openSUSE Security Announce
Threads by month
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 1999 -----
- December
- November
- October
- September
- August
June 2020
- 1 participants
- 73 discussions
[security-announce] openSUSE-SU-2020:0801-1: important: Security update for the Linux Kernel
by opensuse-security@opensuse.org 13 Jun '20
by opensuse-security@opensuse.org 13 Jun '20
13 Jun '20
openSUSE Security Update: Security update for the Linux Kernel
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0801-1
Rating: important
References: #1051510 #1058115 #1065729 #1071995 #1082555
#1083647 #1089895 #1090036 #1103990 #1103991
#1103992 #1104745 #1109837 #1111666 #1112178
#1112374 #1113956 #1114279 #1124278 #1127354
#1127355 #1127371 #1133021 #1142685 #1144333
#1151794 #1152489 #1154824 #1157169 #1158265
#1160388 #1160947 #1164780 #1164871 #1165183
#1165478 #1165741 #1166969 #1166978 #1167574
#1167851 #1167867 #1168332 #1168670 #1168789
#1168829 #1168854 #1169020 #1169514 #1169525
#1169762 #1170056 #1170125 #1170145 #1170284
#1170345 #1170457 #1170522 #1170592 #1170617
#1170618 #1170620 #1170621 #1170740 #1170770
#1170778 #1170791 #1170901 #1171078 #1171098
#1171118 #1171189 #1171191 #1171195 #1171202
#1171205 #1171214 #1171217 #1171218 #1171219
#1171220 #1171244 #1171252 #1171254 #1171293
#1171417 #1171527 #1171599 #1171600 #1171601
#1171602 #1171604 #1171605 #1171606 #1171607
#1171608 #1171609 #1171610 #1171611 #1171612
#1171613 #1171614 #1171615 #1171616 #1171617
#1171618 #1171619 #1171620 #1171621 #1171622
#1171623 #1171624 #1171625 #1171626 #1171662
#1171679 #1171691 #1171692 #1171694 #1171695
#1171736 #1171817 #1171948 #1171949 #1171951
#1171952 #1171979 #1171982 #1171983 #1172017
#1172096 #1172097 #1172098 #1172099 #1172101
#1172102 #1172103 #1172104 #1172127 #1172130
#1172185 #1172188 #1172199 #1172201 #1172202
#1172221 #1172249 #1172251 #1172317 #1172342
#1172343 #1172344 #1172366 #1172378 #1172391
#1172397 #1172453
Cross-References: CVE-2018-1000199 CVE-2019-19462 CVE-2019-20806
CVE-2019-20812 CVE-2019-9455 CVE-2020-0543
CVE-2020-10690 CVE-2020-10711 CVE-2020-10720
CVE-2020-10732 CVE-2020-10751 CVE-2020-10757
CVE-2020-11608 CVE-2020-11609 CVE-2020-12114
CVE-2020-12464 CVE-2020-12652 CVE-2020-12653
CVE-2020-12654 CVE-2020-12655 CVE-2020-12656
CVE-2020-12657 CVE-2020-12659 CVE-2020-12769
CVE-2020-13143
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that solves 25 vulnerabilities and has 132 fixes
is now available.
Description:
The openSUSE Leap 15.1 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2020-0543: Fixed a side channel attack against special registers
which could have resulted in leaking of read values to cores other than
the one which called it. This attack is known as Special Register Buffer
Data Sampling (SRBDS) or "CrossTalk" (bsc#1154824).
- CVE-2018-1000199: Fixed a potential local code execution via ptrace
(bsc#1089895).
- CVE-2019-19462: relay_open in kernel/relay.c allowed local users to
cause a denial of service (such as relay blockage) by triggering a NULL
alloc_percpu result (bnc#1158265).
- CVE-2019-20806: Fixed a null pointer dereference in
tw5864_handle_frame() which may had lead to denial of service
(bsc#1172199).
- CVE-2019-20812: The prb_calc_retire_blk_tmo() function in
net/packet/af_packet.c can result in a denial of service (CPU
consumption and soft lockup) in a certain failure case involving
TPACKET_V3, aka CID-b43d1f9f7067 (bnc#1172453).
- CVE-2019-9455: Fixed a pointer leak due to a WARN_ON statement in a
video driver. This could lead to local information disclosure with
System execution privileges needed (bsc#1170345).
- CVE-2020-10690: Fixed the race between the release of ptp_clock and cdev
(bsc#1170056).
- CVE-2020-10711: Fixed a null pointer dereference in SELinux subsystem
which could have allowed a remote network user to crash the kernel
resulting in a denial of service (bsc#1171191).
- CVE-2020-10720: Fixed a use-after-free read in napi_gro_frags()
(bsc#1170778).
- CVE-2020-10732: Fixed kernel data leak in userspace coredumps due to
uninitialized data (bsc#1171220).
- CVE-2020-10751: Fixed an improper implementation in SELinux LSM hook
where it was assumed that an skb would only contain a single netlink
message (bsc#1171189).
- CVE-2020-10757: Fixed an issue where remaping hugepage DAX to anon mmap
could have caused user PTE access (bsc#1172317).
- CVE-2020-11608: An issue was discovered in
drivers/media/usb/gspca/ov519.c that allowed NULL pointer dereferences
in ov511_mode_init_regs and ov518_mode_init_regs when there are zero
endpoints, aka CID-998912346c0d (bnc#1168829).
- CVE-2020-11609: An issue was discovered in the stv06xx subsystem in
drivers/media/usb/gspca/stv06xx/stv06xx.c and
drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid
descriptors, as demonstrated by a NULL pointer dereference, aka
CID-485b06aadb93 (bnc#1168854).
- CVE-2020-12114: Fixed a pivot_root race condition which could have
allowed local users to cause a denial of service (panic) by corrupting a
mountpoint reference counter (bsc#1171098).
- CVE-2020-12464: Fixed a use-after-free due to a transfer without a
reference (bsc#1170901).
- CVE-2020-12652: Fixed an issue which could have allowed local users to
hold an incorrect lock during the ioctl operation and trigger a race
condition (bsc#1171218).
- CVE-2020-12653: Fixed an issue in the wifi driver which could have
allowed local users to gain privileges or cause a denial of service
(bsc#1171195).
- CVE-2020-12654: Fixed an issue in he wifi driver which could have
allowed a remote AP to trigger a heap-based buffer overflow
(bsc#1171202).
- CVE-2020-12655: Fixed an issue which could have allowed attackers to
trigger a sync of excessive duration via an XFS v5 image with crafted
metadata (bsc#1171217).
- CVE-2020-12656: Fixed an improper handling of certain domain_release
calls leadingch could have led to a memory leak (bsc#1171219).
- CVE-2020-12657: An a use-after-free in block/bfq-iosched.c (bsc#1171205).
- CVE-2020-12659: Fixed an out-of-bounds write (by a user with the
CAP_NET_ADMIN capability) due to improper headroom validation
(bsc#1171214).
- CVE-2020-12769: Fixed an issue which could have allowed attackers to
cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one
(bsc#1171983).
- CVE-2020-13143: Fixed an out-of-bounds read in gadget_dev_desc_UDC_store
in drivers/usb/gadget/configfs.c (bsc#1171982).
The following non-security bugs were fixed:
- ACPI: CPPC: Fix reference count leak in acpi_cppc_processor_probe()
(bsc#1051510).
- ACPI: sysfs: Fix reference count leak in
acpi_sysfs_add_hotplug_profile() (bsc#1051510).
- acpi/x86: ignore unspecified bit positions in the ACPI global lock field
(bsc#1051510).
- Add br_netfilter to kernel-default-base (bsc#1169020)
- agp/intel: Reinforce the barrier after GTT updates (bsc#1051510).
- ALSA: ctxfi: Remove unnecessary cast in kfree (bsc#1051510).
- ALSA: doc: Document PC Beep Hidden Register on Realtek ALC256
(bsc#1051510).
- ALSA: dummy: Fix PCM format loop in proc output (bsc#1111666).
- ALSA: hda: Add driver blacklist (bsc#1051510).
- ALSA: hda: Always use jackpoll helper for jack update after resume
(bsc#1051510).
- ALSA: hda: call runtime_allow() for all hda controllers (bsc#1051510).
- ALSA: hda: Do not release card at firmware loading error (bsc#1051510).
- ALSA: hda: Explicitly permit using autosuspend if runtime PM is
supported (bsc#1051510).
- ALSA: hda/hdmi: fix race in monitor detection during probe (bsc#1051510).
- ALSA: hda/hdmi: fix without unlocked before return (bsc#1051510).
- ALSA: hda: Honor PM disablement in PM freeze and thaw_noirq ops
(bsc#1051510).
- ALSA: hda: Keep the controller initialization even if no codecs found
(bsc#1051510).
- ALSA: hda: Match both PCI ID and SSID for driver blacklist (bsc#1111666).
- ALSA: hda/realtek - Add a model for Thinkpad T570 without DAC workaround
(bsc#1172017).
- ALSA: hda/realtek - Add COEF workaround for ASUS ZenBook UX431DA
(git-fixes).
- ALSA: hda/realtek - Add HP new mute led supported for ALC236 (git-fixes).
- ALSA: hda/realtek - Add more fixup entries for Clevo machines
(git-fixes).
- ALSA: hda/realtek - Add new codec supported for ALC245 (bsc#1051510).
- ALSA: hda/realtek - Add new codec supported for ALC287 (git-fixes).
- ALSA: hda/realtek: Add quirk for Samsung Notebook (git-fixes).
- ALSA: hda/realtek - Add supported new mute Led for HP (git-fixes).
- ALSA: hda/realtek - Enable headset mic of ASUS GL503VM with ALC295
(git-fixes).
- ALSA: hda/realtek - Enable headset mic of ASUS UX550GE with ALC295
(git-fixes).
- ALSA: hda/realtek: Enable headset mic of ASUS UX581LV with ALC295
(git-fixes).
- ALSA: hda/realtek - Enable the headset mic on Asus FX505DT (bsc#1051510).
- ALSA: hda/realtek - Fix S3 pop noise on Dell Wyse (git-fixes).
- ALSA: hda/realtek - Fix silent output on Gigabyte X570 Aorus Xtreme
(bsc#1111666).
- ALSA: hda/realtek - Fix unexpected init_amp override (bsc#1051510).
- ALSA: hda/realtek - Limit int mic boost for Thinkpad T530 (git-fixes
bsc#1171293).
- ALSA: hda/realtek - Two front mics on a Lenovo ThinkCenter (bsc#1051510).
- ALSA: hda: Release resources at error in delayed probe (bsc#1051510).
- ALSA: hda: Remove ASUS ROG Zenith from the blacklist (bsc#1051510).
- ALSA: hda: Skip controller resume if not needed (bsc#1051510).
- ALSA: hwdep: fix a left shifting 1 by 31 UB bug (git-fixes).
- ALSA: iec1712: Initialize STDSP24 properly when using the model=staudio
option (git-fixes).
- ALSA: opti9xx: shut up gcc-10 range warning (bsc#1051510).
- ALSA: pcm: fix incorrect hw_base increase (git-fixes).
- ALSA: pcm: oss: Place the plugin buffer overflow checks correctly
(bsc#1170522).
- ALSA: rawmidi: Fix racy buffer resize under concurrent accesses
(git-fixes).
- ALSA: usb-audio: Add connector notifier delegation (bsc#1051510).
- ALSA: usb-audio: Add control message quirk delay for Kingston HyperX
headset (git-fixes).
- ALSA: usb-audio: add mapping for ASRock TRX40 Creator (git-fixes).
- ALSA: usb-audio: Add mixer workaround for TRX40 and co (bsc#1051510).
- ALSA: usb-audio: Add quirk for Focusrite Scarlett 2i2 (bsc#1051510).
- ALSA: usb-audio: Add static mapping table for ALC1220-VB-based mobos
(bsc#1051510).
- ALSA: usb-audio: Apply async workaround for Scarlett 2i4 2nd gen
(bsc#1051510).
- ALSA: usb-audio: Check mapping at creating connector controls, too
(bsc#1051510).
- ALSA: usb-audio: Correct a typo of NuPrime DAC-10 USB ID (bsc#1051510).
- ALSA: usb-audio: Do not create jack controls for PCM terminals
(bsc#1051510).
- ALSA: usb-audio: Do not override ignore_ctl_error value from the map
(bsc#1051510).
- ALSA: usb-audio: Filter error from connector kctl ops, too (bsc#1051510).
- ALSA: usb-audio: Fix usb audio refcnt leak when getting spdif
(bsc#1051510).
- ALSA: usb-audio: mixer: volume quirk for ESS Technology Asus USB DAC
(git-fixes).
- ALSA: usb-audio: Quirks for Gigabyte TRX40 Aorus Master onboard audio
(git-fixes).
- ALSA: usx2y: Fix potential NULL dereference (bsc#1051510).
- ASoC: codecs: hdac_hdmi: Fix incorrect use of list_for_each_entry
(bsc#1051510).
- ASoC: dapm: connect virtual mux with default value (bsc#1051510).
- ASoC: dapm: fixup dapm kcontrol widget (bsc#1051510).
- ASoC: dpcm: allow start or stop during pause for backend (bsc#1051510).
- ASoC: fix regwmask (bsc#1051510).
- ASoC: msm8916-wcd-digital: Reset RX interpolation path after use
(bsc#1051510).
- ASoC: samsung: Prevent clk_get_rate() calls in atomic context
(bsc#1111666).
- ASoC: topology: Check return value of pcm_new_ver (bsc#1051510).
- ASoC: topology: use name_prefix for new kcontrol (bsc#1051510).
- b43legacy: Fix case where channel status is corrupted (bsc#1051510).
- batman-adv: fix batadv_nc_random_weight_tq (git-fixes).
- batman-adv: Fix refcnt leak in batadv_show_throughput_override
(git-fixes).
- batman-adv: Fix refcnt leak in batadv_store_throughput_override
(git-fixes).
- batman-adv: Fix refcnt leak in batadv_v_ogm_process (git-fixes).
- bcache: avoid unnecessary btree nodes flushing in btree_flush_write()
(git fixes (block drivers)).
- bcache: fix incorrect data type usage in btree_flush_write() (git fixes
(block drivers)).
- bcache: Revert "bcache: shrink btree node cache after bch_btree_check()"
(git fixes (block drivers)).
- blk-mq: honor IO scheduler for multiqueue devices (bsc#1165478).
- blk-mq: simplify blk_mq_make_request() (bsc#1165478).
- block/drbd: delete invalid function drbd_md_mark_dirty_ (bsc#1171527).
- block: drbd: remove a stray unlock in __drbd_send_protocol()
(bsc#1171599).
- block: fix busy device checking in blk_drop_partitions again
(bsc#1171948).
- block: fix busy device checking in blk_drop_partitions (bsc#1171948).
- block: fix memleak of bio integrity data (git fixes (block drivers)).
- block: remove the bd_openers checks in blk_drop_partitions (bsc#1171948).
- bnxt_en: fix memory leaks in bnxt_dcbnl_ieee_getets()
(networking-stable-20_03_28).
- bnxt_en: Reduce BNXT_MSIX_VEC_MAX value to supported CQs per PF
(bsc#1104745).
- bnxt_en: reinitialize IRQs when MTU is modified
(networking-stable-20_03_14).
- bnxt_en: Return error if bnxt_alloc_ctx_mem() fails (bsc#1104745 ).
- bnxt_en: Return error when allocating zero size context memory
(bsc#1104745).
- bonding/alb: make sure arp header is pulled before accessing it
(networking-stable-20_03_14).
- bpf: Fix sk_psock refcnt leak when receiving message (bsc#1083647).
- bpf: Forbid XADD on spilled pointers for unprivileged users
(bsc#1083647).
- brcmfmac: abort and release host after error (bsc#1051510).
- btrfs: fix deadlock with memory reclaim during scrub (bsc#1172127).
- btrfs: fix log context list corruption after rename whiteout error
(bsc#1172342).
- btrfs: fix partial loss of prealloc extent past i_size after fsync
(bsc#1172343).
- btrfs: relocation: add error injection points for cancelling balance
(bsc#1171417).
- btrfs: relocation: Check cancel request after each data page read
(bsc#1171417).
- btrfs: relocation: Check cancel request after each extent found
(bsc#1171417).
- btrfs: relocation: Clear the DEAD_RELOC_TREE bit for orphan roots to
prevent runaway balance (bsc#1171417).
- btrfs: relocation: Fix reloc root leakage and the NULL pointer reference
caused by the leakage (bsc#1171417).
- btrfs: relocation: Work around dead relocation stage loop (bsc#1171417).
- btrfs: reloc: clear DEAD_RELOC_TREE bit for orphan roots to prevent
runaway balance (bsc#1171417 bsc#1160947 bsc#1172366).
- btrfs: reloc: fix reloc root leak and NULL pointer dereference
(bsc#1171417 bsc#1160947 bsc#1172366).
- btrfs: setup a nofs context for memory allocation at btrfs_create_tree()
(bsc#1172127).
- btrfs: setup a nofs context for memory allocation at __btrfs_set_acl
(bsc#1172127).
- btrfs: use nofs context when initializing security xattrs to avoid
deadlock (bsc#1172127).
- can: add missing attribute validation for termination
(networking-stable-20_03_14).
- cdc-acm: close race betrween suspend() and acm_softint (git-fixes).
- cdc-acm: introduce a cool down (git-fixes).
- ceph: check if file lock exists before sending unlock request
(bsc#1168789).
- ceph: demote quotarealm lookup warning to a debug message (bsc#1171692).
- ceph: fix double unlock in handle_cap_export() (bsc#1171694).
- ceph: fix endianness bug when handling MDS session feature bits
(bsc#1171695).
- cgroup, netclassid: periodically release file_lock on classid updating
(networking-stable-20_03_14).
- cifs: Allocate crypto structures on the fly for calculating signatures
of incoming packets (bsc#1144333).
- cifs: Allocate encryption header through kmalloc (bsc#1144333).
- cifs: allow unlock flock and OFD lock across fork (bsc#1144333).
- cifs: check new file size when extending file by fallocate (bsc#1144333).
- cifs: cifspdu.h: Replace zero-length array with flexible-array member
(bsc#1144333).
- cifs: clear PF_MEMALLOC before exiting demultiplex thread (bsc#1144333).
- cifs: do not share tcons with DFS (bsc#1144333).
- cifs: dump the session id and keys also for SMB2 sessions (bsc#1144333).
- cifs: ensure correct super block for DFS reconnect (bsc#1144333).
- cifs: Fix bug which the return value by asynchronous read is error
(bsc#1144333).
- cifs: fix uninitialised lease_key in open_shroot() (bsc#1144333).
- cifs: improve read performance for page size 64KB & cache=strict &
vers=2.1+ (bsc#1144333).
- cifs: Increment num_remote_opens stats counter even in case of
smb2_query_dir_first (bsc#1144333).
- cifs: minor update to comments around the cifs_tcp_ses_lock mutex
(bsc#1144333).
- cifs: protect updating server->dstaddr with a spinlock (bsc#1144333).
- cifs: smb2pdu.h: Replace zero-length array with flexible-array member
(bsc#1144333).
- cifs: smbd: Calculate the correct maximum packet size for segmented
SMBDirect send/receive (bsc#1144333).
- cifs: smbd: Check and extend sender credits in interrupt context
(bsc#1144333).
- cifs: smbd: Check send queue size before posting a send (bsc#1144333).
- cifs: smbd: Do not schedule work to send immediate packet on every
receive (bsc#1144333).
- cifs: smbd: Merge code to track pending packets (bsc#1144333).
- cifs: smbd: Properly process errors on ib_post_send (bsc#1144333).
- cifs: smbd: Update receive credits before sending and deal with credits
roll back on failure before sending (bsc#1144333).
- cifs: Warn less noisily on default mount (bsc#1144333).
- clk: Add clk_hw_unregister_composite helper function definition
(bsc#1051510).
- clk: imx6ull: use OSC clock during AXI rate change (bsc#1051510).
- clk: imx: make mux parent strings const (bsc#1051510).
- clk: mediatek: correct the clocks for MT2701 HDMI PHY module
(bsc#1051510).
- clk: sunxi-ng: a64: Fix gate bit of DSI DPHY (bsc#1051510).
- clocksource/drivers/hyper-v: Set TSC clocksource as default w/
InvariantTSC (bsc#1170620, bsc#1170621).
- clocksource: dw_apb_timer_of: Fix missing clockevent timers
(bsc#1051510).
- component: Silence bind error on -EPROBE_DEFER (bsc#1051510).
- coresight: do not use the BIT() macro in the UAPI header (git fixes
(block drivers)).
- cpufreq: s3c64xx: Remove pointless NULL check in
s3c64xx_cpufreq_driver_init (bsc#1051510).
- crypto: ccp - AES CFB mode is a stream cipher (git-fixes).
- crypto: ccp - Clean up and exit correctly on allocation failure
(git-fixes).
- crypto: ccp - Cleanup misc_dev on sev_exit() (bsc#1114279).
- crypto: ccp - Cleanup sp_dev_master in psp_dev_destroy() (bsc#1114279).
- cxgb4: fix MPS index overwrite when setting MAC address (bsc#1127355).
- cxgb4: fix Txq restart check during backpressure (bsc#1127354
bsc#1127371).
- debugfs: Add debugfs_create_xul() for hexadecimal unsigned long
(git-fixes).
- debugfs_lookup(): switch to lookup_one_len_unlocked() (bsc#1171979).
- devlink: fix return value after hitting end in region read (bsc#1109837).
- devlink: validate length of param values (bsc#1109837).
- devlink: validate length of region addr/len (bsc#1109837).
- dmaengine: dmatest: Fix iteration non-stop logic (bsc#1051510).
- dm mpath: switch paths in dm_blk_ioctl() code path (bsc#1167574).
- dm-raid1: fix invalid return value from dm_mirror (bsc#1172378).
- dm writecache: fix data corruption when reloading the target (git fixes
(block drivers)).
- dm writecache: fix incorrect flush sequence when doing SSD mode commit
(git fixes (block drivers)).
- dm writecache: verify watermark during resume (git fixes (block
drivers)).
- dm zoned: fix invalid memory access (git fixes (block drivers)).
- dm zoned: reduce overhead of backing device checks (git fixes (block
drivers)).
- dm zoned: remove duplicate nr_rnd_zones increase in dmz_init_zone() (git
fixes (block drivers)).
- dm zoned: support zone sizes smaller than 128MiB (git fixes (block
drivers)).
- dp83640: reverse arguments to list_add_tail (git-fixes).
- drivers: hv: Add a module description line to the hv_vmbus driver
(bsc#1172249, bsc#1172251).
- drivers/net/ibmvnic: Update VNIC protocol version reporting
(bsc#1065729).
- drivers: w1: add hwmon support structures (jsc#SLE-11048).
- drivers: w1: add hwmon temp support for w1_therm (jsc#SLE-11048).
- drivers: w1: refactor w1_slave_show to make the temp reading
functionality separate (jsc#SLE-11048).
- drm: amd/acp: fix broken menu structure (bsc#1114279)
- drm/amdgpu: Correctly initialize thermal controller for GPUs with
Powerplay table v0 (e.g Hawaii) (bsc#1111666).
- drm/amdgpu: Fix oops when pp_funcs is unset in ACPI event (bsc#1111666).
- drm/amd/powerplay: force the trim of the mclk dpm_levels if OD is
(bsc#1113956)
- drm/atomic: Take the atomic toys away from X (bsc#1112178) * context
changes
- drm/crc: Actually allow to change the crc source (bsc#1114279) * offset
changes
- drm/dp_mst: Fix clearing payload state on topology disable (bsc#1051510).
- drm/dp_mst: Reformat drm_dp_check_act_status() a bit (bsc#1051510).
- drm/edid: Fix off-by-one in DispID DTD pixel clock (bsc#1114279)
- drm/etnaviv: fix perfmon domain interation (bsc#1113956)
- drm/etnaviv: rework perfmon query infrastructure (bsc#1112178)
- drm/i915: Apply Wa_1406680159:icl,ehl as an engine workaround
(bsc#1112178)
- drm/i915/gvt: Init DPLL/DDI vreg for virtual display instead of
(bsc#1114279)
- drm/i915: HDCP: fix Ri prime check done during link check (bsc#1112178)
- drm/i915: properly sanity check batch_start_offset (bsc#1114279)
- drm/meson: Delete an error message in meson_dw_hdmi_bind() (bsc#1051510).
- drm: NULL pointer dereference [null-pointer-deref] (CWE 476) problem
(bsc#1114279)
- drm/qxl: qxl_release leak in qxl_draw_dirty_fb() (bsc#1051510).
- drm/qxl: qxl_release leak in qxl_hw_surface_alloc() (bsc#1051510).
- drm/qxl: qxl_release use after free (bsc#1051510).
- drm: Remove PageReserved manipulation from drm_pci_alloc (bsc#1114279)
- drm/sun4i: dsi: Allow binding the host without a panel (bsc#1113956)
- drm/sun4i: dsi: Avoid hotplug race with DRM driver bind (bsc#1113956)
- drm/sun4i: dsi: Remove incorrect use of runtime PM (bsc#1113956)
- drm/sun4i: dsi: Remove unused drv from driver context (bsc#1113956)
- dump_stack: avoid the livelock of the dump_lock (git fixes (block
drivers)).
- EDAC, sb_edac: Add support for systems with segmented PCI buses
(bsc#1169525).
- ext4: do not zeroout extents beyond i_disksize (bsc#1167851).
- ext4: fix extent_status fragmentation for plain files (bsc#1171949).
- ext4: use non-movable memory for superblock readahead (bsc#1171952).
- fanotify: fix merging marks masks with FAN_ONDIR (bsc#1171679).
- fbcon: fix null-ptr-deref in fbcon_switch (bsc#1114279)
- fib: add missing attribute validation for tun_id
(networking-stable-20_03_14).
- firmware: qcom: scm: fix compilation error when disabled (bsc#1051510).
- Fix a backport bug, where btrfs_put_root() -> btrfs_put_fs_root()
modification is not needed due to missing dependency
- Following two patches needs to be combined as one commit (one adds
context, later removes which affects existing patch) else commit series
cannot be sequenced.
- fpga: dfl: afu: Corrected error handling levels (git-fixes).
- fs/cifs: fix gcc warning in sid_to_id (bsc#1144333).
- fs/seq_file.c: simplify seq_file iteration code and interface
(bsc#1170125).
- gpio: tegra: mask GPIO IRQs during IRQ shutdown (bsc#1051510).
- gre: fix uninit-value in __iptunnel_pull_header
(networking-stable-20_03_14).
- HID: hid-input: clear unmapped usages (git-fixes).
- HID: hyperv: Add a module description line (bsc#1172249, bsc#1172251).
- HID: i2c-hid: add Trekstor Primebook C11B to descriptor override
(git-fixes).
- HID: i2c-hid: override HID descriptors for certain devices (git-fixes).
- HID: multitouch: add eGalaxTouch P80H84 support (bsc#1051510).
- HID: wacom: Read HID_DG_CONTACTMAX directly for non-generic devices
(git-fixes).
- hrtimer: Annotate lockless access to timer->state (git fixes (block
drivers)).
- hsr: add restart routine into hsr_get_node_list()
(networking-stable-20_03_28).
- hsr: check protocol version in hsr_newlink()
(networking-stable-20_04_17).
- hsr: fix general protection fault in hsr_addr_is_self()
(networking-stable-20_03_28).
- hsr: set .netnsok flag (networking-stable-20_03_28).
- hsr: use rcu_read_lock() in hsr_get_node_{list/status}()
(networking-stable-20_03_28).
- i2c: acpi: Force bus speed to 400KHz if a Silead touchscreen is present
(git-fixes).
- i2c: acpi: put device when verifying client fails (git-fixes).
- i2c: brcmstb: remove unused struct member (git-fixes).
- i2c: core: Allow empty id_table in ACPI case as well (git-fixes).
- i2c: core: decrease reference count of device node in
i2c_unregister_device (git-fixes).
- i2c: dev: Fix the race between the release of i2c_dev and cdev
(bsc#1051510).
- i2c: fix missing pm_runtime_put_sync in i2c_device_probe (git-fixes).
- i2c-hid: properly terminate i2c_hid_dmi_desc_override_table array
(git-fixes).
- i2c: i801: Do not add ICH_RES_IO_SMI for the iTCO_wdt device (git-fixes).
- i2c: iproc: Stop advertising support of SMBUS quick cmd (git-fixes).
- i2c: isch: Remove unnecessary acpi.h include (git-fixes).
- i2c: mux: demux-pinctrl: Fix an error handling path in
'i2c_demux_pinctrl_probe()' (bsc#1051510).
- i2c: st: fix missing struct parameter description (bsc#1051510).
- IB/mlx5: Fix missing congestion control debugfs on rep rdma device
(bsc#1103991).
- ibmvnic: Skip fatal error reset after passive init (bsc#1171078
ltc#184239).
- iio:ad7797: Use correct attribute_group (bsc#1051510).
- iio: adc: stm32-adc: fix device used to request dma (bsc#1051510).
- iio: adc: stm32-adc: fix sleep in atomic context (git-fixes).
- iio: adc: stm32-adc: Use dma_request_chan() instead
dma_request_slave_channel() (bsc#1051510).
- iio: dac: vf610: Fix an error handling path in 'vf610_dac_probe()'
(bsc#1051510).
- iio: sca3000: Remove an erroneous 'get_device()' (bsc#1051510).
- iio: xilinx-xadc: Fix ADC-B powerdown (bsc#1051510).
- iio: xilinx-xadc: Fix clearing interrupt when enabling trigger
(bsc#1051510).
- iio: xilinx-xadc: Fix sequencer configuration for aux channels in
simultaneous mode (bsc#1051510).
- ima: Fix return value of ima_write_policy() (git-fixes).
- input: evdev - call input_flush_device() on release(), not flush()
(bsc#1051510).
- input: hyperv-keyboard - add module description (bsc#1172249,
bsc#1172251).
- input: i8042 - add Acer Aspire 5738z to nomux list (bsc#1051510).
- input: i8042 - add ThinkPad S230u to i8042 reset list (bsc#1051510).
- input: raydium_i2c_ts - use true and false for boolean values
(bsc#1051510).
- input: synaptics-rmi4 - fix error return code in rmi_driver_probe()
(bsc#1051510).
- input: synaptics-rmi4 - really fix attn_data use-after-free (git-fixes).
- input: usbtouchscreen - add support for BonXeon TP (bsc#1051510).
- input: xpad - add custom init packet for Xbox One S controllers
(bsc#1051510).
- iommu/amd: Call domain_flush_complete() in update_domain() (bsc#1172096).
- iommu/amd: Do not flush Device Table in iommu_map_page() (bsc#1172097).
- iommu/amd: Do not loop forever when trying to increase address space
(bsc#1172098).
- iommu/amd: Fix legacy interrupt remapping for x2APIC-enabled system
(bsc#1172099).
- iommu/amd: Fix over-read of ACPI UID from IVRS table (bsc#1172101).
- iommu/amd: Fix race in increase_address_space()/fetch_pte()
(bsc#1172102).
- iommu/amd: Update Device Table in increase_address_space() (bsc#1172103).
- iommu: Fix reference count leak in iommu_group_alloc (bsc#1172397).
- ip6_tunnel: Allow rcv/xmit even if remote address is a local address
(bsc#1166978).
- ipmi: fix hung processes in __get_guid() (git-fixes).
- ipv4: fix a RCU-list lock in fib_triestat_seq_show
(networking-stable-20_04_02).
- ipv6/addrconf: call ipv6_mc_up() for non-Ethernet interface
(networking-stable-20_03_14).
- ipv6: do not auto-add link-local address to lag ports
(networking-stable-20_04_09).
- ipv6: fix IPV6_ADDRFORM operation logic (bsc#1171662).
- ipv6: Fix nlmsg_flags when splitting a multipath route
(networking-stable-20_03_01).
- ipv6: fix restrict IPV6_ADDRFORM operation (bsc#1171662).
- ipv6: Fix route replacement with dev-only route
(networking-stable-20_03_01).
- ipvlan: add cond_resched_rcu() while processing muticast backlog
(networking-stable-20_03_14).
- ipvlan: do not deref eth hdr before checking it's set
(networking-stable-20_03_14).
- ipvlan: do not use cond_resched_rcu() in ipvlan_process_multicast()
(networking-stable-20_03_14).
- iwlwifi: pcie: actually release queue memory in TVQM (bsc#1051510).
- ixgbe: do not check firmware errors (bsc#1170284).
- kABI fix for early XHCI debug (git-fixes).
- kabi for for md: improve handling of bio with REQ_PREFLUSH in
md_flush_request() (git-fixes).
- kabi/severities: Do not track KVM internal symbols.
- kabi/severities: Ingnore get_dev_data() The function is internal to the
AMD IOMMU driver and must not be called by any third party.
- kABI workaround for snd_rawmidi buffer_ref field addition (git-fixes).
- keys: reaching the keys quotas correctly (bsc#1051510).
- KVM: arm64: Change hyp_panic()s dependency on tpidr_el2 (bsc#1133021).
- KVM: arm64: Stop save/restoring host tpidr_el1 on VHE (bsc#1133021).
- KVM: Check validity of resolved slot when searching memslots
(bsc#1172104).
- KVM: s390: vsie: Fix delivery of addressing exceptions (git-fixes).
- KVM: s390: vsie: Fix possible race when shadowing region 3 tables
(git-fixes).
- KVM: s390: vsie: Fix region 1 ASCE sanity shadow address checks
(git-fixes).
- KVM: SVM: Fix potential memory leak in svm_cpu_init() (bsc#1171736).
- KVM x86: Extend AMD specific guest behavior to Hygon virtual CPUs
(bsc#1152489).
- l2tp: Allow management of tunnels and session in user namespace
(networking-stable-20_04_17).
- libata: Remove extra scsi_host_put() in ata_scsi_add_hosts()
(bsc#1051510).
- libata: Return correct status in sata_pmp_eh_recover_pm() when
ATA_DFLAG_DETACH is set (bsc#1051510).
- lib: raid6: fix awk build warnings (git fixes (block drivers)).
- lib/raid6/test: fix build on distros whose /bin/sh is not bash (git
fixes (block drivers)).
- lib/stackdepot.c: fix global out-of-bounds in stack_slabs (git fixes
(block drivers)).
- locks: print unsigned ino in /proc/locks (bsc#1171951).
- mac80211: add ieee80211_is_any_nullfunc() (bsc#1051510).
- mac80211_hwsim: Use kstrndup() in place of kasprintf() (bsc#1051510).
- mac80211: mesh: fix discovery timer re-arming issue / crash
(bsc#1051510).
- macsec: avoid to set wrong mtu (bsc#1051510).
- macsec: restrict to ethernet devices (networking-stable-20_03_28).
- macvlan: add cond_resched() during multicast processing
(networking-stable-20_03_14).
- macvlan: fix null dereference in macvlan_device_event() (bsc#1051510).
- md: improve handling of bio with REQ_PREFLUSH in md_flush_request()
(git-fixes).
- md/raid0: Fix an error message in raid0_make_request() (git fixes (block
drivers)).
- md/raid10: prevent access of uninitialized resync_pages offset
(git-fixes).
- media: dvb: return -EREMOTEIO on i2c transfer failure (bsc#1051510).
- media: platform: fcp: Set appropriate DMA parameters (bsc#1051510).
- media: ti-vpe: cal: fix disable_irqs to only the intended target
(git-fixes).
- mei: release me_cl object reference (bsc#1051510).
- mlxsw: Fix some IS_ERR() vs NULL bugs (networking-stable-20_04_27).
- mlxsw: spectrum_flower: Do not stop at FLOW_ACTION_VLAN_MANGLE
(networking-stable-20_04_09).
- mlxsw: spectrum_mr: Fix list iteration in error path (bsc#1112374).
- mmc: atmel-mci: Fix debugfs on 64-bit platforms (git-fixes).
- mmc: core: Check request type before completing the request (git-fixes).
- mmc: core: Fix recursive locking issue in CQE recovery path (git-fixes).
- mmc: cqhci: Avoid false "cqhci: CQE stuck on" by not open-coding timeout
loop (git-fixes).
- mmc: dw_mmc: Fix debugfs on 64-bit platforms (git-fixes).
- mmc: meson-gx: make sure the descriptor is stopped on errors (git-fixes).
- mmc: meson-gx: simplify interrupt handler (git-fixes).
- mmc: renesas_sdhi: limit block count to 16 bit for old revisions
(git-fixes).
- mmc: sdhci-esdhc-imx: fix the mask for tuning start point (bsc#1051510).
- mmc: sdhci-msm: Clear tuning done flag while hs400 tuning (bsc#1051510).
- mmc: sdhci-of-at91: fix memleak on clk_get failure (git-fixes).
- mmc: sdhci-pci: Fix eMMC driver strength for BYT-based controllers
(bsc#1051510).
- mmc: sdhci: Update the tuning failed messages to pr_debug level
(git-fixes).
- mmc: sdhci-xenon: fix annoying 1.8V regulator warning (bsc#1051510).
- mmc: sdio: Fix potential NULL pointer error in mmc_sdio_init_card()
(bsc#1051510).
- mmc: tmio: fix access width of Block Count Register (git-fixes).
- mm: limit boost_watermark on small zones (git fixes (mm/pgalloc)).
- mm: thp: handle page cache THP correctly in PageTransCompoundMap (git
fixes (block drivers)).
- mtd: cfi: fix deadloop in cfi_cmdset_0002.c do_write_buffer
(bsc#1051510).
- mtd: spi-nor: cadence-quadspi: add a delay in write sequence (git-fixes).
- mtd: spi-nor: enable 4B opcodes for mx66l51235l (git-fixes).
- mtd: spi-nor: fsl-quadspi: Do not let -EINVAL on the bus (git-fixes).
- mwifiex: avoid -Wstringop-overflow warning (bsc#1051510).
- mwifiex: Fix memory corruption in dump_station (bsc#1051510).
- net: bcmgenet: correct per TX/RX ring statistics
(networking-stable-20_04_27).
- net: dsa: b53: Fix ARL register definitions (networking-stable-20_04_27).
- net: dsa: b53: Rework ARL bin logic (networking-stable-20_04_27).
- net: dsa: bcm_sf2: Do not register slave MDIO bus with OF
(networking-stable-20_04_09).
- net: dsa: bcm_sf2: Ensure correct sub-node is parsed
(networking-stable-20_04_09).
- net: dsa: bcm_sf2: Fix overflow checks (git-fixes).
- net: dsa: Fix duplicate frames flooded by learning
(networking-stable-20_03_28).
- net: dsa: mv88e6xxx: fix lockup on warm boot
(networking-stable-20_03_14).
- net/ethernet: add Google GVE driver (jsc#SLE-10538)
- net: fec: add phy_reset_after_clk_enable() support (git-fixes).
- net: fec: validate the new settings in fec_enet_set_coalesce()
(networking-stable-20_03_14).
- net: fib_rules: Correctly set table field when table number exceeds 8
bits (networking-stable-20_03_01).
- net: fix race condition in __inet_lookup_established() (bsc#1151794).
- net: fq: add missing attribute validation for orphan mask
(networking-stable-20_03_14).
- net: hns3: fix "tc qdisc del" failed issue (bsc#1109837).
- net, ip_tunnel: fix interface lookup with no key
(networking-stable-20_04_02).
- net: ipv4: devinet: Fix crash when add/del multicast IP with autojoin
(networking-stable-20_04_17).
- net: ipv6: do not consider routes via gateways for anycast address check
(networking-stable-20_04_17).
- netlink: Use netlink header as base to calculate bad attribute offset
(networking-stable-20_03_14).
- net: macsec: update SCI upon MAC address change
(networking-stable-20_03_14).
- net: memcg: fix lockdep splat in inet_csk_accept()
(networking-stable-20_03_14).
- net: memcg: late association of sock to memcg
(networking-stable-20_03_14).
- net/mlx4_en: avoid indirect call in TX completion
(networking-stable-20_04_27).
- net/mlx5: Add new fields to Port Type and Speed register (bsc#1171118).
- net/mlx5: Expose link speed directly (bsc#1171118).
- net/mlx5: Expose port speed when possible (bsc#1171118).
- net/mlx5: Fix failing fw tracer allocation on s390 (bsc#1103990 ).
- net: mvneta: Fix the case where the last poll did not process all rx
(networking-stable-20_03_28).
- net: netrom: Fix potential nr_neigh refcnt leak in nr_add_node
(networking-stable-20_04_27).
- net/packet: tpacket_rcv: do not increment ring index on drop
(networking-stable-20_03_14).
- net: phy: restore mdio regs in the iproc mdio driver
(networking-stable-20_03_01).
- net: qmi_wwan: add support for ASKEY WWHC050
(networking-stable-20_03_28).
- net: revert default NAPI poll timeout to 2 jiffies
(networking-stable-20_04_17).
- net_sched: cls_route: remove the right filter from hashtable
(networking-stable-20_03_28).
- net_sched: sch_skbprio: add message validation to skbprio_change()
(bsc#1109837).
- net/x25: Fix x25_neigh refcnt leak when receiving frame
(networking-stable-20_04_27).
- nfc: add missing attribute validation for SE API
(networking-stable-20_03_14).
- nfc: add missing attribute validation for vendor subcommand
(networking-stable-20_03_14).
- nfc: pn544: Fix occasional HW initialization failure
(networking-stable-20_03_01).
- NFC: st21nfca: add missed kfree_skb() in an error path (bsc#1051510).
- nfp: abm: fix a memory leak bug (bsc#1109837).
- nfsd4: fix up replay_matches_cache() (git-fixes).
- nfsd: Ensure CLONE persists data and metadata changes to the target file
(git-fixes).
- nfsd: fix delay timer on 32-bit architectures (git-fixes).
- nfsd: fix jiffies/time_t mixup in LRU list (git-fixes).
- nfs: Directory page cache pages need to be locked when read (git-fixes).
- nfsd: memory corruption in nfsd4_lock() (git-fixes).
- nfs: Do not call generic_error_remove_page() while holding locks
(bsc#1170457).
- nfs: Fix memory leaks and corruption in readdir (git-fixes).
- nfs: Fix O_DIRECT accounting of number of bytes read/written (git-fixes).
- nfs: Fix potential posix_acl refcnt leak in nfs3_set_acl (git-fixes).
- nfs: fix racey wait in nfs_set_open_stateid_locked (bsc#1170592).
- NFS/flexfiles: Use the correct TCP timeout for flexfiles I/O (git-fixes).
- NFS/pnfs: Fix pnfs_generic_prepare_to_resend_writes() (git-fixes).
- nfs: Revalidate the file size on a fatal write error (git-fixes).
- NFSv4.0: nfs4_do_fsinfo() should not do implicit lease renewals
(git-fixes).
- NFSv4: Do not allow a cached open with a revoked delegation (git-fixes).
- NFSv4: Fix leak of clp->cl_acceptor string (git-fixes).
- NFSv4-Fix-OPEN-CLOSE-race.patch
- NFSv4/pnfs: Return valid stateids in nfs_layout_find_inode_by_stateid()
(git-fixes).
- NFSv4: try lease recovery on NFS4ERR_EXPIRED (git-fixes).
- NFSv4.x: Drop the slot if nfs4_delegreturn_prepare waits for
layoutreturn (git-fixes).
- nl802154: add missing attribute validation for dev_type
(networking-stable-20_03_14).
- nl802154: add missing attribute validation (networking-stable-20_03_14).
- nvme-fc: print proper nvme-fc devloss_tmo value (bsc#1172391).
- objtool: Fix stack offset tracking for indirect CFAs (bsc#1169514).
- objtool: Fix switch table detection in .text.unlikely (bsc#1169514).
- objtool: Make BP scratch register warning more robust (bsc#1169514).
- padata: Remove broken queue flushing (git-fixes).
- Partially revert "kfifo: fix kfifo_alloc() and kfifo_init()" (git fixes
(block drivers)).
- PCI: hv: Add support for protocol 1.3 and support PCI_BUS_RELATIONS2
(bsc#1172201, bsc#1172202).
- PCI: hv: Decouple the func definition in hv_dr_state from VSP message
(bsc#1172201, bsc#1172202).
- PCI/PM: Call .bridge_d3() hook only if non-NULL (git-fixes).
- perf: Allocate context task_ctx_data for child event (git-fixes).
- perf/cgroup: Fix perf cgroup hierarchy support (git-fixes).
- perf: Copy parent's address filter offsets on clone (git-fixes).
- perf/core: Add sanity check to deal with pinned event failure
(git-fixes).
- perf/core: Avoid freeing static PMU contexts when PMU is unregistered
(git-fixes).
- perf/core: Correct event creation with PERF_FORMAT_GROUP (git-fixes).
- perf/core: Do not WARN() for impossible ring-buffer sizes (git-fixes).
- perf/core: Fix ctx_event_type in ctx_resched() (git-fixes).
- perf/core: Fix error handling in perf_event_alloc() (git-fixes).
- perf/core: Fix exclusive events' grouping (git-fixes).
- perf/core: Fix group scheduling with mixed hw and sw events (git-fixes).
- perf/core: Fix impossible ring-buffer sizes warning (git-fixes).
- perf/core: Fix locking for children siblings group read (git-fixes).
- perf/core: Fix lock inversion between perf,trace,cpuhp (git-fixes
(dependent patch for 18736eef1213)).
- perf/core: Fix perf_event_read_value() locking (git-fixes).
- perf/core: Fix perf_pmu_unregister() locking (git-fixes).
- perf/core: Fix __perf_read_group_add() locking (git-fixes (dependent
patch)).
- perf/core: Fix perf_sample_regs_user() mm check (git-fixes).
- perf/core: Fix possible Spectre-v1 indexing for ->aux_pages (git-fixes).
- perf/core: Fix race between close() and fork() (git-fixes).
- perf/core: Fix the address filtering fix (git-fixes).
- perf/core: Fix use-after-free in uprobe_perf_close() (git-fixes).
- perf/core: Force USER_DS when recording user stack data (git-fixes).
- perf/core: Restore mmap record type correctly (git-fixes).
- perf: Fix header.size for namespace events (git-fixes).
- perf/ioctl: Add check for the sample_period value (git-fixes).
- perf, pt, coresight: Fix address filters for vmas with non-zero offset
(git-fixes).
- perf: Return proper values for user stack errors (git-fixes).
- pinctrl: baytrail: Enable pin configuration setting for GPIO chip
(git-fixes).
- pinctrl: cherryview: Add missing spinlock usage in chv_gpio_irq_handler
(git-fixes).
- pinctrl: sunrisepoint: Fix PAD lock register offset for SPT-H
(git-fixes).
- platform/x86: asus-nb-wmi: Do not load on Asus T100TA and T200TA
(bsc#1051510).
- pnfs: Ensure we do clear the return-on-close layout stateid on fatal
errors (git-fixes).
- powerpc: Add attributes for setjmp/longjmp (bsc#1065729).
- powerpc/pci/of: Parse unassigned resources (bsc#1065729).
- powerpc/setup_64: Set cache-line-size based on cache-block-size
(bsc#1065729).
- powerpc/sstep: Fix DS operand in ld encoding to appropriate value
(bsc#1065729).
- qede: Fix race between rdma destroy workqueue and link change event
(networking-stable-20_03_01).
- r8152: check disconnect status after long sleep
(networking-stable-20_03_14).
- raid6/ppc: Fix build for clang (git fixes (block drivers)).
- random: always use batched entropy for get_random_u{32,64} (bsc#1164871).
- rcu: locking and unlocking need to always be at least barriers (git
fixes (block drivers)).
- Redo patch for SLE15-SP1, based on feedback from IBM:
patches.suse/s390-ftrace-fix-potential-crashes-when-switching-tracers
(bsc#1171244 LTC#185785 git-fixes).
- resolve KABI warning for perf-pt-coresight (git-fixes).
- Revert "ALSA: hda/realtek: Fix pop noise on ALC225" (git-fixes).
- Revert "drm/panel: simple: Add support for Sharp LQ150X1LG11 panels"
(bsc#1114279) * offset changes
- Revert "HID: i2c-hid: add Trekstor Primebook C11B to descriptor
override" Depends on 9b5c747685982d22efffeafc5ec601bd28f6d78b, which was
also reverted.
- Revert "HID: i2c-hid: override HID descriptors for certain devices" This
broke i2c-hid.ko's build, there is no way around it without a big file
rename or renaming the kernel module.
- Revert "i2c-hid: properly terminate i2c_hid_dmi_desc_override_table"
Fixed 9b5c747685982d22efffeafc5ec601bd28f6d78b, which was also reverted.
- Revert "ipc,sem: remove uneeded sem_undo_list lock usage in exit_sem()"
(bsc#1172221).
- Revert "RDMA/cma: Simplify rdma_resolve_addr() error flow" (bsc#1103992).
- rtlwifi: Fix a double free in _rtl_usb_tx_urb_setup() (bsc#1051510).
- s390/cio: avoid duplicated 'ADD' uevents (git-fixes).
- s390/cio: generate delayed uevent for vfio-ccw subchannels (git-fixes).
- s390/cpuinfo: fix wrong output when CPU0 is offline (git-fixes).
- s390/cpum_cf: Add new extended counters for IBM z15 (bsc#1169762
LTC#185291).
- s390/diag: fix display of diagnose call statistics (git-fixes).
- s390/ftrace: fix potential crashes when switching tracers (git-fixes).
- s390/gmap: return proper error code on ksm unsharing (git-fixes).
- s390/ism: fix error return code in ism_probe() (git-fixes).
- s390/pci: do not set affinity for floating irqs (git-fixes).
- s390/pci: Fix possible deadlock in recover_store() (bsc#1165183
LTC#184103).
- s390/pci: Recover handle in clp_set_pci_fn() (bsc#1165183 LTC#184103).
- s390/qeth: cancel RX reclaim work earlier (git-fixes).
- s390/qeth: do not return -ENOTSUPP to userspace (git-fixes).
- s390/qeth: do not warn for napi with 0 budget (git-fixes).
- s390/qeth: fix off-by-one in RX copybreak check (git-fixes).
- s390/qeth: fix promiscuous mode after reset (git-fixes).
- s390/qeth: fix qdio teardown after early init error (git-fixes).
- s390/qeth: handle error due to unsupported transport mode (git-fixes).
- s390/qeth: handle error when backing RX buffer (git-fixes).
- s390/qeth: lock the card while changing its hsuid (git-fixes).
- s390/qeth: support net namespaces for L3 devices (git-fixes).
- s390/time: Fix clk type in get_tod_clock (git-fixes).
- scripts/decodecode: fix trapping instruction formatting (bsc#1065729).
- scripts/dtc: Remove redundant YYLOC global declaration (bsc#1160388).
- scsi: bnx2i: fix potential use after free (bsc#1171600).
- scsi: core: Handle drivers which set sg_tablesize to zero (bsc#1171601)
- scsi: core: save/restore command resid for error handling (bsc#1171602).
- scsi: core: scsi_trace: Use get_unaligned_be*() (bsc#1171604).
- scsi: core: try to get module before removing device (bsc#1171605).
- scsi: csiostor: Adjust indentation in csio_device_reset (bsc#1171606).
- scsi: csiostor: Do not enable IRQs too early (bsc#1171607).
- scsi: esas2r: unlock on error in esas2r_nvram_read_direct()
(bsc#1171608).
- scsi: fnic: fix invalid stack access (bsc#1171609).
- scsi: fnic: fix msix interrupt allocation (bsc#1171610).
- scsi-ibmvfc-Don-t-send-implicit-logouts-prior-to-NPI.patch
- scsi: ibmvscsi: Fix WARN_ON during event pool release (bsc#1170791
ltc#185128).
- scsi-ibmvscsi-Fix-WARN_ON-during-event-pool-release.patch
- scsi: iscsi: Avoid potential deadlock in iscsi_if_rx func (bsc#1171611).
- scsi: iscsi: Fix a potential deadlock in the timeout handler
(bsc#1171612).
- scsi: iscsi: qla4xxx: fix double free in probe (bsc#1171613).
- scsi: lpfc: Change default queue allocation for reduced memory
consumption (bsc#1164780).
- scsi: lpfc: fix: Coverity: lpfc_cmpl_els_rsp(): Null pointer
dereferences (bsc#1171614).
- scsi: lpfc: Fix crash in target side cable pulls hitting WAIT_FOR_UNREG
(bsc#1171615).
- scsi: lpfc: Fix lpfc_nodelist leak when processing unsolicited event
(bsc#1164780).
- scsi: lpfc: Fix MDS Diagnostic Enablement definition (bsc#1164780).
- scsi: lpfc: Fix negation of else clause in lpfc_prep_node_fc4type
(bsc#1164780).
- scsi: lpfc: Fix noderef and address space warnings (bsc#1164780).
- scsi: lpfc: Maintain atomic consistency of queue_claimed flag
(bsc#1164780).
- scsi: lpfc: remove duplicate unloading checks (bsc#1164780).
- scsi: lpfc: Remove re-binding of nvme rport during registration
(bsc#1164780).
- scsi: lpfc: Remove redundant initialization to variable rc (bsc#1164780).
- scsi: lpfc: Remove unnecessary lockdep_assert_held calls (bsc#1164780).
- scsi: lpfc: Update lpfc version to 12.8.0.1 (bsc#1164780).
- scsi: megaraid_sas: Do not initiate OCR if controller is not in ready
state (bsc#1171616).
- scsi: qla2xxx: add ring buffer for tracing debug logs (bsc#1157169).
- scsi-qla2xxx-check-UNLOADING-before-posting-async-wo.patch
- scsi: qla2xxx: check UNLOADING before posting async work (bsc#1157169).
- scsi: qla2xxx: Delete all sessions before unregister local nvme port
(bsc#1157169).
- scsi: qla2xxx: Do not log message when reading port speed via sysfs
(bsc#1157169).
- scsi: qla2xxx: Fix hang when issuing nvme disconnect-all in NPIV
(bsc#1157169).
- scsi: qla2xxx: Fix regression warnings (bsc#1157169).
- scsi: qla2xxx: Remove non functional code (bsc#1157169).
- scsi: qla2xxx: set UNLOADING before waiting for session deletion
(bsc#1157169).
- scsi-qla2xxx-set-UNLOADING-before-waiting-for-sessio.patch
- scsi: qla4xxx: Adjust indentation in qla4xxx_mem_free (bsc#1171617).
- scsi: qla4xxx: fix double free bug (bsc#1171618).
- scsi: sd: Clear sdkp->protection_type if disk is reformatted without PI
(bsc#1171619).
- scsi: sg: add sg_remove_request in sg_common_write (bsc#1171620).
- scsi: tracing: Fix handling of TRANSFER LENGTH == 0 for READ(6) and
WRITE(6) (bsc#1171621).
- scsi: ufs: change msleep to usleep_range (bsc#1171622).
- scsi: ufs: Clean up ufshcd_scale_clks() and clock scaling error out path
(bsc#1171623).
- scsi: ufs: Fix ufshcd_hold() caused scheduling while atomic
(bsc#1171624).
- scsi: ufs: Fix ufshcd_probe_hba() reture value in case
ufshcd_scsi_add_wlus() fails (bsc#1171625).
- scsi: ufs: Recheck bkops level if bkops is disabled (bsc#1171626).
- scsi: zfcp: fix missing erp_lock in port recovery trigger for
point-to-point (git-fixes).
- sctp: fix possibly using a bad saddr with a given dst
(networking-stable-20_04_02).
- sctp: fix refcount bug in sctp_wfree (networking-stable-20_04_02).
- sctp: move the format error check out of __sctp_sf_do_9_1_abort
(networking-stable-20_03_01).
- selftests/powerpc: Fix build errors in powerpc ptrace selftests
(boo#1124278).
- seq_file: fix problem when seeking mid-record (bsc#1170125).
- serial: uartps: Move the spinlock after the read of the tx empty
(git-fixes).
- sfc: detach from cb_page in efx_copy_channel()
(networking-stable-20_03_14).
- signal/pid_namespace: Fix reboot_pid_ns to use send_sig not force_sig
(bsc#1172185).
- slcan: not call free_netdev before rtnl_unlock in slcan_open
(networking-stable-20_03_28).
- slip: make slhc_compress() more robust against malicious packets
(networking-stable-20_03_14).
- smb3: Additional compression structures (bsc#1144333).
- smb3: Add new compression flags (bsc#1144333).
- smb3: change noisy error message to FYI (bsc#1144333).
- smb3: enable swap on SMB3 mounts (bsc#1144333).
- smb3-fix-performance-regression-with-setting-mtime.patch
- smb3: Minor cleanup of protocol definitions (bsc#1144333).
- smb3: remove overly noisy debug line in signing errors (bsc#1144333).
- smb3: smbdirect support can be configured by default (bsc#1144333).
- smb3: use SMB2_SIGNATURE_SIZE define (bsc#1144333).
- spi: bcm2835: Fix 3-wire mode if DMA is enabled (git-fixes).
- spi: bcm63xx-hsspi: Really keep pll clk enabled (bsc#1051510).
- spi: bcm-qspi: when tx/rx buffer is NULL set to 0 (bsc#1051510).
- spi: dw: Add SPI Rx-done wait method to DMA-based transfer (bsc#1051510).
- spi: dw: Add SPI Tx-done wait method to DMA-based transfer (bsc#1051510).
- spi: dw: Zero DMA Tx and Rx configurations on stack (bsc#1051510).
- spi: fsl: do not map irq during probe (git-fixes).
- spi: fsl: use platform_get_irq() instead of of_irq_to_resource()
(git-fixes).
- spi: pxa2xx: Add CS control clock quirk (bsc#1051510).
- spi: qup: call spi_qup_pm_resume_runtime before suspending (bsc#1051510).
- spi: spi-fsl-dspi: Replace interruptible wait queue with a simple
completion (git-fixes).
- spi: spi-s3c64xx: Fix system resume support (git-fixes).
- spi/zynqmp: remove entry that causes a cs glitch (bsc#1051510).
- staging: comedi: dt2815: fix writing hi byte of analog output
(bsc#1051510).
- staging: comedi: Fix comedi_device refcnt leak in comedi_open
(bsc#1051510).
- staging: iio: ad2s1210: Fix SPI reading (bsc#1051510).
- staging: vt6656: Do not set RCR_MULTICAST or RCR_BROADCAST by default
(git-fixes).
- staging: vt6656: Fix drivers TBTT timing counter (git-fixes).
- staging: vt6656: Fix pairwise key entry save (git-fixes).
- sunrpc: expiry_time should be seconds not timeval (git-fixes).
- sunrpc: Fix a potential buffer overflow in 'svc_print_xprts()'
(git-fixes).
- supported.conf: Add br_netfilter to base (bsc#1169020).
- supported.conf: support w1 core and thermometer support
- svcrdma: Fix double svc_rdma_send_ctxt_put() in an error path
(bsc#1103992).
- svcrdma: Fix leak of transport addresses (git-fixes).
- svcrdma: Fix trace point use-after-free race (bsc#1103992 ).
- taskstats: fix data-race (bsc#1172188).
- tcp: cache line align MAX_TCP_HEADER (networking-stable-20_04_27).
- tcp: repair: fix TCP_QUEUE_SEQ implementation
(networking-stable-20_03_28).
- team: add missing attribute validation for array index
(networking-stable-20_03_14).
- team: add missing attribute validation for port ifindex
(networking-stable-20_03_14).
- team: fix hang in team_mode_get() (networking-stable-20_04_27).
- tools lib traceevent: Remove unneeded qsort and uses memmove instead
(git-fixes).
- tpm: ibmvtpm: retry on H_CLOSED in tpm_ibmvtpm_send() (bsc#1065729).
- tpm/tpm_tis: Free IRQ if probing fails (bsc#1082555).
- tpm/tpm_tis: Free IRQ if probing fails (git-fixes).
- tracing: Add a vmalloc_sync_mappings() for safe measure (git-fixes).
- tracing: Disable trace_printk() on post poned tests (git-fixes).
- tracing: Fix the race between registering 'snapshot' event trigger and
triggering 'snapshot' operation (git-fixes).
- tty: rocket, avoid OOB access (git-fixes).
- tun: Do not put_page() for all negative return values from XDP program
(bsc#1109837).
- UAS: fix deadlock in error handling and PM flushing work (git-fixes).
- UAS: no use logging any details in case of ENODEV (git-fixes).
- Update config files: Build w1 bus on arm64 (jsc#SLE-11048)
- Update config files: re-enable CONFIG_HAMRADIO and co (bsc#1170740)
- Update
patches.suse/powerpc-pseries-ddw-Extend-upper-limit-for-huge-DMA-.patch
(bsc#1142685 bsc#1167867 ltc#179509 ltc#184616).
- Update patches.suse/x86-mm-split-vmalloc_sync_all.patch (bsc#1165741,
bsc#1166969).
- Update references:
patches.suse/s390-pci-do-not-set-affinity-for-floating-irqs (bsc#1171817
LTC#185819 git-fixes).
- usb: Add USB_QUIRK_DELAY_CTRL_MSG and USB_QUIRK_DELAY_INIT for Corsair
K70 RGB RAPIDFIRE (git-fixes).
- usb: cdc-acm: restore capability check order (git-fixes).
- usb: core: Fix misleading driver bug report (bsc#1051510).
- usb: dwc3: do not set gadget->is_otg flag (git-fixes).
- usb: dwc3: gadget: Do link recovery for SS and SSP (git-fixes).
- usb: early: Handle AMD's spec-compliant identifiers, too (git-fixes).
- usb: f_fs: Clear OS Extended descriptor counts to zero in
ffs_data_reset() (git-fixes).
- usb: gadget: audio: Fix a missing error return value in audio_bind()
(git-fixes).
- usb: gadget: composite: Inform controller driver of self-powered
(git-fixes).
- usb: gadget: legacy: fix error return code in cdc_bind() (git-fixes).
- usb: gadget: legacy: fix error return code in gncm_bind() (git-fixes).
- usb: gadget: legacy: fix redundant initialization warnings (bsc#1051510).
- usb: gadget: net2272: Fix a memory leak in an error handling path in
'net2272_plat_probe()' (git-fixes).
- usb: gadget: udc: atmel: Fix vbus disconnect handling (git-fixes).
- usb: gadget: udc: atmel: Make some symbols static (git-fixes).
- usb: gadget: udc: bdc: Remove unnecessary NULL checks in
bdc_req_complete (git-fixes).
- usb: host: xhci-plat: keep runtime active when removing host (git-fixes).
- usb: hub: Fix handling of connect changes during sleep (git-fixes).
- usbnet: silence an unnecessary warning (bsc#1170770).
- usb: serial: garmin_gps: add sanity checking for data length (git-fixes).
- usb: serial: option: add BroadMobi BM806U (git-fixes).
- usb: serial: option: add support for ASKEY WWHC050 (git-fixes).
- usb: serial: option: add Wistron Neweb D19Q1 (git-fixes).
- usb: serial: qcserial: Add DW5816e support (git-fixes).
- usb: sisusbvga: Change port variable from signed to unsigned (git-fixes).
- usb-storage: Add unusual_devs entry for JMicron JMS566 (git-fixes).
- usb: uas: add quirk for LaCie 2Big Quadra (git-fixes).
- usb: xhci: Fix NULL pointer dereference when enqueuing trbs from urb sg
list (git-fixes).
- video: fbdev: sis: Remove unnecessary parentheses and commented code
(bsc#1114279)
- video: fbdev: w100fb: Fix a potential double free (bsc#1051510).
- vrf: Check skb for XFRM_TRANSFORMED flag (networking-stable-20_04_27).
- vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines (git-fixes).
- vt: selection, introduce vc_is_sel (git-fixes).
- vt: vt_ioctl: fix race in VT_RESIZEX (git-fixes).
- vt: vt_ioctl: fix use-after-free in vt_in_use() (git-fixes).
- vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console
(git-fixes).
- vxlan: check return value of gro_cells_init()
(networking-stable-20_03_28).
- w1: Add subsystem kernel public interface (jsc#SLE-11048).
- w1: Fix slave count on 1-Wire bus (resend) (jsc#SLE-11048).
- w1: keep balance of mutex locks and refcnts (jsc#SLE-11048).
- w1: use put_device() if device_register() fail (jsc#SLE-11048).
- watchdog: reset last_hw_keepalive time at start (git-fixes).
- wcn36xx: Fix error handling path in 'wcn36xx_probe()' (bsc#1051510).
- wil6210: remove reset file from debugfs (git-fixes).
- wimax/i2400m: Fix potential urb refcnt leak (bsc#1051510).
- workqueue: do not use wq_select_unbound_cpu() for bound works
(bsc#1172130).
- x86/entry/64: Fix unwind hints in kernel exit path (bsc#1058115).
- x86/entry/64: Fix unwind hints in register clearing code (bsc#1058115).
- x86/entry/64: Fix unwind hints in rewind_stack_do_exit() (bsc#1058115).
- x86/entry/64: Fix unwind hints in __switch_to_asm() (bsc#1058115).
- x86/hyperv: Allow guests to enable InvariantTSC (bsc#1170621,
bsc#1170620).
- x86/Hyper-V: Free hv_panic_page when fail to register kmsg dump
(bsc#1170617, bsc#1170618).
- x86/Hyper-V: Report crash data in die() when panic_on_oops is set
(bsc#1170617, bsc#1170618).
- x86/Hyper-V: Report crash register data or kmsg before running crash
kernel (bsc#1170617, bsc#1170618).
- x86/Hyper-V: Report crash register data when sysctl_record_panic_msg is
not set (bsc#1170617, bsc#1170618).
- x86: hyperv: report value of misc_features (git fixes).
- x86/Hyper-V: Trigger crash enlightenment only once during system crash
(bsc#1170617, bsc#1170618).
- x86/Hyper-V: Unload vmbus channel in hv panic callback (bsc#1170617,
bsc#1170618).
- x86/kprobes: Avoid kretprobe recursion bug (bsc#1114279).
- x86/resctrl: Fix invalid attempt at removing the default resource group
(git-fixes).
- x86/resctrl: Preserve CDP enable over CPU hotplug (bsc#1114279).
- x86/unwind/orc: Do not skip the first frame for inactive tasks
(bsc#1058115).
- x86/unwind/orc: Fix error handling in __unwind_start() (bsc#1058115).
- x86/unwind/orc: Fix error path for bad ORC entry type (bsc#1058115).
- x86/unwind/orc: Fix unwind_get_return_address_ptr() for inactive tasks
(bsc#1058115).
- x86/unwind/orc: Prevent unwinding before ORC initialization
(bsc#1058115).
- x86/unwind: Prevent false warnings for non-current tasks (bsc#1058115).
- x86/xen: fix booting 32-bit pv guest (bsc#1071995).
- x86/xen: Make the boot CPU idle task reliable (bsc#1071995).
- x86/xen: Make the secondary CPU idle tasks reliable (bsc#1071995).
- xen/pci: reserve MCFG areas earlier (bsc#1170145).
- xfrm: Always set XFRM_TRANSFORMED in xfrm{4,6}_output_finish
(networking-stable-20_04_27).
- xfs: clear PF_MEMALLOC before exiting xfsaild thread (git-fixes).
- xfs: Correctly invert xfs_buftarg LRU isolation logic (git-fixes).
- xfs: do not ever return a stale pointer from __xfs_dir3_free_read
(git-fixes).
- xprtrdma: Fix completion wait during device removal (git-fixes).
Special Instructions and Notes:
Please reboot the system after installing this update.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-801=1
Package List:
- openSUSE Leap 15.1 (noarch):
kernel-devel-4.12.14-lp151.28.52.1
kernel-docs-4.12.14-lp151.28.52.2
kernel-docs-html-4.12.14-lp151.28.52.2
kernel-macros-4.12.14-lp151.28.52.1
kernel-source-4.12.14-lp151.28.52.1
kernel-source-vanilla-4.12.14-lp151.28.52.1
- openSUSE Leap 15.1 (x86_64):
kernel-debug-4.12.14-lp151.28.52.1
kernel-debug-base-4.12.14-lp151.28.52.1
kernel-debug-base-debuginfo-4.12.14-lp151.28.52.1
kernel-debug-debuginfo-4.12.14-lp151.28.52.1
kernel-debug-debugsource-4.12.14-lp151.28.52.1
kernel-debug-devel-4.12.14-lp151.28.52.1
kernel-debug-devel-debuginfo-4.12.14-lp151.28.52.1
kernel-default-4.12.14-lp151.28.52.1
kernel-default-base-4.12.14-lp151.28.52.1
kernel-default-base-debuginfo-4.12.14-lp151.28.52.1
kernel-default-debuginfo-4.12.14-lp151.28.52.1
kernel-default-debugsource-4.12.14-lp151.28.52.1
kernel-default-devel-4.12.14-lp151.28.52.1
kernel-default-devel-debuginfo-4.12.14-lp151.28.52.1
kernel-kvmsmall-4.12.14-lp151.28.52.1
kernel-kvmsmall-base-4.12.14-lp151.28.52.1
kernel-kvmsmall-base-debuginfo-4.12.14-lp151.28.52.1
kernel-kvmsmall-debuginfo-4.12.14-lp151.28.52.1
kernel-kvmsmall-debugsource-4.12.14-lp151.28.52.1
kernel-kvmsmall-devel-4.12.14-lp151.28.52.1
kernel-kvmsmall-devel-debuginfo-4.12.14-lp151.28.52.1
kernel-obs-build-4.12.14-lp151.28.52.3
kernel-obs-build-debugsource-4.12.14-lp151.28.52.3
kernel-obs-qa-4.12.14-lp151.28.52.3
kernel-syms-4.12.14-lp151.28.52.1
kernel-vanilla-4.12.14-lp151.28.52.1
kernel-vanilla-base-4.12.14-lp151.28.52.1
kernel-vanilla-base-debuginfo-4.12.14-lp151.28.52.1
kernel-vanilla-debuginfo-4.12.14-lp151.28.52.1
kernel-vanilla-debugsource-4.12.14-lp151.28.52.1
kernel-vanilla-devel-4.12.14-lp151.28.52.1
kernel-vanilla-devel-debuginfo-4.12.14-lp151.28.52.1
References:
https://www.suse.com/security/cve/CVE-2018-1000199.html
https://www.suse.com/security/cve/CVE-2019-19462.html
https://www.suse.com/security/cve/CVE-2019-20806.html
https://www.suse.com/security/cve/CVE-2019-20812.html
https://www.suse.com/security/cve/CVE-2019-9455.html
https://www.suse.com/security/cve/CVE-2020-0543.html
https://www.suse.com/security/cve/CVE-2020-10690.html
https://www.suse.com/security/cve/CVE-2020-10711.html
https://www.suse.com/security/cve/CVE-2020-10720.html
https://www.suse.com/security/cve/CVE-2020-10732.html
https://www.suse.com/security/cve/CVE-2020-10751.html
https://www.suse.com/security/cve/CVE-2020-10757.html
https://www.suse.com/security/cve/CVE-2020-11608.html
https://www.suse.com/security/cve/CVE-2020-11609.html
https://www.suse.com/security/cve/CVE-2020-12114.html
https://www.suse.com/security/cve/CVE-2020-12464.html
https://www.suse.com/security/cve/CVE-2020-12652.html
https://www.suse.com/security/cve/CVE-2020-12653.html
https://www.suse.com/security/cve/CVE-2020-12654.html
https://www.suse.com/security/cve/CVE-2020-12655.html
https://www.suse.com/security/cve/CVE-2020-12656.html
https://www.suse.com/security/cve/CVE-2020-12657.html
https://www.suse.com/security/cve/CVE-2020-12659.html
https://www.suse.com/security/cve/CVE-2020-12769.html
https://www.suse.com/security/cve/CVE-2020-13143.html
https://bugzilla.suse.com/1051510
https://bugzilla.suse.com/1058115
https://bugzilla.suse.com/1065729
https://bugzilla.suse.com/1071995
https://bugzilla.suse.com/1082555
https://bugzilla.suse.com/1083647
https://bugzilla.suse.com/1089895
https://bugzilla.suse.com/1090036
https://bugzilla.suse.com/1103990
https://bugzilla.suse.com/1103991
https://bugzilla.suse.com/1103992
https://bugzilla.suse.com/1104745
https://bugzilla.suse.com/1109837
https://bugzilla.suse.com/1111666
https://bugzilla.suse.com/1112178
https://bugzilla.suse.com/1112374
https://bugzilla.suse.com/1113956
https://bugzilla.suse.com/1114279
https://bugzilla.suse.com/1124278
https://bugzilla.suse.com/1127354
https://bugzilla.suse.com/1127355
https://bugzilla.suse.com/1127371
https://bugzilla.suse.com/1133021
https://bugzilla.suse.com/1142685
https://bugzilla.suse.com/1144333
https://bugzilla.suse.com/1151794
https://bugzilla.suse.com/1152489
https://bugzilla.suse.com/1154824
https://bugzilla.suse.com/1157169
https://bugzilla.suse.com/1158265
https://bugzilla.suse.com/1160388
https://bugzilla.suse.com/1160947
https://bugzilla.suse.com/1164780
https://bugzilla.suse.com/1164871
https://bugzilla.suse.com/1165183
https://bugzilla.suse.com/1165478
https://bugzilla.suse.com/1165741
https://bugzilla.suse.com/1166969
https://bugzilla.suse.com/1166978
https://bugzilla.suse.com/1167574
https://bugzilla.suse.com/1167851
https://bugzilla.suse.com/1167867
https://bugzilla.suse.com/1168332
https://bugzilla.suse.com/1168670
https://bugzilla.suse.com/1168789
https://bugzilla.suse.com/1168829
https://bugzilla.suse.com/1168854
https://bugzilla.suse.com/1169020
https://bugzilla.suse.com/1169514
https://bugzilla.suse.com/1169525
https://bugzilla.suse.com/1169762
https://bugzilla.suse.com/1170056
https://bugzilla.suse.com/1170125
https://bugzilla.suse.com/1170145
https://bugzilla.suse.com/1170284
https://bugzilla.suse.com/1170345
https://bugzilla.suse.com/1170457
https://bugzilla.suse.com/1170522
https://bugzilla.suse.com/1170592
https://bugzilla.suse.com/1170617
https://bugzilla.suse.com/1170618
https://bugzilla.suse.com/1170620
https://bugzilla.suse.com/1170621
https://bugzilla.suse.com/1170740
https://bugzilla.suse.com/1170770
https://bugzilla.suse.com/1170778
https://bugzilla.suse.com/1170791
https://bugzilla.suse.com/1170901
https://bugzilla.suse.com/1171078
https://bugzilla.suse.com/1171098
https://bugzilla.suse.com/1171118
https://bugzilla.suse.com/1171189
https://bugzilla.suse.com/1171191
https://bugzilla.suse.com/1171195
https://bugzilla.suse.com/1171202
https://bugzilla.suse.com/1171205
https://bugzilla.suse.com/1171214
https://bugzilla.suse.com/1171217
https://bugzilla.suse.com/1171218
https://bugzilla.suse.com/1171219
https://bugzilla.suse.com/1171220
https://bugzilla.suse.com/1171244
https://bugzilla.suse.com/1171252
https://bugzilla.suse.com/1171254
https://bugzilla.suse.com/1171293
https://bugzilla.suse.com/1171417
https://bugzilla.suse.com/1171527
https://bugzilla.suse.com/1171599
https://bugzilla.suse.com/1171600
https://bugzilla.suse.com/1171601
https://bugzilla.suse.com/1171602
https://bugzilla.suse.com/1171604
https://bugzilla.suse.com/1171605
https://bugzilla.suse.com/1171606
https://bugzilla.suse.com/1171607
https://bugzilla.suse.com/1171608
https://bugzilla.suse.com/1171609
https://bugzilla.suse.com/1171610
https://bugzilla.suse.com/1171611
https://bugzilla.suse.com/1171612
https://bugzilla.suse.com/1171613
https://bugzilla.suse.com/1171614
https://bugzilla.suse.com/1171615
https://bugzilla.suse.com/1171616
https://bugzilla.suse.com/1171617
https://bugzilla.suse.com/1171618
https://bugzilla.suse.com/1171619
https://bugzilla.suse.com/1171620
https://bugzilla.suse.com/1171621
https://bugzilla.suse.com/1171622
https://bugzilla.suse.com/1171623
https://bugzilla.suse.com/1171624
https://bugzilla.suse.com/1171625
https://bugzilla.suse.com/1171626
https://bugzilla.suse.com/1171662
https://bugzilla.suse.com/1171679
https://bugzilla.suse.com/1171691
https://bugzilla.suse.com/1171692
https://bugzilla.suse.com/1171694
https://bugzilla.suse.com/1171695
https://bugzilla.suse.com/1171736
https://bugzilla.suse.com/1171817
https://bugzilla.suse.com/1171948
https://bugzilla.suse.com/1171949
https://bugzilla.suse.com/1171951
https://bugzilla.suse.com/1171952
https://bugzilla.suse.com/1171979
https://bugzilla.suse.com/1171982
https://bugzilla.suse.com/1171983
https://bugzilla.suse.com/1172017
https://bugzilla.suse.com/1172096
https://bugzilla.suse.com/1172097
https://bugzilla.suse.com/1172098
https://bugzilla.suse.com/1172099
https://bugzilla.suse.com/1172101
https://bugzilla.suse.com/1172102
https://bugzilla.suse.com/1172103
https://bugzilla.suse.com/1172104
https://bugzilla.suse.com/1172127
https://bugzilla.suse.com/1172130
https://bugzilla.suse.com/1172185
https://bugzilla.suse.com/1172188
https://bugzilla.suse.com/1172199
https://bugzilla.suse.com/1172201
https://bugzilla.suse.com/1172202
https://bugzilla.suse.com/1172221
https://bugzilla.suse.com/1172249
https://bugzilla.suse.com/1172251
https://bugzilla.suse.com/1172317
https://bugzilla.suse.com/1172342
https://bugzilla.suse.com/1172343
https://bugzilla.suse.com/1172344
https://bugzilla.suse.com/1172366
https://bugzilla.suse.com/1172378
https://bugzilla.suse.com/1172391
https://bugzilla.suse.com/1172397
https://bugzilla.suse.com/1172453
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0804-1: moderate: Security update for texlive-filesystem
by opensuse-security@opensuse.org 13 Jun '20
by opensuse-security@opensuse.org 13 Jun '20
13 Jun '20
openSUSE Security Update: Security update for texlive-filesystem
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0804-1
Rating: moderate
References: #1158910 #1159740
Cross-References: CVE-2020-8016 CVE-2020-8017
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes two vulnerabilities is now available.
Description:
This update for texlive-filesystem fixes the following issues:
Security issues fixed:
- CVE-2020-8016: Fixed a race condition in the spec file (bsc#1159740).
- CVE-2020-8017: Fixed a race condition on a cron job (bsc#1158910).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-804=1
Package List:
- openSUSE Leap 15.1 (i586 x86_64):
libkpathsea6-6.2.3-lp151.12.3.1
libkpathsea6-debuginfo-6.2.3-lp151.12.3.1
libptexenc1-1.3.5-lp151.12.3.1
libptexenc1-debuginfo-1.3.5-lp151.12.3.1
libsynctex1-1.18-lp151.12.3.1
libsynctex1-debuginfo-1.18-lp151.12.3.1
libtexlua52-5-5.2.4-lp151.12.3.1
libtexlua52-5-debuginfo-5.2.4-lp151.12.3.1
libtexluajit2-2.1.0beta2-lp151.12.3.1
libtexluajit2-debuginfo-2.1.0beta2-lp151.12.3.1
texlive-2017.20170520-lp151.12.3.1
texlive-a2ping-bin-2017.20170520.svn27321-lp151.12.3.1
texlive-accfonts-bin-2017.20170520.svn12688-lp151.12.3.1
texlive-adhocfilelist-bin-2017.20170520.svn28038-lp151.12.3.1
texlive-afm2pl-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-afm2pl-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-aleph-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-aleph-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-amstex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-arara-bin-2017.20170520.svn29036-lp151.12.3.1
texlive-asymptote-bin-2017.20170520.svn43843-lp151.12.3.1
texlive-asymptote-bin-debuginfo-2017.20170520.svn43843-lp151.12.3.1
texlive-authorindex-bin-2017.20170520.svn18790-lp151.12.3.1
texlive-autosp-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-autosp-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-bibexport-bin-2017.20170520.svn16219-lp151.12.3.1
texlive-bibtex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-bibtex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-bibtex8-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-bibtex8-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-bibtexu-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-bibtexu-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-bin-devel-2017.20170520-lp151.12.3.1
texlive-bundledoc-bin-2017.20170520.svn17794-lp151.12.3.1
texlive-cachepic-bin-2017.20170520.svn15543-lp151.12.3.1
texlive-checkcites-bin-2017.20170520.svn25623-lp151.12.3.1
texlive-checklistings-bin-2017.20170520.svn38300-lp151.12.3.1
texlive-chktex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-chktex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-cjk-gs-integrate-bin-2017.20170520.svn37223-lp151.12.3.1
texlive-cjkutils-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-cjkutils-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-context-bin-2017.20170520.svn34112-lp151.12.3.1
texlive-convbkmk-bin-2017.20170520.svn30408-lp151.12.3.1
texlive-crossrefware-bin-2017.20170520.svn43866-lp151.12.3.1
texlive-cslatex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-csplain-bin-2017.20170520.svn33902-lp151.12.3.1
texlive-ctanify-bin-2017.20170520.svn24061-lp151.12.3.1
texlive-ctanupload-bin-2017.20170520.svn23866-lp151.12.3.1
texlive-ctie-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-ctie-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-cweb-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-cweb-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-cyrillic-bin-bin-2017.20170520.svn29741-lp151.12.3.1
texlive-de-macro-bin-2017.20170520.svn17399-lp151.12.3.1
texlive-debuginfo-2017.20170520-lp151.12.3.1
texlive-debugsource-2017.20170520-lp151.12.3.1
texlive-detex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-detex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dosepsbin-bin-2017.20170520.svn24759-lp151.12.3.1
texlive-dtl-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dtl-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dtxgen-bin-2017.20170520.svn29031-lp151.12.3.1
texlive-dviasm-bin-2017.20170520.svn8329-lp151.12.3.1
texlive-dvicopy-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dvicopy-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dvidvi-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dvidvi-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dviinfox-bin-2017.20170520.svn44515-lp151.12.3.1
texlive-dviljk-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dviljk-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dvipdfmx-bin-2017.20170520.svn40273-lp151.12.3.1
texlive-dvipng-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dvipng-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dvipos-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dvipos-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dvips-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-dvips-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-dvisvgm-bin-2017.20170520.svn40987-lp151.12.3.1
texlive-dvisvgm-bin-debuginfo-2017.20170520.svn40987-lp151.12.3.1
texlive-ebong-bin-2017.20170520.svn21000-lp151.12.3.1
texlive-eplain-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-epspdf-bin-2017.20170520.svn29050-lp151.12.3.1
texlive-epstopdf-bin-2017.20170520.svn18336-lp151.12.3.1
texlive-exceltex-bin-2017.20170520.svn25860-lp151.12.3.1
texlive-fig4latex-bin-2017.20170520.svn14752-lp151.12.3.1
texlive-findhyph-bin-2017.20170520.svn14758-lp151.12.3.1
texlive-fontinst-bin-2017.20170520.svn29741-lp151.12.3.1
texlive-fontools-bin-2017.20170520.svn25997-lp151.12.3.1
texlive-fontware-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-fontware-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-fragmaster-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-getmap-bin-2017.20170520.svn34971-lp151.12.3.1
texlive-glossaries-bin-2017.20170520.svn37813-lp151.12.3.1
texlive-gregoriotex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-gregoriotex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-gsftopk-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-gsftopk-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-jadetex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-kotex-utils-bin-2017.20170520.svn32101-lp151.12.3.1
texlive-kpathsea-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-kpathsea-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-kpathsea-devel-6.2.3-lp151.12.3.1
texlive-lacheck-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-lacheck-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-latex-bin-bin-2017.20170520.svn14050-lp151.12.3.1
texlive-latex-git-log-bin-2017.20170520.svn30983-lp151.12.3.1
texlive-latex-papersize-bin-2017.20170520.svn42296-lp151.12.3.1
texlive-latex2man-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-latex2nemeth-bin-2017.20170520.svn42300-lp151.12.3.1
texlive-latexdiff-bin-2017.20170520.svn16420-lp151.12.3.1
texlive-latexfileversion-bin-2017.20170520.svn25012-lp151.12.3.1
texlive-latexindent-bin-2017.20170520.svn32150-lp151.12.3.1
texlive-latexmk-bin-2017.20170520.svn10937-lp151.12.3.1
texlive-latexpand-bin-2017.20170520.svn27025-lp151.12.3.1
texlive-lcdftypetools-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-lcdftypetools-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-lilyglyphs-bin-2017.20170520.svn31696-lp151.12.3.1
texlive-listbib-bin-2017.20170520.svn26126-lp151.12.3.1
texlive-listings-ext-bin-2017.20170520.svn15093-lp151.12.3.1
texlive-lollipop-bin-2017.20170520.svn41465-lp151.12.3.1
texlive-ltxfileinfo-bin-2017.20170520.svn29005-lp151.12.3.1
texlive-ltximg-bin-2017.20170520.svn32346-lp151.12.3.1
texlive-lua2dox-bin-2017.20170520.svn29053-lp151.12.3.1
texlive-luaotfload-bin-2017.20170520.svn34647-lp151.12.3.1
texlive-luatex-bin-2017.20170520.svn44549-lp151.12.3.1
texlive-luatex-bin-debuginfo-2017.20170520.svn44549-lp151.12.3.1
texlive-lwarp-bin-2017.20170520.svn43292-lp151.12.3.1
texlive-m-tx-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-m-tx-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-make4ht-bin-2017.20170520.svn37750-lp151.12.3.1
texlive-makedtx-bin-2017.20170520.svn38769-lp151.12.3.1
texlive-makeindex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-makeindex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-match_parens-bin-2017.20170520.svn23500-lp151.12.3.1
texlive-mathspic-bin-2017.20170520.svn23661-lp151.12.3.1
texlive-metafont-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-metafont-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-metapost-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-metapost-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-mex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-mf2pt1-bin-2017.20170520.svn23406-lp151.12.3.1
texlive-mflua-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-mflua-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-mfware-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-mfware-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-mkgrkindex-bin-2017.20170520.svn14428-lp151.12.3.1
texlive-mkjobtexmf-bin-2017.20170520.svn8457-lp151.12.3.1
texlive-mkpic-bin-2017.20170520.svn33688-lp151.12.3.1
texlive-mltex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-mptopdf-bin-2017.20170520.svn18674-lp151.12.3.1
texlive-multibibliography-bin-2017.20170520.svn30534-lp151.12.3.1
texlive-musixtex-bin-2017.20170520.svn37026-lp151.12.3.1
texlive-musixtnt-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-musixtnt-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-omegaware-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-omegaware-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-patgen-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-patgen-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-pax-bin-2017.20170520.svn10843-lp151.12.3.1
texlive-pdfbook2-bin-2017.20170520.svn37537-lp151.12.3.1
texlive-pdfcrop-bin-2017.20170520.svn14387-lp151.12.3.1
texlive-pdfjam-bin-2017.20170520.svn17868-lp151.12.3.1
texlive-pdflatexpicscale-bin-2017.20170520.svn41779-lp151.12.3.1
texlive-pdftex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-pdftex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-pdftools-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-pdftools-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-pdfxup-bin-2017.20170520.svn40690-lp151.12.3.1
texlive-pedigree-perl-bin-2017.20170520.svn25962-lp151.12.3.1
texlive-perltex-bin-2017.20170520.svn16181-lp151.12.3.1
texlive-petri-nets-bin-2017.20170520.svn39165-lp151.12.3.1
texlive-pfarrei-bin-2017.20170520.svn29348-lp151.12.3.1
texlive-pkfix-bin-2017.20170520.svn13364-lp151.12.3.1
texlive-pkfix-helper-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-platex-bin-2017.20170520.svn22859-lp151.12.3.1
texlive-pmx-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-pmx-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-pmxchords-bin-2017.20170520.svn32405-lp151.12.3.1
texlive-ps2pk-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-ps2pk-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-pst-pdf-bin-2017.20170520.svn7838-lp151.12.3.1
texlive-pst2pdf-bin-2017.20170520.svn29333-lp151.12.3.1
texlive-pstools-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-pstools-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-ptex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-ptex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-ptex-fontmaps-bin-2017.20170520.svn44206-lp151.12.3.1
texlive-ptex2pdf-bin-2017.20170520.svn29335-lp151.12.3.1
texlive-ptexenc-devel-1.3.5-lp151.12.3.1
texlive-purifyeps-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-pygmentex-bin-2017.20170520.svn34996-lp151.12.3.1
texlive-pythontex-bin-2017.20170520.svn31638-lp151.12.3.1
texlive-rubik-bin-2017.20170520.svn32919-lp151.12.3.1
texlive-seetexk-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-seetexk-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-splitindex-bin-2017.20170520.svn29688-lp151.12.3.1
texlive-srcredact-bin-2017.20170520.svn38710-lp151.12.3.1
texlive-sty2dtx-bin-2017.20170520.svn21215-lp151.12.3.1
texlive-svn-multi-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-synctex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-synctex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-synctex-devel-1.18-lp151.12.3.1
texlive-tetex-bin-2017.20170520.svn43957-lp151.12.3.1
texlive-tex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-tex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-tex4ebook-bin-2017.20170520.svn37771-lp151.12.3.1
texlive-tex4ht-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-tex4ht-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-texconfig-bin-2017.20170520.svn29741-lp151.12.3.1
texlive-texcount-bin-2017.20170520.svn13013-lp151.12.3.1
texlive-texdef-bin-2017.20170520.svn21802-lp151.12.3.1
texlive-texdiff-bin-2017.20170520.svn15506-lp151.12.3.1
texlive-texdirflatten-bin-2017.20170520.svn12782-lp151.12.3.1
texlive-texdoc-bin-2017.20170520.svn29741-lp151.12.3.1
texlive-texfot-bin-2017.20170520.svn33155-lp151.12.3.1
texlive-texliveonfly-bin-2017.20170520.svn24062-lp151.12.3.1
texlive-texloganalyser-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-texlua-devel-5.2.4-lp151.12.3.1
texlive-texluajit-devel-2.1.0beta2-lp151.12.3.1
texlive-texosquery-bin-2017.20170520.svn43596-lp151.12.3.1
texlive-texsis-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-texware-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-texware-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-thumbpdf-bin-2017.20170520.svn6898-lp151.12.3.1
texlive-tie-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-tie-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-tpic2pdftex-bin-2017.20170520.svn29741-lp151.12.3.1
texlive-ttfutils-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-ttfutils-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-typeoutfileinfo-bin-2017.20170520.svn25648-lp151.12.3.1
texlive-ulqda-bin-2017.20170520.svn13663-lp151.12.3.1
texlive-uplatex-bin-2017.20170520.svn26326-lp151.12.3.1
texlive-uptex-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-uptex-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-urlbst-bin-2017.20170520.svn23262-lp151.12.3.1
texlive-velthuis-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-velthuis-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-vlna-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-vlna-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-vpe-bin-2017.20170520.svn6897-lp151.12.3.1
texlive-web-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-web-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-xdvi-bin-2017.20170520.svn44143-lp151.12.3.1
texlive-xdvi-bin-debuginfo-2017.20170520.svn44143-lp151.12.3.1
texlive-xetex-bin-2017.20170520.svn44361-lp151.12.3.1
texlive-xetex-bin-debuginfo-2017.20170520.svn44361-lp151.12.3.1
texlive-xmltex-bin-2017.20170520.svn3006-lp151.12.3.1
texlive-yplan-bin-2017.20170520.svn34398-lp151.12.3.1
- openSUSE Leap 15.1 (noarch):
perl-biber-2017.20170520.svn30357-lp151.12.3.1
texlive-biber-bin-2017.20170520.svn42679-lp151.12.3.1
texlive-collection-basic-2017.135.svn41616-lp151.8.6.1
texlive-collection-bibtexextra-2017.135.svn44385-lp151.8.6.1
texlive-collection-binextra-2017.135.svn44515-lp151.8.6.1
texlive-collection-context-2017.135.svn42330-lp151.8.6.1
texlive-collection-fontsextra-2017.135.svn43356-lp151.8.6.1
texlive-collection-fontsrecommended-2017.135.svn35830-lp151.8.6.1
texlive-collection-fontutils-2017.135.svn37105-lp151.8.6.1
texlive-collection-formatsextra-2017.135.svn44177-lp151.8.6.1
texlive-collection-games-2017.135.svn42992-lp151.8.6.1
texlive-collection-humanities-2017.135.svn42268-lp151.8.6.1
texlive-collection-langarabic-2017.135.svn44496-lp151.8.6.1
texlive-collection-langchinese-2017.135.svn42675-lp151.8.6.1
texlive-collection-langcjk-2017.135.svn43009-lp151.8.6.1
texlive-collection-langcyrillic-2017.135.svn44401-lp151.8.6.1
texlive-collection-langczechslovak-2017.135.svn32550-lp151.8.6.1
texlive-collection-langenglish-2017.135.svn43650-lp151.8.6.1
texlive-collection-langeuropean-2017.135.svn44414-lp151.8.6.1
texlive-collection-langfrench-2017.135.svn40375-lp151.8.6.1
texlive-collection-langgerman-2017.135.svn42045-lp151.8.6.1
texlive-collection-langgreek-2017.135.svn44192-lp151.8.6.1
texlive-collection-langitalian-2017.135.svn30372-lp151.8.6.1
texlive-collection-langjapanese-2017.135.svn44554-lp151.8.6.1
texlive-collection-langkorean-2017.135.svn42106-lp151.8.6.1
texlive-collection-langother-2017.135.svn44414-lp151.8.6.1
texlive-collection-langpolish-2017.135.svn44371-lp151.8.6.1
texlive-collection-langportuguese-2017.135.svn30962-lp151.8.6.1
texlive-collection-langspanish-2017.135.svn40587-lp151.8.6.1
texlive-collection-latex-2017.135.svn41614-lp151.8.6.1
texlive-collection-latexextra-2017.135.svn44544-lp151.8.6.1
texlive-collection-latexrecommended-2017.135.svn44177-lp151.8.6.1
texlive-collection-luatex-2017.135.svn44500-lp151.8.6.1
texlive-collection-mathscience-2017.135.svn44396-lp151.8.6.1
texlive-collection-metapost-2017.135.svn44297-lp151.8.6.1
texlive-collection-music-2017.135.svn40561-lp151.8.6.1
texlive-collection-pictures-2017.135.svn44395-lp151.8.6.1
texlive-collection-plaingeneric-2017.135.svn44177-lp151.8.6.1
texlive-collection-pstricks-2017.135.svn44460-lp151.8.6.1
texlive-collection-publishers-2017.135.svn44485-lp151.8.6.1
texlive-collection-xetex-2017.135.svn43059-lp151.8.6.1
texlive-devel-2017.135-lp151.8.6.1
texlive-diadia-bin-2017.20170520.svn37645-lp151.12.3.1
texlive-extratools-2017.135-lp151.8.6.1
texlive-filesystem-2017.135-lp151.8.6.1
texlive-scheme-basic-2017.135.svn25923-lp151.8.6.1
texlive-scheme-context-2017.135.svn35799-lp151.8.6.1
texlive-scheme-full-2017.135.svn44177-lp151.8.6.1
texlive-scheme-gust-2017.135.svn44177-lp151.8.6.1
texlive-scheme-infraonly-2017.135.svn41515-lp151.8.6.1
texlive-scheme-medium-2017.135.svn44177-lp151.8.6.1
texlive-scheme-minimal-2017.135.svn13822-lp151.8.6.1
texlive-scheme-small-2017.135.svn41825-lp151.8.6.1
texlive-scheme-tetex-2017.135.svn44187-lp151.8.6.1
References:
https://www.suse.com/security/cve/CVE-2020-8016.html
https://www.suse.com/security/cve/CVE-2020-8017.html
https://bugzilla.suse.com/1158910
https://bugzilla.suse.com/1159740
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0803-1: moderate: Security update for rubygem-bundler
by opensuse-security@opensuse.org 13 Jun '20
by opensuse-security@opensuse.org 13 Jun '20
13 Jun '20
openSUSE Security Update: Security update for rubygem-bundler
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0803-1
Rating: moderate
References: #1143436
Cross-References: CVE-2019-3881
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for rubygem-bundler fixes the following issue:
- CVE-2019-3881: Fixed insecure permissions on a directory in /tmp/ that
allowed malicious code execution (bsc#1143436).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-803=1
Package List:
- openSUSE Leap 15.1 (x86_64):
ruby2.5-rubygem-bundler-1.16.1-lp151.3.3.1
ruby2.5-rubygem-bundler-doc-1.16.1-lp151.3.3.1
References:
https://www.suse.com/security/cve/CVE-2019-3881.html
https://bugzilla.suse.com/1143436
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0799-1: important: Security update for MozillaThunderbird
by opensuse-security@opensuse.org 12 Jun '20
by opensuse-security@opensuse.org 12 Jun '20
12 Jun '20
openSUSE Security Update: Security update for MozillaThunderbird
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0799-1
Rating: important
References: #1172402
Cross-References: CVE-2020-12398 CVE-2020-12405 CVE-2020-12406
CVE-2020-12410
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes four vulnerabilities is now available.
Description:
This update for MozillaThunderbird fixes the following issues:
Mozilla Thunderbird 68.9.0 (bsc#1172402)
- CVE-2020-12405: Fixed a use-after-free in SharedWorkerService.
- CVE-2020-12406: Fixed a JavaScript Type confusion with NativeTypes.
- CVE-2020-12410: Fixed multiple memory safety issues
- CVE-2020-12398: Fixed a potential information leak due to security
downgrade with IMAP STARTTLS
- Use a symbolic icon from branding internals
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-799=1
Package List:
- openSUSE Leap 15.1 (x86_64):
MozillaThunderbird-68.9.0-lp151.2.41.1
MozillaThunderbird-debuginfo-68.9.0-lp151.2.41.1
MozillaThunderbird-debugsource-68.9.0-lp151.2.41.1
MozillaThunderbird-translations-common-68.9.0-lp151.2.41.1
MozillaThunderbird-translations-other-68.9.0-lp151.2.41.1
References:
https://www.suse.com/security/cve/CVE-2020-12398.html
https://www.suse.com/security/cve/CVE-2020-12405.html
https://www.suse.com/security/cve/CVE-2020-12406.html
https://www.suse.com/security/cve/CVE-2020-12410.html
https://bugzilla.suse.com/1172402
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0794-1: moderate: Security update for vim
by opensuse-security@opensuse.org 11 Jun '20
by opensuse-security@opensuse.org 11 Jun '20
11 Jun '20
openSUSE Security Update: Security update for vim
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0794-1
Rating: moderate
References: #1172225
Cross-References: CVE-2019-20807
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for vim fixes the following issues:
- CVE-2019-20807: Fixed an issue where escaping from the restrictive mode
of vim was possible using interfaces (bsc#1172225).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-794=1
Package List:
- openSUSE Leap 15.1 (i586 x86_64):
gvim-8.0.1568-lp151.5.6.1
gvim-debuginfo-8.0.1568-lp151.5.6.1
vim-8.0.1568-lp151.5.6.1
vim-debuginfo-8.0.1568-lp151.5.6.1
vim-debugsource-8.0.1568-lp151.5.6.1
- openSUSE Leap 15.1 (noarch):
vim-data-8.0.1568-lp151.5.6.1
vim-data-common-8.0.1568-lp151.5.6.1
References:
https://www.suse.com/security/cve/CVE-2019-20807.html
https://bugzilla.suse.com/1172225
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0793-1: moderate: Security update for libexif
by opensuse-security@opensuse.org 11 Jun '20
by opensuse-security@opensuse.org 11 Jun '20
11 Jun '20
openSUSE Security Update: Security update for libexif
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0793-1
Rating: moderate
References: #1055857 #1059893 #1120943 #1160770 #1171475
#1171847 #1172105 #1172116 #1172121
Cross-References: CVE-2016-6328 CVE-2017-7544 CVE-2018-20030
CVE-2019-9278 CVE-2020-0093 CVE-2020-12767
CVE-2020-13112 CVE-2020-13113 CVE-2020-13114
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes 9 vulnerabilities is now available.
Description:
This update for libexif to 0.6.22 fixes the following issues:
Security issues fixed:
- CVE-2016-6328: Fixed an integer overflow in parsing MNOTE entry data of
the input file (bsc#1055857).
- CVE-2017-7544: Fixed an out-of-bounds heap read vulnerability in
exif_data_save_data_entry function in libexif/exif-data.c (bsc#1059893).
- CVE-2018-20030: Fixed a denial of service by endless recursion
(bsc#1120943).
- CVE-2019-9278: Fixed an integer overflow (bsc#1160770).
- CVE-2020-0093: Fixed an out-of-bounds read in exif_data_save_data_entry
(bsc#1171847).
- CVE-2020-12767: Fixed a divide-by-zero error in exif_entry_get_value
(bsc#1171475).
- CVE-2020-13112: Fixed a time consumption DoS when parsing canon array
markers (bsc#1172121).
- CVE-2020-13113: Fixed a potential use of uninitialized memory
(bsc#1172105).
- CVE-2020-13114: Fixed various buffer overread fixes due to integer
overflows in maker notes (bsc#1172116).
Non-security issues fixed:
- libexif was updated to version 0.6.22:
* New translations: ms
* Updated translations for most languages
* Some useful EXIF 2.3 tag added:
* EXIF_TAG_GAMMA
* EXIF_TAG_COMPOSITE_IMAGE
* EXIF_TAG_SOURCE_IMAGE_NUMBER_OF_COMPOSITE_IMAGE
* EXIF_TAG_SOURCE_EXPOSURE_TIMES_OF_COMPOSITE_IMAGE
* EXIF_TAG_GPS_H_POSITIONING_ERROR
* EXIF_TAG_CAMERA_OWNER_NAME
* EXIF_TAG_BODY_SERIAL_NUMBER
* EXIF_TAG_LENS_SPECIFICATION
* EXIF_TAG_LENS_MAKE
* EXIF_TAG_LENS_MODEL
* EXIF_TAG_LENS_SERIAL_NUMBER
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-793=1
Package List:
- openSUSE Leap 15.1 (i586 x86_64):
libexif-debugsource-0.6.22-lp151.4.6.1
libexif-devel-0.6.22-lp151.4.6.1
libexif12-0.6.22-lp151.4.6.1
libexif12-debuginfo-0.6.22-lp151.4.6.1
- openSUSE Leap 15.1 (x86_64):
libexif-devel-32bit-0.6.22-lp151.4.6.1
libexif12-32bit-0.6.22-lp151.4.6.1
libexif12-32bit-debuginfo-0.6.22-lp151.4.6.1
References:
https://www.suse.com/security/cve/CVE-2016-6328.html
https://www.suse.com/security/cve/CVE-2017-7544.html
https://www.suse.com/security/cve/CVE-2018-20030.html
https://www.suse.com/security/cve/CVE-2019-9278.html
https://www.suse.com/security/cve/CVE-2020-0093.html
https://www.suse.com/security/cve/CVE-2020-12767.html
https://www.suse.com/security/cve/CVE-2020-13112.html
https://www.suse.com/security/cve/CVE-2020-13113.html
https://www.suse.com/security/cve/CVE-2020-13114.html
https://bugzilla.suse.com/1055857
https://bugzilla.suse.com/1059893
https://bugzilla.suse.com/1120943
https://bugzilla.suse.com/1160770
https://bugzilla.suse.com/1171475
https://bugzilla.suse.com/1171847
https://bugzilla.suse.com/1172105
https://bugzilla.suse.com/1172116
https://bugzilla.suse.com/1172121
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0791-1: moderate: Security update for ucode-intel
by opensuse-security@opensuse.org 10 Jun '20
by opensuse-security@opensuse.org 10 Jun '20
10 Jun '20
openSUSE Security Update: Security update for ucode-intel
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0791-1
Rating: moderate
References: #1154824 #1156353 #1172466
Cross-References: CVE-2020-0543 CVE-2020-0548 CVE-2020-0549
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for ucode-intel fixes the following issues:
Updated Intel CPU Microcode to 20200602 (prerelease) (bsc#1172466)
This update contains security mitigations for:
- CVE-2020-0543: Fixed a side channel attack against special registers
which could have resulted in leaking of read values to cores other than
the one which called it. This attack is known as Special Register
Buffer Data Sampling (SRBDS) or "CrossTalk" (bsc#1154824).
- CVE-2020-0548,CVE-2020-0549: Additional ucode updates were supplied to
mitigate the Vector Register and L1D Eviction Sampling aka
"CacheOutAttack" attacks. (bsc#1156353)
Microcode Table:
Processor Identifier Version Products Model
Stepping F-MO-S/PI Old->New
---- new platforms ----------------------------------------
---- updated platforms ------------------------------------ HSW
C0 6-3c-3/32 00000027->00000028 Core Gen4 BDW-U/Y E0/F0
6-3d-4/c0 0000002e->0000002f Core Gen5 HSW-U C0/D0 6-45-1/72
00000025->00000026 Core Gen4 HSW-H C0 6-46-1/32
0000001b->0000001c Core Gen4 BDW-H/E3 E0/G0 6-47-1/22
00000021->00000022 Core Gen5 SKL-U/Y D0 6-4e-3/c0
000000d6->000000dc Core Gen6 Mobile SKL-U23e K1 6-4e-3/c0
000000d6->000000dc Core Gen6 Mobile SKX-SP B1 6-55-3/97
01000151->01000157 Xeon Scalable SKX-SP H0/M0/U0 6-55-4/b7
02000065->02006906 Xeon Scalable SKX-D M1 6-55-4/b7
02000065->02006906 Xeon D-21xx CLX-SP B0 6-55-6/bf
0400002c->04002f01 Xeon Scalable Gen2 CLX-SP B1 6-55-7/bf
0500002c->04002f01 Xeon Scalable Gen2 SKL-H/S R0/N0 6-5e-3/36
000000d6->000000dc Core Gen6; Xeon E3 v5 AML-Y22 H0
6-8e-9/10 000000ca->000000d6 Core Gen8 Mobile KBL-U/Y H0
6-8e-9/c0 000000ca->000000d6 Core Gen7 Mobile CFL-U43e D0
6-8e-a/c0 000000ca->000000d6 Core Gen8 Mobile WHL-U W0
6-8e-b/d0 000000ca->000000d6 Core Gen8 Mobile AML-Y42 V0
6-8e-c/94 000000ca->000000d6 Core Gen10 Mobile CML-Y42 V0
6-8e-c/94 000000ca->000000d6 Core Gen10 Mobile WHL-U V0
6-8e-c/94 000000ca->000000d6 Core Gen8 Mobile KBL-G/H/S/E3 B0
6-9e-9/2a 000000ca->000000d6 Core Gen7; Xeon E3 v6 CFL-H/S/E3
U0 6-9e-a/22 000000ca->000000d6 Core Gen8 Desktop, Mobile, Xeon E
CFL-S B0 6-9e-b/02 000000ca->000000d6 Core Gen8
CFL-H/S P0 6-9e-c/22 000000ca->000000d6 Core Gen9
CFL-H R0 6-9e-d/22 000000ca->000000d6 Core Gen9 Mobile
Also contains the Intel CPU Microcode update to 20200520:
Processor Identifier Version Products Model
Stepping F-MO-S/PI Old->New
---- new platforms ----------------------------------------
---- updated platforms ------------------------------------ SNB-E/EN/EP
C1/M0 6-2d-6/6d 0000061f->00000621 Xeon E3/E5, Core X SNB-E/EN/EP
C2/M1 6-2d-7/6d 00000718->0000071a Xeon E3/E5, Core X
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-791=1
Package List:
- openSUSE Leap 15.1 (x86_64):
ucode-intel-20200602-lp151.2.24.1
References:
https://www.suse.com/security/cve/CVE-2020-0543.html
https://www.suse.com/security/cve/CVE-2020-0548.html
https://www.suse.com/security/cve/CVE-2020-0549.html
https://bugzilla.suse.com/1154824
https://bugzilla.suse.com/1156353
https://bugzilla.suse.com/1172466
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0790-1: important: Security update for gnutls
by opensuse-security@opensuse.org 10 Jun '20
by opensuse-security@opensuse.org 10 Jun '20
10 Jun '20
openSUSE Security Update: Security update for gnutls
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0790-1
Rating: important
References: #1172461 #1172506
Cross-References: CVE-2020-13777
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that solves one vulnerability and has one errata
is now available.
Description:
This update for gnutls fixes the following issues:
- CVE-2020-13777: Fixed an insecure session ticket key construction which
could have made the TLS server to not bind the session ticket encryption
key with a value supplied by the application until the initial key
rotation, allowing an attacker to bypass authentication in TLS 1.3 and
recover previous conversations in TLS 1.2 (bsc#1172506).
- Fixed an improper handling of certificate chain with cross-signed
intermediate CA certificates (bsc#1172461).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-790=1
Package List:
- openSUSE Leap 15.1 (i586 x86_64):
gnutls-3.6.7-lp151.2.18.1
gnutls-debuginfo-3.6.7-lp151.2.18.1
gnutls-debugsource-3.6.7-lp151.2.18.1
gnutls-guile-3.6.7-lp151.2.18.1
gnutls-guile-debuginfo-3.6.7-lp151.2.18.1
libgnutls-dane-devel-3.6.7-lp151.2.18.1
libgnutls-dane0-3.6.7-lp151.2.18.1
libgnutls-dane0-debuginfo-3.6.7-lp151.2.18.1
libgnutls-devel-3.6.7-lp151.2.18.1
libgnutls30-3.6.7-lp151.2.18.1
libgnutls30-debuginfo-3.6.7-lp151.2.18.1
libgnutls30-hmac-3.6.7-lp151.2.18.1
libgnutlsxx-devel-3.6.7-lp151.2.18.1
libgnutlsxx28-3.6.7-lp151.2.18.1
libgnutlsxx28-debuginfo-3.6.7-lp151.2.18.1
- openSUSE Leap 15.1 (x86_64):
libgnutls-devel-32bit-3.6.7-lp151.2.18.1
libgnutls30-32bit-3.6.7-lp151.2.18.1
libgnutls30-32bit-debuginfo-3.6.7-lp151.2.18.1
libgnutls30-hmac-32bit-3.6.7-lp151.2.18.1
References:
https://www.suse.com/security/cve/CVE-2020-13777.html
https://bugzilla.suse.com/1172461
https://bugzilla.suse.com/1172506
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0789-1: important: Security update for MozillaFirefox
by opensuse-security@opensuse.org 10 Jun '20
by opensuse-security@opensuse.org 10 Jun '20
10 Jun '20
openSUSE Security Update: Security update for MozillaFirefox
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0789-1
Rating: important
References: #1172402
Cross-References: CVE-2020-12405 CVE-2020-12406 CVE-2020-12410
Affected Products:
openSUSE Leap 15.1
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for MozillaFirefox fixes the following issues:
- MozillaFirefox was updated to version 68.9.0 Extended Support Release
(bsc#1172402).
- CVE-2020-12405: Fixed a use-after-free in SharedWorkerService.
- CVE-2020-12406: Fixed a JavaScript Type confusion with NativeTypes.
- CVE-2020-12410: Fixed multiple memory safety bugs.
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-789=1
Package List:
- openSUSE Leap 15.1 (x86_64):
MozillaFirefox-68.9.0-lp151.2.48.1
MozillaFirefox-branding-upstream-68.9.0-lp151.2.48.1
MozillaFirefox-buildsymbols-68.9.0-lp151.2.48.1
MozillaFirefox-debuginfo-68.9.0-lp151.2.48.1
MozillaFirefox-debugsource-68.9.0-lp151.2.48.1
MozillaFirefox-devel-68.9.0-lp151.2.48.1
MozillaFirefox-translations-common-68.9.0-lp151.2.48.1
MozillaFirefox-translations-other-68.9.0-lp151.2.48.1
References:
https://www.suse.com/security/cve/CVE-2020-12405.html
https://www.suse.com/security/cve/CVE-2020-12406.html
https://www.suse.com/security/cve/CVE-2020-12410.html
https://bugzilla.suse.com/1172402
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0
[security-announce] openSUSE-SU-2020:0787-1: moderate: Security update for xawtv
by opensuse-security@opensuse.org 10 Jun '20
by opensuse-security@opensuse.org 10 Jun '20
10 Jun '20
openSUSE Security Update: Security update for xawtv
______________________________________________________________________________
Announcement ID: openSUSE-SU-2020:0787-1
Rating: moderate
References: #1171655
Cross-References: CVE-2020-13696
Affected Products:
openSUSE Backports SLE-15-SP1
______________________________________________________________________________
An update that fixes one vulnerability is now available.
Description:
This update for xawtv fixes the following issues:
- CVE-2020-13696: Fixed an issue in setuid-root program that which could
have allowed arbitrary file existence tests and
open() with O_RDWR (boo#1171655).
This update was imported from the openSUSE:Leap:15.1:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-787=1
Package List:
- openSUSE Backports SLE-15-SP1 (x86_64):
alevtd-3.103-bp151.4.3.1
motv-3.103-bp151.4.3.1
pia-3.103-bp151.4.3.1
tv-common-3.103-bp151.4.3.1
v4l-conf-3.103-bp151.4.3.1
v4l-tools-3.103-bp151.4.3.1
xawtv-3.103-bp151.4.3.1
References:
https://www.suse.com/security/cve/CVE-2020-13696.html
https://bugzilla.suse.com/1171655
--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe(a)opensuse.org
For additional commands, e-mail: opensuse-security-announce+help(a)opensuse.org
1
0