Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:20060-1 Release Date: 2025-02-03T08:57:45Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed a stack-based buffer overflow when formatting error messages (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-52=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * liborc-0_4-0-0.4.34-2.1 * liborc-0_4-0-debuginfo-0.4.34-2.1 * orc-debugsource-0.4.34-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . SUSE Linux Micro has issued an update addressing a critical orc buffer overflow vulnerability. Discover the specifics of the patch and its severity implications within this announcement.. SUSE Linux Micro Patch, Orc Buffer Overflow, Security Issue Update, SUSE Important Advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:20060-1 Release Date: 2025-02-03T08:57:45Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed a stack-based buffer overflow when formatting error messages (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-52=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * liborc-0_4-0-0.4.34-2.1 * orc-debugsource-0.4.34-2.1 * liborc-0_4-0-debuginfo-0.4.34-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . A recent patch addresses a critical security vulnerability in orc on SUSE Linux Micro 6.0 related to buffer overflow risks.. SUSE Security, orc Update, buffer overflow Fix, Linux Micro Security. . Severity: Important. LinuxSecurity.com Team
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:20152-1 Release Date: 2025-03-19T10:36:33Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed a stack-based buffer overflow in the Orc compiler when formatting error messages for certain input files (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-252=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * liborc-0_4-0-0.4.34-3.1 * liborc-0_4-0-debuginfo-0.4.34-3.1 * orc-debugsource-0.4.34-3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . Urgent security patch for SUSE impacting Orc. Resolves buffer overflow vulnerability linked to CVE-2024-40897. Implement updates immediately.. SUSE security, orc update, buffer overflow, patch instructions, CVE-2024. . Severity: Important. LinuxSecurity.com Team
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:20152-1 Release Date: 2025-03-19T10:36:33Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed a stack-based buffer overflow in the Orc compiler when formatting error messages for certain input files (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-252=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * orc-debugsource-0.4.34-3.1 * liborc-0_4-0-0.4.34-3.1 * liborc-0_4-0-debuginfo-0.4.34-3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . Canonical releases patches addressing a severe memory leak in camlp4, boosting stability for Ubuntu Server.. SUSE Linux Micro, orc patch, buffer overflow fix, security update. . Severity: Important. LinuxSecurity.com Team
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:20272-1 Release Date: 2025-04-22T12:08:29Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed stack-based buffer overflow inside the orc compiler when formatting error messages for certain input files (bsc#1228184). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-73=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * orc-debugsource-0.4.34-slfo.1.1_2.1 * liborc-0_4-0-debuginfo-0.4.34-slfo.1.1_2.1 * liborc-0_4-0-0.4.34-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . This report addresses significant vulnerabilities related to orc within the SUSE environment and provides comprehensive patching guidelines along with an assessment of their severity levels.. SUSE Linux Micro, Orc Update, Patch Instructions, Security Rating. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in Orc, which can lead to arbitrary code execution. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Orc: Arbitrary Code Execution Date: May 12, 2025 Bugs: #937127 ID: 202505-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Orc, which can lead to arbitrary code execution Background ========== Orc is a library and set of tools for compiling and executing very simple programs that operate on arrays of data. The "language" is a generic assembly language that represents many of the features available in SIMD architectures, including saturated addition and subtraction, and many arithmetic operations. Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ dev-lang/orc < 0.4.40 > = 0.4.40 Description =========== Please review the CVE identifier referenced below for details. Impact ====== It is possible for a malicious third party to trigger a buffer overflow and effect code execution with the same privileges as the orc compiler is called with by feeding it with malformed orc source files. This only affects developers and CI environments using orcc, not users of liborc. Workaround ========== There is no known workaround at this time. Resolution ========== All Orc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/orc-0.4.40" References ========== [ 1 ] CVE-2024-40897 https://nvd.nist.gov/vuln/detail/CVE-2024-40897 Availability ============ This GLSA and any updates to it are available for viewingat the Gentoo Security Website: https://security.gentoo.org/glsa/202505-05 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An update that solves one vulnerability can now be installed.. # Security update for orc Announcement ID: SUSE-SU-2025:0344-1 Release Date: 2025-02-03T17:06:05Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE ManagerServer 4.3 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed stack-based buffer overflow in the Orc compiler when formatting error messages for certain input files (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-344=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-344=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-344=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-344=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-344=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-344=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-344=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-344=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-344=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-344=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-344=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-344=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-344=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypperin -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-344=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-344=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-344=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-344=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-344=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-344=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-344=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-344=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-344=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-344=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-344=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-344=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * orc-doc-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * openSUSE Leap 15.6 (x86_64) * liborc-0_4-0-32bit-0.4.28-150000.3.9.1 * liborc-0_4-0-32bit-debuginfo-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390xx86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Package Hub 15 15-SP6 (x86_64) * liborc-0_4-0-32bit-0.4.28-150000.3.9.1 * liborc-0_4-0-32bit-debuginfo-0.4.28-150000.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 *orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 *orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Manager Proxy 4.3 (x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * liborc-0_4-0-debuginfo-0.4.28-150000.3.9.1 * orc-debugsource-0.4.28-150000.3.9.1 * orc-debuginfo-0.4.28-150000.3.9.1 * liborc-0_4-0-0.4.28-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . Essential patch for Fedora tackling significant memory leak in gcc, bolstering overall system integrity. Update immediately!. openSUSE update,orc security, software patch, buffer overflow fix, SUSE advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1228184 Cross-References: * CVE-2024-40897 . # Security update for orc Announcement ID: SUSE-SU-2025:0314-1 Release Date: 2025-01-31T16:03:47Z Rating: important References: * bsc#1228184 Cross-References: * CVE-2024-40897 CVSS scores: * CVE-2024-40897 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-40897 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for orc fixes the following issues: * CVE-2024-40897: Fixed stack-based buffer overflow in the Orc compiler when formatting error messages for certain input files (bsc#1228184) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-314=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-314=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * orc-debugsource-0.4.21-3.6.1 * liborc-0_4-0-debuginfo-0.4.21-3.6.1 * orc-debuginfo-0.4.21-3.6.1 * liborc-0_4-0-0.4.21-3.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * liborc-0_4-0-32bit-0.4.21-3.6.1 * liborc-0_4-0-debuginfo-32bit-0.4.21-3.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * liborc-0_4-0-0.4.21-3.6.1 * liborc-0_4-0-debuginfo-0.4.21-3.6.1 * liborc-0_4-0-debuginfo-32bit-0.4.21-3.6.1 *liborc-0_4-0-32bit-0.4.21-3.6.1 * orc-debugsource-0.4.21-3.6.1 * orc-debuginfo-0.4.21-3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40897.html * https://bugzilla.suse.com/show_bug.cgi?id=1228184 . Addresses significant vulnerability affecting orc in SUSE Linux Enterprise, encompassing essential update information and guidance for applying patches.. SUSE Linux Enterprise, orc update, security fix, important advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.