Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

openSUSE: 2023:3825-1 Important: Critical Binutils Security Fix

opensuse
Calendar Grey September 27, 2023
Scroller Opensuse
An upgrade for binutils tackles essential security vulnerabilities, bolstering defense mechanisms on openSUSE platforms with multiple improvements.
This update for binutils fixes the following issues: Update to version 2.41 [jsc#PED-5778]:

Description

This update for binutils fixes the following issues:

Update to version 2.41 [jsc#PED-5778]:

* The MIPS port now supports the Sony Interactive Entertainment Allegrex

processor, used with the PlayStation Portable, which implements the MIPS II

ISA along with a single-precision FPU and a few implementation-specific

integer instructions.

* Objdump's --private option can now be used on PE format files to display the

fields in the file header and section headers.

* New versioned release of libsframe: libsframe.so.1. This release introduces

versioned symbols with version node name LIBSFRAME_1.0. This release also

updates the ABI in an incompatible way: this includes removal of

sframe_get_funcdesc_with_addr API, change in the behavior of

sframe_fre_get_ra_offset and sframe_fre_get_fp_offset APIs.

* SFrame Version 2 is now the default (and only) format version supported by

gas, ld, readelf and objdump.

* Add command-line option, --strip-section-headers, to objcopy and strip to

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3825=1

* Basesystem Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3825=1

* Basesystem Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3825=1

* Development Tools Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3825=1

* Development Tools Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-3825=1

* SUSE Package Hub 15 15-SP4

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3825=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3825=1

* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1

zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-3825=1

*...

Read the Full Advisory

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* cross-hppa64-binutils-debugsource-2.41-150100.7.46.1

* cross-sparc-binutils-debuginfo-2.41-150100.7.46.1

* cross-hppa64-binutils-debuginfo-2.41-150100.7.46.1

* cross-hppa-binutils-debugsource-2.41-150100.7.46.1

* cross-sparc-binutils-2.41-150100.7.46.1

* binutils-gold-2.41-150100.7.46.1

* cross-ia64-binutils-2.41-150100.7.46.1

* cross-spu-binutils-debuginfo-2.41-150100.7.46.1

* cross-avr-binutils-2.41-150100.7.46.1

* cross-sparc64-binutils-2.41-150100.7.46.1

* libctf-nobfd0-debuginfo-2.41-150100.7.46.1

* cross-sparc64-binutils-debuginfo-2.41-150100.7.46.1

* cross-s390-binutils-debugsource-2.41-150100.7.46.1

* cross-xtensa-binutils-2.41-150100.7.46.1

* cross-ppc-binutils-2.41-150100.7.46.1

* cross-ppc-binutils-debugsource-2.41-150100.7.46.1

* cross-epiphany-binutils-2.41-150100.7.46.1

* cross-i386-binutils-debuginfo-2.41-150100.7.46.1

* cross-riscv64-binutils-2.41-150100.7.46.1

* cross-ppc64-binutils-debugsource-2.41-150100.7.46.1

*...

Read the Full Advisory

References

* #1200962

* #1206080

* #1206556

* #1208037

* #1208038

* #1208040

* #1208409

* #1209642

* #1210297

* #1210733

* #1213458

* #1214565

* #1214567

* #1214579

* #1214580

* #1214604

* #1214611

* #1214619

* #1214620

* #1214623

* #1214624

* #1214625

* PED-5778

## References:

* https://www.suse.com/security/cve/CVE-2020-19726.html

* https://www.suse.com/security/cve/CVE-2021-32256.html

* https://www.suse.com/security/cve/CVE-2022-35205.html

* https://www.suse.com/security/cve/CVE-2022-35206.html

* https://www.suse.com/security/cve/CVE-2022-4285.html

* https://www.suse.com/security/cve/CVE-2022-44840.html

* https://www.suse.com/security/cve/CVE-2022-45703.html

* https://www.suse.com/security/cve/CVE-2022-47673.html

* https://www.suse.com/security/cve/CVE-2022-47695.html

* https://www.suse.com/security/cve/CVE-2022-47696.html

* https://www.suse.com/security/cve/CVE-2022-48063.html

* https://www.suse.com/security/cve/CVE-2022-48064.html

* https://www.suse.com/security/cve/CVE-2022-48065.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:3825-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.