SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2021:85-1
Container Tags        : suse/sle15:15.0 , suse/sle15:15.0.4.22.366
Container Release     : 4.22.366
Severity              : important
Type                  : security
References            : 1050625 1050625 1078466 1146705 1172442 1174016 1174016 1175519
                        1176201 1177238 1177238 1177275 1177275 1177427 1177427 1177583
                        1177583 1178775 1178910 1178910 1178966 1178966 1179083 1179083
                        1179222 1179222 1179415 1179816 1179847 1179847 1179909 1179909
                        1180020 1180077 1180083 1180596 1180663 1180721 1181011 1181328
                        1181328 1181358 1181622 1181622 1181831 1182328 1182362 1182629
                        1182629 1183094 1183370 1183371 1183456 1183457 CVE-2017-9271
                        CVE-2017-9271 CVE-2020-11080 CVE-2021-20231 CVE-2021-20232 CVE-2021-24031
                        CVE-2021-24032 CVE-2021-27218 CVE-2021-27219 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:770-1
Released:    Thu Mar 11 20:24:05 2021
Summary:     Security update for libsolv, libzypp, yast2-installation, zypper
Type:        security
Severity:    moderate
References:  1050625,1174016,1177238,1177275,1177427,1177583,1178910,1178966,1179083,1179222,1179415,1179847,1179909,1181328,1181622,1182629,CVE-2017-9271
This update for libsolv, libzypp, yast2-installation, zypper fixes the following issues:

Update zypper to version 1.14.43:

- doc: give more details about creating versioned package locks
  (bsc#1181622)
- man: Document synonymously used patch categories (bsc#1179847)
- Fix source-download commnds help (bsc#1180663)
- man: Recommend to use the --non-interactive global option rather than the command option -y (bsc#1179816)
- Extend apt packagemap (fixes #366)
- --quiet: Fix install summary to write nothing if there's nothing todo (bsc#1180077)
- Prefer /run over /var/run.

Update libzypp to 17.25.8:

- Try to provide a mounted /proc in --root installs (bsc#1181328)
  Some systemd tools require /proc to be mounted and fail if it's
  not there.
- Enable release packages to request a releaxed suse/opensuse
  vendorcheck in dup when migrating. (bsc#1182629)
- Patch: Identify well-known category names (bsc#1179847)
  This allows to use the RH and SUSE patch categrory names
  synonymously:
  (recommended = bugfix) and (optional = feature = enhancement).
- Fix %posttrans script execution (fixes #265)
  The scripts are execuable. No need to call them through 'sh -c'.
- Commit: Fix rpmdb compat symlink in case rpm got removed.
- Repo: Allow multiple baseurls specified on one line (fixes #285)
- Regex: Fix memory leak and undefined behavior.
- Add rpm buildrequires for test suite (fixes #279)
- Use rpmdb2solv new -D switch to tell the location ob the
  rpmdatabase to use.
- BuildRequires:  libsolv-devel >= 0.7.17.
- CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583)
- RepoManager: Force refresh if repo url has changed (bsc#1174016)
- RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966)
- RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427).
- RpmDb: If no database exists use the _dbpath configured in rpm.  Still makes sure a compat
  symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910)
- Fixed update of gpg keys with elongated expire date (bsc#1179222)
- needreboot: remove udev from the list (bsc#1179083)
- Fix lsof monitoring (bsc#1179909)
- Rephrase solver problem descriptions (jsc#SLE-8482)
- Adapt to changed gpg2/libgpgme behavior (bsc#1180721)
- Multicurl backend breaks with with unknown filesize (fixes #277)

Update yast2-installation to 4.0.77:

- Do not cleanup the libzypp cache when the system has low memory,
  incomplete cache confuses libzypp later (bsc#1179415)

Update libsolv to 0.7.17:

- repo_write: fix handling of nested flexarray
- improve choicerule generation a bit more to cover more cases
- harden testcase parser against repos being added too late
- support python-3.10
- check %_dbpath macro in rpmdb code
- handle default/visible/langonly attributes in comps parser
- support multiple collections in updateinfo parser
- add '-D' option in rpmdb2solv to set the dbpath


-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:786-1
Released:    Mon Mar 15 11:19:23 2021
Summary:     Recommended update for zlib
Type:        recommended
Severity:    moderate
References:  1176201
This update for zlib fixes the following issues:

- Fixed hw compression on z15 (bsc#1176201)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:890-1
Released:    Fri Mar 19 15:51:41 2021
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1182328,1182362,CVE-2021-27218,CVE-2021-27219
This update for glib2 fixes the following issues:

- CVE-2021-27218: g_byte_array_new_take takes a gsize as length but stores in a guint, this patch will refuse if the length is larger than guint. (bsc#1182328)

- CVE-2021-27219: g_memdup takes a guint as parameter and sometimes leads into an integer overflow, so add a g_memdup2 function which uses gsize to replace it. (bsc#1182362)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:924-1
Released:    Tue Mar 23 10:00:49 2021
Summary:     Recommended update for filesystem
Type:        recommended
Severity:    moderate
References:  1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094
This update for filesystem the following issues:

- Remove duplicate line due to merge error
- Add fix for 'mesa' creating cache with perm 0700. (bsc#1181011) 
- Fixed an issue causing failure during installation/upgrade a failure. (rh#1548403) (bsc#1146705)
- Allows to override config to add cleanup options of '/var/tmp'. (bsc#1078466)
- Create config to cleanup '/tmp' regular required with 'tmpfs'. (bsc#1175519)

This update for systemd fixes the following issues:

- Fix for a possible memory leak. (bsc#1180020)
- Fix for a case when to a bind mounted directory results inactive mount units. (#7811) (bsc#1180596)
- Fixed an issue when starting a container conflicts with another one. (bsc#1178775)
- Drop most of the tmpfiles that deal with generic paths and avoid warnings. (bsc#1078466, bsc#1181831)
- Don't use shell redirections when calling a rpm macro. (bsc#1183094)
- 'systemd' requires 'aaa_base' >= 13.2. (bsc#1180083)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:931-1
Released:    Wed Mar 24 12:10:41 2021
Summary:     Security update for nghttp2
Type:        security
Severity:    important
References:  1172442,1181358,CVE-2020-11080
This update for nghttp2 fixes the following issues:

- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:934-1
Released:    Wed Mar 24 12:18:21 2021
Summary:     Security update for gnutls
Type:        security
Severity:    important
References:  1183456,1183457,CVE-2021-20231,CVE-2021-20232
This update for gnutls fixes the following issues:

- CVE-2021-20232: Fixed a use after free issue which could have led to memory corruption and other potential consequences (bsc#1183456).
- CVE-2021-20231: Fixed a use after free issue which could have led to memory corruption and other potential consequences (bsc#1183457).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:948-1
Released:    Wed Mar 24 14:31:34 2021
Summary:     Security update for zstd
Type:        security
Severity:    moderate
References:  1183370,1183371,CVE-2021-24031,CVE-2021-24032
This update for zstd fixes the following issues:

- CVE-2021-24031: Added read permissions to files while being compressed or uncompressed (bsc#1183371).
- CVE-2021-24032: Fixed a race condition which could have allowed an attacker to access world-readable destination file (bsc#1183370).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2021:956-1
Released:    Thu Mar 25 19:19:04 2021
Summary:     Security update for libzypp, zypper
Type:        security
Severity:    moderate
References:  1050625,1174016,1177238,1177275,1177427,1177583,1178910,1178966,1179083,1179222,1179816,1179847,1179909,1180077,1180663,1180721,1181328,1181622,1182629,CVE-2017-9271
This update for libzypp, zypper fixes the following issues:

Update zypper to version 1.14.43:

- doc: give more details about creating versioned package locks
  (bsc#1181622)
- man: Document synonymously used patch categories (bsc#1179847)
- Fix source-download commands help (bsc#1180663)
- man: Recommend to use the --non-interactive global option rather than the command option -y (bsc#1179816)
- Extend apt packagemap (fixes #366)
- --quiet: Fix install summary to write nothing if there's nothing todo (bsc#1180077)
- Prefer /run over /var/run.

Update libzypp to 17.25.8:

- Try to provide a mounted /proc in --root installs (bsc#1181328)
  Some systemd tools require /proc to be mounted and fail if it's
  not there.
- Enable release packages to request a releaxed suse/opensuse
  vendorcheck in dup when migrating. (bsc#1182629)
- Patch: Identify well-known category names (bsc#1179847)
  This allows to use the RH and SUSE patch categrory names
  synonymously:
  (recommended = bugfix) and (optional = feature = enhancement).
- Add missing includes for GCC 11 compatibility.
- Fix %posttrans script execution (fixes #265)
  The scripts are execuable. No need to call them through 'sh -c'.
- Commit: Fix rpmdb compat symlink in case rpm got removed.
- Repo: Allow multiple baseurls specified on one line (fixes #285)
- Regex: Fix memory leak and undefined behavior.
- Add rpm buildrequires for test suite (fixes #279)
- Use rpmdb2solv new -D switch to tell the location ob the
  rpmdatabase to use.
- CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583)
- RepoManager: Force refresh if repo url has changed (bsc#1174016)
- RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966)
- RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427).
- RpmDb: If no database exists use the _dbpath configured in rpm.  Still makes sure a compat
  symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910)
- Fixed update of gpg keys with elongated expire date (bsc#1179222)
- needreboot: remove udev from the list (bsc#1179083)
- Fix lsof monitoring (bsc#1179909)
- Rephrase solver problem descriptions (jsc#SLE-8482)
- Adapt to changed gpg2/libgpgme behavior (bsc#1180721)
- Multicurl backend breaks with with unknown filesize (fixes #277)

SUSE: 2021:85-1 suse/sle15 Security Update

March 30, 2021
The container suse/sle15 was updated

Summary

Advisory ID: SUSE-SU-2021:770-1 Released: Thu Mar 11 20:24:05 2021 Summary: Security update for libsolv, libzypp, yast2-installation, zypper Type: security Severity: moderate Advisory ID: SUSE-RU-2021:786-1 Released: Mon Mar 15 11:19:23 2021 Summary: Recommended update for zlib Type: recommended Severity: moderate Advisory ID: SUSE-SU-2021:890-1 Released: Fri Mar 19 15:51:41 2021 Summary: Security update for glib2 Type: security Severity: important Advisory ID: SUSE-RU-2021:924-1 Released: Tue Mar 23 10:00:49 2021 Summary: Recommended update for filesystem Type: recommended Severity: moderate Advisory ID: SUSE-SU-2021:931-1 Released: Wed Mar 24 12:10:41 2021 Summary: Security update for nghttp2 Type: security Severity: important Advisory ID: SUSE-SU-2021:934-1 Released: Wed Mar 24 12:18:21 2021 Summary: Security update for gnutls Type: security Severity: important Advisory ID: SUSE-SU-2021:948-1 Released: Wed Mar 24 14:31:34 2021 Summary: Security update for zstd Type: security Severity: moderate Advisory ID: SUSE-SU-2021:956-1 Released: Thu Mar 25 19:19:04 2021 Summary: Security update for libzypp, zypper Type: security Severity: moderate

References

References : 1050625 1050625 1078466 1146705 1172442 1174016 1174016 1175519

1176201 1177238 1177238 1177275 1177275 1177427 1177427 1177583

1177583 1178775 1178910 1178910 1178966 1178966 1179083 1179083

1179222 1179222 1179415 1179816 1179847 1179847 1179909 1179909

1180020 1180077 1180083 1180596 1180663 1180721 1181011 1181328

1181328 1181358 1181622 1181622 1181831 1182328 1182362 1182629

1182629 1183094 1183370 1183371 1183456 1183457 CVE-2017-9271

CVE-2017-9271 CVE-2020-11080 CVE-2021-20231 CVE-2021-20232 CVE-2021-24031

CVE-2021-24032 CVE-2021-27218 CVE-2021-27219

1050625,1174016,1177238,1177275,1177427,1177583,1178910,1178966,1179083,1179222,1179415,1179847,1179909,1181328,1181622,1182629,CVE-2017-9271

This update for libsolv, libzypp, yast2-installation, zypper fixes the following issues:

Update zypper to version 1.14.43:

- doc: give more details about creating versioned package locks

(bsc#1181622)

- man: Document synonymously used patch categories (bsc#1179847)

- Fix source-download commnds help (bsc#1180663)

- man: Recommend to use the --non-interactive global option rather than the command option -y (bsc#1179816)

- Extend apt packagemap (fixes #366)

- --quiet: Fix install summary to write nothing if there's nothing todo (bsc#1180077)

- Prefer /run over /var/run.

Update libzypp to 17.25.8:

- Try to provide a mounted /proc in --root installs (bsc#1181328)

Some systemd tools require /proc to be mounted and fail if it's

not there.

- Enable release packages to request a releaxed suse/opensuse

vendorcheck in dup when migrating. (bsc#1182629)

- Patch: Identify well-known category names (bsc#1179847)

This allows to use the RH and SUSE patch categrory names

synonymously:

(recommended = bugfix) and (optional = feature = enhancement).

- Fix %posttrans script execution (fixes #265)

The scripts are execuable. No need to call them through 'sh -c'.

- Commit: Fix rpmdb compat symlink in case rpm got removed.

- Repo: Allow multiple baseurls specified on one line (fixes #285)

- Regex: Fix memory leak and undefined behavior.

- Add rpm buildrequires for test suite (fixes #279)

- Use rpmdb2solv new -D switch to tell the location ob the

rpmdatabase to use.

- BuildRequires: libsolv-devel >= 0.7.17.

- CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583)

- RepoManager: Force refresh if repo url has changed (bsc#1174016)

- RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966)

- RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427).

- RpmDb: If no database exists use the _dbpath configured in rpm. Still makes sure a compat

symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910)

- Fixed update of gpg keys with elongated expire date (bsc#1179222)

- needreboot: remove udev from the list (bsc#1179083)

- Fix lsof monitoring (bsc#1179909)

- Rephrase solver problem descriptions (jsc#SLE-8482)

- Adapt to changed gpg2/libgpgme behavior (bsc#1180721)

- Multicurl backend breaks with with unknown filesize (fixes #277)

Update yast2-installation to 4.0.77:

- Do not cleanup the libzypp cache when the system has low memory,

incomplete cache confuses libzypp later (bsc#1179415)

Update libsolv to 0.7.17:

- repo_write: fix handling of nested flexarray

- improve choicerule generation a bit more to cover more cases

- harden testcase parser against repos being added too late

- support python-3.10

- check %_dbpath macro in rpmdb code

- handle default/visible/langonly attributes in comps parser

- support multiple collections in updateinfo parser

- add '-D' option in rpmdb2solv to set the dbpath

1176201

This update for zlib fixes the following issues:

- Fixed hw compression on z15 (bsc#1176201)

1182328,1182362,CVE-2021-27218,CVE-2021-27219

This update for glib2 fixes the following issues:

- CVE-2021-27218: g_byte_array_new_take takes a gsize as length but stores in a guint, this patch will refuse if the length is larger than guint. (bsc#1182328)

- CVE-2021-27219: g_memdup takes a guint as parameter and sometimes leads into an integer overflow, so add a g_memdup2 function which uses gsize to replace it. (bsc#1182362)

1078466,1146705,1175519,1178775,1180020,1180083,1180596,1181011,1181831,1183094

This update for filesystem the following issues:

- Remove duplicate line due to merge error

- Add fix for 'mesa' creating cache with perm 0700. (bsc#1181011)

- Fixed an issue causing failure during installation/upgrade a failure. (rh#1548403) (bsc#1146705)

- Allows to override config to add cleanup options of '/var/tmp'. (bsc#1078466)

- Create config to cleanup '/tmp' regular required with 'tmpfs'. (bsc#1175519)

This update for systemd fixes the following issues:

- Fix for a possible memory leak. (bsc#1180020)

- Fix for a case when to a bind mounted directory results inactive mount units. (#7811) (bsc#1180596)

- Fixed an issue when starting a container conflicts with another one. (bsc#1178775)

- Drop most of the tmpfiles that deal with generic paths and avoid warnings. (bsc#1078466, bsc#1181831)

- Don't use shell redirections when calling a rpm macro. (bsc#1183094)

- 'systemd' requires 'aaa_base' >= 13.2. (bsc#1180083)

1172442,1181358,CVE-2020-11080

This update for nghttp2 fixes the following issues:

- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358)

1183456,1183457,CVE-2021-20231,CVE-2021-20232

This update for gnutls fixes the following issues:

- CVE-2021-20232: Fixed a use after free issue which could have led to memory corruption and other potential consequences (bsc#1183456).

- CVE-2021-20231: Fixed a use after free issue which could have led to memory corruption and other potential consequences (bsc#1183457).

1183370,1183371,CVE-2021-24031,CVE-2021-24032

This update for zstd fixes the following issues:

- CVE-2021-24031: Added read permissions to files while being compressed or uncompressed (bsc#1183371).

- CVE-2021-24032: Fixed a race condition which could have allowed an attacker to access world-readable destination file (bsc#1183370).

1050625,1174016,1177238,1177275,1177427,1177583,1178910,1178966,1179083,1179222,1179816,1179847,1179909,1180077,1180663,1180721,1181328,1181622,1182629,CVE-2017-9271

This update for libzypp, zypper fixes the following issues:

Update zypper to version 1.14.43:

- doc: give more details about creating versioned package locks

(bsc#1181622)

- man: Document synonymously used patch categories (bsc#1179847)

- Fix source-download commands help (bsc#1180663)

- man: Recommend to use the --non-interactive global option rather than the command option -y (bsc#1179816)

- Extend apt packagemap (fixes #366)

- --quiet: Fix install summary to write nothing if there's nothing todo (bsc#1180077)

- Prefer /run over /var/run.

Update libzypp to 17.25.8:

- Try to provide a mounted /proc in --root installs (bsc#1181328)

Some systemd tools require /proc to be mounted and fail if it's

not there.

- Enable release packages to request a releaxed suse/opensuse

vendorcheck in dup when migrating. (bsc#1182629)

- Patch: Identify well-known category names (bsc#1179847)

This allows to use the RH and SUSE patch categrory names

synonymously:

(recommended = bugfix) and (optional = feature = enhancement).

- Add missing includes for GCC 11 compatibility.

- Fix %posttrans script execution (fixes #265)

The scripts are execuable. No need to call them through 'sh -c'.

- Commit: Fix rpmdb compat symlink in case rpm got removed.

- Repo: Allow multiple baseurls specified on one line (fixes #285)

- Regex: Fix memory leak and undefined behavior.

- Add rpm buildrequires for test suite (fixes #279)

- Use rpmdb2solv new -D switch to tell the location ob the

rpmdatabase to use.

- CVE-2017-9271: Fixed information leak in the log file (bsc#1050625 bsc#1177583)

- RepoManager: Force refresh if repo url has changed (bsc#1174016)

- RepoManager: Carefully tidy up the caches. Remove non-directory entries. (bsc#1178966)

- RepoInfo: ignore legacy type= in a .repo file and let RepoManager probe (bsc#1177427).

- RpmDb: If no database exists use the _dbpath configured in rpm. Still makes sure a compat

symlink at /var/lib/rpm exists in case the configures _dbpath is elsewhere. (bsc#1178910)

- Fixed update of gpg keys with elongated expire date (bsc#1179222)

- needreboot: remove udev from the list (bsc#1179083)

- Fix lsof monitoring (bsc#1179909)

- Rephrase solver problem descriptions (jsc#SLE-8482)

- Adapt to changed gpg2/libgpgme behavior (bsc#1180721)

- Multicurl backend breaks with with unknown filesize (fixes #277)

Severity
Container Advisory ID : SUSE-CU-2021:85-1
Container Tags : suse/sle15:15.0 , suse/sle15:15.0.4.22.366
Container Release : 4.22.366
Severity : important
Type : security

Related News