This update for libyajl fixes the following issues: CVE-2023-33460: Fixed memory leak which could cause out-of-memory in server (bsc#1212928).. # Security update for libyajl Announcement ID: SUSE-SU-2023:3301-1 Rating: moderate References: * #1212928 Cross-References: * CVE-2023-33460 CVSS scores: * CVE-2023-33460 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-33460 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for libyajl fixes the following issues: * CVE-2023-33460: Fixed memory leak which could cause out-of-memory in server (bsc#1212928). ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaSTonline_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3301=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3301=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3301=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3301=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3301=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3301=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3301=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3301=1 * SUSE Linux Enterprise Real Time 15 SP3 zypper in -t patch SUSE-SLE-Product-RT-15-SP3-2023-3301=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3301=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3301=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3301=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-3301=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3301=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3301=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) *libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * yajl-debuginfo-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * yajl-2.1.0-150000.4.6.1 * libyajl-devel-static-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.4 (x86_64) * libyajl-devel-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * yajl-debuginfo-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * yajl-2.1.0-150000.4.6.1 * libyajl-devel-static-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * openSUSE Leap 15.5 (x86_64) * libyajl-devel-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-2.1.0-150000.4.6.1 * libyajl2-32bit-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Real Time 15 SP3 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Proxy 4.2 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl-devel-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libyajl2-2.1.0-150000.4.6.1 * libyajl-debugsource-2.1.0-150000.4.6.1 * libyajl2-debuginfo-2.1.0-150000.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-33460.html * https://bugzilla.suse.com/show_bug.cgi?id=1212928 . An important update regarding libyajl details a significant memory leak flaw that impacts several openSUSE offerings.. libyajl Update, openSUSE Security Advisory, memory leak fixes. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libyajl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3162-1 Rating: moderate References: #1198405 Cross-References: CVE-2022-24795 CVSS scores: CVE-2022-24795 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-24795 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Micro 5.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 openSUSE Leap Micro 5.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libyajl fixes the following issues: - CVE-2022-24795: Fixed heap-based bufferoverflow when handling large inputs (bsc#1198405). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap Micro 5.2: zypper in -t patch openSUSE-Leap-Micro-5.2-2022-3162=1 - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3162=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3162=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-3162=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-3162=1 - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2022-3162=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-3162=1 Package List: - openSUSE Leap Micro 5.2 (aarch64 x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl-devel-2.1.0-150000.4.3.1 libyajl-devel-static-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 yajl-2.1.0-150000.4.3.1 yajl-debuginfo-2.1.0-150000.4.3.1 - openSUSE Leap 15.4 (x86_64): libyajl-devel-32bit-2.1.0-150000.4.3.1 libyajl2-32bit-2.1.0-150000.4.3.1 libyajl2-32bit-debuginfo-2.1.0-150000.4.3.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl-devel-2.1.0-150000.4.3.1 libyajl-devel-static-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 yajl-2.1.0-150000.4.3.1 yajl-debuginfo-2.1.0-150000.4.3.1 - openSUSE Leap15.3 (x86_64): libyajl-devel-32bit-2.1.0-150000.4.3.1 libyajl2-32bit-2.1.0-150000.4.3.1 libyajl2-32bit-debuginfo-2.1.0-150000.4.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl-devel-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl-devel-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 - SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 - SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64): libyajl-debugsource-2.1.0-150000.4.3.1 libyajl2-2.1.0-150000.4.3.1 libyajl2-debuginfo-2.1.0-150000.4.3.1 References: https://www.suse.com/security/cve/CVE-2022-24795.html https://bugzilla.suse.com/1198405 . SUSE Security Patch for libyajl resolves a moderate heap overflow vulnerability linked to the management of extensive inputs.. SUSE Linux Update, Buffer Overflow, Security Patch, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libyajl ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1746-1 Rating: moderate References: #1198405 Cross-References: CVE-2022-24795 CVSS scores: CVE-2022-24795 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-24795 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libyajl fixes the following issue: - CVE-2022-24795: Fixed a heap-based buffer overflow when handling large inputs due to an integer overflow (bsc#1198405) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-1746=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-1746=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.0.1-18.7.1 libyajl-devel-2.0.1-18.7.1 libyajl-devel-static-2.0.1-18.7.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libyajl-debugsource-2.0.1-18.7.1 libyajl2-2.0.1-18.7.1 libyajl2-debuginfo-2.0.1-18.7.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libyajl2-32bit-2.0.1-18.7.1 libyajl2-debuginfo-32bit-2.0.1-18.7.1 References: https://www.suse.com/security/cve/CVE-2022-24795.html https://bugzilla.suse.com/1198405 . SUSE Security Advisory for libxml2. Tackles memory leak: SUSE-SU-2022:1804-2, serious vulnerability resolved.. SUSE Linux, libyajl update, buffer overflow fix, security update, vulnerability patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.