An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for glibc ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3830-1 Rating: moderate References: #1027496 #1183085 Cross-References: CVE-2016-10228 CVSS scores: CVE-2016-10228 (NVD) : 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2016-10228 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for glibc fixes the following issues: - libio: do not attempt to free wide buffers of legacy streams (bsc#1183085) - CVE-2016-10228: Rewrite iconv option parsing to fix security issue (bsc#1027496) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-3830=1 - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-3830=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-3830=1 Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): glibc-2.26-13.62.1 glibc-debuginfo-2.26-13.62.1 glibc-debugsource-2.26-13.62.1 glibc-locale-2.26-13.62.1 glibc-locale-base-2.26-13.62.1 glibc-locale-base-debuginfo-2.26-13.62.1 - SUSE LinuxEnterprise Module for Development Tools 15-SP2 (aarch64 ppc64le s390x x86_64): glibc-debuginfo-2.26-13.62.1 glibc-debugsource-2.26-13.62.1 glibc-devel-static-2.26-13.62.1 glibc-utils-2.26-13.62.1 glibc-utils-debuginfo-2.26-13.62.1 glibc-utils-src-debugsource-2.26-13.62.1 - SUSE Linux Enterprise Module for Development Tools 15-SP2 (x86_64): glibc-32bit-debuginfo-2.26-13.62.1 glibc-devel-32bit-2.26-13.62.1 glibc-devel-32bit-debuginfo-2.26-13.62.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): glibc-2.26-13.62.1 glibc-debuginfo-2.26-13.62.1 glibc-debugsource-2.26-13.62.1 glibc-devel-2.26-13.62.1 glibc-devel-debuginfo-2.26-13.62.1 glibc-extra-2.26-13.62.1 glibc-extra-debuginfo-2.26-13.62.1 glibc-locale-2.26-13.62.1 glibc-locale-base-2.26-13.62.1 glibc-locale-base-debuginfo-2.26-13.62.1 glibc-profile-2.26-13.62.1 nscd-2.26-13.62.1 nscd-debuginfo-2.26-13.62.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): glibc-i18ndata-2.26-13.62.1 glibc-info-2.26-13.62.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): glibc-32bit-2.26-13.62.1 glibc-32bit-debuginfo-2.26-13.62.1 glibc-locale-base-32bit-2.26-13.62.1 glibc-locale-base-32bit-debuginfo-2.26-13.62.1 References: https://www.suse.com/security/cve/CVE-2016-10228.html https://bugzilla.suse.com/1027496 https://bugzilla.suse.com/1183085 . A security enhancement for glibc has been issued, targeting a particular vulnerability with moderate risk for SUSE versions.. SUSE Linux, glibc update, moderate threat. . LinuxSecurity.com Team
An update that solves 5 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3615-1 Rating: important References: #1177409 #1177412 #1177413 #1177414 #1178591 #1178963 Cross-References: CVE-2020-27670 CVE-2020-27671 CVE-2020-27672 CVE-2020-27674 CVE-2020-28368 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves 5 vulnerabilities and has one errata is now available. Description: This update for xen fixes the following issues: - bsc#1178963 - VUL-0: xen: stack corruption from XSA-346 change (XSA-355) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP2-2020-3615=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-3615=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP2 (noarch): xen-tools-xendomains-wait-disk-4.13.2_04-3.19.1 - SUSE Linux Enterprise Module for Server Applications 15-SP2 (x86_64): xen-4.13.2_04-3.19.1 xen-debugsource-4.13.2_04-3.19.1 xen-devel-4.13.2_04-3.19.1 xen-tools-4.13.2_04-3.19.1 xen-tools-debuginfo-4.13.2_04-3.19.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): xen-debugsource-4.13.2_04-3.19.1 xen-libs-4.13.2_04-3.19.1 xen-libs-debuginfo-4.13.2_04-3.19.1 xen-tools-domU-4.13.2_04-3.19.1 xen-tools-domU-debuginfo-4.13.2_04-3.19.1 References: https://www.suse.com/security/cve/CVE-2020-27670.html https://www.suse.com/security/cve/CVE-2020-27671.html https://www.suse.com/security/cve/CVE-2020-27672.html https://www.suse.com/security/cve/CVE-2020-27674.html https://www.suse.com/security/cve/CVE-2020-28368.html https://bugzilla.suse.com/1177409 https://bugzilla.suse.com/1177412 https://bugzilla.suse.com/1177413 https://bugzilla.suse.com/1177414 https://bugzilla.suse.com/1178591 https://bugzilla.suse.com/1178963 . Important announcement from SUSE relating to the resolution of five significant vulnerabilities identified within Xen, accompanied by tailored installation guidelines.. SUSE Update, Xen Patch, Security Fix, Server Applications, Basesystem. . Severity: Important. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2158-1 Rating: important References: #1172356 #1174543 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for xen fixes the following issues: - bsc#1174543 - secure boot related fixes - bsc#1172356 - Not able to hot-plug NIC via virt-manager, asks to attach on next reboot while it should be live attached Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-2158=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-2158=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (x86_64): xen-4.12.3_06-3.25.1 xen-debugsource-4.12.3_06-3.25.1 xen-devel-4.12.3_06-3.25.1 xen-tools-4.12.3_06-3.25.1 xen-tools-debuginfo-4.12.3_06-3.25.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): xen-debugsource-4.12.3_06-3.25.1 xen-libs-4.12.3_06-3.25.1 xen-libs-debuginfo-4.12.3_06-3.25.1 xen-tools-domU-4.12.3_06-3.25.1 xen-tools-domU-debuginfo-4.12.3_06-3.25.1 References: https://bugzilla.suse.com/1172356 https://bugzilla.suse.com/1174543 _______________________________________________ sle-security-updates mailing list
An update that fixes 9 vulnerabilities is now available. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:3309-1 Rating: important References: #1154460 #1154464 #1157888 #1158003 #1158004 #1158005 #1158006 #1158007 Cross-References: CVE-2019-18422 CVE-2019-18423 CVE-2019-19577 CVE-2019-19578 CVE-2019-19579 CVE-2019-19580 CVE-2019-19581 CVE-2019-19582 CVE-2019-19583 Affected Products: SUSE Linux Enterprise Module for Server Applications 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes 9 vulnerabilities is now available. Description: This update for xen fixes the following issues: - CVE-2019-19581: Fixed a potential out of bounds on 32-bit Arm (bsc#1158003 XSA-307). - CVE-2019-19582: Fixed a potential infinite loop when x86 accesses to bitmaps with a compile time known size of 64 (bsc#1158003 XSA-307). - CVE-2019-19583: Fixed improper checks which could have allowed HVM/PVH guest userspace code to crash the guest,leading to a guest denial of service (bsc#1158004 XSA-308). - CVE-2019-19578: Fixed an issue where a malicious or buggy PV guest could have caused hypervisor crash resulting in denial of service affecting the entire host (bsc#1158005 XSA-309). - CVE-2019-19580: Fixed a privilege escalation where a malicious PV guest administrator could have been able to escalate their privilege to that of the host (bsc#1158006 XSA-310). - CVE-2019-19577: Fixed an issue where a malicious guest administrator could have caused Xen to access data structures while they are being modified leading to a crash (bsc#1158007 XSA-311). - CVE-2019-19579: Fixed a privilege escaltion where anuntrusted domain with access to a physical device can DMA into host memory (bsc#1157888 XSA-306). - CVE-2019-18423: A malicious guest administrator may cause a hypervisor crash, resulting in a Denial of Service (DoS) (bsc#1154460 XSA-301). - CVE-2019-18422: A malicious ARM guest might contrive to arrange for critical Xen code to run with interrupts erroneously enabled. This could lead to data corruption, denial of service, or possibly even privilege escalation. However a precise attack technique has not been identified. (bsc#1154464 XSA-303) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-2019-3309=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-3309=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15 (x86_64): xen-4.10.4_08-3.28.1 xen-debugsource-4.10.4_08-3.28.1 xen-devel-4.10.4_08-3.28.1 xen-tools-4.10.4_08-3.28.1 xen-tools-debuginfo-4.10.4_08-3.28.1 - SUSE Linux Enterprise Module for Basesystem 15 (x86_64): xen-debugsource-4.10.4_08-3.28.1 xen-libs-4.10.4_08-3.28.1 xen-libs-debuginfo-4.10.4_08-3.28.1 xen-tools-domU-4.10.4_08-3.28.1 xen-tools-domU-debuginfo-4.10.4_08-3.28.1 References: https://www.suse.com/security/cve/CVE-2019-18422.html https://www.suse.com/security/cve/CVE-2019-18423.html https://www.suse.com/security/cve/CVE-2019-19577.html https://www.suse.com/security/cve/CVE-2019-19578.html https://www.suse.com/security/cve/CVE-2019-19579.html https://www.suse.com/security/cve/CVE-2019-19580.html https://www.suse.com/security/cve/CVE-2019-19581.html https://www.suse.com/security/cve/CVE-2019-19582.html https://www.suse.com/security/cve/CVE-2019-19583.html https://bugzilla.suse.com/1154460 https://bugzilla.suse.com/1154464 https://bugzilla.suse.com/1157888 https://bugzilla.suse.com/1158003 https://bugzilla.suse.com/1158004 https://bugzilla.suse.com/1158005 https://bugzilla.suse.com/1158006 https://bugzilla.suse.com/1158007 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for curl ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1357-1 Rating: important References: #1135170 Cross-References: CVE-2019-5436 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for curl fixes the following issues: Security issue fixed: - CVE-2019-5436: Fixed a heap buffer overflow exists in tftp_receive_packet that receives data from a TFTP server (bsc#1135170). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-1357=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1357=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): curl-mini-7.60.0-3.20.1 curl-mini-debuginfo-7.60.0-3.20.1 curl-mini-debugsource-7.60.0-3.20.1 libcurl-mini-devel-7.60.0-3.20.1 libcurl4-mini-7.60.0-3.20.1 libcurl4-mini-debuginfo-7.60.0-3.20.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): curl-7.60.0-3.20.1 curl-debuginfo-7.60.0-3.20.1 curl-debugsource-7.60.0-3.20.1 libcurl-devel-7.60.0-3.20.1 libcurl4-7.60.0-3.20.1 libcurl4-debuginfo-7.60.0-3.20.1 - SUSE Linux EnterpriseModule for Basesystem 15 (x86_64): libcurl4-32bit-7.60.0-3.20.1 libcurl4-32bit-debuginfo-7.60.0-3.20.1 References: https://www.suse.com/security/cve/CVE-2019-5436.html https://bugzilla.suse.com/1135170 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.