Alerts This Week
Warning Icon 1 1,139
Alerts This Week
Warning Icon 1 1,139

openSUSE: 2024:4173-1 important: postgresql, postgresql16, postgresql17 Advisory Security Update

opensuse
Calendar Grey December 4, 2024
Dist Opensuse Esm H88
Update addresses four issues with postgresql. Upgrade recommended for enhanced security and performance improvements.
An update that solves four vulnerabilities, contains one feature and has two security fixes can now be installed.

Description

This update for postgresql, postgresql16, postgresql17 fixes the following

issues:

This update ships postgresql17 , and fixes security issues with postgresql16:

* bsc#1230423: Relax the dependency of extensions on the server version from

exact major.minor to greater or equal, after Tom Lane confirmed on the

PostgreSQL packagers list that ABI stability is being taken care of between

minor releases.

* bsc#1219340: The last fix was not correct. Improve it by removing the

dependency again and call fillup only if it is installed.

postgresql16 was updated to 16.6: * Repair ABI break for extensions that work

with struct ResultRelInfo. * Restore functionality of ALTER {ROLE|DATABASE} SET

role. * Fix cases where a logical replication slot's restart_lsn could go

backwards. * Avoid deleting still-needed WAL files during pg_rewind. * Fix race

conditions associated with dropping shared statistics entries. * Count index

scans in contrib/bloom indexes in the statistics...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.3

zypper in -t patch SUSE-2024-4173=1

* openSUSE Leap 15.4

zypper in -t patch SUSE-2024-4173=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2024-4173=1 SUSE-2024-4173=1

* Basesystem Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-4173=1

* Legacy Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-4173=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-4173=1

* Server Applications Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-4173=1

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS

zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-4173=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

zypper in -t patch...

Read the Full Advisory

Package List

* openSUSE Leap 15.3 (noarch)

* postgresql-17-150300.10.27.1

* postgresql-llvmjit-17-150300.10.27.1

* postgresql-contrib-17-150300.10.27.1

* postgresql-server-17-150300.10.27.1

* postgresql-llvmjit-devel-17-150300.10.27.1

* postgresql-test-17-150300.10.27.1

* postgresql-server-devel-17-150300.10.27.1

* postgresql-pltcl-17-150300.10.27.1

* postgresql-devel-17-150300.10.27.1

* postgresql-plperl-17-150300.10.27.1

* postgresql-plpython-17-150300.10.27.1

* postgresql-docs-17-150300.10.27.1

* openSUSE Leap 15.4 (noarch)

* postgresql-plperl-17-150400.4.18.1

* postgresql-plpython-17-150400.4.18.1

* postgresql-llvmjit-devel-17-150400.4.18.1

* postgresql-contrib-17-150400.4.18.1

* postgresql-llvmjit-17-150400.4.18.1

* postgresql-server-17-150400.4.18.1

* postgresql-server-devel-17-150400.4.18.1

* postgresql-test-17-150400.4.18.1

* postgresql-docs-17-150400.4.18.1

* postgresql-devel-17-150400.4.18.1

* postgresql-pltcl-17-150400.4.18.1

* postgresql-17-150400.4.18.1

* openSUSE Leap 15.5 (noarch)

*...

Read the Full Advisory

References

* bsc#1219340

* bsc#1230423

* bsc#1233323

* bsc#1233325

* bsc#1233326

* bsc#1233327

* jsc#PED-11514

## References:

* https://www.suse.com/security/cve/CVE-2024-10976.html

* https://www.suse.com/security/cve/CVE-2024-10977.html

* https://www.suse.com/security/cve/CVE-2024-10978.html

* https://www.suse.com/security/cve/CVE-2024-10979.html

* https://bugzilla.suse.com/show_bug.cgi?id=1219340

* https://bugzilla.suse.com/show_bug.cgi?id=1230423

* https://bugzilla.suse.com/show_bug.cgi?id=1233323

* https://bugzilla.suse.com/show_bug.cgi?id=1233325

* https://bugzilla.suse.com/show_bug.cgi?id=1233326

* https://bugzilla.suse.com/show_bug.cgi?id=1233327

* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11514&page_caps=&user_role=

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:4173-1
Release Date: 2024-12-04T14:49:16Z
Affected Products: * Basesystem Module 15-SP5 * Legacy Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP5

Topics%20covered

Topics Covered

No topics assigned

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here