Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2022:0934-1 moderate: Security Fix for Binutils Issues

suse
Calendar Grey March 22, 2022
Dist Suse Esm H88
SUSE Security Update addresses 14 issues in binutils to enhance security and stability across multiple systems.
An update that solves 14 vulnerabilities, contains four features and has 5 fixes is now available

Summary

This update for binutils fixes the following issues: - For compatibility on old code stream that expect 'brcl 0,label' to not be disassembled as 'jgnop label' on s390x. (bsc#1192267) This reverts IBM zSeries HLASM support for now. - Fixed that ppc64 optflags did not enable LTO (bsc#1188941). - Fix empty man-pages from broken release tarball - Fixed a memory corruption with rpath option (bsc#1191473). - Fixed slow performance of stripping some binaries (bsc#1183909). Update to binutils 2.37: * The GNU Binutils sources now requires a C99 compiler and library to build. * Support for Realm Management Extension (RME) for AArch64 has been added. * A new linker option '-z report-relative-reloc' for x86 ELF targets has been added to report dynamic relative relocations.

References

#1179898 #1179899 #1179900 #1179901 #1179902

#1179903 #1180451 #1180454 #1180461 #1181452

#1182252 #1183511 #1183909 #1184519 #1184620

#1184794 #1188941 #1191473 #1192267 PM-2767

SLE-18637 SLE-19618 SLE-21561

Cross- CVE-2020-16590 CVE-2020-16591 CVE-2020-16592

CVE-2020-16593 CVE-2020-16598 CVE-2020-16599

CVE-2020-35448 CVE-2020-35493 CVE-2020-35496

CVE-2020-35507 CVE-2021-20197 CVE-2021-20284

CVE-2021-20294 CVE-2021-3487

CVSS scores:

CVE-2020-16590 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2020-16590 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2020-16591 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2020-16591 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Announcement ID: SUSE-SU-2022:0934-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here