Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2022:1157-2 Important: libsolv, libzypp, zypper Security Flaws

suse
Calendar Grey July 14, 2022
Dist Suse Esm H88
SUSE Security Patch resolves critical vulnerabilities in libsolv, libzypp, and zypper to bolster overall system defense.
An update that contains security fixes can now be installed

Summary

This update for libsolv, libzypp, zypper fixes the following issues: Security relevant fix: - Harden package signature checks (bsc#1184501). libsolv update to 0.7.22: - reworked choice rule generation to cover more usecases - support SOLVABLE_PREREQ_IGNOREINST in the ordering code (bsc#1196514) - support parsing of Debian's Multi-Arch indicator - fix segfault on conflict resolution when using bindings - fix split provides not working if the update includes a forbidden vendor change - support strict repository priorities new solver flag: SOLVER_FLAG_STRICT_REPO_PRIORITY - support zstd compressed control files in debian packages - add an ifdef allowing to rename Solvable dependency members ("requires" is a keyword in C++20) - support setting/reading userdata in solv files new functions:

References

#1184501 #1194848 #1195999 #1196061 #1196317

#1196368 #1196514 #1196925 #1197134

Affected Products:

SUSE Linux Enterprise Micro 5.2

https://bugzilla.suse.com/1184501

https://bugzilla.suse.com/1194848

https://bugzilla.suse.com/1195999

https://bugzilla.suse.com/1196061

https://bugzilla.suse.com/1196317

https://bugzilla.suse.com/1196368

https://bugzilla.suse.com/1196514

https://bugzilla.suse.com/1196925

https://bugzilla.suse.com/1197134

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1157-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here