For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
LLVM Toolset provides the LLVM compiler infrastructure framework, the Clang
compiler for the C and C++ languages, the LLDB debugger, and related tools
for code analysis.
Security Fix(es):
* Developer environment: Unicode's bidirectional (BiDi) override characterscan cause trojan source attacks (CVE-2021-42574)
The following changes were introduced in clang in order to facilitate
detection of BiDi Unicode characters:
clang-tidy now finds identifiers that contain Unicode characters with
right-to-left direction, which can be confusing as they may change the
understanding of a whole statement.
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2021-42574 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-007
Red Hat Enterprise Linux AppStream (v. 8):
Source:
clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.src.rpm
compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
libomp-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
lld-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
lldb-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
llvm-12.0.1-2.module+el8.5.0+12488+254d2a07.src.rpm
llvm-toolset-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
python-lit-12.0.1-1.module+el8.5.0+11871+08d0eab5.src.rpm
aarch64:
clang-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-debugsource-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-devel-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-libs-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-libs-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-resource-filesystem-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-tools-extra-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
clang-tools-extra-debuginfo-12.0.1-4.module+el8.5.0+13246+cefb5d4c.aarch64.rpm
compiler-rt-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm
compiler-rt-debuginfo-12.0.1-1.module+el8.5.0+11871+08d0eab5.aarch64.rpm
Read the Full Advisory
An update for the llvm-toolset:rhel8 module is now available for Red HatEnterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
2005819 - CVE-2021-42574 Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks
Get the latest Linux and open source security news straight to your inbox.