Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 24 articles for you...
217

Oracle Linux 9 ELSA-2025-1346 moderate: gcc security fix

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1346 http://linux.oracle.com/errata/ELSA-2025-1346.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: cpp-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-c++-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-gfortran-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-offload-nvptx-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-plugin-annobin-11.5.0-5.0.1.el9_5.x86_64.rpm libasan-11.5.0-5.0.1.el9_5.i686.rpm libasan-11.5.0-5.0.1.el9_5.x86_64.rpm libatomic-11.5.0-5.0.1.el9_5.i686.rpm libatomic-11.5.0-5.0.1.el9_5.x86_64.rpm libgcc-11.5.0-5.0.1.el9_5.i686.rpm libgcc-11.5.0-5.0.1.el9_5.x86_64.rpm libgccjit-11.5.0-5.0.1.el9_5.i686.rpm libgccjit-11.5.0-5.0.1.el9_5.x86_64.rpm libgccjit-devel-11.5.0-5.0.1.el9_5.i686.rpm libgccjit-devel-11.5.0-5.0.1.el9_5.x86_64.rpm libgfortran-11.5.0-5.0.1.el9_5.i686.rpm libgfortran-11.5.0-5.0.1.el9_5.x86_64.rpm libgomp-11.5.0-5.0.1.el9_5.i686.rpm libgomp-11.5.0-5.0.1.el9_5.x86_64.rpm libgomp-offload-nvptx-11.5.0-5.0.1.el9_5.x86_64.rpm libitm-11.5.0-5.0.1.el9_5.i686.rpm libitm-11.5.0-5.0.1.el9_5.x86_64.rpm libitm-devel-11.5.0-5.0.1.el9_5.i686.rpm libitm-devel-11.5.0-5.0.1.el9_5.x86_64.rpm liblsan-11.5.0-5.0.1.el9_5.x86_64.rpm libquadmath-11.5.0-5.0.1.el9_5.i686.rpm libquadmath-11.5.0-5.0.1.el9_5.x86_64.rpm libquadmath-devel-11.5.0-5.0.1.el9_5.i686.rpm libquadmath-devel-11.5.0-5.0.1.el9_5.x86_64.rpm libstdc++-11.5.0-5.0.1.el9_5.i686.rpm libstdc++-11.5.0-5.0.1.el9_5.x86_64.rpm libstdc++-devel-11.5.0-5.0.1.el9_5.i686.rpm libstdc++-devel-11.5.0-5.0.1.el9_5.x86_64.rpm libstdc++-docs-11.5.0-5.0.1.el9_5.x86_64.rpm libtsan-11.5.0-5.0.1.el9_5.x86_64.rpm libubsan-11.5.0-5.0.1.el9_5.i686.rpm libubsan-11.5.0-5.0.1.el9_5.x86_64.rpm gcc-plugin-devel-11.5.0-5.0.1.el9_5.i686.rpm gcc-plugin-devel-11.5.0-5.0.1.el9_5.x86_64.rpm libstdc++-static-11.5.0-5.0.1.el9_5.i686.rpm libstdc++-static-11.5.0-5.0.1.el9_5.x86_64.rpm aarch64: cpp-11.5.0-5.0.1.el9_5.aarch64.rpm gcc-11.5.0-5.0.1.el9_5.aarch64.rpm gcc-c++-11.5.0-5.0.1.el9_5.aarch64.rpm gcc-gfortran-11.5.0-5.0.1.el9_5.aarch64.rpm gcc-plugin-annobin-11.5.0-5.0.1.el9_5.aarch64.rpm libasan-11.5.0-5.0.1.el9_5.aarch64.rpm libatomic-11.5.0-5.0.1.el9_5.aarch64.rpm libgcc-11.5.0-5.0.1.el9_5.aarch64.rpm libgccjit-11.5.0-5.0.1.el9_5.aarch64.rpm libgccjit-devel-11.5.0-5.0.1.el9_5.aarch64.rpm libgfortran-11.5.0-5.0.1.el9_5.aarch64.rpm libgomp-11.5.0-5.0.1.el9_5.aarch64.rpm libitm-11.5.0-5.0.1.el9_5.aarch64.rpm libitm-devel-11.5.0-5.0.1.el9_5.aarch64.rpm liblsan-11.5.0-5.0.1.el9_5.aarch64.rpm libstdc++-11.5.0-5.0.1.el9_5.aarch64.rpm libstdc++-devel-11.5.0-5.0.1.el9_5.aarch64.rpm libstdc++-docs-11.5.0-5.0.1.el9_5.aarch64.rpm libtsan-11.5.0-5.0.1.el9_5.aarch64.rpm libubsan-11.5.0-5.0.1.el9_5.aarch64.rpm gcc-plugin-devel-11.5.0-5.0.1.el9_5.aarch64.rpm libstdc++-static-11.5.0-5.0.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//gcc-11.5.0-5.0.1.el9_5.src.rpm Related CVEs: CVE-2020-11023 Description of changes: [11.5.0-5.0.1] - Merge Oracle patches to 11.5.0-5. Oracle history: _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Recent updates for gcc and associated packages in Oracle Linux 9 have been released, enhancing both system security and overall performance.. Oracle Linux Security, gcc Update, ELSA-2025-1346 Advisory. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2025 Oracle
100

SUSE: Recommended Updates for Crypto-Policies, GCC, Python Security

The container sles-15-sp5-chost-byos-v20231213-arm64 was updated. The following patches have been included in this update:. SUSE Image Update Advisory: sles-15-sp5-chost-byos-v20231213-arm64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2023:873-1 Image Tags : sles-15-sp5-chost-byos-v20231213-arm64:20231213 Image Release : Severity : important Type : security References : 1041742 1111622 1170175 1176785 1184753 1199282 1200528 1203760 1206480 1206667 1206684 1207325 1209998 1210286 1210557 1210660 1211427 1212101 1212418 1212422 1212759 1213639 1213915 1214052 1214460 1214546 1214572 1215427 1215947 1215979 1216091 1216377 1216410 1216419 1216576 1216664 1216862 1217212 1217215 1217573 1217574 CVE-2022-1996 CVE-2022-40897 CVE-2023-2137 CVE-2023-22745 CVE-2023-38470 CVE-2023-38473 CVE-2023-4039 CVE-2023-45803 CVE-2023-46218 CVE-2023-46219 ----------------------------------------------------------------- The container sles-15-sp5-chost-byos-v20231213-arm64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:526-1 Released: Mon Feb 27 13:52:39 2023 Summary: Security update for tpm2-0-tss Type: security Severity: moderate References: 1207325,CVE-2023-22745 This update for tpm2-0-tss fixes the following issues: - CVE-2023-22745: Fixed a memory safety issue that could be exploited by local attackers with TPM access (bsc#1207325). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4450-1 Released: Wed Nov 15 10:55:20 2023 Summary: Recommended update for crypto-policies Type: recommended Severity: moderate References: 1209998 This update for crypto-policies fixes thefollowing issues: - Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands (jsc#PED-5041) - Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby and add a note for transactional systems - Ship the man pages for fips-mode-setup and fips-finish-install - Make the supported versions change in the update-crypto-policies(8) man page persistent (bsc#1209998) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) -Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the samebuild. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4460-1 Released: Thu Nov 16 15:00:20 2023 Summary: Recommended update for rsyslog Type: recommended Severity: moderate References: 1210286 This update for rsyslog fixes the following issue: - fix rsyslog crash in imrelp (bsc#1210286) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4467-1 Released: Thu Nov 16 17:57:51 2023 Summary: Security update for python-urllib3 Type: security Severity: moderate References: 1216377,CVE-2023-45803 This update for python-urllib3 fixes the following issues: - CVE-2023-45803: Fix a request body leak that could occur when receiving a 303 HTTP response (bsc#1216377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4503-1 Released: Tue Nov 21 13:25:12 2023 Summary: Security update for avahi Type: security Severity: moderate References: 1215947,1216419,CVE-2023-38470,CVE-2023-38473 This update for avahi fixes the following issues: - CVE-2023-38470: Ensure each label is at least one byte long (bsc#1215947). - CVE-2023-38473: Fixed a reachable assertion when parsing a host name (bsc#1216419). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4517-1 Released: Tue Nov 21 17:30:27 2023 Summary: Security update for python3-setuptools Type: security Severity: moderate References: 1206667,CVE-2022-40897 This update for python3-setuptools fixes the following issues: - CVE-2022-40897: Fixed Regular Expression Denial of Service (ReDoS) in package_index.py (bsc#1206667). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4534-1 Released: Thu Nov 23 08:13:57 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1041742,1203760,1212422,1215979,1216091 This update for libzypp, zypperfixes the following issues: - Preliminary disable 'rpm --runposttrans' usage for chrooted systems (bsc#1216091) - Fix comment typo on zypp.conf (bsc#1215979) - Attempt to delay %transfiletrigger(postun|in) execution if rpm supports it (bsc#1041742) - Make sure the old target is deleted before a new one is created (bsc#1203760) - Return 104 also if info suggests near matches - Rephrase upgrade message for openSUSE Tumbleweed (bsc#1212422) - commit: Insert a headline to separate output of different rpm scripts (bsc#1041742) ----------------------------------------------------------------- Advisory ID: SUSE-feature-2023:4583-1 Released: Mon Nov 27 10:16:11 2023 Summary: Feature update for python-psutil Type: feature Severity: moderate References: 1111622,1170175,1176785,1184753,1199282 This update for python-psutil, python-requests fixes the following issues: - update python-psutil to 5.9.1 (bsc#1199282, bsc#1184753, jsc#SLE-24629, jsc#PM-3243, gh#giampaolo/psutil#2043) - Fix tests: setuptools changed the builddir library path and does not find the module from it. Use the installed platlib instead and exclude psutil.tests only later. - remove the dependency on net-tools, since it conflicts with busybox-hostnmame which is default on MicroOS - Update python-requests to 2.25.1 (bsc#1176785, bsc#1170175, jsc#ECO-3105, jsc#PM-2352, jsc#PED-7192) - Fixed bug with unintended Authorization header stripping for redirects using default ports (bsc#1111622). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4610-1 Released: Wed Nov 29 14:04:12 2023 Summary: Recommended update for google-guest-configs Type: recommended Severity: moderate References: 1212418,1212759,1214546,1214572 This update for google-guest-configs fixes the following issues: - Update to version 20230808.00 (bsc#1214546, bsc#1214572, bsc#1212418, bsc#1212759) - Replace xxd with dd for google_nvme_id - Setup irq binding for a3 8g vm - dracut: Add a new dracut module for gcpudev rules - src/lib/udev: only create symlinks for GCP devices - Set hostname: consider fully qualified static hostname - Support multiple local SSD controllers - Update OWNERS file - DHCP hostname: don't reset hostname if the hostname hasn't changed ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4619-1 Released: Thu Nov 30 10:13:52 2023 Summary: Security update for sqlite3 Type: security Severity: important References: 1210660,CVE-2023-2137 This update for sqlite3 fixes the following issues: - CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4620-1 Released: Thu Nov 30 11:13:43 2023 Summary: Recommended update for libhugetlbfs Type: recommended Severity: moderate References: 1213639,1216576 This update for libhugetlbfs fixes the following issue: - Add patch for upstream issue (bsc#1216576, bsc#1213639) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4659-1 Released: Wed Dec 6 13:04:57 2023 Summary: Security update for curl Type: security Severity: moderate References: 1217573,1217574,CVE-2023-46218,CVE-2023-46219 This update for curl fixes the following issues: - CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573). - CVE-2023-46219: HSTS long file name clears contents (bsc#1217574). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4671-1 Released: Wed Dec 6 14:33:41 2023 Summary: Recommended update for man Type: recommended Severity: moderate References: This update of man fixes the following problem: - The 'man' commands is delivered to SUSE Linux Enterprise Micro to allow browsing man pages. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4672-1 Released: Wed Dec 6 14:37:37 2023 Summary: Security update for suse-build-key Type: security Severity: important References: 1216410,1217215 This update for suse-build-key fixes the following issues: This update runs a import-suse-build-key script. The previous libzypp-post-script based installation is replaced with a systemd timer and service (bsc#1217215 bsc#1216410 jsc#PED-2777). - suse-build-key-import.service - suse-build-key-import.timer It imports the future SUSE Linux Enterprise 15 4096 bit RSA key primary and reserve keys. After successful import the timer is disabled. To manually import them you can also run: # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-3fa1d6ce-63c9481c.asc # rpm --import /usr/lib/rpm/gnupg/keys/gpg-pubkey-d588dc46-63c939db.asc ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4699-1 Released: Mon Dec 11 07:02:10 2023 Summary: Recommended update for gpg2 Type: recommended Severity: moderate References: 1217212 This update for gpg2 fixes the following issues: - `dirmngr-client --validate` is broken for DER-encoded files (bsc#1217212) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4723-1 Released: Tue Dec 12 09:57:51 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1216862 This update for libtirpc fixes the following issue: - fix sed parsing in specfile (bsc#1216862) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4727-1 Released: Tue Dec 12 12:27:39 2023 Summary: Security update for catatonit, containerd, runc Type: security Severity: important References: 1200528,CVE-2022-1996 This update of runc and containerd fixes the following issues: containerd: - Update to containerd v1.7.8. Upstream release notes: https://github.com/containerd/containerd/releases/tag/v1.7.8 * CVE-2022-1996: Fixed CORS bypass in go-restful (bsc#1200528) catatonit: - Update to catatonit v0.2.0. * Change license toGPL-2.0-or-later. - Update to catatont v0.1.7 * This release adds the ability for catatonit to be used as the only process in a pause container, by passing the -P flag (in this mode no subprocess is spawned and thus no signal forwarding is done). - Update to catatonit v0.1.6, which fixes a few bugs -- mainly ones related to socket activation or features somewhat adjacent to socket activation (such as passing file descriptors). runc: - Update to runc v1.1.10. Upstream changelog is available from https://github.com/opencontainers/runc/releases/tag/v1.1.10 The following package changes have been done: - containerd-ctr-1.7.8-150000.103.1 updated - containerd-1.7.8-150000.103.1 updated - crypto-policies-20210917.c9d86d1-150400.3.6.1 updated - curl-8.0.1-150400.5.36.1 updated - dracut-055+suse.375.g1167ed75-150500.3.15.1 updated - google-guest-configs-20230808.00-150400.13.6.1 updated - gpg2-2.2.27-150300.3.8.1 updated - grub2-i386-pc-2.06-150500.29.11.1 updated - grub2-x86_64-efi-2.06-150500.29.11.1 updated - grub2-2.06-150500.29.11.1 updated - kernel-default-5.14.21-150500.55.39.1 updated - libavahi-client3-0.8-150400.7.10.1 updated - libavahi-common3-0.8-150400.7.10.1 updated - libcurl4-8.0.1-150400.5.36.1 updated - libdevmapper1_03-2.03.22_1.02.196-150500.7.9.1 updated - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libhugetlbfs-2.20-150000.3.8.1 updated - libopeniscsiusr0-0.2.0-150500.46.3.1 updated - libopenssl1_1-1.1.1l-150500.17.22.1 updated - libp11-kit0-0.23.22-150500.8.3.1 updated - libsqlite3-0-3.44.0-150000.3.23.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.23.1 updated - libtirpc3-1.3.4-150300.3.23.1 updated - libtss2-esys0-3.1.0-150400.3.3.1 added - libtss2-fapi1-3.1.0-150400.3.3.1 added - libtss2-mu0-3.1.0-150400.3.3.1 added - libtss2-rc0-3.1.0-150400.3.3.1 added - libtss2-sys1-3.1.0-150400.3.3.1 added - libtss2-tctildr0-3.1.0-150400.3.3.1 added - libxml2-2-2.10.3-150500.5.11.1 updated - libzypp-17.31.22-150400.3.43.1 updated -nvme-cli-2.4+31.gf7ec09-150500.4.12.1 updated - open-iscsi-2.1.9-150500.46.3.1 updated - openssl-1_1-1.1.1l-150500.17.22.1 updated - p11-kit-tools-0.23.22-150500.8.3.1 updated - p11-kit-0.23.22-150500.8.3.1 updated - python3-requests-2.25.1-150300.3.6.1 updated - python3-setuptools-44.1.1-150400.9.6.1 updated - python3-urllib3-1.25.10-150300.4.9.1 updated - rsyslog-module-relp-8.2306.0-150400.5.21.1 updated - rsyslog-8.2306.0-150400.5.21.1 updated - runc-1.1.10-150000.55.1 updated - samba-client-libs-4.17.12+git.427.2619dc0bed-150500.3.14.1 updated - suse-build-key-12.0-150000.8.37.1 updated - suseconnect-ng-1.4.0~git0.b0f7c25bfdfa-150500.3.6.1 updated - system-group-hardware-20170617-150400.24.2.1 updated - system-group-kvm-20170617-150400.24.2.1 updated - system-group-wheel-20170617-150400.24.2.1 updated - system-user-nobody-20170617-150400.24.2.1 updated - tpm2.0-tools-5.2-150400.4.6 added - vim-data-common-9.0.2103-150500.20.6.1 updated - vim-9.0.2103-150500.20.6.1 updated - xen-libs-4.17.2_08-150500.3.15.1 updated - zypper-1.14.66-150400.3.35.1 updated . Recent SUSE security enhancements and advised updates addressing diverse packages and significant vulnerabilities.. SUSE Security Update,SUSE Advisory,SUSE Packages,Recommended Patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 15, 2023 Important SuSE
100

SUSE: 2023:4480-1 Important: gcc13 Security Fix Overview

* bsc#1206480 * bsc#1206684 * bsc#1210557 * bsc#1211427 * bsc#1212101 . # Security update for gcc13 Announcement ID: SUSE-SU-2023:4480-1 Rating: important References: * bsc#1206480 * bsc#1206684 * bsc#1210557 * bsc#1211427 * bsc#1212101 * bsc#1213915 * bsc#1214052 * bsc#1214460 * bsc#1215427 * bsc#1216664 * jsc#PED-153 * jsc#PED-2005 * jsc#PED-252 * jsc#PED-253 * jsc#PED-6584 Cross-References: * CVE-2023-4039 CVSS scores: * CVE-2023-4039 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-4039 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * Toolchain Module 12 An update that solves one vulnerability, contains five features and has nine security fixes can now be installed. ## Description: This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the "Development Tools" module. The Go, D, Ada and Modula 2 language compiler partsare available unsupported via the PackageHub repositories. To use gcc13 compilers use: * install "gcc13" or "gcc13-c++" or one of the other "gcc13-COMPILER" frontend packages. * override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) * Work around third party app crash during C++ standard library initialization. [bsc#1216664] * Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) * Bump included newlib to version 4.3.0. * Update to GCC trunk head (r13-5254-g05b9868b182bb9) * Redo floatn fixinclude pick-up to simply keep what is there. * Turn cross compiler to s390x to a glibc cross. [bsc#1214460] * Also handle -static-pie in the default-PIE specs * Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] * Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] * Add new x86-related intrinsics (amxcomplexintrin.h). * RISC-V: Add support for inlining subword atomic operations * Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. * Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. * Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. * Bump included newlib to version 4.3.0. * Also package libhwasan_preinit.o on aarch64. * Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. * Package libhwasan_preinit.o on x86_64. * Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] * Enable PRU flavour for gcc13 * update floatn fixinclude pickup to check each header separately (bsc#1206480) * Redo floatn fixinclude pick-up to simply keep what is there. * Bump libgo SONAME to libgo22. * Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. * Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. * Depend on at least LLVM 13 for GCN cross compiler. * Update embedded newlib to version 4.2.0 * Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Toolchain Module 12 zypper in -t patch SUSE-SLE-Module-Toolchain-12-2023-4480=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4480=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4480=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4480=1 ## Package List: * Toolchain Module 12 (aarch64 ppc64le s390x x86_64) * gcc13-PIE-13.2.1+git7813-1.10.1 * gcc13-locale-13.2.1+git7813-1.10.1 * gcc13-13.2.1+git7813-1.10.1 * gcc13-fortran-13.2.1+git7813-1.10.1 * gcc13-debuginfo-13.2.1+git7813-1.10.1 * gcc13-c++-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-devel-gcc13-13.2.1+git7813-1.10.1 * cpp13-debuginfo-13.2.1+git7813-1.10.1 * gcc13-fortran-debuginfo-13.2.1+git7813-1.10.1 * gcc13-c++-13.2.1+git7813-1.10.1 * gcc13-debugsource-13.2.1+git7813-1.10.1 * cpp13-13.2.1+git7813-1.10.1 * Toolchain Module 12 (noarch) *gcc13-info-13.2.1+git7813-1.10.1 * Toolchain Module 12 (s390x x86_64) * gcc13-c++-32bit-13.2.1+git7813-1.10.1 * gcc13-32bit-13.2.1+git7813-1.10.1 * gcc13-fortran-32bit-13.2.1+git7813-1.10.1 * libstdc++6-devel-gcc13-32bit-13.2.1+git7813-1.10.1 * Toolchain Module 12 (x86_64) * cross-nvptx-newlib13-devel-13.2.1+git7813-1.10.1 * cross-nvptx-gcc13-13.2.1+git7813-1.10.1 * cross-nvptx-gcc13-debugsource-13.2.1+git7813-1.10.1 * cross-nvptx-gcc13-debuginfo-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libstdc++6-pp-13.2.1+git7813-1.10.1 * libatomic1-debuginfo-13.2.1+git7813-1.10.1 * libitm1-debuginfo-13.2.1+git7813-1.10.1 * libgfortran5-13.2.1+git7813-1.10.1 * libobjc4-13.2.1+git7813-1.10.1 * liblsan0-debuginfo-13.2.1+git7813-1.10.1 * libtsan2-13.2.1+git7813-1.10.1 * libasan8-13.2.1+git7813-1.10.1 * liblsan0-13.2.1+git7813-1.10.1 * libhwasan0-debuginfo-13.2.1+git7813-1.10.1 * libobjc4-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-13.2.1+git7813-1.10.1 * libasan8-debuginfo-13.2.1+git7813-1.10.1 * libitm1-13.2.1+git7813-1.10.1 * libgomp1-debuginfo-13.2.1+git7813-1.10.1 * libgomp1-13.2.1+git7813-1.10.1 * libatomic1-13.2.1+git7813-1.10.1 * libhwasan0-13.2.1+git7813-1.10.1 * libgfortran5-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-13.2.1+git7813-1.10.1 * libgcc_s1-13.2.1+git7813-1.10.1 * libgcc_s1-debuginfo-13.2.1+git7813-1.10.1 * libtsan2-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-locale-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libgfortran5-32bit-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-32bit-13.2.1+git7813-1.10.1 * libgomp1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libasan8-32bit-debuginfo-13.2.1+git7813-1.10.1 * libquadmath0-13.2.1+git7813-1.10.1 * libquadmath0-32bit-13.2.1+git7813-1.10.1 * libasan8-32bit-13.2.1+git7813-1.10.1 * libatomic1-32bit-debuginfo-13.2.1+git7813-1.10.1 *libitm1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libitm1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-32bit-debuginfo-13.2.1+git7813-1.10.1 * libatomic1-32bit-13.2.1+git7813-1.10.1 * libobjc4-32bit-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libobjc4-32bit-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-pp-32bit-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-13.2.1+git7813-1.10.1 * libquadmath0-32bit-debuginfo-13.2.1+git7813-1.10.1 * libgfortran5-32bit-13.2.1+git7813-1.10.1 * libgomp1-32bit-13.2.1+git7813-1.10.1 * libquadmath0-debuginfo-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libstdc++6-pp-13.2.1+git7813-1.10.1 * libatomic1-debuginfo-13.2.1+git7813-1.10.1 * libitm1-debuginfo-13.2.1+git7813-1.10.1 * libgfortran5-13.2.1+git7813-1.10.1 * libobjc4-13.2.1+git7813-1.10.1 * liblsan0-debuginfo-13.2.1+git7813-1.10.1 * libtsan2-13.2.1+git7813-1.10.1 * libasan8-13.2.1+git7813-1.10.1 * liblsan0-13.2.1+git7813-1.10.1 * libobjc4-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-13.2.1+git7813-1.10.1 * libasan8-debuginfo-13.2.1+git7813-1.10.1 * libitm1-13.2.1+git7813-1.10.1 * libgomp1-debuginfo-13.2.1+git7813-1.10.1 * libgomp1-13.2.1+git7813-1.10.1 * libatomic1-13.2.1+git7813-1.10.1 * libgfortran5-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-13.2.1+git7813-1.10.1 * libgcc_s1-13.2.1+git7813-1.10.1 * libgcc_s1-debuginfo-13.2.1+git7813-1.10.1 * libtsan2-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-locale-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 x86_64) * libhwasan0-debuginfo-13.2.1+git7813-1.10.1 * libhwasan0-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server 12 SP5 (ppc64le x86_64) * libquadmath0-13.2.1+git7813-1.10.1 * libquadmath0-debuginfo-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libatomic1-32bit-13.2.1+git7813-1.10.1 * libgfortran5-32bit-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-32bit-13.2.1+git7813-1.10.1 * libasan8-32bit-13.2.1+git7813-1.10.1 * libgfortran5-32bit-13.2.1+git7813-1.10.1 * libitm1-32bit-13.2.1+git7813-1.10.1 * libgomp1-32bit-13.2.1+git7813-1.10.1 * libatomic1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libgomp1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libitm1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libobjc4-32bit-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libobjc4-32bit-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-pp-32bit-13.2.1+git7813-1.10.1 * libubsan1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libasan8-32bit-debuginfo-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-32bit-debuginfo-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server 12 SP5 (x86_64) * libquadmath0-32bit-debuginfo-13.2.1+git7813-1.10.1 * libquadmath0-32bit-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libstdc++6-pp-13.2.1+git7813-1.10.1 * libatomic1-debuginfo-13.2.1+git7813-1.10.1 * libitm1-debuginfo-13.2.1+git7813-1.10.1 * libgfortran5-13.2.1+git7813-1.10.1 * libobjc4-13.2.1+git7813-1.10.1 * liblsan0-debuginfo-13.2.1+git7813-1.10.1 * libquadmath0-13.2.1+git7813-1.10.1 * libtsan2-13.2.1+git7813-1.10.1 * libasan8-13.2.1+git7813-1.10.1 * liblsan0-13.2.1+git7813-1.10.1 * libobjc4-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-13.2.1+git7813-1.10.1 * libasan8-debuginfo-13.2.1+git7813-1.10.1 * libitm1-13.2.1+git7813-1.10.1 * libgomp1-debuginfo-13.2.1+git7813-1.10.1 * libgomp1-13.2.1+git7813-1.10.1 * libatomic1-13.2.1+git7813-1.10.1 * libgfortran5-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-13.2.1+git7813-1.10.1 * libgcc_s1-13.2.1+git7813-1.10.1 * libgcc_s1-debuginfo-13.2.1+git7813-1.10.1 * libquadmath0-debuginfo-13.2.1+git7813-1.10.1 *libstdc++6-debuginfo-13.2.1+git7813-1.10.1 * libtsan2-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-locale-13.2.1+git7813-1.10.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libgfortran5-32bit-debuginfo-13.2.1+git7813-1.10.1 * libstdc++6-32bit-13.2.1+git7813-1.10.1 * libgomp1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libasan8-32bit-debuginfo-13.2.1+git7813-1.10.1 * libquadmath0-32bit-13.2.1+git7813-1.10.1 * libasan8-32bit-13.2.1+git7813-1.10.1 * libatomic1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libitm1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libhwasan0-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libitm1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-32bit-debuginfo-13.2.1+git7813-1.10.1 * libatomic1-32bit-13.2.1+git7813-1.10.1 * libobjc4-32bit-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-debuginfo-13.2.1+git7813-1.10.1 * libobjc4-32bit-debuginfo-13.2.1+git7813-1.10.1 * libubsan1-32bit-13.2.1+git7813-1.10.1 * libstdc++6-pp-32bit-13.2.1+git7813-1.10.1 * libgcc_s1-32bit-13.2.1+git7813-1.10.1 * libquadmath0-32bit-debuginfo-13.2.1+git7813-1.10.1 * libgfortran5-32bit-13.2.1+git7813-1.10.1 * libgomp1-32bit-13.2.1+git7813-1.10.1 * libhwasan0-13.2.1+git7813-1.10.1 ## References: * https://www.suse.com/security/cve/CVE-2023-4039.html * https://bugzilla.suse.com/show_bug.cgi?id=1206480 * https://bugzilla.suse.com/show_bug.cgi?id=1206684 * https://bugzilla.suse.com/show_bug.cgi?id=1210557 * https://bugzilla.suse.com/show_bug.cgi?id=1211427 * https://bugzilla.suse.com/show_bug.cgi?id=1212101 * https://bugzilla.suse.com/show_bug.cgi?id=1213915 * https://bugzilla.suse.com/show_bug.cgi?id=1214052 * https://bugzilla.suse.com/show_bug.cgi?id=1214460 * https://bugzilla.suse.com/show_bug.cgi?id=1215427 * https://bugzilla.suse.com/show_bug.cgi?id=1216664 * * * * * . An essential patch for gcc13 introduces multiple improvements and corrections for SUSE platforms addressing numerous issues.. GCC Security Update, SUSE Patch Instructions,Compile Optimization, GCC Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 20, 2023 Important SuSE
100

SUSE: 2023:3774-1 Important: Security Fixes for SUSE/SLE15

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3774-1 Container Tags : suse/sle15:15.1 , suse/sle15:15.1.6.2.843 Container Release : 6.2.843 Severity : important Type : security References : 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216129 1216664 CVE-2023-4039 CVE-2023-45322 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) -Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlibto version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4464-1 Released: Thu Nov 16 17:56:12 2023 Summary: Security update for libxml2 Type: security Severity: moderate References: 1216129,CVE-2023-45322 This update for libxml2 fixes the following issues: - CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129). The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - libxml2-2-2.9.7-150000.3.63.1 updated . SUSE Container Patch Notice for suse/sle15 encompasses essential security enhancements and updates addressing significant vulnerabilities.. SUSE Container, Security Update, SUSE Linux, Patch Management, Software Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 19, 2023 Important SuSE
100

SUSE: 2023:3773-1 Important Security Update for Toolbox Containers

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.2/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3773-1 Container Tags : suse/sle-micro/5.2/toolbox:12.1 , suse/sle-micro/5.2/toolbox:12.1-6.2.315 , suse/sle-micro/5.2/toolbox:latest Container Release : 6.2.315 Severity : important Type : security References : 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216129 1216664 CVE-2023-4039 CVE-2023-45322 ----------------------------------------------------------------- The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: *CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guardto work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4464-1 Released: Thu Nov 16 17:56:12 2023 Summary: Security update for libxml2 Type: security Severity: moderate References: 1216129,CVE-2023-45322 This update for libxml2 fixes the following issues: - CVE-2023-45322: Fixed a use-after-free in xmlUnlinkNode() in tree.c (bsc#1216129). The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - libxml2-2-2.9.7-150000.3.63.1 updated - container:sles15-image-15.0.0-17.20.212 updated . SUSE Docker Image Advisory for toolkit featuring substantial enhancements and critical security corrections executed proficiently.. SUSE Toolbox Update, Container Security, Importance of Updates, SUSE Patch Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 18, 2023 Important SuSE
100

SUSE SLE Micro 5.3 Toolbox Security Update SUSE-CU-2023:3762-1 Important

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3762-1 Container Tags : suse/sle-micro/5.3/toolbox:12.1 , suse/sle-micro/5.3/toolbox:12.1-5.2.255 , suse/sle-micro/5.3/toolbox:latest Container Release : 5.2.255 Severity : important Type : security References : 1206480 1206684 1209998 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216664 CVE-2023-4039 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4450-1 Released: Wed Nov 15 10:55:20 2023 Summary: Recommended update for crypto-policies Type: recommended Severity: moderate References: 1209998 This update for crypto-policies fixes the following issues: - Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands (jsc#PED-5041) - Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby and add a note for transactional systems - Ship the man pages for fips-mode-setup and fips-finish-install - Make the supported versions change in the update-crypto-policies(8) man page persistent (bsc#1209998) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its baselibraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib toversion 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - crypto-policies-20210917.c9d86d1-150400.3.6.1 updated - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - container:sles15-image-15.0.0-27.14.118 updated . SUSE container enhancement for toolbox resolving crucial security vulnerabilities and updates, encompassing gcc and encryption regulations.. SUSE Update, Security Update, Toolbox Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 18, 2023 Important SuSE
100

SUSE: 2023:3728-1 Important Security Update for suse/sle15 Container

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3728-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.118 , suse/sle15:15.4 , suse/sle15:15.4.27.14.118 Container Release : 27.14.118 Severity : important Type : security References : 1206480 1206684 1209998 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216664 CVE-2023-4039 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4450-1 Released: Wed Nov 15 10:55:20 2023 Summary: Recommended update for crypto-policies Type: recommended Severity: moderate References: 1209998 This update for crypto-policies fixes the following issues: - Enable setting the kernel FIPS mode with the fips-mode-setup and fips-finish-install commands (jsc#PED-5041) - Adapt fips-mode-setup to use the pbl command from the perl-Bootloader package instead of grubby and add a note for transactional systems - Ship the man pages for fips-mode-setup and fips-finish-install - Make the supported versions change in the update-crypto-policies(8) man page persistent (bsc#1209998) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSELinux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. -Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - crypto-policies-20210917.c9d86d1-150400.3.6.1 updated - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated . SUSE enhances the suse/sle15 container by integrating essential security and functional updates in accordance with their latest advisory.. SUSE, Container Update, Security Advisory, Crypto Policies, GCC Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 17, 2023 Important SuSE
100

SUSE: 2023:3723-1 Important Security Update for bci/minimal Container

The container bci/bci-minimal was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3723-1 Container Tags : bci/bci-minimal:15.4 , bci/bci-minimal:15.4.24.13 Container Release : 24.13 Severity : important Type : security References : 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 1215427 1216664 CVE-2023-4039 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4458-1 Released: Thu Nov 16 14:38:48 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,1215427,1216664,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc-13, CXX=g++-13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) -Work around third party app crash during C++ standard library initialization. [bsc#1216664] - Fixed that GCC13 fails to compile some packages with error: unrecognizable insn (bsc#1215427) - Bump included newlib to version 4.3.0. - Update to GCC trunk head (r13-5254-g05b9868b182bb9) - Redo floatn fixinclude pick-up to simply keep what is there. - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allowcross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. We need to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.6.1 updated - libstdc++6-13.2.1+git7813-150000.1.6.1 updated - container:micro-image-15.4.0-23.4 updated . Keep up-to-date with the current SUSE container security patches tackling significant concerns with bci/minimal.. gcc update,bci/minimal update,security patches,SUSE container advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 17, 2023 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200