Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

openSUSE: 2020:0945-1 Moderate: Rust-Cbindgen Security Advisory

opensuse
Calendar Grey July 7, 2020
Dist Opensuse Esm H88
The latest openSUSE update tackles rust-related problems, incorporating vital security upgrades and critical bug resolutions.
An update that solves one vulnerability and has two fixes is now available.

Description

This update for rust, rust-cbindgen fixes the following issues:

rust was updated for use by Firefox 76ESR.

- Fixed miscompilations with rustc 1.43 that lead to LTO failures

(bsc#1173202)

Update to version 1.43.1

- Updated openssl-src to 1.1.1g for CVE-2020-1967.

- Fixed the stabilization of AVX-512 features.

- Fixed `cargo package --list` not working with unpublished dependencies.

Update to version 1.43.0

+ Language:

- Fixed using binary operations with `&{number}` (e.g. `&1.0`) not having

the type inferred correctly.

- Attributes such as `#[cfg()]` can now be used on `if` expressions.

- Syntax only changes:

* Allow `type Foo: Ord` syntactically.

* Fuse associated and extern items up to defaultness.

* Syntactically allow `self` in all `fn` contexts.

* Merge `fn` syntax + cleanup item parsing.

* `item` macro fragments can be interpolated into `trait`s, `impl`s, and

`extern` blocks. For example, you...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-945=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

cargo-1.43.1-lp152.3.5.1

clippy-1.43.1-lp152.3.5.1

rls-1.43.1-lp152.3.5.1

rust-1.43.1-lp152.3.5.1

rust-analysis-1.43.1-lp152.3.5.1

rust-doc-1.43.1-lp152.3.5.1

rust-gdb-1.43.1-lp152.3.5.1

rust-std-static-1.43.1-lp152.3.5.1

rustfmt-1.43.1-lp152.3.5.1

- openSUSE Leap 15.2 (noarch):

cargo-doc-1.43.1-lp152.3.5.1

rust-src-1.43.1-lp152.3.5.1

- openSUSE Leap 15.2 (x86_64):

rust-cbindgen-0.14.1-lp152.2.4.1

References

https://www.suse.com/security/cve/CVE-2020-1967.html

https://bugzilla.suse.com/1115645

https://bugzilla.suse.com/1154817

https://bugzilla.suse.com/1173202

--

Announcement ID: openSUSE-SU-2020:0945-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here