUSE-SU-2023:1582-1
|
| Released | Mon Mar 27 10:31:52 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | moderate |
| References | 1209209,1209210,1209211,1209212,1209214,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538 |
Description:
This update for curl fixes the following issues:
- CVE-2023-27533: Fixed TELNET option IAC injection (bsc#1209209).
- CVE-2023-27534: Fixed SFTP path ~ resolving discrepancy (bsc#1209210).
- CVE-2023-27535: Fixed FTP too eager connection reuse (bsc#1209211).
- CVE-2023-27536: Fixed GSS delegation too eager connection reuse (bsc#1209212).
- CVE-2023-27538: Fixed SSH connection too eager reuse still (bsc#1209214).
| Advisory ID | SUSE-RU-2023:1662-1
|
| Released | Wed Mar 29 10:36:23 2023 |
| Summary | Recommended update for patterns-base |
| Type | recommended |
| Severity | moderate |
| References | 1203537 |
Description:
This update for patterns-base fixes the following issues:
- change label of FIPS 140-2 to 140-3 to reflect our current certifications (bsc#1203537)
| Advisory ID | SUSE-SU-2023:1688-1
|
| Released | Wed Mar 29 18:19:10 2023 |
| Summary | Security update for zstd |
| Type | security |
| Severity | moderate |
| References | 1209533,CVE-2022-4899 |
Description:
This update for zstd fixes the following issues:
- CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533).
| Advisory ID | SUSE-SU-2023:1718-1
|
| Released | Fri Mar 31 15:47:34 2023 |
| Summary | Security update for glibc |
| Type | security |
| Severity | moderate |
| References | 1207571,1207957,1207975,1208358,CVE-2023-0687 |
Description:
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-0687: Fix allocated buffer overflow in gmon (bsc#1207975)
Other issues fixed:
- Fix avx2 strncmp offset compare condition check (bsc#1208358)
- elf: Allow dlopen of filter object to work (bsc#1207571)
- powerpc: Fix unrecognized instruction errors with recent GCC
- x86: Cache computation for AMD architecture (bsc#1207957)
| Advisory ID | SUSE-RU-2023:1779-1
|
| Released | Thu Apr 6 08:16:58 2023 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | 1208432 |
Description:
This update for systemd fixes the following issues:
- Fix return non-zero value when disabling SysVinit service (bsc#1208432)
- Drop build requirement on libpci, it's not no longer needed
- Move systemd-boot and all components managing (secure) UEFI boot into udev
sub-package, so they aren't installed in systemd based containers
| Advisory ID | SUSE-RU-2023:1805-1
|
| Released | Tue Apr 11 10:12:41 2023 |
| Summary | Recommended update for timezone |
| Type | recommended |
| Severity | important |
| References | |
Description:
This update for timezone fixes the following issues:
- Version update from 2022g to 2023c:
* Egypt now uses DST again, from April through October.
* This year Morocco springs forward April 23, not April 30.
* Palestine delays the start of DST this year.
* Much of Greenland still uses DST from 2024 on.
* America/Yellowknife now links to America/Edmonton.
* tzselect can now use current time to help infer timezone.
* The code now defaults to C99 or later.
| Advisory ID | SUSE-SU-2023:2038-1
|
| Released | Wed Apr 26 11:06:20 2023 |
| Summary | Security update for git |
| Type | security |
| Severity | moderate |
| References | 1210686,CVE-2023-25652,CVE-2023-25815,CVE-2023-29007 |
Description:
This update for git fixes the following issues:
- CVE-2023-25652: Fixed partial overwrite of paths outside the working tree (bsc#1210686).
- CVE-2023-25815: Fixed malicious placemtn of crafted message (bsc#1210686).
- CVE-2023-29007: Fixed arbitrary configuration injection (bsc#1210686).
| Advisory ID | SUSE-SU-2023:2066-1
|
| Released | Fri Apr 28 13:54:17 2023 |
| Summary | Security update for shadow |
| Type | security |
| Severity | moderate |
| References | 1210507,CVE-2023-29383 |
Description:
This update for shadow fixes the following issues:
- CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507).
| Advisory ID | SUSE-SU-2023:2111-1
|
| Released | Fri May 5 14:34:00 2023 |
| Summary | Security update for ncurses |
| Type | security |
| Severity | moderate |
| References | 1210434,CVE-2023-29491 |
Description:
This update for ncurses fixes the following issues:
- CVE-2023-29491: Fixed memory corruption issues when processing malformed terminfo data (bsc#1210434).
| Advisory ID | SUSE-RU-2023:2131-1
|
| Released | Tue May 9 13:35:24 2023 |
| Summary | Recommended update for openssh |
| Type | recommended |
| Severity | important |
| References | 1207014 |
Description:
This update for openssh fixes the following issues:
- Remove some patches that cause invalid environment assignments (bsc#1207014).
| Advisory ID | SUSE-SU-2023:2224-1
|
| Released | Wed May 17 09:53:54 2023 |
| Summary | Security update for curl |
| Type | security |
| Severity | important |
| References | 1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322 |
Description:
This update for curl adds the following feature:
Update to version 8.0.1 (jsc#PED-2580)
- CVE-2023-28319: use-after-free in SSH sha256 fingerprint check (bsc#1211230).
- CVE-2023-28320: siglongjmp race condition (bsc#1211231).
- CVE-2023-28321: IDN wildcard matching (bsc#1211232).
- CVE-2023-28322: POST-after-PUT confusion (bsc#1211233).
| Advisory ID | SUSE-RU-2023:2240-1
|
| Released | Wed May 17 19:56:54 2023 |
| Summary | Recommended update for systemd |
| Type | recommended |
| Severity | moderate |
| References | 1203141,1207410 |
Description:
This update for systemd fixes the following issues:
- udev-rules: fix nvme symlink creation on namespace changes (bsc#1207410)
- Optimize when hundred workers claim the same symlink with the same priority (bsc#1203141)
- Add nss-resolve and systemd-network to Packagehub-Subpackages (MSC-626)
| Advisory ID | SUSE-SU-2023:2313-1
|
| Released | Tue May 30 09:29:25 2023 |
| Summary | Security update for c-ares |
| Type | security |
| Severity | important |
| References | 1211604,1211605,1211606,1211607,CVE-2023-31124,CVE-2023-31130,CVE-2023-31147,CVE-2023-32067 |
Description:
This update for c-ares fixes the following issues:
Update to version 1.19.1:
- CVE-2023-32067: 0-byte UDP payload causes Denial of Service (bsc#1211604)
- CVE-2023-31147: Insufficient randomness in generation of DNS query IDs (bsc#1211605)
- CVE-2023-31130: Buffer Underwrite in ares_inet_net_pton() (bsc#1211606)
- CVE-2023-31124: AutoTools does not set CARES_RANDOM_FILE during cross compilation (bsc#1211607)
- Fix uninitialized memory warning in test
- ares_getaddrinfo() should allow a port of 0
- Fix memory leak in ares_send() on error
- Fix comment style in ares_data.h
- Fix typo in ares_init_options.3
- Sync ax_pthread.m4 with upstream
- Sync ax_cxx_compile_stdcxx_11.m4 with upstream to fix uclibc support
| Advisory ID | SUSE-SU-2023:2484-1
|
| Released | Mon Jun 12 08:49:58 2023 |
| Summary | Security update for openldap2 |
| Type | security |
| Severity | moderate |
| References | 1211795,CVE-2023-2953 |
Description:
This update for openldap2 fixes the following issues:
- CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795).