Container summary for bci/python
SUSE-CU-2023:4266-1
Container Advisory ID | SUSE-CU-2023:4266-1 |
Container Tags | bci/python:3 , bci/python:3-16.44 , bci/python:3.10 , bci/python:3.10-16.44 |
Container Release | 16.44 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:4962-1
|
Released | Fri Dec 22 13:45:06 2023 |
Summary | Recommended update for curl |
Type | recommended |
Severity | important |
References | 1216987 |
Description:
This update for curl fixes the following issues:
- libssh: Implement SFTP packet size limit (bsc#1216987)
This update also ships curl to the INSTALLER channel.
SUSE-CU-2023:4204-1
Container Advisory ID | SUSE-CU-2023:4204-1 |
Container Tags | bci/python:3 , bci/python:3-16.43 , bci/python:3.10 , bci/python:3.10-16.43 |
Container Release | 16.43 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4891-1
|
Released | Mon Dec 18 16:31:49 2023 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1201384,1218014,CVE-2023-50495 |
Description:
This update for ncurses fixes the following issues:
- CVE-2023-50495: Fixed a segmentation fault via _nc_wrap_entry() (bsc#1218014)
- Modify reset command to avoid altering clocal if the terminal uses a modem (bsc#1201384)
SUSE-CU-2023:4135-1
Container Advisory ID | SUSE-CU-2023:4135-1 |
Container Tags | bci/python:3 , bci/python:3-16.42 , bci/python:3.10 , bci/python:3.10-16.42 |
Container Release | 16.42 |
The following patches have been included in this update:
SUSE-CU-2023:4077-1
Container Advisory ID | SUSE-CU-2023:4077-1 |
Container Tags | bci/python:3 , bci/python:3-16.41 , bci/python:3.10 , bci/python:3.10-16.41 |
Container Release | 16.41 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:4695-1
|
Released | Fri Dec 8 09:01:20 2023 |
Summary | Recommended update for lifecycle-data-sle-module-development-tools |
Type | recommended |
Severity | moderate |
References | 1216578 |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issues:
- Temporary remove go1.19-openssl EOL, will be readded once we ship get go1.21-openssl yet. (bsc#1216578)
- Mark gcc12 EOL date to April 30th of 2024 (6 months after release of
gcc13) (jsc#PED-6584)
Advisory ID | SUSE-RU-2023:4716-1
|
Released | Mon Dec 11 18:38:23 2023 |
Summary | Recommended update for git |
Type | recommended |
Severity | moderate |
References | 1216501 |
Description:
This update for git fixes the following issues:
- Add rule for /etc/gitconfig in gitweb.cgi apparmor profile (bsc#1216501).
- gitweb.cgi AppArmor profile
- make the profile a named profile
- add local/include to make custom additions easier
Advisory ID | SUSE-RU-2023:4723-1
|
Released | Tue Dec 12 09:57:51 2023 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1216862 |
Description:
This update for libtirpc fixes the following issue:
- fix sed parsing in specfile (bsc#1216862)
SUSE-CU-2023:4021-1
Container Advisory ID | SUSE-CU-2023:4021-1 |
Container Tags | bci/python:3 , bci/python:3-16.35 , bci/python:3.10 , bci/python:3.10-16.35 |
Container Release | 16.35 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4659-1
|
Released | Wed Dec 6 13:04:57 2023 |
Summary | Security update for curl |
Type | security |
Severity | moderate |
References | 1217573,1217574,CVE-2023-46218,CVE-2023-46219 |
Description:
This update for curl fixes the following issues:
- CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573).
- CVE-2023-46219: HSTS long file name clears contents (bsc#1217574).
Advisory ID | SUSE-RU-2023:4671-1
|
Released | Wed Dec 6 14:33:41 2023 |
Summary | Recommended update for man |
Type | recommended |
Severity | moderate |
References | |
Description:
This update of man fixes the following problem:
- The 'man' commands is delivered to SUSE Linux Enterprise Micro
to allow browsing man pages.
SUSE-CU-2023:3946-1
Container Advisory ID | SUSE-CU-2023:3946-1 |
Container Tags | bci/python:3 , bci/python:3-16.31 , bci/python:3.10 , bci/python:3.10-16.31 |
Container Release | 16.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4619-1
|
Released | Thu Nov 30 10:13:52 2023 |
Summary | Security update for sqlite3 |
Type | security |
Severity | important |
References | 1210660,CVE-2023-2137 |
Description:
This update for sqlite3 fixes the following issues:
- CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660).
SUSE-CU-2023:3859-1
Container Advisory ID | SUSE-CU-2023:3859-1 |
Container Tags | bci/python:3 , bci/python:3-16.28 , bci/python:3.10 , bci/python:3.10-16.28 |
Container Release | 16.28 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4537-1
|
Released | Thu Nov 23 09:34:08 2023 |
Summary | Security update for libxml2 |
Type | security |
Severity | moderate |
References | 1216129,CVE-2023-45322 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129).
SUSE-CU-2023:3808-1
Container Advisory ID | SUSE-CU-2023:3808-1 |
Container Tags | bci/python:3 , bci/python:3-16.26 , bci/python:3.10 , bci/python:3.10-16.26 |
Container Release | 16.26 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4524-1
|
Released | Tue Nov 21 17:51:28 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1216922,CVE-2023-5678 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-5678: Fixed generating and checking of excessively long X9.42 DH keys that resulted in a possible Denial of Service (bsc#1216922).
SUSE-CU-2023:3727-1
Container Advisory ID | SUSE-CU-2023:3727-1 |
Container Tags | bci/python:3 , bci/python:3-16.23 , bci/python:3.10 , bci/python:3.10-16.23 |
Container Release | 16.23 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:4450-1
|
Released | Wed Nov 15 10:55:20 2023 |
Summary | Recommended update for crypto-policies |
Type | recommended |
Severity | moderate |
References | 1209998 |
Description:
This update for crypto-policies fixes the following issues:
- Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands
(jsc#PED-5041)
- Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby
and add a note for transactional systems
- Ship the man pages for fips-mode-setup and fips-finish-install
- Make the supported versions change in the update-crypto-policies(8) man page persistent
(bsc#1209998)
Advisory ID | SUSE-SU-2023:4458-1
|
Released | Thu Nov 16 14:38:48 2023 |
Summary | Security update for gcc13 |
Type | security |
Severity | important |
References | 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 |
Description:
This update for gcc13 fixes the following issues:
This update ship the GCC 13.2 compiler suite and its base libraries.
The compiler base libraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 12 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available
unsupported via the PackageHub repositories.
To use gcc13 compilers use:
- install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
- override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages.
For a full changelog with all new GCC13 features, check out
https://gcc.gnu.org/gcc-13/changes.html
Detailed changes:
- CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable
length stack allocations. (bsc#1214052)
- Work around third party app crash during C++ standard library initialization. [bsc#1216664]
- Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427)
- Bump included newlib to version 4.3.0.
- Update to GCC trunk head (r13-5254-g05b9868b182bb9)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Turn cross compiler to s390x to a glibc cross. [bsc#1214460]
- Also handle -static-pie in the default-PIE specs
- Fixed missed optimization in Skia resulting in Firefox crashes when
building with LTO. [bsc#1212101]
- Make libstdc++6-devel packages own their directories since they
can be installed standalone. [bsc#1211427]
- Add new x86-related intrinsics (amxcomplexintrin.h).
- RISC-V: Add support for inlining subword atomic operations
- Use --enable-link-serialization rather that --enable-link-mutex,
the benefit of the former one is that the linker jobs are not
holding tokens of the make's jobserver.
- Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd
for the general state of BPF with GCC.
- Add bootstrap conditional to allow --without=bootstrap to be
specified to speed up local builds for testing.
- Bump included newlib to version 4.3.0.
- Also package libhwasan_preinit.o on aarch64.
- Configure external timezone database provided by the timezone
package. Make libstdc++6 recommend timezone to get a fully
working std::chrono. Install timezone when running the testsuite.
- Package libhwasan_preinit.o on x86_64.
- Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
- Enable PRU flavour for gcc13
- update floatn fixinclude pickup to check each header separately (bsc#1206480)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Bump libgo SONAME to libgo22.
- Do not package libhwasan for biarch (32-bit architecture)
as the extension depends on 64-bit pointers.
- Adjust floatn fixincludes guard to work with SLE12 and earlier
SLE15.
- Depend on at least LLVM 13 for GCN cross compiler.
- Update embedded newlib to version 4.2.0
- Allow cross-pru-gcc12-bootstrap for armv7l architecture.
PRU architecture is used for real-time MCUs embedded into TI
armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for
armv7l in order to build both host applications and PRU firmware
during the same build.
SUSE-CU-2023:3639-1
Container Advisory ID | SUSE-CU-2023:3639-1 |
Container Tags | bci/python:3 , bci/python:3-16.18 , bci/python:3.10 , bci/python:3.10-16.18 |
Container Release | 16.18 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:4310-1
|
Released | Tue Oct 31 14:10:47 2023 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1196647 |
Description:
This Update for libtirpc to 1.3.4, fixing the following issues:
Update to 1.3.4 (bsc#1199467)
* binddynport.c honor ip_local_reserved_ports
- replaces: binddynport-honor-ip_local_reserved_ports.patch
* gss-api: expose gss major/minor error in authgss_refresh()
* rpcb_clnt.c: Eliminate double frees in delete_cache()
* rpcb_clnt.c: memory leak in destroy_addr
* portmapper: allow TCP-only portmapper
* getnetconfigent: avoid potential DoS issue by removing unnecessary sleep
* clnt_raw.c: fix a possible null pointer dereference
* bindresvport.c: fix a potential resource leakage
Update to 1.3.3:
- Fix DoS vulnerability in libtirpc
- replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch
- _rpc_dtablesize: use portable system call
- libtirpc: Fix use-after-free accessing the error number
- Fix potential memory leak of parms.r_addr
- replaces 0001-fix-parms.r_addr-memory-leak.patch
- rpcb_clnt.c add mechanism to try v2 protocol first
- preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch
- Eliminate deadlocks in connects with an MT environment
- clnt_dg_freeres() uncleared set active state may deadlock
- thread safe clnt destruction
- SUNRPC: mutexed access blacklist_read state variable
- SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c
Update to 1.3.2:
- Replace the final SunRPC licenses with BSD licenses
- blacklist: Add a few more well known ports
- libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS
Update to 1.3.1:
- Remove AUTH_DES interfaces from auth_des.h
The unsupported AUTH_DES authentication has be
compiled out since commit d918e41d889 (Wed Oct 9 2019)
replaced by API routines that return errors.
- svc_dg: Free xp_netid during destroy
- Fix memory management issues of fd locks
- libtirpc: replace array with list for per-fd locks
- __svc_vc_dodestroy: fix double free of xp_ltaddr.buf
- __rpc_dtbsize: rlim_cur instead of rlim_max
- pkg-config: use the correct replacements for libdir/includedir
SUSE-CU-2023:3588-1
Container Advisory ID | SUSE-CU-2023:3588-1 |
Container Tags | bci/python:3 , bci/python:3-16.16 , bci/python:3.10 , bci/python:3.10-16.16 |
Container Release | 16.16 |
The following patches have been included in this update:
SUSE-CU-2023:3567-1
Container Advisory ID | SUSE-CU-2023:3567-1 |
Container Tags | bci/python:3 , bci/python:3-16.15 , bci/python:3.10 , bci/python:3.10-16.15 |
Container Release | 16.15 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4162-1
|
Released | Mon Oct 23 15:33:03 2023 |
Summary | Security update for gcc13 |
Type | security |
Severity | important |
References | 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039 |
Description:
This update for gcc13 fixes the following issues:
This update ship the GCC 13.2 compiler suite and its base libraries.
The compiler base libraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 12 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module.
The Go, D, Ada and Modula 2 language compiler parts are available
unsupported via the PackageHub repositories.
To use gcc13 compilers use:
- install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages.
- override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages.
For a full changelog with all new GCC13 features, check out
https://gcc.gnu.org/gcc-13/changes.html
Detailed changes:
- CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable
length stack allocations. (bsc#1214052)
- Turn cross compiler to s390x to a glibc cross. [bsc#1214460]
- Also handle -static-pie in the default-PIE specs
- Fixed missed optimization in Skia resulting in Firefox crashes when
building with LTO. [bsc#1212101]
- Make libstdc++6-devel packages own their directories since they
can be installed standalone. [bsc#1211427]
- Add new x86-related intrinsics (amxcomplexintrin.h).
- RISC-V: Add support for inlining subword atomic operations
- Use --enable-link-serialization rather that --enable-link-mutex,
the benefit of the former one is that the linker jobs are not
holding tokens of the make's jobserver.
- Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd
for the general state of BPF with GCC.
- Add bootstrap conditional to allow --without=bootstrap to be
specified to speed up local builds for testing.
- Bump included newlib to version 4.3.0.
- Also package libhwasan_preinit.o on aarch64.
- Configure external timezone database provided by the timezone
package. Make libstdc++6 recommend timezone to get a fully
working std::chrono. Install timezone when running the testsuite.
- Package libhwasan_preinit.o on x86_64.
- Fixed unwinding on aarch64 with pointer signing. [bsc#1206684]
- Enable PRU flavour for gcc13
- update floatn fixinclude pickup to check each header separately (bsc#1206480)
- Redo floatn fixinclude pick-up to simply keep what is there.
- Bump libgo SONAME to libgo22.
- Do not package libhwasan for biarch (32-bit architecture)
as the extension depends on 64-bit pointers.
- Adjust floatn fixincludes guard to work with SLE12 and earlier
SLE15.
- Depend on at least LLVM 13 for GCN cross compiler.
- Update embedded newlib to version 4.2.0
- Allow cross-pru-gcc12-bootstrap for armv7l architecture.
PRU architecture is used for real-time MCUs embedded into TI
armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for
armv7l in order to build both host applications and PRU firmware
during the same build.
Advisory ID | SUSE-RU-2023:4193-1
|
Released | Wed Oct 25 10:36:43 2023 |
Summary | Recommended update for lifecycle-data-sle-module-development-tools |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issues:
- added EOL dates for previous go1.xx compiler packages (go1.15 to go1.19)
- added EOL dates for previous rust compiler versions (1.43 up to 1.70)
Advisory ID | SUSE-SU-2023:4200-1
|
Released | Wed Oct 25 12:04:29 2023 |
Summary | Security update for nghttp2 |
Type | security |
Severity | important |
References | 1216123,1216174,CVE-2023-44487 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2023-44487: Fixed HTTP/2 Rapid Reset attack. (bsc#1216174)
Advisory ID | SUSE-SU-2023:4217-1
|
Released | Thu Oct 26 12:20:27 2023 |
Summary | Security update for zlib |
Type | security |
Severity | moderate |
References | 1216378,CVE-2023-45853 |
Description:
This update for zlib fixes the following issues:
- CVE-2023-45853: Fixed an integer overflow that would lead to a
buffer overflow in the minizip subcomponent (bsc#1216378).
SUSE-CU-2023:3503-1
Container Advisory ID | SUSE-CU-2023:3503-1 |
Container Tags | bci/python:3 , bci/python:3-16.9 , bci/python:3.10 , bci/python:3.10-16.9 |
Container Release | 16.9 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:4110-1
|
Released | Wed Oct 18 12:35:26 2023 |
Summary | Security update for glibc |
Type | security |
Severity | important |
References | 1215286,1215891,CVE-2023-4813 |
Description:
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-4813: Fixed a potential use-after-free in gaih_inet() (bsc#1215286, BZ #28931)
Also a regression from a previous update was fixed:
- elf: Align argument of __munmap to page size (bsc#1215891, BZ #28676)
Advisory ID | SUSE-RU-2023:4122-1
|
Released | Thu Oct 19 08:24:34 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1215215 |
Description:
This update for openssl-1_1 fixes the following issues:
- Displays 'fips' in the version string (bsc#1215215)
Advisory ID | SUSE-RU-2023:4153-1
|
Released | Fri Oct 20 19:27:58 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | 1215313 |
Description:
This update for systemd fixes the following issues:
- Fix mismatch of nss-resolve version in Package Hub (no source code changes)
Advisory ID | SUSE-RU-2023:4154-1
|
Released | Fri Oct 20 19:33:25 2023 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1107342,1215434 |
Description:
This update for aaa_base fixes the following issues:
- Respect /etc/update-alternatives/java when setting JAVA_HOME (bsc#1215434,bsc#1107342)
SUSE-CU-2023:3434-1
Container Advisory ID | SUSE-CU-2023:3434-1 |
Container Tags | bci/python:3 , bci/python:3-16.4 , bci/python:3.10 , bci/python:3.10-16.4 |
Container Release | 16.4 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2020:1906-1
|
Released | Tue Jul 14 15:58:16 2020 |
Summary | Recommended update for lifecycle-data-sle-module-development-tools |
Type | recommended |
Severity | moderate |
References | 1173407 |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issue:
- Ensure package is installed with its corresponding module when lifecycle package is installed. (bsc#1173407)
Advisory ID | SUSE-RU-2020:3603-1
|
Released | Wed Dec 2 15:11:46 2020 |
Summary | Recommended update for lifecycle-data-sle-module-development-tools |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issues:
- Added expiration data for the GCC 9 yearly update for the Toolchain/Development modules.
(jsc#ECO-2373, jsc#SLE-10950, jsc#SLE-10951)
Advisory ID | SUSE-RU-2021:2245-1
|
Released | Mon Jul 5 12:14:52 2021 |
Summary | Recommended update for lifecycle-data-sle-module-development-tools |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issues:
- mark go1.14 as 'end of life' as go1.16 was released and we only support 2 go versions parallel (jsc#ECO-1484)
Advisory ID | SUSE-feature-2022:950-1
|
Released | Fri Mar 25 12:47:04 2022 |
Summary | Feature update for lifecycle-data-sle-module-development-tools |
Type | feature |
Severity | moderate |
References | |
Description:
This feature update for lifecycle-data-sle-module-development-tools fixes the following issues:
- Added expiration data for GCC 10 yearly update for the Toolchain/Development modules
(jsc#ECO-2373, jsc#SLE-16821, jsc#SLE-16822)
Advisory ID | SUSE-feature-2023:2523-1
|
Released | Fri Jun 16 11:15:25 2023 |
Summary | Feature update for lifecycle-data-sle-module-development-tools |
Type | feature |
Severity | moderate |
References | |
Description:
This update for lifecycle-data-sle-module-development-tools fixes the following issues:
- Added expiration data for GCC 11 yearly update for the Toolchain/Development modules
(jsc#SLE-25046, jsc#SLE-25045, jsc#SLE-25044, jsc#PED-2030, jsc#PED-2033, jsc#PED-2035)
Advisory ID | SUSE-SU-2023:4024-1
|
Released | Tue Oct 10 13:24:40 2023 |
Summary | Security update for shadow |
Type | security |
Severity | low |
References | 1214806,CVE-2023-4641 |
Description:
This update for shadow fixes the following issues:
- CVE-2023-4641: Fixed potential password leak (bsc#1214806).
Advisory ID | SUSE-SU-2023:4044-1
|
Released | Wed Oct 11 09:01:14 2023 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1215888,1215889,CVE-2023-38545,CVE-2023-38546 |
Description:
This update for curl fixes the following issues:
- CVE-2023-38545: Fixed a heap buffer overflow in SOCKS5. (bsc#1215888)
- CVE-2023-38546: Fixed a cookie injection with none file. (bsc#1215889)
Advisory ID | SUSE-RU-2023:4073-1
|
Released | Fri Oct 13 11:40:26 2023 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | low |
References | |
Description:
This update for rpm fixes the following issue:
- Enables build for all python modules (jsc#PED-68, jsc#PED-1988)
Advisory ID | SUSE-RU-2023:4086-1
|
Released | Mon Oct 16 12:48:13 2023 |
Summary | Recommended update for python310 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for python310 fixes the following issues:
- Python documentation uses deprecated Sphinx index entries
(https://github.com/python/cpython/issues/97950)
SUSE-CU-2023:3360-1
Container Advisory ID | SUSE-CU-2023:3360-1 |
Container Tags | bci/python:3 , bci/python:3-15.62 , bci/python:3.10 , bci/python:3.10-15.62 |
Container Release | 15.62 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3994-1
|
Released | Fri Oct 6 13:44:15 2023 |
Summary | Recommended update for git |
Type | recommended |
Severity | moderate |
References | 1215533 |
Description:
This update for git fixes the following issues:
- Downgrade openssh dependency to recommends (bsc#1215533)
Advisory ID | SUSE-SU-2023:3997-1
|
Released | Fri Oct 6 14:13:56 2023 |
Summary | Security update for nghttp2 |
Type | security |
Severity | important |
References | 1215713,CVE-2023-35945 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2023-35945: Fixed memory leak when PUSH_PROMISE or HEADERS frame cannot be sent (bsc#1215713).
SUSE-CU-2023:3278-1
Container Advisory ID | SUSE-CU-2023:3278-1 |
Container Tags | bci/python:3 , bci/python:3-15.61 , bci/python:3.10 , bci/python:3.10-15.61 |
Container Release | 15.61 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:3954-1
|
Released | Tue Oct 3 20:09:47 2023 |
Summary | Security update for libeconf |
Type | security |
Severity | important |
References | 1211078,CVE-2023-22652,CVE-2023-30078,CVE-2023-30079,CVE-2023-32181 |
Description:
This update for libeconf fixes the following issues:
Update to version 0.5.2.
- CVE-2023-30078, CVE-2023-32181: Fixed a stack-buffer-overflow vulnerability in 'econf_writeFile' function (bsc#1211078).
- CVE-2023-30079, CVE-2023-22652: Fixed a stack-buffer-overflow vulnerability in 'read_file' function. (bsc#1211078)
SUSE-CU-2023:3215-1
Container Advisory ID | SUSE-CU-2023:3215-1 |
Container Tags | bci/python:3 , bci/python:3-15.58 , bci/python:3.10 , bci/python:3.10-15.58 |
Container Release | 15.58 |
The following patches have been included in this update:
SUSE-CU-2023:3203-1
Container Advisory ID | SUSE-CU-2023:3203-1 |
Container Tags | bci/python:3 , bci/python:3-15.57 , bci/python:3.10 , bci/python:3.10-15.57 |
Container Release | 15.57 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3814-1
|
Released | Wed Sep 27 18:08:17 2023 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1211829,1212819,1212910 |
Description:
This update for glibc fixes the following issues:
- nscd: Fix netlink cache invalidation if epoll is used (bsc#1212910, BZ #29415)
- Restore lookup of IPv4 mapped addresses in files database (bsc#1212819, BZ #25457)
- elf: Remove excessive p_align check on PT_LOAD segments (bsc#1211829, BZ #28688)
- elf: Properly align PT_LOAD segments (bsc#1211829, BZ #28676)
- ld.so: Always use MAP_COPY to map the first segment (BZ #30452)
- add GB18030-2022 charmap (jsc#PED-4908, BZ #30243)
Advisory ID | SUSE-SU-2023:3823-1
|
Released | Wed Sep 27 18:42:38 2023 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1215026,CVE-2023-38039 |
Description:
This update for curl fixes the following issues:
- CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026)
Advisory ID | SUSE-SU-2023:3824-1
|
Released | Wed Sep 27 18:43:51 2023 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1213463,1214692,CVE-2023-40217 |
Description:
This update for python310 fixes the following issues:
- CVE-2023-40217: Fixed TLS handshake bypass on closed sockets (bsc#1214692)
The following non-security bug was fixed:
- stabilizing FLAG_REF usage (required for reproduceability (bsc#1213463).
SUSE-CU-2023:3138-1
Container Advisory ID | SUSE-CU-2023:3138-1 |
Container Tags | bci/python:3 , bci/python:3-15.56 , bci/python:3.10 , bci/python:3.10-15.56 |
Container Release | 15.56 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3780-1
|
Released | Tue Sep 26 10:58:21 2023 |
Summary | Recommended update hidapi |
Type | recommended |
Severity | moderate |
References | 1214535 |
Description:
This update for hidapi ships the missing libhidapi-raw0 library to SLE and Leap Micro 5.3 and 5.4.
SUSE-CU-2023:3103-1
Container Advisory ID | SUSE-CU-2023:3103-1 |
Container Tags | bci/python:3 , bci/python:3-15.54 , bci/python:3.10 , bci/python:3.10-15.54 |
Container Release | 15.54 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:3661-1
|
Released | Mon Sep 18 21:44:09 2023 |
Summary | Security update for gcc12 |
Type | security |
Severity | important |
References | 1214052,CVE-2023-4039 |
Description:
This update for gcc12 fixes the following issues:
- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).
Advisory ID | SUSE-SU-2023:3699-1
|
Released | Wed Sep 20 11:02:50 2023 |
Summary | Security update for libxml2 |
Type | security |
Severity | important |
References | 1214768,CVE-2023-39615 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2023-39615: Fixed crafted xml can cause global buffer overflow (bsc#1214768).
SUSE-CU-2023:3013-1
Container Advisory ID | SUSE-CU-2023:3013-1 |
Container Tags | bci/python:3 , bci/python:3-15.49 , bci/python:3.10 , bci/python:3.10-15.49 |
Container Release | 15.49 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3611-1
|
Released | Fri Sep 15 09:28:36 2023 |
Summary | Recommended update for sysuser-tools |
Type | recommended |
Severity | moderate |
References | 1195391,1205161,1207778,1213240,1214140 |
Description:
This update for sysuser-tools fixes the following issues:
- Update to version 3.2
- Always create a system group of the same name as the system user (bsc#1205161, bsc#1207778, bsc#1213240)
- Add 'quilt setup' friendly hint to %sysusers_requires usage
- Use append so if a pre file already exists it isn't overridden
- Invoke bash for bash scripts (bsc#1195391)
- Remove all systemd requires not supported on SLE15 (bsc#1214140)
SUSE-CU-2023:2943-1
Container Advisory ID | SUSE-CU-2023:2943-1 |
Container Tags | bci/python:3 , bci/python:3-15.47 , bci/python:3.10 , bci/python:3.10-15.47 |
Container Release | 15.47 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3577-1
|
Released | Mon Sep 11 15:04:01 2023 |
Summary | Recommended update for crypto-policies |
Type | recommended |
Severity | low |
References | 1209998 |
Description:
This update for crypto-policies fixes the following issues:
- Update update-crypto-policies(8) man pages and README.SUSE to mention the supported back-end policies. (bsc#1209998)
SUSE-CU-2023:2875-1
Container Advisory ID | SUSE-CU-2023:2875-1 |
Container Tags | bci/python:3 , bci/python:3-15.45 , bci/python:3.10 , bci/python:3.10-15.45 |
Container Release | 15.45 |
The following patches have been included in this update:
SUSE-CU-2023:2826-1
Container Advisory ID | SUSE-CU-2023:2826-1 |
Container Tags | bci/python:3 , bci/python:3-15.43 , bci/python:3.10 , bci/python:3.10-15.43 |
Container Release | 15.43 |
The following patches have been included in this update:
SUSE-CU-2023:2804-1
Container Advisory ID | SUSE-CU-2023:2804-1 |
Container Tags | bci/python:3 , bci/python:3-15.42 , bci/python:3.10 , bci/python:3.10-15.42 |
Container Release | 15.42 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:3397-1
|
Released | Wed Aug 23 18:35:56 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | moderate |
References | 1213517,1213853,CVE-2023-3817 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853)
- Don't pass zero length input to EVP_Cipher because s390x assembler optimized AES cannot handle zero size. (bsc#1213517)
Advisory ID | SUSE-RU-2023:3410-1
|
Released | Thu Aug 24 06:56:32 2023 |
Summary | Recommended update for audit |
Type | recommended |
Severity | moderate |
References | 1201519,1204844 |
Description:
This update for audit fixes the following issues:
- Create symbolic link from /sbin/audisp-syslog to /usr/sbin/audisp-syslog (bsc#1201519)
- Fix rules not loaded when restarting auditd.service (bsc#1204844)
Advisory ID | SUSE-RU-2023:3451-1
|
Released | Mon Aug 28 12:15:22 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | 1186606,1194609,1208194,1209741,1210702,1211576,1212434,1213185,1213575,1213873 |
Description:
This update for systemd fixes the following issues:
- Fix reboot and shutdown issues by getting only active MD arrays (bsc#1211576, bsc#1212434, bsc#1213575)
- Decrease devlink priority for iso disks (bsc#1213185)
- Do not ignore mount point paths longer than 255 characters (bsc#1208194)
- Refuse hibernation if there's no possible way to resume (bsc#1186606)
- Update 'korean' and 'arabic' keyboard layouts (bsc#1210702)
- Drop some entries no longer needed by YaST (bsc#1194609)
- The 'systemd --user' instances get their own session keyring instead of the user default one (bsc#1209741)
- Dynamically allocate receive buffer to handle large amount of mounts (bsc#1213873)
SUSE-CU-2023:2736-1
Container Advisory ID | SUSE-CU-2023:2736-1 |
Container Tags | bci/python:3 , bci/python:3-15.34 , bci/python:3.10 , bci/python:3.10-15.34 |
Container Release | 15.34 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:3363-1
|
Released | Fri Aug 18 14:54:16 2023 |
Summary | Security update for krb5 |
Type | security |
Severity | important |
References | 1214054,CVE-2023-36054 |
Description:
This update for krb5 fixes the following issues:
- CVE-2023-36054: Fixed a DoS that could be triggered by an authenticated remote user. (bsc#1214054)
SUSE-CU-2023:2684-1
Container Advisory ID | SUSE-CU-2023:2684-1 |
Container Tags | bci/python:3 , bci/python:3-15.32 , bci/python:3.10 , bci/python:3.10-15.32 |
Container Release | 15.32 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:3327-1
|
Released | Wed Aug 16 08:45:25 2023 |
Summary | Security update for pcre2 |
Type | security |
Severity | moderate |
References | 1213514,CVE-2022-41409 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-41409: Fixed integer overflow vulnerability in pcre2test that allows attackers to cause a denial of service via negative input (bsc#1213514).
SUSE-CU-2023:2632-1
Container Advisory ID | SUSE-CU-2023:2632-1 |
Container Tags | bci/python:3 , bci/python:3-15.30 , bci/python:3.10 , bci/python:3.10-15.30 |
Container Release | 15.30 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:3285-1
|
Released | Fri Aug 11 10:30:38 2023 |
Summary | Recommended update for shadow |
Type | recommended |
Severity | moderate |
References | 1206627,1213189 |
Description:
This update for shadow fixes the following issues:
- Prevent lock files from remaining after power interruptions (bsc#1213189)
- Add --prefix support to passwd, chpasswd and chage (bsc#1206627)
Advisory ID | SUSE-RU-2023:3286-1
|
Released | Fri Aug 11 10:32:03 2023 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1194038,1194900 |
Description:
This update for util-linux fixes the following issues:
- Fix blkid for floppy drives (bsc#1194900)
- Fix rpmbuild %checks fail when @ in the directory path (bsc#1194038)
SUSE-CU-2023:2586-1
Container Advisory ID | SUSE-CU-2023:2586-1 |
Container Tags | bci/python:3 , bci/python:3-15.29 , bci/python:3.10 , bci/python:3.10-15.29 |
Container Release | 15.29 |
The following patches have been included in this update:
SUSE-CU-2023:2466-1
Container Advisory ID | SUSE-CU-2023:2466-1 |
Container Tags | bci/python:3 , bci/python:3-15.26 , bci/python:3.10 , bci/python:3.10-15.26 |
Container Release | 15.26 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:2625-1
|
Released | Fri Jun 23 17:16:11 2023 |
Summary | Recommended update for gcc12 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for gcc12 fixes the following issues:
- Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204
* includes regression and other bug fixes
- Speed up builds with --enable-link-serialization.
- Update embedded newlib to version 4.2.0
Advisory ID | SUSE-SU-2023:2648-1
|
Released | Tue Jun 27 09:52:35 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | moderate |
References | 1201627,1207534,CVE-2022-4304 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption.
The previous fix for this timing side channel turned out to cause a
severe 2-3x performance regression in the typical use case (bsc#1207534).
- Update further expiring certificates that affect the testsuite (bsc#1201627).
Advisory ID | SUSE-SU-2023:2765-1
|
Released | Mon Jul 3 20:28:14 2023 |
Summary | Security update for libcap |
Type | security |
Severity | moderate |
References | 1211418,1211419,CVE-2023-2602,CVE-2023-2603 |
Description:
This update for libcap fixes the following issues:
- CVE-2023-2602: Fixed improper memory release in libcap/psx/psx.c:__wrap_pthread_create() (bsc#1211418).
- CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419).
Advisory ID | SUSE-RU-2023:2800-1
|
Released | Mon Jul 10 07:35:22 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1212623 |
Description:
This update for openssl-1_1 fixes the following issues:
- Check the OCSP RESPONSE in openssl s_client command and terminate
connection if a revoked certificate is found. [bsc#1212623]
Advisory ID | SUSE-RU-2023:2811-1
|
Released | Wed Jul 12 11:56:18 2023 |
Summary | Recommended update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for libfido2, python-fido2, yubikey-manager, yubikey-manager-qt fixes the following issues:
This update provides a feature update to the FIDO2 stack.
Changes in libfido2:
- Version 1.13.0 (2023-02-20)
* New API calls:
+ fido_assert_empty_allow_list;
+ fido_cred_empty_exclude_list.
* fido2-token: fix issue when listing large blobs.
- Version 1.12.0 (2022-09-22)
* Support for COSE_ES384.
* Improved support for FIDO 2.1 authenticators.
* New API calls:
+ es384_pk_free;
+ es384_pk_from_EC_KEY;
+ es384_pk_from_EVP_PKEY;
+ es384_pk_from_ptr;
+ es384_pk_new;
+ es384_pk_to_EVP_PKEY;
+ fido_cbor_info_certs_len;
+ fido_cbor_info_certs_name_ptr;
+ fido_cbor_info_certs_value_ptr;
+ fido_cbor_info_maxrpid_minpinlen;
+ fido_cbor_info_minpinlen;
+ fido_cbor_info_new_pin_required;
+ fido_cbor_info_rk_remaining;
+ fido_cbor_info_uv_attempts;
+ fido_cbor_info_uv_modality.
* Documentation and reliability fixes.
- Version 1.11.0 (2022-05-03)
* Experimental PCSC support; enable with -DUSE_PCSC.
* Improved OpenSSL 3.0 compatibility.
* Use RFC1951 raw deflate to compress CTAP 2.1 largeBlobs.
* winhello: advertise 'uv' instead of 'clientPin'.
* winhello: support hmac-secret in fido_dev_get_assert().
* New API calls:
+ fido_cbor_info_maxlargeblob.
* Documentation and reliability fixes.
* Separate build and regress targets.
- Version 1.10.0 (2022-01-17)
* bio: fix CTAP2 canonical CBOR encoding in fido_bio_dev_enroll_*(); gh#480.
* New API calls:
- fido_dev_info_set;
- fido_dev_io_handle;
- fido_dev_new_with_info;
- fido_dev_open_with_info.
* Cygwin and NetBSD build fixes.
* Documentation and reliability fixes.
* Support for TPM 2.0 attestation of COSE_ES256 credentials.
- Version 1.9.0 (2021-10-27)
* Enabled NFC support on Linux.
* Support for FIDO 2.1 'minPinLength' extension.
* Support for COSE_EDDSA, COSE_ES256, and COSE_RS1 attestation.
* Support for TPM 2.0 attestation.
* Support for device timeouts; see fido_dev_set_timeout().
* New API calls:
- es256_pk_from_EVP_PKEY;
- fido_cred_attstmt_len;
- fido_cred_attstmt_ptr;
- fido_cred_pin_minlen;
- fido_cred_set_attstmt;
- fido_cred_set_pin_minlen;
- fido_dev_set_pin_minlen_rpid;
- fido_dev_set_timeout;
- rs256_pk_from_EVP_PKEY.
* Reliability and portability fixes.
* Better handling of HID devices without identification strings; gh#381.
* Better support for FIDO 2.1 authenticators.
* Support for attestation format 'none'.
* New API calls:
- fido_assert_set_clientdata;
- fido_cbor_info_algorithm_cose;
- fido_cbor_info_algorithm_count;
- fido_cbor_info_algorithm_type;
- fido_cbor_info_transports_len;
- fido_cbor_info_transports_ptr;
- fido_cred_set_clientdata;
- fido_cred_set_id;
- fido_credman_set_dev_rk;
- fido_dev_is_winhello.
* fido2-token: new -Sc option to update a resident credential.
* Documentation and reliability fixes.
* HID access serialisation on Linux.
* hid_win: detect devices with vendor or product IDs > 0x7fff
* Support for FIDO 2.1 authenticator configuration.
* Support for FIDO 2.1 UV token permissions.
* Support for FIDO 2.1 'credBlobs' and 'largeBlobs' extensions.
* New API calls
* New fido_init flag to disable fido_dev_open’s U2F fallback
* Experimental NFC support on Linux.
- Enabled hidapi again, issues related to hidapi are fixed upstream
* Documentation and reliability fixes.
* New API calls:
+ fido_cred_authdata_raw_len;
+ fido_cred_authdata_raw_ptr;
+ fido_cred_sigcount;
+ fido_dev_get_uv_retry_count;
+ fido_dev_supports_credman.
* Hardened Windows build.
* Native FreeBSD and NetBSD support.
* Use CTAP2 canonical CBOR when combining hmac-secret and credProtect.
- Create a udev subpackage and ship the udev rule.
Changes in python-fido2:
* Don't fail device discovery when hidraw doesn't support HIDIOCGRAWUNIQ
* Support the latest Windows webauthn.h API (included in Windows 11).
* Add product name and serial number to HidDescriptors.
* Remove the need for the uhid-freebsd dependency on FreeBSD.
* Add new CTAP error codes and improve handling of unknown codes.
* Client: API changes to better support extensions.
* Client.make_credential now returns a AuthenticatorAttestationResponse,
which holds the AttestationObject and ClientData, as well as any
client extension results for the credential.
* Client.get_assertion now returns an AssertionSelection object,
which is used to select between multiple assertions
* Renames: The CTAP1 and CTAP2 classes have been renamed to
Ctap1 and Ctap2, respectively.
* ClientPin: The ClientPin API has been restructured to support
multiple PIN protocols, UV tokens, and token permissions.
* CTAP 2.1 PRE: Several new features have been added for CTAP 2.1
* HID: The platform specific HID code has been revamped
- Version 0.8.1 (released 2019-11-25)
* Bugfix: WindowsClient.make_credential error when resident key requirement is unspecified.
- Version 0.8.0 (released 2019-11-25)
* New fido2.webauthn classes modeled after the W3C WebAuthn spec introduced.
* CTAP2 send_cbor/make_credential/get_assertion and U2fClient request/authenticate timeout arguments replaced with event used to cancel a request.
* Fido2Client:
- make_credential/get_assertion now take WebAuthn options objects.
- timeout is now provided in ms in WebAuthn options objects. Event based cancelation also available by passing an Event.
* Fido2Server:
- ATTESTATION, USER_VERIFICATION, and AUTHENTICATOR_ATTACHMENT enums have been replaced with fido2.webauthn classes.
- RelyingParty has been replaced with PublicKeyCredentialRpEntity, and name is no longer optional.
- Options returned by register_begin/authenticate_begin now omit unspecified values if they are optional, instead of filling in default values.
- Fido2Server.allowed_algorithms now contains a list of PublicKeyCredentialParameters instead of algorithm identifiers.
- Fido2Server.timeout is now in ms and of type int.
* Support native WebAuthn API on Windows through WindowsClient.
- Version 0.7.2 (released 2019-10-24)
* Support for the TPM attestation format.
* Allow passing custom challenges to register/authenticate in Fido2Server.
* Bugfix: CTAP2 CANCEL command response handling fixed.
* Bugfix: Fido2Client fix handling of empty allow_list.
* Bugfix: Fix typo in CTAP2.get_assertions() causing it to fail.
- Version 0.7.1 (released 2019-09-20)
* Enforce canonical CBOR on Authenticator responses by default.
* PCSC: Support extended APDUs.
* Server: Verify that UP flag is set.
* U2FFido2Server: Implement AppID exclusion extension.
* U2FFido2Server: Allow custom U2F facet verification.
* Bugfix: U2FFido2Server.authenticate_complete now returns the result.
- Version 0.7.0 (released 2019-06-17)
* Add support for NFC devices using PCSC.
* Add support for the hmac-secret Authenticator extension.
* Honor max credential ID length and number of credentials to Authenticator.
* Add close() method to CTAP devices to explicitly release their resources.
- Version 0.6.0 (released 2019-05-10)
* Don't fail if CTAP2 Info contains unknown fields.
* Replace cbor loads/dumps functions with encode/decode/decode_from.
* Server: Add support for AuthenticatorAttachment.
* Server: Add support for more key algorithms.
* Client: Expose CTAP2 Info object as Fido2Client.info.
Changes in yubikey-manager:
- Update to version 4.0.9 (released 2022-06-17)
* Dependency: Add support for python-fido2 1.x
* Fix: Drop stated support for Click 6 as features from 7 are being used.
- Update to version 4.0.8 (released 2022-01-31)
* Bugfix: Fix error message for invalid modhex when programing a YubiOTP credential.
* Bugfix: Fix issue with displaying a Steam credential when it is the only account.
* Bugfix: Prevent installation of files in site-packages root.
* Bugfix: Fix cleanup logic in PIV for protected management key.
* Add support for token identifier when programming slot-based HOTP.
* Add support for programming NDEF in text mode.
* Dependency: Add support for Cryptography ⇠38.
** Bugfix release: Fix broken naming for 'YubiKey 4', and a small OATH issue with
touch Steam credentials.
- version 4.0.6 (released 2021-09-08)
** Improve handling of YubiKey device reboots.
** More consistently mask PIN/password input in prompts.
** Support switching mode over CCID for YubiKey Edge.
** Run pkill from PATH instead of fixed location.
- version 4.0.5 (released 2021-07-16)
** Bugfix: Fix PIV feature detection for some YubiKey NEO versions.
** Bugfix: Fix argument short form for --period when adding TOTP credentials.
** Bugfix: More strict validation for some arguments, resulting in better error messages.
** Bugfix: Correctly handle TOTP credentials using period != 30 AND touch_required.
** Bugfix: Fix prompting for access code in the otp settings command (now uses '-A -').
* Add support for fido reset over NFC.
* Bugfix: The --touch argument to piv change-management-key was
ignored.
* Bugfix: Don’t prompt for password when importing PIV key/cert
if file is invalid.
* Bugfix: Fix setting touch-eject/auto-eject for YubiKey 4 and NEO.
* Bugfix: Detect PKCS#12 format when outer sequence uses
indefinite length.
* Dependency: Add support for Click 8.
* Update device names
* Add read_info output to the --diagnose command, and show
exception types.
* Bugfix: Fix read_info for YubiKey Plus.
* Add support for YK5-based FIPS YubiKeys.
* Bugfix: Fix OTP device enumeration on Win32.
* Drop reliance on libusb and libykpersonalize.
* Support the 'fido' and 'otp' subcommands over NFC
* New 'ykman --diagnose' command to aid in troubleshooting.
* New 'ykman apdu' command for sending raw APDUs over the smart
card interface.
* New 'yubikit' package added for custom development and advanced
scripting.
* OpenPGP: Add support for KDF enabled YubiKeys.
* Static password: Add support for FR, IT, UK and BEPO keyboard
layouts.
* Add support for YubiKey 5C NFC
* OpenPGP: set-touch now performs compatibility checks before prompting for PIN
* OpenPGP: Improve error messages and documentation for set-touch
* PIV: read-object command no longer adds a trailing newline
* CLI: Hint at missing permissions when opening a device fails
* Linux: Improve error handling when pcscd is not running
* Windows: Improve how .DLL files are loaded, thanks to Marius Gabriel Mihai for reporting this!
* Bugfix: set-touch now accepts the cached-fixed option
* Bugfix: Fix crash in OtpController.prepare_upload_key() error parsing
* Bugfix: Fix crash in piv info command when a certificate slot contains an invalid certificate
* Library: PivController.read_certificate(slot) now wraps certificate parsing exceptions in new exception type InvalidCertificate
* Library: PivController.list_certificates() now returns None for slots containing invalid certificate, instead of raising an exception
- Version 3.1.0 (released 2019-08-20)
* Add support for YubiKey 5Ci
* OpenPGP: the info command now prints OpenPGP specification version as well
* OpenPGP: Update support for attestation to match OpenPGP v3.4
* PIV: Use UTC time for self-signed certificates
* OTP: Static password now supports the Norman keyboard layout
- Version 3.0.0 (released 2019-06-24)
* Add support for new YubiKey Preview and lightning form factor
* FIDO: Support for credential management
* OpenPGP: Support for OpenPGP attestation, cardholder certificates and
cached touch policies
* OTP: Add flag for using numeric keypad when sending digits
- Version 2.1.1 (released 2019-05-28)
* OTP: Add initial support for uploading Yubico OTP credentials to YubiCloud
* Don’t automatically select the U2F applet on YubiKey NEO, it might be
blocked by the OS
* ChalResp: Always pad challenge correctly
* Bugfix: Don’t crash with older versions of cryptography
* Bugfix: Password was always prompted in OATH command, even if sent as
argument
Changes in yubikey-manager-qt:
* Compatibility update for ykman 5.0.1.
* Update to Python 3.11.
* Update product images.
- Update to version 1.2.4 (released 2021-10-26)
* Update device names and images.
* PIV: Fix import of certificate.
* Improved error handling when using Security Key Series devices.
* PIV: Fix generation of certificate in slot 9c.
* Fix detection of YubiKey Plus
* Compatibility update for yubikey-manager 4.0
* Bugfix: Device caching with multiple devices
* Drop dependencies on libusb and libykpers.
* Add additional product names and images
* Add support for YubiKey 5C NFC
* OTP: Add option to upload YubiOTP credential to YubiCloud
* Linux: Show hint about pcscd service if opening device fails
* Bugfix: Signal handling now compatible with Python 3.8
- Version 1.1.3 (released 2019-08-20)
* Add suppport for YubiKey 5Ci
* PIV: Use UTC time for self-signed certificates
- Version 1.1.2 (released 2019-06-24)
* Add support for new YubiKey Preview
* PIV: The popup for the management key now have a 'Use default' option
* Windows: Fix issue with importing PIV certificates
* Bugfix: generate static password now works correctly
Advisory ID | SUSE-RU-2023:2827-1
|
Released | Fri Jul 14 11:27:47 2023 |
Summary | Recommended update for libxml2 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for libxml2 fixes the following issues:
- Build also for modern python version (jsc#PED-68)
Advisory ID | SUSE-RU-2023:2847-1
|
Released | Mon Jul 17 08:40:42 2023 |
Summary | Recommended update for audit |
Type | recommended |
Severity | moderate |
References | 1210004 |
Description:
This update for audit fixes the following issues:
- Check for AF_UNIX unnamed sockets (bsc#1210004)
- Enable livepatching on main library on x86_64
Advisory ID | SUSE-RU-2023:2855-1
|
Released | Mon Jul 17 16:35:21 2023 |
Summary | Recommended update for openldap2 |
Type | recommended |
Severity | moderate |
References | 1212260 |
Description:
This update for openldap2 fixes the following issues:
- libldap2 crashes on ldap_sasl_bind_s (bsc#1212260)
Advisory ID | SUSE-SU-2023:2882-1
|
Released | Wed Jul 19 11:49:39 2023 |
Summary | Security update for perl |
Type | security |
Severity | important |
References | 1210999,CVE-2023-31484 |
Description:
This update for perl fixes the following issues:
- CVE-2023-31484: Enable TLS cert verification in CPAN (bsc#1210999).
Advisory ID | SUSE-SU-2023:2884-1
|
Released | Wed Jul 19 16:55:25 2023 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1203750,1208471,1211765,CVE-2007-4559,CVE-2023-24329 |
Description:
This update for python310 fixes the following issues:
- Make marshalling of `set` and `frozenset` deterministic (bsc#1211765)
python310 was updated to 3.10.12:
- urllib.parse.urlsplit() now strips leading C0
control and space characters following the specification for
URLs defined by WHATWG in response to CVE-2023-24329
(bsc#1208471).
- Fixed a security in flaw in uu.decode() that could
allow for directory traversal based on the input if no
out_file was specified.
- Do not expose the local on-disk
location in directory indexes produced by
http.client.SimpleHTTPRequestHandler.
- trace.__main__ now uses io.open_code() for files
to be executed instead of raw open().
- CVE-2007-4559: The extraction methods in tarfile, and
shutil.unpack_archive(), have a new filter argument that
allows limiting tar features than may be surprising or
dangerous, such as creating files outside the destination
directory. See Extraction filters for details (fixing
bsc#1203750).
Advisory ID | SUSE-RU-2023:2885-1
|
Released | Wed Jul 19 16:58:43 2023 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1208721,1209229,1211828 |
Description:
This update for glibc fixes the following issues:
- getlogin_r: fix missing fallback if loginuid is unset (bsc#1209229, BZ #30235)
- Exclude static archives from preparation for live patching (bsc#1208721)
- resolv_conf: release lock on allocation failure (bsc#1211828, BZ #30527)
Advisory ID | SUSE-SU-2023:2891-1
|
Released | Wed Jul 19 21:14:33 2023 |
Summary | Security update for curl |
Type | security |
Severity | moderate |
References | 1213237,CVE-2023-32001 |
Description:
This update for curl fixes the following issues:
- CVE-2023-32001: Fixed TOCTOU race condition (bsc#1213237).
Advisory ID | SUSE-RU-2023:2922-1
|
Released | Thu Jul 20 18:34:03 2023 |
Summary | Recommended update for libfido2 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for libfido2 fixes the following issues:
- Use openssl 1.1 still on SUSE Linux Enterprise 15 to avoid pulling unneeded
openssl-3 dependency. (jsc#PED-4521)
Advisory ID | SUSE-SU-2023:2945-1
|
Released | Mon Jul 24 09:37:30 2023 |
Summary | Security update for openssh |
Type | security |
Severity | important |
References | 1186673,1209536,1213004,1213008,1213504,CVE-2023-38408 |
Description:
This update for openssh fixes the following issues:
- CVE-2023-38408: Fixed a condition where specific libaries loaded via
ssh-agent(1)'s PKCS#11 support could be abused to achieve remote code
execution via a forwarded agent socket if those libraries were present on the
victim's system and if the agent was forwarded to an attacker-controlled
system. [bsc#1213504, CVE-2023-38408]
- Close the right filedescriptor and also close fdh in read_hmac to avoid file
descriptor leaks. [bsc#1209536]
- Attempts to mitigate instances of secrets lingering in memory after a session
exits. [bsc#1186673, bsc#1213004, bsc#1213008]
Advisory ID | SUSE-SU-2023:2962-1
|
Released | Tue Jul 25 09:34:53 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | moderate |
References | 1213487,CVE-2023-3446 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487).
SUSE-CU-2023:2060-1
Container Advisory ID | SUSE-CU-2023:2060-1 |
Container Tags | bci/python:3 , bci/python:3-14.7 , bci/python:3.10 , bci/python:3.10-14.7 |
Container Release | 14.7 |
The following patches have been included in this update:
SUSE-CU-2023:2009-1
Container Advisory ID | SUSE-CU-2023:2009-1 |
Container Tags | bci/python:3 , bci/python:3-14.6 , bci/python:3.10 , bci/python:3.10-14.6 |
Container Release | 14.6 |
The following patches have been included in this update:
SUSE-CU-2023:1916-1
Container Advisory ID | SUSE-CU-2023:1916-1 |
Container Tags | bci/python:3 , bci/python:3-14.4 , bci/python:3.10 , bci/python:3.10-14.4 |
Container Release | 14.4 |
The following patches have been included in this update:
SUSE-CU-2023:1862-1
Container Advisory ID | SUSE-CU-2023:1862-1 |
Container Tags | bci/python:3 , bci/python:3-14.3 , bci/python:3.10 , bci/python:3.10-14.3 |
Container Release | 14.3 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2484-1
|
Released | Mon Jun 12 08:49:58 2023 |
Summary | Security update for openldap2 |
Type | security |
Severity | moderate |
References | 1211795,CVE-2023-2953 |
Description:
This update for openldap2 fixes the following issues:
- CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795).
SUSE-CU-2023:1833-1
Container Advisory ID | SUSE-CU-2023:1833-1 |
Container Tags | bci/python:3 , bci/python:3-14.2 , bci/python:3.10 , bci/python:3.10-14.2 |
Container Release | 14.2 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2463-1
|
Released | Thu Jun 8 09:42:28 2023 |
Summary | Security update for python310 |
Type | security |
Severity | moderate |
References | 1203750,CVE-2007-4559 |
Description:
This update for python310 fixes the following issues:
- CVE-2007-4559: Fixed filter for tarfile.extractall (bsc#1203750).
SUSE-CU-2023:1814-1
Container Advisory ID | SUSE-CU-2023:1814-1 |
Container Tags | bci/python:3 , bci/python:3-14.1 , bci/python:3.10 , bci/python:3.10-14.1 |
Container Release | 14.1 |
The following patches have been included in this update:
SUSE-CU-2023:1768-1
Container Advisory ID | SUSE-CU-2023:1768-1 |
Container Tags | bci/python:3 , bci/python:3-13.4 , bci/python:3.10 , bci/python:3.10-13.4 |
Container Release | 13.4 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2342-1
|
Released | Thu Jun 1 11:34:20 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1211430,CVE-2023-2650 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430).
SUSE-CU-2023:1718-1
Container Advisory ID | SUSE-CU-2023:1718-1 |
Container Tags | bci/python:3 , bci/python:3-13.3 , bci/python:3.10 , bci/python:3.10-13.3 |
Container Release | 13.3 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:2317-1
|
Released | Tue May 30 14:01:22 2023 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1210164 |
Description:
This update for util-linux fixes the following issue:
- Add upstream patch to prevent possible performance degradation of libuuid (bsc#1210164)
Advisory ID | SUSE-RU-2023:2333-1
|
Released | Wed May 31 09:01:28 2023 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1210593 |
Description:
This update for zlib fixes the following issue:
- Fix function calling order to avoid crashes (bsc#1210593)
SUSE-CU-2023:1642-1
Container Advisory ID | SUSE-CU-2023:1642-1 |
Container Tags | bci/python:3 , bci/python:3-12.52 , bci/python:3.10 , bci/python:3.10-12.52 , bci/python:latest |
Container Release | 12.52 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2224-1
|
Released | Wed May 17 09:53:54 2023 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322 |
Description:
This update for curl adds the following feature:
Update to version 8.0.1 (jsc#PED-2580)
- CVE-2023-28319: use-after-free in SSH sha256 fingerprint check (bsc#1211230).
- CVE-2023-28320: siglongjmp race condition (bsc#1211231).
- CVE-2023-28321: IDN wildcard matching (bsc#1211232).
- CVE-2023-28322: POST-after-PUT confusion (bsc#1211233).
Advisory ID | SUSE-RU-2023:2240-1
|
Released | Wed May 17 19:56:54 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | 1203141,1207410 |
Description:
This update for systemd fixes the following issues:
- udev-rules: fix nvme symlink creation on namespace changes (bsc#1207410)
- Optimize when hundred workers claim the same symlink with the same priority (bsc#1203141)
- Add nss-resolve and systemd-network to Packagehub-Subpackages (MSC-626)
SUSE-CU-2023:1573-1
Container Advisory ID | SUSE-CU-2023:1573-1 |
Container Tags | bci/python:3 , bci/python:3-12.46 , bci/python:3.10 , bci/python:3.10-12.46 , bci/python:latest |
Container Release | 12.46 |
The following patches have been included in this update:
SUSE-CU-2023:1526-1
Container Advisory ID | SUSE-CU-2023:1526-1 |
Container Tags | bci/python:3 , bci/python:3-12.45 , bci/python:3.10 , bci/python:3.10-12.45 , bci/python:latest |
Container Release | 12.45 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2111-1
|
Released | Fri May 5 14:34:00 2023 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1210434,CVE-2023-29491 |
Description:
This update for ncurses fixes the following issues:
- CVE-2023-29491: Fixed memory corruption issues when processing malformed terminfo data (bsc#1210434).
Advisory ID | SUSE-RU-2023:2114-1
|
Released | Fri May 5 14:37:02 2023 |
Summary | Recommended update for python310-setuptools |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for python310-setuptools fixes the following issues:
- Update to 67.6.1
- Support of pyproject.toml (jsc#PED-3765)
Advisory ID | SUSE-RU-2023:2131-1
|
Released | Tue May 9 13:35:24 2023 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | important |
References | 1207014 |
Description:
This update for openssh fixes the following issues:
- Remove some patches that cause invalid environment assignments (bsc#1207014).
Advisory ID | SUSE-RU-2023:2133-1
|
Released | Tue May 9 13:37:10 2023 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1206513 |
Description:
This update for zlib fixes the following issues:
- Add DFLTCC support for using inflate() with a small window (bsc#1206513)
SUSE-CU-2023:1414-1
Container Advisory ID | SUSE-CU-2023:1414-1 |
Container Tags | bci/python:3 , bci/python:3-12.40 , bci/python:3.10 , bci/python:3.10-12.40 , bci/python:latest |
Container Release | 12.40 |
The following patches have been included in this update:
SUSE-CU-2023:1358-1
Container Advisory ID | SUSE-CU-2023:1358-1 |
Container Tags | bci/python:3 , bci/python:3-12.39 , bci/python:3.10 , bci/python:3.10-12.39 , bci/python:latest |
Container Release | 12.39 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2066-1
|
Released | Fri Apr 28 13:54:17 2023 |
Summary | Security update for shadow |
Type | security |
Severity | moderate |
References | 1210507,CVE-2023-29383 |
Description:
This update for shadow fixes the following issues:
- CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507).
SUSE-CU-2023:1332-1
Container Advisory ID | SUSE-CU-2023:1332-1 |
Container Tags | bci/python:3 , bci/python:3-12.38 , bci/python:3.10 , bci/python:3.10-12.38 , bci/python:latest |
Container Release | 12.38 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2053-1
|
Released | Thu Apr 27 11:31:08 2023 |
Summary | Security update for libxml2 |
Type | security |
Severity | moderate |
References | 1209918,1210411,1210412,CVE-2023-28484,CVE-2023-29469 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2023-29469: Fixed inconsistent result when hashing empty strings (bsc#1210412).
- CVE-2023-28484: Fixed NULL pointer dereference in xmlSchemaFixupComplexType (bsc#1210411).
The following non-security bug was fixed:
- Remove unneeded dependency (bsc#1209918).
SUSE-CU-2023:1294-1
Container Advisory ID | SUSE-CU-2023:1294-1 |
Container Tags | bci/python:3 , bci/python:3-12.34 , bci/python:3.10 , bci/python:3.10-12.34 , bci/python:latest |
Container Release | 12.34 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:2038-1
|
Released | Wed Apr 26 11:06:20 2023 |
Summary | Security update for git |
Type | security |
Severity | moderate |
References | 1210686,CVE-2023-25652,CVE-2023-25815,CVE-2023-29007 |
Description:
This update for git fixes the following issues:
- CVE-2023-25652: Fixed partial overwrite of paths outside the working tree (bsc#1210686).
- CVE-2023-25815: Fixed malicious placemtn of crafted message (bsc#1210686).
- CVE-2023-29007: Fixed arbitrary configuration injection (bsc#1210686).
SUSE-CU-2023:1212-1
Container Advisory ID | SUSE-CU-2023:1212-1 |
Container Tags | bci/python:3 , bci/python:3-12.31 , bci/python:3.10 , bci/python:3.10-12.31 , bci/python:latest |
Container Release | 12.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:1911-1
|
Released | Wed Apr 19 13:02:33 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | moderate |
References | 1209873,1209878,CVE-2023-0465,CVE-2023-0466 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-0465: Invalid certificate policies in leaf certificates were silently ignored (bsc#1209878).
- CVE-2023-0466: Certificate policy check were not enabled (bsc#1209873).
Advisory ID | SUSE-RU-2023:1916-1
|
Released | Wed Apr 19 16:17:58 2023 |
Summary | Recommended update for sles-release |
Type | recommended |
Severity | low |
References | 1208529 |
Description:
This update for sles-release fixes the following issue:
- Filter libhogweed4 and libnettle6 so they dont get orphaned on system upgrades. (bsc#1208529)
SUSE-CU-2023:1156-1
Container Advisory ID | SUSE-CU-2023:1156-1 |
Container Tags | bci/python:3 , bci/python:3-12.25 , bci/python:3.10 , bci/python:3.10-12.25 , bci/python:latest |
Container Release | 12.25 |
The following patches have been included in this update:
SUSE-CU-2023:1087-1
Container Advisory ID | SUSE-CU-2023:1087-1 |
Container Tags | bci/python:3 , bci/python:3-12.22 , bci/python:3.10 , bci/python:3.10-12.22 , bci/python:latest |
Container Release | 12.22 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:1805-1
|
Released | Tue Apr 11 10:12:41 2023 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | |
Description:
This update for timezone fixes the following issues:
- Version update from 2022g to 2023c:
* Egypt now uses DST again, from April through October.
* This year Morocco springs forward April 23, not April 30.
* Palestine delays the start of DST this year.
* Much of Greenland still uses DST from 2024 on.
* America/Yellowknife now links to America/Edmonton.
* tzselect can now use current time to help infer timezone.
* The code now defaults to C99 or later.
SUSE-CU-2023:1057-1
Container Advisory ID | SUSE-CU-2023:1057-1 |
Container Tags | bci/python:3 , bci/python:3-12.21 , bci/python:3.10 , bci/python:3.10-12.21 , bci/python:latest |
Container Release | 12.21 |
The following patches have been included in this update:
SUSE-CU-2023:1021-1
Container Advisory ID | SUSE-CU-2023:1021-1 |
Container Tags | bci/python:3 , bci/python:3-12.20 , bci/python:3.10 , bci/python:3.10-12.20 , bci/python:latest |
Container Release | 12.20 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:1779-1
|
Released | Thu Apr 6 08:16:58 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | 1208432 |
Description:
This update for systemd fixes the following issues:
- Fix return non-zero value when disabling SysVinit service (bsc#1208432)
- Drop build requirement on libpci, it's not no longer needed
- Move systemd-boot and all components managing (secure) UEFI boot into udev
sub-package, so they aren't installed in systemd based containers
SUSE-CU-2023:986-1
Container Advisory ID | SUSE-CU-2023:986-1 |
Container Tags | bci/python:3 , bci/python:3-12.19 , bci/python:3.10 , bci/python:3.10-12.19 , bci/python:latest |
Container Release | 12.19 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:1745-1
|
Released | Tue Apr 4 09:05:23 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | moderate |
References | 1209624,CVE-2023-0464 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-0464: Fixed excessive Resource Usage Verifying X.509 Policy Constraints (bsc#1209624).
SUSE-CU-2023:919-1
Container Advisory ID | SUSE-CU-2023:919-1 |
Container Tags | bci/python:3 , bci/python:3-12.17 , bci/python:3.10 , bci/python:3.10-12.17 , bci/python:latest |
Container Release | 12.17 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:1718-1
|
Released | Fri Mar 31 15:47:34 2023 |
Summary | Security update for glibc |
Type | security |
Severity | moderate |
References | 1207571,1207957,1207975,1208358,CVE-2023-0687 |
Description:
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-0687: Fix allocated buffer overflow in gmon (bsc#1207975)
Other issues fixed:
- Fix avx2 strncmp offset compare condition check (bsc#1208358)
- elf: Allow dlopen of filter object to work (bsc#1207571)
- powerpc: Fix unrecognized instruction errors with recent GCC
- x86: Cache computation for AMD architecture (bsc#1207957)
SUSE-CU-2023:865-1
Container Advisory ID | SUSE-CU-2023:865-1 |
Container Tags | bci/python:3 , bci/python:3-12.16 , bci/python:3.10 , bci/python:3.10-12.16 , bci/python:latest |
Container Release | 12.16 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:1662-1
|
Released | Wed Mar 29 10:36:23 2023 |
Summary | Recommended update for patterns-base |
Type | recommended |
Severity | moderate |
References | 1203537 |
Description:
This update for patterns-base fixes the following issues:
- change label of FIPS 140-2 to 140-3 to reflect our current certifications (bsc#1203537)
Advisory ID | SUSE-SU-2023:1688-1
|
Released | Wed Mar 29 18:19:10 2023 |
Summary | Security update for zstd |
Type | security |
Severity | moderate |
References | 1209533,CVE-2022-4899 |
Description:
This update for zstd fixes the following issues:
- CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533).
SUSE-CU-2023:843-1
Container Advisory ID | SUSE-CU-2023:843-1 |
Container Tags | bci/python:3 , bci/python:3-12.12 , bci/python:3.10 , bci/python:3.10-12.12 , bci/python:latest |
Container Release | 12.12 |
The following patches have been included in this update:
SUSE-CU-2023:817-1
Container Advisory ID | SUSE-CU-2023:817-1 |
Container Tags | bci/python:3 , bci/python:3-12.10 , bci/python:3.10 , bci/python:3.10-12.10 , bci/python:latest |
Container Release | 12.10 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:1582-1
|
Released | Mon Mar 27 10:31:52 2023 |
Summary | Security update for curl |
Type | security |
Severity | moderate |
References | 1209209,1209210,1209211,1209212,1209214,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538 |
Description:
This update for curl fixes the following issues:
- CVE-2023-27533: Fixed TELNET option IAC injection (bsc#1209209).
- CVE-2023-27534: Fixed SFTP path ~ resolving discrepancy (bsc#1209210).
- CVE-2023-27535: Fixed FTP too eager connection reuse (bsc#1209211).
- CVE-2023-27536: Fixed GSS delegation too eager connection reuse (bsc#1209212).
- CVE-2023-27538: Fixed SSH connection too eager reuse still (bsc#1209214).
SUSE-CU-2023:788-1
Container Advisory ID | SUSE-CU-2023:788-1 |
Container Tags | bci/python:3 , bci/python:3-12.7 , bci/python:3.10 , bci/python:3.10-12.7 , bci/python:latest |
Container Release | 12.7 |
The following patches have been included in this update:
SUSE-CU-2023:716-1
Container Advisory ID | SUSE-CU-2023:716-1 |
Container Tags | bci/python:3 , bci/python:3-12.4 , bci/python:3.10 , bci/python:3.10-12.4 , bci/python:latest |
Container Release | 12.4 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:776-1
|
Released | Thu Mar 16 17:29:23 2023 |
Summary | Recommended update for gcc12 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for gcc12 fixes the following issues:
This update ships gcc12 also to the SUSE Linux Enterprise 15 SP1 LTSS and 15 SP2 LTSS products.
SUSE Linux Enterprise 15 SP3 and SP4 get only refreshed builds without changes
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided in the SUSE Linux
Enterprise Module for Development Tools.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
Advisory ID | SUSE-RU-2023:782-1
|
Released | Thu Mar 16 19:08:34 2023 |
Summary | Recommended update for libgcrypt |
Type | recommended |
Severity | moderate |
References | 1208924,1208925,1208926 |
Description:
This update for libgcrypt fixes the following issues:
- FIPS: ECC: Transition to error-state if PCT fail [bsc#1208925]
- FIPS: ECDSA: Avoid no-keytest in ECDSA keygen [bsc#1208924]
- FIPS: PBKDF2: Added additional checks for the minimum key length,
salt length, iteration count and passphrase length to the kdf
FIPS indicator in _gcry_fips_indicator_kdf() [bsc#1208926]
Advisory ID | SUSE-RU-2023:783-1
|
Released | Thu Mar 16 19:09:03 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1208998 |
Description:
This update for openssl-1_1 fixes the following issues:
FIPS: Service-level indicator changes [bsc#1208998]
- Add additional checks required by FIPS 140-3. Minimum values for
PBKDF2 are: 112 bits for key, 128 bits for salt, 1000 for
iteration count and 20 characters for password.
SUSE-CU-2023:694-1
Container Advisory ID | SUSE-CU-2023:694-1 |
Container Tags | bci/python:3 , bci/python:3-11.31 , bci/python:3.10 , bci/python:3.10-11.31 , bci/python:latest |
Container Release | 11.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:748-1
|
Released | Wed Mar 15 20:34:06 2023 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1208471,831629,CVE-2015-20107,CVE-2022-37454,CVE-2022-42919,CVE-2022-45061,CVE-2023-24329 |
Description:
This update for python310 fixes the following issues:
- CVE-2023-24329: Fixed blocklist bypass via the urllib.parse component when supplying a URL that starts with blank characters (bsc#1208471).
Update to 3.10.10:
- Add provides for readline and sqlite3 to the main Python
package.
- Disable NIS for new products, it's deprecated and gets removed
Update to 3.10.9:
- python -m http.server no longer allows terminal
control characters sent within a garbage request to be
printed to the stderr server lo This is done by changing
the http.server BaseHTTPRequestHandler .log_message method
to replace control characters with a \xHH hex escape before
printin
- Avoid publishing list of active per-interpreter
audit hooks via the gc module
- The IDNA codec decoder used on DNS hostnames by
socket or asyncio related name resolution functions no
longer involves a quadratic algorithm. This prevents a
potential CPU denial of service if an out-of-spec excessive
length hostname involving bidirectional characters were
decoded. Some protocols such as urllib http 3xx redirects
potentially allow for an attacker to supply such a name.
- Update bundled libexpat to 2.5.0
- Port XKCP’s fix for the buffer overflows in SHA-3
(CVE-2022-37454).
- On Linux the multiprocessing module returns
to using filesystem backed unix domain sockets for
communication with the forkserver process instead of the
Linux abstract socket namespace. Only code that chooses
to use the “forkserver†start method is affected Abstract
sockets have no permissions and could allow any user
on the system in the same network namespace (often the
whole system) to inject code into the multiprocessing
forkserver process. This was a potential privilege
escalation. Filesystem based socket permissions restrict
this to the forkserver process user as was the default in
Python 3.8 and earlier This prevents Linux CVE-2022-42919
- Fix a reference bug in _imp.create_builtin()
after the creation of the first sub-interpreter for modules
builtins and sys. Patch by Victor Stinner.
- Fixed a bug that was causing a buffer overflow if
the tokenizer copies a line missing the newline caracter
from a file that is as long as the available tokenizer
buffer. Patch by Pablo galindo
- Update faulthandler to emit an error message with
the proper unexpected signal number. Patch by Dong-hee Na.
- Fix subscription of types.GenericAlias instances
containing bare generic types: for example tuple[A, T][int],
where A is a generic type, and T is a type variable.
- Fix detection of MAC addresses for uuid on certain
OSs. Patch by Chaim Sanders
- Print exception class name instead of its string
representation when raising errors from ctypes calls.
- Allow pdb to locate source for frozen modules in
the standard library.
- Raise ValueError instead of SystemError when
methods of uninitialized io.IncrementalNewlineDecoder objects
are called. Patch by Oren Milman.
- Fix a possible assertion failure in io.FileIO when
the opener returns an invalid file descriptor.
- Also escape s in the http.server
BaseHTTPRequestHandler.log_message so that it is technically
possible to parse the line and reconstruct what the original
data was. Without this a xHH is ambiguious as to if it is a
hex replacement we put in or the characters râ€x†came through
in the original request line.
- asyncio.get_event_loop() now only emits a
deprecation warning when a new event loop was created
implicitly. It no longer emits a deprecation warning if the
current event loop was set.
- Fix bug when calling trace.CoverageResults with
valid infile.
- Fix a bug in handling class cleanups in
unittest.TestCase. Now addClassCleanup() uses separate lists
for different TestCase subclasses, and doClassCleanups() only
cleans up the particular class.
- Release the GIL when calling termios APIs to avoid
blocking threads.
- Fix ast.increment_lineno() to also cover
ast.TypeIgnore when changing line numbers.
- Fixed bug where inspect.signature() reported
incorrect arguments for decorated methods.
- Fix SystemError in ctypes when exception was not
set during __initsubclass__.
- Fix statistics.NormalDist pickle with 0 and 1
protocols.
- Update the bundled copy of pip to version 22.3.1.
- Apply bugfixes from importlib_metadata 4.11.4,
namely: In PathDistribution._name_from_stem, avoid
including parts of the extension in the result. In
PathDistribution._normalized_name, ensure names loaded from
the stem of the filename are also normalized, ensuring
duplicate entry points by packages varying only by
non-normalized name are hidden.
- Clean up refleak on failed module initialisation in
_zoneinfo
- Clean up refleaks on failed module initialisation
in in _pickle
- Clean up refleak on failed module initialisation in
_io.
- Fix memory leak in math.dist() when both points
don’t have the same dimension. Patch by Kumar Aditya.
- Fix argument typechecks in _overlapped.WSAConnect()
and _overlapped.Overlapped.WSASendTo() functions.
- Fix internal error in the re module which in
very rare circumstances prevented compilation of a regular
expression containing a conditional expression without the
“else†branch.
- Fix asyncio.StreamWriter.drain() to call
protocol.connection_lost callback only once on Windows.
- Add a mutex to unittest.mock.NonCallableMock to
protect concurrent access to mock attributes.
- Fix hang on Windows in subprocess.wait_closed() in
asyncio with ProactorEventLoop. Patch by Kumar Aditya.
- Fix infinite loop in unittest when a
self-referencing chained exception is raised
- tkinter.Text.count() raises now an exception for
options starting with “-†instead of silently ignoring them.
- On uname_result, restored expectation that _fields
and _asdict would include all six properties including
processor.
- Update the bundled copies of pip and setuptools to
versions 22.3 and 65.5.0 respectively.
- Fix bug in urllib.parse.urlparse() that causes
certain port numbers containing whitespace, underscores,
plus and minus signs, or non-ASCII digits to be incorrectly
accepted.
- Allow venv to pass along PYTHON* variables to
ensurepip and pip when they do not impact path resolution
- On macOS, fix a crash in syslog.syslog() in
multi-threaded applications. On macOS, the libc syslog()
function is not thread-safe, so syslog.syslog() no longer
releases the GIL to call it. Patch by Victor Stinner.
- Allow BUILTINS to be a valid field name for frozen
dataclasses.
- Make sure patch.dict() can be applied on async
functions.
- To avoid apparent memory leaks when
asyncio.open_connection() raises, break reference cycles
generated by local exception and future instances (which has
exception instance as its member var). Patch by Dong Uk,
Kang.
- Prevent error when activating venv in nested fish
instances.
- Restrict use of sockets instead of pipes for stdin
of subprocesses created by asyncio to AIX platform only.
- shutil.copytree() now applies the
ignore_dangling_symlinks argument recursively.
- Fix IndexError in argparse.ArgumentParser when a
store_true action is given an explicit argument.
- Document that calling variadic functions with
ctypes requires special care on macOS/arm64 (and possibly
other platforms).
- Skip test_normalization() of test_unicodedata
if it fails to download NormalizationTest.txt file from
pythontest.net. Patch by Victor Stinner.
- Some C API tests were moved into the new
Lib/test/test_capi/ directory.
- Fix -Wimplicit-int, -Wstrict-prototypes, and
-Wimplicit-function-declaration compiler warnings in
configure checks.
- Fix -Wimplicit-int compiler warning in configure
check for PTHREAD_SCOPE_SYSTEM.
- Specify the full path to the source location for
make docclean (needed for cross-builds).
- Fix NO_MISALIGNED_ACCESSES being not defined
for the SHA3 extension when HAVE_ALIGNED_REQUIRED is
set. Allowing builds on hardware that unaligned memory
accesses are not allowed.
- Fix handling of module docstrings in
Tools/i18n/pygettext.py.
- Add invalid-json.patch fixing invalid JSON in
Doc/howto/logging-cookbook.rst (somehow similar to gh#python/cpython#102582).
SUSE-CU-2023:664-1
Container Advisory ID | SUSE-CU-2023:664-1 |
Container Tags | bci/python:3 , bci/python:3-11.30 , bci/python:3.10 , bci/python:3.10-11.30 , bci/python:latest |
Container Release | 11.30 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:714-1
|
Released | Mon Mar 13 10:53:25 2023 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | important |
References | 1207294 |
Description:
This update for rpm fixes the following issues:
- Fix missing python(abi) for 3.XX versions (bsc#1207294)
SUSE-CU-2023:587-1
Container Advisory ID | SUSE-CU-2023:587-1 |
Container Tags | bci/python:3 , bci/python:3-11.27 , bci/python:3.10 , bci/python:3.10-11.27 , bci/python:latest |
Container Release | 11.27 |
The following patches have been included in this update:
SUSE-CU-2023:559-1
Container Advisory ID | SUSE-CU-2023:559-1 |
Container Tags | bci/python:3 , bci/python:3-11.26 , bci/python:3.10 , bci/python:3.10-11.26 , bci/python:latest |
Container Release | 11.26 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:617-1
|
Released | Fri Mar 3 16:49:06 2023 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | 1207789 |
Description:
This update for jitterentropy fixes the following issues:
- build jitterentropy library with debuginfo (bsc#1207789)
SUSE-CU-2023:528-1
Container Advisory ID | SUSE-CU-2023:528-1 |
Container Tags | bci/python:3 , bci/python:3-11.25 , bci/python:3.10 , bci/python:3.10-11.25 , bci/python:latest |
Container Release | 11.25 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:563-1
|
Released | Tue Feb 28 10:51:46 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1207994 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Serialize jitterentropy calls to avoid thread safety issues [bsc#1207994]
SUSE-CU-2023:417-1
Container Advisory ID | SUSE-CU-2023:417-1 |
Container Tags | bci/python:3 , bci/python:3-11.21 , bci/python:3.10 , bci/python:3.10-11.21 , bci/python:latest |
Container Release | 11.21 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:464-1
|
Released | Mon Feb 20 18:11:37 2023 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for systemd fixes the following issues:
- Merge of v249.15
- Drop workaround related to systemd-timesyncd that addressed a Factory issue.
- Conditionalize the use of /lib/modprobe.d only on systems with split usr
support enabled (i.e. SLE).
- Make use of the %systemd_* rpm macros consistently. Using the upstream
variants will ease the backports of Factory changes to SLE since Factory
systemd uses the upstream variants exclusively.
- machines.target belongs to systemd-container, do its init/cleanup steps from
the scriptlets of this sub-package.
- Make sure we apply the presets on units shipped by systemd package.
- systemd-testsuite: move the integration tests in a dedicated sub directory.
- Move systemd-cryptenroll into udev package.
SUSE-CU-2023:389-1
Container Advisory ID | SUSE-CU-2023:389-1 |
Container Tags | bci/python:3 , bci/python:3-11.17 , bci/python:3.10 , bci/python:3.10-11.17 , bci/python:latest |
Container Release | 11.17 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:429-1
|
Released | Wed Feb 15 17:41:22 2023 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1207990,1207991,1207992,CVE-2023-23914,CVE-2023-23915,CVE-2023-23916 |
Description:
This update for curl fixes the following issues:
- CVE-2023-23914: Fixed HSTS ignored on multiple requests (bsc#1207990).
- CVE-2023-23915: Fixed HSTS amnesia with --parallel (bsc#1207991).
- CVE-2023-23916: Fixed HTTP multi-header compression denial of service (bsc#1207992).
Advisory ID | SUSE-SU-2023:430-1
|
Released | Wed Feb 15 17:42:25 2023 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1208027,1208028,CVE-2023-22490,CVE-2023-23946 |
Description:
This update for git fixes the following issues:
- CVE-2023-22490: Fixed incorrectly usable local clone optimization even when using a non-local transport (bsc#1208027).
- CVE-2023-23946: Fixed issue where a path outside the working tree can be overwritten as the user who is running 'git apply' (bsc#1208028).
SUSE-CU-2023:371-1
Container Advisory ID | SUSE-CU-2023:371-1 |
Container Tags | bci/python:3 , bci/python:3-11.16 , bci/python:3.10 , bci/python:3.10-11.16 , bci/python:latest |
Container Release | 11.16 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:348-1
|
Released | Fri Feb 10 15:08:41 2023 |
Summary | Security update for less |
Type | security |
Severity | moderate |
References | 1207815,CVE-2022-46663 |
Description:
This update for less fixes the following issues:
- CVE-2022-46663: Fixed denial-of-service by printing specially crafted escape sequences to the terminal (bsc#1207815).
SUSE-CU-2023:319-1
Container Advisory ID | SUSE-CU-2023:319-1 |
Container Tags | bci/python:3 , bci/python:3-11.14 , bci/python:3.10 , bci/python:3.10-11.14 , bci/python:latest |
Container Release | 11.14 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:311-1
|
Released | Tue Feb 7 17:36:32 2023 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1207533,1207534,1207536,1207538,CVE-2022-4304,CVE-2022-4450,CVE-2023-0215,CVE-2023-0286 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2023-0286: Fixed X.400 address type confusion in X.509 GENERAL_NAME_cmp for x400Address (bsc#1207533).
- CVE-2023-0215: Fixed use-after-free following BIO_new_NDEF() (bsc#1207536).
- CVE-2022-4450: Fixed double free after calling PEM_read_bio_ex() (bsc#1207538).
- CVE-2022-4304: Fixed timing Oracle in RSA Decryption (bsc#1207534).
SUSE-CU-2023:259-1
Container Advisory ID | SUSE-CU-2023:259-1 |
Container Tags | bci/python:3 , bci/python:3-11.11 , bci/python:3.10 , bci/python:3.10-11.11 , bci/python:latest |
Container Release | 11.11 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:177-1
|
Released | Thu Jan 26 20:57:35 2023 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1194038,1205646 |
Description:
This update for util-linux fixes the following issues:
- Fix tests not passing when '@' character is in build path:
Fixes rpmbuild %checks fail when @ in the directory path (bsc#1194038).
- libuuid continuous clock handling for time based UUIDs:
Prevent use of the new libuuid ABI by uuidd %post before update
of libuuid1 (bsc#1205646).
Advisory ID | SUSE-RU-2023:178-1
|
Released | Thu Jan 26 20:58:21 2023 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1207182 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Add Pair-wise Consistency Test when generating DH key [bsc#1207182]
Advisory ID | SUSE-RU-2023:188-1
|
Released | Fri Jan 27 12:07:19 2023 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | important |
References | 1203652 |
Description:
This update for zlib fixes the following issues:
- Follow up fix for bug bsc#1203652 due to libxml2 issues
Advisory ID | SUSE-SU-2023:201-1
|
Released | Fri Jan 27 15:24:15 2023 |
Summary | Security update for systemd |
Type | security |
Severity | moderate |
References | 1204944,1205000,1207264,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed an issue where users could access coredumps
with changed uid, gid or capabilities (bsc#1205000).
Non-security fixes:
- Enabled the pstore service (jsc#PED-2663).
- Fixed an issue accessing TPM when secure boot is enabled (bsc#1204944).
- Fixed an issue where a pamd file could get accidentally overwritten
after an update (bsc#1207264).
SUSE-CU-2023:188-1
Container Advisory ID | SUSE-CU-2023:188-1 |
Container Tags | bci/python:3 , bci/python:3-11.5 , bci/python:3.10 , bci/python:3.10-11.5 , bci/python:latest |
Container Release | 11.5 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:110-1
|
Released | Fri Jan 20 10:18:16 2023 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1207032,1207033,CVE-2022-23521,CVE-2022-41903 |
Description:
This update for git fixes the following issues:
- CVE-2022-41903: Fixed a heap overflow in the 'git archive' and
'git log --format' commands (bsc#1207033).
- CVE-2022-23521: Fixed an integer overflow that could be triggered
when parsing a gitattributes file (bsc#1207032).
SUSE-CU-2023:169-1
Container Advisory ID | SUSE-CU-2023:169-1 |
Container Tags | bci/python:3 , bci/python:3-11.4 , bci/python:3.10 , bci/python:3.10-11.4 , bci/python:latest |
Container Release | 11.4 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2023:91-1
|
Released | Mon Jan 16 11:14:14 2023 |
Summary | Security update for python310-setuptools |
Type | security |
Severity | moderate |
References | 1206667,CVE-2022-40897 |
Description:
This update for python310-setuptools fixes the following issues:
- CVE-2022-40897: Fixed an excessive CPU usage that could be triggered
by fetching a malicious HTML document (bsc#1206667).
SUSE-CU-2023:133-1
Container Advisory ID | SUSE-CU-2023:133-1 |
Container Tags | bci/python:3 , bci/python:3-11.1 , bci/python:3.10 , bci/python:3.10-11.1 , bci/python:latest |
Container Release | 11.1 |
The following patches have been included in this update:
SUSE-CU-2023:132-1
Container Advisory ID | SUSE-CU-2023:132-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-10.14 , bci/python:latest |
Container Release | 10.14 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:45-1
|
Released | Mon Jan 9 10:32:26 2023 |
Summary | Recommended update for libxml2 |
Type | recommended |
Severity | moderate |
References | 1204585 |
Description:
This update for libxml2 fixes the following issues:
- Add W3C conformance tests to the testsuite (bsc#1204585):
* Added file xmlts20080827.tar.gz
Advisory ID | SUSE-RU-2023:48-1
|
Released | Mon Jan 9 10:37:54 2023 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1199467 |
Description:
This update for libtirpc fixes the following issues:
- Consider /proc/sys/net/ipv4/ip_local_reserved_ports, before binding to a random port (bsc#1199467)
Advisory ID | SUSE-RU-2023:50-1
|
Released | Mon Jan 9 10:42:21 2023 |
Summary | Recommended update for shadow |
Type | recommended |
Severity | moderate |
References | 1205502 |
Description:
This update for shadow fixes the following issues:
- Fix issue with user id field that cannot be interpreted (bsc#1205502)
SUSE-CU-2023:77-1
Container Advisory ID | SUSE-CU-2023:77-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-10.10 , bci/python:latest |
Container Release | 10.10 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2023:25-1
|
Released | Thu Jan 5 09:51:41 2023 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
Version update from 2022f to 2022g (bsc#1177460):
- In the Mexican state of Chihuahua:
* The border strip near the US will change to agree with nearby US locations on 2022-11-30.
* The strip's western part, represented by Ciudad Juarez, switches from -06 all year to -07/-06 with US DST rules,
like El Paso, TX.
* The eastern part, represented by Ojinaga, will observe US DST next year, like Presidio, TX.
* A new Zone America/Ciudad_Juarez splits from America/Ojinaga.
- Much of Greenland, represented by America/Nuuk, stops observing winter time after March 2023, so its daylight saving
time becomes standard time.
- Changes for pre-1996 northern Canada
- Update to past DST transition in Colombia (1993), Singapore (1981)
- 'timegm' is now supported by default
SUSE-CU-2022:3503-1
Container Advisory ID | SUSE-CU-2022:3503-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-10.7 , bci/python:latest |
Container Release | 10.7 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:4628-1
|
Released | Wed Dec 28 09:23:13 2022 |
Summary | Security update for sqlite3 |
Type | security |
Severity | moderate |
References | 1206337,CVE-2022-46908 |
Description:
This update for sqlite3 fixes the following issues:
- CVE-2022-46908: Properly implement the azProhibitedFunctions protection mechanism,
when relying on --safe for execution of an untrusted CLI script (bsc#1206337).
Advisory ID | SUSE-SU-2022:4629-1
|
Released | Wed Dec 28 09:24:07 2022 |
Summary | Security update for systemd |
Type | security |
Severity | important |
References | 1200723,1205000,CVE-2022-4415 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-4415: Fixed systemd-coredump that did not respect the fs.suid_dumpable kernel setting (bsc#1205000).
Bug fixes:
- Support by-path devlink for multipath nvme block devices (bsc#1200723).
SUSE-CU-2022:3450-1
Container Advisory ID | SUSE-CU-2022:3450-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-10.5 , bci/python:latest |
Container Release | 10.5 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:4597-1
|
Released | Wed Dec 21 10:13:11 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1206308,1206309,CVE-2022-43551,CVE-2022-43552 |
Description:
This update for curl fixes the following issues:
- CVE-2022-43552: HTTP Proxy deny use-after-free (bsc#1206309).
- CVE-2022-43551: Fixed HSTS bypass via IDN (bsc#1206308).
SUSE-CU-2022:3414-1
Container Advisory ID | SUSE-CU-2022:3414-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-10.2 , bci/python:latest |
Container Release | 10.2 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4499-1
|
Released | Thu Dec 15 10:48:49 2022 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1179465 |
Description:
This update for openssh fixes the following issues:
- Make ssh connections update their dbus environment (bsc#1179465):
* Add openssh-dbus.sh, openssh-dbus.csh, openssh-dbus.fish
SUSE-CU-2022:3366-1
Container Advisory ID | SUSE-CU-2022:3366-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-9.5 , bci/python:latest |
Container Release | 9.5 |
The following patches have been included in this update:
SUSE-CU-2022:3289-1
Container Advisory ID | SUSE-CU-2022:3289-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-9.1 , bci/python:latest |
Container Release | 9.1 |
The following patches have been included in this update:
SUSE-CU-2022:3223-1
Container Advisory ID | SUSE-CU-2022:3223-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-8.7 , bci/python:latest |
Container Release | 8.7 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4256-1
|
Released | Mon Nov 28 12:36:32 2022 |
Summary | Recommended update for gcc12 |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for gcc12 fixes the following issues:
This update ship the GCC 12 compiler suite and its base libraries.
The compiler baselibraries are provided for all SUSE Linux Enterprise 15
versions and replace the same named GCC 11 ones.
The new compilers for C, C++, and Fortran are provided for SUSE Linux
Enterprise 15 SP3 and SP4, and provided in the 'Development Tools' module.
The Go, D and Ada language compiler parts are available unsupported via the
PackageHub repositories.
To use gcc12 compilers use:
- install 'gcc12' or 'gcc12-c++' or one of the other 'gcc12-COMPILER' frontend packages.
- override your Makefile to use CC=gcc12, CXX=g++12 and similar overrides for the other languages.
For a full changelog with all new GCC12 features, check out
https://gcc.gnu.org/gcc-12/changes.html
SUSE-CU-2022:3180-1
Container Advisory ID | SUSE-CU-2022:3180-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-8.3 , bci/python:latest |
Container Release | 8.3 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4212-1
|
Released | Thu Nov 24 15:53:48 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1190651 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Mark PBKDF2 with key shorter than 112 bits as non-approved (bsc#1190651)
- FIPS: Consider RSA siggen/sigver with PKCS1 padding also approved (bsc#1190651)
- FIPS: Return the correct indicator for a given EC group order bits (bsc#1190651)
SUSE-CU-2022:3179-1
Container Advisory ID | SUSE-CU-2022:3179-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-8.2 , bci/python:latest |
Container Release | 8.2 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4198-1
|
Released | Wed Nov 23 13:15:04 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | moderate |
References | 1202750 |
Description:
This update for rpm fixes the following issues:
- Strip critical bit in signature subpackage parsing
- No longer deadlock DNF after pubkey import (bsc#1202750)
SUSE-CU-2022:3102-1
Container Advisory ID | SUSE-CU-2022:3102-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.35 , bci/python:latest |
Container Release | 7.35 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:4135-1
|
Released | Mon Nov 21 00:13:40 2022 |
Summary | Recommended update for libeconf |
Type | recommended |
Severity | moderate |
References | 1198165 |
Description:
This update for libeconf fixes the following issues:
- Update to version 0.4.6+git
- econftool:
Parsing error: Reporting file and line nr. --delimeters=spaces accepting all kind of spaces for delimiter.
- libeconf:
Parse files correctly on space characters (1198165)
- Update to version 0.4.5+git
- econftool:
New call 'syntax' for checking the configuration files only. Returns an error string with line number if error.
New options '--comment' and '--delimeters'
Advisory ID | SUSE-SU-2022:4153-1
|
Released | Mon Nov 21 14:34:09 2022 |
Summary | Security update for krb5 |
Type | security |
Severity | important |
References | 1205126,CVE-2022-42898 |
Description:
This update for krb5 fixes the following issues:
- CVE-2022-42898: Fixed integer overflow in PAC parsing (bsc#1205126).
SUSE-CU-2022:3048-1
Container Advisory ID | SUSE-CU-2022:3048-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.31 , bci/python:latest |
Container Release | 7.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3999-1
|
Released | Tue Nov 15 17:08:04 2022 |
Summary | Security update for systemd |
Type | security |
Severity | moderate |
References | 1204179,1204968,CVE-2022-3821 |
Description:
This update for systemd fixes the following issues:
- CVE-2022-3821: Fixed buffer overrun in format_timespan() function (bsc#1204968).
- Import commit 0cd50eedcc0692c1f907b24424215f8db7d3b428
* 0469b9f2bc pstore: do not try to load all known pstore modules
* ad05f54439 pstore: Run after modules are loaded
* ccad817445 core: Add trigger limit for path units
* 281d818fe3 core/mount: also add default before dependency for automount mount units
* ffe5b4afa8 logind: fix crash in logind on user-specified message string
- Document udev naming scheme (bsc#1204179)
- Make 'sle15-sp3' net naming scheme still available for backward compatibility
reason
Advisory ID | SUSE-SU-2022:4004-1
|
Released | Tue Nov 15 17:10:13 2022 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1204886,1205244,CVE-2022-42919,CVE-2022-45061 |
Description:
This update for python310 fixes the following issues:
Security fixes:
- CVE-2022-42919: Fixed local privilege escalation via the multiprocessing forkserver start method (bsc#1204886).
- CVE-2022-45061: Fixed a quadratic IDNA decoding time (bsc#1205244).
Other fixes:
- allow building of documentation with the latest Sphinx 5.3.0 (gh#python/cpython#98366).
- Update to 3.10.8:
- Fix multiplying a list by an integer (list *= int): detect
the integer overflow when the new allocated length is close
to the maximum size.
- Fix a shell code injection vulnerability in the
get-remote-certificate.py example script. The script no
longer uses a shell to run openssl commands. (originally
filed as CVE-2022-37460, later withdrawn)
- Fix command line parsing: reject -X int_max_str_digits option
with no value (invalid) when the PYTHONINTMAXSTRDIGITS
environment variable is set to a valid limit.
- When ValueError is raised if an integer is larger than the
limit, mention the sys.set_int_max_str_digits() function in
the error message.
- The deprecated mailcap module now refuses to inject unsafe
text (filenames, MIME types, parameters) into shell
commands. Instead of using such text, it will warn and act
as if a match was not found (or for test commands, as if the
test failed).
- os.sched_yield() now release the GIL while calling
sched_yield(2).
- Bugfix: PyFunction_GetAnnotations() should return a borrowed
reference. It was returning a new reference.
- Fixed a missing incref/decref pair in
Exception.__setstate__().
- Fix overly-broad source position information for chained
comparisons used as branching conditions.
- Fix undefined behaviour in _testcapimodule.c.
- At Python exit, sometimes a thread holding the GIL can
wait forever for a thread (usually a daemon thread) which
requested to drop the GIL, whereas the thread already
exited. To fix the race condition, the thread which requested
the GIL drop now resets its request before exiting.
- Fix a possible assertion failure, fatal error, or SystemError
if a line tracing event raises an exception while opcode
tracing is enabled.
- Fix undefined behaviour in C code of null pointer arithmetic.
- Do not expose KeyWrapper in _functools.
- When loading a file with invalid UTF-8 inside a multi-line
string, a correct SyntaxError is emitted.
- Disable incorrect pickling of the C implemented classmethod
descriptors.
- Fix AttributeError missing name and obj attributes in .
object.__getattribute__() bpo-42316: Document some places .
where an assignment expression needs parentheses .
- Wrap network errors consistently in urllib FTP support, so
the test suite doesn’t fail when a network is available but
the public internet is not reachable.
- Fixes AttributeError when subprocess.check_output() is used
with argument input=None and either of the arguments encoding
or errors are used.
- Avoid spurious tracebacks from asyncio when default executor
cleanup is delayed until after the event loop is closed (e.g.
as the result of a keyboard interrupt).
- Avoid a crash in the C version of
asyncio.Future.remove_done_callback() when an evil argument
is passed.
- Remove tokenize.NL check from tabnanny.
- Make Semaphore run faster.
- Fix generation of the default name of
tkinter.Checkbutton. Previously, checkbuttons in different
parent widgets could have the same short name and share
the same state if arguments “name†and “variable†are not
specified. Now they are globally unique.
- Update bundled libexpat to 2.4.9
- Fix race condition in asyncio where process_exited() called
before the pipe_data_received() leading to inconsistent
output.
- Fixed check in multiprocessing.resource_tracker that
guarantees that the length of a write to a pipe is not
greater than PIPE_BUF.
- Corrected type annotation for dataclass attribute
pstats.FunctionProfile.ncalls to be str.
- Fix the faulthandler implementation of
faulthandler.register(signal, chain=True) if the sigaction()
function is not available: don’t call the previous signal
handler if it’s NULL.
- In inspect, fix overeager replacement of “typing.†in
formatting annotations.
- Fix asyncio.streams.StreamReaderProtocol to keep a strong
reference to the created task, so that it’s not garbage
collected
- Fix handling compiler warnings (SyntaxWarning and
DeprecationWarning) in codeop.compile_command() when checking
for incomplete input. Previously it emitted warnings and
raised a SyntaxError. Now it always returns None for
incomplete input without emitting any warnings.
- Fixed flickering of the turtle window when the tracer is
turned off.
- Allow asyncio.StreamWriter.drain() to be awaited concurrently
by multiple tasks.
- Fix broken asyncio.Semaphore when acquire is cancelled.
- Fix ast.unparse() when ImportFrom.level is None
- Improve performance of urllib.request.getproxies_environment
when there are many environment variables
- Fix ! in c domain ref target syntax via a conf.py patch, so
it works as intended to disable ref target resolution.
- Clarified the conflicting advice given in the ast
documentation about ast.literal_eval() being “safe†for use
on untrusted input while at the same time warning that it
can crash the process. The latter statement is true and is
deemed unfixable without a large amount of work unsuitable
for a bugfix. So we keep the warning and no longer claim that
literal_eval is safe.
- Update tutorial introduction output to use 3.10+ SyntaxError
invalid range.
Advisory ID | SUSE-RU-2022:4066-1
|
Released | Fri Nov 18 10:43:00 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1177460,1202324,1204649,1205156 |
Description:
This update for timezone fixes the following issues:
Update timezone version from 2022a to 2022f (bsc#1177460, bsc#1204649, bsc#1205156):
- Mexico will no longer observe DST except near the US border
- Chihuahua moves to year-round -06 on 2022-10-30
- Fiji no longer observes DST
- In vanguard form, GMT is now a Zone and Etc/GMT a link
- zic now supports links to links, and vanguard form uses this
- Simplify four Ontario zones
- Fix a Y2438 bug when reading TZif data
- Enable 64-bit time_t on 32-bit glibc platforms
- Omit large-file support when no longer needed
- Jordan and Syria switch from +02/+03 with DST to year-round +03
- Palestine transitions are now Saturdays at 02:00
- Simplify three Ukraine zones into one
- Improve tzselect on intercontinental Zones
- Chile's DST is delayed by a week in September 2022 (bsc#1202324)
- Iran no longer observes DST after 2022
- Rename Europe/Kiev to Europe/Kyiv
- New `zic -R` command option
- Vanguard form now uses %z
Advisory ID | SUSE-SU-2022:4081-1
|
Released | Fri Nov 18 15:40:46 2022 |
Summary | Security update for dpkg |
Type | security |
Severity | low |
References | 1199944,CVE-2022-1664 |
Description:
This update for dpkg fixes the following issues:
- CVE-2022-1664: Fixed a directory traversal vulnerability in Dpkg::Source::Archive (bsc#1199944).
SUSE-CU-2022:2994-1
Container Advisory ID | SUSE-CU-2022:2994-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.24 , bci/python:latest |
Container Release | 7.24 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3961-1
|
Released | Mon Nov 14 07:33:50 2022 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | important |
References | 1203652 |
Description:
This update for zlib fixes the following issues:
- Fix updating strm.adler with inflate() if DFLTCC is used (bsc#1203652)
Advisory ID | SUSE-RU-2022:3974-1
|
Released | Mon Nov 14 15:39:20 2022 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1201959,1204211 |
Description:
This update for util-linux fixes the following issues:
- Fix file conflict during upgrade (bsc#1204211)
- libuuid improvements (bsc#1201959, PED-1150):
libuuid: Fix range when parsing UUIDs.
Improve cache handling for short running applications-increment the cache size over runtime.
Implement continuous clock handling for time based UUIDs.
Check clock value from clock file to provide seamless libuuid.
SUSE-CU-2022:2948-1
Container Advisory ID | SUSE-CU-2022:2948-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.21 , bci/python:latest |
Container Release | 7.21 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3931-1
|
Released | Thu Nov 10 11:26:01 2022 |
Summary | Security update for git |
Type | security |
Severity | moderate |
References | 1204455,1204456,CVE-2022-39253,CVE-2022-39260 |
Description:
This update for git fixes the following issues:
- CVE-2022-39260: Fixed overflow in split_cmdline() (bsc#1204456).
- CVE-2022-39253: Fixed dereference issue with symbolic links via the `--local` clone mechanism (bsc#1204455).
SUSE-CU-2022:2924-1
Container Advisory ID | SUSE-CU-2022:2924-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.20 , bci/python:latest |
Container Release | 7.20 |
The following patches have been included in this update:
SUSE-CU-2022:2923-1
Container Advisory ID | SUSE-CU-2022:2923-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.19 , bci/python:latest |
Container Release | 7.19 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3904-1
|
Released | Tue Nov 8 10:52:13 2022 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1192439 |
Description:
This update for openssh fixes the following issue:
- Prevent empty messages from being sent. (bsc#1192439)
Advisory ID | SUSE-RU-2022:3910-1
|
Released | Tue Nov 8 13:05:04 2022 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for pam fixes the following issue:
- Update pam_motd to the most current version. (PED-1712)
SUSE-CU-2022:2864-1
Container Advisory ID | SUSE-CU-2022:2864-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.16 , bci/python:latest |
Container Release | 7.16 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3884-1
|
Released | Mon Nov 7 10:59:26 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1204708,CVE-2022-43680 |
Description:
This update for expat fixes the following issues:
- CVE-2022-43680: Fixed use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate (bsc#1204708).
SUSE-CU-2022:2825-1
Container Advisory ID | SUSE-CU-2022:2825-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.14 , bci/python:latest |
Container Release | 7.14 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3870-1
|
Released | Fri Nov 4 11:12:08 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1190651,1202148 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Add a missing dependency on jitterentropy-devel for libopenssl-1_1-devel (bsc#1202148)
- FIPS: OpenSSL service-level indicator: Allow AES XTS 256 (bsc#1190651)
SUSE-CU-2022:2764-1
Container Advisory ID | SUSE-CU-2022:2764-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.11 , bci/python:latest |
Container Release | 7.11 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3784-1
|
Released | Wed Oct 26 18:03:28 2022 |
Summary | Security update for libtasn1 |
Type | security |
Severity | critical |
References | 1204690,CVE-2021-46848 |
Description:
This update for libtasn1 fixes the following issues:
- CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)
Advisory ID | SUSE-SU-2022:3785-1
|
Released | Wed Oct 26 20:20:19 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1204383,1204386,CVE-2022-32221,CVE-2022-42916 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32221: Fixed POST following PUT confusion (bsc#1204383).
- CVE-2022-42916: Fixed HSTS bypass via IDN (bsc#1204386).
Advisory ID | SUSE-RU-2022:3787-1
|
Released | Thu Oct 27 04:41:09 2022 |
Summary | Recommended update for permissions |
Type | recommended |
Severity | important |
References | 1194047,1203911 |
Description:
This update for permissions fixes the following issues:
- Fix regression introduced by backport of security fix (bsc#1203911)
- Add permissions for enlightenment helper on 32bit arches (bsc#1194047)
SUSE-CU-2022:2724-1
Container Advisory ID | SUSE-CU-2022:2724-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-7.5 , bci/python:latest |
Container Release | 7.5 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2796-1
|
Released | Fri Aug 12 14:34:31 2022 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for jitterentropy fixes the following issues:
jitterentropy is included in version 3.4.0 (jsc#SLE-24941):
This is a FIPS 140-3 / NIST 800-90b compliant userspace jitter entropy generator library,
used by other FIPS libraries.
Advisory ID | SUSE-RU-2022:3328-1
|
Released | Wed Sep 21 12:48:56 2022 |
Summary | Recommended update for jitterentropy |
Type | recommended |
Severity | moderate |
References | 1202870 |
Description:
This update for jitterentropy fixes the following issues:
- Hide the non-GNUC constructs that are library internal from the
exported header, to make it usable in builds with strict C99
compliance. (bsc#1202870)
Advisory ID | SUSE-RU-2022:3551-1
|
Released | Fri Oct 7 17:03:55 2022 |
Summary | Recommended update for libgcrypt |
Type | recommended |
Severity | moderate |
References | 1182983,1190700,1191020,1202117 |
Description:
This update for libgcrypt fixes the following issues:
- FIPS: Fixed gpg/gpg2 gets out of core handler in FIPS mode while
typing Tab key to Auto-Completion. [bsc#1182983]
- FIPS: Ported libgcrypt to use jitterentropy [bsc#1202117, jsc#SLE-24941]
* Enable the jitter based entropy generator by default in random.conf
* Update the internal jitterentropy to version 3.4.0
- FIPS: Get most of the entropy from rndjent_poll [bsc#1202117]
- FIPS: Check keylength in gcry_fips_indicator_kdf() [bsc#1190700]
* Consider approved keylength greater or equal to 112 bits.
- FIPS: Zeroize buffer and digest in check_binary_integrity() [bsc#1191020]
Advisory ID | SUSE-RU-2022:3555-1
|
Released | Mon Oct 10 14:05:12 2022 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | important |
References | 1199492 |
Description:
This update for aaa_base fixes the following issues:
- The wrapper rootsh is not a restricted shell. (bsc#1199492)
Advisory ID | SUSE-RU-2022:3663-1
|
Released | Wed Oct 19 19:05:21 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1121365,1180995,1190651,1190653,1190888,1193859,1198471,1198472,1201293,1202148,1203046,1203069 |
Description:
This update for openssl-1_1 fixes the following issues:
- FIPS: Default to RFC-7919 groups for genparam and dhparam
- FIPS: list only FIPS approved digest and public key algorithms
[bsc#1121365, bsc#1190888, bsc#1193859, bsc#1198471, bsc#1198472]
- FIPS: Add KAT for the RAND_DRBG implementation [bsc#1203069]
- FIPS: openssl: RAND api should call into FIPS DRBG [bsc#1201293]
* The FIPS_drbg implementation is not FIPS validated anymore. To
provide backwards compatibility for applications that need FIPS
compliant RNG number generation and use FIPS_drbg_generate,
this function was re-wired to call the FIPS validated DRBG
instance instead through the RAND_bytes() call.
- FIPS: Fix minor memory leaks by FIPS patch [bsc#1203046]
- FIPS: OpenSSL: Port openssl to use jitterentropy [bsc#1202148, jsc#SLE-24941]
libcrypto.so now requires libjitterentropy3 library.
- FIPS: OpenSSL Provide a service-level indicator [bsc#1190651]
- FIPS: Add zeroization of temporary variables to the hmac integrity
function FIPSCHECK_verify(). [bsc#1190653]
Advisory ID | SUSE-SU-2022:3692-1
|
Released | Fri Oct 21 16:15:07 2022 |
Summary | Security update for libxml2 |
Type | security |
Severity | important |
References | 1204366,1204367,CVE-2022-40303,CVE-2022-40304 |
Description:
This update for libxml2 fixes the following issues:
- CVE-2022-40303: Fixed integer overflows with XML_PARSE_HUGE (bsc#1204366).
- CVE-2022-40304: Fixed dict corruption caused by entity reference cycles (bsc#1204367).
SUSE-CU-2022:2592-1
Container Advisory ID | SUSE-CU-2022:2592-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-6.8 , bci/python:latest |
Container Release | 6.8 |
The following patches have been included in this update:
SUSE-CU-2022:2541-1
Container Advisory ID | SUSE-CU-2022:2541-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-6.7 , bci/python:latest |
Container Release | 6.7 |
The following patches have been included in this update:
SUSE-CU-2022:2496-1
Container Advisory ID | SUSE-CU-2022:2496-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-6.4 , bci/python:latest |
Container Release | 6.4 |
The following patches have been included in this update:
SUSE-CU-2022:2467-1
Container Advisory ID | SUSE-CU-2022:2467-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.42 , bci/python:latest |
Container Release | 5.42 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3473-1
|
Released | Fri Sep 30 10:33:55 2022 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1202624,1203125,CVE-2020-10735,CVE-2021-28861 |
Description:
This update for python310 fixes the following issues:
Updated to version 3.10.7:
- CVE-2020-10735: Fixed DoS due to missing limit of amount of digits when converting text to int (bsc#1203125).
- CVE-2021-28861: Fixed an open redirect in the http server when an URI path starts with // (bsc#1202624).
Advisory ID | SUSE-SU-2022:3489-1
|
Released | Sat Oct 1 13:35:24 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1203438,CVE-2022-40674 |
Description:
This update for expat fixes the following issues:
- CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438).
SUSE-CU-2022:2421-1
Container Advisory ID | SUSE-CU-2022:2421-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.39 , bci/python:latest |
Container Release | 5.39 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3452-1
|
Released | Wed Sep 28 12:13:43 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1201942 |
Description:
This update for glibc fixes the following issues:
- Reversing calculation of __x86_shared_non_temporal_threshold (bsc#1201942)
- powerpc: Optimized memcmp for power10 (jsc#PED-987)
SUSE-CU-2022:2377-1
Container Advisory ID | SUSE-CU-2022:2377-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.37 , bci/python:latest |
Container Release | 5.37 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3353-1
|
Released | Fri Sep 23 15:23:40 2022 |
Summary | Security update for permissions |
Type | security |
Severity | moderate |
References | 1203018,CVE-2022-31252 |
Description:
This update for permissions fixes the following issues:
- CVE-2022-31252: Fixed chkstat group controlled paths (bsc#1203018).
SUSE-CU-2022:2297-1
Container Advisory ID | SUSE-CU-2022:2297-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.31 , bci/python:latest |
Container Release | 5.31 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:3271-1
|
Released | Wed Sep 14 06:45:39 2022 |
Summary | Security update for perl |
Type | security |
Severity | moderate |
References | 1047178,CVE-2017-6512 |
Description:
This update for perl fixes the following issues:
- CVE-2017-6512: Fixed File::Path rmtree/remove_tree race condition (bsc#1047178).
Advisory ID | SUSE-feature-2022:3302-1
|
Released | Mon Sep 19 08:51:02 2022 |
Summary | Feature update for python310-pip |
Type | feature |
Severity | moderate |
References | 1201041 |
Description:
This feature update for python310-pip and python-rpm-macros provides:
python310-pip:
Upgrade from version 20.2.4 to version 22.0.4 (jsc#SLE-24539)
- Adjust SPEC file to generate python310 module only
- Avoid cycle: BuildRequire ca-certificates only in tests
- This version is not compatible with Python 3.6 and thus not suitable for SUSE Linux Enterprise 15.
- Drop the doctype check, that presented a warning for index pages that use non-compliant HTML 5.
- Print the exception via rich.traceback, when running with `--debug`.
- Only calculate topological installation order, for packages that are going to be installed/upgraded.
* This error occurred when determining the installation order for a very specific combination of
upgrading of already installed packages, change of dependencies and fetching some packages
from a package index. This combination was especially common in Read the Docs' builds.
- Use html.parser by default, instead of falling back to html5lib when --use-deprecated=html5lib is not passed.
- Clarify that using per-requirement overrides disables the usage of wheels.
- Instead of failing on index pages that use non-compliant HTML 5, print a deprecation warning
and fall back to html5lib-based parsing for now.
This simplifies the migration for non-compliant index pages, by letting such indexes function with a warning.
- Accept lowercase on index pages.
- Properly handle links parsed by html5lib, when using --use-deprecated=html5lib.
- Changed PackageFinder to parse HTML documents using the
stdlib :class:`html.parser.HTMLParser` class instead of the
html5lib package.
- For now, the deprecated html5lib code remains and can be used with the --use-deprecated=html5lib
command line option. However, it will be removed in a future pip release.
- Completely replace :pypi:`tox` in our development workflow, with :pypi:`nox`.
- Deprecate alternative progress bar styles, leaving only on and off as available choices.
- Drop support for Python 3.6.
- Disable location mismatch warnings on Python versions prior to 3.10.
* These warnings were helping identify potential issues as part
of the sysconfig -> distutils transition, and we no longer
need to rely on reports from older Python versions for information on the transition.
- Utilize rich for presenting pip's default download progress bar.
- Present a better error message when an invalid wheel file is
encountered, providing more context where the invalid wheel file is.
- Documents the --require-virtualenv flag for pip install.
- pip install autocompletes paths.
- Allow Python distributors to opt-out from or opt-in to the
sysconfig installation scheme backend by setting
sysconfig._PIP_USE_SYSCONFIG to True or False.
- Make it possible to deselect tests requiring cryptography package on systems where it cannot be installed.
- Start using Rich for presenting error messages in a consistent format.
- Improve presentation of errors from subprocesses.
- Forward pip's verbosity configuration to VCS tools to control their output accordingly.
- Optimize installation order calculation to improve
performance when installing requirements that form a complex
dependency graph with a large amount of edges.
- When a package is requested by the user for upgrade,
correctly identify that the extra-ed variant of that same
package depended by another user-requested package is
requesting the same package, and upgrade it accordingly.
- Prevent pip from installing yanked releases unless explicitly
pinned via the `==` or `===` operators.
- Stop backtracking on build failures, by instead surfacing
them to the user and aborting immediately. This behaviour
provides more immediate feedback when a package cannot be
built due to missing build dependencies or platform
incompatibility.
- Silence Value for does not match warning caused by
an erroneous patch in Slackware-distributed Python 3.9.
- Fix an issue where pip did not consider dependencies with and without extras to be equal
- Always refuse installing or building projects that have no ``pyproject.toml`` nor ``setup.py``.
- Tweak running-as-root detection, to check ``os.getuid`` if it exists, on Unix-y and non-Linux/non-MacOS machines.
- When installing projects with a ``pyproject.toml`` in editable mode, and the build
backend does not support :pep:`660`, prepare metadata using
``prepare_metadata_for_build_wheel`` instead of ``setup.py egg_info``. Also, refuse
installing projects that only have a ``setup.cfg`` and no ``setup.py`` nor
``pyproject.toml``. These restore the pre-21.3 behaviour.
- Restore compatibility of where configuration files are loaded from on MacOS
- Upgrade pep517 to 0.12.0
- Improve deprecation warning regarding the copying of source trees when installing from a local directory.
- Suppress location mismatch warnings when pip is invoked from a Python source
tree, so ``ensurepip`` does not emit warnings on CPython ``make install``.
- On Python 3.10 or later, the installation scheme backend has been changed to use
``sysconfig``. This is to anticipate the deprecation of ``distutils`` in Python
3.10, and its scheduled removal in 3.12. For compatibility considerations, pip
installations running on Python 3.9 or lower will continue to use ``distutils``.
- Remove the ``--build-dir`` option and aliases, one last time.
- In-tree builds are now the default. ``--use-feature=in-tree-build`` is now
ignored. ``--use-deprecated=out-of-tree-build`` may be used temporarily to ease the transition.
- Un-deprecate source distribution re-installation behaviour.
- Replace vendored appdirs with platformdirs.
- Support `PEP 610 `_ to detect
editable installs in ``pip freeze`` and ``pip list``. The ``pip list`` column output
has a new ``Editable project location`` column, and the JSON output has a new
``editable_project_location`` field.
- ``pip freeze`` will now always fallback to reporting the editable project
location when it encounters a VCS error while analyzing an editable
requirement. Before, it sometimes reported the requirement as non-editable.
- ``pip show`` now sorts ``Requires`` and ``Required-By`` alphabetically.
- Do not raise error when there are no files to remove with ``pip cache purge/remove``.
Instead log a warning and continue (to log that we removed 0 files).
- When backtracking during dependency resolution, prefer the dependencies
which are involved in the most recent conflict. This can significantly reduce the amount of backtracking required.
- Cache requirement objects, to improve performance reducing reparses of requirement strings.
- Support editable installs for projects that have a ``pyproject.toml`` and use a
build backend that supports :pep:`660`.
- When a revision is specified in a Git URL, use git's partial clone feature to speed up source retrieval.
- Add a ``--debug`` flag, to enable a mode that doesn't log errors and
propagates them to the top level instead. This is primarily to aid with debugging pip's crashes.
- If a host is explicitly specified as trusted by the user (via the
--trusted-host option), cache HTTP responses from it in addition to HTTPS ones.
- Present a better error message, when a ``file:`` URL is not found.
- Fix the auth credential cache to allow for the case in which the index url contains the username, but the password
comes from an external source, such as keyring.
- Fix double unescape of HTML ``data-requires-python`` and ``data-yanked`` attributes.
- New resolver: Fixes depth ordering of packages during resolution, e.g. a
dependency 2 levels deep will be ordered before a dependency 3 levels deep.
python-rpm-macros:
Update from version 20220106.80d3756 to version 20220809.cf8a7b8 (bsc#1201041)
- Pass `--ignore-installed` to `pip install` in %pyproject_install
- restore end-of-line in alternative scriptlets
- make python_flavored_alternatives less verbose
- Move install of libalts from sciptlets to python_clone -a
- hard-code %py_ver
- print proper error on missing python interpreter
- Update compile-macros.sh
- Create python_flavored_alternatives and use for testing
- Switch primary_interpreter from python38 to python310
- Avoid bashism in %()
- Fix flavor executable substitution
- Keep python38 as primary python3
- Add python310 to the buildset
- Move python39 to the primary place in %pythons
- Disable python36 flavor in Factory buildset
- Add python310 flavor macros to compile set
Advisory ID | SUSE-SU-2022:3305-1
|
Released | Mon Sep 19 11:45:57 2022 |
Summary | Security update for libtirpc |
Type | security |
Severity | important |
References | 1201680,CVE-2021-46828 |
Description:
This update for libtirpc fixes the following issues:
- CVE-2021-46828: Fixed denial of service vulnerability with lots of connections (bsc#1201680).
Advisory ID | SUSE-SU-2022:3307-1
|
Released | Mon Sep 19 13:26:51 2022 |
Summary | Security update for sqlite3 |
Type | security |
Severity | moderate |
References | 1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737 |
Description:
This update for sqlite3 fixes the following issues:
- CVE-2022-35737: Fixed an array-bounds overflow if billions of bytes are used in a string argument to a C API (bnc#1201783).
- CVE-2021-36690: Fixed an issue with the SQLite Expert extension when a column has no collating sequence (bsc#1189802).
- Package the Tcl bindings here again so that we only ship one copy of SQLite (bsc#1195773).
SUSE-CU-2022:2233-1
Container Advisory ID | SUSE-CU-2022:2233-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.26 , bci/python:latest |
Container Release | 5.26 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3262-1
|
Released | Tue Sep 13 15:34:29 2022 |
Summary | Recommended update for gcc11 |
Type | recommended |
Severity | moderate |
References | 1199140 |
Description:
This update for gcc11 ships some missing 32bit libraries for s390x. (bsc#1199140)
SUSE-CU-2022:2178-1
Container Advisory ID | SUSE-CU-2022:2178-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.22 , bci/python:latest |
Container Release | 5.22 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:3127-1
|
Released | Wed Sep 7 04:36:10 2022 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1198752,1200800 |
Description:
This update for libtirpc fixes the following issues:
- Exclude ipv6 addresses in client protocol version 2 code (bsc#1200800)
- Fix memory leak in params.r_addr assignement (bsc#1198752)
Advisory ID | SUSE-RU-2022:3215-1
|
Released | Thu Sep 8 15:58:27 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for rpm fixes the following issues:
- Support Ed25519 RPM signatures [jsc#SLE-24714]
SUSE-CU-2022:2066-1
Container Advisory ID | SUSE-CU-2022:2066-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.18 , bci/python:latest |
Container Release | 5.18 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2929-1
|
Released | Mon Aug 29 11:21:47 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1202310 |
Description:
This update for timezone fixes the following issue:
- Reflect new Chile DST change (bsc#1202310)
Advisory ID | SUSE-SU-2022:2947-1
|
Released | Wed Aug 31 09:16:21 2022 |
Summary | Security update for zlib |
Type | security |
Severity | important |
References | 1202175,CVE-2022-37434 |
Description:
This update for zlib fixes the following issues:
- CVE-2022-37434: Fixed heap-based buffer over-read or buffer overflow via large gzip header extra field (bsc#1202175).
Advisory ID | SUSE-RU-2022:2977-1
|
Released | Thu Sep 1 12:30:19 2022 |
Summary | Recommended update for util-linux |
Type | recommended |
Severity | moderate |
References | 1197178,1198731 |
Description:
This update for util-linux fixes the following issues:
- agetty: Resolve tty name even if stdin is specified (bsc#1197178)
- libmount: When moving a mount point, update all sub mount entries in utab (bsc#1198731)
Advisory ID | SUSE-SU-2022:3003-1
|
Released | Fri Sep 2 15:01:44 2022 |
Summary | Security update for curl |
Type | security |
Severity | low |
References | 1202593,CVE-2022-35252 |
Description:
This update for curl fixes the following issues:
- CVE-2022-35252: Fixed a potential injection of control characters
into cookies, which could be exploited by sister sites to cause a
denial of service (bsc#1202593).
SUSE-CU-2022:1947-1
Container Advisory ID | SUSE-CU-2022:1947-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.10 , bci/python:latest |
Container Release | 5.10 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2920-1
|
Released | Fri Aug 26 15:17:02 2022 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | important |
References | 1195059,1201795 |
Description:
This update for systemd fixes the following issues:
- Don't replace /etc/systemd/system/tmp.mount symlink with a dangling one pointing to /usr/lib/systemd/ (bsc#1201795)
- Drop or soften some of the deprecation warnings (jsc#PED-944)
- Ensure root user can login even if systemd-user-sessions.service is not activated yet (bsc#1195059)
- Avoid applying presets to any services shipped by the experimental sub-package, as they aren't enabled by default
- analyze: Fix offline check for syscal filter
- calendarspec: Fix timer skipping the next elapse
- core: Allow command argument to be longer
- hwdb: Add AV production controllers to hwdb and add uaccess
- hwdb: Allow console users access to rfkill
- hwdb: Allow end-users root-less access to TL866 EPROM readers
- hwdb: Permit unsetting power/persist for USB devices
- hwdb: Tag IR cameras as such
- hwdb: Fix parsing issue
- hwdb: Make usb match patterns uppercase
- hwdb: Update the hardware database
- journal-file: Stop using the event loop if it's already shutting down
- journal-remote: Disable `--trust` option when gnutls is disabled and check_permission() should not be called
- journald: Ensure resources are properly allocated for SIGTERM handling
- kernel-install: Ensure modules.builtin.alias.bin is removed when no longer needed
- macro: Account for negative values in DECIMAL_STR_WIDTH()
- manager: Disallow clone3() function call in seccomp filters
- missing-syscall: Define MOVE_MOUNT_T_EMPTY_PATH if missing
- pid1,cgroup-show: Prevent failure if cgroup.procs in some subcgroups is not readable
- resolve: Fix typo in dns_class_is_pseudo()
- sd-event: Improve handling of process events and termination of processes
- sd-ipv4acd: Fix ARP packet conflicts occurring when sender hardware is one of the host's interfaces
- stdio-bridge: Improve the meaning of the error message
- tmpfiles: Check for the correct directory
SUSE-CU-2022:1946-1
Container Advisory ID | SUSE-CU-2022:1946-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.9 , bci/python:latest |
Container Release | 5.9 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2901-1
|
Released | Fri Aug 26 03:34:23 2022 |
Summary | Recommended update for elfutils |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for elfutils fixes the following issues:
- Fix runtime dependency for devel package
Advisory ID | SUSE-RU-2022:2904-1
|
Released | Fri Aug 26 05:28:34 2022 |
Summary | Recommended update for openldap2 |
Type | recommended |
Severity | moderate |
References | 1198341 |
Description:
This update for openldap2 fixes the following issues:
- Prevent memory reuse which may lead to instability (bsc#1198341)
SUSE-CU-2022:1808-1
Container Advisory ID | SUSE-CU-2022:1808-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-5.1 , bci/python:latest |
Container Release | 5.1 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2717-1
|
Released | Tue Aug 9 12:54:16 2022 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1198627,CVE-2022-29458 |
Description:
This update for ncurses fixes the following issues:
- CVE-2022-29458: Fixed segfaulting out-of-bounds read in convert_strings in tinfo/read_entry.c (bsc#1198627).
SUSE-CU-2022:1761-1
Container Advisory ID | SUSE-CU-2022:1761-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.30 , bci/python:latest |
Container Release | 4.30 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2632-1
|
Released | Wed Aug 3 09:51:00 2022 |
Summary | Security update for permissions |
Type | security |
Severity | important |
References | 1198720,1200747,1201385 |
Description:
This update for permissions fixes the following issues:
- apptainer: fix starter-suid location (bsc#1198720)
- static permissions: remove deprecated bind / named chroot entries (bsc#1200747)
- postfix: add postlog setgid for maildrop binary (bsc#1201385)
SUSE-CU-2022:1688-1
Container Advisory ID | SUSE-CU-2022:1688-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.25 , bci/python:latest |
Container Release | 4.25 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2550-1
|
Released | Tue Jul 26 14:00:21 2022 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1201431,CVE-2022-29187 |
Description:
This update for git fixes the following issues:
- CVE-2022-29187: Incomplete fix for CVE-2022-24765: potential command injection via git worktree (bsc#1201431).
Advisory ID | SUSE-SU-2022:2552-1
|
Released | Tue Jul 26 14:55:40 2022 |
Summary | Security update for libxml2 |
Type | security |
Severity | important |
References | 1196490,1199132,CVE-2022-23308,CVE-2022-29824 |
Description:
This update for libxml2 fixes the following issues:
Update to 2.9.14:
- CVE-2022-29824: Fixed integer overflow that could have led to an out-of-bounds write in buf.c (xmlBuf*) and tree.c (xmlBuffer*) (bsc#1199132).
Update to version 2.9.13:
- CVE-2022-23308: Fixed a use-after-free of ID and IDREF attributes. (bsc#1196490)
Advisory ID | SUSE-SU-2022:2566-1
|
Released | Wed Jul 27 15:04:49 2022 |
Summary | Security update for pcre2 |
Type | security |
Severity | important |
References | 1199235,CVE-2022-1587 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1587: Fixed out-of-bounds read due to bug in recursions (bsc#1199235).
SUSE-CU-2022:1645-1
Container Advisory ID | SUSE-CU-2022:1645-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.22 , bci/python:latest |
Container Release | 4.22 |
The following patches have been included in this update:
SUSE-CU-2022:1610-1
Container Advisory ID | SUSE-CU-2022:1610-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.20 , bci/python:latest |
Container Release | 4.20 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2469-1
|
Released | Thu Jul 21 04:38:31 2022 |
Summary | Recommended update for systemd |
Type | recommended |
Severity | important |
References | 1137373,1181658,1194708,1195157,1197570,1198732,1200170,1201276 |
Description:
This update for systemd fixes the following issues:
- Make {/etc,/usr/lib}/systemd/network owned by both udev and systemd-network. The configuration files put in these
directories are read by both udevd and systemd-networkd (bsc#1201276)
- Allow control characters in environment variable values (bsc#1200170)
- Fix issues with multipath setup (bsc#1137373, bsc#1181658, bsc#1194708, bsc#1195157, bsc#1197570)
- Fix parsing error in s390 udev rules conversion script (bsc#1198732)
- core/device: device_coldplug(): don't set DEVICE_DEAD
- core/device: do not downgrade device state if it is already enumerated
- core/device: drop unnecessary condition
Advisory ID | SUSE-RU-2022:2493-1
|
Released | Thu Jul 21 14:35:08 2022 |
Summary | Recommended update for rpm-config-SUSE |
Type | recommended |
Severity | moderate |
References | 1193282 |
Description:
This update for rpm-config-SUSE fixes the following issues:
- Add SBAT values macros for other packages (bsc#1193282)
Advisory ID | SUSE-RU-2022:2494-1
|
Released | Thu Jul 21 15:16:42 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | important |
References | 1200855,1201560,1201640 |
Description:
This update for glibc fixes the following issues:
- Remove tunables from static tls surplus patch which caused crashes (bsc#1200855)
- i386: Disable check_consistency for GCC 5 and above (bsc#1201640, BZ #25788)
SUSE-CU-2022:1572-1
Container Advisory ID | SUSE-CU-2022:1572-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.17 , bci/python:latest |
Container Release | 4.17 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2018:1332-1
|
Released | Tue Jul 17 09:01:19 2018 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1073299,1093392 |
Description:
This update for timezone provides the following fixes:
- North Korea switches back from +0830 to +09 on 2018-05-05.
- Ireland's standard time is in the summer, with negative DST offset to standard time used
in Winter. (bsc#1073299)
- yast2-country is no longer setting TIMEZONE in /etc/sysconfig/clock and is calling systemd
timedatectl instead. Do not set /etc/localtime on timezone package updates to avoid
setting an incorrect timezone. (bsc#1093392)
Advisory ID | SUSE-RU-2018:2463-1
|
Released | Thu Oct 25 14:48:34 2018 |
Summary | Recommended update for timezone, timezone-java |
Type | recommended |
Severity | moderate |
References | 1104700,1112310 |
Description:
This update for timezone, timezone-java fixes the following issues:
The timezone database was updated to 2018f:
- Volgograd moves from +03 to +04 on 2018-10-28.
- Fiji ends DST 2019-01-13, not 2019-01-20.
- Most of Chile changes DST dates, effective 2019-04-06 (bsc#1104700)
- Corrections to past timestamps of DST transitions
- Use 'PST' and 'PDT' for Philippine time
- minor code changes to zic handling of the TZif format
- documentation updates
Other bugfixes:
- Fixed a zic problem with the 1948-1951 DST transition in Japan (bsc#1112310)
Advisory ID | SUSE-RU-2018:2550-1
|
Released | Wed Oct 31 16:16:56 2018 |
Summary | Recommended update for timezone, timezone-java |
Type | recommended |
Severity | moderate |
References | 1113554 |
Description:
This update provides the latest time zone definitions (2018g), including the following change:
- Morocco switched from +00/+01 to permanent +01 effective 2018-10-28 (bsc#1113554)
Advisory ID | SUSE-RU-2019:102-1
|
Released | Tue Jan 15 18:02:58 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1120402 |
Description:
This update for timezone fixes the following issues:
- Update 2018i:
São Tomé and Príncipe switches from +01 to +00 on 2019-01-01. (bsc#1120402)
- Update 2018h:
Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21
New zone Asia/Qostanay because Qostanay, Kazakhstan didn't move
Metlakatla, Alaska observes PST this winter only
Guess Morocco will continue to adjust clocks around Ramadan
Add predictions for Iran from 2038 through 2090
Advisory ID | SUSE-RU-2019:790-1
|
Released | Thu Mar 28 12:06:17 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1130557 |
Description:
This update for timezone fixes the following issues:
timezone was updated 2019a:
- Palestine 'springs forward' on 2019-03-30 instead of 2019-03-23
- Metlakatla 'fell back' to rejoin Alaska Time on 2019-01-20 at 02:00
- Israel observed DST in 1980 (08-02/09-13) and 1984 (05-05/08-25)
- zic now has an -r option to limit the time range of output data
Advisory ID | SUSE-RU-2019:1815-1
|
Released | Thu Jul 11 07:47:55 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1140016 |
Description:
This update for timezone fixes the following issues:
- Timezone update 2019b. (bsc#1140016):
- Brazil no longer observes DST.
- 'zic -b slim' outputs smaller TZif files.
- Palestine's 2019 spring-forward transition was on 03-29, not 03-30.
- Add info about the Crimea situation.
Advisory ID | SUSE-RU-2019:2762-1
|
Released | Thu Oct 24 07:08:44 2019 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1150451 |
Description:
This update for timezone fixes the following issues:
- Fiji observes DST from 2019-11-10 to 2020-01-12.
- Norfolk Island starts observing Australian-style DST.
Advisory ID | SUSE-RU-2020:1303-1
|
Released | Mon May 18 09:40:36 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1169582 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020a. (bsc#1169582)
* Morocco springs forward on 2020-05-31, not 2020-05-24.
* Canada's Yukon advanced to -07 year-round on 2020-03-08.
* America/Nuuk renamed from America/Godthab.
* zic now supports expiration dates for leap second lists.
Advisory ID | SUSE-RU-2020:1542-1
|
Released | Thu Jun 4 13:24:37 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1172055 |
Description:
This update for timezone fixes the following issue:
- zdump --version reported 'unknown' (bsc#1172055)
Advisory ID | SUSE-RU-2020:3099-1
|
Released | Thu Oct 29 19:33:41 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020b (bsc#1177460)
* Revised predictions for Morocco's changes starting in 2023.
* Canada's Yukon changes to -07 on 2020-11-01, not 2020-03-08.
* Macquarie Island has stayed in sync with Tasmania since 2011.
* Casey, Antarctica is at +08 in winter and +11 in summer.
* zic no longer supports -y, nor the TYPE field of Rules.
Advisory ID | SUSE-RU-2020:3123-1
|
Released | Tue Nov 3 09:48:13 2020 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | important |
References | 1177460,1178346,1178350,1178353 |
Description:
This update for timezone fixes the following issues:
- Generate 'fat' timezone files (was default before 2020b). (bsc#1178346, bsc#1178350, bsc#1178353)
- Palestine ends DST earlier than predicted, on 2020-10-24. (bsc#1177460)
- Fiji starts DST later than usual, on 2020-12-20. (bsc#1177460)
Advisory ID | SUSE-RU-2021:179-1
|
Released | Wed Jan 20 13:38:51 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
- timezone update 2020f (bsc#1177460)
* 'make rearguard_tarballs' no longer generates a bad rearguard.zi,
fixing a 2020e bug.
- timezone update 2020e (bsc#1177460)
* Volgograd switches to Moscow time on 2020-12-27 at 02:00.
Advisory ID | SUSE-RU-2021:301-1
|
Released | Thu Feb 4 08:46:27 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
- timezone update 2021a (bsc#1177460)
* South Sudan changes from +03 to +02 on 2021-02-01 at 00:00.
Advisory ID | SUSE-RU-2021:2573-1
|
Released | Thu Jul 29 14:21:52 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1188127 |
Description:
This update for timezone fixes the following issue:
- From systemd v249: when enumerating time zones the timedatectl tool will now consult the 'tzdata.zi' file shipped by
the IANA time zone database package, in addition to 'zone1970.tab', as before. This makes sure time zone aliases are
now correctly supported. This update adds the 'tzdata.zi' file (bsc#1188127).
Advisory ID | SUSE-RU-2021:3883-1
|
Released | Thu Dec 2 11:47:07 2021 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
Update timezone to 2021e (bsc#1177460)
- Palestine will fall back 10-29 (not 10-30) at 01:00
- Fiji suspends DST for the 2021/2022 season
- 'zic -r' marks unspecified timestamps with '-00'
- Fix a bug in 'zic -b fat' that caused old timestamps to be mishandled in 32-bit-only readers
- Refresh timezone info for china
Advisory ID | SUSE-RU-2022:1118-1
|
Released | Tue Apr 5 18:34:06 2022 |
Summary | Recommended update for timezone |
Type | recommended |
Severity | moderate |
References | 1177460 |
Description:
This update for timezone fixes the following issues:
- timezone update 2022a (bsc#1177460):
* Palestine will spring forward on 2022-03-27, not on 03-26
* `zdump -v` now outputs better failure indications
* Bug fixes for code that reads corrupted TZif data
SUSE-CU-2022:1553-1
Container Advisory ID | SUSE-CU-2022:1553-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.16 , bci/python:latest |
Container Release | 4.16 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2022:2406-1
|
Released | Fri Jul 15 11:49:01 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1197718,1199140,1200334,1200855 |
Description:
This update for glibc fixes the following issues:
- powerpc: Fix VSX register number on __strncpy_power9 (bsc#1200334)
- Disable warnings due to deprecated libselinux symbols used by nss and nscd (bsc#1197718)
- i386: Remove broken CAN_USE_REGISTER_ASM_EBP (bsc#1197718)
- rtld: Avoid using up static TLS surplus for optimizations (bsc#1200855, BZ #25051)
This readds the s390 32bit glibc and libcrypt1 libraries (glibc-32bit, glibc-locale-base-32bit, libcrypt1-32bit).
SUSE-CU-2022:1497-1
Container Advisory ID | SUSE-CU-2022:1497-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.13 , bci/python:latest |
Container Release | 4.13 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2360-1
|
Released | Tue Jul 12 12:01:39 2022 |
Summary | Security update for pcre2 |
Type | security |
Severity | important |
References | 1199232,CVE-2022-1586 |
Description:
This update for pcre2 fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
Advisory ID | SUSE-SU-2022:2361-1
|
Released | Tue Jul 12 12:05:01 2022 |
Summary | Security update for pcre |
Type | security |
Severity | important |
References | 1199232,CVE-2022-1586 |
Description:
This update for pcre fixes the following issues:
- CVE-2022-1586: Fixed unicode property matching issue. (bsc#1199232)
SUSE-CU-2022:1496-1
Container Advisory ID | SUSE-CU-2022:1496-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.12 , bci/python:latest |
Container Release | 4.12 |
The following patches have been included in this update:
SUSE-CU-2022:1435-1
Container Advisory ID | SUSE-CU-2022:1435-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.10 , bci/python:latest |
Container Release | 4.10 |
The following patches have been included in this update:
Advisory ID | SUSE-SU-2022:2291-1
|
Released | Wed Jul 6 13:04:37 2022 |
Summary | Security update for python310 |
Type | security |
Severity | important |
References | 1198511,CVE-2015-20107 |
Description:
This update for python310 fixes the following issues:
- CVE-2015-20107: avoid command injection in the mailcap module (bsc#1198511).
- Update to 3.10.5:
- Core and Builtins
- gh-93418: Fixed an assert where an f-string has an equal
sign '=' following an expression, but there's no trailing
brace. For example, f'{i='.
- gh-91924: Fix __ltrace__ debug feature if the stdout
encoding is not UTF-8. Patch by Victor Stinner.
- gh-93061: Backward jumps after async for loops are no
longer given dubious line numbers.
- gh-93065: Fix contextvars HAMT implementation to handle
iteration over deep trees.
- The bug was discovered and fixed by Eli Libman. See
MagicStack/immutables#84 for more details.
- gh-92311: Fixed a bug where setting frame.f_lineno to jump
over a list comprehension could misbehave or crash.
- gh-92112: Fix crash triggered by an evil custom mro() on
a metaclass.
- gh-92036: Fix a crash in subinterpreters related to the
garbage collector. When a subinterpreter is deleted,
untrack all objects tracked by its GC. To prevent a crash
in deallocator functions expecting objects to be tracked by
the GC, leak a strong reference to these objects on
purpose, so they are never deleted and their deallocator
functions are not called. Patch by Victor Stinner.
- gh-91421: Fix a potential integer overflow in
_Py_DecodeUTF8Ex.
- bpo-47212: Raise IndentationError instead of SyntaxError
for a bare except with no following indent. Improve
SyntaxError locations for an un-parenthesized generator
used as arguments. Patch by Matthieu Dartiailh.
- bpo-47182: Fix a crash when using a named unicode character
like '\N{digit nine}' after the main interpreter has been
initialized a second time.
- bpo-47117: Fix a crash if we fail to decode characters in
interactive mode if the tokenizer buffers are
uninitialized. Patch by Pablo Galindo.
- bpo-39829: Removed the __len__() call when initializing
a list and moved initializing to list_extend. Patch by
Jeremiah Pascual.
- bpo-46962: Classes and functions that unconditionally
declared their docstrings ignoring the
--without-doc-strings compilation flag no longer do so.
- The classes affected are ctypes.UnionType,
pickle.PickleBuffer, testcapi.RecursingInfinitelyError, and
types.GenericAlias.
- The functions affected are 24 methods in ctypes.
- Patch by Oleg Iarygin.
- bpo-36819: Fix crashes in built-in encoders with error
handlers that return position less or equal than the
starting position of non-encodable characters.
- Library
- gh-93156: Accessing the pathlib.PurePath.parents sequence
of an absolute path using negative index values produced
incorrect results.
- gh-89973: Fix re.error raised in fnmatch if the pattern
contains a character range with upper bound lower than
lower bound (e.g. [c-a]). Now such ranges are interpreted
as empty ranges.
- gh-93010: In a very special case, the email package tried
to append the nonexistent InvalidHeaderError to the defect
list. It should have been InvalidHeaderDefect.
- gh-92839: Fixed crash resulting from calling
bisect.insort() or bisect.insort_left() with the key
argument not equal to None.
- gh-91581: utcfromtimestamp() no longer attempts to resolve
fold in the pure Python implementation, since the fold is
never 1 in UTC. In addition to being slightly faster in the
common case, this also prevents some errors when the
timestamp is close to datetime.min. Patch by Paul Ganssle.
- gh-92530: Fix an issue that occurred after interrupting
threading.Condition.notify().
- gh-92049: Forbid pickling constants re._constants.SUCCESS
etc. Previously, pickling did not fail, but the result
could not be unpickled.
- bpo-47029: Always close the read end of the pipe used by
multiprocessing.Queue after the last write of buffered data
to the write end of the pipe to avoid BrokenPipeError at
garbage collection and at multiprocessing.Queue.close()
calls. Patch by Géry Ogam.
- gh-91401: Provide a fail-safe way to disable subprocess use
of vfork() via a private subprocess._USE_VFORK attribute.
While there is currently no known need for this, if you
find a need please only set it to False. File a CPython
issue as to why you needed it and link to that from
a comment in your code. This attribute is documented as
a footnote in 3.11.
- gh-91910: Add missing f prefix to f-strings in error
messages from the multiprocessing and asyncio modules.
- gh-91810: ElementTree method write() and function
tostring() now use the text file's encoding ('UTF-8' if not
available) instead of locale encoding in XML declaration
when encoding='unicode' is specified.
- gh-91832: Add required attribute to argparse.Action repr
output.
- gh-91700: Compilation of regular expression containing
a conditional expression (?(group)...) now raises an
appropriate re.error if the group number refers to not
defined group. Previously an internal RuntimeError was
raised.
- gh-91676: Fix unittest.IsolatedAsyncioTestCase to shutdown
the per test event loop executor before returning from its
run method so that a not yet stopped or garbage collected
executor state does not persist beyond the test.
- gh-90568: Parsing \N escapes of Unicode Named Character
Sequences in a regular expression raises now re.error
instead of TypeError.
- gh-91595: Fix the comparison of character and integer
inside Tools.gdb.libpython.write_repr(). Patch by Yu Liu.
- gh-90622: Worker processes for
concurrent.futures.ProcessPoolExecutor are no longer
spawned on demand (a feature added in 3.9) when the
multiprocessing context start method is 'fork' as that can
lead to deadlocks in the child processes due to a fork
happening while threads are running.
- gh-91575: Update case-insensitive matching in the re module
to the latest Unicode version.
- gh-91581: Remove an unhandled error case in the
C implementation of calls to datetime.fromtimestamp with no
time zone (i.e. getting a local time from an epoch
timestamp). This should have no user-facing effect other
than giving a possibly more accurate error message when
called with timestamps that fall on 10000-01-01 in the
local time. Patch by Paul Ganssle.
- bpo-47260: Fix os.closerange() potentially being a no-op in
a Linux seccomp sandbox.
- bpo-39064: zipfile.ZipFile now raises zipfile.BadZipFile
instead of ValueError when reading a corrupt zip file in
which the central directory offset is negative.
- bpo-47151: When subprocess tries to use vfork, it now falls
back to fork if vfork returns an error. This allows use in
situations where vfork isn't allowed by the OS kernel.
- bpo-27929: Fix asyncio.loop.sock_connect() to only resolve
names for socket.AF_INET or socket.AF_INET6 families.
Resolution may not make sense for other families, like
socket.AF_BLUETOOTH and socket.AF_UNIX.
- bpo-43323: Fix errors in the email module if the charset
itself contains undecodable/unencodable characters.
- bpo-47101: hashlib.algorithms_available now lists only
algorithms that are provided by activated crypto providers
on OpenSSL 3.0. Legacy algorithms are not listed unless the
legacy provider has been loaded into the default OSSL
context.
- bpo-46787: Fix concurrent.futures.ProcessPoolExecutor
exception memory leak
- bpo-45393: Fix the formatting for await x and not x in the
operator precedence table when using the help() system.
- bpo-46415: Fix ipaddress.ip_{address,interface,network}
raising TypeError instead of ValueError if given invalid
tuple as address parameter.
- bpo-28249: Set doctest.DocTest.lineno to None when object
does not have __doc__.
- bpo-45138: Fix a regression in the sqlite3 trace callback
where bound parameters were not expanded in the passed
statement string. The regression was introduced in Python
3.10 by bpo-40318. Patch by Erlend E. Aasland.
- bpo-44493: Add missing terminated NUL in sockaddr_un's
length
- This was potentially observable when using non-abstract
AF_UNIX datagram sockets to processes written in another
programming language.
- bpo-42627: Fix incorrect parsing of Windows registry proxy
settings
- bpo-36073: Raise ProgrammingError instead of segfaulting on
recursive usage of cursors in sqlite3 converters. Patch by
Sergey Fedoseev.
- Documentation
- gh-86438: Clarify that -W and PYTHONWARNINGS are matched
literally and case-insensitively, rather than as regular
expressions, in warnings.
- gh-92240: Added release dates for 'What's New in Python
3.X' for 3.0, 3.1, 3.2, 3.8 and 3.10
- gh-91888: Add a new gh role to the documentation to link to
GitHub issues.
- gh-91783: Document security issues concerning the use of
the function shutil.unpack_archive()
- gh-91547: Remove 'Undocumented modules' page.
- bpo-44347: Clarify the meaning of dirs_exist_ok, a kwarg of
shutil.copytree().
- bpo-38668: Update the introduction to documentation for
os.path to remove warnings that became irrelevant after the
implementations of PEP 383 and PEP 529.
- bpo-47138: Pin Jinja to a version compatible with Sphinx
version 3.2.1.
- bpo-46962: All docstrings in code snippets are now wrapped
into PyDoc_STR() to follow the guideline of PEP 7's
Documentation Strings paragraph. Patch by Oleg Iarygin.
- bpo-26792: Improve the docstrings of runpy.run_module() and
runpy.run_path(). Original patch by Andrew Brezovsky.
- bpo-40838: Document that inspect.getdoc(),
inspect.getmodule(), and inspect.getsourcefile() might
return None.
- bpo-45790: Adjust inaccurate phrasing in Defining Extension
Types: Tutorial about the ob_base field and the macros used
to access its contents.
- bpo-42340: Document that in some circumstances
KeyboardInterrupt may cause the code to enter an
inconsistent state. Provided a sample workaround to avoid
it if needed.
- bpo-41233: Link the errnos referenced in
Doc/library/exceptions.rst to their respective section in
Doc/library/errno.rst, and vice versa. Previously this was
only done for EINTR and InterruptedError. Patch by Yan
'yyyyyyyan' Orestes.
- bpo-38056: Overhaul the Error Handlers documentation in
codecs.
- bpo-13553: Document tkinter.Tk args.
- Tests
- gh-92886: Fixing tests that fail when running with
optimizations (-O) in test_imaplib.py.
- gh-92670: Skip
test_shutil.TestCopy.test_copyfile_nonexistent_dir test on
AIX as the test uses a trailing slash to force the OS
consider the path as a directory, but on AIX the trailing
slash has no effect and is considered as a file.
- gh-91904: Fix initialization of
PYTHONREGRTEST_UNICODE_GUARD which prevented running
regression tests on non-UTF-8 locale.
- gh-91607: Fix test_concurrent_futures to test the correct
multiprocessing start method context in several cases where
the test logic mixed this up.
- bpo-47205: Skip test for sched_getaffinity() and
sched_setaffinity() error case on FreeBSD.
- bpo-47104: Rewrite asyncio.to_thread() tests to use
unittest.IsolatedAsyncioTestCase.
- bpo-29890: Add tests for ipaddress.IPv4Interface and
ipaddress.IPv6Interface construction with tuple arguments.
Original patch and tests by louisom.
- Tools/Demos
- gh-91583: Fix regression in the code generated by Argument
Clinic for functions with the defining_class parameter.
- Update to 3.10.4:
- bpo-46968: Check for the existence of the 'sys/auxv.h' header
in faulthandler to avoid compilation problems in systems
where this header doesn't exist. Patch by Pablo Galindo
- bpo-23691: Protect the re.finditer() iterator from
re-entering.
- bpo-42369: Fix thread safety of zipfile._SharedFile.tell() to
avoid a 'zipfile.BadZipFile: Bad CRC-32 for file' exception
when reading a ZipFile from multiple threads.
- bpo-38256: Fix binascii.crc32() when it is compiled to use
zlib'c crc32 to work properly on inputs 4+GiB in length
instead of returning the wrong result. The workaround prior
to this was to always feed the function data in increments
smaller than 4GiB or to just call the zlib module function.
- bpo-39394: A warning about inline flags not at the start of
the regular expression now contains the position of the flag.
- bpo-47061: Deprecate the various modules listed by PEP 594:
- aifc, asynchat, asyncore, audioop, cgi, cgitb, chunk, crypt,
imghdr, msilib, nntplib, nis, ossaudiodev, pipes, smtpd,
sndhdr, spwd, sunau, telnetlib, uu, xdrlib
- bpo-2604: Fix bug where doctests using globals would fail
when run multiple times.
- bpo-45997: Fix asyncio.Semaphore re-aquiring FIFO order.
- bpo-47022: The asynchat, asyncore and smtpd modules have been
deprecated since at least Python 3.6. Their documentation and
deprecation warnings and have now been updated to note they
will removed in Python 3.12 (PEP 594).
- bpo-46421: Fix a unittest issue where if the command was
invoked as python -m unittest and the filename(s) began with
a dot (.), a ValueError is returned.
- bpo-40296: Fix supporting generic aliases in pydoc.
- Update to 3.10.3:
- bpo-46940: Avoid overriding AttributeError metadata
information for nested attribute access calls. Patch by Pablo
Galindo.
- bpo-46852: Rename the private undocumented
float.__set_format__() method to float.__setformat__() to fix
a typo introduced in Python 3.7. The method is only used by
test_float. Patch by Victor Stinner.
- bpo-46794: Bump up the libexpat version into 2.4.6
- bpo-46820: Fix parsing a numeric literal immediately (without
spaces) followed by 'not in' keywords, like in 1not in x. Now
the parser only emits a warning, not a syntax error.
- bpo-46762: Fix an assert failure in debug builds when a '<',
'>', or '=' is the last character in an f-string that's
missing a closing right brace.
- bpo-46724: Make sure that all backwards jumps use the
JUMP_ABSOLUTE instruction, rather than JUMP_FORWARD with an
argument of (2**32)+offset.
- bpo-46732: Correct the docstring for the __bool__() method.
Patch by Jelle Zijlstra.
- bpo-46707: Avoid potential exponential backtracking when
producing some syntax errors involving lots of brackets.
Patch by Pablo Galindo.
- bpo-40479: Add a missing call to va_end() in
Modules/_hashopenssl.c.
- bpo-46615: When iterating over sets internally in
setobject.c, acquire strong references to the resulting items
from the set. This prevents crashes in corner-cases of
various set operations where the set gets mutated.
- bpo-45773: Remove two invalid 'peephole' optimizations from
the bytecode compiler.
- bpo-43721: Fix docstrings of getter, setter, and deleter to
clarify that they create a new copy of the property.
- bpo-46503: Fix an assert when parsing some invalid N escape
sequences in f-strings.
- bpo-46417: Fix a race condition on setting a type __bases__
attribute: the internal function add_subclass() now gets the
PyTypeObject.tp_subclasses member after calling
PyWeakref_NewRef() which can trigger a garbage collection
which can indirectly modify PyTypeObject.tp_subclasses. Patch
by Victor Stinner.
- bpo-46383: Fix invalid signature of _zoneinfo's module_free
function to resolve a crash on wasm32-emscripten platform.
- bpo-46070: Py_EndInterpreter() now explicitly untracks all
objects currently tracked by the GC. Previously, if an object
was used later by another interpreter, calling
PyObject_GC_UnTrack() on the object crashed if the previous
or the next object of the PyGC_Head structure became
a dangling pointer. Patch by Victor Stinner.
- bpo-46339: Fix a crash in the parser when retrieving the
error text for multi-line f-strings expressions that do not
start in the first line of the string. Patch by Pablo Galindo
- bpo-46240: Correct the error message for unclosed parentheses
when the tokenizer doesn't reach the end of the source when
the error is reported. Patch by Pablo Galindo
- bpo-46091: Correctly calculate indentation levels for lines
with whitespace character that are ended by line continuation
characters. Patch by Pablo Galindo
- bpo-43253: Fix a crash when closing transports where the
underlying socket handle is already invalid on the Proactor
event loop.
- bpo-47004: Apply bugfixes from importlib_metadata 4.11.3,
including bugfix for EntryPoint.extras, which was returning
match objects and not the extras strings.
- bpo-46985: Upgrade pip wheel bundled with ensurepip (pip
22.0.4)
- bpo-46968: faulthandler: On Linux 5.14 and newer, dynamically
determine size of signal handler stack size CPython allocates
using getauxval(AT_MINSIGSTKSZ). This changes allows for
Python extension's request to Linux kernel to use AMX_TILE
instruction set on Sapphire Rapids Xeon processor to succeed,
unblocking use of the ISA in frameworks.
- bpo-46955: Expose asyncio.base_events.Server as
asyncio.Server. Patch by Stefan Zabka.
- bpo-23325: The signal module no longer assumes that SIG_IGN
and SIG_DFL are small int singletons.
- bpo-46932: Update bundled libexpat to 2.4.7
- bpo-25707: Fixed a file leak in
xml.etree.ElementTree.iterparse() when the iterator is not
exhausted. Patch by Jacob Walls.
- bpo-44886: Inherit asyncio proactor datagram transport from
asyncio.DatagramTransport.
- bpo-46827: Support UDP sockets in asyncio.loop.sock_connect()
for selector-based event loops. Patch by Thomas Grainger.
- bpo-46811: Make test suite support Expat >=2.4.5
- bpo-46252: Raise TypeError if ssl.SSLSocket is passed to
transport-based APIs.
- bpo-46784: Fix libexpat symbols collisions with user
dynamically loaded or statically linked libexpat in embedded
Python.
- bpo-39327: shutil.rmtree() can now work with VirtualBox
shared folders when running from the guest operating-system.
- bpo-46756: Fix a bug in
urllib.request.HTTPPasswordMgr.find_user_password() and
urllib.request.HTTPPasswordMgrWithPriorAuth.is_authenticated()
which allowed to bypass authorization. For example, access to
URI example.org/foobar was allowed if the user was authorized
for URI example.org/foo.
- bpo-46643: In typing.get_type_hints(), support evaluating
stringified ParamSpecArgs and ParamSpecKwargs annotations.
Patch by Gregory Beauregard.
- bpo-45863: When the tarfile module creates a pax format
archive, it will put an integer representation of timestamps
in the ustar header (if possible) for the benefit of older
unarchivers, in addition to the existing full-precision
timestamps in the pax extended header.
- bpo-46676: Make typing.ParamSpec args and kwargs equal to
themselves. Patch by Gregory Beauregard.
- bpo-46672: Fix NameError in asyncio.gather() when initial
type check fails.
- bpo-46655: In typing.get_type_hints(), support evaluating
bare stringified TypeAlias annotations. Patch by Gregory
Beauregard.
- bpo-45948: Fixed a discrepancy in the C implementation of the
xml.etree.ElementTree module. Now, instantiating an
xml.etree.ElementTree.XMLParser with a target=None keyword
provides a default xml.etree.ElementTree.TreeBuilder target
as the Python implementation does.
- bpo-46521: Fix a bug in the codeop module that was
incorrectly identifying invalid code involving string quotes
as valid code.
- bpo-46581: Brings ParamSpec propagation for GenericAlias in
line with Concatenate (and others).
- bpo-46591: Make the IDLE doc URL on the About IDLE dialog
clickable.
- bpo-46400: expat: Update libexpat from 2.4.1 to 2.4.4
- bpo-46487: Add the get_write_buffer_limits method to
asyncio.transports.WriteTransport and to the SSL transport.
- bpo-45173: Note the configparser deprecations will be removed
in Python 3.12.
- bpo-46539: In typing.get_type_hints(), support evaluating
stringified ClassVar and Final annotations inside Annotated.
Patch by Gregory Beauregard.
- bpo-46491: Allow typing.Annotated to wrap typing.Final and
typing.ClassVar. Patch by Gregory Beauregard.
- bpo-46436: Fix command-line option -d/--directory in module
http.server which is ignored when combined with command-line
option --cgi. Patch by Géry Ogam.
- bpo-41403: Make mock.patch() raise a TypeError with
a relevant error message on invalid arg. Previously it
allowed a cryptic AttributeError to escape.
- bpo-46474: In importlib.metadata.EntryPoint.pattern, avoid
potential REDoS by limiting ambiguity in consecutive
whitespace.
- bpo-46469: asyncio generic classes now return
types.GenericAlias in __class_getitem__ instead of the same
class.
- bpo-46434: pdb now gracefully handles help when __doc__ is
missing, for example when run with pregenerated optimized
.pyc files.
- bpo-46333: The __eq__() and __hash__() methods of
typing.ForwardRef now honor the module parameter of
typing.ForwardRef. Forward references from different modules
are now differentiated.
- bpo-46246: Add missing __slots__ to
importlib.metadata.DeprecatedList. Patch by Arie Bovenberg.
- bpo-46266: Improve day constants in calendar.
- Now all constants (MONDAY ... SUNDAY) are documented, tested,
and added to __all__.
- bpo-46232: The ssl module now handles certificates with bit
strings in DN correctly.
- bpo-43118: Fix a bug in inspect.signature() that was causing
it to fail on some subclasses of classes with
a __text_signature__ referencing module globals. Patch by
Weipeng Hong.
- bpo-26552: Fixed case where failing asyncio.ensure_future()
did not close the coroutine. Patch by Kumar Aditya.
- bpo-21987: Fix an issue with tarfile.TarFile.getmember()
getting a directory name with a trailing slash.
- bpo-20392: Fix inconsistency with uppercase file extensions
in MimeTypes.guess_type(). Patch by Kumar Aditya.
- bpo-46080: Fix exception in argparse help text generation if
a argparse.BooleanOptionalAction argument's default is
argparse.SUPPRESS and it has help specified. Patch by Felix
Fontein.
- bpo-44439: Fix .write() method of a member file in ZipFile,
when the input data is an object that supports the buffer
protocol, the file length may be wrong.
- bpo-45703: When a namespace package is imported before
another module from the same namespace is created/installed
in a different sys.path location while the program is
running, calling the importlib.invalidate_caches() function
will now also guarantee the new module is noticed.
- bpo-24959: Fix bug where unittest sometimes drops frames from
tracebacks of exceptions raised in tests.
- bpo-44791: Fix substitution of ParamSpec in Concatenate with
different parameter expressions. Substitution with a list of
types returns now a tuple of types. Substitution with
Concatenate returns now a Concatenate with concatenated lists
of arguments.
- bpo-14156: argparse.FileType now supports an argument of '-'
in binary mode, returning the .buffer attribute of
sys.stdin/sys.stdout as appropriate. Modes including 'x' and
'a' are treated equivalently to 'w' when argument is '-'.
Patch contributed by Josh Rosenberg
- bpo-46463: Fixes escape4chm.py script used when building the
CHM documentation file
- bpo-46913: Fix test_faulthandler.test_sigfpe() if Python is
built with undefined behavior sanitizer (UBSAN): disable
UBSAN on the faulthandler_sigfpe() function. Patch by Victor
Stinner.
- bpo-46708: Prevent default asyncio event loop policy
modification warning after test_asyncio execution.
- bpo-46678: The function make_legacy_pyc in
Lib/test/support/import_helper.py no longer fails when
PYTHONPYCACHEPREFIX is set to a directory on a different
device from where tempfiles are stored.
- bpo-46616: Ensures test_importlib.test_windows cleans up
registry keys after completion.
- bpo-44359: test_ftplib now silently ignores socket errors to
prevent logging unhandled threading exceptions. Patch by
Victor Stinner.
- bpo-46542: Fix a Python crash in test_lib2to3 when using
Python built in debug mode: limit the recursion limit. Patch
by Victor Stinner.
- bpo-46576: test_peg_generator now disables compiler
optimization when testing compilation of its own C extensions
to significantly speed up the testing on non-debug builds of
CPython.
- bpo-46542: Fix test_json tests checking for RecursionError:
modify these tests to use support.infinite_recursion(). Patch
by Victor Stinner.
- bpo-13886: Skip test_builtin PTY tests on non-ASCII
characters if the readline module is loaded. The readline
module changes input() behavior, but test_builtin is not
intented to test the readline module. Patch by Victor
Stinner.
- bpo-38472: Fix GCC detection in setup.py when
cross-compiling. The C compiler is now run with LC_ALL=C.
Previously, the detection failed with a German locale.
- bpo-46513: configure no longer uses AC_C_CHAR_UNSIGNED macro
and pyconfig.h no longer defines reserved symbol
__CHAR_UNSIGNED__.
- bpo-45296: Clarify close, quit, and exit in IDLE. In the File
menu, 'Close' and 'Exit' are now 'Close Window' (the current
one) and 'Exit' is now 'Exit IDLE' (by closing all windows).
In Shell, 'quit()' and 'exit()' mean 'close Shell'. If there
are no other windows, this also exits IDLE.
- bpo-45447: Apply IDLE syntax highlighting to pyi files. Patch
by Alex Waygood and Terry Jan Reedy.
- bpo-46433: The internal function _PyType_GetModuleByDef now
correctly handles inheritance patterns involving static
types.
- bpo-14916: Fixed bug in the tokenizer that prevented
PyRun_InteractiveOne from parsing from the provided FD.
Advisory ID | SUSE-SU-2022:2294-1
|
Released | Wed Jul 6 13:34:15 2022 |
Summary | Security update for expat |
Type | security |
Severity | important |
References | 1196025,1196026,1196168,1196169,1196171,1196784,CVE-2022-25235,CVE-2022-25236,CVE-2022-25313,CVE-2022-25314,CVE-2022-25315 |
Description:
This update for expat fixes the following issues:
- CVE-2022-25236: Fixed possible namespace-separator characters insertion into namespace URIs (bsc#1196025).
- Fixed a regression caused by the patch for CVE-2022-25236 (bsc#1196784).
- CVE-2022-25235: Fixed UTF-8 character validation in a certain context (bsc#1196026).
- CVE-2022-25313: Fixed stack exhaustion in build_model() via uncontrolled recursion (bsc#1196168).
- CVE-2022-25314: Fixed integer overflow in copyString (bsc#1196169).
- CVE-2022-25315: Fixed integer overflow in storeRawNames (bsc#1196171).
Advisory ID | SUSE-SU-2022:2305-1
|
Released | Wed Jul 6 13:38:42 2022 |
Summary | Security update for curl |
Type | security |
Severity | important |
References | 1200734,1200735,1200736,1200737,CVE-2022-32205,CVE-2022-32206,CVE-2022-32207,CVE-2022-32208 |
Description:
This update for curl fixes the following issues:
- CVE-2022-32205: Set-Cookie denial of service (bsc#1200734)
- CVE-2022-32206: HTTP compression denial of service (bsc#1200735)
- CVE-2022-32207: Unpreserved file permissions (bsc#1200736)
- CVE-2022-32208: FTP-KRB bad message verification (bsc#1200737)
Advisory ID | SUSE-SU-2022:2308-1
|
Released | Wed Jul 6 14:15:13 2022 |
Summary | Security update for openssl-1_1 |
Type | security |
Severity | important |
References | 1185637,1199166,1200550,1201099,CVE-2022-1292,CVE-2022-2068,CVE-2022-2097 |
Description:
This update for openssl-1_1 fixes the following issues:
- CVE-2022-1292: Fixed command injection in c_rehash (bsc#1199166).
- CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550)
- CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099).
SUSE-CU-2022:1369-1
Container Advisory ID | SUSE-CU-2022:1369-1 |
Container Tags | bci/python:3 , bci/python:3.10 , bci/python:3.10-4.3 , bci/python:latest |
Container Release | 4.3 |
The following patches have been included in this update:
Advisory ID | SUSE-RU-2018:1999-1
|
Released | Tue Sep 25 08:20:35 2018 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1071321 |
Description:
This update for zlib provides the following fixes:
- Speedup zlib on power8. (fate#325307)
- Add safeguard against negative values in uInt. (bsc#1071321)
Advisory ID | SUSE-RU-2018:2370-1
|
Released | Mon Oct 22 14:02:01 2018 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1102310,1104531 |
Description:
This update for aaa_base provides the following fixes:
- Let bash.bashrc work even for (m)ksh. (bsc#1104531)
- Fix an error at login if java system directory is empty. (bsc#1102310)
Advisory ID | SUSE-RU-2018:2569-1
|
Released | Fri Nov 2 19:00:18 2018 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1110700 |
Description:
This update for pam fixes the following issues:
- Remove limits for nproc from /etc/security/limits.conf (bsc#1110700)
Advisory ID | SUSE-RU-2018:2607-1
|
Released | Wed Nov 7 15:42:48 2018 |
Summary | Optional update for gcc8 |
Type | recommended |
Severity | low |
References | 1084812,1084842,1087550,1094222,1102564 |
Description:
The GNU Compiler GCC 8 is being added to the Development Tools Module by this
update.
The update also supplies gcc8 compatible libstdc++, libgcc_s1 and other
gcc derived libraries for the Basesystem module of SUSE Linux Enterprise 15.
Various optimizers have been improved in GCC 8, several of bugs fixed,
quite some new warnings added and the error pin-pointing and
fix-suggestions have been greatly improved.
The GNU Compiler page for GCC 8 contains a summary of all the changes that
have happened:
https://gcc.gnu.org/gcc-8/changes.html
Also changes needed or common pitfalls when porting software are described on:
https://gcc.gnu.org/gcc-8/porting_to.html
Advisory ID | SUSE-SU-2018:2825-1
|
Released | Mon Dec 3 15:35:02 2018 |
Summary | Security update for pam |
Type | security |
Severity | important |
References | 1115640,CVE-2018-17953 |
Description:
This update for pam fixes the following issue:
Security issue fixed:
- CVE-2018-17953: Fixed IP address and subnet handling of pam_access.so that was not honoured correctly when a single host was specified (bsc#1115640).
Advisory ID | SUSE-SU-2018:2861-1
|
Released | Thu Dec 6 14:32:01 2018 |
Summary | Security update for ncurses |
Type | security |
Severity | important |
References | 1103320,1115929,CVE-2018-19211 |
Description:
This update for ncurses fixes the following issues:
Security issue fixed:
- CVE-2018-19211: Fixed denial of service issue that was triggered by a NULL pointer dereference at function _nc_parse_entry (bsc#1115929).
Non-security issue fixed:
- Remove scree.xterm from terminfo data base as with this screen uses fallback TERM=screen (bsc#1103320).
Advisory ID | SUSE-RU-2019:44-1
|
Released | Tue Jan 8 13:07:32 2019 |
Summary | Recommended update for acl |
Type | recommended |
Severity | low |
References | 953659 |
Description:
This update for acl fixes the following issues:
- test: Add helper library to fake passwd/group files.
- quote: Escape literal backslashes. (bsc#953659)
Advisory ID | SUSE-SU-2019:247-1
|
Released | Wed Feb 6 07:18:45 2019 |
Summary | Security update for lua53 |
Type | security |
Severity | moderate |
References | 1123043,CVE-2019-6706 |
Description:
This update for lua53 fixes the following issues:
Security issue fixed:
- CVE-2019-6706: Fixed a use-after-free bug in the lua_upvaluejoin function of lapi.c (bsc#1123043)
Advisory ID | SUSE-SU-2019:571-1
|
Released | Thu Mar 7 18:13:46 2019 |
Summary | Security update for file |
Type | security |
Severity | moderate |
References | 1096974,1096984,1126117,1126118,1126119,CVE-2018-10360,CVE-2019-8905,CVE-2019-8906,CVE-2019-8907 |
Description:
This update for file fixes the following issues:
The following security vulnerabilities were addressed:
- CVE-2018-10360: Fixed an out-of-bounds read in the function do_core_note in
readelf.c, which allowed remote attackers to cause a denial of service
(application crash) via a crafted ELF file (bsc#1096974)
- CVE-2019-8905: Fixed a stack-based buffer over-read in do_core_note in readelf.c
(bsc#1126118)
- CVE-2019-8906: Fixed an out-of-bounds read in do_core_note in readelf. c
(bsc#1126119)
- CVE-2019-8907: Fixed a stack corruption in do_core_note in readelf.c
(bsc#1126117)
Advisory ID | SUSE-RU-2019:732-1
|
Released | Mon Mar 25 14:10:04 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1088524,1118364,1128246 |
Description:
This update for aaa_base fixes the following issues:
- Restore old position of ssh/sudo source of profile (bsc#1118364).
- Update logic for JRE_HOME env variable (bsc#1128246)
Advisory ID | SUSE-SU-2019:788-1
|
Released | Thu Mar 28 11:55:06 2019 |
Summary | Security update for sqlite3 |
Type | security |
Severity | moderate |
References | 1119687,CVE-2018-20346 |
Description:
This update for sqlite3 to version 3.27.2 fixes the following issue:
Security issue fixed:
- CVE-2018-20346: Fixed a remote code execution vulnerability in FTS3 (Magellan) (bsc#1119687).
Release notes: https://www.sqlite.org/releaselog/3_27_2.html
Advisory ID | SUSE-RU-2019:1002-1
|
Released | Wed Apr 24 10:13:34 2019 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1110304,1129576 |
Description:
This update for zlib fixes the following issues:
- Fixes a segmentation fault error (bsc#1110304, bsc#1129576)
Advisory ID | SUSE-SU-2019:1040-1
|
Released | Thu Apr 25 17:09:21 2019 |
Summary | Security update for samba |
Type | security |
Severity | important |
References | 1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880 |
Description:
This update for samba fixes the following issues:
Security issue fixed:
- CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060).
ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):
- Out of bound read in ldb_wildcard_compare
- Hold at most 10 outstanding paged result cookies
- Put 'results_store' into a doubly linked list
- Refuse to build Samba against a newer minor version of ldb
Non-security issues fixed:
- Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377).
- Abide to the load_printers parameter in smb.conf (bsc#1124223).
- Provide the 32bit samba winbind PAM module and its dependend 32bit libraries.
Advisory ID | SUSE-SU-2019:1127-1
|
Released | Thu May 2 09:39:24 2019 |
Summary | Security update for sqlite3 |
Type | security |
Severity | moderate |
References | 1130325,1130326,CVE-2019-9936,CVE-2019-9937 |
Description:
This update for sqlite3 to version 3.28.0 fixes the following issues:
Security issues fixed:
- CVE-2019-9936: Fixed a heap-based buffer over-read, when running fts5 prefix
queries inside transaction (bsc#1130326).
- CVE-2019-9937: Fixed a denial of service related to interleaving reads and writes in
a single transaction with an fts5 virtual table (bsc#1130325).
Advisory ID | SUSE-RU-2019:1312-1
|
Released | Wed May 22 12:19:12 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1096191 |
Description:
This update for aaa_base fixes the following issue:
* Shell detection in /etc/profile and /etc/bash.bashrc was broken within AppArmor-confined containers
(bsc#1096191)
Advisory ID | SUSE-SU-2019:1368-1
|
Released | Tue May 28 13:15:38 2019 |
Summary | Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root |
Type | security |
Severity | important |
References | 1134524,CVE-2019-5021 |
Description:
This update for sles12sp3-docker-image, sles12sp4-image, system-user-root fixes the following issues:
- CVE-2019-5021: Include an invalidated root password by default, not an empty one (bsc#1134524)
Advisory ID | SUSE-SU-2019:1372-1
|
Released | Tue May 28 16:53:28 2019 |
Summary | Security update for libtasn1 |
Type | security |
Severity | moderate |
References | 1105435,CVE-2018-1000654 |
Description:
This update for libtasn1 fixes the following issues:
Security issue fixed:
- CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435).
Advisory ID | SUSE-RU-2019:1631-1
|
Released | Fri Jun 21 11:17:21 2019 |
Summary | Recommended update for xz |
Type | recommended |
Severity | low |
References | 1135709 |
Description:
This update for xz fixes the following issues:
Add SUSE-Public-Domain licence as some parts of xz utils (liblzma,
xz, xzdec, lzmadec, documentation, translated messages, tests,
debug, extra directory) are in public domain licence [bsc#1135709]
Advisory ID | SUSE-RU-2019:2134-1
|
Released | Wed Aug 14 11:54:56 2019 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1136717,1137624,1141059,SLE-5807 |
Description:
This update for zlib fixes the following issues:
- Update the s390 patchset. (bsc#1137624)
- Tweak zlib-power8 to have type of crc32_vpmsum conform to usage. (bsc#1141059)
- Use FAT LTO objects in order to provide proper static library.
- Do not enable the previous patchset on s390 but just s390x. (bsc#1137624)
- Add patchset for s390 improvements. (jsc#SLE-5807, bsc#1136717)
Advisory ID | SUSE-RU-2019:2188-1
|
Released | Wed Aug 21 10:10:29 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1140647 |
Description:
This update for aaa_base fixes the following issues:
- Make systemd detection cgroup oblivious. (bsc#1140647)
Advisory ID | SUSE-RU-2019:2423-1
|
Released | Fri Sep 20 16:41:45 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1146866,SLE-9132 |
Description:
This update for aaa_base fixes the following issues:
Added sysctl.d/51-network.conf to tighten network security (bsc#1146866) (jira#SLE-9132)
Following settings have been tightened (and set to 0):
- net.ipv4.conf.all.accept_redirects
- net.ipv4.conf.default.accept_redirects
- net.ipv4.conf.default.accept_source_route
- net.ipv6.conf.all.accept_redirects
- net.ipv6.conf.default.accept_redirects
Advisory ID | SUSE-SU-2019:2533-1
|
Released | Thu Oct 3 15:02:50 2019 |
Summary | Security update for sqlite3 |
Type | security |
Severity | moderate |
References | 1150137,CVE-2019-16168 |
Description:
This update for sqlite3 fixes the following issues:
Security issue fixed:
- CVE-2019-16168: Fixed improper validation of sqlite_stat1 field that could lead to denial of service (bsc#1150137).
Advisory ID | SUSE-RU-2019:2870-1
|
Released | Thu Oct 31 08:09:14 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1051143,1138869,1151023 |
Description:
This update for aaa_base provides the following fixes:
- Check if variables can be set before modifying them to avoid warnings on login with a
restricted shell. (bsc#1138869)
- Add s390x compressed kernel support. (bsc#1151023)
- service: Check if there is a second argument before using it. (bsc#1051143)
Advisory ID | SUSE-SU-2019:2997-1
|
Released | Mon Nov 18 15:16:38 2019 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595 |
Description:
This update for ncurses fixes the following issues:
Security issues fixed:
- CVE-2019-17594: Fixed a heap-based buffer over-read in the _nc_find_entry function (bsc#1154036).
- CVE-2019-17595: Fixed a heap-based buffer over-read in the fmt_entry function (bsc#1154037).
Non-security issue fixed:
- Removed screen.xterm from terminfo database (bsc#1103320).
Advisory ID | SUSE-SU-2019:3061-1
|
Released | Mon Nov 25 17:34:22 2019 |
Summary | Security update for gcc9 |
Type | security |
Severity | moderate |
References | 1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536 |
Description:
This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html
The base system compiler libraries libgcc_s1, libstdc++6 and others are
now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 /
CXX=g++-9 during configuration for using it.
Security issues fixed:
- CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145)
- CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649)
Non-security issues fixed:
- Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254)
- Fixed miscompilation for vector shift on s390. (bsc#1141897)
Advisory ID | SUSE-SU-2019:3086-1
|
Released | Thu Nov 28 10:02:24 2019 |
Summary | Security update for libidn2 |
Type | security |
Severity | moderate |
References | 1154884,1154887,CVE-2019-12290,CVE-2019-18224 |
Description:
This update for libidn2 to version 2.2.0 fixes the following issues:
- CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884).
- CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887).
Advisory ID | SUSE-RU-2019:3166-1
|
Released | Wed Dec 4 11:24:42 2019 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1007715,1084934,1157278 |
Description:
This update for aaa_base fixes the following issues:
- Use official key binding functions in inputrc that is replace up-history with previous-history, down-history with next-history and backward-delete-word with backward-kill-word. (bsc#1084934)
- Add some missed key escape sequences for urxvt-unicode terminal as well. (bsc#1007715)
- Clear broken ghost entry in patch which breaks 'readline'. (bsc#1157278)
Advisory ID | SUSE-RU-2020:256-1
|
Released | Wed Jan 29 09:39:17 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1157794,1160970 |
Description:
This update for aaa_base fixes the following issues:
- Improves the way how the Java path is created to fix an issue with sapjvm. (bsc#1157794)
- Drop 'dev.cdrom.autoclose' = 0 from sysctl config. (bsc#1160970)
Advisory ID | SUSE-RU-2020:480-1
|
Released | Tue Feb 25 17:38:22 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1160735 |
Description:
This update for aaa_base fixes the following issues:
- Change 'rp_filter' to increase the default priority to ethernet over the wifi. (bsc#1160735)
Advisory ID | SUSE-RU-2020:525-1
|
Released | Fri Feb 28 11:49:36 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1164562 |
Description:
This update for pam fixes the following issues:
- Add libdb as build-time dependency to enable pam_userdb module.
Enable pam_userdb.so (jsc#sle-7258, bsc#1164562)
Advisory ID | SUSE-RU-2020:633-1
|
Released | Tue Mar 10 16:23:08 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1139939,1151023 |
Description:
This update for aaa_base fixes the following issues:
- get_kernel_version: fix for current kernel on s390x (bsc#1151023, bsc#1139939)
- added '-h'/'--help' to the command old
- change feedback url from http://www.suse.de/feedback to https://github.com/openSUSE/aaa_base/issues
Advisory ID | SUSE-RU-2020:689-1
|
Released | Fri Mar 13 17:09:01 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1166510 |
Description:
This update for PAM fixes the following issue:
- The license of libdb linked against pam_userdb is not always wanted,
so we temporary disabled pam_userdb again. It will be published
in a different package at a later time. (bsc#1166510)
Advisory ID | SUSE-RU-2020:917-1
|
Released | Fri Apr 3 15:02:25 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1166510 |
Description:
This update for pam fixes the following issues:
- Moved pam_userdb into a separate package pam-extra. (bsc#1166510)
Advisory ID | SUSE-SU-2020:948-1
|
Released | Wed Apr 8 07:44:21 2020 |
Summary | Security update for gmp, gnutls, libnettle |
Type | security |
Severity | moderate |
References | 1152692,1155327,1166881,1168345,CVE-2020-11501 |
Description:
This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:
- CVE-2020-11501: Fixed zero random value in DTLS client hello (bsc#1168345)
FIPS related bugfixes:
- FIPS: Install checksums for binary integrity verification which are
required when running in FIPS mode (bsc#1152692, jsc#SLE-9518)
- FIPS: Fixed a cfb8 decryption issue, no longer truncate output IV if
input is shorter than block size. (bsc#1166881)
- FIPS: Added Diffie Hellman public key verification test. (bsc#1155327)
Advisory ID | SUSE-RU-2020:1226-1
|
Released | Fri May 8 10:51:05 2020 |
Summary | Recommended update for gcc9 |
Type | recommended |
Severity | moderate |
References | 1149995,1152590,1167898 |
Description:
This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.
- Includes a fix for Internal compiler error when building HepMC (bsc#1167898)
- Includes fix for binutils version parsing
- Add libstdc++6-pp provides and conflicts to avoid file conflicts
with same minor version of libstdc++6-pp from gcc10.
- Add gcc9 autodetect -g at lto link (bsc#1149995)
- Install go tool buildid for bootstrapping go
Advisory ID | SUSE-SU-2020:1294-1
|
Released | Mon May 18 07:38:36 2020 |
Summary | Security update for file |
Type | security |
Severity | moderate |
References | 1154661,1169512,CVE-2019-18218 |
Description:
This update for file fixes the following issues:
Security issues fixed:
- CVE-2019-18218: Fixed a heap-based buffer overflow in cdf_read_property_info() (bsc#1154661).
Non-security issue fixed:
- Fixed broken '--help' output (bsc#1169512).
Advisory ID | SUSE-RU-2020:1328-1
|
Released | Mon May 18 17:16:04 2020 |
Summary | Recommended update for grep |
Type | recommended |
Severity | moderate |
References | 1155271 |
Description:
This update for grep fixes the following issues:
- Update testsuite expectations, no functional changes (bsc#1155271)
Advisory ID | SUSE-RU-2020:1404-1
|
Released | Mon May 25 15:32:34 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1138793,1166260 |
Description:
This update for zlib fixes the following issues:
- Including the latest fixes from IBM (bsc#1166260)
IBM Z mainframes starting from version z15 provide DFLTCC instruction, which implements
deflate algorithm in hardware with estimated compression and decompression performance
orders of magnitude faster than the current zlib and ratio comparable with that of level 1.
- Add SUSE specific fix to solve bsc#1138793.
The fix will avoid to test if the app was linked with exactly same version of zlib
like the one that is present on the runtime.
Advisory ID | SUSE-RU-2020:1506-1
|
Released | Fri May 29 17:22:11 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1087982,1170527 |
Description:
This update for aaa_base fixes the following issues:
- Not all XTerm based emulators do have a terminfo entry. (bsc#1087982)
- Better support of Midnight Commander. (bsc#1170527)
Advisory ID | SUSE-RU-2020:1954-1
|
Released | Sat Jul 18 03:07:15 2020 |
Summary | Recommended update for cracklib |
Type | recommended |
Severity | moderate |
References | 1172396 |
Description:
This update for cracklib fixes the following issues:
- Fixed a buffer overflow when processing long words.
Advisory ID | SUSE-RU-2020:2083-1
|
Released | Thu Jul 30 10:27:59 2020 |
Summary | Recommended update for diffutils |
Type | recommended |
Severity | moderate |
References | 1156913 |
Description:
This update for diffutils fixes the following issue:
- Disable a sporadically failing test for ppc64 and ppc64le builds. (bsc#1156913)
Advisory ID | SUSE-RU-2020:2420-1
|
Released | Tue Sep 1 13:48:35 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1174551,1174736 |
Description:
This update for zlib provides the following fixes:
- Permit a deflateParams() parameter change as soon as possible. (bsc#1174736)
- Fix DFLTCC not flushing EOBS when creating raw streams. (bsc#1174551)
Advisory ID | SUSE-RU-2020:2651-1
|
Released | Wed Sep 16 14:42:55 2020 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1175811,1175830,1175831 |
Description:
This update for zlib fixes the following issues:
- Fix compression level switching (bsc#1175811, bsc#1175830, bsc#1175831)
- Enable hardware compression on s390/s390x (jsc#SLE-13776)
Advisory ID | SUSE-RU-2020:2869-1
|
Released | Tue Oct 6 16:13:20 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1011548,1153943,1153946,1161239,1171762 |
Description:
This update for aaa_base fixes the following issues:
- DIR_COLORS (bug#1006973):
- add screen.xterm-256color
- add TERM rxvt-unicode-256color
- sort and merge TERM entries in etc/DIR_COLORS
- check for Packages.db and use this instead of Packages. (bsc#1171762)
- Rename path() to _path() to avoid using a general name.
- refresh_initrd call modprobe as /sbin/modprobe (bsc#1011548)
- etc/profile add some missing ;; in case esac statements
- profile and csh.login: on s390x set TERM to dumb on dumb terminal (bsc#1153946)
- backup-rpmdb: exit if zypper is running (bsc#1161239)
- Add color alias for ip command (jsc#sle-9880, jsc#SLE-7679, bsc#1153943)
Advisory ID | SUSE-SU-2020:2947-1
|
Released | Fri Oct 16 15:23:07 2020 |
Summary | Security update for gcc10, nvptx-tools |
Type | security |
Severity | moderate |
References | 1172798,1172846,1173972,1174753,1174817,1175168,CVE-2020-13844 |
Description:
This update for gcc10, nvptx-tools fixes the following issues:
This update provides the GCC10 compiler suite and runtime libraries.
The base SUSE Linux Enterprise libraries libgcc_s1, libstdc++6 are replaced by
the gcc10 variants.
The new compiler variants are available with '-10' suffix, you can specify them
via:
CC=gcc-10
CXX=g++-10
or similar commands.
For a detailed changelog check out https://gcc.gnu.org/gcc-10/changes.html
Changes in nvptx-tools:
Advisory ID | SUSE-RU-2020:2983-1
|
Released | Wed Oct 21 15:03:03 2020 |
Summary | Recommended update for file |
Type | recommended |
Severity | moderate |
References | 1176123 |
Description:
This update for file fixes the following issues:
- Fixes an issue when file displays broken 'ELF' interpreter. (bsc#1176123)
Advisory ID | SUSE-RU-2020:3462-1
|
Released | Fri Nov 20 13:14:35 2020 |
Summary | Recommended update for pam and sudo |
Type | recommended |
Severity | moderate |
References | 1174593,1177858,1178727 |
Description:
This update for pam and sudo fixes the following issue:
pam:
- pam_xauth: do not *free* a string which has been successfully passed to *putenv*. (bsc#1177858)
- Initialize the local variable *daysleft* to avoid a misleading warning for password expire days. (bsc#1178727)
- Run /usr/bin/xauth using the old user's and group's identifiers. (bsc#1174593)
sudo:
- Fix a problem with pam_xauth which checks effective and real uids to get the real identity of the user. (bsc#1174593)
Advisory ID | SUSE-RU-2020:3620-1
|
Released | Thu Dec 3 17:03:55 2020 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for pam fixes the following issues:
- Check if the password is part of the username. (jsc#SLE-16719, jsc#SLE-16720)
- Check whether the password contains a substring of of the user's name of at least `` characters length in
some form. This is enabled by the new parameter `usersubstr=`
Advisory ID | SUSE-RU-2020:3703-1
|
Released | Mon Dec 7 20:17:32 2020 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1179431 |
Description:
This update for aaa_base fixes the following issue:
- Avoid semicolon within (t)csh login script on S/390. (bsc#1179431)
Advisory ID | SUSE-RU-2020:3942-1
|
Released | Tue Dec 29 12:22:01 2020 |
Summary | Recommended update for libidn2 |
Type | recommended |
Severity | moderate |
References | 1180138 |
Description:
This update for libidn2 fixes the following issues:
- The library is actually dual licensed, GPL-2.0-or-later or LGPL-3.0-or-later,
adjusted the RPM license tags (bsc#1180138)
Advisory ID | SUSE-RU-2021:220-1
|
Released | Tue Jan 26 14:00:51 2021 |
Summary | Recommended update for keyutils |
Type | recommended |
Severity | moderate |
References | 1180603 |
Description:
This update for keyutils fixes the following issues:
- Adjust the library license to be LPGL-2.1+ only (the tools are GPL2+, the library is just LGPL-2.1+) (bsc#1180603)
Advisory ID | SUSE-RU-2021:293-1
|
Released | Wed Feb 3 12:52:34 2021 |
Summary | Recommended update for gmp |
Type | recommended |
Severity | moderate |
References | 1180603 |
Description:
This update for gmp fixes the following issues:
- correct license statements of packages (library itself is no GPL-3.0) (bsc#1180603)
Advisory ID | SUSE-OU-2021:339-1
|
Released | Mon Feb 8 13:16:07 2021 |
Summary | Optional update for pam |
Type | optional |
Severity | low |
References | |
Description:
This update for pam fixes the following issues:
- Added rpm macros for this package, so that other packages can make use of it
This patch is optional to be installed - it doesn't fix any bugs.
Advisory ID | SUSE-RU-2021:786-1
|
Released | Mon Mar 15 11:19:23 2021 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1176201 |
Description:
This update for zlib fixes the following issues:
- Fixed hw compression on z15 (bsc#1176201)
Advisory ID | SUSE-RU-2021:924-1
|
Released | Tue Mar 23 10:00:49 2021 |
Summary | Recommended update for filesystem |
Type | recommended |
Severity | moderate |
References | 1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094 |
Description:
This update for filesystem the following issues:
- Remove duplicate line due to merge error
- Add fix for 'mesa' creating cache with perm 0700. (bsc#1181011)
- Fixed an issue causing failure during installation/upgrade a failure. (rh#1548403) (bsc#1146705)
- Allows to override config to add cleanup options of '/var/tmp'. (bsc#1078466)
- Create config to cleanup '/tmp' regular required with 'tmpfs'. (bsc#1175519)
This update for systemd fixes the following issues:
- Fix for a possible memory leak. (bsc#1180020)
- Fix for a case when to a bind mounted directory results inactive mount units. (#7811) (bsc#1180596)
- Fixed an issue when starting a container conflicts with another one. (bsc#1178775)
- Drop most of the tmpfiles that deal with generic paths and avoid warnings. (bsc#1078466, bsc#1181831)
- Don't use shell redirections when calling a rpm macro. (bsc#1183094)
- 'systemd' requires 'aaa_base' >= 13.2. (bsc#1180083)
Advisory ID | SUSE-SU-2021:930-1
|
Released | Wed Mar 24 12:09:23 2021 |
Summary | Security update for nghttp2 |
Type | security |
Severity | important |
References | 1172442,1181358,CVE-2020-11080 |
Description:
This update for nghttp2 fixes the following issues:
- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358)
Advisory ID | SUSE-RU-2021:1643-1
|
Released | Wed May 19 13:51:48 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | important |
References | 1181443,1184358,1185562 |
Description:
This update for pam fixes the following issues:
- Fixed a bug, where the 'unlimited'/'-1' value was not interpreted correctly (bsc#1181443)
- Fixed a bug, where pam_access interpreted the keyword 'LOCAL' incorrectly, leading to
an attempt to resolve it as a hostname (bsc#1184358)
- In the 32-bit compatibility package for 64-bit architectures, require 'systemd-32bit' to be also installed as it contains pam_systemd.so for 32 bit applications. (bsc#1185562)
Advisory ID | SUSE-RU-2021:1861-1
|
Released | Fri Jun 4 09:59:40 2021 |
Summary | Recommended update for gcc10 |
Type | recommended |
Severity | moderate |
References | 1029961,1106014,1178577,1178624,1178675,1182016 |
Description:
This update for gcc10 fixes the following issues:
- Disable nvptx offloading for aarch64 again since it doesn't work
- Fixed a build failure issue. (bsc#1182016)
- Fix for memory miscompilation on 'aarch64'. (bsc#1178624, bsc#1178577)
- Fix 32bit 'libgnat.so' link. (bsc#1178675)
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it stays /%lib. (bsc#1029961)
- Build complete set of multilibs for arm-none target. (bsc#1106014)
Advisory ID | SUSE-RU-2021:1937-1
|
Released | Thu Jun 10 10:47:09 2021 |
Summary | Recommended update for nghttp2 |
Type | recommended |
Severity | moderate |
References | 1186642 |
Description:
This update for nghttp2 fixes the following issue:
- The (lib)nghttp2 packages had a lower release number in SUSE Linux Enterprise 15 sp2 and sp3 than in 15 sp1, which could lead
to migration issues. (bsc#1186642)
Advisory ID | SUSE-RU-2021:2146-1
|
Released | Wed Jun 23 17:55:14 2021 |
Summary | Recommended update for openssh |
Type | recommended |
Severity | moderate |
References | 1115550,1174162 |
Description:
This update for openssh fixes the following issues:
- Fixed a race condition leading to a sshd termination of multichannel sessions with non-root users (bsc#1115550, bsc#1174162).
Advisory ID | SUSE-RU-2021:2173-1
|
Released | Mon Jun 28 14:59:45 2021 |
Summary | Recommended update for automake |
Type | recommended |
Severity | moderate |
References | 1040589,1047218,1182604,1185540,1186049 |
Description:
This update for automake fixes the following issues:
- Implement generated autoconf makefiles reproducible (bsc#1182604)
- Add fix to avoid date variations in docs. (bsc#1047218, jsc#SLE-17848)
- Avoid bashisms in test-driver script. (bsc#1185540)
This update for pcre fixes the following issues:
- Do not run profiling 'check' in parallel to make package build reproducible. (bsc#1040589)
This update for brp-check-suse fixes the following issues:
- Add fixes to support reproducible builds. (bsc#1186049)
Advisory ID | SUSE-SU-2021:2196-1
|
Released | Tue Jun 29 09:41:39 2021 |
Summary | Security update for lua53 |
Type | security |
Severity | moderate |
References | 1175448,1175449,CVE-2020-24370,CVE-2020-24371 |
Description:
This update for lua53 fixes the following issues:
Update to version 5.3.6:
- CVE-2020-24371: lgc.c mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage (bsc#1175449)
- CVE-2020-24370: ldebug.c allows a negation overflow and segmentation fault in getlocal and setlocal (bsc#1175448)
- Long brackets with a huge number of '=' overflow some internal buffer arithmetic.
Advisory ID | SUSE-SU-2021:2320-1
|
Released | Wed Jul 14 17:01:06 2021 |
Summary | Security update for sqlite3 |
Type | security |
Severity | important |
References | 1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327 |
Description:
This update for sqlite3 fixes the following issues:
- Update to version 3.36.0
- CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener
optimization (bsc#1173641)
- CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in
isAuxiliaryVtabOperator (bsc#1164719)
- CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error (bsc#1160439)
- CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input (bsc#1160438)
- CVE-2019-19923: improper handling of certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer
dereference (bsc#1160309)
- CVE-2019-19924: improper error handling in sqlite3WindowRewrite() (bsc#1159850)
- CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive (bsc#1159847)
- CVE-2019-19926: improper handling of certain errors during parsing multiSelect in select.c (bsc#1159715)
- CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference
(bsc#1159491)
- CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with
a shadow table name (bsc#1158960)
- CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated
columns (bsc#1158959)
- CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views
in conjunction with ALTER TABLE statements (bsc#1158958)
- CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column,
which allows attackers to cause a denial of service (bsc#1158812)
- CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a
sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage (bsc#1157818)
- CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability (bsc#928701)
- CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names (bsc#928700)
- CVE-2020-13434: integer overflow in sqlite3_str_vappendf (bsc#1172115)
- CVE-2020-13630: (bsc#1172234: use-after-free in fts3EvalNextRow
- CVE-2020-13631: virtual table allowed to be renamed to one of its shadow tables (bsc#1172236)
- CVE-2020-13632: NULL pointer dereference via crafted matchinfo() query (bsc#1172240)
- CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091)
Advisory ID | SUSE-SU-2021:2555-1
|
Released | Thu Jul 29 08:29:55 2021 |
Summary | Security update for git |
Type | security |
Severity | moderate |
References | 1168930,1183026,1183580,CVE-2021-21300 |
Description:
This update for git fixes the following issues:
Update from version 2.26.2 to version 2.31.1 (jsc#SLE-18152)
Security fixes:
- CVE-2021-21300: On case-insensitive file systems with support for symbolic links, if Git is configured globally
to apply delay-capable clean/smudge filters (such as Git LFS), Git could run remote code during a clone. (bsc#1183026)
Non security changes:
- Add `sysusers` file to create `git-daemon` user.
- Remove `perl-base` and `openssh-server` dependency on `git-core`and provide a `perl-Git` package. (jsc#SLE-17838)
- `fsmonitor` bug fixes
- Fix `git bisect` to take an annotated tag as a good/bad endpoint
- Fix a corner case in `git mv` on case insensitive systems
- Require only `openssh-clients` where possible (like Tumbleweed or SUSE Linux Enterprise >= 15 SP3). (bsc#1183580)
- Drop `rsync` requirement, not necessary anymore.
- Use of `pack-redundant` command is discouraged and will trigger a warning. The replacement is `repack -d`.
- The `--format=%(trailers)` mechanism gets enhanced to make it easier to design output for machine consumption.
- No longer give message to choose between rebase or merge upon pull if the history `fast-forwards`.
- The configuration variable `core.abbrev` can be set to `no` to force no abbreviation regardless of the hash algorithm
- `git rev-parse` can be explicitly told to give output as absolute or relative path with the
`--path-format=(absolute|relative)` option.
- Bash completion update to make it easier for end-users to add completion for their custom `git` subcommands.
- `git maintenance` learned to drive scheduled maintenance on platforms whose native scheduling methods are not 'cron'.
- After expiring a reflog and making a single commit, the reflog for the branch would record a single entry that
knows both `@{0}` and `@{1}`, but we failed to answer 'what commit were we on?', i.e. `@{1}`
- `git bundle` learns `--stdin` option to read its refs from the standard input.
Also, it now does not lose refs when they point at the same object.
- `git log` learned a new `--diff-merges=` option.
- `git ls-files` can and does show multiple entries when the index is unmerged, which is a source for confusion
unless `-s/-u` option is in use. A new option `--deduplicate` has been introduced.
- `git worktree list` now annotates worktrees as prunable, shows locked and prunable attributes
in `--porcelain mode`, and gained a `--verbose` option.
- `git clone` tries to locally check out the branch pointed at by HEAD of the remote repository after it
is done, but the protocol did not convey the information necessary to do so when copying an empty repository.
The protocol v2 learned how to do so.
- There are other ways than `..` for a single token to denote a `commit range', namely `^!`
and `^-`, but `git range-diff` did not understand them.
- The `git range-diff` command learned `--(left|right)-only` option to show only one side of the compared range.
- `git mergetool` feeds three versions (base, local and remote) of a conflicted path unmodified.
The command learned to optionally prepare these files with unconflicted parts already resolved.
- The `.mailmap` is documented to be read only from the root level of a working tree, but a stray file
in a bare repository also was read by accident, which has been corrected.
- `git maintenance` tool learned a new `pack-refs` maintenance task.
- Improved error message given when a configuration variable that is expected to have a boolean value.
- Signed commits and tags now allow verification of objects, whose two object names
(one in SHA-1, the other in SHA-256) are both signed.
- `git rev-list` command learned `--disk-usage` option.
- `git diff`, `git log` `--{skip,rotate}-to=` allows the user to discard diff output for early
paths or move them to the end of the output.
- `git difftool` learned `--skip-to=` option to restart an interrupted session from an arbitrary path.
- `git grep` has been tweaked to be limited to the sparse checkout paths.
- `git rebase --[no-]fork-point` gained a configuration variable `rebase.forkPoint` so that users do not have
to keep specifying a non-default setting.
- `git stash` did not work well in a sparsely checked out working tree.
- Newline characters in the host and path part of `git://` URL are now forbidden.
- `Userdiff` updates for PHP, Rust, CSS
- Avoid administrator error leading to data loss with `git push --force-with-lease[=
[]` by
introducing `--force-if-includes`
]
- only pull `asciidoctor` for the default ruby version
- The `--committer-date-is-author-date` option of `rebase` and `am` subcommands lost the e-mail address by
mistake in 2.29
- The transport protocol v2 has become the default again
- `git worktree` gained a `repair` subcommand, `git init --separate-git-dir` no longer corrupts administrative data
related to linked worktrees
- `git maintenance` introduced for repository maintenance tasks
- `fetch.writeCommitGraph` is deemed to be still a bit too risky and is no longer part of the
`feature.experimental` set.
- The commands in the `diff` family honors the `diff.relative` configuration variable.
- `git diff-files` has been taught to say paths that are marked as `intent-to-add` are new files,
not modified from an empty blob.
- `git gui` now allows opening work trees from the start-up dialog.
- `git bugreport` reports what shell is in use.
- Some repositories have commits that record wrong committer timezone; `git fast-import` has an option to pass
these timestamps intact to allow recreating existing repositories as-is.
- `git describe` will always use the `long` version when giving its output based misplaced tags
- `git pull` issues a warning message until the `pull.rebase` configuration variable is explicitly given
Advisory ID | SUSE-RU-2021:2606-1
|
Released | Wed Aug 4 13:16:09 2021 |
Summary | Recommended update for libcbor |
Type | recommended |
Severity | moderate |
References | 1102408 |
Description:
This update for libcbor fixes the following issues:
- Implement a fix to avoid building shared library twice. (bsc#1102408)
Advisory ID | SUSE-SU-2021:2682-1
|
Released | Thu Aug 12 20:06:19 2021 |
Summary | Security update for rpm |
Type | security |
Severity | important |
References | 1179416,1181805,1183543,1183545,CVE-2021-20266,CVE-2021-20271,CVE-2021-3421 |
Description:
This update for rpm fixes the following issues:
- Changed default package verification level to 'none' to be compatible to rpm-4.14.1
- Made illegal obsoletes a warning
- Fixed a potential access of freed mem in ndb's glue code (bsc#1179416)
- Added support for enforcing signature policy and payload verification step to
transactions (jsc#SLE-17817)
- Added :humansi and :hmaniec query formatters for human readable output
- Added query selectors for whatobsoletes and whatconflicts
- Added support for sorting caret higher than base version
- rpm does no longer require the signature header to be in a contiguous
region when signing (bsc#1181805)
Security fixes:
- CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an
attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM
repository, to cause RPM database corruption. The highest threat from this vulnerability is to
data integrity (bsc#1183543)
- CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file.
This flaw allows an attacker who can convince a victim to install a seemingly verifiable package,
whose signature header was modified, to cause RPM database corruption and execute code. The highest
threat from this vulnerability is to data integrity, confidentiality, and system availability (bsc#1183545)
- CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker
who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability
is to system availability.
Advisory ID | SUSE-RU-2021:3182-1
|
Released | Tue Sep 21 17:04:26 2021 |
Summary | Recommended update for file |
Type | recommended |
Severity | moderate |
References | 1189996 |
Description:
This update for file fixes the following issues:
- Fixes exception thrown by memory allocation problem (bsc#1189996)
Advisory ID | SUSE-SU-2021:3291-1
|
Released | Wed Oct 6 16:45:36 2021 |
Summary | Security update for glibc |
Type | security |
Severity | moderate |
References | 1186489,1187911,CVE-2021-33574,CVE-2021-35942 |
Description:
This update for glibc fixes the following issues:
- CVE-2021-33574: Fixed use __pthread_attr_copy in mq_notify (bsc#1186489).
- CVE-2021-35942: Fixed wordexp handle overflow in positional parameter number (bsc#1187911).
Advisory ID | SUSE-SU-2021:3445-1
|
Released | Fri Oct 15 09:03:39 2021 |
Summary | Security update for rpm |
Type | security |
Severity | important |
References | 1183659,1185299,1187670,1188548 |
Description:
This update for rpm fixes the following issues:
Security issues fixed:
- PGP hardening changes (bsc#1185299)
Maintaince issues fixed:
- Fixed zstd detection (bsc#1187670)
- Added ndb rofs support (bsc#1188548)
- Fixed deadlock when multiple rpm processes try tp acquire the database lock (bsc#1183659)
Advisory ID | SUSE-SU-2021:3490-1
|
Released | Wed Oct 20 16:31:55 2021 |
Summary | Security update for ncurses |
Type | security |
Severity | moderate |
References | 1190793,CVE-2021-39537 |
Description:
This update for ncurses fixes the following issues:
- CVE-2021-39537: Fixed an heap-based buffer overflow in _nc_captoinfo. (bsc#1190793)
Advisory ID | SUSE-RU-2021:3494-1
|
Released | Wed Oct 20 16:48:46 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1190052 |
Description:
This update for pam fixes the following issues:
- Added pam_faillock to the set of available PAM modules. (jsc#SLE-20638)
- Added new file macros.pam on request of systemd. (bsc#1190052)
Advisory ID | SUSE-RU-2021:3510-1
|
Released | Tue Oct 26 11:22:15 2021 |
Summary | Recommended update for pam |
Type | recommended |
Severity | important |
References | 1191987 |
Description:
This update for pam fixes the following issues:
- Fixed a bad directive file which resulted in
the 'securetty' file to be installed as 'macros.pam'.
(bsc#1191987)
Advisory ID | SUSE-SU-2021:3529-1
|
Released | Wed Oct 27 09:23:32 2021 |
Summary | Security update for pcre |
Type | security |
Severity | moderate |
References | 1172973,1172974,CVE-2019-20838,CVE-2020-14155 |
Description:
This update for pcre fixes the following issues:
Update pcre to version 8.45:
- CVE-2020-14155: Fixed integer overflow via a large number after a '(?C' substring (bsc#1172974).
- CVE-2019-20838: Fixed buffer over-read in JIT compiler (bsc#1172973)
Advisory ID | SUSE-RU-2021:3766-1
|
Released | Tue Nov 23 07:07:43 2021 |
Summary | Recommended update for git |
Type | recommended |
Severity | moderate |
References | 1192023 |
Description:
This update for git fixes the following issues:
- Installation of the 'git-daemon' package needs nogroup group dependency (bsc#1192023)
Advisory ID | SUSE-RU-2021:3799-1
|
Released | Wed Nov 24 18:07:54 2021 |
Summary | Recommended update for gcc11 |
Type | recommended |
Severity | moderate |
References | 1187153,1187273,1188623 |
Description:
This update for gcc11 fixes the following issues:
The additional GNU compiler collection GCC 11 is provided:
To select these compilers install the packages:
- gcc11
- gcc-c++11
- and others with 11 prefix.
to select them for building:
The compiler baselibraries (libgcc_s1, libstdc++6 and others) are being replaced by the GCC 11 variants.
Advisory ID | SUSE-RU-2021:3872-1
|
Released | Thu Dec 2 07:25:55 2021 |
Summary | Recommended update for cracklib |
Type | recommended |
Severity | moderate |
References | 1191736 |
Description:
This update for cracklib fixes the following issues:
- Enable build time tests (bsc#1191736)
Advisory ID | SUSE-RU-2021:3891-1
|
Released | Fri Dec 3 10:21:49 2021 |
Summary | Recommended update for keyutils |
Type | recommended |
Severity | moderate |
References | 1029961,1113013,1187654 |
Description:
This update for keyutils fixes the following issues:
- Add /etc/keys/ and /usr/etc/keys/ directory (bsc#1187654)
keyutils was updated to 1.6.3 (jsc#SLE-20016):
- Revert the change notifications that were using /dev/watch_queue.
- Apply the change notifications that use pipe2(O_NOTIFICATION_PIPE).
- Allow 'keyctl supports' to retrieve raw capability data.
- Allow 'keyctl id' to turn a symbolic key ID into a numeric ID.
- Allow 'keyctl new_session' to name the keyring.
- Allow 'keyctl add/padd/etc.' to take hex-encoded data.
- Add 'keyctl watch*' to expose kernel change notifications on keys.
- Add caps for namespacing and notifications.
- Set a default TTL on keys that upcall for name resolution.
- Explicitly clear memory after it's held sensitive information.
- Various manual page fixes.
- Fix C++-related errors.
- Add support for keyctl_move().
- Add support for keyctl_capabilities().
- Make key=val list optional for various public-key ops.
- Fix system call signature for KEYCTL_PKEY_QUERY.
- Fix 'keyctl pkey_query' argument passing.
- Use keyctl_read_alloc() in dump_key_tree_aux().
- Various manual page fixes.
Updated to 1.6:
- Apply various specfile cleanups from Fedora.
- request-key: Provide a command line option to suppress helper execution.
- request-key: Find least-wildcard match rather than first match.
- Remove the dependency on MIT Kerberos.
- Fix some error messages
- keyctl_dh_compute.3: Suggest /proc/crypto for list of available hashes.
- Fix doc and comment typos.
- Add public key ops for encrypt, decrypt, sign and verify (needs linux-4.20).
- Add pkg-config support for finding libkeyutils.
- upstream isn't offering PGP signatures for the source tarballs anymore
Updated to 1.5.11 (bsc#1113013)
- Add keyring restriction support.
- Add KDF support to the Diffie-Helman function.
- DNS: Add support for AFS config files and SRV records
Advisory ID | SUSE-SU-2021:3899-1
|
Released | Fri Dec 3 11:27:41 2021 |
Summary | Security update for aaa_base |
Type | security |
Severity | moderate |
References | 1162581,1174504,1191563,1192248 |
Description:
This update for aaa_base fixes the following issues:
- Allowed ping and ICMP commands without CAP_NET_RAW (bsc#1174504).
- Add $HOME/.local/bin to PATH, if it exists (bsc#1192248).
- Fixed get_kernel_version.c to work also for recent kernels on the s390/X platform (bsc#1191563).
- Support xz compressed kernel (bsc#1162581)
Advisory ID | SUSE-SU-2021:3942-1
|
Released | Mon Dec 6 14:46:05 2021 |
Summary | Security update for brotli |
Type | security |
Severity | moderate |
References | 1175825,CVE-2020-8927 |
Description:
This update for brotli fixes the following issues:
- CVE-2020-8927: Fixed integer overflow when input chunk is larger than 2GiB (bsc#1175825).
Advisory ID | SUSE-SU-2021:3946-1
|
Released | Mon Dec 6 14:57:42 2021 |
Summary | Security update for gmp |
Type | security |
Severity | moderate |
References | 1192717,CVE-2021-43618 |
Description:
This update for gmp fixes the following issues:
- CVE-2021-43618: Fixed buffer overflow via crafted input in mpz/inp_raw.c (bsc#1192717).
Advisory ID | SUSE-SU-2021:3950-1
|
Released | Mon Dec 6 14:59:37 2021 |
Summary | Security update for openssh |
Type | security |
Severity | important |
References | 1190975,CVE-2021-41617 |
Description:
This update for openssh fixes the following issues:
- CVE-2021-41617: Fixed privilege escalation when AuthorizedKeysCommand/AuthorizedPrincipalsCommand are configured (bsc#1190975).
Advisory ID | SUSE-RU-2021:3980-1
|
Released | Thu Dec 9 16:42:19 2021 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1191592 |
Description:
glibc was updated to fix the following issue:
- Support for new IBM Z Hardware (bsc#1191592, jsc#IBM-869)
Advisory ID | SUSE-SU-2021:4153-1
|
Released | Wed Dec 22 11:00:48 2021 |
Summary | Security update for openssh |
Type | security |
Severity | important |
References | 1183137,CVE-2021-28041 |
Description:
This update for openssh fixes the following issues:
- CVE-2021-28041: Fixed double free in ssh-agent (bsc#1183137).
Advisory ID | SUSE-RU-2021:4182-1
|
Released | Thu Dec 23 11:51:51 2021 |
Summary | Recommended update for zlib |
Type | recommended |
Severity | moderate |
References | 1192688 |
Description:
This update for zlib fixes the following issues:
- Fix hardware compression incorrect result on z15 hardware (bsc#1192688)
Advisory ID | SUSE-RU-2022:96-1
|
Released | Tue Jan 18 05:14:44 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | important |
References | 1180125,1190824,1193711 |
Description:
This update for rpm fixes the following issues:
- Fix header check so that old rpms no longer get rejected (bsc#1190824)
- Add explicit requirement on python-rpm-macros (bsc#1180125, bsc#1193711)
Advisory ID | SUSE-RU-2022:207-1
|
Released | Thu Jan 27 09:24:49 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | |
Description:
This update for glibc fixes the following issues:
- Add support for livepatches on x86_64 for SUSE Linux Enterprise 15 SP4 (jsc#SLE-20049).
Advisory ID | SUSE-RU-2022:227-1
|
Released | Mon Jan 31 06:05:25 2022 |
Summary | Recommended update for git |
Type | recommended |
Severity | moderate |
References | 1193722 |
Description:
This update for git fixes the following issues:
- update to 2.34.1 (bsc#1193722):
* 'git grep' looking in a blob that has non-UTF8 payload was
completely broken when linked with certain versions of PCREv2
library in the latest release.
* 'git pull' with any strategy when the other side is behind us
should succeed as it is a no-op, but doesn't.
* An earlier change in 2.34.0 caused JGit application (that abused
GIT_EDITOR mechanism when invoking 'git config') to get stuck with
a SIGTTOU signal; it has been reverted.
* An earlier change that broke .gitignore matching has been reverted.
* SubmittingPatches document gained a syntactically incorrect mark-up,
which has been corrected.
- git 2.33.0:
* 'git send-email' learned the '--sendmail-cmd' command line option
and the 'sendemail.sendmailCmd' configuration variable, which is a
more sensible approach than the current way of repurposing the
'smtp-server' that is meant to name the server to instead name the
command to talk to the server.
* The userdiff pattern for C# learned the token 'record'.
* 'git rev-list' learns to omit the 'commit ' header
lines from the output with the `--no-commit-header` option.
* 'git worktree add --lock' learned to record why the worktree is
locked with a custom message.
* internal improvements including performance optimizations
* a number of bug fixes
- git 2.32.0:
* '.gitattributes', '.gitignore', and '.mailmap' files that are
symbolic links are ignored
* 'git apply --3way' used to first attempt a straight
application, and only fell back to the 3-way merge algorithm
when the straight application failed. Starting with this
version, the command will first try the 3-way merge algorithm
and only when it fails (either resulting with conflict or the
base versions of blobs are missing), falls back to the usual
patch application.
* 'git stash show' can now show the untracked part of the stash
* Improved 'git repack' strategy
* http code can now unlock a certificate with a cached password
respectively.
* 'git clone --reject-shallow' option fails the clone as soon as
we notice that we are cloning from a shallow repository.
* 'gitweb' learned 'e-mail privacy' feature
* Multiple improvements to output and configuration options
* Bug fixes and developer visible fixes
Advisory ID | SUSE-SU-2022:330-1
|
Released | Fri Feb 4 09:29:08 2022 |
Summary | Security update for glibc |
Type | security |
Severity | important |
References | 1194640,1194768,1194770,1194785,CVE-2021-3999,CVE-2022-23218,CVE-2022-23219 |
Description:
This update for glibc fixes the following issues:
- CVE-2021-3999: Fixed incorrect errno in getcwd (bsc#1194640)
- CVE-2022-23219: Fixed buffer overflow in sunrpc clnt_create for 'unix' (bsc#1194768)
- CVE-2022-23218: Fixed buffer overflow in sunrpc svcunix_create (bsc#1194770)
Features added:
- IBM Power 10 string operation improvements (bsc#1194785, jsc#SLE-18195)
Advisory ID | SUSE-RU-2022:383-1
|
Released | Tue Feb 15 17:47:36 2022 |
Summary | Recommended update for cyrus-sasl |
Type | recommended |
Severity | moderate |
References | 1194265 |
Description:
This update for cyrus-sasl fixes the following issues:
- Fixed an issue when in postfix 'sasl' authentication with password fails. (bsc#1194265)
- Add config parameter '--with-dblib=gdbm'
- Avoid converting of '/etc/sasldb2 by every update. Convert '/etc/sasldb2' only if it is a Berkeley DB.
Advisory ID | SUSE-RU-2022:520-1
|
Released | Fri Feb 18 12:45:19 2022 |
Summary | Recommended update for rpm |
Type | recommended |
Severity | moderate |
References | 1194968 |
Description:
This update for rpm fixes the following issues:
- Revert unwanted /usr/bin/python to /usr/bin/python2 change we got with the update to 4.14.3 (bsc#1194968)
Advisory ID | SUSE-RU-2022:692-1
|
Released | Thu Mar 3 15:46:47 2022 |
Summary | Recommended update for filesystem |
Type | recommended |
Severity | moderate |
References | 1190447 |
Description:
This update for filesystem fixes the following issues:
- Release ported filesystem to LTSS channels (bsc#1190447).
Advisory ID | SUSE-SU-2022:743-1
|
Released | Mon Mar 7 22:08:12 2022 |
Summary | Security update for cyrus-sasl |
Type | security |
Severity | important |
References | 1194265,1196036,CVE-2022-24407 |
Description:
This update for cyrus-sasl fixes the following issues:
- CVE-2022-24407: Fixed SQL injection in sql_auxprop_store in plugins/sql.c (bsc#1196036).
The following non-security bugs were fixed:
- postfix: sasl authentication with password fails (bsc#1194265).
Advisory ID | SUSE-RU-2022:789-1
|
Released | Thu Mar 10 11:22:05 2022 |
Summary | Recommended update for update-alternatives |
Type | recommended |
Severity | moderate |
References | 1195654 |
Description:
This update for update-alternatives fixes the following issues:
- Break bash - update-alternatives cycle rewrite of '%post' in 'lua'. (bsc#1195654)
Advisory ID | SUSE-RU-2022:861-1
|
Released | Tue Mar 15 23:30:48 2022 |
Summary | Recommended update for openssl-1_1 |
Type | recommended |
Severity | moderate |
References | 1182959,1195149,1195792,1195856 |
Description:
This update for openssl-1_1 fixes the following issues:
openssl-1_1:
- Fix PAC pointer authentication in ARM (bsc#1195856)
- Pull libopenssl-1_1 when updating openssl-1_1 with the same version (bsc#1195792)
- FIPS: Fix function and reason error codes (bsc#1182959)
- Enable zlib compression support (bsc#1195149)
glibc:
- Resolve installation issue of `glibc-devel` in SUSE Linux Enterprise Micro 5.1
linux-glibc-devel:
- Resolve installation issue of `linux-kernel-headers` in SUSE Linux Enterprise Micro 5.1
libxcrypt:
- Resolve installation issue of `libxcrypt-devel` in SUSE Linux Enterprise Micro 5.1
zlib:
- Resolve installation issue of `zlib-devel` in SUSE Linux Enterprise Micro 5.1
Advisory ID | SUSE-RU-2022:936-1
|
Released | Tue Mar 22 18:10:17 2022 |
Summary | Recommended update for filesystem and systemd-rpm-macros |
Type | recommended |
Severity | moderate |
References | 1196275,1196406 |
Description:
This update for filesystem and systemd-rpm-macros fixes the following issues:
filesystem:
- Add path /lib/modprobe.d (bsc#1196275, jsc#SLE-20639)
systemd-rpm-macros:
- Make %_modprobedir point to /lib/modprobe.d (bsc#1196275, bsc#1196406)
Advisory ID | SUSE-RU-2022:1047-1
|
Released | Wed Mar 30 16:20:56 2022 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1196093,1197024 |
Description:
This update for pam fixes the following issues:
- Define _pam_vendordir as the variable is needed by systemd and others. (bsc#1196093)
- Between allocating the variable 'ai' and free'ing them, there are two 'return NO' were we don't free this variable.
This patch inserts freaddrinfo() calls before the 'return NO;'s. (bsc#1197024)
Advisory ID | SUSE-SU-2022:1061-1
|
Released | Wed Mar 30 18:27:06 2022 |
Summary | Security update for zlib |
Type | security |
Severity | important |
References | 1197459,CVE-2018-25032 |
Description:
This update for zlib fixes the following issues:
- CVE-2018-25032: Fixed memory corruption on deflate (bsc#1197459).
Advisory ID | SUSE-RU-2022:1099-1
|
Released | Mon Apr 4 12:53:05 2022 |
Summary | Recommended update for aaa_base |
Type | recommended |
Severity | moderate |
References | 1194883 |
Description:
This update for aaa_base fixes the following issues:
- Set net.ipv4.ping_group_range to allow ICMP ping (bsc#1194883)
- Include all fixes and changes for systemwide inputrc to remove the 8 bit escape sequence which interfere with UTF-8
multi byte characters as well as support the vi mode of readline library
Advisory ID | SUSE-SU-2022:1158-1
|
Released | Tue Apr 12 14:44:43 2022 |
Summary | Security update for xz |
Type | security |
Severity | important |
References | 1198062,CVE-2022-1271 |
Description:
This update for xz fixes the following issues:
- CVE-2022-1271: Fixed an incorrect escaping of malicious filenames (ZDI-CAN-16587). (bsc#1198062)
Advisory ID | SUSE-RU-2022:1281-1
|
Released | Wed Apr 20 12:26:38 2022 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | moderate |
References | 1196647 |
Description:
This update for libtirpc fixes the following issues:
- Add option to enforce connection via protocol version 2 first (bsc#1196647)
Advisory ID | SUSE-RU-2022:1374-1
|
Released | Mon Apr 25 15:02:13 2022 |
Summary | Recommended update for openldap2 |
Type | recommended |
Severity | moderate |
References | 1191157,1197004 |
Description:
This update for openldap2 fixes the following issues:
- allow specification of max/min TLS version with TLS1.3 (bsc#1191157)
- libldap was able to be out of step with openldap in some cases which could cause incorrect installations and symbol
resolution failures. openldap2 and libldap now are locked to their related release versions. (bsc#1197004)
- restore CLDAP functionality in CLI tools (jsc#PM-3288)
Advisory ID | SUSE-RU-2022:1409-1
|
Released | Tue Apr 26 12:54:57 2022 |
Summary | Recommended update for gcc11 |
Type | recommended |
Severity | moderate |
References | 1195628,1196107 |
Description:
This update for gcc11 fixes the following issues:
- Add a list of Obsoletes to libstdc++6-pp-gcc11 so updates from
packages provided by older GCC work. Add a requires from that
package to the corresponding libstc++6 package to keep those
at the same version. [bsc#1196107]
- Fixed memory corruption when creating dependences with the D language frontend.
- Add gcc11-PIE, similar to gcc-PIE but affecting gcc11 [bsc#1195628]
- Put libstdc++6-pp Requires on the shared library and drop
to Recommends.
Advisory ID | SUSE-RU-2022:1451-1
|
Released | Thu Apr 28 10:47:22 2022 |
Summary | Recommended update for perl |
Type | recommended |
Severity | moderate |
References | 1193489 |
Description:
This update for perl fixes the following issues:
- Fix Socket::VERSION evaluation and stabilize Socket:VERSION comparisons (bsc#1193489)
Advisory ID | SUSE-SU-2022:1484-1
|
Released | Mon May 2 16:47:10 2022 |
Summary | Security update for git |
Type | security |
Severity | important |
References | 1181400,1198234,CVE-2022-24765 |
Description:
This update for git fixes the following issues:
- Updated to version 2.35.3:
- CVE-2022-24765: Fixed a potential command injection via git worktree (bsc#1198234).
Advisory ID | SUSE-RU-2022:1655-1
|
Released | Fri May 13 15:36:10 2022 |
Summary | Recommended update for pam |
Type | recommended |
Severity | moderate |
References | 1197794 |
Description:
This update for pam fixes the following issue:
- Do not include obsolete header files (bsc#1197794)
Advisory ID | SUSE-RU-2022:1658-1
|
Released | Fri May 13 15:40:20 2022 |
Summary | Recommended update for libpsl |
Type | recommended |
Severity | important |
References | 1197771 |
Description:
This update for libpsl fixes the following issues:
- Fix libpsl compilation issues (bsc#1197771)
Advisory ID | SUSE-SU-2022:1670-1
|
Released | Mon May 16 10:06:30 2022 |
Summary | Security update for openldap2 |
Type | security |
Severity | important |
References | 1199240,CVE-2022-29155 |
Description:
This update for openldap2 fixes the following issues:
- CVE-2022-29155: Fixed SQL injection in back-sql (bsc#1199240).
Advisory ID | SUSE-RU-2022:1709-1
|
Released | Tue May 17 17:35:47 2022 |
Summary | Recommended update for libcbor |
Type | recommended |
Severity | important |
References | 1197743 |
Description:
This update for libcbor fixes the following issues:
- Fix build errors occuring on SUSE Linux Enterprise 15 Service Pack 4
Advisory ID | SUSE-SU-2022:1718-1
|
Released | Tue May 17 17:44:43 2022 |
Summary | Security update for e2fsprogs |
Type | security |
Severity | important |
References | 1198446,CVE-2022-1304 |
Description:
This update for e2fsprogs fixes the following issues:
- CVE-2022-1304: Fixed out-of-bounds read/write leading to segmentation fault
and possibly arbitrary code execution. (bsc#1198446)
Advisory ID | SUSE-RU-2022:1887-1
|
Released | Tue May 31 09:24:18 2022 |
Summary | Recommended update for grep |
Type | recommended |
Severity | moderate |
References | 1040589 |
Description:
This update for grep fixes the following issues:
- Make profiling deterministic. (bsc#1040589, SLE-24115)
Advisory ID | SUSE-RU-2022:1899-1
|
Released | Wed Jun 1 10:43:22 2022 |
Summary | Recommended update for libtirpc |
Type | recommended |
Severity | important |
References | 1198176 |
Description:
This update for libtirpc fixes the following issues:
- Add a check for nullpointer in check_address to prevent client from crashing (bsc#1198176)
Advisory ID | SUSE-RU-2022:1909-1
|
Released | Wed Jun 1 16:25:35 2022 |
Summary | Recommended update for glibc |
Type | recommended |
Severity | moderate |
References | 1198751 |
Description:
This update for glibc fixes the following issues:
- Add the correct name for the IBM Z16 (bsc#1198751).
Advisory ID | SUSE-RU-2022:2019-1
|
Released | Wed Jun 8 16:50:07 2022 |
Summary | Recommended update for gcc11 |
Type | recommended |
Severity | moderate |
References | 1192951,1193659,1195283,1196861,1197065 |
Description:
This update for gcc11 fixes the following issues:
Update to the GCC 11.3.0 release.
- includes SLS hardening backport on x86_64. [bsc#1195283]
- includes change to adjust gnats idea of the target, fixing the build of gprbuild. [bsc#1196861]
- fixed miscompile of embedded premake in 0ad on i586. [bsc#1197065]
- use --with-cpu rather than specifying --with-arch/--with-tune
- Fix D memory corruption in -M output.
- Fix ICE in is_this_parameter with coroutines. [bsc#1193659]
- fixes issue with debug dumping together with -o /dev/null
- fixes libgccjit issue showing up in emacs build [bsc#1192951]
- Package mwaitintrin.h