Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE Linux Enterprise: 2022:1130-1 Important: libsolv Security Fix

suse
Calendar Grey April 8, 2022
Dist Suse Esm H88
A vital patch has been released for libsolv, libzypp, and zypper, addressing urgent vulnerabilities.
An update that contains security fixes can now be installed

Summary

This update for libsolv, libzypp, zypper fixes the following issues: Security relevant fix: - Harden package signature checks (bsc#1184501). libsolv to 0.7.22: - reworked choice rule generation to cover more usecases - support SOLVABLE_PREREQ_IGNOREINST in the ordering code (bsc#1196514) - support parsing of Debian's Multi-Arch indicator - fix segfault on conflict resolution when using bindings - fix split provides not working if the update includes a forbidden vendor change - support strict repository priorities new solver flag: SOLVER_FLAG_STRICT_REPO_PRIORITY - support zstd compressed control files in debian packages - add an ifdef allowing to rename Solvable dependency members ("requires" is a keyword in C++20) - support setting/reading userdata in solv files new functions:

References

#1184501 #1194848 #1195999 #1196061 #1196317

#1196368 #1196514 #1196925 #1197134

Affected Products:

SUSE Linux Enterprise Desktop 15

SUSE Linux Enterprise High Performance Computing 15

SUSE Linux Enterprise High Performance Computing 15-ESPOS

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise Installer 15

SUSE Linux Enterprise Server 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server for SAP Applications 15

https://bugzilla.suse.com/1184501

https://bugzilla.suse.com/1194848

https://bugzilla.suse.com/1195999

https://bugzilla.suse.com/1196061

https://bugzilla.suse.com/1196317

https://bugzilla.suse.com/1196368

https://bugzilla.suse.com/1196514

https://bugzilla.suse.com/1196925

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1130-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here