References : 1065270 1127591 1186870 1195633 1199132 1199282 1199880 1200710
1201088 1201617 1203201 1203599 1203746 1204585 1206483 1206513
1206781 1207014 1207022 1207571 1207843 1207957 1207975 1207992
1208036 1208283 1208329 1208358 1208820 1208905 1209122 1209209
1209210 1209211 1209212 1209214 1209361 1209362 1209406 1209533
1209621 1209624 1209713 1209714 1209873 1209878 1210135 1210153
1210164 1210243 1210314 1210411 1210412 1210434 1210507 1210593
1210719 1210784 1210870 1210944 1211090 1211231 1211232 1211233
1211246 1211339 1211430 1211795 CVE-2021-3541 CVE-2022-29824
CVE-2022-4899 CVE-2023-0464 CVE-2023-0465 CVE-2023-0466 CVE-2023-0687
CVE-2023-23916 CVE-2023-23931 CVE-2023-24593 CVE-2023-25180 CVE-2023-25577
CVE-2023-2650 CVE-2023-27533 CVE-2023-27534 CVE-2023-27535 CVE-2023-27536
CVE-2023-27538 CVE-2023-28320 CVE-2023-28321 CVE-2023-28322 CVE-2023-28484
CVE-2023-28486 CVE-2023-28487 CVE-2023-29383 CVE-2023-29469 CVE-2023-29491
CVE-2023-2953 CVE-2023-30861
1200710,1203746,1206781,1207022,1207843
This update for nfs-utils fixes the following issues:
- Rename all drop-in options.conf files as 10-options.conf
This makes it easier for other packages to over-ride with a drop-in with a later sequence number (bsc#1207843)
- Avoid modprobe errors when sysctl is not installed (bsc#1200710 bsc#1207022 bsc#1206781)
- Add '-S scope' option to rpc.nfsd to simplify fail-over cluster configuration (bsc#1203746)
1208283,CVE-2023-25577
This update for python-Werkzeug fixes the following issues:
- CVE-2023-25577: Fixed high resource usage when parsing multipart form data with many fields (bsc#1208283).
1203201,1206483,1209361,1209362,CVE-2023-28486,CVE-2023-28487
This update for sudo fixes the following issue:
Security fixes:
- CVE-2023-28486: Fixed missing control characters escaping in log messages (bsc#1209362).
- CVE-2023-28487: Fixed missing control characters escaping in sudoreplay output (bsc#1209361).
Other fixes:
- Fix a situation where 'sudo -U otheruser -l' would dereference a NULL pointer (bsc#1206483).
- Do not re-enable the reader when flushing the buffers as part of pty_finish() (bsc#1203201).
1207992,1209209,1209210,1209211,1209212,1209214,CVE-2023-23916,CVE-2023-27533,CVE-2023-27534,CVE-2023-27535,CVE-2023-27536,CVE-2023-27538
This update for curl fixes the following issues:
- CVE-2023-27533: Fixed TELNET option IAC injection (bsc#1209209).
- CVE-2023-27534: Fixed SFTP path ~ resolving discrepancy (bsc#1209210).
- CVE-2023-27535: Fixed FTP too eager connection reuse (bsc#1209211).
- CVE-2023-27536: Fixed GSS delegation too eager connection reuse (bsc#1209212).
- CVE-2023-27538: Fixed SSH connection too eager reuse still (bsc#1209214).
- CVE-2023-23916: Fixed HTTP multi-header compression denial of service (bsc#1207992).
1207571,1207957,1207975,1208358,CVE-2023-0687
This update for glibc fixes the following issues:
Security issue fixed:
- CVE-2023-0687: Fix allocated buffer overflow in gmon (bsc#1207975)
Other issues fixed:
- Fix avx2 strncmp offset compare condition check (bsc#1208358)
- elf: Allow dlopen of filter object to work (bsc#1207571)
- powerpc: Fix unrecognized instruction errors with recent GCC
- x86: Cache computation for AMD architecture (bsc#1207957)
This update for systemd-presets-common-SUSE fixes the following issue:
- Enable systemd-pstore.service by default (jsc#PED-2663)
1208905
This update for smartmontools fixes the following issues:
- Fix `smartctl` issue affecting NVMe on big endian systems (bsc#1208905)
1208036,CVE-2023-23931
This update for python-cryptography fixes the following issues:
- CVE-2023-23931: Fixed memory corruption in Cipher.update_into (bsc#1208036).
1209624,1209873,1209878,CVE-2023-0464,CVE-2023-0465,CVE-2023-0466
This update for openssl-1_1 fixes the following issues:
- CVE-2023-0464: Fixed excessive Resource Usage Verifying X.509 Policy Constraints (bsc#1209624).
- CVE-2023-0465: Invalid certificate policies in leaf certificates were silently ignored (bsc#1209878).
- CVE-2023-0466: Certificate policy check were not enabled (bsc#1209873).
This update for timezone fixes the following issues:
- Version update from 2022g to 2023c:
* Egypt now uses DST again, from April through October.
* This year Morocco springs forward April 23, not April 30.
* Palestine delays the start of DST this year.
* Much of Greenland still uses DST from 2024 on.
* America/Yellowknife now links to America/Edmonton.
* tzselect can now use current time to help infer timezone.
* The code now defaults to C99 or later.
1203599
This update for elfutils fixes the following issues:
- go1.19 builds created debuginfo that was not extractable using rpm / elfutils 0.177. (bsc#1203599)
1201617
This update for xmlsec1 fixes the following issue:
- Ship missing xmlsec1 to synchronize its version across different products (bsc#1201617)
1065270,1199132,1204585,1210411,1210412,CVE-2021-3541,CVE-2022-29824,CVE-2023-28484,CVE-2023-29469
This update for libxml2 fixes the following issues:
- CVE-2023-29469: Fixed inconsistent result when hashing empty strings (bsc#1210412).
- CVE-2023-28484: Fixed NULL pointer dereference in xmlSchemaFixupComplexType (bsc#1210411).
- CVE-2022-29824: Fixed integer overflow leading to out-of-bounds write in buf.c (bsc#1199132).
The following non-security bugs were fixed:
- Added W3C conformance tests to the testsuite (bsc#1204585).
- Fixed NULL pointer dereference when parsing invalid data (glgo#libxml2!15) (bsc#1065270) .
1210507,CVE-2023-29383
This update for shadow fixes the following issues:
- CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507).
1209533,CVE-2022-4899
This update for zstd fixes the following issues:
- CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533).
1209713,1209714,1210135,CVE-2023-24593,CVE-2023-25180
This update for glib2 fixes the following issues:
- CVE-2023-24593: Fixed a denial of service caused by handling a malicious text-form variant (bsc#1209714).
- CVE-2023-25180: Fixed a denial of service caused by malicious serialised variant (bsc#1209713).
The following non-security bug was fixed:
- Fixed regression on s390x (bsc#1210135, glgo#GNOME/glib!2978).
1209122
This update for procps fixes the following issue:
- Allow - as leading character to ignore possible errors on systctl entries (bsc#1209122)
1210434,CVE-2023-29491
This update for ncurses fixes the following issues:
- CVE-2023-29491: Fixed memory corruption issues when processing malformed terminfo data (bsc#1210434).
1207014
This update for openssh fixes the following issues:
- Remove some patches that cause invalid environment assignments (bsc#1207014).
1206513
This update for zlib fixes the following issues:
- Add DFLTCC support for using inflate() with a small window (bsc#1206513)
1186870,1199282
This update for python-packaging fixes the following issues:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Add patch to fix testsuite on big-endian targets
- Ignore python3.6.2 since the test doesn't support it.
- update to 21.3:
* Add a pp3-none-any tag
* Replace the blank pyparsing 3 exclusion with a 3.0.5 exclusion
* Fix a spelling mistake
- update to 21.2:
* Update documentation entry for 21.1.
* Update pin to pyparsing to exclude 3.0.0.
* PEP 656: musllinux support
* Drop support for Python 2.7, Python 3.4 and Python 3.5
* Replace distutils usage with sysconfig
* Add support for zip files
* Use cached hash attribute to short-circuit tag equality comparisons
* Specify the default value for the 'specifier' argument to 'SpecifierSet'
* Proper keyword-only 'warn' argument in packaging.tags
* Correctly remove prerelease suffixes from ~= check
* Fix type hints for 'Version.post' and 'Version.dev'
* Use typing alias 'UnparsedVersion'
* Improve type inference
* Tighten the return typeo
- Add Provides: for python*dist(packaging). (bsc#1186870)
- add no-legacyversion-warning.patch to restore compatibility with 20.4
- update to 20.9:
* Add support for the ``macosx_10_*_universal2`` platform tags
* Introduce ``packaging.utils.parse_wheel_filename()`` and ``parse_sdist_filename()``
- update to 20.8:
* Revert back to setuptools for compatibility purposes for some Linux distros
* Do not insert an underscore in wheel tags when the interpreter version number is more than 2 digits
* Fix flit configuration, to include LICENSE files
* Make `intel` a recognized CPU architecture for the `universal` macOS platform tag
* Add some missing type hints to `packaging.requirements`
* Officially support Python 3.9
* Deprecate the ``LegacyVersion`` and ``LegacySpecifier`` classes
* Handle ``OSError`` on non-dynamic executables when attempting to resolve the glibc version string.
- update to 20.4:
* Canonicalize version before comparing specifiers.
* Change type hint for ``canonicalize_name`` to return ``packaging.utils.NormalizedName``.
This enables the use of static typing tools (like mypy) to detect mixing of normalized and un-normalized names.
1211231,1211232,1211233,1211339,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322
This update for curl fixes the following issues:
- CVE-2023-28320: Fixed siglongjmp race condition (bsc#1211231).
- CVE-2023-28321: Fixed IDN wildcard matching (bsc#1211232).
- CVE-2023-28322: Fixed POST-after-PUT confusion (bsc#1211233).
1127591,1195633,1208329,1209406,1210870
This update for libzypp, zypper fixes the following issues:
- Installing local RPM packages fails if /usr/bin/find is not installed (bsc#1195633)
- multicurl: propagate ssl settings stored in repo url (bsc#1127591)
- MediaCurl: Fix endless loop if wrong credentials are stored in credentials.cat (bsc#1210870)
- zypp.conf: Introduce 'download.connect_timeout' [60 sec.] (bsc#1208329)
- Teach MediaNetwork to retry on HTTP2 errors.
- Fix selecting installed patterns from picklist (bsc#1209406)
- man: better explanation of --priority
1211246,CVE-2023-30861
This update for python-Flask fixes the following issues:
- CVE-2023-30861: Fixed a potential cookie confusion due to incorrect
caching (bsc#1211246).
1210593
This update for zlib fixes the following issue:
- Fix function calling order to avoid crashes (bsc#1210593)
1211430,CVE-2023-2650
This update for openssl-1_1 fixes the following issues:
- CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430).
1210164
This update for util-linux fixes the following issues:
- Add upstream patches (bsc#1210164, bsc#1210164, bsc#1210164)
1211795,CVE-2023-2953
This update for openldap2 fixes the following issues:
- CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795).
1199880,1201088,1208820,1209621,1210153,1210243,1210314,1210719,1210784,1210944,1211090
This update for ceph, ceph-image, ceph-iscsi fixes the following issues:
- Update to 16.2.13-66-g54799ee0666:
+ (bsc#1199880) mgr: don't dump global config holding gil
+ (bsc#1209621) cephadm: fix NFS haproxy failover if active node disappears + (bsc#1210153) mgr/cephadm: fix handling of mgr upgrades with 3 or more mgrs + (bsc#1210243, bsc#1210314) ceph-volume: fix regression in activate
+ (bsc#1210719) cephadm: mount host /etc/hosts for daemon containers in podman deployments
+ (bsc#1210784) mgr/dashboard: Fix SSO error: 'str' object has no attribute 'decode'
+ (bsc#1210944) cmake: patch boost source to support python 3.11 + (bsc#1211090) fix FTBFS on s390x
- Add _multibuild to define additional spec files as additional
flavors. Eliminates the need for source package links in OBS.
- Update to 16.2.11-65-g8b7e6fc0182:
+ (bsc#1201088) test/librados: fix FTBFS on gcc 13
+ (bsc#1208820) mgr/dashboard: allow to pass controls on iscsi disk create
- Update to 16.2.11-62-gce6291a3463:
+ (bsc#1201088) fix FTBFS on gcc 13
- Update to 16.2.13-66-g54799ee0666:
+ (bsc#1199880) mgr: don't dump global config holding gil
+ (bsc#1209621) cephadm: fix NFS haproxy failover if active node disappears + (bsc#1210153) mgr/cephadm: fix handling of mgr upgrades with 3 or more mgrs + (bsc#1210243, bsc#1210314) ceph-volume: fix regression in activate
+ (bsc#1210719) cephadm: mount host /etc/hosts for daemon containers in podman deployments
+ (bsc#1210784) mgr/dashboard: Fix SSO error: 'str' object has no attribute 'decode'
+ (bsc#1210944) cmake: patch boost source to support python 3.11 + (bsc#1211090) fix FTBFS on s390x
- Add _multibuild to define additional spec files as additional
flavors. Eliminates the need for source package links in OBS.
- Update to 16.2.11-65-g8b7e6fc0182:
+ (bsc#1201088) test/librados: fix FTBFS on gcc 13
+ (bsc#1208820) mgr/dashboard: allow to pass controls on iscsi disk create
- Update to 16.2.11-62-gce6291a3463:
+ (bsc#1201088) fix FTBFS on gcc 13
- Update to 3.5+1679292226.g8769429:
+ rbd-target-api: don't ignore controls on disk create (bsc#1208820)
- checkin.sh: default to ses7 branch
The following package changes have been done:
- ceph-base-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-common-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-grafana-dashboards-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-iscsi-3.5+1679292226.g8769429-150300.3.6.1 updated
- ceph-mds-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mgr-cephadm-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mgr-dashboard-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mgr-modules-core-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mgr-rook-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mgr-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-mon-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-osd-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-prometheus-alerts-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-radosgw-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- cephadm-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- ceph-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- glib2-tools-2.62.6-150200.3.15.1 updated
- glibc-locale-base-2.31-150300.46.1 updated
- glibc-2.31-150300.46.1 updated
- libblkid1-2.36.2-150300.4.35.1 updated
- libcephfs2-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- libcephsqlite-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- libcurl4-7.66.0-150200.4.57.1 updated
- libdw1-0.177-150300.11.6.1 updated
- libebl-plugins-0.177-150300.11.6.1 updated
- libelf1-0.177-150300.11.6.1 updated
- libfdisk1-2.36.2-150300.4.35.1 updated
- libgio-2_0-0-2.62.6-150200.3.15.1 updated
- libglib-2_0-0-2.62.6-150200.3.15.1 updated
- libgmodule-2_0-0-2.62.6-150200.3.15.1 updated
- libgobject-2_0-0-2.62.6-150200.3.15.1 updated
- libldap-2_4-2-2.4.46-150200.14.14.1 updated
- libldap-data-2.4.46-150200.14.14.1 updated
- libmount1-2.36.2-150300.4.35.1 updated
- libncurses6-6.1-150000.5.15.1 updated
- libopenssl1_1-hmac-1.1.1d-150200.11.65.1 updated
- libopenssl1_1-1.1.1d-150200.11.65.1 updated
- libprocps7-3.3.15-150000.7.31.1 updated
- librados2-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- librbd1-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- librgw2-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- libsmartcols1-2.36.2-150300.4.35.1 updated
- libsolv-tools-0.7.24-150200.18.1 updated
- libuuid1-2.36.2-150300.4.35.1 updated
- libxml2-2-2.9.7-150000.3.57.1 updated
- libxmlsec1-1-1.2.28-150100.7.13.4 updated
- libxmlsec1-openssl1-1.2.28-150100.7.13.4 updated
- libz1-1.2.11-150000.3.45.1 updated
- libzstd1-1.4.4-150000.1.9.1 updated
- libzypp-17.31.11-150200.61.1 updated
- login_defs-4.8.1-150300.4.6.1 updated
- ncurses-utils-6.1-150000.5.15.1 updated
- nfs-client-2.1.1-150100.10.32.1 updated
- nfs-kernel-server-2.1.1-150100.10.32.1 updated
- openssh-clients-8.4p1-150300.3.18.2 updated
- openssh-common-8.4p1-150300.3.18.2 updated
- openssh-fips-8.4p1-150300.3.18.2 updated
- openssh-server-8.4p1-150300.3.18.2 updated
- openssh-8.4p1-150300.3.18.2 updated
- openssl-1_1-1.1.1d-150200.11.65.1 updated
- procps-3.3.15-150000.7.31.1 updated
- python3-Flask-1.0.2-150100.6.3.1 updated
- python3-Werkzeug-1.0.1-150300.3.3.1 updated
- python3-ceph-argparse-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- python3-ceph-common-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- python3-cephfs-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- python3-cryptography-3.3.2-150200.19.1 updated
- python3-packaging-21.3-150200.3.3.1 updated
- python3-rados-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- python3-rbd-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- python3-rgw-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- rbd-mirror-16.2.13.66+g54799ee0666-150300.3.11.1 updated
- shadow-4.8.1-150300.4.6.1 updated
- smartmontools-7.2-150300.8.8.1 updated
- sudo-1.9.5p2-150300.3.24.1 updated
- systemd-presets-common-SUSE-15-150100.8.20.1 updated
- terminfo-base-6.1-150000.5.15.1 updated
- timezone-2023c-150000.75.23.1 updated
- util-linux-systemd-2.36.2-150300.4.35.1 updated
- util-linux-2.36.2-150300.4.35.1 updated
- zypper-1.14.60-150200.51.1 updated
- container:sles15-image-15.0.0-17.20.146 updated