Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22112 http://linux.oracle.com/errata/ELSA-2026-22112.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: delve-1.25.2-1.0.1.module+el8.10.0+90715+2d4d8dfd.x86_64.rpm golang-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.x86_64.rpm golang-bin-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.x86_64.rpm golang-docs-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-misc-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-race-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.x86_64.rpm golang-src-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-tests-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm go-toolset-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.x86_64.rpm aarch64: delve-1.25.2-1.0.1.module+el8.10.0+90715+2d4d8dfd.aarch64.rpm golang-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.aarch64.rpm golang-bin-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.aarch64.rpm golang-docs-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-misc-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-race-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.aarch64.rpm golang-src-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm golang-tests-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.noarch.rpm go-toolset-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/delve-1.25.2-1.0.1.module+el8.10.0+90715+2d4d8dfd.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/golang-1.25.9-1.0.1.module+el8.10.0+90898+1e3c34bb.src.rpm Related CVEs: CVE-2026-33811 CVE-2026-33814 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 Description of changes: delve golang [1.25.9-1.0.1] - EXPERIMENTAL: Introduce fipsnoenforceems GODEBUG var - Backported from OL9u7 - Resolves:OLDIS-53586 _______________________________________________ El-errata mailing list
An update that solves one vulnerability and has two security fixes can now be installed.. # Security update for openssh Announcement ID: SUSE-SU-2025:01638-1 Release Date: 2025-05-21T10:48:47Z Rating: moderate References: * bsc#1236826 * bsc#1239671 * bsc#1241012 Cross-References: * CVE-2025-32728 CVSS scores: * CVE-2025-32728 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N * CVE-2025-32728 ( SUSE ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-32728 ( NVD ): 4.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for openssh fixes the following issue: Security fixes: * CVE-2025-32728: Fixed logic error in DisableForwarding option (bsc#1241012) Other fixes: \- Fix ssh client segfault with GSSAPIKeyExchange=yes in ssh_kex2 due to gssapi proposal not being correctly initialized (bsc#1236826). The problem was introduced in the rebase of the patch for 9.6p1 \- Enable --with- logind to call the SetTTY dbus method in systemd. This allows "wall" to print messages in ssh ttys (bsc#1239671) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1638=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1638=1 openSUSE-SLE-15.6-2025-1638=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1638=1 ## PackageList: * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssh-askpass-gnome-9.6p1-150600.6.26.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.26.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.26.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * openssh-helpers-9.6p1-150600.6.26.1 * openssh-clients-9.6p1-150600.6.26.1 * openssh-helpers-debuginfo-9.6p1-150600.6.26.1 * openssh-cavs-9.6p1-150600.6.26.1 * openssh-debugsource-9.6p1-150600.6.26.1 * openssh-server-debuginfo-9.6p1-150600.6.26.1 * openssh-9.6p1-150600.6.26.1 * openssh-debuginfo-9.6p1-150600.6.26.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.26.1 * openssh-askpass-gnome-debugsource-9.6p1-150600.6.26.1 * openssh-fips-9.6p1-150600.6.26.1 * openssh-cavs-debuginfo-9.6p1-150600.6.26.1 * openssh-server-9.6p1-150600.6.26.1 * openssh-common-9.6p1-150600.6.26.1 * openssh-clients-debuginfo-9.6p1-150600.6.26.1 * openssh-askpass-gnome-9.6p1-150600.6.26.1 * openssh-common-debuginfo-9.6p1-150600.6.26.1 * openssh-askpass-gnome-debuginfo-9.6p1-150600.6.26.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * openssh-helpers-9.6p1-150600.6.26.1 * openssh-clients-9.6p1-150600.6.26.1 * openssh-helpers-debuginfo-9.6p1-150600.6.26.1 * openssh-debugsource-9.6p1-150600.6.26.1 * openssh-9.6p1-150600.6.26.1 * openssh-debuginfo-9.6p1-150600.6.26.1 * openssh-server-config-disallow-rootlogin-9.6p1-150600.6.26.1 * openssh-fips-9.6p1-150600.6.26.1 * openssh-server-9.6p1-150600.6.26.1 * openssh-common-9.6p1-150600.6.26.1 * openssh-clients-debuginfo-9.6p1-150600.6.26.1 * openssh-server-debuginfo-9.6p1-150600.6.26.1 * openssh-common-debuginfo-9.6p1-150600.6.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32728.html * https://bugzilla.suse.com/show_bug.cgi?id=1236826 * https://bugzilla.suse.com/show_bug.cgi?id=1239671 *https://bugzilla.suse.com/show_bug.cgi?id=1241012 . A security patch for OpenSSH tackles a moderately serious vulnerability, offering crucial repairs for SUSE systems.. openssh updates, SUSE Linux, security patches, threat mitigation, open source security. . LinuxSecurity.com Team
Backport fix for CVE-2024-6387 (rhbz#2294879). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-213f33544e 2024-07-02 18:06:45.897682 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 39 Version : 9.3p1 Release : 11.fc39 URL : https://www.openssh.org/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2024-6387 (rhbz#2294879) -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 1 2024 Daniel Milnes - 9.3p1-11 - Backport fix for CVE-2024-6387 (rhbz#2294879) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2294905 - CVE-2024-6387 openssh: Possible remote code execution due to a race condition in signal handling [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2294905 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-213f33544e' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188 . # Security update for libssh Announcement ID: SUSE-SU-2024:0539-1 Rating: important References: * bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188 * bsc#1211190 * bsc#1218126 * bsc#1218186 * bsc#1218209 * jsc#PED-7719 Cross-References: * CVE-2019-14889 * CVE-2020-16135 * CVE-2020-1730 * CVE-2021-3634 * CVE-2023-1667 * CVE-2023-2283 * CVE-2023-48795 * CVE-2023-6004 * CVE-2023-6918 CVSS scores: * CVE-2019-14889 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2019-14889 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-14889 ( NVD ): 7.1 CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2020-16135 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2020-16135 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2020-1730 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2020-1730 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2021-3634 ( SUSE ): 3.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2021-3634 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-1667 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2023-1667 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-2283 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2023-2283 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2023-48795 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-48795 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-6004 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2023-6004 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2023-6918 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-6918 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE LinuxEnterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves nine vulnerabilities and contains one feature can now be installed. ## Description: This update for libssh fixes the following issues: Update to version 0.9.8 (jsc#PED-7719): * Fix CVE-2023-6004: Command injection using proxycommand (bsc#1218209) * Fix CVE-2023-48795: Potential downgrade attack using strict kex (bsc#1218126) * Fix CVE-2023-6918: Missing checks for return values of MD functions (bsc#1218186) * Allow @ in usernames when parsing from URI composes Update to version 0.9.7 * Fix CVE-2023-1667: a NULL dereference during rekeying with algorithm guessing (bsc#1211188) * Fix CVE-2023-2283: a possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190) * Fix several memory leaks in GSSAPI handling code Update to version 0.9.6 (bsc#1189608, CVE-2021-3634) * https://git.libssh.org/projects/libssh.git/tag/?h=libssh-0.9.6 Update to version 0.9.5 (bsc#1174713, CVE-2020-16135): * CVE-2020-16135: Avoid null pointer dereference in sftpserver (T232) * Improve handling of library initialization (T222) * Fix parsing of subsecond times in SFTP (T219) * Make the documentation reproducible * Remove deprecated API usage in OpenSSL * Fix regression of ssh_channel_poll_timeout() returning SSH_AGAIN * Define version in one place (T226) * Prevent invalid free when using different C runtimes than OpenSSL (T229) * Compatibility improvements to testsuite Update to version 0.9.4: * https://www.libssh.org/2020/04/09/libssh-0-9-4-and-libssh-0-8-9-security-release/ * Fix possible Denial of Service attack when using AES-CTR-ciphers CVE-2020-1730 (bsc#1168699) Update to version 0.9.3: * Fixed CVE-2019-14889 - SCP: Unsanitized location leads to command execution (bsc#1158095) *SSH-01-003 Client: Missing NULL check leads to crash in erroneous state * SSH-01-006 General: Various unchecked Null-derefs cause DOS * SSH-01-007 PKI Gcrypt: Potential UAF/double free with RSA pubkeys * SSH-01-010 SSH: Deprecated hash function in fingerprinting * SSH-01-013 Conf-Parsing: Recursive wildcards in hostnames lead to DOS * SSH-01-014 Conf-Parsing: Integer underflow leads to OOB array access * SSH-01-001 State Machine: Initial machine states should be set explicitly * SSH-01-002 Kex: Differently bound macros used to iterate same array * SSH-01-005 Code-Quality: Integer sign confusion during assignments * SSH-01-008 SCP: Protocol Injection via unescaped File Names * SSH-01-009 SSH: Update documentation which RFCs are implemented * SSH-01-012 PKI: Information leak via uninitialized stack buffer Update to version 0.9.2: * Fixed libssh-config.cmake * Fixed issues with rsa algorithm negotiation (T191) * Fixed detection of OpenSSL ed25519 support (T197) Update to version 0.9.1: * Added support for Ed25519 via OpenSSL * Added support for X25519 via OpenSSL * Added support for localuser in Match keyword * Fixed Match keyword to be case sensitive * Fixed compilation with LibreSSL * Fixed error report of channel open (T75) * Fixed sftp documentation (T137) * Fixed known_hosts parsing (T156) * Fixed build issue with MinGW (T157) * Fixed build with gcc 9 (T164) * Fixed deprecation issues (T165) * Fixed known_hosts directory creation (T166) Update to verion 0.9.0: * Added support for AES-GCM * Added improved rekeying support * Added performance improvements * Disabled blowfish support by default * Fixed several ssh config parsing issues * Added support for DH Group Exchange KEX * Added support for Encrypt-then-MAC mode * Added support for parsing server side configuration file * Added support for ECDSA/Ed25519 certificates * Added FIPS 140-2 compatibility * Improved known_hosts parsing * Improved documentation * ImprovedOpenSSL API usage for KEX, DH, and signatures * Add libssh client and server config files ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-539=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-539=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-539=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-539=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libssh-devel-0.9.8-3.12.2 * libssh4-debuginfo-0.9.8-3.12.2 * libssh4-0.9.8-3.12.2 * libssh-debugsource-0.9.8-3.12.2 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * libssh4-debuginfo-0.9.8-3.12.2 * libssh-config-0.9.8-3.12.2 * libssh4-0.9.8-3.12.2 * libssh-debugsource-0.9.8-3.12.2 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libssh4-32bit-0.9.8-3.12.2 * libssh4-debuginfo-32bit-0.9.8-3.12.2 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * libssh4-debuginfo-0.9.8-3.12.2 * libssh-config-0.9.8-3.12.2 * libssh4-0.9.8-3.12.2 * libssh-debugsource-0.9.8-3.12.2 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libssh4-32bit-0.9.8-3.12.2 * libssh4-debuginfo-32bit-0.9.8-3.12.2 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * libssh4-debuginfo-0.9.8-3.12.2 * libssh-config-0.9.8-3.12.2 * libssh4-0.9.8-3.12.2 * libssh-debugsource-0.9.8-3.12.2 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libssh4-32bit-0.9.8-3.12.2 * libssh4-debuginfo-32bit-0.9.8-3.12.2 ## References: *https://www.suse.com/security/cve/CVE-2019-14889.html * https://www.suse.com/security/cve/CVE-2020-16135.html * https://www.suse.com/security/cve/CVE-2020-1730.html * https://www.suse.com/security/cve/CVE-2021-3634.html * https://www.suse.com/security/cve/CVE-2023-1667.html * https://www.suse.com/security/cve/CVE-2023-2283.html * https://www.suse.com/security/cve/CVE-2023-48795.html * https://www.suse.com/security/cve/CVE-2023-6004.html * https://www.suse.com/security/cve/CVE-2023-6918.html * https://bugzilla.suse.com/show_bug.cgi?id=1158095 * https://bugzilla.suse.com/show_bug.cgi?id=1168699 * https://bugzilla.suse.com/show_bug.cgi?id=1174713 * https://bugzilla.suse.com/show_bug.cgi?id=1189608 * https://bugzilla.suse.com/show_bug.cgi?id=1211188 * https://bugzilla.suse.com/show_bug.cgi?id=1211190 * https://bugzilla.suse.com/show_bug.cgi?id=1218126 * https://bugzilla.suse.com/show_bug.cgi?id=1218186 * https://bugzilla.suse.com/show_bug.cgi?id=1218209 * . This software patch targets vital libssh concerns, improving platform safety in response to recent risks and weaknesses.. libssh security, Linux patch management, security update process, command injection risk. . Severity: Important. LinuxSecurity.com Team
* bsc#1218690 * bsc#1218810 Cross-References: * CVE-2023-6129 . # Security update for openssl-3 Announcement ID: SUSE-SU-2024:0172-1 Rating: moderate References: * bsc#1218690 * bsc#1218810 Cross-References: * CVE-2023-6129 * CVE-2023-6237 CVSS scores: * CVE-2023-6129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6237 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues: * CVE-2023-6129: Fixed vector register clobbering on PowerPC. (bsc#1218690) * CVE-2023-6237: Fixed excessive time spent checking invalid RSA public keys. (bsc#1218810) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-172=1 openSUSE-SLE-15.5-2024-172=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-172=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * openssl-3-debuginfo-3.0.8-150500.5.24.1 * libopenssl3-3.0.8-150500.5.24.1 * openssl-3-debugsource-3.0.8-150500.5.24.1 * libopenssl3-debuginfo-3.0.8-150500.5.24.1 * libopenssl-3-devel-3.0.8-150500.5.24.1 * openssl-3-3.0.8-150500.5.24.1 * openSUSE Leap 15.5 (x86_64) * libopenssl3-32bit-3.0.8-150500.5.24.1 * libopenssl3-32bit-debuginfo-3.0.8-150500.5.24.1 * libopenssl-3-devel-32bit-3.0.8-150500.5.24.1 * openSUSE Leap 15.5 (noarch) *openssl-3-doc-3.0.8-150500.5.24.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libopenssl-3-devel-64bit-3.0.8-150500.5.24.1 * libopenssl3-64bit-3.0.8-150500.5.24.1 * libopenssl3-64bit-debuginfo-3.0.8-150500.5.24.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * openssl-3-debuginfo-3.0.8-150500.5.24.1 * libopenssl3-3.0.8-150500.5.24.1 * openssl-3-debugsource-3.0.8-150500.5.24.1 * libopenssl3-debuginfo-3.0.8-150500.5.24.1 * libopenssl-3-devel-3.0.8-150500.5.24.1 * openssl-3-3.0.8-150500.5.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6129.html * https://www.suse.com/security/cve/CVE-2023-6237.html * https://bugzilla.suse.com/show_bug.cgi?id=1218690 * https://bugzilla.suse.com/show_bug.cgi?id=1218810 . A small update for openssl-3 fixes issues such as memory leaks and improves DSA key checks.. OpenSSL Security Update, SUSE Advisory, CVSS Score Update, Linux Fix, RSA Security. . LinuxSecurity.com Team
* bsc#1128114 * bsc#1214256 * bsc#1214726 Cross-References: . # Security update for poppler Announcement ID: SUSE-SU-2023:4562-1 Rating: moderate References: * bsc#1128114 * bsc#1214256 * bsc#1214726 Cross-References: * CVE-2019-9545 * CVE-2020-36023 * CVE-2022-37052 CVSS scores: * CVE-2019-9545 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-9545 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2020-36023 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-36023 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-37052 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2019-9545: Fixed an uncontrolled recursion issue that could cause a crash (bsc#1128114). * CVE-2022-37052: Fixed a crash that could be triggered when opening a crafted file (bsc#1214726). * CVE-2020-36023: Fixed a stack bugger overflow in FoFiType1C:cvtGlyph (bsc#1214256). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaSTonline_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4562=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4562=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4562=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4562=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4562=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4562=1 ## Package List: * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * poppler-debugsource-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 * SUSE Manager Proxy 4.2 (x86_64) * libpoppler-glib-devel-0.79.0-150200.3.26.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.26.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * libpoppler-devel-0.79.0-150200.3.26.1 * poppler-debugsource-0.79.0-150200.3.26.1 * libpoppler-cpp0-0.79.0-150200.3.26.1 * poppler-tools-0.79.0-150200.3.26.1 * libpoppler-glib8-0.79.0-150200.3.26.1 * poppler-tools-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 * typelib-1_0-Poppler-0_18-0.79.0-150200.3.26.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * libpoppler-glib-devel-0.79.0-150200.3.26.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.26.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * libpoppler-devel-0.79.0-150200.3.26.1 * poppler-debugsource-0.79.0-150200.3.26.1 * libpoppler-cpp0-0.79.0-150200.3.26.1 * poppler-tools-0.79.0-150200.3.26.1 * libpoppler-glib8-0.79.0-150200.3.26.1 *poppler-tools-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 * typelib-1_0-Poppler-0_18-0.79.0-150200.3.26.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * libpoppler-glib-devel-0.79.0-150200.3.26.1 * libpoppler-cpp0-debuginfo-0.79.0-150200.3.26.1 * libpoppler-glib8-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * libpoppler-devel-0.79.0-150200.3.26.1 * poppler-debugsource-0.79.0-150200.3.26.1 * libpoppler-cpp0-0.79.0-150200.3.26.1 * poppler-tools-0.79.0-150200.3.26.1 * libpoppler-glib8-0.79.0-150200.3.26.1 * poppler-tools-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 * typelib-1_0-Poppler-0_18-0.79.0-150200.3.26.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 * openSUSE Leap 15.4 (x86_64) * libpoppler89-32bit-0.79.0-150200.3.26.1 * libpoppler89-32bit-debuginfo-0.79.0-150200.3.26.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.26.1 * poppler-debugsource-0.79.0-150200.3.26.1 * libpoppler89-0.79.0-150200.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2019-9545.html * https://www.suse.com/security/cve/CVE-2020-36023.html * https://www.suse.com/security/cve/CVE-2022-37052.html * https://bugzilla.suse.com/show_bug.cgi?id=1128114 * https://bugzilla.suse.com/show_bug.cgi?id=1214256 * https://bugzilla.suse.com/show_bug.cgi?id=1214726 . To tackle minor concerns in Poppler for better stability within SUSE settings, the following measures were adopted:. Poppler Update, Software Fixes, SUSE System Security. . LinuxSecurity.com Team
This update for go1.20-openssl fixes the following issues: Update to version 1.20.11.1 cut from the go1.20-openssl-fips branch at the revision tagged go1.20.11-1-openssl-fips.. # Security update for go1.20-openssl Announcement ID: SUSE-SU-2023:4472-1 Rating: important References: * bsc#1206346 * bsc#1215985 * bsc#1216109 * bsc#1216943 * bsc#1216944 Cross-References: * CVE-2023-39323 * CVE-2023-39325 * CVE-2023-44487 * CVE-2023-45283 * CVE-2023-45284 CVSS scores: * CVE-2023-39323 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-39323 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-39325 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39325 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45283 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2023-45284 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N Affected Products: * Development Tools Module 15-SP4 * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves five vulnerabilities can now be installed. ## Description: This update for go1.20-openssl fixes the following issues: Update to version 1.20.11.1 cutfrom the go1.20-openssl-fips branch at the revision tagged go1.20.11-1-openssl-fips. * Update to go1.20.11 go1.20.11 (released 2023-11-07) includes security fixes to the path/filepath package, as well as bug fixes to the linker and the net/http package. * security: fix CVE-2023-45283 CVE-2023-45284 path/filepath: insecure parsing of Windows paths (bsc#1216943, bsc#1216944) * cmd/link: split text sections for arm 32-bit * net/http: http2 page fails on firefox/safari if pushing resources Update to version 1.20.10.1 cut from the go1.20-openssl-fips branch at the revision tagged go1.20.10-1-openssl-fips. * Update to go1.20.10 go1.20.10 (released 2023-10-10) includes a security fix to the net/http package. * security: fix CVE-2023-39325 CVE-2023-44487 net/http: rapid stream resets can cause excessive work (bsc#1216109) go1.20.9 (released 2023-10-05) includes one security fixes to the cmd/go package, as well as bug fixes to the go command and the linker. * security: fix CVE-2023-39323 cmd/go: line directives allows arbitrary execution during build (bsc#1215985) * cmd/link: issues with Apple's new linker in Xcode 15 beta ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4472=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4472=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4472=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4472=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * go1.20-openssl-doc-1.20.11.1-150000.1.14.1 * go1.20-openssl-debuginfo-1.20.11.1-150000.1.14.1 * go1.20-openssl-1.20.11.1-150000.1.14.1 * go1.20-openssl-race-1.20.11.1-150000.1.14.1 *openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * go1.20-openssl-doc-1.20.11.1-150000.1.14.1 * go1.20-openssl-debuginfo-1.20.11.1-150000.1.14.1 * go1.20-openssl-1.20.11.1-150000.1.14.1 * go1.20-openssl-race-1.20.11.1-150000.1.14.1 * Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64) * go1.20-openssl-doc-1.20.11.1-150000.1.14.1 * go1.20-openssl-debuginfo-1.20.11.1-150000.1.14.1 * go1.20-openssl-1.20.11.1-150000.1.14.1 * go1.20-openssl-race-1.20.11.1-150000.1.14.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * go1.20-openssl-doc-1.20.11.1-150000.1.14.1 * go1.20-openssl-debuginfo-1.20.11.1-150000.1.14.1 * go1.20-openssl-1.20.11.1-150000.1.14.1 * go1.20-openssl-race-1.20.11.1-150000.1.14.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39323.html * https://www.suse.com/security/cve/CVE-2023-39325.html * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2023-45283.html * https://www.suse.com/security/cve/CVE-2023-45284.html * https://bugzilla.suse.com/show_bug.cgi?id=1206346 * https://bugzilla.suse.com/show_bug.cgi?id=1215985 * https://bugzilla.suse.com/show_bug.cgi?id=1216109 * https://bugzilla.suse.com/show_bug.cgi?id=1216943 * https://bugzilla.suse.com/show_bug.cgi?id=1216944 . The release of go1.20-openssl addresses significant vulnerabilities and offers crucial guidelines for users to apply necessary patches.. opensuse, go1.20-openssl, security advisory, patch instructions. . Severity: Important. LinuxSecurity.com Team
* bsc#1030253 * bsc#1095425 * bsc#1103893 * bsc#1112183 * bsc#1146907 . # Security update for icu73_2 Announcement ID: SUSE-SU-2023:3563-3 Rating: moderate References: * bsc#1030253 * bsc#1095425 * bsc#1103893 * bsc#1112183 * bsc#1146907 * bsc#1158955 * bsc#1159131 * bsc#1161007 * bsc#1162882 * bsc#1166844 * bsc#1167603 * bsc#1182252 * bsc#1182645 * bsc#1192935 * bsc#1193951 * bsc#354372 * bsc#437293 * bsc#824262 * jsc#PED-4917 * jsc#SLE-11118 Cross-References: * CVE-2020-10531 * CVE-2020-21913 CVSS scores: * CVE-2020-10531 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2020-10531 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2020-21913 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2020-21913 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap Micro 5.2 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves two vulnerabilities, contains two features and has 16 securityfixes can now be installed. ## Description: This update for icu73_2 fixes the following issues: * Update to release 73.2 * CLDR extends the support for âshortâ Chinese sort orders to cover some additional, required characters for Level 2. This is carried over into ICU collation. * ICU has a modified character conversion table, mapping some GB18030 characters to Unicode characters that were encoded after GB18030-2005. * fixes builds where UCHAR_TYPE is re-defined such as libqt5-qtwebengine * Update to release 73.1 * Improved Japanese and Korean short-text line breaking * Reduction of C++ memory use in date formatting * Update to release 72.1 * Support for Unicode 15, including new characters, scripts, emoji, and corresponding API constants. * Support for CLDR 42 locale data with various additions and corrections. * Shift to tzdb 2022e. Pre-1970 data for a number of timezones has been removed. * bump library packagename to libicu71 to match the version. * update to 71.1: * updates to CLDR 41 locale data with various additions and corrections. * phrase-based line breaking for Japanese. Existing line breaking methods follow standards and conventions for body text but do not work well for short Japanese text, such as in titles and headings. This new feature is optimized for these use cases. * support for Hindi written in Latin letters (hi_Latn). The CLDR data for this increasingly popular locale has been significantly revised and expanded. Note that based on user expectations, hi_Latn incorporates a large amount of English, and can also be referred to as âHinglishâ. * time zone data updated to version 2022a. Note that pre-1970 data for a number of time zones has been removed, as has been the case in the upstream tzdata release since 2021b. * ICU-21793 Fix ucptrietest golden diff [bsc#1192935] * Update to release 70.1: * Unicode 14 (new characters, scripts, emoji, and API constants) * CLDR 40 (many additions and corrections) * Fixes formeasurement unit formatting * Can now be built with up to C++20 compilers * ICU-21613 Fix undefined behaviour in ComplexUnitsConverter::applyRounder * Update to release 69.1 * CLDR 39 * For Norwegian, "no" is back to being the canonical code, with "nb" treated as equivalent. This aligns handling of Norwegian with other macro language codes. * Binary prefixes in measurement units (KiB, MiB, etc.) * Time zone offsets from local time: New APIs BasicTimeZone::getOffsetFromLocal() (C++) and ucal_getTimeZoneOffsetFromLocal() * Backport ICU-21366 (bsc#1182645) * Update to release 68.2 * Fix memory problem in FormattedStringBuilder * Fix assertion when setKeywordValue w/ long value. * Fix UBSan breakage on 8bit of rbbi * fix int32_t overflow in listFormat * Fix memory handling in MemoryPool::operator=() * Fix memory leak in AliasReplacer * Add back icu.keyring, see https://unicode-org.atlassian.net/browse/ICU-21361 Update to release 68.1: * CLDR 38 * Measurement unit preferences * PluralRules selection for ranges of numbers * Locale ID canonicalization now conforms to the CLDR spec including edge cases * DateIntervalFormat supports output options such as capitalization * Measurement units are normalized in skeleton string output * Time zone data (tzdata) version 2020d * Add the provides for libicu to Make.Net core can install successfully. (bsc#1167603, bsc#1161007) Update to version 67.1: * Unicode 13 (ICU-20893, same as in ICU 66) * Total of 5930 new characters * 4 new scripts * 55 new emoji characters, plus additional new sequences * New CJK extension, first characters in plane 3: U+30000..U+3134A * CLDR 37 * New language at Modern coverage: Nigerian Pidgin * New languages at Basic coverage: Fulah (Adlam), Maithili, Manipuri, Santali, Sindhi (Devanagari), Sundanese * Region containment: EU no longer includes GB * Unicode 13 root collation data and Chinese data for collation and transliteration * DateTimePatternGenerator now obeys the "hc" preference in thelocale identifier (ICU-20442) * Various other improvements for ECMA-402 conformance * Number skeletons have a new "concise" form that can be used in MessageFormat strings (ICU-20418) * Currency formatting options for formal and other currency display name variants (ICU-20854) * ListFormatter: new public API to select the style & type (ICU-12863) * ListFormatter now selects the proper âandâ/âorâ form for Spanish & Hebrew (ICU-21016) * Locale ID canonicalization upgraded to implement the complete CLDR spec (ICU-20834, ICU-20272) * LocaleMatcher: New option to ignore one-way matches (ICU-20936), and other tweaks to the code (ICU-20916, ICU-20917) and data (from CLDR) * acceptLanguage() reimplemented via LocaleMatcher (ICU-20700) * Data build tool: tzdbNames.res moved from the "zone_tree" category to the "zone_supplemental" category (ICU-21073) * Fixed uses of u8"literals" broken by the C++20 introduction of the incompatible char8_t type (ICU-20972), * and added a few API overloads to reduce the need for reinterpret_cast (ICU-20984). * Support for manipulating CLDR 37 unit identifiers in MeasureUnit. * Fix potential integer overflow in UnicodeString:doAppend (bsc#1166844, CVE-2020-10531). Update to version 66.1: * Unicode 13 support * Fix uses of u8"literals" broken by C++20 introduction of incompatible char8_t type. (ICU-20972) * use LocalMemory for cmd to prevent use after free (bsc#1193951 CVE-2020-21913). * Remove /usr/lib(64)/icu/current [bsc#1158955]. Update to release 65.1 (jsc#SLE-11118): * Updated to CLDR 36 locale data with many additions and corrections, and some new measurement units. * The Java LocaleMatcher API is improved, and ported to C++. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.2 zypper in -t patchSUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3563=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3563=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-3563=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3563=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3563=1 * openSUSE Leap Micro 5.2 zypper in -t patch SUSE-2023-3563=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3563=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3563=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3563=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3563=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3563=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3563=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3563=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3563=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3563=1 ## Package List: * SUSE Manager Retail Branch Server 4.2 (x86_64) * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-devel-73.2-150000.1.3.1 * libicu73_2-doc-73.2-150000.1.3.1 * SUSE Manager Retail Branch Server 4.2 (noarch) * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-devel-73.2-150000.1.3.1 * libicu73_2-doc-73.2-150000.1.3.1 * SUSE Manager Server 4.2 (noarch) *libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.1 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.2 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * openSUSE Leap Micro 5.2 (aarch64 ppc64le s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * openSUSE Leap Micro 5.2 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * openSUSE Leap Micro 5.3 (aarch64 ppc64le s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * openSUSE Leap Micro 5.3 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * openSUSE Leap Micro 5.4 (aarch64 ppc64le s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * openSUSE Leap Micro 5.4 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSELinux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libicu73_2-73.2-150000.1.3.1 * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-devel-73.2-150000.1.3.1 * libicu73_2-doc-73.2-150000.1.3.1 * Basesystem Module 15-SP4 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-devel-73.2-150000.1.3.1 *libicu73_2-doc-73.2-150000.1.3.1 * Basesystem Module 15-SP5 (noarch) * libicu73_2-bedata-73.2-150000.1.3.1 * libicu73_2-ledata-73.2-150000.1.3.1 * SUSE Manager Proxy 4.2 (x86_64) * libicu73_2-debuginfo-73.2-150000.1.3.1 * icu73_2-debuginfo-73.2-150000.1.3.1 * libicu73_2-73.2-150000.1.3.1 * icu73_2-debugsource-73.2-150000.1.3.1 * libicu73_2-devel-73.2-150000.1.3.1 * libicu73_2-doc-73.2-150000.1.3.1 * SUSE Manager Proxy 4.2 (noarch) * libicu73_2-ledata-73.2-150000.1.3.1 ## References: * https://www.suse.com/security/cve/CVE-2020-10531.html * https://www.suse.com/security/cve/CVE-2020-21913.html * https://bugzilla.suse.com/show_bug.cgi?id=1030253 * https://bugzilla.suse.com/show_bug.cgi?id=1095425 * https://bugzilla.suse.com/show_bug.cgi?id=1103893 * https://bugzilla.suse.com/show_bug.cgi?id=1112183 * https://bugzilla.suse.com/show_bug.cgi?id=1146907 * https://bugzilla.suse.com/show_bug.cgi?id=1158955 * https://bugzilla.suse.com/show_bug.cgi?id=1159131 * https://bugzilla.suse.com/show_bug.cgi?id=1161007 * https://bugzilla.suse.com/show_bug.cgi?id=1162882 * https://bugzilla.suse.com/show_bug.cgi?id=1166844 * https://bugzilla.suse.com/show_bug.cgi?id=1167603 * https://bugzilla.suse.com/show_bug.cgi?id=1182252 * https://bugzilla.suse.com/show_bug.cgi?id=1182645 * https://bugzilla.suse.com/show_bug.cgi?id=1192935 * https://bugzilla.suse.com/show_bug.cgi?id=1193951 * https://bugzilla.suse.com/show_bug.cgi?id=354372 * https://bugzilla.suse.com/show_bug.cgi?id=437293 * https://bugzilla.suse.com/show_bug.cgi?id=824262 * * . Crucial patch released for icu73_2. Various citations noted and guidelines presented for SUSE upgrade.. SUSE Linux, Security Update, icu73 Improvements, Package Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.