Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2019:3061-1 Moderate: gcc9 Heap Overflow And Miscompilation Fixes

suse
Calendar Grey November 25, 2019
Dist Suse Esm H88
SUSE has released a security patch for gcc9 that mitigates moderate concerns stemming from two identified vulnerabilities associated with the gcc compiler.
An update that solves two vulnerabilities and has 5 fixes is now available

Summary

This update includes the GNU Compiler Collection 9. A full changelog is provided by the GCC team on: The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages. To use it, install "gcc9" or "gcc9-c++" or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it. Security issues fixed: - CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145) - CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649) Non-security issues fixed: - Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254) - Fixed miscompilation for vector shift on s390. (bsc#1141897) Patch Instructions:

References

#1114592 #1135254 #1141897 #1142649 #1142654

#1148517 #1149145

Cross- CVE-2019-14250 CVE-2019-15847

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Development Tools 15-SP1

SUSE Linux Enterprise Module for Development Tools 15

SUSE Linux Enterprise Module for Basesystem 15-SP1

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2019-14250.html

https://www.suse.com/security/cve/CVE-2019-15847.html

https://bugzilla.suse.com/1114592

https://bugzilla.suse.com/1135254

https://bugzilla.suse.com/1141897

https://bugzilla.suse.com/1142649

https://bugzilla.suse.com/1142654

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3061-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here