openSUSE Recommended Update: Recommended update for timezone
______________________________________________________________________________
Announcement ID: openSUSE-RU-2019:1082-1
Rating: moderate
References: #1130557
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for timezone fixes the following issues:
timezone was updated 2019a:
* Palestine "springs forward" on 2019-03-30 instead of 2019-03-23
* Metlakatla "fell back" to rejoin Alaska Time on 2019-01-20 at 02:00
* Israel observed DST in 1980 (08-02/09-13) and 1984 (05-05/08-25)
* zic now has an -r option to limit the time range of output data
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1082=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
timezone-2019a-lp150.61.1
timezone-debuginfo-2019a-lp150.61.1
timezone-debugsource-2019a-lp150.61.1
References:
https://bugzilla.suse.com/1130557
openSUSE Security Update: Security update for ovmf
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1083-1
Rating: important
References: #1127820 #1127821 #1127822
Cross-References: CVE-2018-12178 CVE-2018-12180 CVE-2018-3630
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for ovmf fixes the following issues:
Security issues fixed:
- CVE-2018-12180: Fixed a buffer overflow in BlockIo service, which could
lead to memory read/write overrun (bsc#1127820).
- CVE-2018-12178: Fixed an improper DNS check upon receiving a new DNS
packet (bsc#1127821).
- CVE-2018-3630: Fixed a logic error in FV parsing which could allow a
local attacker to bypass the chain of trust checks (bsc#1127822).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1083=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
ovmf-2017+git1510945757.b2662641d5-lp150.4.13.1
ovmf-tools-2017+git1510945757.b2662641d5-lp150.4.13.1
- openSUSE Leap 15.0 (noarch):
qemu-ovmf-ia32-2017+git1510945757.b2662641d5-lp150.4.13.1
qemu-ovmf-x86_64-2017+git1510945757.b2662641d5-lp150.4.13.1
- openSUSE Leap 15.0 (x86_64):
qemu-ovmf-x86_64-debug-2017+git1510945757.b2662641d5-lp150.4.13.1
References:
https://www.suse.com/security/cve/CVE-2018-12178.htmlhttps://www.suse.com/security/cve/CVE-2018-12180.htmlhttps://www.suse.com/security/cve/CVE-2018-3630.htmlhttps://bugzilla.suse.com/1127820https://bugzilla.suse.com/1127821https://bugzilla.suse.com/1127822
openSUSE Recommended Update: Recommended update for timezone
______________________________________________________________________________
Announcement ID: openSUSE-RU-2019:1081-1
Rating: moderate
References: #1130557
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for timezone fixes the following issues:
timezone was update to 2019a (bsc#1130557):
* Palestine "springs forward" on 2019-03-30 instead of 2019-03-23
* Metlakatla "fell back" to rejoin Alaska Time on 2019-01-20 at 02:00
* Israel observed DST in 1980 (08-02/09-13) and 1984 (05-05/08-25)
* zic now has an -r option to limit the time range of output data
This update was imported from the SUSE:SLE-12:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1081=1
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
timezone-2019a-61.1
timezone-debuginfo-2019a-61.1
timezone-debugsource-2019a-61.1
References:
https://bugzilla.suse.com/1130557
openSUSE Security Update: Security update for the Linux Kernel
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1085-1
Rating: important
References: #1012382 #1020413 #1065600 #1070767 #1075697
#1082943 #1087092 #1090435 #1102959 #1103429
#1106929 #1109137 #1109248 #1119019 #1119843
#1120691 #1120902 #1121713 #1121805 #1124235
#1125315 #1125446 #1126389 #1126772 #1126773
#1126805 #1127082 #1127155 #1127561 #1127725
#1127731 #1127961 #1128166 #1128452 #1128565
#1128696 #1128756 #1128893 #1129080 #1129179
#1129237 #1129238 #1129239 #1129240 #1129241
#1129413 #1129414 #1129415 #1129416 #1129417
#1129418 #1129419 #1129581 #1129770 #1129923
Cross-References: CVE-2019-2024 CVE-2019-9213
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that solves two vulnerabilities and has 53 fixes
is now available.
Description:
The openSUSE Leap 42.3 kernel was updated to 4.4.176 to receive various
security and bugfixes.
The following security bugs were fixed:
- CVE-2019-9213: expand_downwards in mm/mmap.c lacked a check for the mmap
minimum address, which made it easier for attackers to exploit kernel
NULL pointer dereferences on non-SMAP platforms. This is related to a
capability check for the wrong task (bnc#1128166).
- CVE-2019-2024: A use-after-free when disconnecting a source was fixed
which could lead to crashes. bnc#1129179).
The following non-security bugs were fixed:
- ax25: fix possible use-after-free (bnc#1012382).
- block_dev: fix crash on chained bios with O_DIRECT (bsc#1090435).
- block: do not use bio->bi_vcnt to figure out segment number
(bsc#1128893).
- bnxt_re: Fix couple of memory leaks that could lead to IOMMU call traces
(bsc#1020413).
- bpf: fix replace_map_fd_with_map_ptr's ldimm64 second imm field
(bsc#1012382).
- btrfs: ensure that a DUP or RAID1 block group has exactly two stripes
(bsc#1128452).
- ceph: avoid repeatedly adding inode to mdsc->snap_flush_list
(bsc#1126773).
- ch: add missing mutex_lock()/mutex_unlock() in ch_release()
(bsc#1124235).
- ch: fixup refcounting imbalance for SCSI devices (bsc#1124235).
- copy_mount_string: Limit string length to PATH_MAX (bsc#1082943).
- device property: Fix the length used in PROPERTY_ENTRY_STRING()
(bsc#1129770).
- Drivers: hv: vmbus: Check for ring when getting debug info (bsc#1126389).
- drm: Fix error handling in drm_legacy_addctx (bsc#1106929)
- drm/nouveau/bios/ramcfg: fix missing parentheses when calculating RON
(bsc#1106929)
- drm/nouveau/pmu: do not print reply values if exec is false (bsc#1106929)
- drm/radeon/evergreen_cs: fix missing break in switch statement
(bsc#1106929)
- drm/vmwgfx: Do not double-free the mode stored in par->set_mode
(bsc#1103429)
- enic: add wq clean up budget (bsc#1075697, bsc#1120691. bsc#1102959).
- enic: do not overwrite error code (bnc#1012382).
- fbdev: chipsfb: remove set but not used variable 'size' (bsc#1106929)
- ibmvnic: Report actual backing device speed and duplex values
(bsc#1129923).
- ibmvscsi: Fix empty event pool access during host removal (bsc#1119019).
- Input: mms114 - fix license module information (bsc#1087092).
- iommu/dmar: Fix buffer overflow during PCI bus notification
(bsc#1129237).
- iommu/io-pgtable-arm-v7s: Only kmemleak_ignore L2 tables (bsc#1129238).
- iommu/vt-d: Check identity map for hot-added devices (bsc#1129239).
- iommu/vt-d: Fix NULL pointer reference in intel_svm_bind_mm()
(bsc#1129240).
- ixgbe: fix crash in build_skb Rx code path (git-fixes).
- kABI: protect struct inet_peer (kabi).
- kallsyms: Handle too long symbols in kallsyms.c (bsc#1126805).
- KMPs: obsolete older KMPs of the same flavour (bsc#1127155, bsc#1109137).
- KVM: arm/arm64: vgic-its: Check CBASER/BASER validity before enabling
the ITS (bsc#1109248).
- KVM: arm/arm64: vgic-its: Check GITS_BASER Valid bit before saving
tables (bsc#1109248).
- KVM: arm/arm64: vgic-its: Fix return value for device table restore
(bsc#1109248).
- KVM: arm/arm64: vgic-its: Fix vgic_its_restore_collection_table returned
value (bsc#1109248).
- kvm: nVMX: Do not halt vcpu when L1 is injecting events to L2
(bsc#1129413).
- kvm: nVMX: Free the VMREAD/VMWRITE bitmaps if alloc_kvm_area() fails
(bsc#1129414).
- kvm: nVMX: NMI-window and interrupt-window exiting should wake L2 from
HLT (bsc#1129415).
- kvm: nVMX: Set VM instruction error for VMPTRLD of unbacked page
(bsc#1129416).
- kvm: VMX: Do not allow reexecute_instruction() when skipping MMIO instr
(bsc#1129417).
- kvm: vmx: Set IA32_TSC_AUX for legacy mode guests (bsc#1129418).
- kvm: x86: Add AMD's EX_CFG to the list of ignored MSRs (bsc#1127082).
- kvm: x86: IA32_ARCH_CAPABILITIES is always supported (bsc#1129419).
- libceph: handle an empty authorize reply (bsc#1126772).
- mdio_bus: Fix use-after-free on device_register fails (git-fixes).
- mfd: as3722: Handle interrupts on suspend (bnc#1012382).
- mfd: as3722: Mark PM functions as __maybe_unused (bnc#1012382).
- mISDN: fix a race in dev_expire_timer() (bnc#1012382).
- mlxsw: pci: Correctly determine if descriptor queue is full (git-fixes).
- mlxsw: reg: Use correct offset in field definiton (git-fixes).
- mm, devm_memremap_pages: mark devm_memremap_pages() EXPORT_SYMBOL_GPL
(bnc#1012382).
- mm,memory_hotplug: fix scan_movable_pages() for gigantic hugepages
(bsc#1127731).
- net: Add header for usage of fls64() (bnc#1012382).
- net: Do not allocate page fragments that are not skb aligned
(bnc#1012382).
- net: dsa: bcm_sf2: Do not assume DSA master supports WoL (git-fixes).
- net: dsa: mv88e6xxx: fix port VLAN maps (git-fixes).
- net: Fix for_each_netdev_feature on Big endian (bnc#1012382).
- net: fix IPv6 prefix route residue (bnc#1012382).
- net/hamradio/6pack: Convert timers to use timer_setup() (git-fixes).
- net/hamradio/6pack: use mod_timer() to rearm timers (git-fixes).
- net: ipv4: use a dedicated counter for icmp_v4 redirect packets
(bnc#1012382).
- net: lan78xx: Fix race in tx pending skb size calculation (git-fixes).
- net/mlx4_core: drop useless LIST_HEAD (git-fixes).
- net/mlx4_core: Fix qp mtt size calculation (git-fixes).
- net/mlx4_core: Fix reset flow when in command polling mode (git-fixes).
- net/mlx4: Fix endianness issue in qp context params (git-fixes).
- net/mlx5: Continue driver initialization despite debugfs failure
(git-fixes).
- net/mlx5e: Fix TCP checksum in LRO buffers (git-fixes).
- net/mlx5: Fix driver load bad flow when having fw initializing timeout
(git-fixes).
- net/mlx5: fix uaccess beyond "count" in debugfs read/write handlers
(git-fixes).
- net/mlx5: Fix use-after-free in self-healing flow (git-fixes).
- net/mlx5: Return success for PAGE_FAULT_RESUME in internal error state
(git-fixes).
- net: mv643xx_eth: fix packet corruption with TSO and tiny unaligned
packets (git-fixes).
- net: phy: Avoid polling PHY with PHY_IGNORE_INTERRUPTS (git-fixes).
- net: phy: bcm7xxx: Fix shadow mode 2 disabling (git-fixes).
- net: qca_spi: Fix race condition in spi transfers (git-fixes).
- net: stmmac: Fix a race in EEE enable callback (bnc#1012382).
- net: stmmac: Fix a race in EEE enable callback (git-fixes).
- net: thunderx: set tso_hdrs pointer to NULL in nicvf_free_snd_queue
(git-fixes).
- net/x25: do not hold the cpu too long in x25_new_lci() (bnc#1012382).
- pci/pme: Fix hotplug/sysfs remove deadlock in pcie_pme_remove()
(bsc#1129241).
- perf/x86: Add sysfs entry to freeze counters on SMI (bsc#1121805).
- perf/x86/intel: Delay memory deallocation until x86_pmu_dead_cpu()
(bsc#1121805).
- perf/x86/intel: Do not enable freeze-on-smi for PerfMon V1 (bsc#1121805).
- perf/x86/intel: Fix memory corruption (bsc#1121805).
- perf/x86/intel: Generalize dynamic constraint creation (bsc#1121805).
- perf/x86/intel: Implement support for TSX Force Abort (bsc#1121805).
- perf/x86/intel: Make cpuc allocations consistent (bsc#1121805).
- phy: micrel: Ensure interrupts are reenabled on resume (git-fixes).
- powerpc/pseries: Add CPU dlpar remove functionality (bsc#1128756).
- powerpc/pseries: Consolidate CPU hotplug code to hotplug-cpu.c
(bsc#1128756).
- powerpc/pseries: Factor out common cpu hotplug code (bsc#1128756).
- powerpc/pseries: Perform full re-add of CPU for topology update
post-migration (bsc#1128756).
- pppoe: fix reception of frames with no mac header (git-fixes).
- pptp: dst_release sk_dst_cache in pptp_sock_destruct (git-fixes).
- pseries/energy: Use OF accessor function to read ibm,drc-indexes
(bsc#1129080).
- RDMA/bnxt_re: Synchronize destroy_qp with poll_cq (bsc#1125446).
- Refresh
patches.suse/scsi-do-not-print-reservation-conflict-for-TEST-UNIT.patch
(bsc#1119843)
- Revert "mm, devm_memremap_pages: mark devm_memremap_pages()
EXPORT_SYMBOL_GPL" (bnc#1012382).
- Revert "x86/platform/UV: Use efi_runtime_lock to serialise BIOS calls"
(bsc#1128565).
- s390/qeth: cancel close_dev work before removing a card (LTC#175898,
bsc#1127561).
- scsi: aacraid: Fix missing break in switch statement (bsc#1128696).
- scsi: ibmvscsi: Fix empty event pool access during host removal
(bsc#1119019).
- scsi: lpfc: do not set queue->page_count to 0 if pc_sli4_params.wqpcnt
is invalid (bsc#1127725).
- scsi: qla2xxx: Fix early srb free on abort (bsc#1121713).
- scsi: qla2xxx: Fix for double free of SRB structure (bsc#1121713).
- scsi: qla2xxx: Increase abort timeout value (bsc#1121713).
- scsi: qla2xxx: Move {get|rel}_sp to base_qpair struct (bsc#1121713).
- scsi: qla2xxx: Return switch command on a timeout (bsc#1121713).
- scsi: qla2xxx: Turn off IOCB timeout timer on IOCB completion
(bsc#1121713).
- scsi: qla2xxx: Use correct qpair for ABTS/CMD (bsc#1121713).
- scsi: sym53c8xx: fix NULL pointer dereference panic in sym_int_sir()
(bsc#1125315).
- sky2: Increase D3 delay again (bnc#1012382).
- tcp: clear icsk_backoff in tcp_write_queue_purge() (bnc#1012382).
- tcp: tcp_v4_err() should be more careful (bnc#1012382).
- team: avoid complex list operations in team_nl_cmd_options_set()
(bnc#1012382).
- team: Free BPF filter when unregistering netdev (git-fixes).
- tracing: Do not free iter->trace in fail path of tracing_open_pipe()
(bsc#1129581).
- vsock: cope with memory allocation failure at socket creation time
(bnc#1012382).
- vxlan: test dev->flags & IFF_UP before calling netif_rx() (bnc#1012382).
- wireless: airo: potential buffer overflow in sprintf() (bsc#1120902).
- x86: Add TSX Force Abort CPUID/MSR (bsc#1121805).
- x86: livepatch: Treat R_X86_64_PLT32 as R_X86_64_PC32 (bnc#1012382).
- xen, cpu_hotplug: Prevent an out of bounds access (bsc#1065600).
- xen: remove pre-xen3 fallback handlers (bsc#1065600).
- xfs: remove filestream item xfs_inode reference (bsc#1127961).
Special Instructions and Notes:
Please reboot the system after installing this update.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1085=1
Package List:
- openSUSE Leap 42.3 (x86_64):
kernel-debug-4.4.176-96.1
kernel-debug-base-4.4.176-96.1
kernel-debug-base-debuginfo-4.4.176-96.1
kernel-debug-debuginfo-4.4.176-96.1
kernel-debug-debugsource-4.4.176-96.1
kernel-debug-devel-4.4.176-96.1
kernel-debug-devel-debuginfo-4.4.176-96.1
kernel-default-4.4.176-96.1
kernel-default-base-4.4.176-96.1
kernel-default-base-debuginfo-4.4.176-96.1
kernel-default-debuginfo-4.4.176-96.1
kernel-default-debugsource-4.4.176-96.1
kernel-default-devel-4.4.176-96.1
kernel-obs-build-4.4.176-96.1
kernel-obs-build-debugsource-4.4.176-96.1
kernel-obs-qa-4.4.176-96.1
kernel-syms-4.4.176-96.1
kernel-vanilla-4.4.176-96.1
kernel-vanilla-base-4.4.176-96.1
kernel-vanilla-base-debuginfo-4.4.176-96.1
kernel-vanilla-debuginfo-4.4.176-96.1
kernel-vanilla-debugsource-4.4.176-96.1
kernel-vanilla-devel-4.4.176-96.1
- openSUSE Leap 42.3 (noarch):
kernel-devel-4.4.176-96.1
kernel-docs-4.4.176-96.1
kernel-docs-html-4.4.176-96.1
kernel-docs-pdf-4.4.176-96.1
kernel-macros-4.4.176-96.1
kernel-source-4.4.176-96.1
kernel-source-vanilla-4.4.176-96.1
References:
https://www.suse.com/security/cve/CVE-2019-2024.htmlhttps://www.suse.com/security/cve/CVE-2019-9213.htmlhttps://bugzilla.suse.com/1012382https://bugzilla.suse.com/1020413https://bugzilla.suse.com/1065600https://bugzilla.suse.com/1070767https://bugzilla.suse.com/1075697https://bugzilla.suse.com/1082943https://bugzilla.suse.com/1087092https://bugzilla.suse.com/1090435https://bugzilla.suse.com/1102959https://bugzilla.suse.com/1103429https://bugzilla.suse.com/1106929https://bugzilla.suse.com/1109137https://bugzilla.suse.com/1109248https://bugzilla.suse.com/1119019https://bugzilla.suse.com/1119843https://bugzilla.suse.com/1120691https://bugzilla.suse.com/1120902https://bugzilla.suse.com/1121713https://bugzilla.suse.com/1121805https://bugzilla.suse.com/1124235https://bugzilla.suse.com/1125315https://bugzilla.suse.com/1125446https://bugzilla.suse.com/1126389https://bugzilla.suse.com/1126772https://bugzilla.suse.com/1126773https://bugzilla.suse.com/1126805https://bugzilla.suse.com/1127082https://bugzilla.suse.com/1127155https://bugzilla.suse.com/1127561https://bugzilla.suse.com/1127725https://bugzilla.suse.com/1127731https://bugzilla.suse.com/1127961https://bugzilla.suse.com/1128166https://bugzilla.suse.com/1128452https://bugzilla.suse.com/1128565https://bugzilla.suse.com/1128696https://bugzilla.suse.com/1128756https://bugzilla.suse.com/1128893https://bugzilla.suse.com/1129080https://bugzilla.suse.com/1129179https://bugzilla.suse.com/1129237https://bugzilla.suse.com/1129238https://bugzilla.suse.com/1129239https://bugzilla.suse.com/1129240https://bugzilla.suse.com/1129241https://bugzilla.suse.com/1129413https://bugzilla.suse.com/1129414https://bugzilla.suse.com/1129415https://bugzilla.suse.com/1129416https://bugzilla.suse.com/1129417https://bugzilla.suse.com/1129418https://bugzilla.suse.com/1129419https://bugzilla.suse.com/1129581https://bugzilla.suse.com/1129770https://bugzilla.suse.com/1129923
openSUSE Security Update: Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork, runc
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1079-1
Rating: important
References: #1001161 #1048046 #1051429 #1112980 #1114832
#1118897 #1118898 #1118899 #1121412 #1121967
#1124308
Cross-References: CVE-2018-16873 CVE-2018-16874 CVE-2018-16875
CVE-2019-5736
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that solves four vulnerabilities and has 7 fixes
is now available.
Description:
This update for containerd, docker, docker-runc,
golang-github-docker-libnetwork, runc fixes the following issues:
Security issues fixed:
- CVE-2018-16875: Fixed a CPU Denial of Service (bsc#1118899).
- CVE-2018-16874: Fixed a vulnerabity in go get command which could allow
directory traversal in GOPATH mode (bsc#1118898).
- CVE-2018-16873: Fixed a vulnerability in go get command which could
allow remote code execution when executed with -u in GOPATH mode
(bsc#1118897).
- CVE-2019-5736: Effectively copying /proc/self/exe during re-exec to
avoid write attacks to the host runc binary, which could lead to a
container breakout (bsc#1121967).
Other changes and bug fixes:
- Update shell completion to use Group: System/Shells.
- Add daemon.json file with rotation logs configuration (bsc#1114832)
- Update to Docker 18.09.1-ce (bsc#1124308) and to to runc 96ec2177ae84.
See upstream changelog in the packaged
/usr/share/doc/packages/docker/CHANGELOG.md.
- Disable leap based builds for kubic flavor (bsc#1121412).
- Allow users to explicitly specify the NIS domain name of a container
(bsc#1001161).
- Update docker.service to match upstream and avoid rlimit problems
(bsc#1112980).
- Update go requirements to >= go1.10
- Use -buildmode=pie for tests and binary build (bsc#1048046 and
bsc#1051429).
- Remove the usage of 'cp -r' to reduce noise in the build logs.
This update was imported from the SUSE:SLE-12:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1079=1
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
containerd-1.2.2-22.1
containerd-ctr-1.2.2-22.1
containerd-kubic-1.2.2-22.1
containerd-kubic-ctr-1.2.2-22.1
docker-libnetwork-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
docker-libnetwork-debuginfo-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
docker-libnetwork-kubic-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
docker-libnetwork-kubic-debuginfo-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
docker-runc-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-debuginfo-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-debugsource-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-kubic-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-kubic-debuginfo-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-kubic-debugsource-1.0.0rc6+gitr3748_96ec2177ae84-11.1
golang-github-docker-libnetwork-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
golang-github-docker-libnetwork-debugsource-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
golang-github-docker-libnetwork-kubic-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
golang-github-docker-libnetwork-kubic-debugsource-0.7.0.1+gitr2711_2cfbf9b1f981-11.1
- openSUSE Leap 42.3 (noarch):
containerd-kubic-test-1.2.2-22.1
containerd-test-1.2.2-22.1
docker-bash-completion-18.09.1_ce-54.1
docker-kubic-bash-completion-18.09.1_ce-54.1
docker-kubic-zsh-completion-18.09.1_ce-54.1
docker-runc-kubic-test-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-runc-test-1.0.0rc6+gitr3748_96ec2177ae84-11.1
docker-zsh-completion-18.09.1_ce-54.1
- openSUSE Leap 42.3 (x86_64):
docker-18.09.1_ce-54.1
docker-debuginfo-18.09.1_ce-54.1
docker-debugsource-18.09.1_ce-54.1
docker-kubic-18.09.1_ce-54.1
docker-kubic-debuginfo-18.09.1_ce-54.1
docker-kubic-debugsource-18.09.1_ce-54.1
docker-kubic-kubeadm-criconfig-18.09.1_ce-54.1
docker-kubic-test-18.09.1_ce-54.1
docker-kubic-test-debuginfo-18.09.1_ce-54.1
docker-test-18.09.1_ce-54.1
docker-test-debuginfo-18.09.1_ce-54.1
References:
https://www.suse.com/security/cve/CVE-2018-16873.htmlhttps://www.suse.com/security/cve/CVE-2018-16874.htmlhttps://www.suse.com/security/cve/CVE-2018-16875.htmlhttps://www.suse.com/security/cve/CVE-2019-5736.htmlhttps://bugzilla.suse.com/1001161https://bugzilla.suse.com/1048046https://bugzilla.suse.com/1051429https://bugzilla.suse.com/1112980https://bugzilla.suse.com/1114832https://bugzilla.suse.com/1118897https://bugzilla.suse.com/1118898https://bugzilla.suse.com/1118899https://bugzilla.suse.com/1121412https://bugzilla.suse.com/1121967https://bugzilla.suse.com/1124308
openSUSE Recommended Update: Recommended update for cmake
______________________________________________________________________________
Announcement ID: openSUSE-RU-2019:1080-1
Rating: moderate
References: #1129024
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that has one recommended fix can now be installed.
Description:
This update for cmake fixes the following issues:
- Add support for %cmake_build macro for compat with newer systems
(bsc#1129024)
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1080=1
Package List:
- openSUSE Leap 15.0 (i586 x86_64):
cmake-3.10.2-lp150.2.3.1
cmake-debuginfo-3.10.2-lp150.2.3.1
cmake-debugsource-3.10.2-lp150.2.3.1
- openSUSE Leap 15.0 (x86_64):
cmake-gui-3.10.2-lp150.2.3.1
cmake-gui-debuginfo-3.10.2-lp150.2.3.1
cmake-gui-debugsource-3.10.2-lp150.2.3.1
cmake-man-3.10.2-lp150.2.3.1
References:
https://bugzilla.suse.com/1129024
openSUSE Recommended Update: Recommended update for open-vm-tools
______________________________________________________________________________
Announcement ID: openSUSE-RU-2019:1078-1
Rating: moderate
References: #1115118 #1121964 #1122435 #1124397
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that has four recommended fixes can now be
installed.
Description:
This update fixes the following issues:
- Link VGAuthService to libxmlsec1 rather than libxml-security-c in SLE
products where available (bsc#1122435)
- Improves handling of certain quiesced snapshot failures (bsc#1124397)
- Update vmtoolsd.service to support cloud-init customization by default
by adding "DefaultDependencies=no" and "Before=cloud-init-local.service"
to the [Unit] section
of vmtoolsd.service (bsc#1121964)
- Update open-vm-tools to 10.3.5 (bsc#1115118)
- Bugfix: open-vm-tools has logged warnings, when taking a snapshot of a
Linux guest on a vSphere host
- Bugfix: open-vm-tools service crashed on Linux systems which are not
running on a VMware platform
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Patch Instructions:
To install this openSUSE Recommended Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1078=1
Package List:
- openSUSE Leap 42.3 (x86_64):
libvmtools-devel-10.3.5-22.1
libvmtools0-10.3.5-22.1
libvmtools0-debuginfo-10.3.5-22.1
open-vm-tools-10.3.5-22.1
open-vm-tools-debuginfo-10.3.5-22.1
open-vm-tools-debugsource-10.3.5-22.1
open-vm-tools-desktop-10.3.5-22.1
open-vm-tools-desktop-debuginfo-10.3.5-22.1
References:
https://bugzilla.suse.com/1115118https://bugzilla.suse.com/1121964https://bugzilla.suse.com/1122435https://bugzilla.suse.com/1124397
openSUSE Security Update: Security update for MozillaFirefox
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1077-1
Rating: important
References: #1129821 #1130262
Cross-References: CVE-2018-18506 CVE-2019-9788 CVE-2019-9790
CVE-2019-9791 CVE-2019-9792 CVE-2019-9793
CVE-2019-9794 CVE-2019-9795 CVE-2019-9796
CVE-2019-9810 CVE-2019-9813
Affected Products:
openSUSE Leap 15.0
______________________________________________________________________________
An update that fixes 11 vulnerabilities is now available.
Description:
This update for MozillaFirefox fixes the following issues:
Mozilla Firefox was updated to 60.6.1esr / MFSA 2019-10 (bsc#1130262)
* CVE-2019-9810: IonMonkey MArraySlice has incorrect alias information
* CVE-2019-9813: Ionmonkey type confusion with __proto__ mutations
Mozilla Firefox was updated to 60.6.0esr / MFSA 2019-08 (boo#1129821)
* CVE-2019-9790: Use-after-free when removing in-use DOM elements
* CVE-2019-9791: Type inference is incorrect for constructors entered
through on-stack replacement with IonMonkey
* CVE-2019-9792: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script
* CVE-2019-9793: Improper bounds checks when Spectre mitigations are
disabled
* CVE-2019-9794: Command line arguments not discarded during execution
* CVE-2019-9795: Type-confusion in IonMonkey JIT compiler
* CVE-2019-9796: Use-after-free with SMIL animation controller
* CVE-2018-18506: Proxy Auto-Configuration file can define localhost
access to be proxied
* CVE-2019-9788: Memory safety bugs fixed in Firefox 66 and Firefox ESR
60.6
Mozilla Firefox 60.5.2esr also had one change:
* Fix a frequent crash when reading various Reuters news articles.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.0:
zypper in -t patch openSUSE-2019-1077=1
Package List:
- openSUSE Leap 15.0 (x86_64):
MozillaFirefox-60.6.1-lp150.3.45.1
MozillaFirefox-branding-upstream-60.6.1-lp150.3.45.1
MozillaFirefox-buildsymbols-60.6.1-lp150.3.45.1
MozillaFirefox-debuginfo-60.6.1-lp150.3.45.1
MozillaFirefox-debugsource-60.6.1-lp150.3.45.1
MozillaFirefox-devel-60.6.1-lp150.3.45.1
MozillaFirefox-translations-common-60.6.1-lp150.3.45.1
MozillaFirefox-translations-other-60.6.1-lp150.3.45.1
References:
https://www.suse.com/security/cve/CVE-2018-18506.htmlhttps://www.suse.com/security/cve/CVE-2019-9788.htmlhttps://www.suse.com/security/cve/CVE-2019-9790.htmlhttps://www.suse.com/security/cve/CVE-2019-9791.htmlhttps://www.suse.com/security/cve/CVE-2019-9792.htmlhttps://www.suse.com/security/cve/CVE-2019-9793.htmlhttps://www.suse.com/security/cve/CVE-2019-9794.htmlhttps://www.suse.com/security/cve/CVE-2019-9795.htmlhttps://www.suse.com/security/cve/CVE-2019-9796.htmlhttps://www.suse.com/security/cve/CVE-2019-9810.htmlhttps://www.suse.com/security/cve/CVE-2019-9813.htmlhttps://bugzilla.suse.com/1129821https://bugzilla.suse.com/1130262
openSUSE Security Update: Security update for qemu
______________________________________________________________________________
Announcement ID: openSUSE-SU-2019:1074-1
Rating: important
References: #1056334 #1056386 #1084604 #1113231 #1114957
#1116717 #1117275 #1119493 #1121600 #1123156
Cross-References: CVE-2017-13672 CVE-2017-13673 CVE-2018-16872
CVE-2018-18954 CVE-2018-19364 CVE-2018-19489
CVE-2018-7858 CVE-2019-6778
Affected Products:
openSUSE Leap 42.3
______________________________________________________________________________
An update that solves 8 vulnerabilities and has two fixes
is now available.
Description:
This update for qemu fixes the following issues:
Security vulnerabilities addressed:
- CVE-2019-6778: Fixed an out-of-bounds access in slirp (bsc#1123156)
- CVE-2018-16872: Fixed a host security vulnerability related to handling
symlinks in usb-mtp (bsc#1119493)
- CVE-2018-19489: Fixed a Denial-of-Service in virtfs (bsc#1117275)
- CVE-2018-19364: Fixed an use-after-free vulnerability if virtfs
interface is deliberately abused (bsc#1116717)
- CVE-2018-18954: Fixed an out-of-bounds access performing PowerNV memory
operations (bsc#1114957)
- CVE-2017-13673: Fixed a reachable assert failure during during display
update (bsc#1056386)
- CVE-2017-13672: Fixed an out-of-bounds read access during display update
(bsc#1056334)
- CVE-2018-7858: Fixed an out-of-bounds access in cirrus when updating vga
display allowing for Denial-of-Service (bsc#1084604)
Other bug fixes and changes:
- Fix pwrite64/pread64/write to return 0 over -1 for a zero length NULL
buffer in qemu (bsc#1121600)
- Fix bad guest time after migration (bsc#1113231)
This update was imported from the SUSE:SLE-12-SP3:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2019-1074=1
Package List:
- openSUSE Leap 42.3 (i586 x86_64):
qemu-linux-user-2.9.1-56.1
qemu-linux-user-debuginfo-2.9.1-56.1
qemu-linux-user-debugsource-2.9.1-56.1
- openSUSE Leap 42.3 (noarch):
qemu-ipxe-1.0.0+-56.1
qemu-seabios-1.10.2-56.1
qemu-sgabios-8-56.1
qemu-vgabios-1.10.2-56.1
- openSUSE Leap 42.3 (x86_64):
qemu-2.9.1-56.1
qemu-arm-2.9.1-56.1
qemu-arm-debuginfo-2.9.1-56.1
qemu-block-curl-2.9.1-56.1
qemu-block-curl-debuginfo-2.9.1-56.1
qemu-block-dmg-2.9.1-56.1
qemu-block-dmg-debuginfo-2.9.1-56.1
qemu-block-iscsi-2.9.1-56.1
qemu-block-iscsi-debuginfo-2.9.1-56.1
qemu-block-rbd-2.9.1-56.1
qemu-block-rbd-debuginfo-2.9.1-56.1
qemu-block-ssh-2.9.1-56.1
qemu-block-ssh-debuginfo-2.9.1-56.1
qemu-debugsource-2.9.1-56.1
qemu-extra-2.9.1-56.1
qemu-extra-debuginfo-2.9.1-56.1
qemu-guest-agent-2.9.1-56.1
qemu-guest-agent-debuginfo-2.9.1-56.1
qemu-ksm-2.9.1-56.1
qemu-kvm-2.9.1-56.1
qemu-lang-2.9.1-56.1
qemu-ppc-2.9.1-56.1
qemu-ppc-debuginfo-2.9.1-56.1
qemu-s390-2.9.1-56.1
qemu-s390-debuginfo-2.9.1-56.1
qemu-testsuite-2.9.1-56.2
qemu-tools-2.9.1-56.1
qemu-tools-debuginfo-2.9.1-56.1
qemu-x86-2.9.1-56.1
qemu-x86-debuginfo-2.9.1-56.1
References:
https://www.suse.com/security/cve/CVE-2017-13672.htmlhttps://www.suse.com/security/cve/CVE-2017-13673.htmlhttps://www.suse.com/security/cve/CVE-2018-16872.htmlhttps://www.suse.com/security/cve/CVE-2018-18954.htmlhttps://www.suse.com/security/cve/CVE-2018-19364.htmlhttps://www.suse.com/security/cve/CVE-2018-19489.htmlhttps://www.suse.com/security/cve/CVE-2018-7858.htmlhttps://www.suse.com/security/cve/CVE-2019-6778.htmlhttps://bugzilla.suse.com/1056334https://bugzilla.suse.com/1056386https://bugzilla.suse.com/1084604https://bugzilla.suse.com/1113231https://bugzilla.suse.com/1114957https://bugzilla.suse.com/1116717https://bugzilla.suse.com/1117275https://bugzilla.suse.com/1119493https://bugzilla.suse.com/1121600https://bugzilla.suse.com/1123156