SUSE-CU-2026:9573-1: Security update of suse/kiosk/xorg-client

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Sep 6 12:41:45 UTC 2026


SUSE Container Update Advisory: suse/kiosk/xorg-client
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9573-1
Container Tags        : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.1 , suse/kiosk/xorg-client:latest
Container Release     : 80.1
Severity              : critical
Type                  : security
References            : 1029961 1081723 1081723 1096405 1096406 1096407 1096408 1097410
                        1105435 1106873 1114407 1115750 1118118 1119069 1119105 1119687
                        1124223 1125410 1126377 1130325 1130326 1131060 1131686 1141322
                        1141322 1146358 1146359 1150137 1157818 1158527 1158812 1158958
                        1158959 1158960 1159491 1159715 1159819 1159819 1159847 1159850
                        1160309 1160438 1160439 1164719 1168422 1169746 1170671 1171978
                        1172091 1172115 1172234 1172236 1172240 1172879 1173641 1174230
                        1174697 1175960 1176206 1176384 1176756 1176899 1176934 1177977
                        1179382 1180520 1183942 1184161 1185116 1185116 1188891 1189517
                        1189802 1191467 1191525 1191546 1191546 1191546 1191546 1192079
                        1192079 1192080 1192080 1192086 1192086 1192087 1192087 1192228
                        1192228 1195115 1195391 1195773 1196147 1196148 1196150 1198146
                        1198486 1198486 1198932 1198980 1198980 1198980 1199474 1200027
                        1200027 1200321 1201234 1201298 1201298 1201298 1201298 1201511
                        1201783 1202118 1202118 1202645 1202870 1202870 1203446 1204272
                        1204690 1204729 1204729 1206337 1207038 1207209 1208056 1208138
                        1208242 1208999 1210660 1211643 1212230 1212607 1214254 1214980
                        1214980 1215204 1216198 1216594 1216598 1217119 1218640 1219213
                        1219276 1219391 1221052 1222804 1222807 1222811 1222813 1222814
                        1222821 1222822 1222826 1222828 1222830 1222833 1222834 1222834
                        1223179 1223724 1223903 1224044 1224113 1224113 1224113 1224113
                        1224115 1224116 1224118 1225365 1226192 1226227 1226586 1226724
                        1226731 1226733 1227642 1227669 1227670 1227671 1227918 1228120
                        1228120 1228322 1228924 1230166 1230932 1231463 1231463 1233282
                        1233420 1233421 1234225 1236834 1236878 1236974 1237236 1237240
                        1237241 1237242 1237374 1237374 1240897 1241020 1241078 1241189
                        1241701 1242844 1243503 1243867 1244057 1244057 1244554 1244555
                        1244557 1244590 1244596 1244700 1245034 1245227 1246114 1246232
                        1246233 1246267 1246296 1246299 1246533 1246597 1247106 1247108
                        1247503 1247581 1247582 1247589 1247850 1247858 1247985 1248117
                        1248278 1248330 1248586 1249049 1249055 1249128 1250413 1250553
                        1250750 1251263 1253783 1254132 1254297 1254353 1254353 1254662
                        1254670 1254670 1254878 1255451 1256341 1256459 1256498 1256499
                        1256500 1256804 1256805 1256807 1256808 1256809 1256810 1256811
                        1256812 1257049 1257235 1257353 1257354 1257355 1257593 1257594
                        1257595 1257922 1257960 1258083 1258568 1259619 1260411 1261210
                        1261546 1261568 1261569 1261570 1261571 1261572 1261742 1261743
                        1261998 1263704 1263705 1263707 1263708 1263709 1263710 1263711
                        1263712 1263713 1263714 1263715 1263716 1267733 1268012 1268013
                        1268434 1268853 1269779 1269790 1270008 1270009 1270010 1270016
                        1270018 1270021 928700 928701 CVE-2015-3414 CVE-2015-3415 CVE-2018-0495
                        CVE-2018-1000654 CVE-2018-12384 CVE-2018-12404 CVE-2018-12405
                        CVE-2018-17466 CVE-2018-18492 CVE-2018-18493 CVE-2018-18494 CVE-2018-18498
                        CVE-2018-18508 CVE-2018-20346 CVE-2018-4180 CVE-2018-4181 CVE-2018-4182
                        CVE-2018-4183 CVE-2018-4700 CVE-2019-11745 CVE-2019-16168 CVE-2019-17006
                        CVE-2019-17006 CVE-2019-19244 CVE-2019-19317 CVE-2019-19603 CVE-2019-19645
                        CVE-2019-19646 CVE-2019-19880 CVE-2019-19923 CVE-2019-19924 CVE-2019-19925
                        CVE-2019-19926 CVE-2019-19959 CVE-2019-20218 CVE-2019-3880 CVE-2019-8675
                        CVE-2019-8696 CVE-2019-8842 CVE-2019-9936 CVE-2019-9937 CVE-2020-10001
                        CVE-2020-12399 CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 CVE-2020-13434
                        CVE-2020-13435 CVE-2020-13630 CVE-2020-13631 CVE-2020-13632 CVE-2020-15358
                        CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 CVE-2020-15683
                        CVE-2020-15969 CVE-2020-25648 CVE-2020-3898 CVE-2020-6829 CVE-2020-9327
                        CVE-2021-23981 CVE-2021-23982 CVE-2021-23984 CVE-2021-23987 CVE-2021-25317
                        CVE-2021-36690 CVE-2021-42523 CVE-2021-46848 CVE-2022-1210 CVE-2022-23491
                        CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 CVE-2022-26691 CVE-2022-31741
                        CVE-2022-31741 CVE-2022-3479 CVE-2022-35737 CVE-2022-46908 CVE-2022-48622
                        CVE-2023-0767 CVE-2023-2137 CVE-2023-25435 CVE-2023-32324 CVE-2023-32360
                        CVE-2023-34241 CVE-2023-38469 CVE-2023-38471 CVE-2023-4504 CVE-2023-52356
                        CVE-2023-5388 CVE-2023-5388 CVE-2024-12133 CVE-2024-12224 CVE-2024-12243
                        CVE-2024-13978 CVE-2024-34397 CVE-2024-35235 CVE-2024-47175 CVE-2024-52533
                        CVE-2024-52615 CVE-2024-52616 CVE-2024-6655 CVE-2024-6655 CVE-2024-7006
                        CVE-2025-10911 CVE-2025-13151 CVE-2025-1352 CVE-2025-13601 CVE-2025-1372
                        CVE-2025-1376 CVE-2025-1377 CVE-2025-14087 CVE-2025-14512 CVE-2025-14831
                        CVE-2025-29087 CVE-2025-29088 CVE-2025-3277 CVE-2025-32988 CVE-2025-32989
                        CVE-2025-32990 CVE-2025-3360 CVE-2025-4373 CVE-2025-49794 CVE-2025-49795
                        CVE-2025-49796 CVE-2025-50422 CVE-2025-58060 CVE-2025-58364 CVE-2025-58436
                        CVE-2025-58436 CVE-2025-58436 CVE-2025-59529 CVE-2025-6021 CVE-2025-6052
                        CVE-2025-6170 CVE-2025-61915 CVE-2025-6199 CVE-2025-6395 CVE-2025-68276
                        CVE-2025-68468 CVE-2025-68471 CVE-2025-6965 CVE-2025-7039 CVE-2025-70873
                        CVE-2025-7345 CVE-2025-7425 CVE-2025-7709 CVE-2025-7709 CVE-2025-8176
                        CVE-2025-8177 CVE-2025-8534 CVE-2025-8732 CVE-2025-8851 CVE-2025-8961
                        CVE-2025-9165 CVE-2025-9187 CVE-2025-9820 CVE-2025-9900 CVE-2026-0988
                        CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11822 CVE-2026-11824
                        CVE-2026-11979 CVE-2026-12912 CVE-2026-1484 CVE-2026-1485 CVE-2026-1489
                        CVE-2026-1757 CVE-2026-22693 CVE-2026-24401 CVE-2026-25727 CVE-2026-27447
                        CVE-2026-2781 CVE-2026-33845 CVE-2026-33846 CVE-2026-34933 CVE-2026-34978
                        CVE-2026-34979 CVE-2026-34980 CVE-2026-34990 CVE-2026-36849 CVE-2026-3833
                        CVE-2026-39314 CVE-2026-39316 CVE-2026-40393 CVE-2026-42009 CVE-2026-42010
                        CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015
                        CVE-2026-4775 CVE-2026-4775 CVE-2026-50593 CVE-2026-5201 CVE-2026-5260
                        CVE-2026-5419 CVE-2026-56109 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012
                        CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 
-----------------------------------------------------------------

The container suse/kiosk/xorg-client was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2018:1476-1
Released:    Thu Aug  2 14:20:03 2018
Summary:     Security update for cups
Type:        security
Severity:    moderate
References:  1096405,1096406,1096407,1096408,CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183
This update for cups fixes the following issues:

The following security vulnerabilities were fixed:

- Fixed a local privilege escalation to root and sandbox bypasses in the
  scheduler
- CVE-2018-4180: Fixed a local privilege escalation to root in dnssd backend
  (bsc#1096405)
- CVE-2018-4181: Limited local file reads as root via cupsd.conf include
  directive (bsc#1096406)
- CVE-2018-4182: Fixed a sandbox bypass due to insecure error handling
  (bsc#1096407)
- CVE-2018-4183: Fixed a sandbox bypass due to profile misconfiguration
  (bsc#1096408)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2018:2882-1
Released:    Mon Dec 10 08:07:44 2018
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1115750,CVE-2018-4700
This update for cups fixes the following issues:

Security issue fixed:

- CVE-2018-4700: Fixed extremely predictable cookie generation that is effectively breaking the CSRF protection of the CUPS web interface (bsc#1115750).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2018:3044-1
Released:    Fri Dec 21 18:47:21 2018
Summary:     Security update for MozillaFirefox, mozilla-nspr and mozilla-nss
Type:        security
Severity:    important
References:  1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498
This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues:

Issues fixed in MozillaFirefox:

- Update to Firefox ESR 60.4 (bsc#1119105)
- CVE-2018-17466: Fixed a buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11
- CVE-2018-18492: Fixed a use-after-free with select element
- CVE-2018-18493: Fixed a buffer overflow in accelerated 2D canvas with Skia
- CVE-2018-18494: Fixed a Same-origin policy violation using location attribute and performance.getEntries
  to steal cross-origin URLs
- CVE-2018-18498: Fixed a integer overflow when calculating buffer sizes for images
- CVE-2018-12405: Fixed a few memory safety bugs

Issues fixed in mozilla-nss:

- Update to NSS 3.40.1 (bsc#1119105)
- CVE-2018-12404: Fixed a cache side-channel variant of the Bleichenbacher attack (bsc#1119069)
- CVE-2018-12384: Fixed an issue in the SSL handshake. NSS responded to an
  SSLv2-compatible ClientHello with a ServerHello that had an all-zero random. (bsc#1106873)
- CVE-2018-0495: Fixed a memory-cache side-channel attack with ECDSA signatures (bsc#1097410)
- Fixed a decryption failure during FFDHE key exchange
- Various security fixes in the ASN.1 code

Issues fixed in mozilla-nspr:

- Update mozilla-nspr to 4.20 (bsc#1119105)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:608-1
Released:    Wed Mar 13 15:21:02 2019
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1118118
This update for cups fixes the following issues:

- Fixed validation of UTF-8 filenames to avoid crashes (bsc#1118118)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:788-1
Released:    Thu Mar 28 11:55:06 2019
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1119687,CVE-2018-20346
This update for sqlite3 to version 3.27.2 fixes the following issue:

Security issue fixed: 

- CVE-2018-20346: Fixed a remote code execution vulnerability in FTS3 (Magellan) (bsc#1119687).

Release notes: https://www.sqlite.org/releaselog/3_27_2.html

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:1040-1
Released:    Thu Apr 25 17:09:21 2019
Summary:     Security update for samba
Type:        security
Severity:    important
References:  1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880
This update for samba fixes the following issues:

Security issue fixed:

- CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060).


ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686):

- Out of bound read in ldb_wildcard_compare
- Hold at most 10 outstanding paged result cookies
- Put 'results_store' into a doubly linked list
- Refuse to build Samba against a newer minor version of ldb


Non-security issues fixed:

- Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377).
- Abide to the load_printers parameter in smb.conf (bsc#1124223).
- Provide the 32bit samba winbind PAM module and its dependend 32bit libraries.
  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:1127-1
Released:    Thu May  2 09:39:24 2019
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1130325,1130326,CVE-2019-9936,CVE-2019-9937
This update for sqlite3 to version 3.28.0 fixes the following issues:

Security issues fixed:

- CVE-2019-9936: Fixed a heap-based buffer over-read, when running fts5 prefix
  queries inside transaction (bsc#1130326).
- CVE-2019-9937: Fixed a denial of service related to interleaving reads and writes in
  a single transaction with an fts5 virtual table (bsc#1130325).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:1372-1
Released:    Tue May 28 16:53:28 2019
Summary:     Security update for libtasn1
Type:        security
Severity:    moderate
References:  1105435,CVE-2018-1000654
This update for libtasn1 fixes the following issues:

Security issue fixed:

- CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:2142-1
Released:    Wed Aug 14 18:14:04 2019
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1141322

  
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.45 (bsc#1141322) :

* New function in pk11pub.h: PK11_FindRawCertsWithSubject
* The following CA certificates were Removed:
  CN = Certinomis - Root CA (bmo#1552374)
* Implement Delegated Credentials (draft-ietf-tls-subcerts) (bmo#1540403)
  This adds a new experimental function SSL_DelegateCredential
  Note: In 3.45, selfserv does not yet support delegated credentials (See bmo#1548360).
  Note: In 3.45 the SSLChannelInfo is left unmodified, while an upcoming change in 3.46 will set SSLChannelInfo.authKeyBits to that of the delegated credential for better policy enforcement (See bmo#1563078).
* Replace ARM32 Curve25519 implementation with one from fiat-crypto (bmo#1550579)
* Expose a function PK11_FindRawCertsWithSubject for finding certificates with a given subject on a given slot (bmo#1552262)
* Add IPSEC IKE support to softoken (bmo#1546229)
* Add support for the Elbrus lcc compiler (<=1.23) (bmo#1554616)
* Expose an external clock for SSL (bmo#1543874)
  This adds new experimental functions: SSL_SetTimeFunc, 
  SSL_CreateAntiReplayContext, SSL_SetAntiReplayContext, and 
  SSL_ReleaseAntiReplayContext.
  The experimental function SSL_InitAntiReplay is removed.
* Various changes in response to the ongoing FIPS review (bmo#1546477)
  Note: The source package size has increased substantially due to the new FIPS test vectors. This will likely prompt follow-on work, but please accept our apologies in the meantime.

mozilla-nspr was updated to version 4.21

* Changed prbit.h to use builtin function on aarch64.
* Removed Gonk/B2G references.  


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:2533-1
Released:    Thu Oct  3 15:02:50 2019
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1150137,CVE-2019-16168
This update for sqlite3 fixes the following issues:

Security issue fixed:

- CVE-2019-16168: Fixed improper validation of sqlite_stat1 field that could lead to denial of service (bsc#1150137).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3030-1
Released:    Thu Nov 21 19:11:25 2019
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1146358,1146359,CVE-2019-8675,CVE-2019-8696
This update for cups fixes the following issues:
	  
- CVE-2019-8675: Fixed a stack buffer overflow in libcups's asn1_get_type function(bsc#1146358). 
- CVE-2019-8696: Fixed a stack buffer overflow in libcups's asn1_get_packed function (bsc#1146359).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3395-1
Released:    Mon Dec 30 14:05:06 2019
Summary:     Security update for mozilla-nspr, mozilla-nss
Type:        security
Severity:    moderate
References:  1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.47.1:

Security issues fixed:

- CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819).
- CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527).
- CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322).

mozilla-nspr was updated to version 4.23:

- Whitespace in C files was cleaned up and no longer uses tab characters for indenting.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1083-1
Released:    Thu Apr 23 11:31:23 2020
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1168422,CVE-2020-3898
This update for cups fixes the following issues:

- CVE-2020-3898: Fixed a heap buffer overflow in ppdFindOption() (bsc#1168422).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1677-1
Released:    Thu Jun 18 18:16:39 2020
Summary:     Security update for mozilla-nspr, mozilla-nss
Type:        security
Severity:    important
References:  1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to version 3.53

- CVE-2020-12399: Fixed a timing attack on DSA signature generation (bsc#1171978).
- CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819).
Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes

mozilla-nspr to version 4.25

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:3091-1
Released:    Thu Oct 29 16:35:37 2020
Summary:     Security update for MozillaThunderbird and mozilla-nspr
Type:        security
Severity:    important
References:  1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969
This update for MozillaThunderbird and mozilla-nspr fixes the following issues:

- Mozilla Thunderbird 78.4
  * new: MailExtensions: browser.tabs.sendMessage API added
  * new: MailExtensions: messageDisplayScripts API added
  * changed: Yahoo and AOL mail users using password authentication will be migrated to OAuth2
  * changed: MailExtensions: messageDisplay APIs extended to support multiple selected messages
  * changed: MailExtensions: compose.begin functions now support creating a message with attachments
  * fixed: Thunderbird could freeze when updating global search index
  * fixed: Multiple issues with handling of self-signed SSL certificates addressed
  * fixed: Recipient address fields in compose window could expand to fill all available space
  * fixed: Inserting emoji characters in message compose window caused unexpected behavior
  * fixed: Button to restore default folder icon color was not keyboard accessible
  * fixed: Various keyboard navigation fixes
  * fixed: Various color-related theme fixes
  * fixed: MailExtensions: Updating attachments with onBeforeSend.addListener() did not work
  MFSA 2020-47 (bsc#1177977)
  * CVE-2020-15969 Use-after-free in usersctp
  * CVE-2020-15683 Memory safety bugs fixed in Thunderbird 78.4
- Mozilla Thunderbird 78.3.3
  * OpenPGP: Improved support for encrypting with subkeys
  * OpenPGP message status icons were not visible in message header pane
  * Creating a new calendar event did not require an event title
- Mozilla Thunderbird 78.3.2 (bsc#1176899)
  * OpenPGP: Improved support for encrypting with subkeys
  * OpenPGP: Encrypted messages with international characters were sometimes displayed incorrectly
  * Single-click deletion of recipient pills with middle mouse button restored
  * Searching an address book list did not display results
  * Dark mode, high contrast, and Windows theming fixes
- Mozilla Thunderbird 78.3.1
  * fix crash in nsImapProtocol::CreateNewLineFromSocket
- Mozilla Thunderbird 78.3.0
  MFSA 2020-44 (bsc#1176756)
  * CVE-2020-15677 Download origin spoofing via redirect
  * CVE-2020-15676 XSS when pasting attacker-controlled data into a contenteditable element
  * CVE-2020-15678 When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after- free scenario
  * CVE-2020-15673 Memory safety bugs fixed in Thunderbird 78.3

- update mozilla-nspr to version 4.25.1
  * The macOS platform code for shared library loading was
    changed to support macOS 11.
  * Dependency needed for the MozillaThunderbird udpate

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:285-1
Released:    Tue Feb  2 13:08:54 2021
Summary:     Security update for cups
Type:        security
Severity:    moderate
References:  1170671,1180520,CVE-2019-8842,CVE-2020-10001
This update for cups fixes the following issues:

- CVE-2020-10001: Fixed an out-of-bounds read in the ippReadIO function (bsc#1180520).
- CVE-2019-8842: Fixed an out-of-bounds read in an extension field (bsc#1170671).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:1007-1
Released:    Thu Apr  1 17:47:20 2021
Summary:     Security update for MozillaFirefox
Type:        security
Severity:    important
References:  1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987
This update for MozillaFirefox fixes the following issues:

- Firefox was updated to 78.9.0 ESR  (MFSA 2021-11, bsc#1183942)
  * CVE-2021-23981: Texture upload into an unbound backing buffer resulted in an out-of-bound read
  * CVE-2021-23982: Internal network hosts could have been probed by a malicious webpage
  * CVE-2021-23984: Malicious extensions could have spoofed popup information
  * CVE-2021-23987: Memory safety bugs 	  

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:1021-1
Released:    Tue Apr  6 14:30:30 2021
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1175960
This update for cups fixes the following issues:

- Fixed the web UI kerberos authentication (bsc#1175960)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:1454-1
Released:    Fri Apr 30 09:22:26 2021
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1184161,CVE-2021-25317
This update for cups fixes the following issues:

- CVE-2021-25317: ownership of /var/log/cups could allow privilege escalation from lp user to root via symlink attacks (bsc#1184161)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:2320-1
Released:    Wed Jul 14 17:01:06 2021
Summary:     Security update for sqlite3
Type:        security
Severity:    important
References:  1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327
This update for sqlite3 fixes the following issues:

- Update to version 3.36.0
- CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener
  optimization (bsc#1173641)
- CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in
  isAuxiliaryVtabOperator (bsc#1164719)
- CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error (bsc#1160439)
- CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input (bsc#1160438)
- CVE-2019-19923: improper handling  of  certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer
  dereference (bsc#1160309)
- CVE-2019-19924: improper error handling in sqlite3WindowRewrite() (bsc#1159850)
- CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive (bsc#1159847)
- CVE-2019-19926: improper handling  of certain errors during parsing  multiSelect in select.c (bsc#1159715)
- CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference
  (bsc#1159491)
- CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with
  a shadow table name (bsc#1158960)
- CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated
  columns (bsc#1158959)
- CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views
  in conjunction with ALTER TABLE statements (bsc#1158958)
- CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column,
  which allows attackers to cause a denial of service (bsc#1158812)
- CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a
  sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage (bsc#1157818)
- CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability (bsc#928701)
- CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names (bsc#928700)
- CVE-2020-13434: integer overflow in sqlite3_str_vappendf (bsc#1172115)
- CVE-2020-13630: (bsc#1172234: use-after-free in fts3EvalNextRow
- CVE-2020-13631: virtual table allowed to be renamed to one of its shadow tables (bsc#1172236)
- CVE-2020-13632: NULL pointer dereference via crafted matchinfo() query (bsc#1172240)
- CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:3115-1
Released:    Thu Sep 16 14:04:26 2021
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829
This update for mozilla-nspr fixes the following issues:

mozilla-nspr was updated to version 4.32:

* implement new socket option PR_SockOpt_DontFrag
* support larger DNS records by increasing the default buffer
  size for DNS queries 
* Lock access to PRCallOnceType members in PR_CallOnce* for
  thread safety bmo#1686138
* PR_GetSystemInfo supports a new flag PR_SI_RELEASE_BUILD to get
  information about the operating system build version.


Mozilla NSS was updated to version 3.68:

* bmo#1713562 - Fix test leak.
* bmo#1717452 - NSS 3.68 should depend on NSPR 4.32.
* bmo#1693206 - Implement PKCS8 export of ECDSA keys.
* bmo#1712883 - DTLS 1.3 draft-43.
* bmo#1655493 - Support SHA2 HW acceleration using Intel SHA Extension.
* bmo#1713562 - Validate ECH public names.
* bmo#1717610 - Add function to get seconds from epoch from pkix::Time.

update to NSS 3.67

* bmo#1683710 - Add a means to disable ALPN.
* bmo#1715720 - Fix nssckbi version number in NSS 3.67 (was supposed to be incremented in 3.66).
* bmo#1714719 - Set NSS_USE_64 on riscv64 target when using GYP/Ninja.
* bmo#1566124 - Fix counter increase in ppc-gcm-wrap.c.
* bmo#1566124 - Fix AES_GCM mode on ppc64le for messages of length more than 255-byte.

update to NSS 3.66

* bmo#1710716 - Remove Expired Sonera Class2 CA from NSS.
* bmo#1710716 - Remove Expired Root Certificates from NSS - QuoVadis Root Certification Authority.
* bmo#1708307 - Remove Trustis FPS Root CA from NSS.
* bmo#1707097 - Add Certum Trusted Root CA to NSS.
* bmo#1707097 - Add Certum EC-384 CA to NSS.
* bmo#1703942 - Add ANF Secure Server Root CA to NSS.
* bmo#1697071 - Add GLOBALTRUST 2020 root cert to NSS.
* bmo#1712184 - NSS tools manpages need to be updated to reflect that sqlite is the default database.
* bmo#1712230 - Don't build ppc-gcm.s with clang integrated assembler.
* bmo#1712211 - Strict prototype error when trying to compile nss code that includes blapi.h.
* bmo#1710773 - NSS needs FIPS 180-3 FIPS indicators.
* bmo#1709291 - Add VerifyCodeSigningCertificateChain.

update to NSS 3.65

* bmo#1709654 - Update for NetBSD configuration.
* bmo#1709750 - Disable HPKE test when fuzzing.
* bmo#1566124 - Optimize AES-GCM for ppc64le.
* bmo#1699021 - Add AES-256-GCM to HPKE.
* bmo#1698419 - ECH -10 updates.
* bmo#1692930 - Update HPKE to final version.
* bmo#1707130 - NSS should use modern algorithms in PKCS#12 files by default.
* bmo#1703936 - New coverity/cpp scanner errors.
* bmo#1697303 - NSS needs to update it's csp clearing to FIPS 180-3 standards.
* bmo#1702663 - Need to support RSA PSS with Hashing PKCS #11 Mechanisms.
* bmo#1705119 - Deadlock when using GCM and non-thread safe tokens.

update to NSS 3.64

* bmo#1705286 - Properly detect mips64.
* bmo#1687164 - Introduce NSS_DISABLE_CRYPTO_VSX and
		disable_crypto_vsx.
* bmo#1698320 - replace __builtin_cpu_supports('vsx') with
		ppc_crypto_support() for clang.
* bmo#1613235 - Add POWER ChaCha20 stream cipher vector
		acceleration.

Fixed in 3.63

* bmo#1697380 - Make a clang-format run on top of helpful contributions.
* bmo#1683520 - ECCKiila P384, change syntax of nested structs
		initialization to prevent build isses with GCC 4.8.
* bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual
		scalar multiplication.
* bmo#1683520 - ECCKiila P521, change syntax of nested structs
		initialization to prevent build isses with GCC 4.8.
* bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual
		scalar multiplication.
* bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683.
* bmo#1694214 - tstclnt can't enable middlebox compat mode.
* bmo#1694392 - NSS does not work with PKCS #11 modules not supporting
		profiles.
* bmo#1685880 - Minor fix to prevent unused variable on early return.
* bmo#1685880 - Fix for the gcc compiler version 7 to support setenv
		with nss build.
* bmo#1693217 - Increase nssckbi.h version number for March 2021 batch
		of root CA changes, CA list version 2.48.
* bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's
		'Chambers of Commerce' and 'Global Chambersign' roots.
* bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER.
* bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS.
* bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS.
* bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs
		from NSS.
* bmo#1687822 - Turn off Websites trust bit for the “Staat der
		Nederlanden Root CA - G3” root cert in NSS.
* bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce
		Root - 2008' and 'Global Chambersign Root - 2008’.
* bmo#1694291 - Tracing fixes for ECH.

update to NSS 3.62

* bmo#1688374 - Fix parallel build NSS-3.61 with make
* bmo#1682044 - pkix_Build_GatherCerts() + pkix_CacheCert_Add()
		can corrupt 'cachedCertTable'
* bmo#1690583 - Fix CH padding extension size calculation
* bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail
* bmo#1690421 - Install packaged libabigail in docker-builds image
* bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing
* bmo#1674819 - Fixup a51fae403328, enum type may be signed
* bmo#1681585 - Add ECH support to selfserv
* bmo#1681585 - Update ECH to Draft-09
* bmo#1678398 - Add Export/Import functions for HPKE context
* bmo#1678398 - Update HPKE to draft-07

update to NSS 3.61

* bmo#1682071 - Fix issue with IKE Quick mode deriving incorrect key
		values under certain conditions.
* bmo#1684300 - Fix default PBE iteration count when NSS is compiled
		with NSS_DISABLE_DBM.
* bmo#1651411 - Improve constant-timeness in RSA operations.
* bmo#1677207 - Upgrade Google Test version to latest release.
* bmo#1654332 - Add aarch64-make target to nss-try.

Update to NSS 3.60.1:

Notable changes in NSS 3.60:
* TLS 1.3 Encrypted Client Hello (draft-ietf-tls-esni-08) support
  has been added, replacing the previous ESNI (draft-ietf-tls-esni-01)
  implementation. See bmo#1654332 for more information.
* December 2020 batch of Root CA changes, builtins library updated
  to version 2.46. See bmo#1678189, bmo#1678166, and bmo#1670769
  for more information.

Update to NSS 3.59.1:

* bmo#1679290 - Fix potential deadlock with certain third-party
		PKCS11 modules

Update to NSS 3.59:

Notable changes:

* Exported two existing functions from libnss:
  CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData

Bugfixes

* bmo#1607449 - Lock cert->nssCertificate to prevent a potential data race
* bmo#1672823 - Add Wycheproof test cases for HMAC, HKDF, and DSA
* bmo#1663661 - Guard against NULL token in nssSlot_IsTokenPresent
* bmo#1670835 - Support enabling and disabling signatures via Crypto Policy
* bmo#1672291 - Resolve libpkix OCSP failures on SHA1 self-signed
		root certs when SHA1 signatures are disabled.
* bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to
		solve some test intermittents
* bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in
		our CVE-2020-25648 fix that broke purple-discord
		(boo#1179382)
* bmo#1666891 - Support key wrap/unwrap with RSA-OAEP
* bmo#1667989 - Fix gyp linking on Solaris
* bmo#1668123 - Export CERT_AddCertToListHeadWithData and
		CERT_AddCertToListTailWithData from libnss
* bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA
* bmo#1663091 - Remove unnecessary assertions in the streaming
		ASN.1 decoder that affected decoding certain PKCS8
		private keys when using NSS debug builds
*  bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS.

update to NSS 3.58

Bugs fixed:

* bmo#1641480 (CVE-2020-25648)
  Tighten CCS handling for middlebox compatibility mode.
* bmo#1631890 - Add support for Hybrid Public Key Encryption
  (draft-irtf-cfrg-hpke) support for TLS Encrypted Client Hello
  (draft-ietf-tls-esni).
* bmo#1657255 - Add CI tests that disable SHA1/SHA2 ARM crypto
  extensions.
* bmo#1668328 - Handle spaces in the Python path name when using
  gyp on Windows.
* bmo#1667153 - Add PK11_ImportDataKey for data object import.
* bmo#1665715 - Pass the embedded SCT list extension (if present)
  to TrustDomain::CheckRevocation instead of the notBefore value.

update to NSS 3.57

* The following CA certificates were Added:
  bmo#1663049 - CN=Trustwave Global Certification Authority
      SHA-256 Fingerprint: 97552015F5DDFC3C8788C006944555408894450084F100867086BC1A2BB58DC8
  bmo#1663049 - CN=Trustwave Global ECC P256 Certification Authority
      SHA-256 Fingerprint: 945BBC825EA554F489D1FD51A73DDF2EA624AC7019A05205225C22A78CCFA8B4
  bmo#1663049 - CN=Trustwave Global ECC P384 Certification Authority
      SHA-256 Fingerprint: 55903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097
* The following CA certificates were Removed:
  bmo#1651211 - CN=EE Certification Centre Root CA
      SHA-256 Fingerprint: 3E84BA4342908516E77573C0992F0979CA084E4685681FF195CCBA8A229B8A76
  bmo#1656077 - O=Government Root Certification Authority; C=TW
      SHA-256 Fingerprint: 7600295EEFE85B9E1FD624DB76062AAAAE59818A54D2774CD4C0B2C01131E1B3
* Trust settings for the following CA certificates were Modified:
  bmo#1653092 - CN=OISTE WISeKey Global Root GA CA
      Websites (server authentication) trust bit removed.
* https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes

update to NSS 3.56

Notable changes

* bmo#1650702 - Support SHA-1 HW acceleration on ARMv8
* bmo#1656981 - Use MPI comba and mulq optimizations on x86-64 MacOS.
* bmo#1654142 - Add CPU feature detection for Intel SHA extension.
* bmo#1648822 - Add stricter validation of DH keys in FIPS mode.
* bmo#1656986 - Properly detect arm64 during GYP build architecture
		detection.
* bmo#1652729 - Add build flag to disable RC2 and relocate to
		lib/freebl/deprecated.
* bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay.
* bmo#1588941 - Send empty certificate message when scheme selection
		fails.
* bmo#1652032 - Fix failure to build in Windows arm64 makefile
		cross-compilation.
* bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent.
* bmo#1653975 - Fix 3.53 regression by setting 'all' as the default
		makefile target.
* bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert.
* bmo#1659814 - Fix interop.sh failures with newer tls-interop
		commit and dependencies.
* bmo#1656519 - NSPR dependency updated to 4.28

update to NSS 3.55

Notable changes
* P384 and P521 elliptic curve implementations are replaced with
  verifiable implementations from Fiat-Crypto [0] and ECCKiila [1].
* PK11_FindCertInSlot is added. With this function, a given slot
  can be queried with a DER-Encoded certificate, providing performance
  and usability improvements over other mechanisms. (bmo#1649633)
* DTLS 1.3 implementation is updated to draft-38. (bmo#1647752)

Relevant Bugfixes

* bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and
  P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila.
* bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature.
* bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding.
* bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part
  ChaCha20 (which was not functioning correctly) and more strictly
  enforce tag length.
* bmo#1649648 - Don't memcpy zero bytes (sanitizer fix).
* bmo#1649316 - Don't memcpy zero bytes (sanitizer fix).
* bmo#1649322 - Don't memcpy zero bytes (sanitizer fix).
* bmo#1653202 - Fix initialization bug in blapitest when compiled
  with NSS_DISABLE_DEPRECATED_SEED.
* bmo#1646594 - Fix AVX2 detection in makefile builds.
* bmo#1649633 - Add PK11_FindCertInSlot to search a given slot
  for a DER-encoded certificate.
* bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo.
* bmo#1647752 - Update DTLS 1.3 implementation to draft-38.
* bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI.
* bmo#1649226 - Add Wycheproof ECDSA tests.
* bmo#1637222 - Consistently enforce IV requirements for DES and 3DES.
* bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in
  RSA_CheckSignRecover.
* bmo#1646324 - Advertise PKCS#1 schemes for certificates in the
  signature_algorithms extension.

update to NSS 3.54

Notable changes

* Support for TLS 1.3 external pre-shared keys (bmo#1603042).
* Use ARM Cryptography Extension for SHA256, when available
  (bmo#1528113)
* The following CA certificates were Added:
  bmo#1645186 - certSIGN Root CA G2.
  bmo#1645174 - e-Szigno Root CA 2017.
  bmo#1641716 - Microsoft ECC Root Certificate Authority 2017.
  bmo#1641716 - Microsoft RSA Root Certificate Authority 2017.
* The following CA certificates were Removed:
  bmo#1645199 - AddTrust Class 1 CA Root.
  bmo#1645199 - AddTrust External CA Root.
  bmo#1641718 - LuxTrust Global Root 2.
  bmo#1639987 - Staat der Nederlanden Root CA - G2.
  bmo#1618402 - Symantec Class 2 Public Primary Certification Authority - G4.
  bmo#1618402 - Symantec Class 1 Public Primary Certification Authority - G4.
  bmo#1618402 - VeriSign Class 3 Public Primary Certification Authority - G3.

* A number of certificates had their Email trust bit disabled.
  See bmo#1618402 for a complete list.

Bugs fixed

* bmo#1528113 - Use ARM Cryptography Extension for SHA256.
* bmo#1603042 - Add TLS 1.3 external PSK support.
* bmo#1642802 - Add uint128 support for HACL* curve25519 on Windows.
* bmo#1645186 - Add 'certSIGN Root CA G2' root certificate.
* bmo#1645174 - Add Microsec's 'e-Szigno Root CA 2017' root certificate.
* bmo#1641716 - Add Microsoft's non-EV root certificates.
* bmo1621151 - Disable email trust bit for 'O=Government
	       Root Certification Authority; C=TW' root.
* bmo#1645199 - Remove AddTrust root certificates.
* bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate.
* bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root
		certificate.
* bmo#1618402 - Remove Symantec root certificates and disable email trust
		bit.
* bmo#1640516 - NSS 3.54 should depend on NSPR 4.26.
* bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c.
* bmo#1642153 - Fix infinite recursion building NSS.
* bmo#1642638 - Fix fuzzing assertion crash.
* bmo#1642871 - Enable SSL_SendSessionTicket after resumption.
* bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs.
* bmo#1643557 - Fix numerous compile warnings in NSS.
* bmo#1644774 - SSL gtests to use ClearServerCache when resetting
		self-encrypt keys.
* bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c.
* bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:1659-1
Released:    Fri May 13 15:41:32 2022
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1189517,1195115
This update for cups fixes the following issues:

- CUPS printservice takes much longer than before with a big number of printers (bsc#1189517)
- CUPS PreserveJobHistory doesn't work with seconds (bsc#1195115)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:1861-1
Released:    Thu May 26 12:07:40 2022
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1199474,CVE-2022-26691
This update for cups fixes the following issues:

- CVE-2022-26691: Fixed an authentication bypass and code execution vulnerability (bsc#1199474)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:1898-1
Released:    Tue May 31 18:03:55 2022
Summary:     Security update for fribidi
Type:        security
Severity:    moderate
References:  1196147,1196148,1196150,CVE-2022-25308,CVE-2022-25309,CVE-2022-25310
This update for fribidi fixes the following issues:

- CVE-2022-25308: Fixed stack out of bounds read (bsc#1196147).
- CVE-2022-25309: Fixed heap-buffer-overflow in fribidi_cap_rtl_to_unicode (bsc#1196148).
- CVE-2022-25310: Fixed NULL pointer dereference in fribidi_remove_bidi_marks (bsc#1196150).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:2533-1
Released:    Fri Jul 22 17:37:15 2022
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
This update for mozilla-nss fixes the following issues:

Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:

- Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). 
- FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck()
  (bsc#1198980).
- FIPS: mark algorithms as approved/non-approved according to security policy
  (bsc#1191546, bsc#1201298).
- FIPS: remove hard disabling of unapproved algorithms. This requirement is now
  fulfilled by the service level indicator (bsc#1200325).
- Run test suite at build time, and make it pass (bsc#1198486).
- FIPS: skip algorithms that are hard disabled in FIPS mode.
- Prevent expired PayPalEE cert from failing the tests.
- Allow checksumming to be disabled, but only if we entered FIPS mode
  due to NSS_FIPS being set, not if it came from /proc.
- FIPS: Make the PBKDF known answer test compliant with NIST SP800-132.
- Update FIPS validation string to version-release format.
- FIPS: remove XCBC MAC from list of FIPS approved algorithms.
- Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID
  for build.
- FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080).
- FIPS: allow testing of unapproved algorithms (bsc#1192228).
- FIPS: add version indicators. (bmo#1729550, bsc#1192086).
- FIPS: fix some secret clearing (bmo#1697303, bsc#1192087).

Version update to NSS 3.79:

- Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls.
- Update mercurial in clang-format docker image.
- Use of uninitialized pointer in lg_init after alloc fail.
- selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo.
- Add SECMOD_LockedModuleHasRemovableSlots.
- Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP.
- Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts.
- TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version.
- Correct invalid record inner and outer content type alerts.
- NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding.
- improve error handling after nssCKFWInstance_CreateObjectHandle.
- Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple.
- NSS 3.79 should depend on NSPR 4.34   

Version update to NSS 3.78.1:

- Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple

Version update to NSS 3.78:

- Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests.
- Reworked overlong record size checks and added TLS1.3 specific boundaries.
- Add ECH Grease Support to tstclnt
- Add a strict variant of moz::pkix::CheckCertHostname.
- Change SSL_REUSE_SERVER_ECDHE_KEY default to false.
- Make SEC_PKCS12EnableCipher succeed
- Update zlib in NSS to 1.2.12.

Version update to NSS 3.77:

- Fix link to TLS page on wireshark wiki
- Add two D-TRUST 2020 root certificates.
- Add Telia Root CA v2 root certificate.
- Remove expired explicitly distrusted certificates from certdata.txt.
- support specific RSA-PSS parameters in mozilla::pkix
- Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate.
- Remove token member from NSSSlot struct.
- Provide secure variants of mpp_pprime and mpp_make_prime.
- Support UTF-8 library path in the module spec string.
- Update nssUTF8_Length to RFC 3629 and fix buffer overrun.
- Update googletest to 1.11.0
- Add SetTls13GreaseEchSize to experimental API.
- TLS 1.3 Illegal legacy_version handling/alerts.
- Fix calculation of ECH HRR Transcript.
- Allow ld path to be set as environment variable.
- Ensure we don't read uninitialized memory in ssl gtests.
- Fix DataBuffer Move Assignment.
- internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3
- rework signature verification in mozilla::pkix

Version update to NSS 3.76.1

- Remove token member from NSSSlot struct.
- Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots.
- Check return value of PK11Slot_GetNSSToken.
- Use Wycheproof JSON for RSASSA-PSS
- Add SHA256 fingerprint comments to old certdata.txt entries.
- Avoid truncating files in nss-release-helper.py.
- Throw illegal_parameter alert for illegal extensions in handshake message.

Version update to NSS 3.75

- Make DottedOIDToCode.py compatible with python3.
- Avoid undefined shift in SSL_CERT_IS while fuzzing.
- Remove redundant key type check.
- Update ABI expectations to match ECH changes.
- Enable CKM_CHACHA20.
- check return on NSS_NoDB_Init and NSS_Shutdown.
- Run ECDSA test vectors from bltest as part of the CI tests.
- Add ECDSA test vectors to the bltest command line tool.
- Allow to build using clang's integrated assembler.
- Allow to override python for the build.
- test HKDF output rather than input.
- Use ASSERT macros to end failed tests early.
- move assignment operator for DataBuffer.
- Add test cases for ECH compression and unexpected extensions in SH.
- Update tests for ECH-13.
- Tidy up error handling.
- Add tests for ECH HRR Changes.
- Server only sends GREASE HRR extension if enabled by preference.
- Update generation of the Associated Data for ECH-13.
- When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello.
- Allow for compressed, non-contiguous, extensions.
- Scramble the PSK extension in CHOuter.
- Split custom extension handling for ECH.
- Add ECH-13 HRR Handling.
- Client side ECH padding.
- Stricter ClientHelloInner Decompression.
- Remove ECH_inner extension, use new enum format.
- Update the version number for ECH-13 and adjust the ECHConfig size.

Version update to NSS 3.74

- mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses
- Ensure clients offer consistent ciphersuites after HRR
- NSS does not properly restrict server keys based on policy
- Set nssckbi version number to 2.54
- Replace Google Trust Services LLC (GTS) R4 root certificate
- Replace Google Trust Services LLC (GTS) R3 root certificate
- Replace Google Trust Services LLC (GTS) R2 root certificate
- Replace Google Trust Services LLC (GTS) R1 root certificate
- Replace GlobalSign ECC Root CA R4
- Remove Expired Root Certificates - DST Root CA X3
- Remove Expiring Cybertrust Global Root and GlobalSign root certificates
- Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate
- Add iTrusChina ECC root certificate
- Add iTrusChina RSA root certificate
- Add ISRG Root X2 root certificate
- Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate
- Avoid a clang 13 unused variable warning in opt build
- Check for missing signedData field
- Ensure DER encoded signatures are within size limits

- enable key logging option (boo#1195040)

Version update to NSS 3.73.1:

- Add SHA-2 support to mozilla::pkix's OSCP implementation

Version update to NSS 3.73

- check for missing signedData field.
- Ensure DER encoded signatures are within size limits.
- NSS needs FiPS 140-3 version indicators.
- pkix_CacheCert_Lookup doesn't return cached certs
- sunset Coverity from NSS

Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures

Version update to NSS 3.72

- Fix nsinstall parallel failure.
- Increase KDF cache size to mitigate perf regression in about:logins

Version update to NSS 3.71

- Set nssckbi version number to 2.52.
- Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py
- Import of PKCS#12 files with Camellia encryption is not supported
- Add HARICA Client ECC Root CA 2021.
- Add HARICA Client RSA Root CA 2021.
- Add HARICA TLS ECC Root CA 2021.
- Add HARICA TLS RSA Root CA 2021.
- Add TunTrust Root CA certificate to NSS.

Version update to NSS 3.70

- Update test case to verify fix.
- Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max
- Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback
- Avoid using a lookup table in nssb64d.
- Use HW accelerated SHA2 on AArch64 Big Endian.
- Change default value of enableHelloDowngradeCheck to true.
- Cache additional PBE entries.
- Read HPKE vectors from official JSON.

Version update to NSS 3.69.1:

- Disable DTLS 1.0 and 1.1 by default
- integrity checks in key4.db not happening on private components with AES_CBC

NSS 3.69:

- Disable DTLS 1.0 and 1.1 by default (backed out again)
- integrity checks in key4.db not happening on private components with AES_CBC (backed out again)
- SSL handling of signature algorithms ignores environmental invalid algorithms.
- sqlite 3.34 changed it's open semantics, causing nss failures.
- Gtest update changed the gtest reports, losing gtest details in all.sh reports.
- NSS incorrectly accepting 1536 bit DH primes in FIPS mode
- SQLite calls could timeout in starvation situations.
- Coverity/cpp scanner errors found in nss 3.67
- Import the NSS documentation from MDN in nss/doc.
- NSS using a tempdir to measure sql performance not active

Version Update to 3.68.4 (bsc#1200027)

- CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple.  (bmo#1767590)


Mozilla NSPR was updated to version 4.34:

* add an API that returns a preferred loopback IP on hosts that have two IP stacks available.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:2595-1
Released:    Fri Jul 29 16:00:42 2022
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741
This update for mozilla-nss fixes the following issues:

Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4:

- Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). 
- FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck()
  (bsc#1198980).
- FIPS: mark algorithms as approved/non-approved according to security policy
  (bsc#1191546, bsc#1201298).
- FIPS: remove hard disabling of unapproved algorithms. This requirement is now
  fulfilled by the service level indicator (bsc#1200325).
- Run test suite at build time, and make it pass (bsc#1198486).
- FIPS: skip algorithms that are hard disabled in FIPS mode.
- Prevent expired PayPalEE cert from failing the tests.
- Allow checksumming to be disabled, but only if we entered FIPS mode
  due to NSS_FIPS being set, not if it came from /proc.
- FIPS: Make the PBKDF known answer test compliant with NIST SP800-132.
- Update FIPS validation string to version-release format.
- FIPS: remove XCBC MAC from list of FIPS approved algorithms.
- Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID
  for build.
- FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080).
- FIPS: allow testing of unapproved algorithms (bsc#1192228).
- FIPS: add version indicators. (bmo#1729550, bsc#1192086).
- FIPS: fix some secret clearing (bmo#1697303, bsc#1192087).

Version update to NSS 3.79:

- Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls.
- Update mercurial in clang-format docker image.
- Use of uninitialized pointer in lg_init after alloc fail.
- selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo.
- Add SECMOD_LockedModuleHasRemovableSlots.
- Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP.
- Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts.
- TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version.
- Correct invalid record inner and outer content type alerts.
- NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding.
- improve error handling after nssCKFWInstance_CreateObjectHandle.
- Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple.
- NSS 3.79 should depend on NSPR 4.34   

Version update to NSS 3.78.1:

- Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple

Version update to NSS 3.78:

- Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests.
- Reworked overlong record size checks and added TLS1.3 specific boundaries.
- Add ECH Grease Support to tstclnt
- Add a strict variant of moz::pkix::CheckCertHostname.
- Change SSL_REUSE_SERVER_ECDHE_KEY default to false.
- Make SEC_PKCS12EnableCipher succeed
- Update zlib in NSS to 1.2.12.

Version update to NSS 3.77:

- Fix link to TLS page on wireshark wiki
- Add two D-TRUST 2020 root certificates.
- Add Telia Root CA v2 root certificate.
- Remove expired explicitly distrusted certificates from certdata.txt.
- support specific RSA-PSS parameters in mozilla::pkix
- Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate.
- Remove token member from NSSSlot struct.
- Provide secure variants of mpp_pprime and mpp_make_prime.
- Support UTF-8 library path in the module spec string.
- Update nssUTF8_Length to RFC 3629 and fix buffer overrun.
- Update googletest to 1.11.0
- Add SetTls13GreaseEchSize to experimental API.
- TLS 1.3 Illegal legacy_version handling/alerts.
- Fix calculation of ECH HRR Transcript.
- Allow ld path to be set as environment variable.
- Ensure we don't read uninitialized memory in ssl gtests.
- Fix DataBuffer Move Assignment.
- internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3
- rework signature verification in mozilla::pkix

Version update to NSS 3.76.1

- Remove token member from NSSSlot struct.
- Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots.
- Check return value of PK11Slot_GetNSSToken.
- Use Wycheproof JSON for RSASSA-PSS
- Add SHA256 fingerprint comments to old certdata.txt entries.
- Avoid truncating files in nss-release-helper.py.
- Throw illegal_parameter alert for illegal extensions in handshake message.

Version update to NSS 3.75

- Make DottedOIDToCode.py compatible with python3.
- Avoid undefined shift in SSL_CERT_IS while fuzzing.
- Remove redundant key type check.
- Update ABI expectations to match ECH changes.
- Enable CKM_CHACHA20.
- check return on NSS_NoDB_Init and NSS_Shutdown.
- Run ECDSA test vectors from bltest as part of the CI tests.
- Add ECDSA test vectors to the bltest command line tool.
- Allow to build using clang's integrated assembler.
- Allow to override python for the build.
- test HKDF output rather than input.
- Use ASSERT macros to end failed tests early.
- move assignment operator for DataBuffer.
- Add test cases for ECH compression and unexpected extensions in SH.
- Update tests for ECH-13.
- Tidy up error handling.
- Add tests for ECH HRR Changes.
- Server only sends GREASE HRR extension if enabled by preference.
- Update generation of the Associated Data for ECH-13.
- When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello.
- Allow for compressed, non-contiguous, extensions.
- Scramble the PSK extension in CHOuter.
- Split custom extension handling for ECH.
- Add ECH-13 HRR Handling.
- Client side ECH padding.
- Stricter ClientHelloInner Decompression.
- Remove ECH_inner extension, use new enum format.
- Update the version number for ECH-13 and adjust the ECHConfig size.

Version update to NSS 3.74

- mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses
- Ensure clients offer consistent ciphersuites after HRR
- NSS does not properly restrict server keys based on policy
- Set nssckbi version number to 2.54
- Replace Google Trust Services LLC (GTS) R4 root certificate
- Replace Google Trust Services LLC (GTS) R3 root certificate
- Replace Google Trust Services LLC (GTS) R2 root certificate
- Replace Google Trust Services LLC (GTS) R1 root certificate
- Replace GlobalSign ECC Root CA R4
- Remove Expired Root Certificates - DST Root CA X3
- Remove Expiring Cybertrust Global Root and GlobalSign root certificates
- Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate
- Add iTrusChina ECC root certificate
- Add iTrusChina RSA root certificate
- Add ISRG Root X2 root certificate
- Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate
- Avoid a clang 13 unused variable warning in opt build
- Check for missing signedData field
- Ensure DER encoded signatures are within size limits

- enable key logging option (boo#1195040)

Version update to NSS 3.73.1:

- Add SHA-2 support to mozilla::pkix's OSCP implementation

Version update to NSS 3.73

- check for missing signedData field.
- Ensure DER encoded signatures are within size limits.
- NSS needs FiPS 140-3 version indicators.
- pkix_CacheCert_Lookup doesn't return cached certs
- sunset Coverity from NSS

Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures

Version update to NSS 3.72

- Fix nsinstall parallel failure.
- Increase KDF cache size to mitigate perf regression in about:logins

Version update to NSS 3.71

- Set nssckbi version number to 2.52.
- Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py
- Import of PKCS#12 files with Camellia encryption is not supported
- Add HARICA Client ECC Root CA 2021.
- Add HARICA Client RSA Root CA 2021.
- Add HARICA TLS ECC Root CA 2021.
- Add HARICA TLS RSA Root CA 2021.
- Add TunTrust Root CA certificate to NSS.

Version update to NSS 3.70

- Update test case to verify fix.
- Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max
- Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback
- Avoid using a lookup table in nssb64d.
- Use HW accelerated SHA2 on AArch64 Big Endian.
- Change default value of enableHelloDowngradeCheck to true.
- Cache additional PBE entries.
- Read HPKE vectors from official JSON.

Version update to NSS 3.69.1:

- Disable DTLS 1.0 and 1.1 by default
- integrity checks in key4.db not happening on private components with AES_CBC

NSS 3.69:

- Disable DTLS 1.0 and 1.1 by default (backed out again)
- integrity checks in key4.db not happening on private components with AES_CBC (backed out again)
- SSL handling of signature algorithms ignores environmental invalid algorithms.
- sqlite 3.34 changed it's open semantics, causing nss failures.
- Gtest update changed the gtest reports, losing gtest details in all.sh reports.
- NSS incorrectly accepting 1536 bit DH primes in FIPS mode
- SQLite calls could timeout in starvation situations.
- Coverity/cpp scanner errors found in nss 3.67
- Import the NSS documentation from MDN in nss/doc.
- NSS using a tempdir to measure sql performance not active

Version Update to 3.68.4 (bsc#1200027)

- CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple.  (bmo#1767590)



-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:2901-1
Released:    Fri Aug 26 03:34:23 2022
Summary:     Recommended update for elfutils
Type:        recommended
Severity:    moderate
References:  
This update for elfutils fixes the following issues:

- Fix runtime dependency for devel package

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:2939-1
Released:    Mon Aug 29 14:49:17 2022
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1201298,1202645
This update for mozilla-nss fixes the following issues:

Update to NSS 3.79.1 (bsc#1202645)

* compare signature and signatureAlgorithm fields in legacy certificate verifier.
* Uninitialized value in cert_ComputeCertType.
* protect SFTKSlot needLogin with slotLock.
* avoid data race on primary password change.
* check for null template in sec_asn1{d,e}_push_state.

- FIPS: unapprove the rest of the DSA ciphers, keeping signature verification only (bsc#1201298).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:3241-1
Released:    Mon Sep 12 07:21:04 2022
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1201511
This update for cups fixes the following issues:

- Stuck print jobs being cancelled immediately, despite MaxJobTime being set to 0 (bsc#1201511)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:3307-1
Released:    Mon Sep 19 13:26:51 2022
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737
This update for sqlite3 fixes the following issues:

- CVE-2022-35737: Fixed an array-bounds overflow if billions of bytes are used in a string argument to a C API (bnc#1201783).
- CVE-2021-36690: Fixed an issue with the SQLite Expert extension when a column has no collating sequence (bsc#1189802).
  
- Package the Tcl bindings here again so that we only ship one copy of SQLite (bsc#1195773).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:3784-1
Released:    Wed Oct 26 18:03:28 2022
Summary:     Security update for libtasn1
Type:        security
Severity:    critical
References:  1204690,CVE-2021-46848
This update for libtasn1 fixes the following issues:

- CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:3873-1
Released:    Fri Nov  4 14:58:08 2022
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1191546,1198980,1201298,1202870,1204729
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nspr was updated to version 4.34.1:

* add file descriptor sanity checks in the NSPR poll function.

mozilla-nss was updated to NSS 3.79.2 (bsc#1204729):

* Bump minimum NSPR version to 4.34.1.
* Gracefully handle null nickname in CERT_GetCertNicknameWithValidity.

Other fixes that were applied:

- FIPS: Allow the use of DSA keys (verification only) (bsc#1201298).
- FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file
  (bsc#1198980).
- FIPS: Allow the use of longer symmetric keys via the service level indicator
  (bsc#1191546).
- FIPS: Prevent TLS sessions from getting flagged as non-FIPS (bsc#1191546).
- FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298).
- FIPS: Use libjitterentropy for entropy (bsc#1202870).
- FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:3958-1
Released:    Fri Nov 11 15:20:45 2022
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1191546,1198980,1201298,1202870,1204729
This update for mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.79.2 (bsc#1204729)

* Bump minimum NSPR version to 4.34.1.
* Gracefully handle null nickname in CERT_GetCertNicknameWithValidity.

- FIPS: Allow the use of DSA keys (verification only) (bsc#1201298).
- FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file
  (bsc#1198980).
- FIPS: Allow the use of longer symmetric keys via the service level indicator
  (bsc#1191546).
- FIPS: Export sftk_FIPSRepeatIntegrityCheck() correctly (bsc#1198980).
- FIPS: Prevent sessions from getting flagged as non-FIPS (bsc#1191546).
- FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298).
- FIPS: Enable userspace entropy gathering via libjitterentropy (bsc#1202870).
- FIPS: Prevent keys from getting flagged as non-FIPS and add remaining TLS mechanisms.
- FIPS: Use libjitterentropy for entropy. 
- FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:4492-1
Released:    Wed Dec 14 13:52:39 2022
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1191546,1198980,1201298
This update for mozilla-nss fixes the following issues:

- FIPS: Disapprove the creation of DSA keys, i.e. mark them as not-fips (bsc#1201298)
- FIPS: Allow the use SHA keygen mechs (bsc#1191546).
- FIPS: ensure abort() is called when the repeat integrity check fails (bsc#1198980).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:4628-1
Released:    Wed Dec 28 09:23:13 2022
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1206337,CVE-2022-46908
This update for sqlite3 fixes the following issues:

- CVE-2022-46908: Properly implement the azProhibitedFunctions protection mechanism, 
  when relying on --safe for execution of an untrusted CLI script (bsc#1206337).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:119-1
Released:    Fri Jan 20 10:28:07 2023
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1204272,1207038,CVE-2022-23491,CVE-2022-3479
This update for mozilla-nss fixes the following issues:

- CVE-2022-3479: Fixed a potential crash that could be triggered when
  a server requested a client authentication certificate, but the
  client had no certificates stored (bsc#1204272).
- Updated to version 3.79.3 (bsc#1207038):
  - CVE-2022-23491: Removed trust for 3 root certificates from TrustCor.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:434-1
Released:    Thu Feb 16 09:08:05 2023
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1208138,CVE-2023-0767
This update for mozilla-nss fixes the following issues:

  Updated to NSS 3.79.4 (bsc#1208138):

  - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:1810-1
Released:    Tue Apr 11 12:06:13 2023
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1191467,1191525,1198932,1200321,1201234,1203446
This update for cups fixes the following issues:

- Fix print jobs on cups.sock return with EAGAIN (Resource temporarily unavailable) (bsc#1191525)
- Fix '/usr/bin/lpr: Error - The printer or class does not exist (bsc#1203446)
- Improves logging on 'IPP_STATUS_ERROR_NOT_FOUND' error (bsc#1191467, bsc#1198932)
- Add 'After=network.target sssd.service' to the systemd unit (bsc#1201234, bsc#1200321)    

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:1939-1
Released:    Fri Apr 21 11:14:30 2023
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1191546,1207209,1208242,1208999
This update for mozilla-nss fixes the following issues:

- FIPS 140-3: Adjust SLI reporting for PBKDF2 parameter validation (bsc#1208999)
- FIPS 140-3: Update session->lastOpWasFIPS before destroying the key after
  derivation in the CKM_TLS12_KEY_AND_MAC_DERIVE,
  CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256,
  CKM_TLS_KEY_AND_MAC_DERIVE and CKM_SSL3_KEY_AND_MAC_DERIVE cases. (bsc#1191546)
- FIPS 140-3: more changes for pairwise consistency checks. (bsc#1207209)
- Add manpages to mozilla-nss-tools (bsc#1208242)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2347-1
Released:    Thu Jun  1 14:33:10 2023
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1211643,CVE-2023-32324
This update for cups fixes the following issues:

- CVE-2023-32324: Fixed a buffer overflow in format_log_line() which could cause a denial-of-service (bsc#1211643).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:2616-1
Released:    Thu Jun 22 16:47:50 2023
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1212230,CVE-2023-34241
This update for cups fixes the following issues:

- CVE-2023-34241: Fixed a use-after-free problem in cupsdAcceptClient() (bsc#1212230).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:2788-1
Released:    Thu Jul  6 11:51:02 2023
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1185116,1202118
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nspr was updated to version 4.35

* fixes for building with clang
* use the number of online processors for the
  PR_GetNumberOfProcessors() API on some platforms
* fix build on mips+musl libc
* Add support for the LoongArch 64-bit architecture

mozilla-nss was update to NSS 3.90:

* clang-format lib/freebl/stubs.c
* Add a constant time select function
* Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access.
* output early build errors by default
* Update the technical constraints for KamuSM
* Add BJCA Global Root CA1 and CA2 root certificates
* Enable default UBSan Checks
* Add explicit handling of zero length records
* Tidy up DTLS ACK Error Handling Path
* Refactor zero length record tests
* Fix compiler warning via correct assert
* run linux tests on nss-t/t-linux-xlarge-gcp
* In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator
* Fix reading raw negative numbers
* Repairing unreachable code in clang built with gyp
* Integrate Vale Curve25519
* Removing unused flags for Hacl*
* Adding a better error message
* Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6
* Fall back to the softokn when writing certificate trust
* FIPS-104-3 requires we restart post programmatically
* cmd/ecperf: fix dangling pointer warning on gcc 13
* Update ACVP dockerfile for compatibility with debian package changes
* Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files
* Removed deprecated sprintf function and replaced with snprintf
* fix rst warnings in nss doc
* Fix incorrect pygment style
* Change GYP directive to apply across platforms
* Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag

- Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116)

update to NSS 3.89.1

* Update the technical constraints for KamuSM.
* Add BJCA Global Root CA1 and CA2 root certificates.

update to NSS 3.89

* revert freebl/softoken RSA_MIN_MODULUS_BITS increase
* PR_STATIC_ASSERT is cursed
* Need to add policy control to keys lengths for signatures
* Fix unreachable code warning in fuzz builds
* Fix various compiler warnings in NSS
* Enable various compiler warnings for clang builds
* set PORT error after sftk_HMACCmp failure
* Need to add policy control to keys lengths for signatures
* remove data length assertion in sec_PKCS7Decrypt
* Make high tag number assertion failure an error
* CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384
* Tolerate certificate_authorities xtn in ClientHello
* Fix build failure on Windows
* migrate Win 2012 tasks to Azure
* fix title length in doc
* Add interop tests for HRR and PSK to GREASE suite
* Add presence/absence tests for TLS GREASE
* Correct addition of GREASE value to ALPN xtn
* CH extension permutation
* TLS GREASE (RFC8701)
* improve handling of unknown PKCS#12 safe bag types
* use a different treeherder symbol for each docker image build task
* remove nested table in rst doc
* Export NSS_CMSSignerInfo_GetDigestAlgTag
* build failure while implicitly casting SECStatus to PRUInt32

update to NSS 3.88.1

* improve handling of unknown PKCS#12 safe bag types

update to NSS 3.88

* remove nested table in rst doc
* Export NSS_CMSSignerInfo_GetDigestAlgTag.
* build failure while implicitly casting SECStatus to PRUInt32
* Add check for ClientHello SID max length
* Added EarlyData ALPN test support to BoGo shim
* ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup
* On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm
* ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test
* Added Bogo ECH rejection test support
* Added ECH 0Rtt support to BoGo shim
* RSA OAEP Wycheproof JSON
* RSA decrypt Wycheproof JSON
* ECDSA Wycheproof JSON
* ECDH Wycheproof JSON
* PKCS#1v1.5 wycheproof json
* Use X25519 wycheproof json
* Move scripts to python3
* Properly link FuzzingEngine for oss-fuzz.
* Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384)
* NSS needs to move off of DSA for integrity checks
* Add initial testing with ACVP vector sets using acvp-rust
* Don't clone libFuzzer, rely on clang instead

update to NSS 3.87

* NULL password encoding incorrect
* Fix rng stub signature for fuzzing builds
* Updating the compiler parsing for build
* Modification of supported compilers
* tstclnt crashes when accessing gnutls server without a user cert in the database.
* Add configuration option to enable source-based coverage sanitizer
* Update ECCKiila generated files.
* Add support for the LoongArch 64-bit architecture
* add checks for zero-length RSA modulus to avoid memory errors and failed assertions later
* Additional zero-length RSA modulus checks

update to NSS 3.86

* conscious language removal in NSS
* Set nssckbi version number to 2.60
* Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates
* Remove Staat der Nederlanden EV Root CA from NSS
* Remove EC-ACC root cert from NSS
* Remove SwissSign Platinum CA - G2 from NSS
* Remove Network Solutions Certificate Authority
* compress docker image artifact with zstd
* Migrate nss from AWS to GCP
* Enable static builds in the CI
* Removing SAW docker from the NSS build system
* Initialising variables in the rsa blinding code
* Implementation of the double-signing of the message for ECDSA
* Adding exponent blinding for RSA.

update to NSS 3.85

* Modification of the primes.c and dhe-params.c in order to have better looking tables
* Update zlib in NSS to 1.2.13
* Skip building modutil and shlibsign when building in Firefox
* Mark _nss_version_c unused on clang-cl
* bmo#1795668 - Remove redundant variable definitions in lowhashtest
* Add note about python executable to build instructions.

update to NSS 3.84
* Bump minimum NSPR version to 4.35
* Add a flag to disable building libnssckbi.

update to NSS 3.83

* Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags
* Set nssckbi version number to 2.58
* Add two SECOM root certificates to NSS
* Add two DigitalSign root certificates to NSS
* Remove Camerfirma Global Chambersign Root from NSS
* Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test
* Removed skipping of ECH on equality of private and public server name
* Added comment and bug reference to ECHRandomHRRExtension bogo test
* Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR
* Added check for server only sending ECH extension with retry configs
  in EncryptedExtensions and if not accepting ECH. Changed config setting
  behavior to skip configs with unsupported mandatory extensions instead
  of failing
* Added ECH client support to BoGo shim. Changed CHInner creation to
  skip TLS 1.2 only extensions to comply with BoGo
* Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs
* Update BoGo tests to recent BoringSSL version
* Bump minimum NSPR version to 4.34.1

update to NSS 3.82

* check for null template in sec_asn1{d,e}_push_state
* QuickDER: Forbid NULL tags with non-zero length
* Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite
* Cast the result of GetProcAddress
* pk11wrap: Tighten certificate lookup based on PKCS #11 URI.

update to NSS 3.81

* Enable aarch64 hardware crypto support on OpenBSD
* make NSS_SecureMemcmp 0/1 valued
* Add no_application_protocol alert handler and test client error code is set
* Gracefully handle null nickname in CERT_GetCertNicknameWithValidity
* required for Firefox 104

- raised NSPR requirement to 4.34.1

- changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118)

update to NSS 3.80

* Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h.
* Add support for asynchronous client auth hooks.
* nss-policy-check: make unknown keyword check optional.
* GatherBuffer: Reduced plaintext buffer allocations
	  by allocating it on initialization. Replaced
	  redundant code with assert. Debug builds: Added
	  buffer freeing/allocation for each record.
* Mark 3.79 as an ESR release.
* Bump nssckbi version number for June.
* Remove Hellenic Academic 2011 Root.
* Add E-Tugra Roots.
* Add Certainly Roots.
* Add DigitCert Roots.
* Protect SFTKSlot needLogin with slotLock.
* Compare signature and signatureAlgorithm fields in legacy certificate verifier.
* Uninitialized value in cert_VerifyCertChainOld.
* Unchecked return code in sec_DecodeSigAlg.
* Uninitialized value in cert_ComputeCertType.
* Avoid data race on primary password change.
* Replace ppc64 dcbzl intrinisic.
* Allow LDFLAGS override in makefile builds.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:2814-1
Released:    Wed Jul 12 22:05:25 2023
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1185116,1202118
This update for mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.90:

* Add a constant time select function
* Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access.
* output early build errors by default
* Update the technical constraints for KamuSM
* Add BJCA Global Root CA1 and CA2 root certificates
* Enable default UBSan Checks
* Add explicit handling of zero length records
* Tidy up DTLS ACK Error Handling Path
* Refactor zero length record tests
* Fix compiler warning via correct assert
* run linux tests on nss-t/t-linux-xlarge-gcp
* In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator
* Fix reading raw negative numbers
* Repairing unreachable code in clang built with gyp
* Integrate Vale Curve25519
* Removing unused flags for Hacl*
* Adding a better error message
* Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6
* Fall back to the softokn when writing certificate trust
* FIPS-104-3 requires we restart post programmatically
* cmd/ecperf: fix dangling pointer warning on gcc 13
* Update ACVP dockerfile for compatibility with debian package changes
* Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files
* Removed deprecated sprintf function and replaced with snprintf
* fix rst warnings in nss doc
* Fix incorrect pygment style
* Change GYP directive to apply across platforms
* Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag

- Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116)

update to NSS 3.89.1

* Update the technical constraints for KamuSM.
* Add BJCA Global Root CA1 and CA2 root certificates.

update to NSS 3.89

* revert freebl/softoken RSA_MIN_MODULUS_BITS increase
* PR_STATIC_ASSERT is cursed
* Need to add policy control to keys lengths for signatures
* Fix unreachable code warning in fuzz builds
* Fix various compiler warnings in NSS
* Enable various compiler warnings for clang builds
* set PORT error after sftk_HMACCmp failure
* Need to add policy control to keys lengths for signatures
* remove data length assertion in sec_PKCS7Decrypt
* Make high tag number assertion failure an error
* CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384
* Tolerate certificate_authorities xtn in ClientHello
* Fix build failure on Windows
* migrate Win 2012 tasks to Azure
* fix title length in doc
* Add interop tests for HRR and PSK to GREASE suite
* Add presence/absence tests for TLS GREASE
* Correct addition of GREASE value to ALPN xtn
* CH extension permutation
* TLS GREASE (RFC8701)
* improve handling of unknown PKCS#12 safe bag types
* use a different treeherder symbol for each docker image build task
* remove nested table in rst doc
* Export NSS_CMSSignerInfo_GetDigestAlgTag
* build failure while implicitly casting SECStatus to PRUInt32

update to NSS 3.88.1

* improve handling of unknown PKCS#12 safe bag types

update to NSS 3.88

* remove nested table in rst doc
* Export NSS_CMSSignerInfo_GetDigestAlgTag.
* build failure while implicitly casting SECStatus to PRUInt32
* Add check for ClientHello SID max length
* Added EarlyData ALPN test support to BoGo shim
* ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup
* On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm
* ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test
* Added Bogo ECH rejection test support
* Added ECH 0Rtt support to BoGo shim
* RSA OAEP Wycheproof JSON
* RSA decrypt Wycheproof JSON
* ECDSA Wycheproof JSON
* ECDH Wycheproof JSON
* PKCS#1v1.5 wycheproof json
* Use X25519 wycheproof json
* Move scripts to python3
* Properly link FuzzingEngine for oss-fuzz.
* Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384)
* NSS needs to move off of DSA for integrity checks
* Add initial testing with ACVP vector sets using acvp-rust
* Don't clone libFuzzer, rely on clang instead

update to NSS 3.87

* NULL password encoding incorrect
* Fix rng stub signature for fuzzing builds
* Updating the compiler parsing for build
* Modification of supported compilers
* tstclnt crashes when accessing gnutls server without a user cert in the database.
* Add configuration option to enable source-based coverage sanitizer
* Update ECCKiila generated files.
* Add support for the LoongArch 64-bit architecture
* add checks for zero-length RSA modulus to avoid memory errors and failed assertions later
* Additional zero-length RSA modulus checks

update to NSS 3.86

* conscious language removal in NSS
* Set nssckbi version number to 2.60
* Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates
* Remove Staat der Nederlanden EV Root CA from NSS
* Remove EC-ACC root cert from NSS
* Remove SwissSign Platinum CA - G2 from NSS
* Remove Network Solutions Certificate Authority
* compress docker image artifact with zstd
* Migrate nss from AWS to GCP
* Enable static builds in the CI
* Removing SAW docker from the NSS build system
* Initialising variables in the rsa blinding code
* Implementation of the double-signing of the message for ECDSA
* Adding exponent blinding for RSA.

update to NSS 3.85

* Modification of the primes.c and dhe-params.c in order to have better looking tables
* Update zlib in NSS to 1.2.13
* Skip building modutil and shlibsign when building in Firefox
* Use __STDC_VERSION__ rather than __STDC__ as a guard
* Remove redundant variable definitions in lowhashtest
* Add note about python executable to build instructions.

update to NSS 3.84

* Bump minimum NSPR version to 4.35
* Add a flag to disable building libnssckbi.

update to NSS 3.83

* Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags
* Set nssckbi version number to 2.58
* Add two SECOM root certificates to NSS
* Add two DigitalSign root certificates to NSS
* Remove Camerfirma Global Chambersign Root from NSS
* Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test
* Removed skipping of ECH on equality of private and public server name
* Added comment and bug reference to ECHRandomHRRExtension bogo test
* Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR
* Added check for server only sending ECH extension
	with retry configs in EncryptedExtensions and if not
	accepting ECH. Changed config setting behavior to
	skip configs with unsupported mandatory extensions
	instead of failing
* Added ECH client support to BoGo shim. Changed
	CHInner creation to skip TLS 1.2 only extensions to
	comply with BoGo
* Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs
* Update BoGo tests to recent BoringSSL version
* Bump minimum NSPR version to 4.34.1

update to NSS 3.82

* check for null template in sec_asn1{d,e}_push_state
* QuickDER: Forbid NULL tags with non-zero length
* Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite
* Cast the result of GetProcAddress
* pk11wrap: Tighten certificate lookup based on PKCS #11 URI.

update to NSS 3.81

* Enable aarch64 hardware crypto support on OpenBSD
* make NSS_SecureMemcmp 0/1 valued
* Add no_application_protocol alert handler and test client error code is set
* Gracefully handle null nickname in CERT_GetCertNicknameWithValidity
* required for Firefox 104

- raised NSPR requirement to 4.34.1

- changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118)

update to NSS 3.80

* Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h.
* Add support for asynchronous client auth hooks.
* nss-policy-check: make unknown keyword check optional.
* GatherBuffer: Reduced plaintext buffer allocations
	by allocating it on initialization. Replaced
	redundant code with assert. Debug builds: Added
	buffer freeing/allocation for each record.
* Mark 3.79 as an ESR release.
* Bump nssckbi version number for June.
* Remove Hellenic Academic 2011 Root.
* Add E-Tugra Roots.
* Add Certainly Roots.
* Add DigitCert Roots.
* Protect SFTKSlot needLogin with slotLock.
* Compare signature and signatureAlgorithm fields in legacy certificate verifier.
* Uninitialized value in cert_VerifyCertChainOld.
* Unchecked return code in sec_DecodeSigAlg.
* Uninitialized value in cert_ComputeCertType.
* Avoid data race on primary password change.
* Replace ppc64 dcbzl intrinisic.
* Allow LDFLAGS override in makefile builds.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:3707-1
Released:    Wed Sep 20 17:12:03 2023
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1214254,1215204,CVE-2023-32360,CVE-2023-4504
This update for cups fixes the following issues:

- CVE-2023-4504: Fixed heap overflow in OpenPrinting CUPS Postscript Parsing (bsc#1215204).
- CVE-2023-32360: Fixed Information leak through Cups-Get-Document operation (bsc#1214254).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:4619-1
Released:    Thu Nov 30 10:13:52 2023
Summary:     Security update for sqlite3
Type:        security
Severity:    important
References:  1210660,CVE-2023-2137
This update for sqlite3 fixes the following issues:

- CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2023:4700-1
Released:    Mon Dec 11 07:03:27 2023
Summary:     Recommended update for p11-kit
Type:        recommended
Severity:    moderate
References:  
This update for p11-kit fixes the following issues:

- Ensure that programs using <p11-kit/pkcs11x.h> can be compiled with CRYPTOKI_GNU.
  Fixes GnuTLS builds (jsc#PED-6705).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2023:4968-1
Released:    Mon Dec 25 09:12:49 2023
Summary:     Security update for jbigkit
Type:        security
Severity:    low
References:  1198146,CVE-2022-1210
This update for jbigkit fixes the following issues:

- CVE-2022-1210: Fixed denial of service in TIFF File Handler (bsc#1198146).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:26-1
Released:    Thu Jan  4 11:15:24 2024
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1214980
This update for mozilla-nss fixes the following issues:

Mozilla NSS was updated to NSS 3.90.1

* regenerate NameConstraints test certificates.
* add OSXSAVE and XCR0 tests to AVX2 detection.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:597-1
Released:    Thu Feb 22 20:07:11 2024
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1216198,CVE-2023-5388
This update for mozilla-nss fixes the following issues:

Update to NSS 3.90.2:

- CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:1474-1
Released:    Tue Apr 30 06:21:02 2024
Summary:     Recommended update for cups
Type:        recommended
Severity:    important
References:  1217119
This update for cups fixes the following issues:

- Fix occasional stuck on poll() loop (bsc#1217119)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:1950-1
Released:    Fri Jun  7 17:20:14 2024
Summary:     Security update for glib2
Type:        security
Severity:    moderate
References:  1224044,CVE-2024-34397
This update for glib2 fixes the following issues:

Update to version 2.78.6:

+ Fix a regression with IBus caused by the fix for CVE-2024-34397

Changes in version 2.78.5:

+ Fix CVE-2024-34397: GDBus signal subscriptions for well-known
  names are vulnerable to unicast spoofing. (bsc#1224044)
+ Bugs fixed:
  - gvfs-udisks2-volume-monitor SIGSEGV in
    g_content_type_guess_for_tree() due to filename with bad
    encoding
  - gcontenttype: Make filename valid utf-8 string before processing.
  - gdbusconnection: Don't deliver signals if the sender doesn't match.

Changes in version 2.78.4:

+ Bugs fixed:
  - Fix generated RST anchors for methods, signals and properties.
  - docs/reference: depend on a native gtk-doc.
  - gobject_gdb.py: Do not break bt on optimized build.
  - gregex: clean up usage of _GRegex.jit_status.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2003-1
Released:    Wed Jun 12 07:30:30 2024
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1223179,1225365,CVE-2024-35235
This update for cups fixes the following issues:

- CVE-2024-35235: Fixed a bug in cupsd that could allow an attacker to change the permissions of other files in the system. (bsc#1225365)
- Handle local 'Negotiate' authentication response for cli clients (bsc#1223179)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2076-1
Released:    Wed Jun 19 05:25:07 2024
Summary:     Security update for gdk-pixbuf
Type:        security
Severity:    important
References:  1195391,1219276,1223903,CVE-2022-48622
This update for gdk-pixbuf fixes the following issues:

gdk-pixbuf was updated to version 2.42.12:

- Security issues fixed:

  * CVE-2022-48622: Fixed vulnerability where a crafted .ani file could allow an attacker to overwrite heap metadata,
    leading to a denial of service or code execution attack to a denial of service or code execution attack 
    (bsc#1219276)

- Changes in version 2.42.12:

  + ani: Reject files with multiple INA or IART chunks,
  + ani: validate chunk size,
  + Updated translations.

- Enable other image loaders such as xpm and xbm (bsc#1223903)

- Changes in version 2.42.11:

  + Disable fringe loaders by default.
  + Introspection fixes.
  + Updated translations.

- Changes in version 2.42.10:

  + Search for rst2man.py.
  + Update the memory size limit for JPEG images.
  + Updated translations.

- Fixed loading of larger images
- Avoid Bash specific syntax in baselibs postscript (bsc#1195391) 

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2200-1
Released:    Tue Jun 25 13:53:17 2024
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1216594,1216598,1226586,CVE-2023-38469,CVE-2023-38471
This update for avahi fixes the following issues:

- CVE-2023-38471: Fixed a reachable assertion in dbus_set_host_name. (bsc#1216594)
- CVE-2023-38469: Fixed a reachable assertion in avahi_dns_packet_append_record. (bsc#1216598)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2340-1
Released:    Tue Jul  9 07:33:29 2024
Summary:     Recommended update for pixman
Type:        recommended
Severity:    moderate
References:  1221052
This update for pixman fixes the following issues:

- Update to version 0.43.4
  + Fix incorrect compositing on big-endian architectures (bsc#1221052)
  + Allow building on clang/arm32

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2633-1
Released:    Tue Jul 30 09:13:34 2024
Summary:     Security update for gtk3
Type:        security
Severity:    important
References:  1228120,CVE-2024-6655
This update for gtk3 fixes the following issues:

- CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2667-1
Released:    Tue Jul 30 16:14:00 2024
Summary:     Recommended update for libxkbcommon
Type:        recommended
Severity:    moderate
References:  1218640,1228322

This update of libxkbcommon fixes the following issue:

- ship libxkbregistry0-32bit and libxbkregistry-devel-32bit for use by Wine. (bsc#1218640 bsc#1228322)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2671-1
Released:    Tue Jul 30 21:10:57 2024
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1226192
This update for cups fixes the following issues:

- Require the exact matching version-release of all libcups* sub-packages (bsc#1226192)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2684-1
Released:    Wed Jul 31 20:04:41 2024
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388
This update for mozilla-nss fixes the following issues:

- Fixed startup crash of Firefox when using FIPS-mode (bsc#1223724).
- Added 'Provides: nss' so other RPMs that require 'nss' can
  be installed (jira PED-6358).

- FIPS: added safe memsets (bsc#1222811)
- FIPS: restrict AES-GCM (bsc#1222830)
- FIPS: Updated FIPS approved cipher lists (bsc#1222813, bsc#1222814, bsc#1222821, bsc#1222822, bsc#1224118)
- FIPS: Updated FIPS self tests (bsc#1222807, bsc#1222828, bsc#1222834)
- FIPS: Updated FIPS approved cipher lists (bsc#1222804, bsc#1222826, bsc#1222833, bsc#1224113, bsc#1224115, bsc#1224116)

- Require `sed` for mozilla-nss-sysinit, as setup-nsssysinit.sh 
  depends on it and will create a broken, empty config, if sed is
  missing (bsc#1227918)

Update to NSS 3.101.2:

* bmo#1905691 - ChaChaXor to return after the function



update to NSS 3.101.1:

* GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.

update to NSS 3.101:

* add diagnostic assertions for SFTKObject refcount.
* freeing the slot in DeleteCertAndKey if authentication failed
* fix formatting issues.
* Add Firmaprofesional CA Root-A Web to NSS.
* remove invalid acvp fuzz test vectors.
* pad short P-384 and P-521 signatures gtests.
* remove unused FreeBL ECC code.
* pad short P-384 and P-521 signatures.
* be less strict about ECDSA private key length.
* Integrate HACL* P-521.
* Integrate HACL* P-384.
* memory leak in create_objects_from_handles.
* ensure all input is consumed in a few places in mozilla::pkix
* SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
* clean up escape handling
* Use lib::pkix as default validator instead of the old-one
* Need to add high level support for PQ signing.
* Certificate Compression: changing the allocation/freeing of buffer + Improving the documentation
* SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
* Allow for non-full length ecdsa signature when using softoken
* Modification of .taskcluster.yml due to mozlint indent defects
* Implement support for PBMAC1 in PKCS#12
* disable VLA warnings for fuzz builds.
* remove redundant AllocItem implementation.
* add PK11_ReadDistrustAfterAttribute.
* - Clang-formatting of SEC_GetMgfTypeByOidTag update
* Set SEC_ERROR_LIBRARY_FAILURE on self-test failure
* sftk_getParameters(): Fix fallback to default variable after error with configfile.
* Switch to the mozillareleases/image_builder image

- switch from ec_field_GFp to ec_field_plain

Update to NSS 3.100:

* merge pk11_kyberSlotList into pk11_ecSlotList for faster Xyber operations.
* remove ckcapi.
* avoid a potential PK11GenericObject memory leak.
* Remove incomplete ESDH code.
* Decrypt RSA OAEP encrypted messages.
* Fix certutil CRLDP URI code.
* Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys.
* Add ability to encrypt and decrypt CMS messages using ECDH.
* Correct Templates for key agreement in smime/cmsasn.c.
* Moving the decodedCert allocation to NSS.
* Allow developers to speed up repeated local execution of NSS tests that depend on certificates.

Update to NSS 3.99:

* Removing check for message len in ed25519 (bmo#1325335)
* add ed25519 to SECU_ecName2params. (bmo#1884276)
* add EdDSA wycheproof tests. (bmo#1325335)
* nss/lib layer code for EDDSA. (bmo#1325335)
* Adding EdDSA implementation. (bmo#1325335)
* Exporting Certificate Compression types (bmo#1881027)
* Updating ACVP docker to rust 1.74 (bmo#1880857)
* Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 (bmo#1325335)
* Add NSS_CMSRecipient_IsSupported. (bmo#1877730)

Update to NSS 3.98:

* (CVE-2023-5388) Timing attack against RSA decryption in TLS
* Certificate Compression: enabling the check that the compression was advertised
* Move Windows workers to nss-1/b-win2022-alpha
* Remove Email trust bit from OISTE WISeKey Global Root GC CA
* Replace `distutils.spawn.find_executable` with `shutil.which` within `mach` in `nss`
* Certificate Compression: Updating nss_bogo_shim to support Certificate compression
* TLS Certificate Compression (RFC 8879) Implementation
* Add valgrind annotations to freebl kyber operations for constant-time execution tests
* Set nssckbi version number to 2.66
* Add Telekom Security roots
* Add D-Trust 2022 S/MIME roots
* Remove expired Security Communication RootCA1 root
* move keys to a slot that supports concatenation in PK11_ConcatSymKeys
* remove unmaintained tls-interop tests
* bogo: add support for the -ipv6 and -shim-id shim flags
* bogo: add support for the -curves shim flag and update Kyber expectations
* bogo: adjust expectation for a key usage bit test
* mozpkix: add option to ignore invalid subject alternative names
* Fix selfserv not stripping `publicname:` from -X value
* take ownership of ecckilla shims
* add valgrind annotations to freebl/ec.c
* PR_INADDR_ANY needs PR_htonl before assignment to inet.ip
* Update zlib to 1.3.1

Update to NSS 3.97:

* make Xyber768d00 opt-in by policy
* add libssl support for xyber768d00
* add PK11_ConcatSymKeys
* add Kyber and a PKCS#11 KEM interface to softoken
* add a FreeBL API for Kyber
* part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff
* part 1: add a script for vendoring kyber from pq-crystals repo
* Removing the calls to RSA Blind from loader.*
* fix worker type for level3 mac tasks
* RSA Blind implementation
* Remove DSA selftests
* read KWP testvectors from JSON
* Backed out changeset dcb174139e4f
* Fix CKM_PBE_SHA1_DES2_EDE_CBC derivation
* Wrap CC shell commands in gyp expansions

Update to NSS 3.96.1:

* Use pypi dependencies for MacOS worker in ./build_gyp.sh
* p7sign: add -a hash and -u certusage (also p7verify cleanups)
* add a defensive check for large ssl_DefSend return values
* Add dependency to the taskcluster script for Darwin
* Upgrade version of the MacOS worker for the CI

Update to NSS 3.95:

* Bump builtins version number.
* Remove Email trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068 root cert.
* Remove 4 DigiCert (Symantec/Verisign) Root Certificates
* Remove 3 TrustCor Root Certificates from NSS.
* Remove Camerfirma root certificates from NSS.
* Remove old Autoridad de Certificacion Firmaprofesional Certificate.
* Add four Commscope root certificates to NSS.
* Add TrustAsia Global Root CA G3 and G4 root certificates.
* Include P-384 and P-521 Scalar Validation from HACL*
* Include P-256 Scalar Validation from HACL*.
* After the HACL 256 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the softoken level
* Add means to provide library parameters to C_Initialize
* add OSXSAVE and XCR0 tests to AVX2 detection.
* Typo in ssl3_AppendHandshakeNumber
* Introducing input check of ssl3_AppendHandshakeNumber
* Fix Invalid casts in instance.c

Update to NSS 3.94:

* Updated code and commit ID for HACL*
* update ACVP fuzzed test vector: refuzzed with current NSS
* Softoken C_ calls should use system FIPS setting to select NSC_ or FC_ variants
* NSS needs a database tool that can dump the low level representation of the database
* declare string literals using char in pkixnames_tests.cpp
* avoid implicit conversion for ByteString
* update rust version for acvp docker
* Moving the init function of the mpi_ints before clean-up in ec.c
* P-256 ECDH and ECDSA from HACL*
* Add ACVP test vectors to the repository
* Stop relying on std::basic_string<uint8_t>
* Transpose the PPC_ABI check from Makefile to gyp

Update to NSS 3.93:

* Update zlib in NSS to 1.3.
* softoken: iterate hashUpdate calls for long inputs.
* regenerate NameConstraints test certificates (bsc#1214980).

Update to NSS 3.92:

* Set nssckbi version number to 2.62
* Add 4 Atos TrustedRoot Root CA certificates to NSS
* Add 4 SSL.com Root CA certificates
* Add Sectigo E46 and R46 Root CA certificates
* Add LAWtrust Root CA2 (4096)
* Remove E-Tugra Certification Authority root
* Remove Camerfirma Chambers of Commerce Root.
* Remove Hongkong Post Root CA 1
* Remove E-Tugra Global Root CA ECC v3 and RSA v3
* Avoid redefining BYTE_ORDER on hppa Linux

Update to NSS 3.91:

* Implementation of the HW support check for ADX instruction
* Removing the support of Curve25519
* Fix comment about the addition of ticketSupportsEarlyData
* Adding args to enable-legacy-db build
* dbtests.sh failure in 'certutil dump keys with explicit default trust flags'
* Initialize flags in slot structures
* Improve the length check of RSA input to avoid heap overflow
* Followup Fixes
* avoid processing unexpected inputs by checking for m_exptmod base sign
* add a limit check on order_k to avoid infinite loop
* Update HACL* to commit 5f6051d2
* add SHA3 to cryptohi and softoken
* HACL SHA3
* Disabling ASM C25519 for A but X86_64

Update to NSS 3.90.3:

* GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
* clean up escape handling.
* remove redundant AllocItem implementation.
* Disable ASM support for Curve25519.
* Disable ASM support for Curve25519 for all but X86_64. 

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3117-1
Released:    Tue Sep  3 17:07:39 2024
Summary:     Security update for tiff
Type:        security
Severity:    moderate
References:  1228924,CVE-2024-7006
This update for tiff fixes the following issues:

- CVE-2024-7006: Fixed null pointer dereference in tif_dirinfo.c (bsc#1228924)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3131-1
Released:    Tue Sep  3 17:42:24 2024
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1224113
This update for mozilla-nss fixes the following issues:

- FIPS: Enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3185-1
Released:    Tue Sep 10 08:15:38 2024
Summary:     Recommended update for cups
Type:        recommended
Severity:    moderate
References:  1226227
This update for cups fixes the following issues:

- Fixed cupsd failing to authenticate users when group membership is required (bsc#1226227)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3219-1
Released:    Thu Sep 12 13:16:33 2024
Summary:     Security update for colord
Type:        security
Severity:    moderate
References:  1208056
This update for colord fixes the following issues:

- Fixed a potential local privilege escalation by removing the script in the specfile which changes the ownership of /var/lib/colord. (bsc#1208056)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3846-1
Released:    Thu Oct 31 11:07:10 2024
Summary:     Recommended update for gnutls
Type:        recommended
Severity:    moderate
References:  1226724,1226731,1226733,1227642,1227669,1227670,1227671,1230166
This update for gnutls fixes the following issues:

- FIPS: Do not allow curve P-192 for signature or keypair verification [bsc#1227669]
- FIPS: Allow to perform the integrity check with the hmac provided by each library [bsc#1226724]
- FIPS: Mark gnutls_hash_fast operations as approved in SLI. [bsc#1230166]
- FIPS: Run pairwise consistency test only in FIPS mode. [bsc#1226733]
- FIPS: Use full hash+sign operations, not low level primitives in PCT test. [bsc#1226733]
- FIPS: Mark SHA1 as not allowed for signature verification in both RSA and ECDSA sigVer. [bsc#1227642]
- FIPS: Allow RSA signature verification with min of 2048 bit modulus. [bsc#1227670]
- FIPS: Remove not needed DSA in selfchecks in FIPS mode. [bsc#1227671, bsc#1226731]

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:4196-1
Released:    Thu Dec  5 13:56:06 2024
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1233420,CVE-2024-52616
This update for avahi fixes the following issues:

- CVE-2024-52616: Fixed Avahi Wide-Area DNS Predictable Transaction IDs (bsc#1233420)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:4244-1
Released:    Fri Dec  6 14:04:39 2024
Summary:     Recommended update for shared-mime-info
Type:        recommended
Severity:    moderate
References:  1231463
This update for shared-mime-info fixes the following issue:

- Uninstall silently if update-mime-database is not present (bsc#1231463).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:4254-1
Released:    Fri Dec  6 18:03:05 2024
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1231463,1233282,CVE-2024-52533
This update for glib2 fixes the following issues:

Security issues fixed:

- CVE-2024-52533: Fix a single byte buffer overflow in set_connect_msg() (bsc#1233282).

Non-security issue fixed:

- Fix error when uninstalling packages (bsc#1231463).


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:31-1
Released:    Tue Jan  7 15:44:10 2025
Summary:     Security update for gtk3
Type:        security
Severity:    important
References:  1172879,1228120,CVE-2024-6655
This update for gtk3 fixes the following issues:

- CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120).

Other fixes:  
- Updated to version 3.24.43
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:548-1
Released:    Fri Feb 14 11:19:24 2025
Summary:     Security update for libtasn1
Type:        security
Severity:    important
References:  1236878,CVE-2024-12133
This update for libtasn1 fixes the following issues:

- CVE-2024-12133: the processing of input DER data containing a large number of SEQUENCE OF or SET OF elements takes
  quadratic time to complete. (bsc#1236878)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:753-1
Released:    Fri Feb 28 17:30:35 2025
Summary:     Security update for tiff
Type:        security
Severity:    moderate
References:  1212607,1219213,1236834,CVE-2023-25435,CVE-2023-52356
This update for tiff fixes the following issues:

- CVE-2023-25435: Heap-buffer-overflow in extractContigSamplesShifted8bits() in tiffcrop.c (bsc#1212607).
- CVE-2023-52356: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service (bsc#1219213).


Other bugfixes:

- Fixed tiff build issue on s390x as test 12 test_directory fails (bsc#1236834).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:764-1
Released:    Mon Mar  3 09:43:37 2025
Summary:     Security update for gnutls
Type:        security
Severity:    moderate
References:  1236974,CVE-2024-12243
This update for gnutls fixes the following issues:

- CVE-2024-12243: quadratic complexity of DER input decoding in libtasn1 can lead to a DoS (bsc#1236974).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:794-1
Released:    Thu Mar  6 07:59:29 2025
Summary:     Recommended update for pkg-config
Type:        recommended
Severity:    important
References:  1237374
This update for pkg-config fixes the following issues:

- Build with system GLib instead of bundled GLib (bsc#1237374).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:820-1
Released:    Mon Mar 10 15:17:28 2025
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  1222834
This update for mozilla-nss fixes the following issues:

- FIPS: Do not pass in bad targetKeyLength parameters when checking for
  FIPS approval after keygen. This was causing false rejections.
- FIPS: Approve RSA signature verification  mechanisms with PKCS padding and
  legacy moduli (bsc#1222834).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1245-1
Released:    Mon Apr 14 13:31:49 2025
Summary:     Recommended update for pkg-config
Type:        recommended
Severity:    moderate
References:  1237374
This update for rsync fixes the following issues:

- Security scan found old glib in pkg-config (bsc#1237374).
- This update for pkg-config changes attribute to the author who actually
  makes the change

-----------------------------------------------------------------
Advisory ID: SUSE-OU-2025:1258-1
Released:    Mon Apr 14 18:49:52 2025
Summary:     Recommended update for dpdk
Type:        optional
Severity:    low
References:  1219391
This update for gnome-color-manager, colord, gnome-online-accounts, libnma, NetworkManager-applet
 fixes the following issues:

- Add non x86_64 binaries to SUSE Package Hub, no source change in any package. (bsc#1219391)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1367-1
Released:    Thu Apr 24 16:38:48 2025
Summary:     Security update for glib2
Type:        security
Severity:    moderate
References:  1240897,CVE-2025-3360
This update for glib2 fixes the following issues:

- CVE-2025-3360: Fixed integer overflow and buffer underread when parsing a very long 
  and invalid ISO 8601 timestamp with g_date_time_new_from_iso8601() (bsc#1240897)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1456-1
Released:    Wed May  7 17:13:32 2025
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1241020,1241078,1241189,CVE-2025-29087,CVE-2025-29088,CVE-2025-3277
This update for sqlite3 fixes the following issues:

- CVE-2025-29087,CVE-2025-3277: Fixed integer overflow in sqlite concat function (bsc#1241020)
- CVE-2025-29088: Fixed integer overflow through the SQLITE_DBCONFIG_LOOKASIDE component (bsc#1241078)

Other fixes:

- Updated to version 3.49.1 from Factory (jsc#SLE-16032)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2167-1
Released:    Mon Jun 30 09:14:40 2025
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1242844,1244596,CVE-2025-4373,CVE-2025-6052
This update for glib2 fixes the following issues:

- CVE-2025-6052: Fixed integer overflow in g_string_maybe_expand() leads to potential buffer overflow in GString (bsc#1244596).
- CVE-2025-4373: Fixed buffer underflow through glib/gstring.c via function g_string_insert_unichar (bsc#1242844).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2260-1
Released:    Wed Jul  9 19:04:24 2025
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1244554,1244555,1244557,1244590,1244700,CVE-2025-49794,CVE-2025-49795,CVE-2025-49796,CVE-2025-6021,CVE-2025-6170
This update for libxml2 fixes the following issues:

- CVE-2025-49794: Fixed a heap use after free which could lead to denial of service. (bsc#1244554)
- CVE-2025-49796: Fixed type confusion which could lead to denial of service. (bsc#1244557)
- CVE-2025-49795: Fixed a null pointer dereference which could lead to denial of service. (bsc#1244555)
- CVE-2025-6170: Fixed a stack buffer overflow which could lead to a crash. (bsc#1244700)
- CVE-2025-6021: Fixed an integer overflow in xmlBuildQName() which could lead to stack buffer overflow. (bsc#1244590)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2274-1
Released:    Thu Jul 10 14:35:40 2025
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1081723,1224113
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.112:

   * Fix alias for mac workers on try
   * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault
   * ABI/API break in ssl certificate processing
   * remove unnecessary assertion in sec_asn1d_init_state_based_on_template
   * bmo#1965754 Update taskgraph to v14.2.1
   * Workflow for automation of the release on GitHub when pushing a tag
   * fix faulty assertions in SEC_ASN1DecoderUpdate
   * Renegotiations should use a fresh ECH GREASE buffer
   * bmo#1951396 Update taskgraph to v14.1.1
   * Partial fix for ACVP build CI job
   * Initialize find in sftk_searchDatabase
   * Add clang-18 to extra builds
   * Fault tolerant git fetch for fuzzing
   * Tolerate intermittent failures in ssl_policy_pkix_ocsp
   * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set
   * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls
   * Remove Cryptofuzz CI version check

Update to NSS 3.111:

  * FIPS changes need to be upstreamed: force ems policy
  * Turn off Websites Trust Bit from CAs
  * Update nssckbi version following April 2025 Batch of Changes
  * Disable SMIME ‘trust bit’ for GoDaddy CAs
  * Replaced deprecated sprintf function with snprintf in dbtool.c
  * Need up update NSS for PKCS 3.1
  * avoid leaking localCert if it is already set in ssl3_FillInCachedSID
  * Decrease ASAN quarantine size for Cryptofuzz in CI
  * selfserv: Add support for zlib certificate compression

Update to NSS 3.110:

  * FIPS changes need to be upstreamed: force ems policy
  * Prevent excess allocations in sslBuffer_Grow
  * Remove Crl templates from ASN1 fuzz target
  * Remove CERT_CrlTemplate from ASN1 fuzz target
  * Fix memory leak in NSS_CMSMessage_IsSigned
  * NSS policy updates
  * Improve locking in nssPKIObject_GetInstances
  * Fix race in sdb_GetMetaData
  * Fix member access within null pointer
  * Increase smime fuzzer memory limit
  * Enable resumption when using custom extensions
  * change CN of server12 test certificate
  * Part 2: Add missing check in
                  NSS_CMSDigestContext_FinishSingle
  * Part 1: Fix smime UBSan errors
  * FIPS changes need to be upstreamed: updated key checks
  * Don't build libpkix in static builds
  * handle `-p all` in try syntax
  * fix opt-make builds to actually be opt
  * fix opt-static builds to actually be opt
  * Remove extraneous assert



Update to NSS 3.109:

  * Call BL_Init before RNG_RNGInit() so that special
                  SHA instructions can be used if available
  * NSS policy updates - fix inaccurate key policy issues
  * SMIME fuzz target
  * ASN1 decoder fuzz target
  * Part 2: Revert “Extract testcases from ssl gtests
                  for fuzzing”
  * Add fuzz/README.md
  * Part 4: Fix tstclnt arguments script
  * Extend pkcs7 fuzz target
  * Extend certDN fuzz target
  * revert changes to HACL* files from bug 1866841
  * Part 3: Package frida corpus script

Update to NSS 3.108:

  * libclang-16 -> libclang-19
  * Turn off Secure Email Trust Bit for Security
                  Communication ECC RootCA1
  * Turn off Secure Email Trust Bit for BJCA Global Root
                  CA1 and BJCA Global Root CA2
  * Remove SwissSign Silver CA – G2
  * Add D-Trust 2023 TLS Roots to NSS
  * fix fips test failure on windows
  * change default sensitivity of KEM keys
  * Part 1: Introduce frida hooks and script
  * add missing arm_neon.h include to gcm.c
  * ci: update windows workers to win2022
  * strip trailing carriage returns in tools tests
  * work around unix/windows path translation issues
                  in cert test script
  * ci: let the windows setup script work without $m
  * detect msys
  * add a specialized CTR_Update variant for AES-GCM
  * NSS policy updates
  * FIPS changes need to be upstreamed: FIPS 140-3 RNG
  * FIPS changes need to be upstreamed: Add SafeZero
  * FIPS changes need to be upstreamed Updated POST
  * Segmentation fault in SECITEM_Hash during pkcs12 processing
  * Extending NSS with LoadModuleFromFunction functionality
  * Ensure zero-initialization of collectArgs.cert
  * pkcs7 fuzz target use CERT_DestroyCertificate
  * Fix actual underlying ODR violations issue
  * mozilla::pkix: allow reference ID labels to begin
                  and/or end with hyphens
  * don't look for secmod.db in nssutil_ReadSecmodDB if
                  NSS_DISABLE_DBM is set
  * Fix memory leak in pkcs7 fuzz target
  * Set -O2 for ASan builds in CI
  * Change branch of tlsfuzzer dependency
  * Run tests in CI for ASan builds with detect_odr_violation=1
  * Fix coverage failure in CI
  * Add fuzzing for delegated credentials, DTLS short
                  header and Tls13BackendEch
  * Add fuzzing for SSL_EnableTls13GreaseEch and
                  SSL_SetDtls13VersionWorkaround
  * Part 3: Restructure fuzz/
  * Extract testcases from ssl gtests for fuzzing
  * Force Cryptofuzz to use NSS in CI
  * Fix Cryptofuzz on 32 bit in CI
  * Update Cryptofuzz repository link
  * fix build error from 9505f79d
  * simplify error handling in get_token_objects_for_cache
  * nss doc: fix a warning
  * pkcs12 fixes from RHEL need to be picked up



Update to NSS 3.107:

  * Remove MPI fuzz targets.
  * Remove globals `lockStatus` and `locksEverDisabled`.
  * Enable PKCS8 fuzz target.
  * Integrate Cryptofuzz in CI.
  * Part 2: Set tls server target socket options in config class
  * Part 1: Set tls client target socket options in config class
  * Support building with thread sanitizer.
  * set nssckbi version number to 2.72.
  * remove Websites Trust Bit from Entrust Root
                  Certification Authority - G4.
  * remove Security Communication RootCA3 root cert.
  * remove SecureSign RootCA11 root cert.
  * Add distrust-after for TLS to Entrust Roots.
  * bmo#1927096 Update expected error code in pk12util pbmac1 tests.
  * Use random tstclnt args with handshake collection script
  * Remove extraneous assert in ssl3gthr.c.
  * Adding missing release notes for NSS_3_105.
  * Enable the disabled mlkem tests for dtls.
  * NSS gtests filter cleans up the constucted buffer
                  before the use.
  * Make ssl_SetDefaultsFromEnvironment thread-safe.
  * Remove short circuit test from ssl_Init.



Update to NSS 3.106:

  * NSS 3.106 should be distributed with NSPR 4.36.
  * pk12util: improve error handling in p12U_ReadPKCS12File.
  * Correctly destroy bulkkey in error scenario.
  * PKCS7 fuzz target, r=djackson,nss-reviewers.
  * Extract certificates with handshake collection script.
  * Specify len_control for fuzz targets.
  * Fix memory leak in dumpCertificatePEM.
  * Fix UBSan errors for SECU_PrintCertificate and
                  SECU_PrintCertificateBasicInfo.
  * add new error codes to mozilla::pkix for Firefox to use.
  * allow null phKey in NSC_DeriveKey.
  * Only create seed corpus zip from existing corpus.
  * Use explicit allowlist for for KDF PRFS.
  * Increase optimization level for fuzz builds.
  * Remove incorrect assert.
  * Use libFuzzer options from fuzz/options/\*.options in CI.
  * Polish corpus collection for automation.
  * Detect new and unfuzzed SSL options.
  * PKCS12 fuzzing target.

Update to NSS 3.105:

  * Allow importing PKCS#8 private EC keys missing public key
  * UBSAN fix: applying zero offset to null pointer in sslsnce.c
  * set KRML_MUSTINLINE=inline in makefile builds
  * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys
  * override default definition of KRML_MUSTINLINE
  * libssl support for mlkem768x25519
  * support for ML-KEM-768 in softoken and pk11wrap
  * Add Libcrux implementation of ML-KEM 768 to FreeBL
  * Avoid misuse of ctype(3) functions
  * part 2: run clang-format
  * part 1: upgrade to clang-format 13
  * clang-format fuzz
  * DTLS client message buffer may not empty be on retransmit
  * Optionally print config for TLS client and server
                  fuzz target
  * Fix some simple documentation issues in NSS.
  * improve performance of NSC_FindObjectsInit when
                  template has CKA_TOKEN attr
  * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN

Update to NSS 3.104:

  * Copy original corpus to heap-allocated buffer
  * Fix min ssl version for DTLS client fuzzer
  * Remove OS2 support just like we did on NSPR
  * clang-format NSS improvements
  * Adding basicutil.h to use HexString2SECItem function
  * removing dirent.c from build
  * Allow handing in keymaterial to shlibsign to make
                  the output reproducible
  * remove nec4.3, sunos4, riscos and SNI references
  * remove other old OS (BSDI, old HP UX, NCR,
                  openunix, sco, unixware or reliantUnix
  * remove mentions of WIN95
  * remove mentions of WIN16
  * More explicit directory naming
  * Add more options to TLS server fuzz target
  * Add more options to TLS client fuzz target
  * Use OSS-Fuzz corpus in NSS CI
  * set nssckbi version number to 2.70.
  * Remove Email Trust bit from ACCVRAIZ1 root cert.
  * Remove Email Trust bit from certSIGN ROOT CA.
  * Add Cybertrust Japan Roots to NSS.
  * Add Taiwan CA Roots to NSS.
  * remove search by decoded serial in
                  nssToken_FindCertificateByIssuerAndSerialNumber
  * Fix tstclnt CI build failure
  * vfyserv: ensure peer cert chain is in db for
                  CERT_VerifyCertificateNow
  * Enable all supported protocol versions for UDP
  * Actually use random PSK hash type
  * Initialize NSS DB once
  * Additional ECH cipher suites and PSK hash types
  * Automate corpus file generation for TLS client Fuzzer
  * Fix crash with UNSAFE_FUZZER_MODE
  * clang-format shlibsign.c

Update to NSS 3.103:

  * move list size check after lock acquisition in sftk_PutObjectToList.
  * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH,
  * Adjust libFuzzer size limits
  * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm,
                  SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk
  * Add fuzzing support for SSL_ENABLE_GREASE and
                  SSL_ENABLE_CH_EXTENSION_PERMUTATION

- Make the rpms reproducible, by using a hardcoded, static key to generate the checksums (*.chk-files)
- FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).

Update to NSS 3.102.1:

  * ChaChaXor to return after the function

Update to NSS 3.102:

  * Add Valgrind annotations to freebl Chacha20-Poly1305.
  * missing sqlite header.
  * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
  * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling.
  * correct length of raw SPKI data before printing in pp utility.

- Make NSS-build reproducible.
  Use key from openssl (bsc#1081723)

- Exclude the SHA-1 hash from SLI approval.

mozilla-nspr was updated to version 4.36:

  * renamed the prwin16.h header to prwin.h
  * various build, test and automation script fixes
  * major parts of the source code were reformatted

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2287-1
Released:    Fri Jul 11 11:26:25 2025
Summary:     Recommended update for Mesa
Type:        recommended
Severity:    important
References:  1241701,1245034
This update for Mesa fixes the following issues:

- Fixes Wayland session when using SP7 as vmware guest (bsc#1245034)
- Fixes crash in libgallium on virtualbox (bsc#1241701)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2323-1
Released:    Wed Jul 16 04:07:18 2025
Summary:     Recommended update for mozilla-nspr, mozilla-nss
Type:        recommended
Severity:    moderate
References:  1081723,1224113
This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to NSS 3.112:

   * Fix alias for mac workers on try
   * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault
   * ABI/API break in ssl certificate processing
   * remove unnecessary assertion in sec_asn1d_init_state_based_on_template
   * update taskgraph to v14.2.1
   * Workflow for automation of the release on GitHub when pushing a tag
   * fix faulty assertions in SEC_ASN1DecoderUpdate
   * Renegotiations should use a fresh ECH GREASE buffer
   * update taskgraph to v14.1.1
   * Partial fix for ACVP build CI job
   * Initialize find in sftk_searchDatabase
   * Add clang-18 to extra builds
   * Fault tolerant git fetch for fuzzing
   * Tolerate intermittent failures in ssl_policy_pkix_ocsp
   * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set
   * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls
   * Remove Cryptofuzz CI version check

Update to NSS 3.111:

  * FIPS changes need to be upstreamed: force ems policy
  * Turn off Websites Trust Bit from CAs
  * Update nssckbi version following April 2025 Batch of Changes
  * Disable SMIME ‘trust bit’ for GoDaddy CAs
  * Replaced deprecated sprintf function with snprintf in dbtool.c
  * Need up update NSS for PKCS 3.1
  * avoid leaking localCert if it is already set in ssl3_FillInCachedSID
  * Decrease ASAN quarantine size for Cryptofuzz in CI
  * selfserv: Add support for zlib certificate compression

Update to NSS 3.110:

  * FIPS changes need to be upstreamed: force ems policy
  * Prevent excess allocations in sslBuffer_Grow
  * Remove Crl templates from ASN1 fuzz target
  * Remove CERT_CrlTemplate from ASN1 fuzz target
  * Fix memory leak in NSS_CMSMessage_IsSigned
  * NSS policy updates
  * Improve locking in nssPKIObject_GetInstances
  * Fix race in sdb_GetMetaData
  * Fix member access within null pointer
  * Increase smime fuzzer memory limit
  * Enable resumption when using custom extensions
  * change CN of server12 test certificate
  * Part 2: Add missing check in
                  NSS_CMSDigestContext_FinishSingle
  * Part 1: Fix smime UBSan errors
  * FIPS changes need to be upstreamed: updated key checks
  * Don't build libpkix in static builds
  * handle `-p all` in try syntax
  * fix opt-make builds to actually be opt
  * fix opt-static builds to actually be opt
  * Remove extraneous assert

Update to NSS 3.109:

  * Call BL_Init before RNG_RNGInit() so that special
                  SHA instructions can be used if available
  * NSS policy updates - fix inaccurate key policy issues
  * SMIME fuzz target
  * ASN1 decoder fuzz target
  * Part 2: Revert “Extract testcases from ssl gtests
                  for fuzzing”
  * Add fuzz/README.md
  * Part 4: Fix tstclnt arguments script
  * Extend pkcs7 fuzz target
  * Extend certDN fuzz target
  * revert changes to HACL* files from bug 1866841
  * Part 3: Package frida corpus script

Update to NSS 3.108:

  * libclang-16 -> libclang-19
  * Turn off Secure Email Trust Bit for Security
                  Communication ECC RootCA1
  * Turn off Secure Email Trust Bit for BJCA Global Root
                  CA1 and BJCA Global Root CA2
  * Remove SwissSign Silver CA – G2
  * Add D-Trust 2023 TLS Roots to NSS
  * fix fips test failure on windows
  * change default sensitivity of KEM keys
  * Part 1: Introduce frida hooks and script
  * add missing arm_neon.h include to gcm.c
  * ci: update windows workers to win2022
  * strip trailing carriage returns in tools tests
  * work around unix/windows path translation issues
                  in cert test script
  * ci: let the windows setup script work without $m
  * detect msys
  * add a specialized CTR_Update variant for AES-GCM
  * NSS policy updates
  * FIPS changes need to be upstreamed: FIPS 140-3 RNG
  * FIPS changes need to be upstreamed: Add SafeZero
  * FIPS changes need to be upstreamed - updated POST
  * Segmentation fault in SECITEM_Hash during pkcs12 processing
  * Extending NSS with LoadModuleFromFunction functionality
  * Ensure zero-initialization of collectArgs.cert
  * pkcs7 fuzz target use CERT_DestroyCertificate
  * Fix actual underlying ODR violations issue
  * mozilla::pkix: allow reference ID labels to begin
                  and/or end with hyphens
  * don't look for secmod.db in nssutil_ReadSecmodDB if
                  NSS_DISABLE_DBM is set
  * Fix memory leak in pkcs7 fuzz target
  * Set -O2 for ASan builds in CI
  * Change branch of tlsfuzzer dependency
  * Run tests in CI for ASan builds with detect_odr_violation=1
  * Fix coverage failure in CI
  * Add fuzzing for delegated credentials, DTLS short
                  header and Tls13BackendEch
  * Add fuzzing for SSL_EnableTls13GreaseEch and
                  SSL_SetDtls13VersionWorkaround
  * Part 3: Restructure fuzz/
  * Extract testcases from ssl gtests for fuzzing
  * Force Cryptofuzz to use NSS in CI
  * Fix Cryptofuzz on 32 bit in CI
  * Update Cryptofuzz repository link
  * fix build error from 9505f79d
  * simplify error handling in get_token_objects_for_cache
  * nss doc: fix a warning
  * pkcs12 fixes from RHEL need to be picked up

Update to NSS 3.107:

  * Remove MPI fuzz targets.
  * Remove globals `lockStatus` and `locksEverDisabled`.
  * Enable PKCS8 fuzz target.
  * Integrate Cryptofuzz in CI.
  * Part 2: Set tls server target socket options in config class
  * Part 1: Set tls client target socket options in config class
  * Support building with thread sanitizer.
  * set nssckbi version number to 2.72.
  * remove Websites Trust Bit from Entrust Root
                  Certification Authority - G4.
  * remove Security Communication RootCA3 root cert.
  * remove SecureSign RootCA11 root cert.
  * Add distrust-after for TLS to Entrust Roots.
  * update expected error code in pk12util pbmac1 tests.
  * Use random tstclnt args with handshake collection script
  * Remove extraneous assert in ssl3gthr.c.
  * Adding missing release notes for NSS_3_105.
  * Enable the disabled mlkem tests for dtls.
  * NSS gtests filter cleans up the constucted buffer
                  before the use.
  * Make ssl_SetDefaultsFromEnvironment thread-safe.
  * Remove short circuit test from ssl_Init.



Update to NSS 3.106:

  * NSS 3.106 should be distributed with NSPR 4.36.
  * pk12util: improve error handling in p12U_ReadPKCS12File.
  * Correctly destroy bulkkey in error scenario.
  * PKCS7 fuzz target, r=djackson,nss-reviewers.
  * Extract certificates with handshake collection script.
  * Specify len_control for fuzz targets.
  * Fix memory leak in dumpCertificatePEM.
  * Fix UBSan errors for SECU_PrintCertificate and
                  SECU_PrintCertificateBasicInfo.
  * add new error codes to mozilla::pkix for Firefox to use.
  * allow null phKey in NSC_DeriveKey.
  * Only create seed corpus zip from existing corpus.
  * Use explicit allowlist for for KDF PRFS.
  * Increase optimization level for fuzz builds.
  * Remove incorrect assert.
  * Use libFuzzer options from fuzz/options/\*.options in CI.
  * Polish corpus collection for automation.
  * Detect new and unfuzzed SSL options.
  * PKCS12 fuzzing target.

Update to NSS 3.105:

  * Allow importing PKCS#8 private EC keys missing public key
  * UBSAN fix: applying zero offset to null pointer in sslsnce.c
  * set KRML_MUSTINLINE=inline in makefile builds
  * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys
  * override default definition of KRML_MUSTINLINE
  * libssl support for mlkem768x25519
  * support for ML-KEM-768 in softoken and pk11wrap
  * Add Libcrux implementation of ML-KEM 768 to FreeBL
  * Avoid misuse of ctype(3) functions
  * part 2: run clang-format
  * part 1: upgrade to clang-format 13
  * clang-format fuzz
  * DTLS client message buffer may not empty be on retransmit
  * Optionally print config for TLS client and server
                  fuzz target
  * Fix some simple documentation issues in NSS.
  * improve performance of NSC_FindObjectsInit when
                  template has CKA_TOKEN attr
  * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN

Update to NSS 3.104:

  * Copy original corpus to heap-allocated buffer
  * Fix min ssl version for DTLS client fuzzer
  * Remove OS2 support just like we did on NSPR
  * clang-format NSS improvements
  * Adding basicutil.h to use HexString2SECItem function
  * removing dirent.c from build
  * Allow handing in keymaterial to shlibsign to make
                  the output reproducible
  * remove nec4.3, sunos4, riscos and SNI references
  * remove other old OS (BSDI, old HP UX, NCR,
                  openunix, sco, unixware or reliantUnix
  * remove mentions of WIN95
  * remove mentions of WIN16
  * More explicit directory naming
  * Add more options to TLS server fuzz target
  * Add more options to TLS client fuzz target
  * Use OSS-Fuzz corpus in NSS CI
  * set nssckbi version number to 2.70.
  * Remove Email Trust bit from ACCVRAIZ1 root cert.
  * Remove Email Trust bit from certSIGN ROOT CA.
  * Add Cybertrust Japan Roots to NSS.
  * Add Taiwan CA Roots to NSS.
  * remove search by decoded serial in
                  nssToken_FindCertificateByIssuerAndSerialNumber
  * Fix tstclnt CI build failure
  * vfyserv: ensure peer cert chain is in db for
                  CERT_VerifyCertificateNow
  * Enable all supported protocol versions for UDP
  * Actually use random PSK hash type
  * Initialize NSS DB once
  * Additional ECH cipher suites and PSK hash types
  * Automate corpus file generation for TLS client Fuzzer
  * Fix crash with UNSAFE_FUZZER_MODE
  * clang-format shlibsign.c

Update to NSS 3.103:

  * move list size check after lock acquisition in sftk_PutObjectToList.
  * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH,
  * Follow-up to fix test for presence of file nspr.patch.
  * Adjust libFuzzer size limits
  * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm,
                  SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk
  * Add fuzzing support for SSL_ENABLE_GREASE and
                  SSL_ENABLE_CH_EXTENSION_PERMUTATION

- Make the rpms reproducible,
  by using a hardcoded, static key to generate the checksums (*.chk-files)
- FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).

Update to NSS 3.102.1:

  * ChaChaXor to return after the function

Update to NSS 3.102:

  * Add Valgrind annotations to freebl Chacha20-Poly1305.
  * missing sqlite header.
  * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
  * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling.
  * correct length of raw SPKI data before printing in pp utility.

- Make NSS-build reproducible
  Use key from openssl (bsc#1081723)

- FIPS: exclude the SHA-1 hash from SLI approval.

mozilla-nspr was updated to version 4.36:

  * renamed the prwin16.h header to prwin.h
  * configure was updated from 2.69 to 2.71
  * various build, test and automation script fixes
  * major parts of the source code were reformatted

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2595-1
Released:    Fri Aug  1 17:13:59 2025
Summary:     Security update for gnutls
Type:        security
Severity:    important
References:  1246232,1246233,1246267,1246299,CVE-2025-32988,CVE-2025-32989,CVE-2025-32990,CVE-2025-6395
This update for gnutls fixes the following issues:

- CVE-2025-6395: Fix NULL pointer dereference when 2nd Client Hello omits PSK (bsc#1246299)
- CVE-2025-32988: Fix double-free due to incorrect ownership handling in the export logic of SAN entries containing an otherName (bsc#1246232)
- CVE-2025-32989: Fix heap buffer overread when handling the CT SCT extension during X.509 certificate parsing (bsc#1246233)
- CVE-2025-32990: Fix 1-byte heap buffer overflow when parsing templates with certtool (bsc#1246267)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2617-1
Released:    Mon Aug  4 09:04:59 2025
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1246296,CVE-2025-7425
This update for libxml2 fixes the following issues:

- CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2672-1
Released:    Mon Aug  4 15:06:13 2025
Summary:     Security update for sqlite3
Type:        security
Severity:    important
References:  1246597,CVE-2025-6965
This update for sqlite3 fixes the following issues:

- Update to version 3.50.2
- CVE-2025-6965: Fixed an integer truncation to avoid assertion faults. (bsc#1246597)
    
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2770-1
Released:    Tue Aug 12 15:50:12 2025
Summary:     Security update for tiff
Type:        security
Severity:    important
References:  1243503,1247106,1247108,CVE-2025-8176,CVE-2025-8177
This update for tiff fixes the following issues:

- Updated TIFFMergeFieldInfo() with read_count=write_count=0 for FIELD_IGNORE (bsc#1243503)
- CVE-2025-8176: Fixed heap use-after-free in tools/tiffmedian.c (bsc#1247108)
- CVE-2025-8177: Fixed possible buffer overflow in tools/thumbnail.c:setrow() 
  when processing malformed TIFF files (bsc#1247106)
- Add -DCMAKE_POLICY_VERSION_MINIMUM=3.5 to fix FTBFS with cmake4
- Add %check section
- Remove Group: declarations, no longer used

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2954-1
Released:    Thu Aug 21 15:42:53 2025
Summary:     Security update for gdk-pixbuf
Type:        security
Severity:    important
References:  1245227,1246114,CVE-2025-6199,CVE-2025-7345
This update for gdk-pixbuf fixes the following issues:

- CVE-2025-6199: Fixed uninitialized memory leading to arbitrary memory contents leak (bsc#1245227)
- CVE-2025-7345: Fixed heap buffer overflow within the gdk_pixbuf__jpeg_image_load_increment function (bsc#1246114)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3261-1
Released:    Thu Sep 18 06:35:19 2025
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1230932,1246533,1249049,1249128,CVE-2024-47175,CVE-2025-58060,CVE-2025-58364
This update for cups fixes the following issues:

- CVE-2024-47175: no validation of IPP attributes in `ppdCreatePPDFromIPP2` when writing to a temporary PPD file allows
  for the injection of attacker-controlled data to the resulting PPD (bsc#1230932).
- CVE-2025-58060: no password check when `AuthType` is set to anything but `Basic` and a request is made with an
  `Authorization: Basic` header (bsc#1249049).
- CVE-2025-58364: unsafe deserialization and validation of printer attributes leads to NULL pointer dereference
  (bsc#1249128).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:3286-1
Released:    Mon Sep 22 08:02:27 2025
Summary:     Recommended update for gtk3
Type:        recommended
Severity:    moderate
References:  1247503
This update for gtk3 fixes the following issues:

- Fixed issue with window dimensions (bsc#1247503)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3333-1
Released:    Wed Sep 24 08:55:10 2025
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1233421,CVE-2024-52615
This update for avahi fixes the following issues:

- CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing
  attacks (bsc#1233421).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3348-1
Released:    Wed Sep 24 16:05:03 2025
Summary:     Security update for tiff
Type:        security
Severity:    moderate
References:  1247581,1247582,1248117,1248330,CVE-2024-13978,CVE-2025-8534,CVE-2025-8961,CVE-2025-9165
This update for tiff fixes the following issues:

- CVE-2025-9165: local execution manipulation leading to memory leak (bsc#1248330).
- CVE-2024-13978: null pointer dereference in component fax2ps (bsc#1247581)
- CVE-2025-8534: null pointer dereference in function PS_Lvl2page (bsc#1247582).
- CVE-2025-8961: segmentation fault via main function of tiffcrop utility (bsc#1248117).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3449-1
Released:    Thu Oct  2 09:15:17 2025
Summary:     Security update for cairo
Type:        security
Severity:    low
References:  1247589,CVE-2025-50422
This update for cairo fixes the following issues:

- CVE-2025-50422: Fixed Poppler crash on malformed input (bsc#1247589)

- Update to version 1.18.4:
  + The dependency on LZO has been made optional through a build
    time configuration toggle.
  + You can build Cairo against a Freetype installation that does
    not have the FT_Color type.
  + Cairo tests now build on Solaris 11.4 with GCC 14.
  + The DirectWrite backend now builds on MINGW 11.
  + The DirectWrite backend now supports font variations and proper
    glyph coverage.
- Use tarball in lieu of source service due to freedesktop gitlab
  migration, will switch back at next release at the latest.
- Add pkgconfig(lzo2) BuildRequires: New optional dependency, build
  lzo2 support feature.

- Convert to source service: allows for easier upgrades by the
  GNOME team.

- Update to version 1.18.2:
  + The malloc-stats code has been removed from the tests directory
  + Cairo now requires a version of pixman equal to, or newer than,
    0.40.
  + There have been multiple build fixes for newer versions of GCC
    for MSVC; for Solaris; and on macOS 10.7.
  + PNG errors caused by loading malformed data are correctly
    propagated to callers, so they can handle the case.
  + Both stroke and fill colors are now set when showing glyphs on
    a PDF surface.
  + All the font options are copied when creating a fallback font
    object.
  + When drawing text on macOS, Cairo now tries harder to select
    the appropriate font name.
  + Cairo now prefers the COLRv1 table inside a font, if one is
    available.
  + Cairo requires a C11 toolchain when building.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3804-1
Released:    Mon Oct 27 12:35:04 2025
Summary:     Security update for mozilla-nss
Type:        security
Severity:    important
References:  1251263,CVE-2025-9187
This update for mozilla-nss fixes the following issues:

- Move NSS DB password hash away from SHA-1

Update to NSS 3.112.2:

  * Prevent leaks during pkcs12 decoding.
  * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates

Update to NSS 3.112.1:

  * restore support for finding certificates by decoded serial number.


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3949-1
Released:    Wed Nov  5 11:04:35 2025
Summary:     Security update for colord
Type:        security
Severity:    moderate
References:  1250750,CVE-2021-42523
This update for colord fixes the following issues:

- CVE-2021-42523: The original fix was wrong and did not properly free the error, resulting in a crash that has now been addressed (bsc#1250750).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3957-1
Released:    Wed Nov  5 16:45:18 2025
Summary:     Security update for tiff
Type:        security
Severity:    important
References:  1248278,1250413,CVE-2025-8851,CVE-2025-9900
This update for tiff fixes the following issues:

Update to 4.7.1:

- CVE-2025-8851: Fixed stack-based buffer overflow (bsc#1248278).
- CVE-2025-9900: Fixed write-what-where via TIFFReadRGBAImageOriented (bsc#1250413).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:3982-1
Released:    Thu Nov  6 19:21:10 2025
Summary:     Recommended update for lcms2
Type:        recommended
Severity:    moderate
References:  1247985
This update for lcms2 fixes the following issue:

- Enable threads support and avoid linker errors (bsc#1247985).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:4179-1
Released:    Mon Nov 24 08:27:54 2025
Summary:     Recommended update for mozilla-nspr
Type:        recommended
Severity:    moderate
References:  
This update for mozilla-nspr fixes the following issues:

- update to NSPR 4.36.2
    * Fixed a syntax error in test file parsetm.c, which was introduced in 4.36.1
- update to NSPR 4.36.1
    * Incorrect time value produced by PR_ParseTimeString and
      PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4092-1
Released:    Mon Nov 24 10:08:22 2025
Summary:     Security update for elfutils
Type:        security
Severity:    moderate
References:  1237236,1237240,1237241,1237242,CVE-2025-1352,CVE-2025-1372,CVE-2025-1376,CVE-2025-1377
This update for elfutils fixes the following issues:

- Fixing build/testsuite for more recent glibc and kernels.

- Fixing denial of service and general buffer overflow errors
  (bsc#1237236, bsc#1237240, bsc#1237241, bsc#1237242):

  - CVE-2025-1376: Fixed denial of service in  function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip
  - CVE-2025-1377: Fixed denial of service in function gelf_getsymshndx of the file strip.c of the component eu-strip
  - CVE-2025-1372: Fixed buffer overflow in function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf
  - CVE-2025-1352: Fixed SEGV (illegal read access) in function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf

- Fixing testsuite race conditions in run-debuginfod-find.sh.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4290-1
Released:    Fri Nov 28 10:04:11 2025
Summary:     Security update for cups
Type:        security
Severity:    moderate
References:  1234225,1244057,1253783,CVE-2025-58436,CVE-2025-61915
This update for cups fixes the following issues:

- CVE-2025-61915: Fixed a local denial-of-service via cupsd.conf update and related issues. (bsc#1253783)
- CVE-2025-58436: Fixed an issue where a slow client communication leads to a possible DoS attack. (bsc#1244057)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4308-1
Released:    Fri Nov 28 16:38:46 2025
Summary:     Security update for glib2
Type:        security
Severity:    moderate
References:  1249055,CVE-2025-7039
This update for glib2 fixes the following issues:

- CVE-2025-7039: Fixed buffer under-read on glib through glib/gfileutils.c via get_tmp_file() (bsc#1249055)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4319-1
Released:    Wed Dec  3 13:34:00 2025
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1254353,CVE-2025-58436
This update for cups fixes the following issues:

- The fix for CVE-2025-58436 causes a regression where
  GTK applications will hang. (bsc#1254353)

  See also https://github.com/OpenPrinting/cups/issues/1429

  The fix has been temporary disabled.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4323-1
Released:    Mon Dec  8 19:14:15 2025
Summary:     Security update for gnutls
Type:        security
Severity:    moderate
References:  1254132,CVE-2025-9820
This update for gnutls fixes the following issues:

- CVE-2025-9820: Fixed buffer overflow in gnutls_pkcs11_token_init. (bsc#1254132)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4425-1
Released:    Wed Dec 17 12:20:02 2025
Summary:     Security update for cups
Type:        security
Severity:    moderate
References:  1244057,1254353,CVE-2025-58436
This update for cups fixes the following issues:

Security issues fixed:

- CVE-2025-58436: single client sending slow messages to cupsd can delay the application and make it unusable for other
  clients (bsc#1244057).

Other issues fixed:    
    
- Update the CVE-2025-58436 patch to fix a regression that causes GTK applications to hang (bsc#1254353).
  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:18-1
Released:    Mon Jan  5 11:52:25 2026
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1254297,1254662,1254878,CVE-2025-13601,CVE-2025-14087,CVE-2025-14512
This update for glib2 fixes the following issues:

- CVE-2025-14512: integer overflow in the GIO `escape_byte_string()` function when processing malicious files or remote
  filesystem attribute values can lead to denial-of-service (bsc#1254878).
- CVE-2025-14087: buffer underflow in the GVariant parser `bytestring_parse()` and `string_parse()`functions when
  processing attacker-influenced data may lead to crash or code execution (bsc#1254662).
- CVE-2025-13601: heap-based buffer overflow in the `g_escape_uri_string()` function when processing strings with a
  large number of unacceptable characters may lead to crash or code execution (bsc#1254297).

  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:224-1
Released:    Thu Jan 22 13:18:20 2026
Summary:     Security update for libtasn1
Type:        security
Severity:    moderate
References:  1256341,CVE-2025-13151

This update for libtasn1 fixes the following issues:

- CVE-2025-13151: stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:243-1
Released:    Thu Jan 22 14:57:36 2026
Summary:     Security update for librsvg
Type:        security
Severity:    moderate
References:  1243867,CVE-2024-12224
This update for librsvg fixes the following issues:

Update to version 2.57.4 - bsc#1243867:

  + CVE-2024-12224: RUSTSEC-2024-0421 - idna accepts Punycode labels that do not produce any non-ASCII when decoded.
  + RUSTSEC-2024-0404 - Unsoundness in anstream.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:259-1
Released:    Thu Jan 22 17:10:44 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1256498,1256499,1256500,CVE-2025-68276,CVE-2025-68468,CVE-2025-68471
This update for avahi fixes the following issues:

- CVE-2025-68276: Fixed refuse to create wide-area record browsers when 
  wide-area is off (bsc#1256498)
- CVE-2025-68471: Fixed DoS bug by changing assert to return (bsc#1256500)
- CVE-2025-68468: Fixed DoS bug by removing incorrect assertion (bsc#1256499)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:286-1
Released:    Sat Jan 24 00:35:35 2026
Summary:     Security update for glib2
Type:        security
Severity:    low
References:  1257049,CVE-2026-0988
This update for glib2 fixes the following issues:

- CVE-2026-0988: Fixed a potential integer overflow in g_buffered_input_stream_peek (bsc#1257049).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:287-1
Released:    Sat Jan 24 00:35:49 2026
Summary:     Security update for harfbuzz
Type:        security
Severity:    moderate
References:  1256459,CVE-2026-22693
This update for harfbuzz fixes the following issues:

- CVE-2026-22693: Fixed a NULL pointer dereference in SubtableUnicodesCache::create (bsc#1256459).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:373-1
Released:    Wed Feb  4 03:50:41 2026
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1257353,1257354,1257355,CVE-2026-1484,CVE-2026-1485,CVE-2026-1489
This update for glib2 fixes the following issues:

- CVE-2026-1485: Fixed buffer underflow and out-of-bounds access due to integer wraparound in content type parsing (bsc#1257354).
- CVE-2026-1484: Fixed buffer underflow and out-of-bounds access due to miscalculated buffer boundaries in the Base64 encoding routine (bsc#1257355).
- CVE-2026-1489: Fixed undersized heap allocation followed by out-of-bounds access due to integer overflow in Unicode case conversion (bsc#1257353).
  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:432-1
Released:    Wed Feb 11 10:11:56 2026
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1248586,1254670,CVE-2025-7709
This update for sqlite3 fixes the following issues:

- Update to v3.51.2:
- CVE-2025-7709: Fixed an integer overflow in the FTS5 extension. (bsc#1254670)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:605-1
Released:    Tue Feb 24 12:19:11 2026
Summary:     Security update for libxml2
Type:        security
Severity:    moderate
References:  1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757
This update for libxml2 fixes the following issues:

- CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811)
- CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812)
- CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595)
- CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553)
- CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858)
- CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:813-1
Released:    Thu Mar  5 09:33:59 2026
Summary:     Security update for mozilla-nss
Type:        security
Severity:    moderate
References:  1258568,CVE-2026-2781
This update for mozilla-nss fixes the following issues:

Update to NSS 3.112.3:

* CVE-2026-2781: Avoid integer overflow in platform-independent ghash (bsc#1258568)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:829-1
Released:    Thu Mar  5 16:17:08 2026
Summary:     Security update for gnutls
Type:        security
Severity:    moderate
References:  1257960,1258083,CVE-2025-14831
This update for gnutls fixes the following issues:

Security issue:

- CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a
  large number of name constraints and subject alternative names (bsc#1257960).

Other updates and bugfixes:

- update libgnutls package to avoid binder getting calculated with SHA256 (bsc#1258083, jsc#PED-15752, jsc#PED-15753).
- lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2
- tests/psk-file: Add testing for _credentials2 functions
- lib/psk: add null check for binder algo
- pre_shared_key: fix memleak when retrying with different binder algo
- pre_shared_key: add null check on pskcred

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1065-1
Released:    Thu Mar 26 11:38:12 2026
Summary:     Security update for sqlite3
Type:        security
Severity:    moderate
References:  1254670,1259619,CVE-2025-70873,CVE-2025-7709
This update for sqlite3 fixes the following issues:

Update sqlite3 to 3.51.3:

- CVE-2025-7709: Integer Overflow in FTS5 Extension (bsc#1254670).
- CVE-2025-70873: SQLite zipfile extension may disclose uninitialized heap memory during inflation (bsc#1259619).

Changelog:

 * Fix the WAL-reset database corruption bug:
   https://sqlite.org/wal.html#walresetbug

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1399-1
Released:    Thu Apr 16 12:44:14 2026
Summary:     Security update for cups
Type:        security
Severity:    important
References:  1261568,CVE-2026-34990
This update for cups fixes the following issue:

- CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1441-1
Released:    Fri Apr 17 16:18:19 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1257235,CVE-2026-24401
This update for avahi fixes the following issue:

- CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response
  containing a recursive CNAME record (bsc#1257235).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:1561-1
Released:    Thu Apr 23 08:34:49 2026
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  
This update for mozilla-nss fixes the following issues:

Update to NSS 3.112.4:

  * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey.
  * Improving the allocation of S/MIME DecryptSymKey.
  * store email on subject cache_entry in NSS trust domain.
  * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation.
  * Improve size calculations in CMS content buffering.
  * avoid integer overflow while escaping RFC822 Names.
  * Reject excessively large ASN.1 SEQUENCE OF in quickder.
  * Deep copy profile data in CERT_FindSMimeProfile.
  * Improve input validation in DSAU signature decoding.
  * avoid integer overflow in RSA_EMSAEncodePSS.
  * RSA_EMSAEncodePSS should validate the length of mHash.
  * Add a maximum cert uncompressed len and tests.
  * Clarify extension negotiation mechanism for TLS Handshakes.
  * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree.
  * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag.
  * Remove invalid PORT_Free().
  * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed.
  * make ss->ssl3.hs.cookie an owned-copy of the cookie. 

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1576-1
Released:    Thu Apr 23 17:53:21 2026
Summary:     Security update for gdk-pixbuf
Type:        security
Severity:    important
References:  1261210,CVE-2026-5201
This update for gdk-pixbuf fixes the following issue:

- CVE-2026-5201: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
  (bsc#1261210).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1750-1
Released:    Thu May  7 13:52:09 2026
Summary:     Security update for librsvg
Type:        security
Severity:    important
References:  1257922,CVE-2026-25727
This update for librsvg fixes the following issue:

- CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion
  (bsc#1257922).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1845-1
Released:    Wed May 13 17:26:41 2026
Summary:     Security update for Mesa
Type:        security
Severity:    moderate
References:  1261998,CVE-2026-40393
This update for Mesa fixes the following issue:

- CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on
  an untrusted party (bsc#1261998).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1967-1
Released:    Mon May 18 10:12:42 2026
Summary:     Security update for tiff
Type:        security
Severity:    important
References:  1260411,CVE-2026-4775
This update for tiff fixes the following issue

- CVE-2026-4775: signed integer overflow in the `putcontig8bitYCbCr44tile` function (bsc#1260411).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2115-1
Released:    Fri May 29 17:27:13 2026
Summary:     Security update for gnutls
Type:        security
Severity:    important
References:  1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-5260,CVE-2026-5419
This update for gnutls fixes the following issues

- CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707).
- CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715).
- CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716).
- CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704).
- CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705).
- CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708).
- CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709).
- CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710).
- CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711).
- CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712).
- CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713).
- CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2297-1
Released:    Mon Jun  8 12:16:51 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1261546,CVE-2026-34933
This update for avahi fixes the following issue:

- CVE-2026-34933: Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus
  method call with conflicting publish flags (bsc#1261546).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2478-1
Released:    Mon Jun 22 10:46:59 2026
Summary:     Security update for graphite2
Type:        security
Severity:    important
References:  1267733,CVE-2026-50593
This update for graphite2 fixes the following issue:

- CVE-2026-50593: Out-of-bounds write via Graphite actions (bsc#1267733).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2528-1
Released:    Tue Jun 23 11:06:07 2026
Summary:     Security update for sqlite3
Type:        security
Severity:    important
References:  1268012,1268013,CVE-2026-11822,CVE-2026-11824
This update for sqlite3 fixes the following issues

Update to 3.53.2:

- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause
  process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).
- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers
  to cause a crash or execute arbitrary code (bsc#1268013).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2637-1
Released:    Thu Jun 25 17:42:10 2026
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  
This update for mozilla-nss fixes the following issues:

Update to NSS 3.112.5:

* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max.
* update to version 2.84 of builtins module.

- Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2732-1
Released:    Thu Jul  2 19:41:27 2026
Summary:     Security update for cups
Type:        security
Severity:    moderate
References:  1261569,1261570,1261571,1261572,1261742,1261743,CVE-2026-27447,CVE-2026-34978,CVE-2026-34979,CVE-2026-34980,CVE-2026-39314,CVE-2026-39316
This update for cups fixes the following issues

- CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572).
- CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571).
- CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570).
- CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
  (bsc#1261569).
- CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743).
- CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2853-1
Released:    Fri Jul 10 19:54:25 2026
Summary:     Security update for tiff
Type:        security
Severity:    important
References:  1268434,1269779,CVE-2026-12912,CVE-2026-36849,CVE-2026-4775
This update for tiff fixes the following issues:

Update to version 4.7.2.

Security issues fixed:

- CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779).
- CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value
  (bsc#1268434).

Other updates and bugfixes:

- Version 4.7.2:
  - Software configuration changes:
    * cmake: Fix bundle identifiers to use reverse-DNS format
    * cmake: Fix and improve Apple framework build support
    * cmake: Use TurboJPEG CONFIG by default (issue #767)
    * cmake: changes related to 8-/12-bit modes
    * cmake: Replace CMath::CMath with direct link to avoid export.
    * Support for iOS-derived builds
    * Simplify cmake byte order version check
    * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions
    * configure.ac: Require bootstrap with at least Autoconf 2.71.
  - Library changes:
    * New/improved functionalities::
    + Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781)
  - Bug fixes:
    * Handle negative TIFFReadFile results before state updates (issue #854)
    * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip
    * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777)
    * tif_dirwrite.c: add integer overflow checks to allocation size calculations
    * tif_print.c: add integer overflow checks to allocation size calculations
    * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop
    * DumpModeSeek: add bounds check to prevent OOB pointer advance
    * TIFFGrowStrips: fix use-after-free on partial realloc failure.
    * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before
      accessing it.
    * TIFFRGBAImage: avoid int overflows in put functions (issue #830)
    * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792)
    * tif_getimage: Widen pointer-offset arithmetic in tif_getimage
    * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798)
    * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling
      block to prevent out-of-bounds writes. (issue #753)
    * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787)
    * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831)
    * TIFFLinkDirectory() checks for IFD loops (issue #788)
    * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails.
    * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805)
    * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values
      (https://github.com/OSGeo/gdal/issues/13465)
    * tif_getimage: reject tile widths that would overflow toskew (issue #808)
    * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit.
    * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777).
    * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode
      (https://issues.oss-fuzz.com/issues/471328917)
    * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode
    * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755).
    * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749)
    * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892)
    * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory
      disclosure (issue #826)
    * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773)
    * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501)
    * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow
    * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850)
    * PixarLog: error out on invalid ABGR output buffer sizes.
    * PixarLog: complete ABGR bounds check for multi-row strip decoding.
    * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824)
    * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789).
    * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797)
    * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds
      (https://issues.oss-fuzz.com/issues/506737072)
    * OJPEG: fix integer overflow in subsampling buffer allocation.
    * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795).
    * OJPEG fix potential integer overflow/out-of-bounds access (issue #796).
    * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b)
    * fix null pointer deference in issue #782.
    * fix stack-overflow in issue #784.
  - Other changes:
    * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739).
    * Harden integer size and offset calculations (issue #897)
    * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication
    * Move widening casts inside multiplication scope.
    * Lots of compiler warning fixes related to enabling more warning flags
    * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773)
    * TIFFFillStrip(): prevent harmless unsigned integer overflow

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released:    Fri Jul 17 13:39:27 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1269790,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3218-1
Released:    Thu Jul 23 19:34:12 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1255451,CVE-2025-59529
This update for avahi fixes the following issue:

- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3270-1
Released:    Mon Jul 27 13:01:22 2026
Summary:     Security update for alsa
Type:        security
Severity:    moderate
References:  1268853,CVE-2026-56109
This update for alsa fixes the following issue

- CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory
  (bsc#1268853).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3341-1
Released:    Tue Jul 28 12:09:19 2026
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues:

- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
  (bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
  bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
  read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
  bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).


The following package changes have been done:

- gtk3-data-3.24.43-150600.3.10.1 added
- gtk3-schema-3.24.43-150600.3.10.1 added
- hicolor-icon-theme-0.17-150600.19.2 added
- libasound2-1.2.10-150600.4.3.1 added
- libavahi-common3-0.8-150600.15.21.1 added
- libdatrie1-0.2.9-1.25 added
- libepoxy0-1.5.10-150500.1.2 added
- libffi7-3.2.1.git259-10.8 added
- libfribidi0-1.0.10-150400.3.3.1 added
- libglib-2_0-0-2.78.6-150600.4.38.1 added
- libgraphite2-3-1.3.14-150600.3.3.1 added
- libjbig2-2.1-150000.3.5.1 added
- libjpeg8-8.2.2-150600.22.5 added
- liblcms2-2-2.15-150600.3.3.2 added
- libnettle8-3.10.1-150700.2.16 added
- libpixman-1-0-0.43.4-150600.3.3.1 added
- libsqlite3-0-3.53.2-150000.3.42.1 added
- libthai-data-0.1.29-150400.1.4 added
- libudev1-254.27-150600.4.71.2 added
- libunistring2-0.9.10-1.1 added
- libwayland-egl1-99~1.23.1-150700.1.3 added
- mozilla-nspr-4.36.2-150000.3.36.1 added
- libgbm1-24.3.3-150700.93.8.1 added
- libwayland-client0-1.23.1-150700.1.3 added
- libp11-kit0-0.23.22-150500.8.3.1 added
- pkg-config-0.29.2-150600.15.6.3 added
- libgobject-2_0-0-2.78.6-150600.4.38.1 added
- libgmodule-2_0-0-2.78.6-150600.4.38.1 added
- libfreebl3-3.112.5-150400.3.69.2 added
- libhogweed6-3.10.1-150700.2.16 added
- libthai0-0.1.29-150400.1.4 added
- libidn2-0-2.2.0-3.6.1 added
- libxml2-2-2.12.10-150700.4.14.1 added
- libelf1-0.185-150400.5.8.3 added
- libtiff6-4.7.2-150600.3.29.1 added
- mozilla-nss-certs-3.112.5-150400.3.69.2 added
- libxcb-shm0-1.17.0-150700.1.2 added
- libxcb-render0-1.17.0-150700.1.2 added
- libwayland-cursor0-1.23.1-150700.1.3 added
- xkeyboard-config-2.42-150700.1.1 added
- libatk-1_0-0-2.50.0-150600.1.2 added
- shared-mime-info-2.4-150600.3.3.2 added
- libsoftokn3-3.112.5-150400.3.69.2 added
- mozilla-nss-3.112.5-150400.3.69.2 added
- libXrender1-0.9.10-1.30 added
- libXfixes3-6.0.0-150400.1.4 added
- libXdamage1-1.1.4-1.23 added
- libXcomposite1-0.4.4-1.23 added
- libxkbcommon0-1.5.0-150600.3.3.1 added
- libtasn1-6-4.13-150000.4.14.1 added
- libtasn1-4.13-150000.4.14.1 added
- gio-branding-SLE-15-150600.35.2.1 added
- libgio-2_0-0-2.78.6-150600.4.38.1 added
- glib2-tools-2.78.6-150600.4.38.1 added
- libharfbuzz0-8.3.0-150600.3.3.1 added
- libXcursor1-1.1.15-1.18 added
- libXrandr2-1.5.1-2.17 added
- libXinerama1-1.1.3-1.22 added
- libXi6-1.7.9-3.2.1 added
- libavahi-client3-0.8-150600.15.21.1 added
- libgnutls30-3.8.3-150600.4.20.1 added
- libcolord2-1.4.6-150600.3.8.1 added
- gdk-pixbuf-query-loaders-2.42.12-150600.3.11.1 added
- libcairo2-1.18.4-150600.3.3.1 added
- libXft2-2.3.2-1.33 added
- libatspi0-2.50.0-150600.1.2 added
- libgdk_pixbuf-2_0-0-2.42.12-150600.3.11.1 added
- libcairo-gobject2-1.18.4-150600.3.3.1 added
- libpango-1_0-0-1.51.1-150600.1.3 added
- libatk-bridge-2_0-0-2.50.0-150600.1.2 added
- librsvg-2-2-2.57.4-150600.3.8.2 added
- gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 added
- system-user-lp-20170617-150400.24.2.1 added
- cups-config-2.2.7-150000.3.93.1 added
- libcups2-2.2.7-150000.3.93.1 added
- gtk3-tools-3.24.43-150600.3.10.1 added
- libgtk-3-0-3.24.43-150600.3.10.1 added
- container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated
- bash-4.4-150400.27.6.1 removed
- bash-sh-4.4-150400.27.6.1 removed
- coreutils-8.32-150400.9.12.1 removed
- filesystem-15.0-11.8.1 removed
- glibc-2.38-150600.14.52.1 removed
- libacl1-2.2.52-4.3.1 removed
- libattr1-2.4.47-2.19 removed
- libcap2-2.63-150400.3.6.1 removed
- libgcc_s1-15.3.0+git11272-150000.1.12.1 removed
- libgmp10-6.1.2-4.9.1 removed
- libncurses6-6.1-150000.5.33.1 removed
- libpcre2-8-0-10.42-150600.1.26 removed
- libreadline7-7.0-150400.27.6.1 removed
- libselinux1-3.5-150600.3.3.1 removed
- libstdc++6-15.3.0+git11272-150000.1.12.1 removed
- sles-release-15.7-150700.67.6.1 removed
- system-user-root-20190513-3.3.1 removed
- terminfo-base-6.1-150000.5.33.1 removed


More information about the sle-container-updates mailing list