SUSE-CU-2020:389-1: Security update of caasp/v4/gangway
sle-updates at lists.suse.com
sle-updates at lists.suse.com
Wed Aug 12 01:56:23 MDT 2020
SUSE Container Update Advisory: caasp/v4/gangway
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2020:389-1
Container Tags : caasp/v4/gangway:3.1.0 , caasp/v4/gangway:3.1.0-rev4 , caasp/v4/gangway:3.1.0-rev4-build3.10.1
Container Release : 3.10.1
Severity : important
Type : security
References : 1007715 1013125 1051143 1082318 1084671 1084934 1087982 1090047
1092920 1093414 1102840 1103320 1103678 1106383 1107116 1107121
1111499 1114592 1123919 1125689 1130873 1130873 1133297 1133495
1135114 1135254 1137001 1138793 1138869 1139459 1139459 1139939
1139959 1140631 1141897 1142649 1142654 1145023 1145554 1146182
1146184 1146415 1146991 1148517 1148788 1148987 1149145 1149332
1149511 1149995 1150595 1150734 1151023 1151023 1151377 1151582
1152590 1152692 1152755 1153351 1154019 1154036 1154037 1154256
1154295 1154661 1154803 1154803 1154804 1154805 1154871 1154884
1154887 1155198 1155199 1155205 1155207 1155271 1155298 1155327
1155337 1155338 1155339 1155346 1155574 1155678 1155819 1156158
1156159 1156213 1156300 1156482 1156913 1157198 1157278 1157292
1157315 1157377 1157775 1157794 1157893 1158095 1158095 1158101
1158485 1158763 1158809 1158830 1158921 1158996 1159003 1159314
1159814 1159928 1160039 1160160 1160571 1160594 1160595 1160735
1160764 1160970 1160979 1161215 1161216 1161218 1161219 1161220
1161262 1161436 1161517 1161521 1161779 1161816 1162108 1162108
1162152 1162518 1162698 1162930 1163184 1163922 1164505 1164538
1164543 1164543 1164562 1164717 1164950 1164950 1165011 1165476
1165476 1165539 1165573 1165573 1165579 1165784 1166106 1166260
1166481 1166510 1166510 1166610 1166610 1166748 1166881 1167122
1167122 1167163 1167223 1167631 1167674 1167898 1168076 1168345
1168364 1168699 1168835 1168990 1168990 1169357 1169488 1169512
1169569 1169944 1169947 1169947 1169992 1170527 1170771 1170801
1170801 1171145 1171173 1171224 1171224 1171422 1171863 1171864
1171866 1171872 1171883 1172021 1172072 1172135 1172135 1172295
1172348 1172461 1172506 1172698 1172704 1172925 1172925 1173027
1173039 1173055 1173106 1173165 1173227 1173229 1173422 1173984
1174011 CVE-2018-16428 CVE-2018-16429 CVE-2019-12290 CVE-2019-12450
CVE-2019-13012 CVE-2019-13627 CVE-2019-14250 CVE-2019-14866 CVE-2019-14889
CVE-2019-14889 CVE-2019-1551 CVE-2019-15847 CVE-2019-17594 CVE-2019-17595
CVE-2019-18218 CVE-2019-18224 CVE-2019-18802 CVE-2019-18900 CVE-2019-19126
CVE-2019-19956 CVE-2019-19956 CVE-2019-20386 CVE-2019-20388 CVE-2019-3687
CVE-2019-3688 CVE-2019-3690 CVE-2019-5188 CVE-2019-9511 CVE-2019-9513
CVE-2020-10029 CVE-2020-10543 CVE-2020-10878 CVE-2020-11501 CVE-2020-12243
CVE-2020-12723 CVE-2020-13777 CVE-2020-1712 CVE-2020-1712 CVE-2020-1730
CVE-2020-1752 CVE-2020-7595 CVE-2020-8013 CVE-2020-8023 CVE-2020-8177
CVE-2020-8557 SLE-6533 SLE-6536 SLE-7687 SLE-8789 SLE-9171
-----------------------------------------------------------------
The container caasp/v4/gangway was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2018:2780-1
Released: Mon Nov 26 17:46:10 2018
Summary: Security update for glib2
Type: security
Severity: moderate
References: 1107116,1107121,1111499,CVE-2018-16428,CVE-2018-16429
This update for glib2 fixes the following issues:
Security issues fixed:
- CVE-2018-16428: Do not do a NULL pointer dereference (crash).
Avoid that, at the cost of introducing a new translatable error
message (bsc#1107121).
- CVE-2018-16429: Fixed out-of-bounds read vulnerability ing_markup_parse_context_parse() (bsc#1107116).
Non-security issue fixed:
- various GVariant parsing issues have been resolved (bsc#1111499)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:251-1
Released: Wed Feb 6 11:22:43 2019
Summary: Recommended update for glib2
Type: recommended
Severity: moderate
References: 1090047
This update for glib2 provides the following fix:
- Enable systemtap. (fate#326393, bsc#1090047)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:1594-1
Released: Fri Jun 21 10:17:15 2019
Summary: Security update for glib2
Type: security
Severity: important
References: 1103678,1137001,CVE-2019-12450
This update for glib2 fixes the following issues:
Security issue fixed:
- CVE-2019-12450: Fixed an improper file permission when copy operation
takes place (bsc#1137001).
Other issue addressed:
- glib2 was handling an UNKNOWN connectivity state from NetworkManager as if there
was a connection thus giving false positives to PackageKit (bsc#1103678)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:1833-1
Released: Fri Jul 12 17:53:51 2019
Summary: Security update for glib2
Type: security
Severity: moderate
References: 1139959,CVE-2019-13012
This update for glib2 fixes the following issues:
Security issue fixed:
- CVE-2019-13012: Fixed improper restriction of file permissions when creating directories (bsc#1139959).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:2812-1
Released: Tue Oct 29 14:57:55 2019
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1139459,1140631,1145023,1150595,SLE-7687
This update for systemd provides the following fixes:
- Fix a problem that would cause invoking try-restart to an inactive service to hang when
a daemon-reload is invoked before the try-restart returned. (bsc#1139459)
- man: Add a note about _netdev usage.
- units: Replace remote-cryptsetup-pre.target with remote-fs-pre.target.
- units: Add [Install] section to remote-cryptsetup.target.
- cryptsetup: Ignore _netdev, since it is used in generator.
- cryptsetup-generator: Use remote-cryptsetup.target when _netdev is present. (jsc#SLE-7687)
- cryptsetup-generator: Add a helper utility to create symlinks.
- units: Add remote-cryptsetup.target and remote-cryptsetup-pre.target.
- man: Add an explicit description of _netdev to systemd.mount(5).
- man: Order fields alphabetically in crypttab(5).
- man: Make crypttab(5) a bit easier to read.
- units: Order cryptsetup-pre.target before cryptsetup.target.
- Fix reporting of enabled-runtime units.
- sd-bus: Deal with cookie overruns. (bsc#1150595)
- rules: Add by-id symlinks for persistent memory. (bsc#1140631)
- Buildrequire polkit so /usr/share/polkit-1/rules.d subdir can be only owned by polkit.
(bsc#1145023)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:2870-1
Released: Thu Oct 31 08:09:14 2019
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1051143,1138869,1151023
This update for aaa_base provides the following fixes:
- Check if variables can be set before modifying them to avoid warnings on login with a
restricted shell. (bsc#1138869)
- Add s390x compressed kernel support. (bsc#1151023)
- service: Check if there is a second argument before using it. (bsc#1051143)
-----------------------------------------------------------------
Advisory ID: SUSE-OU-2019:2980-1
Released: Thu Nov 14 22:45:33 2019
Summary: Optional update for curl
Type: optional
Severity: low
References: 1154019
This update for curl doesn't address any user visible issues.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:2997-1
Released: Mon Nov 18 15:16:38 2019
Summary: Security update for ncurses
Type: security
Severity: moderate
References: 1103320,1154036,1154037,CVE-2019-17594,CVE-2019-17595
This update for ncurses fixes the following issues:
Security issues fixed:
- CVE-2019-17594: Fixed a heap-based buffer over-read in the _nc_find_entry function (bsc#1154036).
- CVE-2019-17595: Fixed a heap-based buffer over-read in the fmt_entry function (bsc#1154037).
Non-security issue fixed:
- Removed screen.xterm from terminfo database (bsc#1103320).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:3010-1
Released: Tue Nov 19 18:10:58 2019
Summary: Recommended update for zypper and libsolv
Type: recommended
Severity: moderate
References: 1145554,1146415,1149511,1153351,SLE-9171
This update for zypper and libsolv fixes the following issues:
Package: zypper
- Improved the documentation of $releasever and --releasever usescases (bsc#1149511)
- zypper will now ask only once when multiple packages share the same license text (bsc#1145554)
- Added a new 'solver.focus' option for /etc/zypp/zypp.conf to define systemwide focus
mode when resolving jobs (bsc#1146415)
- Fixes an issue where 'zypper lu' didn't list all available package updates (bsc#1153351)
- Added a new --repo option to the 'download' command to allow to specify a repository (jsc#SLE-9171)
Package: libsolv
- Fixes issues when updating too many packages in focusbest mode
- Fixes the handling of disabled and installed packages in distupgrade
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3059-1
Released: Mon Nov 25 17:33:07 2019
Summary: Security update for cpio
Type: security
Severity: moderate
References: 1155199,CVE-2019-14866
This update for cpio fixes the following issues:
- CVE-2019-14866: Fixed an improper validation of the values written
in the header of a TAR file through the to_oct() function which could
have led to unexpected TAR generation (bsc#1155199).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3061-1
Released: Mon Nov 25 17:34:22 2019
Summary: Security update for gcc9
Type: security
Severity: moderate
References: 1114592,1135254,1141897,1142649,1142654,1148517,1149145,CVE-2019-14250,CVE-2019-15847,SLE-6533,SLE-6536
This update includes the GNU Compiler Collection 9.
A full changelog is provided by the GCC team on:
https://www.gnu.org/software/gcc/gcc-9/changes.html
The base system compiler libraries libgcc_s1, libstdc++6 and others are
now built by the gcc 9 packages.
To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 /
CXX=g++-9 during configuration for using it.
Security issues fixed:
- CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145)
- CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649)
Non-security issues fixed:
- Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254)
- Fixed miscompilation for vector shift on s390. (bsc#1141897)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:3070-1
Released: Tue Nov 26 12:39:29 2019
Summary: Recommended update for gpg2
Type: recommended
Severity: low
References: 1152755
This update for gpg2 provides the following fix:
- Remove a build requirement on self. This is causing Leap 15.2 bootstrap to fail. (bsc#1152755)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3086-1
Released: Thu Nov 28 10:02:24 2019
Summary: Security update for libidn2
Type: security
Severity: moderate
References: 1154884,1154887,CVE-2019-12290,CVE-2019-18224
This update for libidn2 to version 2.2.0 fixes the following issues:
- CVE-2019-12290: Fixed an improper round-trip check when converting A-labels to U-labels (bsc#1154884).
- CVE-2019-18224: Fixed a heap-based buffer overflow that was caused by long domain strings (bsc#1154887).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3087-1
Released: Thu Nov 28 10:03:00 2019
Summary: Security update for libxml2
Type: security
Severity: low
References: 1123919
This update for libxml2 doesn't fix any additional security issues, but correct its rpm changelog to reflect
all CVEs that have been fixed over the past.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:3118-1
Released: Fri Nov 29 14:41:35 2019
Summary: Recommended update for e2fsprogs
Type: recommended
Severity: moderate
References: 1154295
This update for e2fsprogs fixes the following issues:
- Make minimum size estimates more reliable for mounted filesystem. (bsc#1154295)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:3166-1
Released: Wed Dec 4 11:24:42 2019
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1007715,1084934,1157278
This update for aaa_base fixes the following issues:
- Use official key binding functions in inputrc that is replace up-history with previous-history, down-history with next-history and backward-delete-word with backward-kill-word. (bsc#1084934)
- Add some missed key escape sequences for urxvt-unicode terminal as well. (bsc#1007715)
- Clear broken ghost entry in patch which breaks 'readline'. (bsc#1157278)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3181-1
Released: Thu Dec 5 11:43:07 2019
Summary: Security update for permissions
Type: security
Severity: moderate
References: 1093414,1150734,1157198,CVE-2019-3688,CVE-2019-3690
This update for permissions fixes the following issues:
- CVE-2019-3688: Changed wrong ownership in /usr/sbin/pinger to root:squid
which could have allowed a squid user to gain persistence by changing the
binary (bsc#1093414).
- CVE-2019-3690: Fixed a privilege escalation through untrusted symbolic
links (bsc#1150734).
- Fixed a regression which caused sagmentation fault (bsc#1157198).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2019:3240-1
Released: Tue Dec 10 10:40:19 2019
Summary: Recommended update for ca-certificates-mozilla, p11-kit
Type: recommended
Severity: moderate
References: 1154871
This update for ca-certificates-mozilla, p11-kit fixes the following issues:
Changes in ca-certificates-mozilla:
- export correct p11kit trust attributes so Firefox detects built in
certificates (bsc#1154871).
Changes in p11-kit:
- support loading NSS attribute CKA_NSS_MOZILLA_CA_POLICY so Firefox
detects built in certificates (bsc#1154871)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3267-1
Released: Wed Dec 11 11:19:53 2019
Summary: Security update for libssh
Type: security
Severity: important
References: 1158095,CVE-2019-14889
This update for libssh fixes the following issues:
- CVE-2019-14889: Fixed an arbitrary command execution (bsc#1158095).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2019:3392-1
Released: Fri Dec 27 13:33:29 2019
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1148987,1155338,1155339,CVE-2019-13627
This update for libgcrypt fixes the following issues:
Security issues fixed:
- CVE-2019-13627: Mitigation against an ECDSA timing attack (bsc#1148987).
Bug fixes:
- Added CMAC AES self test (bsc#1155339).
- Added CMAC TDES self test missing (bsc#1155338).
- Fix test dsa-rfc6979 in FIPS mode.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:69-1
Released: Fri Jan 10 12:33:59 2020
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1155346,1157775,1158101,1158809,CVE-2019-1551,SLE-8789
This update for openssl-1_1 fixes the following issues:
Security issue fixed:
- CVE-2019-1551: Fixed an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli (bsc#1158809).
Various FIPS related improvements were done:
- FIPS: Backport SSH KDF to openssl (jsc#SLE-8789, bsc#1157775).
- Port FIPS patches from SLE-12 (bsc#1158101).
- Use SHA-2 in the RSA pairwise consistency check (bsc#1155346).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:129-1
Released: Mon Jan 20 09:21:13 2020
Summary: Security update for libssh
Type: security
Severity: important
References: 1158095,CVE-2019-14889
This update for libssh fixes the following issues:
- CVE-2019-14889: Fixed an unwanted command execution in scp caused by unsanitized location (bsc#1158095).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:225-1
Released: Fri Jan 24 06:49:07 2020
Summary: Recommended update for procps
Type: recommended
Severity: moderate
References: 1158830
This update for procps fixes the following issues:
- Fix for 'ps -C' allowing to accept any arguments longer than 15 characters anymore. (bsc#1158830)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:256-1
Released: Wed Jan 29 09:39:17 2020
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1157794,1160970
This update for aaa_base fixes the following issues:
- Improves the way how the Java path is created to fix an issue with sapjvm. (bsc#1157794)
- Drop 'dev.cdrom.autoclose' = 0 from sysctl config. (bsc#1160970)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:262-1
Released: Thu Jan 30 11:02:42 2020
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1149332,1151582,1157292,1157893,1158996,CVE-2019-19126
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2019-19126: Fixed to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition (bsc#1157292).
Bug fixes:
- Fixed z15 (s390x) strstr implementation that can return incorrect results if search string cross page boundary (bsc#1157893).
- Fixed Hardware support in toolchain (bsc#1151582).
- Fixed syscalls during early process initialization (SLE-8348).
- Fixed an array overflow in backtrace for PowerPC (bsc#1158996).
- Moved to posix_spawn on popen (bsc#1149332).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:265-1
Released: Thu Jan 30 14:05:34 2020
Summary: Security update for e2fsprogs
Type: security
Severity: moderate
References: 1160571,CVE-2019-5188
This update for e2fsprogs fixes the following issues:
- CVE-2019-5188: Fixed a code execution vulnerability in the directory rehashing functionality (bsc#1160571).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:279-1
Released: Fri Jan 31 12:01:39 2020
Summary: Recommended update for p11-kit
Type: recommended
Severity: moderate
References: 1013125
This update for p11-kit fixes the following issues:
- Also build documentation (bsc#1013125)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:335-1
Released: Thu Feb 6 11:37:24 2020
Summary: Security update for systemd
Type: security
Severity: important
References: 1084671,1092920,1106383,1133495,1151377,1154256,1155207,1155574,1156213,1156482,1158485,1159814,1161436,1162108,CVE-2019-20386,CVE-2020-1712
This update for systemd fixes the following issues:
- CVE-2020-1712 (bsc#bsc#1162108)
Fix a heap use-after-free vulnerability, when asynchronous
Polkit queries were performed while handling Dbus messages. A local
unprivileged attacker could have abused this flaw to crash systemd services or
potentially execute code and elevate their privileges, by sending specially
crafted Dbus messages.
- Use suse.pool.ntp.org server pool on SLE distros (jsc#SLE-7683)
- libblkid: open device in nonblock mode. (bsc#1084671)
- udev/cdrom_id: Do not open CD-rom in exclusive mode. (bsc#1154256)
- bus_open leak sd_event_source when udevadm triggerã (bsc#1161436 CVE-2019-20386)
- fileio: introduce read_full_virtual_file() for reading virtual files in sysfs, procfs (bsc#1133495 bsc#1159814)
- fileio: initialize errno to zero before we do fread()
- fileio: try to read one byte too much in read_full_stream()
- logind: consider 'greeter' sessions suitable as 'display' sessions of a user (bsc#1158485)
- logind: never elect a session that is stopping as display
- journal: include kmsg lines from the systemd process which exec()d us (#8078)
- udevd: don't use monitor after manager_exit()
- udevd: capitalize log messages in on_sigchld()
- udevd: merge conditions to decrease indentation
- Revert 'udevd: fix crash when workers time out after exit is signal caught'
- core: fragments of masked units ought not be considered for NeedDaemonReload (#7060) (bsc#1156482)
- udevd: fix crash when workers time out after exit is signal caught
- udevd: wait for workers to finish when exiting (bsc#1106383)
- Improve bash completion support (bsc#1155207)
* shell-completion: systemctl: do not list template units in {re,}start
* shell-completion: systemctl: pass current word to all list_unit*
* bash-completion: systemctl: pass current partial unit to list-unit* (bsc#1155207)
* bash-completion: systemctl: use systemctl --no-pager
* bash-completion: also suggest template unit files
* bash-completion: systemctl: add missing options and verbs
* bash-completion: use the first argument instead of the global variable (#6457)
- networkd: VXLan Make group and remote variable separate (bsc#1156213)
- networkd: vxlan require Remote= to be a non multicast address (#8117) (bsc#1156213)
- fs-util: let's avoid unnecessary strerror()
- fs-util: introduce inotify_add_watch_and_warn() helper
- ask-password: improve log message when inotify limit is reached (bsc#1155574)
- shared/install: failing with -ELOOP can be due to the use of an alias in install_error() (bsc#1151377)
- man: alias names can't be used with enable command (bsc#1151377)
- Add boot option to not use swap at system start (jsc#SLE-7689)
- Allow YaST to select Iranian (Persian, Farsi) keyboard layout
(bsc#1092920)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:339-1
Released: Thu Feb 6 13:03:22 2020
Summary: Recommended update for openldap2
Type: recommended
Severity: low
References: 1158921
This update for openldap2 provides the following fix:
- Add libldap-data to the product (as it contains ldap.conf). (bsc#1158921)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:432-1
Released: Fri Feb 21 14:34:16 2020
Summary: Security update for libsolv, libzypp, zypper
Type: security
Severity: moderate
References: 1135114,1154804,1154805,1155198,1155205,1155298,1155678,1155819,1156158,1157377,1158763,CVE-2019-18900
This update for libsolv, libzypp, zypper fixes the following issues:
Security issue fixed:
- CVE-2019-18900: Fixed assert cookie file that was world readable (bsc#1158763).
Bug fixes
- Fixed removing orphaned packages dropped by to-be-installed products (bsc#1155819).
- Adds libzypp API to mark all obsolete kernels according to the existing purge-kernel script rules (bsc#1155198).
- Do not enforce 'en' being in RequestedLocales If the user decides to have a system without explicit language support he may do so (bsc#1155678).
- Load only target resolvables for zypper rm (bsc#1157377).
- Fix broken search by filelist (bsc#1135114).
- Replace python by a bash script in zypper-log (fixes#304, fixes#306, bsc#1156158).
- Do not sort out requested locales which are not available (bsc#1155678).
- Prevent listing duplicate matches in tables. XML result is provided within the new list-patches-byissue element (bsc#1154805).
- XML add patch issue-date and issue-list (bsc#1154805).
- Fix zypper lp --cve/bugzilla/issue options (bsc#1155298).
- Always execute commit when adding/removing locales (fixes bsc#1155205).
- Fix description of --table-style,-s in man page (bsc#1154804).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:451-1
Released: Tue Feb 25 10:50:35 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1155337,1161215,1161216,1161218,1161219,1161220
This update for libgcrypt fixes the following issues:
- ECDSA: Check range of coordinates (bsc#1161216)
- FIPS: libgcrypt DSA PQG parameter generation: Missing value [bsc#1161219]
- FIPS: libgcrypt DSA PQG verification incorrect results [bsc#1161215]
- FIPS: libgcrypt RSA siggen/keygen: 4k not supported [bsc#1161220]
- FIPS: keywrap gives incorrect results [bsc#1161218]
- FIPS: RSA/DSA/ECDSA are missing hashing operation [bsc#1155337]
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:476-1
Released: Tue Feb 25 14:23:14 2020
Summary: Recommended update for perl
Type: recommended
Severity: moderate
References: 1102840,1160039
This update for perl fixes the following issues:
- Some packages make assumptions about the date and time they are built.
This update will solve the issues caused by calling the perl function timelocal
expressing the year with two digit only instead of four digits. (bsc#1102840) (bsc#1160039)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:480-1
Released: Tue Feb 25 17:38:22 2020
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1160735
This update for aaa_base fixes the following issues:
- Change 'rp_filter' to increase the default priority to ethernet over the wifi. (bsc#1160735)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:525-1
Released: Fri Feb 28 11:49:36 2020
Summary: Recommended update for pam
Type: recommended
Severity: moderate
References: 1164562
This update for pam fixes the following issues:
- Add libdb as build-time dependency to enable pam_userdb module.
Enable pam_userdb.so (jsc#sle-7258, bsc#1164562)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:547-1
Released: Fri Feb 28 16:26:21 2020
Summary: Security update for permissions
Type: security
Severity: moderate
References: 1148788,1160594,1160764,1161779,1163922,CVE-2019-3687,CVE-2020-8013
This update for permissions fixes the following issues:
Security issues fixed:
- CVE-2019-3687: Fixed a privilege escalation which could allow a local user to read network traffic if wireshark is installed (bsc#1148788)
- CVE-2020-8013: Fixed an issue where chkstat set unintended setuid/capabilities for mrsh and wodim (bsc#1163922).
Non-security issues fixed:
- Fixed a regression where chkstat breaks without /proc available (bsc#1160764, bsc#1160594).
- Fixed capability handling when doing multiple permission changes at once (bsc#1161779).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:572-1
Released: Tue Mar 3 13:25:41 2020
Summary: Recommended update for cyrus-sasl
Type: recommended
Severity: moderate
References: 1162518
This update for cyrus-sasl fixes the following issues:
- Added support for retrieving negotiated SSF in gssapi plugin (bsc#1162518)
- Fixed GSS-SPNEGO to use flags negotiated by GSSAPI for SSF (bsc#1162518)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:573-1
Released: Tue Mar 3 13:37:28 2020
Summary: Recommended update for ca-certificates-mozilla
Type: recommended
Severity: moderate
References: 1160160
This update for ca-certificates-mozilla to 2.40 fixes the following issues:
Updated to 2.40 state of the Mozilla NSS Certificate store (bsc#1160160):
Removed certificates:
- Certplus Class 2 Primary CA
- Deutsche Telekom Root CA 2
- CN=Swisscom Root CA 2
- UTN-USERFirst-Client Authentication and Email
added certificates:
- Entrust Root Certification Authority - G4
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:597-1
Released: Thu Mar 5 15:24:09 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1164950
This update for libgcrypt fixes the following issues:
- FIPS: Run the self-tests from the constructor [bsc#1164950]
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:633-1
Released: Tue Mar 10 16:23:08 2020
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1139939,1151023
This update for aaa_base fixes the following issues:
- get_kernel_version: fix for current kernel on s390x (bsc#1151023, bsc#1139939)
- added '-h'/'--help' to the command old
- change feedback url from http://www.suse.de/feedback to https://github.com/openSUSE/aaa_base/issues
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:668-1
Released: Fri Mar 13 10:48:58 2020
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1163184,1164505,1165784,CVE-2020-10029
This update for glibc fixes the following issues:
- CVE-2020-10029: Fixed a potential overflow in on-stack buffer
during range reduction (bsc#1165784).
- Fixed an issue where pthread were not always locked correctly (bsc#1164505).
- Document mprotect and introduce section on memory protection (bsc#1163184).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:689-1
Released: Fri Mar 13 17:09:01 2020
Summary: Recommended update for pam
Type: recommended
Severity: moderate
References: 1166510
This update for PAM fixes the following issue:
- The license of libdb linked against pam_userdb is not always wanted,
so we temporary disabled pam_userdb again. It will be published
in a different package at a later time. (bsc#1166510)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:475-1
Released: Thu Mar 19 11:00:46 2020
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1160595
This update for systemd fixes the following issues:
- Remove TasksMax limit for both user and system slices (jsc#SLE-10123)
- Backport IP filtering feature (jsc#SLE-7743 bsc#1160595)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:726-1
Released: Thu Mar 19 13:23:03 2020
Summary: Security update for nghttp2
Type: security
Severity: moderate
References: 1125689,1146182,1146184,1159003,1166481,CVE-2019-18802,CVE-2019-9511,CVE-2019-9513
This update for nghttp2 fixes the following issues:
Security issues fixed:
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).
- CVE-2019-18802: Fixed malformed request header may cause bypass of route matchers resulting in escalation of privileges or information disclosure (bsc#1159003)
Bug fixes and enhancements:
- Fixed mistake in spec file (bsc#1125689)
Update to version 1.40.0 to fix CVE-2019-18802 in envoy-proxy and
cilium-proxy (bsc#1166481)
* lib: Add nghttp2_check_authority as public API
* lib: Fix the bug that stream is closed with wrong error code
* lib: Faster huffman encoding and decoding
* build: Avoid filename collision of static and dynamic lib
* build: Add new flag ENABLE_STATIC_CRT for Windows
* build: cmake: Support building nghttpx with systemd
* third-party: Update neverbleed to fix memory leak
* nghttpx: Fix bug that mruby is incorrectly shared between
backends
* nghttpx: Reconnect h1 backend if it lost connection before
sending headers
* nghttpx: Returns 408 if backend timed out before sending
headers
* nghttpx: Fix request stal
- Conditionally remove dependecy on jemalloc for SLE-12
- Require correct library from devel package - boo#1125689
Update to version 1.39.2 (bsc#1146184, bsc#1146182):
* This release fixes CVE-2019-9511 âData Dribbleâ and CVE-2019-9513
âResource Loopâ vulnerability in nghttpx and nghttpd. Specially crafted HTTP/2
frames cause Denial of Service by consuming CPU time. Check out
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
for details. For nghttpx, additionally limiting inbound traffic by
--read-rate and --read-burst options is quite effective against
this kind of attack.
* Add nghttp2_option_set_max_outbound_ack API function
* nghttpx: Fix request stall
Update to version 1.39.1:
* This release fixes the bug that log-level is not set with
cmd-line or configuration file. It also fixes FPE with default
backend.
Changes for version 1.39.0:
* libnghttp2 now ignores content-length in 200 response to
CONNECT request as per RFC 7230.
* mruby has been upgraded to 2.0.1.
* libnghttp2-asio now supports boost-1.70.
* http-parser has been replaced with llhttp.
* nghttpx now ignores Content-Length and Transfer-Encoding in 1xx
or 200 to CONNECT.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:729-1
Released: Thu Mar 19 14:44:22 2020
Summary: Recommended update for glibc
Type: recommended
Severity: moderate
References: 1166106
This update for glibc fixes the following issues:
- Allow dlopen of filter object to work (bsc#1166106, BZ #16272)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:793-1
Released: Wed Mar 25 15:16:00 2020
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1139459,1161262,1162108,1164717,1165579,CVE-2020-1712
This update for systemd fixes the following issues:
- manager: fix job mode when signalled to shutdown etc (bsc#1161262)
- remove fallback for user/exit.target
- dbus method Manager.Exit() does not start exit.target
- do not install rescue.target for alt-â
- %j/%J unit specifiers
Added support for I/O scheduler selection with blk-mq (bsc#1165579, bsc#1164717).
Added the udev 60-ssd-scheduler.rules:
- This rules file which select the default IO scheduler for SSDs is
being moved out from the git repo since this is not related to
systemd or udev at all and is maintained by the kernel team.
- core: coldplug possible nop_job (bsc#1139459)
- Revert 'udev: use 'deadline' IO scheduler for SSD disks'
- Fix typo in function name
- polkit: when authorizing via PK let's re-resolve callback/userdata instead of caching it (bsc#1162108 CVE-2020-1712)
- sd-bus: introduce API for re-enqueuing incoming messages
- polkit: on async pk requests, re-validate action/details
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:814-1
Released: Mon Mar 30 16:23:42 2020
Summary: Recommended update for QR-Code-generator, boost, libreoffice, myspell-dictionaries, xmlsec1
Type: recommended
Severity: moderate
References: 1161816,1162152,1167223
This update for QR-Code-generator, boost, libreoffice, myspell-dictionaries, xmlsec1 fixes the following issues:
libreoffice was updated to 6.4.2.2 (jsc#SLE-11174 jsc#SLE-11175 jsc#SLE-11176 bsc#1167223):
Full Release Notes can be found on:
https://wiki.documentfoundation.org/ReleaseNotes/6.4
- Fixed broken handling of non-ASCII characters in the KDE filedialog
(bsc#1161816)
- Move the animation library to core package bsc#1162152
xmlsec1 was updated to 1.2.28:
* Added BoringSSL support (chenbd).
* Added gnutls-3.6.x support (alonbl).
* Added DSA and ECDSA key size getter for MSCNG (vmiklos).
* Added --enable-mans configuration option (alonbl).
* Added coninuous build integration for MacOSX (vmiklos).
* Several other small fixes (more details).
- Make sure to recommend at least one backend when you install
just xmlsec1
- Drop the gnutls backend as based on the tests it is quite borked:
* We still have nss and openssl backend for people to use
Version update to 1.2.27:
* Added AES-GCM support for OpenSSL and MSCNG (snargit).
* Added DSA-SHA256 and ECDSA-SHA384 support for NSS (vmiklos).
* Added RSA-OAEP support for MSCNG (vmiklos).
* Continuous build integration in Travis and Appveyor.
* Several other small fixes (more details).
myspell-dictionaries was updated to 20191219:
* Updated the English dictionaries: GB+US+CA+AU
* Bring shipped Spanish dictionary up to version 2.5
boost was updated to fix:
- add a backport of Boost.Optional::has_value() for LibreOffice
The QR-Code-generator is shipped:
- Initial commit, needed by libreoffice 6.4
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:820-1
Released: Tue Mar 31 13:02:22 2020
Summary: Security update for glibc
Type: security
Severity: important
References: 1167631,CVE-2020-1752
This update for glibc fixes the following issues:
- CVE-2020-1752: Fixed a use after free in glob which could have allowed
a local attacker to create a specially crafted path that, when processed
by the glob function, could potentially have led to arbitrary code execution
(bsc#1167631).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:834-1
Released: Tue Mar 31 17:21:34 2020
Summary: Recommended update for permissions
Type: recommended
Severity: moderate
References: 1167163
This update for permissions fixes the following issue:
- whitelist s390-tools set group ID (setgid) bit on log directory. (bsc#1167163)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:846-1
Released: Thu Apr 2 07:24:07 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1164950,1166748,1167674
This update for libgcrypt fixes the following issues:
- FIPS: Remove an unneeded check in _gcry_global_constructor (bsc#1164950)
- FIPS: Fix drbg to be threadsafe (bsc#1167674)
- FIPS: Run self-tests from constructor during power-on [bsc#1166748]
* Set up global_init as the constructor function:
* Relax the entropy requirements on selftest. This is especially
important for virtual machines to boot properly before the RNG
is available:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:917-1
Released: Fri Apr 3 15:02:25 2020
Summary: Recommended update for pam
Type: recommended
Severity: moderate
References: 1166510
This update for pam fixes the following issues:
- Moved pam_userdb into a separate package pam-extra. (bsc#1166510)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:948-1
Released: Wed Apr 8 07:44:21 2020
Summary: Security update for gmp, gnutls, libnettle
Type: security
Severity: moderate
References: 1152692,1155327,1166881,1168345,CVE-2020-11501
This update for gmp, gnutls, libnettle fixes the following issues:
Security issue fixed:
- CVE-2020-11501: Fixed zero random value in DTLS client hello (bsc#1168345)
FIPS related bugfixes:
- FIPS: Install checksums for binary integrity verification which are
required when running in FIPS mode (bsc#1152692, jsc#SLE-9518)
- FIPS: Fixed a cfb8 decryption issue, no longer truncate output IV if
input is shorter than block size. (bsc#1166881)
- FIPS: Added Diffie Hellman public key verification test. (bsc#1155327)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:961-1
Released: Wed Apr 8 13:34:06 2020
Summary: Recommended update for e2fsprogs
Type: recommended
Severity: moderate
References: 1160979
This update for e2fsprogs fixes the following issues:
- e2fsck: clarify overflow link count error message (bsc#1160979)
- ext2fs: update allocation info earlier in ext2fs_mkdir() (bsc#1160979)
- ext2fs: implement dir entry creation in htree directories (bsc#1160979)
- tests: add test to excercise indexed directories with metadata_csum (bsc#1160979)
- tune2fs: update dir checksums when clearing dir_index feature (bsc#1160979)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:967-1
Released: Thu Apr 9 11:41:53 2020
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1168699,CVE-2020-1730
This update for libssh fixes the following issues:
- CVE-2020-1730: Fixed a possible denial of service when using AES-CTR (bsc#1168699).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:969-1
Released: Thu Apr 9 11:43:17 2020
Summary: Security update for permissions
Type: security
Severity: moderate
References: 1168364
This update for permissions fixes the following issues:
- Fixed spelling of icinga group (bsc#1168364)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:981-1
Released: Mon Apr 13 15:43:44 2020
Summary: Recommended update for rpm
Type: recommended
Severity: moderate
References: 1156300
This update for rpm fixes the following issues:
- Fix for language package macros to avoid wrong requirement on shared library. (bsc#1156300)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1026-1
Released: Fri Apr 17 16:14:43 2020
Summary: Recommended update for libsolv
Type: recommended
Severity: moderate
References: 1159314
This update for libsolv fixes the following issues:
libsolv was updated to version 0.7.11:
- fix solv_zchunk decoding error if large chunks are used (bsc#1159314)
- treat retracted pathes as irrelevant
- made add_update_target work with multiversion installs
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1047-1
Released: Tue Apr 21 10:33:06 2020
Summary: Recommended update for gnutls
Type: recommended
Severity: moderate
References: 1168835
This update for gnutls fixes the following issues:
- Backport AES XTS support (bsc#1168835)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1063-1
Released: Wed Apr 22 10:46:50 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1165539,1169569
This update for libgcrypt fixes the following issues:
This update for libgcrypt fixes the following issues:
- FIPS: Switch the PCT to use the new signature operation (bsc#1165539)
- FIPS: Verify that the generated signature and the original input differ in test_keys function for RSA, DSA and ECC (bsc#1165539)
- Add zero-padding when qx and qy have different lengths when assembling the Q point from affine coordinates.
- Ship the FIPS checksum file in the shared library package and create a separate trigger file for the FIPS selftests (bsc#1169569)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1108-1
Released: Fri Apr 24 16:31:01 2020
Summary: Recommended update for gnutls
Type: recommended
Severity: moderate
References: 1169992
This update for gnutls fixes the following issues:
- FIPS: Do not check for /etc/system-fips which we don't have (bsc#1169992)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1175-1
Released: Tue May 5 08:33:43 2020
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1165011,1168076
This update for systemd fixes the following issues:
- Fix check for address to keep interface names stable. (bsc#1168076)
- Fix for checking non-normalized WHAT for network FS. (bsc#1165011)
- Allow to specify an arbitrary string for when vfs is used. (bsc#1165011)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1214-1
Released: Thu May 7 11:20:34 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1169944
This update for libgcrypt fixes the following issues:
- FIPS: libgcrypt: Fixed a double free in test_keys() on failed signature verification (bsc#1169944)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1219-1
Released: Thu May 7 17:10:42 2020
Summary: Security update for openldap2
Type: security
Severity: important
References: 1170771,CVE-2020-12243
This update for openldap2 fixes the following issues:
- CVE-2020-12243: Fixed a denial of service related to recursive filters (bsc#1170771).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1226-1
Released: Fri May 8 10:51:05 2020
Summary: Recommended update for gcc9
Type: recommended
Severity: moderate
References: 1149995,1152590,1167898
This update for gcc9 fixes the following issues:
This update ships the GCC 9.3 release.
- Includes a fix for Internal compiler error when building HepMC (bsc#1167898)
- Includes fix for binutils version parsing
- Add libstdc++6-pp provides and conflicts to avoid file conflicts
with same minor version of libstdc++6-pp from gcc10.
- Add gcc9 autodetect -g at lto link (bsc#1149995)
- Install go tool buildid for bootstrapping go
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1271-1
Released: Wed May 13 13:17:59 2020
Summary: Recommended update for permissions
Type: recommended
Severity: important
References: 1171173
This update for permissions fixes the following issues:
- Remove setuid bit for newgidmap and newuidmap in paranoid profile. (bsc#1171173)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1290-1
Released: Fri May 15 16:39:59 2020
Summary: Recommended update for gnutls
Type: recommended
Severity: moderate
References: 1171422
This update for gnutls fixes the following issues:
- Add RSA 4096 key generation support in FIPS mode (bsc#1171422)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1294-1
Released: Mon May 18 07:38:36 2020
Summary: Security update for file
Type: security
Severity: moderate
References: 1154661,1169512,CVE-2019-18218
This update for file fixes the following issues:
Security issues fixed:
- CVE-2019-18218: Fixed a heap-based buffer overflow in cdf_read_property_info() (bsc#1154661).
Non-security issue fixed:
- Fixed broken '--help' output (bsc#1169512).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1299-1
Released: Mon May 18 07:43:21 2020
Summary: Security update for libxml2
Type: security
Severity: moderate
References: 1159928,1161517,1161521,CVE-2019-19956,CVE-2019-20388,CVE-2020-7595
This update for libxml2 fixes the following issues:
- CVE-2019-20388: Fixed a memory leak in xmlSchemaPreRun (bsc#1161521).
- CVE-2019-19956: Fixed a memory leak (bsc#1159928).
- CVE-2020-7595: Fixed an infinite loop in an EOF situation (bsc#1161517).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1328-1
Released: Mon May 18 17:16:04 2020
Summary: Recommended update for grep
Type: recommended
Severity: moderate
References: 1155271
This update for grep fixes the following issues:
- Update testsuite expectations, no functional changes (bsc#1155271)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1361-1
Released: Thu May 21 09:31:18 2020
Summary: Recommended update for libgcrypt
Type: recommended
Severity: moderate
References: 1171872
This update for libgcrypt fixes the following issues:
- FIPS: RSA/DSA/ECC test_keys() print out debug messages only in debug mode (bsc#1171872)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1400-1
Released: Mon May 25 14:09:02 2020
Summary: Recommended update for glibc
Type: recommended
Severity: moderate
References: 1162930
This update for glibc fixes the following issues:
- nptl: wait for pending setxid request also in detached thread. (bsc#1162930)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1404-1
Released: Mon May 25 15:32:34 2020
Summary: Recommended update for zlib
Type: recommended
Severity: moderate
References: 1138793,1166260
This update for zlib fixes the following issues:
- Including the latest fixes from IBM (bsc#1166260)
IBM Z mainframes starting from version z15 provide DFLTCC instruction, which implements
deflate algorithm in hardware with estimated compression and decompression performance
orders of magnitude faster than the current zlib and ratio comparable with that of level 1.
- Add SUSE specific fix to solve bsc#1138793.
The fix will avoid to test if the app was linked with exactly same version of zlib
like the one that is present on the runtime.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1506-1
Released: Fri May 29 17:22:11 2020
Summary: Recommended update for aaa_base
Type: recommended
Severity: moderate
References: 1087982,1170527
This update for aaa_base fixes the following issues:
- Not all XTerm based emulators do have a terminfo entry. (bsc#1087982)
- Better support of Midnight Commander. (bsc#1170527)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1532-1
Released: Thu Jun 4 10:16:12 2020
Summary: Security update for libxml2
Type: security
Severity: moderate
References: 1172021,CVE-2019-19956
This update for libxml2 fixes the following issues:
- CVE-2019-19956: Reverted the upstream fix for this memory leak because it introduced other, more severe vulnerabilities (bsc#1172021).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1579-1
Released: Tue Jun 9 17:05:23 2020
Summary: Recommended update for audit
Type: recommended
Severity: important
References: 1156159,1172295
This update for audit fixes the following issues:
- Fix hang on startup. (bsc#1156159)
- Fix specfile to require libauparse0 and libaudit1 after splitting audit-libs. (bsc#1172295)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1584-1
Released: Tue Jun 9 18:39:15 2020
Summary: Security update for gnutls
Type: security
Severity: important
References: 1172461,1172506,CVE-2020-13777
This update for gnutls fixes the following issues:
- CVE-2020-13777: Fixed an insecure session ticket key construction which could
have made the TLS server to not bind the session ticket encryption key with a
value supplied by the application until the initial key rotation, allowing
an attacker to bypass authentication in TLS 1.3 and recover previous
conversations in TLS 1.2 (bsc#1172506).
- Fixed an improper handling of certificate chain with cross-signed intermediate
CA certificates (bsc#1172461).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1611-1
Released: Fri Jun 12 09:38:03 2020
Summary: Recommended update for libsolv, libzypp, zypper
Type: recommended
Severity: moderate
References: 1130873,1154803,1164543,1165476,1165573,1166610,1167122,1168990
This update for libsolv, libzypp, zypper fixes the following issues:
libsolv was updated to 0.7.13 to fix:
- Fix solvable swapping messing up idarrays
- fix ruleinfo of complex dependencies returning the wrong origin
libzypp was updated to 17.23.4 to fix:
- Get retracted patch status from updateinfo data (jsc#SLE-8770)
libsolv injects the indicator provides into packages only.
- remove 'using namespace std;' (bsc#1166610, fixes #218)
- Online doc: add 'Hardware (modalias) dependencies' page
(fixes #216)
- Add HistoryLogReader actionFilter to parse only specific
HistoryActionIDs.
- RepoVariables: Add safe guard in case the caller does not own a
zypp instance.
- Enable c++17. Define libyzpp CXX_STANDARD in ZyppCommon.cmake.
- Fix package status computation regarding unneeded, orphaned, recommended
and suggested packages (broken in 17.23.0) (bsc#1165476)
- Log patch status changes to history (jsc#SLE-5116)
- Allow to disable all WebServer dependent tests when building. OBS
wants to be able to get rid of the nginx/FastCGI-devel build
requirement. Use 'rpmbuild --without mediabackend_tests' or
'cmake -DDISABLE_MEDIABACKEND_TESTS=1'.
- update translations
- boost: Fix deprecated auto_unit_test.hpp includes.
- Disable zchunk on Leap-15.0 and SLE15-* while there is no libzck.
- Fix decision whether to download ZCHUNK files.
libzypp and libsolv must both be able to read the format.
- yum::Downloader: Prefer zchunk compressed metadata if libvsolv
supports it.
- Selectable: Fix highestAvailableVersionObj if only retracted
packages are available. Avoid using retracted items as candidate
(jsc#SLE-8770)
- RpmDb: Become rpmdb backend independent (jsc#SLE-7272)
- RpmDb: Close API offering a custom rpmdb path
It's actually not needed and for this to work also libsolv needs
to support it. You can sill use a librpmDb::db_const_iterator to
access a database at a custom location (ro).
- Remove legacy rpmV3database conversion code.
- Reformat manpages to workaround asciidoctor shortcomings
(bsc#1154803, bsc#1167122, bsc#1168990)
- Remove undocumented rug legacy stuff.
- Remove 'using namespace std;' (bsc#1166610)
- patch table: Add 'Since' column if history data are available
(jsc#SLE-5116)
zypper was updated to version 1.14.36:
- Tag 'retracted' patch status in info and list-patches (jsc#SLE-8770)
- Tag 'R'etracted items in search tabes status columns (jsc#SLE-8770)
- Relax 'Do not allow the abbreviation of cli arguments' in
legacy distibutions (bsc#1164543)
- Correctly detect ambigous switch abbreviations (bsc#1165573)
- zypper-aptitude: don't supplement zypper.
supplementing zypper means zypper-aptitude gets installed by
default and pulls in perl. Neither is desired on small systems.
- Do not allow the abbreviation of cli arguments (bsc#1164543)
- accoring to according in all translation files.
- Always show exception history if available.
- Use default package cache location for temporary repos (bsc#1130873)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1637-1
Released: Wed Jun 17 15:07:58 2020
Summary: Recommended update for zypper
Type: recommended
Severity: important
References: 1169947,1172925
This update for zypper fixes the following issues:
- Print switch abbrev warning to stderr (bsc#1172925)
- Fix typo in man page (bsc#1169947)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1682-1
Released: Fri Jun 19 09:44:54 2020
Summary: Security update for perl
Type: security
Severity: important
References: 1171863,1171864,1171866,1172348,CVE-2020-10543,CVE-2020-10878,CVE-2020-12723
This update for perl fixes the following issues:
- CVE-2020-10543: Fixed a heap buffer overflow in regular expression compiler which could have
allowed overwriting of allocated memory with attacker's data (bsc#1171863).
- CVE-2020-10878: Fixed multiple integer overflows which could have allowed the insertion of
instructions into the compiled form of Perl regular expression (bsc#1171864).
- CVE-2020-12723: Fixed an attacker's corruption of the intermediate language state of a
compiled regular expression (bsc#1171866).
- Fixed a bad warning in features.ph (bsc#1172348).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1759-1
Released: Thu Jun 25 18:44:37 2020
Summary: Recommended update for krb5
Type: recommended
Severity: moderate
References: 1169357
This update for krb5 fixes the following issue:
- Call systemd to reload the services instead of init-scripts. (bsc#1169357)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1760-1
Released: Thu Jun 25 18:46:13 2020
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1157315,1162698,1164538,1169488,1171145,1172072
This update for systemd fixes the following issues:
- Merge branch 'SUSE/v234' into SLE15
units: starting suspend.target should not fail when suspend is successful (bsc#1172072)
core/mount: do not add Before=local-fs.target or remote-fs.target if nofail mount option is set
mount: let mount_add_extras() take care of remote-fs.target deps (bsc#1169488)
mount: set up local-fs.target/remote-fs.target deps in mount_add_default_dependencies() too
udev: rename the persistent link for ATA devices (bsc#1164538)
shared/install: try harder to find enablement symlinks when disabling a unit (bsc#1157315)
tmpfiles: remove unnecessary assert (bsc#1171145)
test-engine: manager_free() was called too early
pid1: by default make user units inherit their umask from the user manager (bsc#1162698)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1773-1
Released: Fri Jun 26 08:05:59 2020
Summary: Security update for curl
Type: security
Severity: important
References: 1173027,CVE-2020-8177
This update for curl fixes the following issues:
- CVE-2020-8177: Fixed an issue where curl could have been tricked by a malicious
server to overwrite a local file when using the -J option (bsc#1173027).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1396-1
Released: Fri Jul 3 12:33:05 2020
Summary: Security update for zstd
Type: security
Severity: moderate
References: 1082318,1133297
This update for zstd fixes the following issues:
- Fix for build error caused by wrong static libraries. (bsc#1133297)
- Correction in spec file marking the license as documentation. (bsc#1082318)
- Add new package for SLE-15. (jsc#ECO-1886)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1856-1
Released: Mon Jul 6 17:05:51 2020
Summary: Security update for openldap2
Type: security
Severity: important
References: 1172698,1172704,CVE-2020-8023
This update for openldap2 fixes the following issues:
- CVE-2020-8023: Fixed a potential local privilege escalation from ldap to root when OPENLDAP_CONFIG_BACKEND='ldap' was used (bsc#1172698).
- Changed DB_CONFIG to root:ldap permissions (bsc#1172704).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2020:1860-1
Released: Mon Jul 6 17:09:44 2020
Summary: Security update for permissions
Type: security
Severity: moderate
References: 1171883
This update for permissions fixes the following issues:
- Removed conflicting entries which might expose pcp to security issues (bsc#1171883)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1869-1
Released: Tue Jul 7 15:08:12 2020
Summary: Recommended update for libsolv, libzypp, zypper
Type: recommended
Severity: moderate
References: 1130873,1154803,1164543,1165476,1165573,1166610,1167122,1168990,1169947,1170801,1171224,1172135,1172925
This update for libsolv, libzypp, zypper fixes the following issues:
libsolv was updated to 0.7.14:
- Enable zstd compression support
- Support blacklisted packages in solver_findproblemrule()
(bnc#1172135)
- Support rules with multiple negative literals in choice rule
generation
- Fix solvable swapping messing up idarrays
- fix ruleinfo of complex dependencies returning the wrong origin
libzypp was updated to 17.23.7:
- Enable zchunk metadata download if libsolv supports it.
- Older kernel-devel packages are not properly purged (bsc#1171224)
- doc: enhance service plugin example.
- Get retracted patch status from updateinfo data (jsc#SLE-8770)
libsolv injects the indicator provides into packages only.
- remove 'using namespace std;' (bsc#1166610, fixes #218)
- Online doc: add 'Hardware (modalias) dependencies' page
(fixes #216)
- Add HistoryLogReader actionFilter to parse only specific
HistoryActionIDs.
- RepoVariables: Add safe guard in case the caller does not own a
zypp instance.
- Enable c++17. Define libyzpp CXX_STANDARD in ZyppCommon.cmake.
- Fix package status computation regarding unneeded, orphaned, recommended
and suggested packages (broken in 17.23.0) (bsc#1165476)
- Log patch status changes to history (jsc#SLE-5116)
- Allow to disable all WebServer dependent tests when building. OBS
wants to be able to get rid of the nginx/FastCGI-devel build
requirement. Use 'rpmbuild --without mediabackend_tests' or
'cmake -DDISABLE_MEDIABACKEND_TESTS=1'.
- boost: Fix deprecated auto_unit_test.hpp includes.
- Disable zchunk on Leap-15.0 and SLE15-* while there is no libzck.
- Fix decision whether to download ZCHUNK files.
libzypp and libsolv must both be able to read the format.
- yum::Downloader: Prefer zchunk compressed metadata if libvsolv
supports it.
- Selectable: Fix highestAvailableVersionObj if only retracted
packages are available. Avoid using retracted items as candidate
(jsc#SLE-8770)
- RpmDb: Become rpmdb backend independent (jsc#SLE-7272)
- RpmDb: Close API offering a custom rpmdb path
It's actually not needed and for this to work also libsolv needs
to support it. You can sill use a librpmDb::db_const_iterator to
access a database at a custom location (ro).
- Remove legacy rpmV3database conversion code.
- Fix core dump with corrupted history file (bsc#1170801)
zypper was updated to 1.14.37:
- Reformat manpages to workaround asciidoctor shortcomings
(bsc#1154803, bsc#1167122, bsc#1168990)
- Remove undocumented rug legacy stuff.
- Remove 'using namespace std;' (bsc#1166610)
- patch table: Add 'Since' column if history data are available
(jsc#SLE-5116)
- Tag 'retracted' patch status in info and list-patches (jsc#SLE-8770)
- Tag 'R'etracted items in search tabes status columns (jsc#SLE-8770)
- Relax 'Do not allow the abbreviation of cli arguments' in
legacy distibutions (bsc#1164543)
- Correctly detect ambigous switch abbreviations (bsc#1165573)
- zypper-aptitude: don't supplement zypper.
supplementing zypper means zypper-aptitude gets installed by
default and pulls in perl. Neither is desired on small systems.
- Do not allow the abbreviation of cli arguments (bsc#1164543)
- accoring to according in all translation files.
- Always show exception history if available.
- Use default package cache location for temporary repos (bsc#1130873)
- Print switch abbrev warning to stderr (bsc#1172925)
- Fix typo in man page (bsc#1169947)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:2040-1
Released: Fri Jul 24 13:58:53 2020
Summary: Recommended update for libsolv, libzypp
Type: recommended
Severity: moderate
References: 1170801,1171224,1172135,1173106,1174011
This update for libsolv, libzypp fixes the following issues:
libsolv was updated to version 0.7.14:
- Enable zstd compression support for sle15
- Support blacklisted packages in solver_findproblemrule() (bsc#1172135)
- Support rules with multiple negative literals in choice rule
generation
libzypp was updated to version 17.24.0:
- Enable zchunk metadata download if libsolv supports it.
- Older kernel-devel packages are not properly purged (bsc#1171224)
- doc: enhance service plugin example.
- Fix core dump with corrupted history file (bsc#1170801)
- Better handling of the purge-kernels algorithm. (bsc#1173106)
- Proactively send credentials if the URL specifes '?auth=basic' and a username.
(bsc#1174011)
- ZYPP_MEDIA_CURL_DEBUG: Strip credentials in header log. (bsc#1174011)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:2083-1
Released: Thu Jul 30 10:27:59 2020
Summary: Recommended update for diffutils
Type: recommended
Severity: moderate
References: 1156913
This update for diffutils fixes the following issue:
- Disable a sporadically failing test for ppc64 and ppc64le builds. (bsc#1156913)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:2099-1
Released: Fri Jul 31 08:06:40 2020
Summary: Recommended update for systemd
Type: recommended
Severity: moderate
References: 1173227,1173229,1173422
This update for systemd fixes the following issues:
- migrate-sysconfig-i18n.sh: fixed marker handling (bsc#1173229)
The marker is used to make sure the script is run only once. Instead
of storing it in /usr, use /var which is more appropriate for such
file.
Also make it owned by systemd package.
- Fix inconsistent file modes for some ghost files (bsc#1173227)
Ghost files are assumed by rpm to have mode 000 by default which is
not consistent with file permissions set at runtime.
Also /var/lib/systemd/random-seed was tracked wrongly as a
directory.
Also don't track (ghost) /etc/systemd/system/runlevel*.target
aliases since we're not supposed to track units or aliases user
might define/override.
- Fix build of systemd on openSUSE Leap 15.2 (bsc#1173422)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:2204-1
Released: Tue Aug 11 14:33:37 2020
Summary: Bugfixes on cilium, gangway and skuba and security fix for Kubernetes (cve-2020-8557)
Type: recommended
Severity: moderate
References: 1146991,1173039,1173055,1173165,1173984,CVE-2020-8557
= Required Actions
== Kubernetes (Security fix)
This fix will be applied to the kubelet daemon running on the nodes by `skuba-update`.
See https://documentation.suse.com/suse-caasp/4.2/html/caasp-admin/_cluster_updates.html#_base_os_updates for more details.
Make sure you look at the Release Notes https://www.suse.com/releasenotes/x86_64/SUSE-CAASP/4/#_changes_in_4_2_2 for any known bug.
== Cilium Bugfix
Cilium will be updated by `skuba addon upgrade`. No action is required from your side.
For more info see https://documentation.suse.com/suse-caasp/4.2/html/caasp-admin/_cluster_updates.html#_generating_an_overview_of_available_addon_updates
== Gangway bugfix
Gangway will be updated by `skuba addon upgrade`. No action is required from your side.
For more info see https://documentation.suse.com/suse-caasp/4.2/html/caasp-admin/_cluster_updates.html#_generating_an_overview_of_available_addon_updates
== Skuba
In order to update skuba, you need to update the admin workstation.
See detailed instructions at https://documentation.suse.com/suse-caasp/4.1/html/caasp-admin/_cluster_updates.html#_update_management_workstation
More information about the sle-updates
mailing list