Advisory ID: SUSE-SU-2021:778-1 Released: Fri Mar 12 17:42:25 2021 Summary: Security update for glib2 Type: security Severity: important Advisory ID: SUSE-RU-2021:786-1 Released: Mon Mar 15 11:19:23 2021 Summary: Recommended update for zlib Type: recommended Severity: moderate Advisory ID: SUSE-RU-2021:874-1 Released: Thu Mar 18 09:41:54 2021 Summary: Recommended update for libsolv, libzypp, zypper
References : 1078466 1146705 1172442 1175519 1176201 1178775 1179847 1180020
1180083 1180596 1181011 1181328 1181358 1181622 1181831 1182328
1182362 1182629 1183094 1183370 1183371 1183456 1183457 1183852
CVE-2020-11080 CVE-2021-20231 CVE-2021-20232 CVE-2021-24031 CVE-2021-24032
CVE-2021-27218 CVE-2021-27219 CVE-2021-3449
1182328,1182362,CVE-2021-27218,CVE-2021-27219
This update for glib2 fixes the following issues:
- CVE-2021-27218: g_byte_array_new_take takes a gsize as length but stores in a guint, this patch will refuse if
the length is larger than guint. (bsc#1182328)
- CVE-2021-27219: g_memdup takes a guint as parameter and sometimes leads into an integer overflow, so add a g_memdup2 function which uses gsize to replace it. (bsc#1182362)
1176201
Get the latest Linux and open source security news straight to your inbox.