This update for rpm fixes the following issues:
- Changed default package verification level to 'none' to be compatible to
rpm-4.14.1
- Made illegal obsoletes a warning
- Fixed a potential access of freed mem in ndb's glue code (bsc#1179416)
- Added support for enforcing signature policy and payload verification
step to transactions (jsc#SLE-17817)
- Added :humansi and :hmaniec query formatters for human readable output
- Added query selectors for whatobsoletes and whatconflicts
- Added support for sorting caret higher than base version
- rpm does no longer require the signature header to be in a contiguous
region when signing (bsc#1181805)
Security fixes:
- CVE-2021-3421: A flaw was found in the RPM package in the read
functionality. This flaw allows an attacker who can convince a victim to
install a seemingly verifiable package or compromise an RPM repository,
to cause RPM database corruption. The highest threat from...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-2682=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
python-rpm-debugsource-4.14.3-37.2
python2-rpm-4.14.3-37.2
python2-rpm-debuginfo-4.14.3-37.2
python3-rpm-4.14.3-37.2
python3-rpm-debuginfo-4.14.3-37.2
rpm-4.14.3-37.2
rpm-build-4.14.3-37.2
rpm-build-debuginfo-4.14.3-37.2
rpm-debuginfo-4.14.3-37.2
rpm-debugsource-4.14.3-37.2
rpm-devel-4.14.3-37.2
rpm-ndb-4.14.3-37.2
rpm-ndb-debuginfo-4.14.3-37.2
rpm-ndb-debugsource-4.14.3-37.2
- openSUSE Leap 15.3 (x86_64):
rpm-32bit-4.14.3-37.2
rpm-32bit-debuginfo-4.14.3-37.2
rpm-ndb-32bit-4.14.3-37.2
rpm-ndb-32bit-debuginfo-4.14.3-37.2
https://www.suse.com/security/cve/CVE-2021-20266.html
https://www.suse.com/security/cve/CVE-2021-20271.html
https://www.suse.com/security/cve/CVE-2021-3421.html
https://bugzilla.suse.com/1179416
https://bugzilla.suse.com/1181805
https://bugzilla.suse.com/1183543
https://bugzilla.suse.com/1183545
Get the latest Linux and open source security news straight to your inbox.