The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1375-1 Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.130 , suse/sle15:15.3 , suse/sle15:15.3.17.20.130 Container Release : 17.20.130 Severity : moderate Type : security References : 1209533 1209713 1209714 1210135 1210507 CVE-2022-4899 CVE-2023-24593 CVE-2023-25180 CVE-2023-29383 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2070-1 Released: Fri Apr 28 13:56:33 2023 Summary: Security update for shadow Type: security Severity: moderate References: 1210507,CVE-2023-29383 This update for shadow fixes the following issues: - CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2074-1 Released: Fri Apr 28 17:02:25 2023 Summary: Security update for zstd Type: security Severity: moderate References: 1209533,CVE-2022-4899 This update for zstd fixes the following issues: - CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2076-1 Released: Fri Apr 28 17:35:05 2023 Summary: Security update for glib2 Type: security Severity: moderate References: 1209713,1209714,1210135,CVE-2023-24593,CVE-2023-25180 This update for glib2 fixes the following issues: - CVE-2023-24593: Fixed a denial of service caused by handling a malicious text-form variant (bsc#1209714). - CVE-2023-25180: Fixed a denial of service caused bymalicious serialised variant (bsc#1209713). The following non-security bug was fixed: - Fixed regression on s390x (bsc#1210135, glgo#GNOME/glib!2978). The following package changes have been done: - libglib-2_0-0-2.62.6-150200.3.15.1 updated - libzstd1-1.4.4-150000.1.9.1 updated - login_defs-4.8.1-150300.4.6.1 updated - shadow-4.8.1-150300.4.6.1 updated . SUSE Container Advisory ID SUSE-CU-2023:1380-1 incorporates important security patches for suse/sle15 targeting several moderate vulnerabilities.. SUSE Bundles, Container Security, SUSE Updates. . LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:886-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.46 , suse/sle15:15.4 , suse/sle15:15.4.27.14.46 Container Release : 27.14.46 Severity : moderate Type : security References : 1203537 1209533 CVE-2022-4899 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1662-1 Released: Wed Mar 29 10:36:23 2023 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: 1203537 This update for patterns-base fixes the following issues: - change label of FIPS 140-2 to 140-3 to reflect our current certifications (bsc#1203537) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1688-1 Released: Wed Mar 29 18:19:10 2023 Summary: Security update for zstd Type: security Severity: moderate References: 1209533,CVE-2022-4899 This update for zstd fixes the following issues: - CVE-2022-4899: Fixed buffer overrun in util.c (bsc#1209533). The following package changes have been done: - libzstd1-1.5.0-150400.3.3.1 updated - patterns-base-fips-20200124-150400.20.4.1 updated . SUSE Container Update Notification for suse/sle15 encompasses various security enhancements and modifications to package variations available.. SUSE Container Update,zstd Buffer Overrun,moderate Severity,suse/sle15 Update. . LinuxSecurity.com Team
Update to zstd-1.5.4, fixes CVE-2022.4899.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-af177441a9 2023-03-30 01:14:14.931070 --------------------------------------------------------------------------------Name : mingw-zstd Product : Fedora 36 Version : 1.5.4 Release : 1.fc36 URL : https://github.com/facebook/zstd Summary : MinGW Windows zstd library Description : MinGW Windows zstd library. --------------------------------------------------------------------------------Update Information: Update to zstd-1.5.4, fixes CVE-2022.4899. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 15 2023 Sandro Mani - 1.5.4-1 - Update to 1.5.4 * Thu Jan 19 2023 Fedora Release Engineering - 1.5.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Thu Jul 21 2022 Fedora Release Engineering - 1.5.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Fri Mar 25 2022 Sandro Mani - 1.5.2-2 - Rebuild with mingw-gcc-12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2179865 - CVE-2022-4899 mingw-zstd: zstd: buffer overrun in util.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2179865 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-af177441a9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for zstd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0481-1 Rating: moderate References: #1183370 #1183371 Cross-References: CVE-2021-24031 CVE-2021-24032 CVSS scores: CVE-2021-24031 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-24031 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-24032 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-24032 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for zstd fixes the following issues: - CVE-2021-24031: Added read permissions to files while being compressed or uncompressed (bsc#1183371). - CVE-2021-24032: Fixed a race condition which could have allowed an attacker to access world-readable destination file (bsc#1183370). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-481=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libzstd-devel-1.4.4-lp152.2.3.1 libzstd-devel-static-1.4.4-lp152.2.3.1 libzstd1-1.4.4-lp152.2.3.1 libzstd1-debuginfo-1.4.4-lp152.2.3.1 zstd-1.4.4-lp152.2.3.1 zstd-debuginfo-1.4.4-lp152.2.3.1 zstd-debugsource-1.4.4-lp152.2.3.1 - openSUSE Leap 15.2 (x86_64): libzstd1-32bit-1.4.4-lp152.2.3.1 libzstd1-32bit-debuginfo-1.4.4-lp152.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-24031.html https://www.suse.com/security/cve/CVE-2021-24032.html https://bugzilla.suse.com/1183370 https://bugzilla.suse.com/1183371 . OpenSUSE has released a moderate zstd update to address vulnerabilities affecting system security and stability. Users should apply this update to protect their systems.. OpenSUSE Security Update,zstd Update,Moderate Security Fix,zstd Issues. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for zstd ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0948-1 Rating: moderate References: #1183370 #1183371 Cross-References: CVE-2021-24031 CVE-2021-24032 CVSS scores: CVE-2021-24031 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-24031 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-24032 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-24032 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for zstd fixes the following issues: - CVE-2021-24031: Added read permissions to files while being compressed or uncompressed (bsc#1183371). - CVE-2021-24032: Fixed a race condition which could have allowed an attacker to access world-readable destination file (bsc#1183370). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-948=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-948=1 Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): libzstd1-1.4.4-1.6.1 libzstd1-debuginfo-1.4.4-1.6.1 zstd-debuginfo-1.4.4-1.6.1 zstd-debugsource-1.4.4-1.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libzstd-devel-1.4.4-1.6.1 libzstd1-1.4.4-1.6.1 libzstd1-debuginfo-1.4.4-1.6.1 zstd-1.4.4-1.6.1 zstd-debuginfo-1.4.4-1.6.1 zstd-debugsource-1.4.4-1.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): libzstd1-32bit-1.4.4-1.6.1 libzstd1-32bit-debuginfo-1.4.4-1.6.1 References: https://www.suse.com/security/cve/CVE-2021-24031.html https://www.suse.com/security/cve/CVE-2021-24032.html https://bugzilla.suse.com/1183370 https://bugzilla.suse.com/1183371 . SUSE Security Update tackles multiple vulnerabilities in the zstd library, enhancing safeguards against possible exploits.. SUSE MicroOS Update,zstd Security Patch,File Access Control,Security Patch Instructions. . LinuxSecurity.com Team
An update that contains security fixes and contains one feature can now be installed. . SUSE Security Update: Security update for zstd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1396-3 Rating: moderate References: #1082318 #1133297 ECO-1886 Affected Products: SUSE Linux Enterprise Installer 15-SP1 SUSE Linux Enterprise Installer 15 ______________________________________________________________________________ An update that contains security fixes and contains one feature can now be installed. Description: This update for zstd fixes the following issues: - Fix for build error caused by wrong static libraries. (bsc#1133297) - Correction in spec file marking the license as documentation. (bsc#1082318) - Add new package for SLE-15. (jsc#ECO-1886) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Installer 15-SP1: zypper in -t patch SUSE-SLE-INSTALLER-15-SP1-2020-1396=1 - SUSE Linux Enterprise Installer 15: zypper in -t patch SUSE-SLE-INSTALLER-15-2020-1396=1 Package List: - SUSE Linux Enterprise Installer 15-SP1 (aarch64 ppc64le s390x x86_64): libzstd1-1.4.4-1.3.1 - SUSE Linux Enterprise Installer 15 (aarch64 ppc64le s390x x86_64): libzstd1-1.4.4-1.3.1 References: https://bugzilla.suse.com/1082318 https://bugzilla.suse.com/1133297 . Apply the SUSE Security Update for zstd (SUSE-SU-2020:1396-3) to resolve critical security vulnerabilities and introduce enhanced functionality.. SUSE Security Update,zstd patch,software installation,SUSE Linux Enterprise,security fixes. . LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for zstd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1396-2 Rating: moderate References: #1082318 #1133297 Affected Products: SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for zstd fixes the following issues: - Fix for build error caused by wrong static libraries. (bsc#1133297) - Correction in spec file marking the license as documentation. (bsc#1082318) - Add new package for SLE-15. (jsc#ECO-1886) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2020-1396=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2020-1396=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-1396=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-1396=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-1396=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise Server for SAP 15 (x86_64): libzstd1-32bit-1.4.4-1.3.1 libzstd1-32bit-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libzstd-devel-1.4.4-1.3.1 libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 zstd-1.4.4-1.3.1 zstd-debuginfo-1.4.4-1.3.1 zstd-debugsource-1.4.4-1.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): libzstd1-32bit-1.4.4-1.3.1 libzstd1-32bit-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (x86_64): libzstd1-32bit-1.4.4-1.3.1 libzstd1-32bit-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (x86_64): libzstd1-32bit-1.4.4-1.3.1 libzstd1-32bit-debuginfo-1.4.4-1.3.1 References: https://bugzilla.suse.com/1082318 https://bugzilla.suse.com/1133297 _______________________________________________ sle-security-updates mailing list
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for zstd ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1396-1 Rating: moderate References: #1082318 #1133297 Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for zstd fixes the following issues: - Fix for build error caused by wrong static libraries. (bsc#1133297) - Correction in spec file marking the license as documentation. (bsc#1082318) - Add new package for SLE-15. (jsc#ECO-1886) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-1396=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libzstd-devel-1.4.4-1.3.1 libzstd1-1.4.4-1.3.1 libzstd1-debuginfo-1.4.4-1.3.1 zstd-1.4.4-1.3.1 zstd-debuginfo-1.4.4-1.3.1 zstd-debugsource-1.4.4-1.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): libzstd1-32bit-1.4.4-1.3.1 libzstd1-32bit-debuginfo-1.4.4-1.3.1 References: https://bugzilla.suse.com/1082318 https://bugzilla.suse.com/1133297 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.