An update that solves one vulnerability can now be installed.. # gsl-2.8-5.1 on GA media Announcement ID: openSUSE-SU-2026:10449-1 Rating: moderate Cross-References: * CVE-2024-50610 CVSS scores: * CVE-2024-50610 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2024-50610 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the gsl-2.8-5.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * gsl 2.8-5.1 * gsl-devel 2.8-5.1 * gsl-doc 2.8-5.1 * gsl-examples 2.8-5.1 * libgsl28 2.8-5.1 * libgslcblas0 2.8-5.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50610.html . Update for openSUSE addresses moderate risk CVE-2024-50610 in gsl 2.8-5.1 package to enhance system security.. openSUSE Tumbleweed security, gsl package update, CVE-2024-50610, moderate risk advisory, Linux security patch. . LinuxSecurity.com Team
GNU Scientific Library could be made to crash or execute arbitrary code if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6472-1 November 07, 2023 gsl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: GNU Scientific Library could be made to crash or execute arbitrary code if it received specially crafted input. Software Description: - gsl: A modern numerical library for C and C++ programmers Details: It was discovered that GNU Scientific Library incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: gsl-bin 2.7.1+dfsg-3ubuntu0.23.04.1 libgsl-dev 2.7.1+dfsg-3ubuntu0.23.04.1 libgsl27 2.7.1+dfsg-3ubuntu0.23.04.1 libgslcblas0 2.7.1+dfsg-3ubuntu0.23.04.1 Ubuntu 22.04 LTS (Available with Ubuntu Pro): gsl-bin 2.7.1+dfsg-3ubuntu0.22.04.1~esm1 libgsl-dev 2.7.1+dfsg-3ubuntu0.22.04.1~esm1 libgsl27 2.7.1+dfsg-3ubuntu0.22.04.1~esm1 libgslcblas0 2.7.1+dfsg-3ubuntu0.22.04.1~esm1 Ubuntu 20.04 LTS: gsl-bin 2.5+dfsg-6+deb10u1build0.20.04.1 libgsl-dev 2.5+dfsg-6+deb10u1build0.20.04.1 libgsl23 2.5+dfsg-6+deb10u1build0.20.04.1 libgslcblas0 2.5+dfsg-6+deb10u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): gsl-bin 2.4+dfsg-6ubuntu0.1~esm1 libgsl-dev 2.4+dfsg-6ubuntu0.1~esm1 libgsl23 2.4+dfsg-6ubuntu0.1~esm1 libgslcblas0 2.4+dfsg-6ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): gsl-bin 2.1+dfsg-2ubuntu0.1~esm1 libgsl-dev 2.1+dfsg-2ubuntu0.1~esm1 libgsl2 2.1+dfsg-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6472-1 CVE-2020-35357 Package Information: https://launchpad.net/ubuntu/+source/gsl/2.7.1+dfsg-3ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/gsl/2.5+dfsg-6+deb10u1build0.20.04.1 . The recent GSL vulnerability poses a risk to Ubuntu LTS platforms, possibly enabling malicious actors to run arbitrary code or trigger system failures.. GNU Scientific Library Update, Ubuntu Code Execution Threat, GSL Security Advisory. . Severity: Critical. LinuxSecurity.com Team
* #1214681 Cross-References: * CVE-2020-35357 . # Security update for gsl Announcement ID: SUSE-SU-2023:4051-1 Rating: moderate References: * #1214681 Cross-References: * CVE-2020-35357 CVSS scores: * CVE-2020-35357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-35357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gsl fixes the following issues: * CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-4051=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2023-4051=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * gsl-debuginfo-1.16-5.4.1 * gsl-debugsource-1.16-5.4.1 * gsl-devel-1.16-5.4.1 * gsl-1.16-5.4.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * gsl-debuginfo-1.16-5.4.1 * gsl-debugsource-1.16-5.4.1 * gsl-1.16-5.4.1 ## References: * https://www.suse.com/security/cve/CVE-2020-35357.html * https://bugzilla.suse.com/show_bug.cgi?id=1214681 . Patch release for gsl addresses buffer overflow vulnerability classified as moderate. Apply updates using YaST or with zypper update.. SUSE Linux,gsl security,patchinstructions,CVE update. . Severity: Important. LinuxSecurity.com Team
This update for gsl fixes the following issues: CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681). # Security update for gsl Announcement ID: SUSE-SU-2023:3858-1 Rating: moderate References: * #1214681 Cross-References: * CVE-2020-35357 CVSS scores: * CVE-2020-35357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-35357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP4 * Desktop Applications Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gsl fixes the following issues: * CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3858=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3858=1 * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-3858=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-3858=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3858=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3858=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * gsl_2_6-gnu-hpc-doc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-debugsource-2.6-150200.3.4.3 * gsl-debuginfo-2.6-150200.3.4.3 * gsl-debugsource-2.6-150200.3.4.3 * libgsl-gnu-hpc-2.6-150200.3.4.3 * gsl-devel-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-devel-2.6-150200.3.4.3 * libgslcblas0-2.6-150200.3.4.3 * libgslcblas_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 * libgsl_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 * libgsl25-2.6-150200.3.4.3 * libgslcblas-gnu-hpc-2.6-150200.3.4.3 * libgsl25-debuginfo-2.6-150200.3.4.3 * gsl-2.6-150200.3.4.3 * libgslcblas_2_6-gnu-hpc-2.6-150200.3.4.3 * libgslcblas0-debuginfo-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 * libgsl_2_6-gnu-hpc-2.6-150200.3.4.3 * gsl-doc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-module-2.6-150200.3.4.3 * openSUSE Leap 15.4 (noarch) * gsl_2_6-gnu-hpc-examples-2.6-150200.3.4.3 * gsl-gnu-hpc-doc-2.6-150200.3.4.3 * gsl-examples-2.6-150200.3.4.3 * gsl-gnu-hpc-2.6-150200.3.4.3 * gsl-gnu-hpc-devel-2.6-150200.3.4.3 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * gsl_2_6-gnu-hpc-doc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-debugsource-2.6-150200.3.4.3 * gsl-debuginfo-2.6-150200.3.4.3 * gsl-debugsource-2.6-150200.3.4.3 * libgsl-gnu-hpc-2.6-150200.3.4.3 * gsl-devel-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-devel-2.6-150200.3.4.3 * libgslcblas0-2.6-150200.3.4.3 * libgslcblas_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 *libgsl_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 * libgsl25-2.6-150200.3.4.3 * libgslcblas-gnu-hpc-2.6-150200.3.4.3 * libgsl25-debuginfo-2.6-150200.3.4.3 * gsl-2.6-150200.3.4.3 * libgslcblas_2_6-gnu-hpc-2.6-150200.3.4.3 * libgslcblas0-debuginfo-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-debuginfo-2.6-150200.3.4.3 * libgsl_2_6-gnu-hpc-2.6-150200.3.4.3 * gsl-doc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-2.6-150200.3.4.3 * gsl_2_6-gnu-hpc-module-2.6-150200.3.4.3 * openSUSE Leap 15.5 (noarch) * gsl_2_6-gnu-hpc-examples-2.6-150200.3.4.3 * gsl-gnu-hpc-doc-2.6-150200.3.4.3 * gsl-examples-2.6-150200.3.4.3 * gsl-gnu-hpc-2.6-150200.3.4.3 * gsl-gnu-hpc-devel-2.6-150200.3.4.3 * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * gsl-devel-2.6-150200.3.4.3 * libgslcblas0-2.6-150200.3.4.3 * libgslcblas0-debuginfo-2.6-150200.3.4.3 * gsl-debuginfo-2.6-150200.3.4.3 * libgsl25-debuginfo-2.6-150200.3.4.3 * gsl-debugsource-2.6-150200.3.4.3 * libgsl25-2.6-150200.3.4.3 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * gsl-devel-2.6-150200.3.4.3 * libgslcblas0-2.6-150200.3.4.3 * libgslcblas0-debuginfo-2.6-150200.3.4.3 * gsl-debuginfo-2.6-150200.3.4.3 * libgsl25-debuginfo-2.6-150200.3.4.3 * gsl-debugsource-2.6-150200.3.4.3 * libgsl25-2.6-150200.3.4.3 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x) * libgslcblas0-2.6-150200.3.4.3 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x) * libgslcblas0-2.6-150200.3.4.3 ## References: * https://www.suse.com/security/cve/CVE-2020-35357.html * https://bugzilla.suse.com/show_bug.cgi?id=1214681 . Important patch for gsl resolved a buffer overflow vulnerability linked to CVE-2020-35357 in openSUSE systems. Find further details!. CVE Fix, openSUSE Update, gsl Security, Software Update, Stack Issue. . LinuxSecurity.com Team
A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library). Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3576-1
This update for gsl fixes the following issues: CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681). # Security update for gsl Announcement ID: SUSE-SU-2023:3527-1 Rating: moderate References: * #1214681 Cross-References: * CVE-2020-35357 CVSS scores: * CVE-2020-35357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-35357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Workstation Extension 15 SP4 * SUSE Linux Enterprise Workstation Extension 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gsl fixes the following issues: * CVE-2020-35357: Fixed a stack out of bounds read in gsl_stats_quantile_from_sorted_data(). (bsc#1214681) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-3527=1 * SUSE Linux Enterprise Workstation Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2023-3527=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3527=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3527=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP4 (x86_64) * libgsl23-debuginfo-2.4-150100.9.4.1 * gsl-debuginfo-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl-debugsource-2.4-150100.9.4.1 * SUSELinux Enterprise Workstation Extension 15 SP5 (x86_64) * libgsl23-debuginfo-2.4-150100.9.4.1 * gsl-debuginfo-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl-debugsource-2.4-150100.9.4.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * gsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-doc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-debugsource-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-devel-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl23-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl23-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * openSUSE Leap 15.4 (noarch) * gsl_2_4-gnu-hpc-examples-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-module-2.4-150100.9.4.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * gsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-doc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-debugsource-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-devel-2.4-150100.9.4.1 * libgslcblas_2_4-gnu-hpc-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-2.4-150100.9.4.1 * libgsl_2_4-gnu-hpc-debuginfo-2.4-150100.9.4.1 * openSUSE Leap 15.5 (noarch) * gsl_2_4-gnu-hpc-examples-2.4-150100.9.4.1 * gsl_2_4-gnu-hpc-module-2.4-150100.9.4.1 ## References: * https://www.suse.com/security/cve/CVE-2020-35357.html * https://bugzilla.suse.com/show_bug.cgi?id=1214681 . This patch resolves a vulnerability in GSL, correcting stack overflow incidents and improving overall system stability.. gsl security advisory, openSUSE update, stack overflow fix, system integrity update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.