---
title: "CVE-2019-9511"
canonical: "https://kb.cynergy.app/space/MD/899350993/CVE-2019-9511"
format: markdown
---
**Description:**

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to queue the data in 1-byte chunks. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

**Published On:**

2019-08-13

**Updated On:**

2022-02-22

**Trending:**

FALSE

**CWE:**

CWE-770

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| RHSA-2019:2925 | OpenSource | nodejs-packaging-17-3.module+el8+2873+aa7dfd9a | An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2019:2925](https://access.redhat.com/errata/RHSA-2019:2925) |
| RHSA-2019:2799 | OpenSource | nginx-1.14.1-9.module+el8.0.0+4108+af250afe | An update for the nginx:1.14 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2019:2799](https://access.redhat.com/errata/RHSA-2019:2799) |
| RHSA-2019:2692 | OpenSource | nghttp2-1.33.0-1.el8_0.1 | An update for nghttp2 is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2019:2692](https://access.redhat.com/errata/RHSA-2019:2692) |
| MGASA-2019-0291 | mageia | Updated nghttp2 packages fix security vulnerabilities | The updated packages fix security vulnerabilities:<br>Some HTTP/2 implementations are vulnerable to window size manipulation  
and stream prioritization manipulation, potentially leading to a denial  
of service. The attacker requests a large amount of data from a specified  
resource over multiple streams. They manipulate window size and stream  
priority to force the server to queue the data in 1-byte chunks. Depending  
on how efficiently this data is queued, this can consume excess CPU,  
memory, or both. (CVE-2019-9511)<br>Some HTTP/2 implementations are vulnerable to resource loops, potentially  
leading to a denial of service. The attacker creates multiple request  
streams and continually shuffles the priority of the streams in a way that  
causes substantial churn to the priority tree. This can consume excess CPU.  
(CVE-2019-9513) | 2019-09-30 | [http://advisories.mageia.org/MGASA-2019-0291.html](http://advisories.mageia.org/MGASA-2019-0291.html) |
| MGASA-2019-0342 | mageia | Updated nginx packages fix security vulnerabilities | Updated nginx packages fix security vulnerabilities:<br>When using HTTP/2 a client might cause excessive memory consumption and  
CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516). | 2020-04-13 | [http://advisories.mageia.org/MGASA-2019-0342.html](http://advisories.mageia.org/MGASA-2019-0342.html) |
| openSUSE-SU-2019:2115-1 | suse | Security update for nodejs8 | This update for nodejs8 to version 8.16.1 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).<br>Bug fixes:<br>- Fixed that npm resolves its default config file like in all other versions, as /etc/nodejs/npmrc (bsc#1144919).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2019-09-11 | [http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html) |
| openSUSE-SU-2019:2114-1 | suse | Security update for nodejs10 | This update for nodejs10 to version 10.16.3 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2019-09-11 | [http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html) |
| openSUSE-SU-2019:2120-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2019-09-11 | [http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html) |
| openSUSE-SU-2019:2232-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).<br>Bug fixes and enhancements:<br>- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Feature: Add W&S module (FATE#326776, bsc#1112438)<br>This update was imported from the SUSE:SLE-15:Update update project. | 2019-10-03 | [http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html) |
| openSUSE-SU-2019:2234-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).<br>Bug fixes and enhancements:<br>- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Feature: Add W&S module (FATE#326776, bsc#1112438)<br>This update was imported from the SUSE:SLE-15:Update update project. | 2019-10-03 | [http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html) |
| openSUSE-SU-2019:2264-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2019-10-07 | [http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html](http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html) |
| CPUOct2019 | oracle | Oracle Critical Patch Update Advisory - October 2019 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2019-10-17 | [http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html) |
| RHSA-2019:2692 | redhat | Red Hat Security Advisory: nghttp2 security update | An update for nghttp2 is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-11 | [https://access.redhat.com/errata/RHSA-2019:2692](https://access.redhat.com/errata/RHSA-2019:2692) |
| RHSA-2019:2745 | redhat | Red Hat Security Advisory: rh-nginx110-nginx security update | An update for rh-nginx110-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-13 | [https://access.redhat.com/errata/RHSA-2019:2745](https://access.redhat.com/errata/RHSA-2019:2745) |
| RHSA-2019:2746 | redhat | Red Hat Security Advisory: rh-nginx112-nginx security update | An update for rh-nginx112-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-13 | [https://access.redhat.com/errata/RHSA-2019:2746](https://access.redhat.com/errata/RHSA-2019:2746) |
| RHSA-2019:2775 | redhat | Red Hat Security Advisory: rh-nginx114-nginx security update | An update for rh-nginx114-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-18 | [https://access.redhat.com/errata/RHSA-2019:2775](https://access.redhat.com/errata/RHSA-2019:2775) |
| RHSA-2019:2799 | redhat | Red Hat Security Advisory: nginx:1.14 security update | An update for the nginx:1.14 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-20 | [https://access.redhat.com/errata/RHSA-2019:2799](https://access.redhat.com/errata/RHSA-2019:2799) |
| RHSA-2019:2925 | redhat | Red Hat Security Advisory: nodejs:10 security update | An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-09-30 | [https://access.redhat.com/errata/RHSA-2019:2925](https://access.redhat.com/errata/RHSA-2019:2925) |
| RHSA-2019:2939 | redhat | Red Hat Security Advisory: rh-nodejs10-nodejs security update | An update for rh-nodejs10-nodejs is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-01 | [https://access.redhat.com/errata/RHSA-2019:2939](https://access.redhat.com/errata/RHSA-2019:2939) |
| RHSA-2019:2949 | redhat | Red Hat Security Advisory: httpd24-httpd and httpd24-nghttp2 security update | An update for httpd24-httpd and httpd24-nghttp2 is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-03 | [https://access.redhat.com/errata/RHSA-2019:2949](https://access.redhat.com/errata/RHSA-2019:2949) |
| RHSA-2019:2955 | redhat | Red Hat Security Advisory: rh-nodejs8-nodejs security update | An update for rh-nodejs8-nodejs is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-03 | [https://access.redhat.com/errata/RHSA-2019:2955](https://access.redhat.com/errata/RHSA-2019:2955) |
| RHSA-2019:2966 | redhat | Red Hat Security Advisory: Red Hat Quay v3.1.1 security update | Updated Quay packages that fix several bugs and add various enhancements are now available.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-05 | [https://access.redhat.com/errata/RHSA-2019:2966](https://access.redhat.com/errata/RHSA-2019:2966) |
| RHSA-2019:3041 | redhat | Red Hat Security Advisory: Red Hat OpenShift Service Mesh 1.0.1 RPMs | Red Hat OpenShift Service Mesh 1.0.1.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-10-15 | [https://access.redhat.com/errata/RHSA-2019:3041](https://access.redhat.com/errata/RHSA-2019:3041) |
| RHSA-2019:3932 | redhat | Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 6 | Updated packages that provide Red Hat JBoss Core Services Pack Apache Server 2.4.37 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-21 | [https://access.redhat.com/errata/RHSA-2019:3932](https://access.redhat.com/errata/RHSA-2019:3932) |
| RHSA-2019:3933 | redhat | Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release on RHEL 7 | An update is now available for JBoss Core Services on RHEL 7.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-21 | [https://access.redhat.com/errata/RHSA-2019:3933](https://access.redhat.com/errata/RHSA-2019:3933) |
| RHSA-2019:3935 | redhat | Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Security Release | Red Hat JBoss Core Services Pack Apache Server 2.4.37 zip release  
for RHEL 6, RHEL 7 and Microsoft Windows is available.<br>Red Hat Product Security has rated this update as having a security impact  
of Important. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability  
from the CVE link(s) in the References section. | 2019-11-21 | [https://access.redhat.com/errata/RHSA-2019:3935](https://access.redhat.com/errata/RHSA-2019:3935) |
| RHSA-2019:4018 | redhat | Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.5 on RHEL 6 security update | An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 6.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-27 | [https://access.redhat.com/errata/RHSA-2019:4018](https://access.redhat.com/errata/RHSA-2019:4018) |
| RHSA-2019:4019 | redhat | Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.5 on RHEL 7 security update | An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 7.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-27 | [https://access.redhat.com/errata/RHSA-2019:4019](https://access.redhat.com/errata/RHSA-2019:4019) |
| RHSA-2019:4020 | redhat | Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.5 on RHEL 8 security update | An update is now available for Red Hat JBoss Enterprise Application Platform 7.2 for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-27 | [https://access.redhat.com/errata/RHSA-2019:4020](https://access.redhat.com/errata/RHSA-2019:4020) |
| RHSA-2019:4021 | redhat | Red Hat Security Advisory: Red Hat JBoss Enterprise Application Platform 7.2.5 security update | An update is now available for Red Hat JBoss Enterprise Application Platform 7.2.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2019-11-27 | [https://access.redhat.com/errata/RHSA-2019:4021](https://access.redhat.com/errata/RHSA-2019:4021) |
| RHSA-2020:0922 | redhat | Red Hat Security Advisory: Red Hat AMQ Broker 7.6 release and security update | Red Hat AMQ Broker 7.6 is now available from the Red Hat Customer Portal.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-03-23 | [https://access.redhat.com/errata/RHSA-2020:0922](https://access.redhat.com/errata/RHSA-2020:0922) |
| RHSA-2020:3192 | redhat | Red Hat Security Advisory: Red Hat Fuse 7.7.0 release and security update | A minor version update (from 7.6 to 7.7) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2020-07-29 | [https://access.redhat.com/errata/RHSA-2020:3192](https://access.redhat.com/errata/RHSA-2020:3192) |
| FEDORA-2019-4427fd65be | fedora | Fedora 29 Update: mod_http2-1.15.3-2.fc29 | Rebuilt with newer nghttp2 | 2019-08-30 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-4427fd65be](https://bodhi.fedoraproject.org/updates/FEDORA-2019-4427fd65be) |
| FEDORA-2019-63ba15cc83 | fedora | Fedora 30 Update: mod_http2-1.15.3-2.fc30 | Rebuilt with newer nghttp2  ----  This update includes the latest upstream  
release of `mod_http2`, version **1.15.3**.  Upstream changes include:  * fixes  
Timeout vs. KeepAliveTimeout behaviour, see PR 63534. * Fixes stream cleanup  
when connection throttling is in place. * Counts stream resets by client on  
streams initiated by client as cause for connection throttling. * Header length  
checks are now logged similar to HTTP/1.1 protocol handler  * Header length is  
checked also on the merged value from several header instances and results in a  
431 response. * fixing mod_proxy_http2 to support trailers in both directions.  
See PR 63502. | 2019-08-31 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-63ba15cc83](https://bodhi.fedoraproject.org/updates/FEDORA-2019-63ba15cc83) |
| FEDORA-2019-7a0b45fdc4 | fedora | Fedora 29 Update: nginx-1.16.1-1.fc29 | Security fix for CVE-2019-9511, CVE-2019-9513, CVE-2019-9516 | 2020-10-10 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-7a0b45fdc4](https://bodhi.fedoraproject.org/updates/FEDORA-2019-7a0b45fdc4) |
| FEDORA-2019-81985a8858 | fedora | Fedora 30 Update: nghttp2-1.39.2-1.fc30 | - update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513) | 2019-08-23 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-81985a8858](https://bodhi.fedoraproject.org/updates/FEDORA-2019-81985a8858) |
| FEDORA-2019-8a437d5c2f | fedora | Fedora 29 Update: nghttp2-1.39.2-1.fc29 | - update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513) | 2019-08-28 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-8a437d5c2f](https://bodhi.fedoraproject.org/updates/FEDORA-2019-8a437d5c2f) |
| FEDORA-2019-befd924cfe | fedora | Fedora 30 Update: nginx-1.16.1-1.fc30 | Fixes CVE-2019-9511, CVE-2019-9513, CVE-2019-9516 | 2019-08-22 | [https://bodhi.fedoraproject.org/updates/FEDORA-2019-befd924cfe](https://bodhi.fedoraproject.org/updates/FEDORA-2019-befd924cfe) |
| openSUSE-SU-2019:2115-1 | suse | Security update for nodejs8 | This update for nodejs8 to version 8.16.1 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).<br>Bug fixes:<br>- Fixed that npm resolves its default config file like in all other versions, as /etc/nodejs/npmrc (bsc#1144919).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html](https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html) |
| openSUSE-SU-2019:2114-1 | suse | Security update for nodejs10 | This update for nodejs10 to version 10.16.3 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html](https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html) |
| openSUSE-SU-2019:2120-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025).<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html](https://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html) |
| openSUSE-SU-2019:2232-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).<br>Bug fixes and enhancements:<br>- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Feature: Add W&S module (FATE#326776, bsc#1112438)<br>This update was imported from the SUSE:SLE-15:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html](https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00003.html) |
| openSUSE-SU-2019:2234-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).<br>Bug fixes and enhancements:<br>- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Feature: Add W&S module (FATE#326776, bsc#1112438)<br>This update was imported from the SUSE:SLE-15:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html](https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00005.html) |
| openSUSE-SU-2019:2264-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).<br>This update was imported from the SUSE:SLE-15:Update update project. | 2021-04-16 | [https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html](https://lists.opensuse.org/opensuse-security-announce/2019-10/msg00014.html) |
| SUSE Image SUSE-IU-2022:42-1 | suse | SUSE-IU-2022:42-1 | This image update for google/sles-12-sp4-byos-v20220126 contains the following changes:  
Package SUSEConnect was updated:<br>- Update to 0.3.32- Allow --regcode and --instance-data attributes at the same time (jsc#PCT-164)
- Document that 'debug' can also get set in the config file
- --status will also print the subscription name
- Update to 0.3.31
- Disallow registering via SUSEConnect if the system is managed by SUSE Manager.
- Add subscription name to output of 'SUSEConnect --status'
- Update to 0.3.30
- send payload of GET requests as part of the url,<br>not in the body (see bsc#1185611)<br>Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package at was updated:<br>- Increase TasksMax limit from 512 (systemd default) to 4915,  fix bsc#1058557<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bash-4.3-boo1192785.patch  * setuid causing permission denied on popen (bsc#1192785)
- Add patch bsc1177369.patch to fix bsc#1177369
- tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Fixed CVE-2021-25219:  The lame-ttl option controls how long named caches certain types<br>of broken responses from authoritative servers (see the security  
  advisory for details). This caching mechanism could be abused by  
  an attacker to significantly degrade resolver performance. The  
  vulnerability has been mitigated by changing the default value of  
  lame-ttl to 0 and overriding any explicitly set value with 0,  
  effectively disabling this mechanism altogether. ISC's testing has  
  determined that doing that has a negligible impact on resolver  
  performance while also preventing abuse.  
  Administrators may observe more traffic towards servers issuing  
  certain types of broken responses than in previous BIND 9 releases.  
  [bsc#1192146, CVE-2021-25219, bind-CVE-2021-25219.patch]<br>- Some debugs were still in the patch for bsc#1181495.<br>[bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package binutils was updated:<br>- Add binutils-revert-hlasm-insns.diff for compatibility on old  code stream that expect 'brcl 0,label' to not be disassembled<br>as 'jgnop label' on s390x.  [bsc#1192267]<br>- Rebase binutils-2.37-branch.diff: fixes PR28523 aka boo#1188941.
- Fix empty man-pages from broken release tarball [PR28144].
- Update binutils-skip-rpaths.patch with contained a memory corruption<br>(boo#1191473).<br>- Configure with --disable-x86-used-note on old code streams.
- Disable libalternatives temporarily for build cycle reasons.
- make TARGET-bfd=headers again, we patch bfd-in.h
- This state submitted to SLE12 and SLE15 code streams for annual<br>toolchain update. [jsc#PM-2767, jsc#SLE-21561, jsc#SLE-19618]<br>- Bump binutils-2.37-branch.diff to 66d5c7003, to include fixes for<br>PR28422, PR28192, PR28391.  Also adds some s390x arch14  
  instructions [jsc#SLE-18637].<br>- Using libalternatives instead of update-alternatives.
- Adjust for testsuite fails on older products that configure<br>binutils in different ways, adds  binutils-compat-old-behaviour.diff  
  and adjusts binutils-revert-nm-symversion.diff and  
  binutils-revert-plt32-in-branches.diff.<br>- Bump binutils-2.37-branch.diff: fixes PR28138.
- Use LTO &amp; PGO build.
- Update to binutils 2.37:
- The GNU Binutils sources now requires a C99 compiler and library to<br>build.<br>- Support for the arm-symbianelf format has been removed.
- Support for Realm Management Extension (RME) for AArch64 has been<br>added.<br>- A new linker option '-z report-relative-reloc' for x86 ELF targets<br>has been added to report dynamic relative relocations.<br>- A new linker option '-z start-stop-gc' has been added to disable<br>special treatment of __start_*/__stop_* references when<br>- -gc-sections.
- A new linker options '-Bno-symbolic' has been added which will<br>cancel the '-Bsymbolic' and '-Bsymbolic-functions' options.<br>- The readelf tool has a new command line option which can be used to<br>specify how the numeric values of symbols are reported.<br>- -sym-base=0|8|10|16 tells readelf to display the values in base 8,<br>base 10 or base 16.  A sym base of 0 represents the default action  
    of displaying values under 10000 in base 10 and values above that in  
    base 16.<br>- A new format has been added to the nm program.  Specifying<br>'--format=just-symbols' (or just using -j) will tell the program to  
    only display symbol names and nothing else.<br>- A new command line option '--keep-section-symbols' has been added to<br>objcopy and strip.  This stops the removal of unused section symbols  
    when the file is copied.  Removing these symbols saves space, but  
    sometimes they are needed by other tools.<br>- The '--weaken', '--weaken-symbol' and '--weaken-symbols' options<br>supported by objcopy now make undefined symbols weak on targets that  
    support weak symbols.<br>- Readelf and objdump can now display and use the contents of .debug_sup<br>sections.<br>- Readelf and objdump will now follow links to separate debug info<br>files by default.  This behaviour can be stopped via the use of the  
    new '-wN' or '--debug-dump=no-follow-links' options for readelf and  
    the '-WN' or '--dwarf=no-follow-links' options for objdump.  Also  
    the old behaviour can be restored by the use of the  
    '--enable-follow-debug-links=no' configure time option.  
    The semantics of the =follow-links option have also been slightly  
    changed.  When enabled, the option allows for the loading of symbol  
    tables and string tables from the separate files which can be used  
    to enhance the information displayed when dumping other sections,  
    but it does not automatically imply that information from the  
    separate files should be displayed.  
    If other debug section display options are also enabled (eg  
    '--debug-dump=info') then the contents of matching sections in both  
    the main file and the separate debuginfo file *will* be displayed.  
    This is because in most cases the debug section will only be present  
    in one of the files.  
    If however non-debug section display options are enabled (eg  
    '--sections') then the contents of matching parts of the separate  
    debuginfo file will *not* be displayed.  This is because in most  
    cases the user probably only wanted to load the symbol information  
    from the separate debuginfo file.  In order to change this behaviour  
    a new command line option --process-links can be used.  This will  
    allow di0pslay options to applied to both the main file and any  
    separate debuginfo files.<br>- Nm has a new command line option: '--quiet'.  This suppresses &quot;/no<br>symbols&quot;/ diagnostic.<br>- Includes fixes for these CVEs:<br>bnc#1181452 aka CVE-2021-20197 aka PR26945  
  bnc#1183511 aka CVE-2021-20284 aka PR26931  
  bnc#1184519 aka CVE-2021-20294 aka PR26929  
  bnc#1184620 aka CVE-2021-3487 aka PR26946  
  bnc#1184794 aka CVE-2020-35448 aka PR26574<br>- Also fixes:<br>bsc#1183909 - slow performance of stripping some binaries<br>- Rebased patches: binutils-build-as-needed.diff, binutils-fix-abierrormsg.diff,<br>binutils-fix-invalid-op-errata.diff, binutils-fix-relax.diff,  
  binutils-revert-nm-symversion.diff, binutils-revert-plt32-in-branches.diff<br>- Removed patches (are in upstream): ppc-ensure-undef-dynamic-weak-undefined.patch and<br>ppc-use-local-plt.patch.<br>- Add binutils-2.37-branch.diff.gz.
- ppc-ensure-undef-dynamic-weak-undefined.patch: PPC: ensure_undef_dynamic<br>on weak undef only in plt<br>- ppc-use-local-plt.patch: PowerPC use_local_plt (prerequisite for above<br>patch)<br>- Update 2.36 branch diff which fixes PR27587.
- Do not run make TARGET-bfd=headers separately.
- Bump 2.36 branch diff (includes fix for PR27441 aka bsc#1182252).
- Bump 2.36 branch diff.
- Update 2.36 branch diff which should fix PR27311 completely.<br>It fixes also PR27284.<br>- Remove temporary fix 0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.
- Add temporary upstream fix for PR27311<br>0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.<br>- Update to binutils 2.36:<br>New features in the Assembler:  
    General:<br>- When setting the link order attribute of ELF sections, it is now<br>possible to use a numeric section index instead of symbol name.<br>- Added a .nop directive to generate a single no-op instruction in<br>a target neutral manner.  This instruction does have an effect on  
    DWARF line number generation, if that is active.<br>- Removed --reduce-memory-overheads and --hash-size as gas now<br>uses hash tables that can be expand and shrink automatically.  
    X86/x86_64:<br>- Add support for AVX VNNI, HRESET, UINTR, TDX, AMX and Key<br>Locker instructions.<br>- Support non-absolute segment values for lcall and ljmp.
- Add {disp16} pseudo prefix to x86 assembler.
- Configure with --enable-x86-used-note by default for Linux/x86.<br>ARM/AArch64:<br>- Add support for Cortex-A78, Cortex-A78AE and Cortex-X1,<br>Cortex-R82, Neoverse V1, and Neoverse N2 cores.<br>- Add support for ETMv4 (Embedded Trace Macrocell), ETE (Embedded<br>Trace Extension), TRBE (Trace Buffer Extension), CSRE (Call  
    Stack Recorder Extension) and BRBE (Branch Record Buffer  
    Extension) system registers.<br>- Add support for Armv8-R and Armv8.7-A ISA extensions.
- Add support for DSB memory nXS barrier, WFET and WFIT<br>instruction for Armv8.7.<br>- Add support for +csre feature for -march. Add CSR PDEC<br>instruction for CSRE feature in AArch64.<br>- Add support for +flagm feature for -march in Armv8.4 AArch64.
- Add support for +ls64 feature for -march in Armv8.7<br>AArch64. Add atomic 64-byte load/store instructions for this  
    feature.<br>- Add support for +pauth (Pointer Authentication) feature for
- march in AArch64.<br>New features in the Linker:<br>- Add --error-handling-script=&lt;NAME&gt; command line option to allow<br>a helper script to be invoked when an undefined symbol or a  
    missing library is encountered.  This option can be suppressed  
    via the configure time switch: --enable-error-handling-script=no.<br>- Add -z x86-64-{baseline|v[234]} to the x86 ELF linker to mark<br>x86-64-{baseline|v[234]} ISA level as needed.<br>- Add -z unique-symbol to avoid duplicated local symbol names.
- The creation of PE format DLLs now defaults to using a more<br>secure set of DLL characteristics.<br>- The linker now deduplicates the types in .ctf sections.  The new<br>command-line option --ctf-share-types describes how to do this:  
    its default value, share-unconflicted, produces the most compact  
    output.<br>- The linker now omits the &quot;/variable section&quot;/ from .ctf sections<br>by default, saving space.  This is almost certainly what you  
    want unless you are working on a project that has its own  
    analogue of symbol tables that are not reflected in the ELF  
    symtabs.  
  New features in other binary tools:<br>- The ar tool's previously unused l modifier is now used for<br>specifying dependencies of a static library. The arguments of  
    this option (or --record-libdeps long form option) will be  
    stored verbatim in the __.LIBDEP member of the archive, which  
    the linker may read at link time.<br>- Readelf can now display the contents of LTO symbol table<br>sections when asked to do so via the --lto-syms command line  
    option.<br>- Readelf now accepts the -C command line option to enable the<br>demangling of symbol names.  In addition the --demangle=&lt;style&gt;,<br>- -no-demangle, --recurse-limit and --no-recurse-limit options<br>are also now availale.<br>- Includes fixes for these CVEs:<br>bnc#1179898 aka CVE-2020-16590 aka PR25821  
  bnc#1179899 aka CVE-2020-16591 aka PR25822  
  bnc#1179900 aka CVE-2020-16592 aka PR25823  
  bnc#1179901 aka CVE-2020-16593 aka PR25827  
  bnc#1179902 aka CVE-2020-16598 aka PR25840  
  bnc#1179903 aka CVE-2020-16599 aka PR25842  
  bnc#1180451 aka CVE-2020-35493 aka PR25307  
  bnc#1180454 aka CVE-2020-35496 aka PR25308  
  bnc#1180461 aka CVE-2020-35507 aka PR25308<br>- Rebase the following patches:
- binutils-fix-relax.diff
- binutils-revert-nm-symversion.diff
- binutils-revert-plt32-in-branches.diff
- Add missing dependency on bc (ld.gold testsuite uses it).
- Use --enable-obsolete for cross builds as ia64 is deprecated now.
- Add binutils-2.36-branch.diff.gz.
- Add binutils-fix-relax.diff to fix linking relaxation problems<br>with old object files hitting some enterprise software. [bsc#1179341]<br>- Update binutils-2.35-branch.diff.gz to commit 1c5243df:
- Fixes PR26520, aka [bsc#1179036], a problem in addr2line with<br>certain DWARF variable descriptions.<br>- Also fixes PR26711, PR26656, PR26655, PR26929, PR26808, PR25878,<br>PR26740, PR26778, PR26763, PR26685, PR26699, PR26902, PR26869,  
    PR26711<br>- The above includes fixes for dwo files produced by modern dwp,<br>fixing several problems in the DWARF reader.<br>- Reapply spec file cleanup from format_spec_file
- Remove a SLE10 version check
- Update to 2.35.1 and rebased branch diff:
- This is a point release over the previous 2.35 version, containing bug<br>fixes, and as an exception to the usual rule, one new feature.  The  
  new feature is the support for a new directive in the assembler:  
  &quot;/.nop&quot;/.  This directive creates a single no-op instruction in whatever  
  encoding is correct for the target architecture.  Unlike the .space or  
  .fill this is a real instruction, and it does affect the generation of  
  DWARF line number tables, should they be enabled.<br>- Update binutils-2.35-branch.diff.gz to commit 23f268a0:
- Add xBPF target
- Fix various problems with DWARF 5 support in gas
- Toolchain module update for SLE15 [jsc#ECO-2373]
- Includes changes that were SLE-only in binutils-add-z15-name.diff<br>for [bsc#1160590, jsc#SLE-7903 aka jsc#SLE-7464]<br>- Amend binutils-revert-plt32-in-branches.diff to adjust also new<br>testcases.<br>- Add binutils-2.35-branch.diff.gz: it includes fix for<br>nm -B for objects compiled with -flto and -fcommon.<br>- Add binutils-revert-nm-symversion.diff to be compatible with old<br>output of nm relied on in scripts.<br>- Add binutils-fix-abierrormsg.diff to work around an eager (new)<br>error message occuring without inputs and as-needed (affects  
  nvme-cli build).<br>- Update to binutils 2.35:
- The asseembler can now produce DWARF-5 format line number tables.
- Readelf now has a &quot;/lint&quot;/ mode to enable extra checks of the files it is processing.
- Readelf will now display &quot;/[...]&quot;/ when it has to truncate a symbol name.<br>The old behaviour - of displaying as many characters as possible, up to  
    the 80 column limit - can be restored by the use of the --silent-truncation  
    option.<br>- The linker can now produce a dependency file listing the inputs that it<br>has processed, much like the -M -MP option supported by the compiler.<br>- Regenerate add-ulp-section.diff with -p1 due to a fuzzing issue.
- Remove binutils-2.34-branch.diff.gz.
- Regenerate binutils-build-as-needed.diff due to a fuzzing issue.
- Regenerate binutils-fix-invalid-op-errata.diff as one hunk was upstreamed.
- Remove upstreamed patch binutils-pr25593.diff.
- Regenerate unit-at-a-time.patch due to a fuzzing issue.
- Regenerate binutils-revert-plt32-in-branches.diff.
- Update binutils-2.34-branch.diff.gz.
- Remove fix-try_load_plugin.patch as it is part<br>of the updated binutils-2.34-branch.diff.gz patch.<br>- Add binutils-pr25593.diff to fix DT_NEEDED order with -flto<br>[bsc#1163744]<br>- Update fix-try_load_plugin.patch to latest version.
- Add fix-try_load_plugin.patch in order to fix fallback caused<br>by backport for PR25355.<br>- Update to binutils 2.34:
- The disassembler (objdump --disassemble) now has an option to<br>generate ascii art thats show the arcs between that start and end  
    points of control flow instructions.<br>- The binutils tools now have support for debuginfod.  Debuginfod is a<br>HTTP service for distributing ELF/DWARF debugging information as  
    well as source code.  The tools can now connect to debuginfod  
    servers in order to download debug information about the files that  
    they are processing.<br>- The assembler and linker now support the generation of ELF format<br>files for the Z80 architecture.<br>- Rename and get binutils-2.34-branch.diff.gz (boo#1160254).
- Rebase add-ulp-section.diff, binutils-revert-plt32-in-branches.diff,<br>cross-avr-size.patch and binutils-skip-rpaths.patch.<br>- Add new subpackages for libctf and libctf-nobfd.
- Disable LTO due to boo#1163333.
- Includes fixes for these CVEs:<br>bnc#1153768 aka CVE-2019-17451 aka PR25070  
  bnc#1153770 aka CVE-2019-17450 aka PR25078<br>- Disable LTO during testsuite run
- Add binutils-fix-invalid-op-errata.diff to fix various<br>build fails on aarch64 (PR25210, bsc#1157755).<br>- Add add-ulp-section.diff for user space live patching.
- Update to binutils 2.33.1:
- Adds support for the Arm Scalable Vector Extension version 2<br>(SVE2) instructions, the Arm Transactional Memory Extension (TME)  
    instructions and the Armv8.1-M Mainline and M-profile Vector  
    Extension (MVE) instructions.<br>- Adds support for the Arm Cortex-A76AE, Cortex-A77 and Cortex-M35P<br>processors and the AArch64 Cortex-A34, Cortex-A65, Cortex-A65AE,  
    Cortex-A76AE, and Cortex-A77 processors.<br>- Adds a .float16 directive for both Arm and AArch64 to allow<br>encoding of 16-bit floating point literals.<br>- For MIPS, Add -m[no-]fix-loongson3-llsc option to fix (or not)<br>Loongson3 LLSC Errata.  Add a --enable-mips-fix-loongson3-llsc=[yes|no]  
    configure time option to set the default behavior. Set the default  
    if the configure option is not used to &quot;/no&quot;/.<br>- The Cortex-A53 Erratum 843419 workaround now supports a choice of<br>which workaround to use.  The option --fix-cortex-a53-843419 now  
    takes an optional argument --fix-cortex-a53-843419[=full|adr|adrp]  
    which can be used to force a particular workaround to be used.  
    See --help for AArch64 for more details.<br>- Add support for GNU_PROPERTY_AARCH64_FEATURE_1_BTI and<br>GNU_PROPERTY_AARCH64_FEATURE_1_PAC  in ELF GNU program properties  
    in the AArch64 ELF linker.<br>- Add -z force-bti for AArch64 to enable GNU_PROPERTY_AARCH64_FEATURE_1_BTI<br>on output while warning about missing GNU_PROPERTY_AARCH64_FEATURE_1_BTI  
    on inputs and use PLTs protected with BTI.<br>- Add -z pac-plt for AArch64 to pick PAC enabled PLTs.
- Add --source-comment[=&lt;txt&gt;] option to objdump which if present,<br>provides a prefix to source code lines displayed in a disassembly.<br>- Add --set-section-alignment &lt;section-name&gt;=&lt;power-of-2-align&gt;<br>option to objcopy to allow the changing of section alignments.<br>- Add --verilog-data-width option to objcopy for verilog targets to<br>control width of data elements in verilog hex format.<br>- The separate debug info file options of readelf (--debug-dump=links<br>and --debug-dump=follow) and objdump (--dwarf=links and<br>- -dwarf=follow-links) will now display and/or follow multiple<br>links if more than one are present in a file.  (This usually  
    happens when gcc's -gsplit-dwarf option is used).  
    In addition objdump's --dwarf=follow-links now also affects its  
    other display options, so that for example, when combined with<br>- -syms it will cause the symbol tables in any linked debug info<br>files to also be displayed.  In addition when combined with<br>- -disassemble the --dwarf= follow-links option will ensure that<br>any symbol tables in the linked files are read and used when  
    disassembling code in the main file.<br>- Add support for dumping types encoded in the Compact Type Format<br>to objdump and readelf.<br>- Includes fixes for these CVEs:<br>bnc#1126826 aka CVE-2019-9077 aka PR1126826  
  bnc#1126829 aka CVE-2019-9075 aka PR1126829  
  bnc#1126831 aka CVE-2019-9074 aka PR24235  
  bnc#1140126 aka CVE-2019-12972 aka PR23405  
  bnc#1143609 aka CVE-2019-14444 aka PR24829  
  bnc#1142649 aka CVE-2019-14250 aka PR90924<br>- Remove patches that are now included in the release:<br>binutils-2.32-branch.diff.gz, binutils-fix-ld-segv.diff,  
  binutils-pr24486.patch, riscv-abi-check.patch,  
  rx-gas-padding-pr24464.patch.<br>- Add binutils-2.33-branch.diff.gz patch.
- Rebase binutils-revert-plt32-in-branches.diff and<br>cross-avr-size.patch patch.<br>Package bzip2 was updated:<br>- Implement %check, bsc#1191648- Remove bzip2-faster.patch, it causes a crash with libarchive and<br>valgrind points out uninitialized memory. See  
  [https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576](https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576)  
  Required for bsc#1188891<br>- Fix basisms in bzgrep and bznew
- bzip2-1.0.6-fix-bashisms.patch<br>Package ca-certificates-mozilla was updated:<br>- remove the DST_Root_CA_X3.pem trust, as it expires september 30th 2021.  (bsc#1190858)<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package cloud-netconfig was updated:<br>- Update to version 1.6:  + Ignore proxy when accessing metadata (bsc#1187939)<br>+ Print warning in case metadata is not accessible  
  + Documentation update<br>Package cpio was updated:<br>- Fix segmentation fault caused by a regression (bsc#1189465)  * fix-CVE-2021-38185_4.patch
- Add another patch to fix regression (bsc#1189465)
- fix-CVE-2021-38185_3.patch
- Fix regression in last update (bsc#1189465)
- fix-CVE-2021-38185_2.patch
- Fix CVE-2021-38185 Remote code execution caused by an integer overflow in ds_fgetstr<br>(CVE-2021-38185, bsc#1189206)<br>- fix-CVE-2021-38185.patch<br>Package cracklib was updated:<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package cronie was updated:<br>- Increase limit of allowed entries in crontab files to fix bsc#1187508  * cronie-1.4.11-increase_crontab_limit.patch<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- libssh: do not let libssh create socket [bsc#1192790]  * Fixes sftp over a proxy failure in curl with error:<br>Failure establishing ssh session<br>- Add curl-libssh-socket.patch
- MIME: Properly check Content-Type even if it has parameters
- Add curl-check-content-type.patch [bsc#1190153]
- Security fix: [bsc#1190374, CVE-2021-22947]
- STARTTLS protocol injection via MITM
- Add curl-CVE-2021-22947.patch
- Security fix: [bsc#1190373, CVE-2021-22946]
- Protocol downgrade required TLS bypassed
- Add curl-CVE-2021-22946.patch
- Security fix: [bsc#1188220, CVE-2021-22925]
- TELNET stack contents disclosure again
- Add curl-CVE-2021-22925.patch
- Security fix: [bsc#1188219, CVE-2021-22924]
- Bad connection reuse due to flawed path name checks
- Add curl-CVE-2021-22924.patch
- Security fix: Disable the metalink feature:
- Insufficiently Protected Credentials [bsc#1188218, CVE-2021-22923]
- Wrong content via metalink not discarded [bsc#1188217, CVE-2021-22922]
- Security fix: [bsc#1186114, CVE-2021-22898]
- TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch
- Fix: SFTP uploads result in empty uploaded files [bsc#1177976]
- Add curl-fix-O_APPEND.patch
- Security fix: [bsc#1179593, CVE-2020-8286]
- Inferior OCSP verification: libcurl offers &quot;/OCSP stapling&quot;/ via<br>the 'CURLOPT_SSL_VERIFYSTATUS' option that, when set, verifies  
    the OCSP response that a server responds with as part of the TLS  
    handshake. It then aborts the TLS negotiation if something is  
    wrong with the response. The same feature can be enabled with  
    '--cert-status' using the curl tool.<br>- As part of the OCSP response verification, a client should verify<br>that the response is indeed set out for the correct certificate.  
    This step was not performed by libcurl when built or told to use  
    OpenSSL as TLS backend.<br>- Add curl-CVE-2020-8286.patch
- Security fix: [bsc#1179399, CVE-2020-8285]
- FTP wildcard stack overflow: The wc_statemach() internal<br>function has been rewritten to use an ordinary loop instead of  
    the recursive approach.<br>- Add curl-CVE-2020-8285.patch
- Security fix: [bsc#1179398, CVE-2020-8284]
- Trusting FTP PASV responses: When curl performs a passive FTP<br>transfer, it first tries the 'EPSV' command and if that is not  
    supported, it falls back to using 'PASV'. A malicious server  
    can use the 'PASV' response to trick curl into connecting  
    back to a given IP address and port, and this way potentially  
    make curl extract information about services that are otherwise  
    private and not disclosed.<br>- The IP address part of the response is now ignored by default,<br>by making 'CURLOPT_FTP_SKIP_PASV_IP' default to '1L'. The same  
    goes for the command line tool, which then might need  
    '--no-ftp-skip-pasv-ip' set to prevent curl from ignoring the  
    address in the server response.<br>- Add curl-CVE-2020-8284.patch
- Security fix: [bsc#1175109, CVE-2020-8231]
- An application that performs multiple requests with libcurl's<br>multi API and sets the 'CURLOPT_CONNECT_ONLY' option, might in  
    rare circumstances experience that when subsequently using the  
    setup connect-only transfer, libcurl will pick and use the wrong  
    connection and instead pick another one the application has  
    created since then.<br>- Add curl-CVE-2020-8231.patch<br>Package cyrus-sasl-saslauthd was updated:<br>- bsc#1159635 VUL-0: CVE-2019-19906: cyrus-sasl: cyrus-sasl  has an out-of-bounds write leading to unauthenticated remote<br>denial-of-service in OpenLDAP via a malformed LDAP packet  
  o apply upstream patch<br>- 0001-Fix-587.patch
- Fixed GSS-SPNEGO to use flags negotiated by GSSAPI for SSF (bsc#1162518)
- Add 0001-Fix-GSS-SPNEGO-mechanism-s-incompatible-behavior.patch
- Added support for retrieving negotiated SSF in gssapi plugin (bsc#1162518)
- Add 0002-Drop-unused-parameter-from-gssapi_spnego_ssf.patch
- Add 0003-Check-return-error-from-gss_wrap_size_limit.patch
- Add 0004-Add-support-for-retrieving-the-mech_ssf.patch<br>Package dbus-1 was updated:<br>- Fix CVE-2020-35512 - shared UID's caused issues (CVE-2020-35512 bsc#1187105)  * fix-upstream-userdb-constpointer.patch
- fix-upstream-CVE-2020-35512.patch
- Fix CVE-2020-12049 truncated messages lead to resource exhaustion<br>(CVE-2020-12049, bsc#1172505)<br>- fix-upstream-CVE-2020-12049_2.patch<br>Package dbus-1-x11 was updated:<br>- Fix CVE-2020-35512 - shared UID's caused issues (CVE-2020-35512 bsc#1187105)  * fix-upstream-userdb-constpointer.patch
- fix-upstream-CVE-2020-35512.patch
- Fix CVE-2020-12049 truncated messages lead to resource exhaustion<br>(CVE-2020-12049, bsc#1172505)<br>- fix-upstream-CVE-2020-12049_2.patch<br>Package dhcp was updated:<br>- CVE-2021-25217, bsc#1186382, dhcp-CVE-2021-25217.patch: A buffer  overrun in lease file parsing code can be used to exploit a<br>common vulnerability shared by dhcpd and dhclient.<br>Package efivar was updated:<br>- Add efivar-bsc1192344-fix-open-dbx.patch to fix the dbx opening  failed by &quot;/Operation not permitted&quot;/. (bsc#1192344, jsc#PM-3148)
- Removed -fstack-clash-protection in CFLAGS when gcc &lt; 8
- The -flto causes ld error, so add<br>export LDFLAGS=&quot;/-flto-partition=one&quot;/  
  This solution is from openSUSE:Factory/efivar:  
    Fri Aug 14 08:20:09 UTC 2020 - Martin Liška [&lt;mliska@suse.cz](#)&gt;<br>- Do not partition LTO as we may reach new GAS error:<br>Error: invalid attempt to declare external version  
    name as default in symbol `efi_set_variable@@LIBEFIVAR_0.24'<br>Package expat was updated:<br>- Security fix (CVE-2021-45960, bsc#1194251)  * A left shift by 29 (or more) places in the storeAtts function<br>in xmlparse.c can lead to realloc misbehavior.<br>- Added expat-CVE-2021-45960.patch
- Security fix (CVE-2021-46143, bsc#1194362)
- Integer overflow exists for m_groupSize in doProlog
- Added expat-CVE-2021-46143.patch
- Security fix (CVE-2022-22822, bsc#1194474)
- Integer overflow in addBinding in xmlparse.c
- Added expat-CVE-2022-22822.patch
- Security fix (CVE-2022-22823, bsc#1194476)
- Integer overflow in build_model in xmlparse.c
- Added expat-CVE-2022-22823.patch
- Security fix (CVE-2022-22824, bsc#1194477)
- Integer overflow in defineAttribute in xmlparse.c
- Added expat-CVE-2022-22824.patch
- Security fix (CVE-2022-22825, bsc#1194478)
- Integer overflow in lookup in xmlparse.c
- Added expat-CVE-2022-22825.patch
- Security fix (CVE-2022-22826, bsc#1194479)
- Integer overflow in nextScaffoldPart in xmlparse.c
- Added expat-CVE-2022-22826.patch
- Security fix (CVE-2022-22827, bsc#1194480)
- Integer overflow in storeAtts in xmlparse.c
- Added expat-CVE-2022-22826.patch<br>Package file was updated:<br>- Add temporary patch CVE-2019-18218-46a8443f.patch from upstream  to fix bsc#1154661 -- heap-based buffer overflow in cdf_read_property_info in cdf.c<br>as well as bsc#1189093<br>Package gettext-runtime was updated:<br>- Added msgfmt-double-free.patch to fix a double free error  (CVE-2018-18751 bsc#1113719)<br>Package glib2 was updated:<br>- Add glib2-CVE-2021-27218.patch: g_byte_array_new_take takes a  gsize as length but stores in a guint, this patch will refuse if<br>the length is larger than guint. (bsc#1182328,  
  glgo#GNOME/glib!1944)<br>- Add glib2-CVE-2021-27219-add-g_memdup2.patch: g_memdup takes a<br>guint as parameter and sometimes leads into an integer overflow,  
  so add a g_memdup2 function which uses gsize to replace it.  
  (bsc#1182362, glgo#GNOME/glib!1927, glgo#GNOME/glib!1933,  
  glgo#GNOME/glib!1943)<br>Package glibc was updated:<br>- mq-notify-use-after-free.patch: Use __pthread_attr_copy in mq_notify  (CVE-2021-33574, bsc#1186489, BZ #27896)
- wordexp-param-overflow.patch: wordexp: handle overflow in positional<br>parameter number (CVE-2021-35942, bsc#1187911, BZ #28011)<br>- iconv-option-parsing.patch: Rewrite iconv option parsing<br>(CVE-2016-10228, bsc#1027496, BZ #19519)<br>- force-elision-race.patch: Fix race in pthread_mutex_lock while promoting<br>to PTHREAD_MUTEX_ELISION_NP (bsc#1131330, BZ #23275)<br>- s390-memmove-ifunc-selector-arch13.patch: S390: Also check vector<br>support in memmove ifunc-selector (bsc#1184034, BZ #27511)<br>- iconv-redundant-shift.patch: iconv: Accept redundant shift sequences in<br>IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)<br>- iconv-ucs4-loop-bounds.patch: iconv: Fix incorrect UCS4 inner loop<br>bounds (CVE-2020-29562, bsc#1179694, BZ #26923)<br>- printf-long-double-non-normal.patch: x86: Harden prin | 2022-03-25 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-byos-v20220126/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-byos-v20220126/) |
| SUSE Image SUSE-IU-2022:43-1 | suse | SUSE-IU-2022:43-1 | This image update for google/sles-12-sp4-sap-byos-v20220126 contains the following changes:  
Package SUSEConnect was updated:<br>- Update to 0.3.32- Allow --regcode and --instance-data attributes at the same time (jsc#PCT-164)
- Document that 'debug' can also get set in the config file
- --status will also print the subscription name
- Update to 0.3.31
- Disallow registering via SUSEConnect if the system is managed by SUSE Manager.
- Add subscription name to output of 'SUSEConnect --status'
- Update to 0.3.30
- send payload of GET requests as part of the url,<br>not in the body (see bsc#1185611)<br>Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package at was updated:<br>- Increase TasksMax limit from 512 (systemd default) to 4915,  fix bsc#1058557<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bash-4.3-boo1192785.patch  * setuid causing permission denied on popen (bsc#1192785)
- Add patch bsc1177369.patch to fix bsc#1177369
- tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Fixed CVE-2021-25219:  The lame-ttl option controls how long named caches certain types<br>of broken responses from authoritative servers (see the security  
  advisory for details). This caching mechanism could be abused by  
  an attacker to significantly degrade resolver performance. The  
  vulnerability has been mitigated by changing the default value of  
  lame-ttl to 0 and overriding any explicitly set value with 0,  
  effectively disabling this mechanism altogether. ISC's testing has  
  determined that doing that has a negligible impact on resolver  
  performance while also preventing abuse.  
  Administrators may observe more traffic towards servers issuing  
  certain types of broken responses than in previous BIND 9 releases.  
  [bsc#1192146, CVE-2021-25219, bind-CVE-2021-25219.patch]<br>- Some debugs were still in the patch for bsc#1181495.<br>[bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package binutils was updated:<br>- Add binutils-revert-hlasm-insns.diff for compatibility on old  code stream that expect 'brcl 0,label' to not be disassembled<br>as 'jgnop label' on s390x.  [bsc#1192267]<br>- Rebase binutils-2.37-branch.diff: fixes PR28523 aka boo#1188941.
- Fix empty man-pages from broken release tarball [PR28144].
- Update binutils-skip-rpaths.patch with contained a memory corruption<br>(boo#1191473).<br>- Configure with --disable-x86-used-note on old code streams.
- Disable libalternatives temporarily for build cycle reasons.
- make TARGET-bfd=headers again, we patch bfd-in.h
- This state submitted to SLE12 and SLE15 code streams for annual<br>toolchain update. [jsc#PM-2767, jsc#SLE-21561, jsc#SLE-19618]<br>- Bump binutils-2.37-branch.diff to 66d5c7003, to include fixes for<br>PR28422, PR28192, PR28391.  Also adds some s390x arch14  
  instructions [jsc#SLE-18637].<br>- Using libalternatives instead of update-alternatives.
- Adjust for testsuite fails on older products that configure<br>binutils in different ways, adds  binutils-compat-old-behaviour.diff  
  and adjusts binutils-revert-nm-symversion.diff and  
  binutils-revert-plt32-in-branches.diff.<br>- Bump binutils-2.37-branch.diff: fixes PR28138.
- Use LTO &amp; PGO build.
- Update to binutils 2.37:
- The GNU Binutils sources now requires a C99 compiler and library to<br>build.<br>- Support for the arm-symbianelf format has been removed.
- Support for Realm Management Extension (RME) for AArch64 has been<br>added.<br>- A new linker option '-z report-relative-reloc' for x86 ELF targets<br>has been added to report dynamic relative relocations.<br>- A new linker option '-z start-stop-gc' has been added to disable<br>special treatment of __start_*/__stop_* references when<br>- -gc-sections.
- A new linker options '-Bno-symbolic' has been added which will<br>cancel the '-Bsymbolic' and '-Bsymbolic-functions' options.<br>- The readelf tool has a new command line option which can be used to<br>specify how the numeric values of symbols are reported.<br>- -sym-base=0|8|10|16 tells readelf to display the values in base 8,<br>base 10 or base 16.  A sym base of 0 represents the default action  
    of displaying values under 10000 in base 10 and values above that in  
    base 16.<br>- A new format has been added to the nm program.  Specifying<br>'--format=just-symbols' (or just using -j) will tell the program to  
    only display symbol names and nothing else.<br>- A new command line option '--keep-section-symbols' has been added to<br>objcopy and strip.  This stops the removal of unused section symbols  
    when the file is copied.  Removing these symbols saves space, but  
    sometimes they are needed by other tools.<br>- The '--weaken', '--weaken-symbol' and '--weaken-symbols' options<br>supported by objcopy now make undefined symbols weak on targets that  
    support weak symbols.<br>- Readelf and objdump can now display and use the contents of .debug_sup<br>sections.<br>- Readelf and objdump will now follow links to separate debug info<br>files by default.  This behaviour can be stopped via the use of the  
    new '-wN' or '--debug-dump=no-follow-links' options for readelf and  
    the '-WN' or '--dwarf=no-follow-links' options for objdump.  Also  
    the old behaviour can be restored by the use of the  
    '--enable-follow-debug-links=no' configure time option.  
    The semantics of the =follow-links option have also been slightly  
    changed.  When enabled, the option allows for the loading of symbol  
    tables and string tables from the separate files which can be used  
    to enhance the information displayed when dumping other sections,  
    but it does not automatically imply that information from the  
    separate files should be displayed.  
    If other debug section display options are also enabled (eg  
    '--debug-dump=info') then the contents of matching sections in both  
    the main file and the separate debuginfo file *will* be displayed.  
    This is because in most cases the debug section will only be present  
    in one of the files.  
    If however non-debug section display options are enabled (eg  
    '--sections') then the contents of matching parts of the separate  
    debuginfo file will *not* be displayed.  This is because in most  
    cases the user probably only wanted to load the symbol information  
    from the separate debuginfo file.  In order to change this behaviour  
    a new command line option --process-links can be used.  This will  
    allow di0pslay options to applied to both the main file and any  
    separate debuginfo files.<br>- Nm has a new command line option: '--quiet'.  This suppresses &quot;/no<br>symbols&quot;/ diagnostic.<br>- Includes fixes for these CVEs:<br>bnc#1181452 aka CVE-2021-20197 aka PR26945  
  bnc#1183511 aka CVE-2021-20284 aka PR26931  
  bnc#1184519 aka CVE-2021-20294 aka PR26929  
  bnc#1184620 aka CVE-2021-3487 aka PR26946  
  bnc#1184794 aka CVE-2020-35448 aka PR26574<br>- Also fixes:<br>bsc#1183909 - slow performance of stripping some binaries<br>- Rebased patches: binutils-build-as-needed.diff, binutils-fix-abierrormsg.diff,<br>binutils-fix-invalid-op-errata.diff, binutils-fix-relax.diff,  
  binutils-revert-nm-symversion.diff, binutils-revert-plt32-in-branches.diff<br>- Removed patches (are in upstream): ppc-ensure-undef-dynamic-weak-undefined.patch and<br>ppc-use-local-plt.patch.<br>- Add binutils-2.37-branch.diff.gz.
- ppc-ensure-undef-dynamic-weak-undefined.patch: PPC: ensure_undef_dynamic<br>on weak undef only in plt<br>- ppc-use-local-plt.patch: PowerPC use_local_plt (prerequisite for above<br>patch)<br>- Update 2.36 branch diff which fixes PR27587.
- Do not run make TARGET-bfd=headers separately.
- Bump 2.36 branch diff (includes fix for PR27441 aka bsc#1182252).
- Bump 2.36 branch diff.
- Update 2.36 branch diff which should fix PR27311 completely.<br>It fixes also PR27284.<br>- Remove temporary fix 0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.
- Add temporary upstream fix for PR27311<br>0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.<br>- Update to binutils 2.36:<br>New features in the Assembler:  
    General:<br>- When setting the link order attribute of ELF sections, it is now<br>possible to use a numeric section index instead of symbol name.<br>- Added a .nop directive to generate a single no-op instruction in<br>a target neutral manner.  This instruction does have an effect on  
    DWARF line number generation, if that is active.<br>- Removed --reduce-memory-overheads and --hash-size as gas now<br>uses hash tables that can be expand and shrink automatically.  
    X86/x86_64:<br>- Add support for AVX VNNI, HRESET, UINTR, TDX, AMX and Key<br>Locker instructions.<br>- Support non-absolute segment values for lcall and ljmp.
- Add {disp16} pseudo prefix to x86 assembler.
- Configure with --enable-x86-used-note by default for Linux/x86.<br>ARM/AArch64:<br>- Add support for Cortex-A78, Cortex-A78AE and Cortex-X1,<br>Cortex-R82, Neoverse V1, and Neoverse N2 cores.<br>- Add support for ETMv4 (Embedded Trace Macrocell), ETE (Embedded<br>Trace Extension), TRBE (Trace Buffer Extension), CSRE (Call  
    Stack Recorder Extension) and BRBE (Branch Record Buffer  
    Extension) system registers.<br>- Add support for Armv8-R and Armv8.7-A ISA extensions.
- Add support for DSB memory nXS barrier, WFET and WFIT<br>instruction for Armv8.7.<br>- Add support for +csre feature for -march. Add CSR PDEC<br>instruction for CSRE feature in AArch64.<br>- Add support for +flagm feature for -march in Armv8.4 AArch64.
- Add support for +ls64 feature for -march in Armv8.7<br>AArch64. Add atomic 64-byte load/store instructions for this  
    feature.<br>- Add support for +pauth (Pointer Authentication) feature for
- march in AArch64.<br>New features in the Linker:<br>- Add --error-handling-script=&lt;NAME&gt; command line option to allow<br>a helper script to be invoked when an undefined symbol or a  
    missing library is encountered.  This option can be suppressed  
    via the configure time switch: --enable-error-handling-script=no.<br>- Add -z x86-64-{baseline|v[234]} to the x86 ELF linker to mark<br>x86-64-{baseline|v[234]} ISA level as needed.<br>- Add -z unique-symbol to avoid duplicated local symbol names.
- The creation of PE format DLLs now defaults to using a more<br>secure set of DLL characteristics.<br>- The linker now deduplicates the types in .ctf sections.  The new<br>command-line option --ctf-share-types describes how to do this:  
    its default value, share-unconflicted, produces the most compact  
    output.<br>- The linker now omits the &quot;/variable section&quot;/ from .ctf sections<br>by default, saving space.  This is almost certainly what you  
    want unless you are working on a project that has its own  
    analogue of symbol tables that are not reflected in the ELF  
    symtabs.  
  New features in other binary tools:<br>- The ar tool's previously unused l modifier is now used for<br>specifying dependencies of a static library. The arguments of  
    this option (or --record-libdeps long form option) will be  
    stored verbatim in the __.LIBDEP member of the archive, which  
    the linker may read at link time.<br>- Readelf can now display the contents of LTO symbol table<br>sections when asked to do so via the --lto-syms command line  
    option.<br>- Readelf now accepts the -C command line option to enable the<br>demangling of symbol names.  In addition the --demangle=&lt;style&gt;,<br>- -no-demangle, --recurse-limit and --no-recurse-limit options<br>are also now availale.<br>- Includes fixes for these CVEs:<br>bnc#1179898 aka CVE-2020-16590 aka PR25821  
  bnc#1179899 aka CVE-2020-16591 aka PR25822  
  bnc#1179900 aka CVE-2020-16592 aka PR25823  
  bnc#1179901 aka CVE-2020-16593 aka PR25827  
  bnc#1179902 aka CVE-2020-16598 aka PR25840  
  bnc#1179903 aka CVE-2020-16599 aka PR25842  
  bnc#1180451 aka CVE-2020-35493 aka PR25307  
  bnc#1180454 aka CVE-2020-35496 aka PR25308  
  bnc#1180461 aka CVE-2020-35507 aka PR25308<br>- Rebase the following patches:
- binutils-fix-relax.diff
- binutils-revert-nm-symversion.diff
- binutils-revert-plt32-in-branches.diff
- Add missing dependency on bc (ld.gold testsuite uses it).
- Use --enable-obsolete for cross builds as ia64 is deprecated now.
- Add binutils-2.36-branch.diff.gz.
- Add binutils-fix-relax.diff to fix linking relaxation problems<br>with old object files hitting some enterprise software. [bsc#1179341]<br>- Update binutils-2.35-branch.diff.gz to commit 1c5243df:
- Fixes PR26520, aka [bsc#1179036], a problem in addr2line with<br>certain DWARF variable descriptions.<br>- Also fixes PR26711, PR26656, PR26655, PR26929, PR26808, PR25878,<br>PR26740, PR26778, PR26763, PR26685, PR26699, PR26902, PR26869,  
    PR26711<br>- The above includes fixes for dwo files produced by modern dwp,<br>fixing several problems in the DWARF reader.<br>- Reapply spec file cleanup from format_spec_file
- Remove a SLE10 version check
- Update to 2.35.1 and rebased branch diff:
- This is a point release over the previous 2.35 version, containing bug<br>fixes, and as an exception to the usual rule, one new feature.  The  
  new feature is the support for a new directive in the assembler:  
  &quot;/.nop&quot;/.  This directive creates a single no-op instruction in whatever  
  encoding is correct for the target architecture.  Unlike the .space or  
  .fill this is a real instruction, and it does affect the generation of  
  DWARF line number tables, should they be enabled.<br>- Update binutils-2.35-branch.diff.gz to commit 23f268a0:
- Add xBPF target
- Fix various problems with DWARF 5 support in gas
- Toolchain module update for SLE15 [jsc#ECO-2373]
- Includes changes that were SLE-only in binutils-add-z15-name.diff<br>for [bsc#1160590, jsc#SLE-7903 aka jsc#SLE-7464]<br>- Amend binutils-revert-plt32-in-branches.diff to adjust also new<br>testcases.<br>- Add binutils-2.35-branch.diff.gz: it includes fix for<br>nm -B for objects compiled with -flto and -fcommon.<br>- Add binutils-revert-nm-symversion.diff to be compatible with old<br>output of nm relied on in scripts.<br>- Add binutils-fix-abierrormsg.diff to work around an eager (new)<br>error message occuring without inputs and as-needed (affects  
  nvme-cli build).<br>- Update to binutils 2.35:
- The asseembler can now produce DWARF-5 format line number tables.
- Readelf now has a &quot;/lint&quot;/ mode to enable extra checks of the files it is processing.
- Readelf will now display &quot;/[...]&quot;/ when it has to truncate a symbol name.<br>The old behaviour - of displaying as many characters as possible, up to  
    the 80 column limit - can be restored by the use of the --silent-truncation  
    option.<br>- The linker can now produce a dependency file listing the inputs that it<br>has processed, much like the -M -MP option supported by the compiler.<br>- Regenerate add-ulp-section.diff with -p1 due to a fuzzing issue.
- Remove binutils-2.34-branch.diff.gz.
- Regenerate binutils-build-as-needed.diff due to a fuzzing issue.
- Regenerate binutils-fix-invalid-op-errata.diff as one hunk was upstreamed.
- Remove upstreamed patch binutils-pr25593.diff.
- Regenerate unit-at-a-time.patch due to a fuzzing issue.
- Regenerate binutils-revert-plt32-in-branches.diff.
- Update binutils-2.34-branch.diff.gz.
- Remove fix-try_load_plugin.patch as it is part<br>of the updated binutils-2.34-branch.diff.gz patch.<br>- Add binutils-pr25593.diff to fix DT_NEEDED order with -flto<br>[bsc#1163744]<br>- Update fix-try_load_plugin.patch to latest version.
- Add fix-try_load_plugin.patch in order to fix fallback caused<br>by backport for PR25355.<br>- Update to binutils 2.34:
- The disassembler (objdump --disassemble) now has an option to<br>generate ascii art thats show the arcs between that start and end  
    points of control flow instructions.<br>- The binutils tools now have support for debuginfod.  Debuginfod is a<br>HTTP service for distributing ELF/DWARF debugging information as  
    well as source code.  The tools can now connect to debuginfod  
    servers in order to download debug information about the files that  
    they are processing.<br>- The assembler and linker now support the generation of ELF format<br>files for the Z80 architecture.<br>- Rename and get binutils-2.34-branch.diff.gz (boo#1160254).
- Rebase add-ulp-section.diff, binutils-revert-plt32-in-branches.diff,<br>cross-avr-size.patch and binutils-skip-rpaths.patch.<br>- Add new subpackages for libctf and libctf-nobfd.
- Disable LTO due to boo#1163333.
- Includes fixes for these CVEs:<br>bnc#1153768 aka CVE-2019-17451 aka PR25070  
  bnc#1153770 aka CVE-2019-17450 aka PR25078<br>- Disable LTO during testsuite run
- Add binutils-fix-invalid-op-errata.diff to fix various<br>build fails on aarch64 (PR25210, bsc#1157755).<br>- Add add-ulp-section.diff for user space live patching.
- Update to binutils 2.33.1:
- Adds support for the Arm Scalable Vector Extension version 2<br>(SVE2) instructions, the Arm Transactional Memory Extension (TME)  
    instructions and the Armv8.1-M Mainline and M-profile Vector  
    Extension (MVE) instructions.<br>- Adds support for the Arm Cortex-A76AE, Cortex-A77 and Cortex-M35P<br>processors and the AArch64 Cortex-A34, Cortex-A65, Cortex-A65AE,  
    Cortex-A76AE, and Cortex-A77 processors.<br>- Adds a .float16 directive for both Arm and AArch64 to allow<br>encoding of 16-bit floating point literals.<br>- For MIPS, Add -m[no-]fix-loongson3-llsc option to fix (or not)<br>Loongson3 LLSC Errata.  Add a --enable-mips-fix-loongson3-llsc=[yes|no]  
    configure time option to set the default behavior. Set the default  
    if the configure option is not used to &quot;/no&quot;/.<br>- The Cortex-A53 Erratum 843419 workaround now supports a choice of<br>which workaround to use.  The option --fix-cortex-a53-843419 now  
    takes an optional argument --fix-cortex-a53-843419[=full|adr|adrp]  
    which can be used to force a particular workaround to be used.  
    See --help for AArch64 for more details.<br>- Add support for GNU_PROPERTY_AARCH64_FEATURE_1_BTI and<br>GNU_PROPERTY_AARCH64_FEATURE_1_PAC  in ELF GNU program properties  
    in the AArch64 ELF linker.<br>- Add -z force-bti for AArch64 to enable GNU_PROPERTY_AARCH64_FEATURE_1_BTI<br>on output while warning about missing GNU_PROPERTY_AARCH64_FEATURE_1_BTI  
    on inputs and use PLTs protected with BTI.<br>- Add -z pac-plt for AArch64 to pick PAC enabled PLTs.
- Add --source-comment[=&lt;txt&gt;] option to objdump which if present,<br>provides a prefix to source code lines displayed in a disassembly.<br>- Add --set-section-alignment &lt;section-name&gt;=&lt;power-of-2-align&gt;<br>option to objcopy to allow the changing of section alignments.<br>- Add --verilog-data-width option to objcopy for verilog targets to<br>control width of data elements in verilog hex format.<br>- The separate debug info file options of readelf (--debug-dump=links<br>and --debug-dump=follow) and objdump (--dwarf=links and<br>- -dwarf=follow-links) will now display and/or follow multiple<br>links if more than one are present in a file.  (This usually  
    happens when gcc's -gsplit-dwarf option is used).  
    In addition objdump's --dwarf=follow-links now also affects its  
    other display options, so that for example, when combined with<br>- -syms it will cause the symbol tables in any linked debug info<br>files to also be displayed.  In addition when combined with<br>- -disassemble the --dwarf= follow-links option will ensure that<br>any symbol tables in the linked files are read and used when  
    disassembling code in the main file.<br>- Add support for dumping types encoded in the Compact Type Format<br>to objdump and readelf.<br>- Includes fixes for these CVEs:<br>bnc#1126826 aka CVE-2019-9077 aka PR1126826  
  bnc#1126829 aka CVE-2019-9075 aka PR1126829  
  bnc#1126831 aka CVE-2019-9074 aka PR24235  
  bnc#1140126 aka CVE-2019-12972 aka PR23405  
  bnc#1143609 aka CVE-2019-14444 aka PR24829  
  bnc#1142649 aka CVE-2019-14250 aka PR90924<br>- Remove patches that are now included in the release:<br>binutils-2.32-branch.diff.gz, binutils-fix-ld-segv.diff,  
  binutils-pr24486.patch, riscv-abi-check.patch,  
  rx-gas-padding-pr24464.patch.<br>- Add binutils-2.33-branch.diff.gz patch.
- Rebase binutils-revert-plt32-in-branches.diff and<br>cross-avr-size.patch patch.<br>Package bzip2 was updated:<br>- Implement %check, bsc#1191648- Remove bzip2-faster.patch, it causes a crash with libarchive and<br>valgrind points out uninitialized memory. See  
  [https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576](https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576)  
  Required for bsc#1188891<br>- Fix basisms in bzgrep and bznew
- bzip2-1.0.6-fix-bashisms.patch<br>Package ca-certificates-mozilla was updated:<br>- remove the DST_Root_CA_X3.pem trust, as it expires september 30th 2021.  (bsc#1190858)<br>Package cairo was updated:<br>- Add cairo-fix-infinite-loop-bsc1122321-CVE-2019-6462.patch: This  fixes a potentially infinite loop (bsc#1122321, CVE-2019-6462,<br>glfo#cairo/cairo#155).<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package cloud-netconfig was updated:<br>- Update to version 1.6:  + Ignore proxy when accessing metadata (bsc#1187939)<br>+ Print warning in case metadata is not accessible  
  + Documentation update<br>Package compat-openssl098 was updated:<br>- Other OpenSSL functions that print ASN.1 data have been found to assume that  the ASN1_STRING byte array will be NUL terminated, even though this is not<br>guaranteed for strings that have been directly constructed. Where an application  
  requests an ASN.1 structure to be printed, and where that ASN.1 structure  
  contains ASN1_STRINGs that have been directly constructed by the application  
  without NUL terminating the &quot;/data&quot;/ field, then a read buffer overrun can occur.<br>- CVE-2021-3712 continued
- bsc#1189521
- Add CVE-2021-3712-other-ASN1_STRING-issues.patch
- Sourced from openssl-CVE-2021-3712.tar.bz2 posted on bsc-1189521<br>2021-08-24 00:47 PDT by Marcus Meissner<br>- The function X509_CERT_AUX_print() has a bug which may cause a read buffer overrun<br>when printing certificate details. A malicious actor could construct a  
  certificate to deliberately hit this bug, which may result in a crash of the  
  application (causing a Denial of Service attack).<br>- CVE-2021-3712
- bsc#1189521
- Add CVE-2021-3712-Fix-read-buffer-overrun-in-X509_CERT_AUX_print.patch
- Security fixes:
- Integer overflow in CipherUpdate: Incorrect SSLv2 rollback<br>protection [bsc#1182333, CVE-2021-23840]<br>- Null pointer deref in X509_issuer_and_serial_hash()<br>[bsc#1182331, CVE-2021-23841]<br>- Add openssl-CVE-2021-23840.patch openssl-CVE-2021-23841.patch<br>Package corosync was updated:<br>- bsc#1191419, Update cancel_token_hold_on_retransmit_option patch, fix parsing of the option in corosync-2.3.6  Modified: bsc#1189680-cancel_token_hold_on_retransmit-option.patch
- corosync totem: bsc#1189680, Add cancel_token_hold_on_retransmit config option<br>Added: bsc#1189680-cancel_token_hold_on_retransmit-option.patch<br>- Fix bsc#1166899, return value of &quot;/corosync-quorumtool -s&quot;/ was not correct<br>Added: bug-1166899-quorumtool-Fix-exit-status-codes.patch<br>- totempg: Fix memory leak (bsc#1083030)<br>Package cpio was updated:<br>- Fix segmentation fault caused by a regression (bsc#1189465)  * fix-CVE-2021-38185_4.patch
- Add another patch to fix regression (bsc#1189465)
- fix-CVE-2021-38185_3.patch
- Fix regression in last update (bsc#1189465)
- fix-CVE-2021-38185_2.patch
- Fix CVE-2021-38185 Remote code execution caused by an integer overflow in ds_fgetstr<br>(CVE-2021-38185, bsc#1189206)<br>- fix-CVE-2021-38185.patch<br>Package cracklib was updated:<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package crmsh was updated:<br>- Update to version 4.1.1+git.1642405877.e4f905fc:  * Fix: ui_resource: Parse node and lifetime correctly (bsc#1192618)
- Fix: ui_resource: Parse lifetime option correctly (bsc#1191508)
- Fix: utils: Improve detect_cloud function and support non-Hyper-V in Azure
- Update to version 4.1.1+git.1630047134.803a70f2:
- Fix: hb_report: Using python way to collect ra trace files (bsc#1189641)
- Fix: history: use utils.mkdirp instead of system mkdir command(bsc#1179999, CVE-2020-35459)
- Remove patch:
- 0001-Fix-history-use-utils.mkdirp-instead-of-system-mkdir.patch
- Update to version 4.1.1+git.1625191010.47a3ee14:
- Dev: crash_test: Add big warnings to have users' attention to potential failover
- Dev: crash_test: rename preflight_check as crash_test (jsc#SLE-18367 for ECO jsc#SLE-18374)
- Fix: completers: return complete start/stop resource id list correctly(bsc#1180137)
- Medium: integrate preflight_check into crmsh
- Fix: help: show help message from argparse(bsc#1175982)
- Fix: resource: make untrace consistent with trace (bsc#1187396)
- Fix: parse: shouldn't allow property setting with an empty value(bsc#1185423)
- Update to version 4.1.0+git.1620355744.c0b5142f:
- Fix: bootstrap: change StrictHostKeyChecking=no as a constants(bsc#1185437)
- Dev: bootstrap: disable unnecessary warnings (bsc#1178118)
- Fix: bootstrap: raise warning when configuring diskless SBD with node's count less than 3(bsc#1181907)
- Fix: bootstrap: sync corosync.conf before finished joining(bsc#1183359)
- Fix: bootstrap: parse space in sbd device correctly(bsc#1183883)
- Fix: bootstrap: get the peer node name correctly (bsc#1183654)
- Fix: update verion and author (bsc#1183689)
- Fix: ui_resource: change return code and error to warning for some unharmful actions(bsc#1180332)
- Fix: ui_configure: raise error when params not exist(bsc#1180126)
- Update to version 4.1.0+git.1614156984.f4f5e146:
- Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Dev: utils: change default file mod as 644 for str2file function
- Dev: lock: give more specific error message when raise ClaimLockError
- Dev: hb_report: Detect if any ocfs2 partitions exist
- Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688)
- Dev: corosync: change the permission of corosync.conf to 644
- Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869)
- Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)<br>Package cronie was updated:<br>- Increase limit of allowed entries in crontab files to fix bsc#1187508  * cronie-1.4.11-increase_crontab_limit.patch<br>Package csync2 was updated:<br>- VUL-1: CVE-2019-15522: csync2: daemon fails to enforce TLS  (bsc#1147137)
- VUL-1: CVE-2019-15523: csync2: incorrect TLS handshake error handling<br>(bsc#1147139)  
  Apply upstream patch:  
  0001-fail-HELLO-command-when-SSL-is-required.patch  
  0002-repeat-gnutls_handshake-call-in-case-of-warnings.patch<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- libssh: do not let libssh create socket [bsc#1192790]  * Fixes sftp over a proxy failure in curl with error:<br>Failure establishing ssh session<br>- Add curl-libssh-socket.patch
- MIME: Properly check Content-Type even if it has parameters
- Add curl-check-content-type.patch [bsc#1190153]
- Security fix: [bsc#1190374, CVE-2021-22947]
- STARTTLS protocol injection via MITM
- Add curl-CVE-2021-22947.patch
- Security fix: [bsc#1190373, CVE-2021-22946]
- Protocol downgrade required TLS bypassed
- Add curl-CVE-2021-22946.patch
- Security fix: [bsc#1188220, CVE-2021-22925]
- TELNET stack contents disclosure again
- Add curl-CVE-2021-22925.patch
- Security fix: [bsc#1188219, CVE-2021-22924]
- Bad connection reuse due to flawed path name checks
- Add curl-CVE-2021-22924.patch
- Security fix: Disable the metalink feature:
- Insufficiently Protected Credentials [bsc#1188218, CVE-2021-22923]
- Wrong content via metalink not discarded [bsc#1188217, CVE-2021-22922]
- Security fix: [bsc#1186114, CVE-2021-22898]
- TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch
- Fix: SFTP uploads result in empty uploaded files [bsc#1177976]
- Add curl-fix-O_APPEND.patch
- Security fix: [bsc#1179593, CVE-2020-8286]
- Inferior OCSP verification: libcurl offers &quot;/OCSP stapling&quot;/ via<br>the 'CURLOPT_SSL_VERIFYSTATUS' option that, when set, verifies  
    the OCSP response that a server responds with as part of the TLS  
    handshake. It then aborts the TLS negotiation if something is  
    wrong with the response. The same feature can be enabled with  
    '--cert-status' using the curl tool.<br>- As part of the OCSP response verification, a client should verify<br>that the response is indeed set out for the correct certificate.  
    This step was not performed by libcurl when built or told to use  
    OpenSSL as TLS backend.<br>- Add curl-CVE-2020-8286.patch
- Security fix: [bsc#1179399, CVE-2020-8285]
- FTP wildcard stack overflow: The wc_statemach() internal<br>function has been rewritten to use an ordinary loop instead of  
    the recursive approach.<br>- Add curl-CVE-2020-8285.patch
- Security fix: [bsc#1179398, CVE-2020-8284]
- Trusting FTP PASV responses: When curl performs a passive FTP<br>transfer, it first tries the 'EPSV' command and if that is not  
    supported, it falls back to using 'PASV'. A malicious server  
    can use the 'PASV' response to trick curl into connecting  
    back to a given IP address and port, and this way potentially  
    make curl extract information about services that are otherwise  
    private and not disclosed.<br>- The IP address part of the response is now ignored by default,<br>by making 'CURLOPT_FTP_SKIP_PASV_IP' default to '1L'. The same  
    goes for the command line tool, which then might need  
    '--no-ftp-skip-pasv-ip' set to prevent curl from ignoring the  
    address in the server response.<br>- Add curl-CVE-2020-8284.patch
- Security fix: [bsc#1175109, CVE-2020-8231]
- An application that performs multiple requests with libcurl's<br>multi API and sets the 'CURLOPT_CONNECT_ONLY' option, might in  
    rare circumstances experience that when subsequently using the  
    setup connect-only transfer, libcurl will pick and use the wrong  
    connec | 2022-03-25 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-sap-byos-v20220126/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-sap-byos-v20220126/) |
| SUSE Image SUSE-IU-2022:44-1 | suse | SUSE-IU-2022:44-1 | This image update for google/sles-12-sp4-sap-v20220126 contains the following changes:  
Package SUSEConnect was updated:<br>- Update to 0.3.32- Allow --regcode and --instance-data attributes at the same time (jsc#PCT-164)
- Document that 'debug' can also get set in the config file
- --status will also print the subscription name
- Update to 0.3.31
- Disallow registering via SUSEConnect if the system is managed by SUSE Manager.
- Add subscription name to output of 'SUSEConnect --status'
- Update to 0.3.30
- send payload of GET requests as part of the url,<br>not in the body (see bsc#1185611)<br>Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package at was updated:<br>- Increase TasksMax limit from 512 (systemd default) to 4915,  fix bsc#1058557<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bash-4.3-boo1192785.patch  * setuid causing permission denied on popen (bsc#1192785)
- Add patch bsc1177369.patch to fix bsc#1177369
- tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Fixed CVE-2021-25219:  The lame-ttl option controls how long named caches certain types<br>of broken responses from authoritative servers (see the security  
  advisory for details). This caching mechanism could be abused by  
  an attacker to significantly degrade resolver performance. The  
  vulnerability has been mitigated by changing the default value of  
  lame-ttl to 0 and overriding any explicitly set value with 0,  
  effectively disabling this mechanism altogether. ISC's testing has  
  determined that doing that has a negligible impact on resolver  
  performance while also preventing abuse.  
  Administrators may observe more traffic towards servers issuing  
  certain types of broken responses than in previous BIND 9 releases.  
  [bsc#1192146, CVE-2021-25219, bind-CVE-2021-25219.patch]<br>- Some debugs were still in the patch for bsc#1181495.<br>[bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package binutils was updated:<br>- Add binutils-revert-hlasm-insns.diff for compatibility on old  code stream that expect 'brcl 0,label' to not be disassembled<br>as 'jgnop label' on s390x.  [bsc#1192267]<br>- Rebase binutils-2.37-branch.diff: fixes PR28523 aka boo#1188941.
- Fix empty man-pages from broken release tarball [PR28144].
- Update binutils-skip-rpaths.patch with contained a memory corruption<br>(boo#1191473).<br>- Configure with --disable-x86-used-note on old code streams.
- Disable libalternatives temporarily for build cycle reasons.
- make TARGET-bfd=headers again, we patch bfd-in.h
- This state submitted to SLE12 and SLE15 code streams for annual<br>toolchain update. [jsc#PM-2767, jsc#SLE-21561, jsc#SLE-19618]<br>- Bump binutils-2.37-branch.diff to 66d5c7003, to include fixes for<br>PR28422, PR28192, PR28391.  Also adds some s390x arch14  
  instructions [jsc#SLE-18637].<br>- Using libalternatives instead of update-alternatives.
- Adjust for testsuite fails on older products that configure<br>binutils in different ways, adds  binutils-compat-old-behaviour.diff  
  and adjusts binutils-revert-nm-symversion.diff and  
  binutils-revert-plt32-in-branches.diff.<br>- Bump binutils-2.37-branch.diff: fixes PR28138.
- Use LTO &amp; PGO build.
- Update to binutils 2.37:
- The GNU Binutils sources now requires a C99 compiler and library to<br>build.<br>- Support for the arm-symbianelf format has been removed.
- Support for Realm Management Extension (RME) for AArch64 has been<br>added.<br>- A new linker option '-z report-relative-reloc' for x86 ELF targets<br>has been added to report dynamic relative relocations.<br>- A new linker option '-z start-stop-gc' has been added to disable<br>special treatment of __start_*/__stop_* references when<br>- -gc-sections.
- A new linker options '-Bno-symbolic' has been added which will<br>cancel the '-Bsymbolic' and '-Bsymbolic-functions' options.<br>- The readelf tool has a new command line option which can be used to<br>specify how the numeric values of symbols are reported.<br>- -sym-base=0|8|10|16 tells readelf to display the values in base 8,<br>base 10 or base 16.  A sym base of 0 represents the default action  
    of displaying values under 10000 in base 10 and values above that in  
    base 16.<br>- A new format has been added to the nm program.  Specifying<br>'--format=just-symbols' (or just using -j) will tell the program to  
    only display symbol names and nothing else.<br>- A new command line option '--keep-section-symbols' has been added to<br>objcopy and strip.  This stops the removal of unused section symbols  
    when the file is copied.  Removing these symbols saves space, but  
    sometimes they are needed by other tools.<br>- The '--weaken', '--weaken-symbol' and '--weaken-symbols' options<br>supported by objcopy now make undefined symbols weak on targets that  
    support weak symbols.<br>- Readelf and objdump can now display and use the contents of .debug_sup<br>sections.<br>- Readelf and objdump will now follow links to separate debug info<br>files by default.  This behaviour can be stopped via the use of the  
    new '-wN' or '--debug-dump=no-follow-links' options for readelf and  
    the '-WN' or '--dwarf=no-follow-links' options for objdump.  Also  
    the old behaviour can be restored by the use of the  
    '--enable-follow-debug-links=no' configure time option.  
    The semantics of the =follow-links option have also been slightly  
    changed.  When enabled, the option allows for the loading of symbol  
    tables and string tables from the separate files which can be used  
    to enhance the information displayed when dumping other sections,  
    but it does not automatically imply that information from the  
    separate files should be displayed.  
    If other debug section display options are also enabled (eg  
    '--debug-dump=info') then the contents of matching sections in both  
    the main file and the separate debuginfo file *will* be displayed.  
    This is because in most cases the debug section will only be present  
    in one of the files.  
    If however non-debug section display options are enabled (eg  
    '--sections') then the contents of matching parts of the separate  
    debuginfo file will *not* be displayed.  This is because in most  
    cases the user probably only wanted to load the symbol information  
    from the separate debuginfo file.  In order to change this behaviour  
    a new command line option --process-links can be used.  This will  
    allow di0pslay options to applied to both the main file and any  
    separate debuginfo files.<br>- Nm has a new command line option: '--quiet'.  This suppresses &quot;/no<br>symbols&quot;/ diagnostic.<br>- Includes fixes for these CVEs:<br>bnc#1181452 aka CVE-2021-20197 aka PR26945  
  bnc#1183511 aka CVE-2021-20284 aka PR26931  
  bnc#1184519 aka CVE-2021-20294 aka PR26929  
  bnc#1184620 aka CVE-2021-3487 aka PR26946  
  bnc#1184794 aka CVE-2020-35448 aka PR26574<br>- Also fixes:<br>bsc#1183909 - slow performance of stripping some binaries<br>- Rebased patches: binutils-build-as-needed.diff, binutils-fix-abierrormsg.diff,<br>binutils-fix-invalid-op-errata.diff, binutils-fix-relax.diff,  
  binutils-revert-nm-symversion.diff, binutils-revert-plt32-in-branches.diff<br>- Removed patches (are in upstream): ppc-ensure-undef-dynamic-weak-undefined.patch and<br>ppc-use-local-plt.patch.<br>- Add binutils-2.37-branch.diff.gz.
- ppc-ensure-undef-dynamic-weak-undefined.patch: PPC: ensure_undef_dynamic<br>on weak undef only in plt<br>- ppc-use-local-plt.patch: PowerPC use_local_plt (prerequisite for above<br>patch)<br>- Update 2.36 branch diff which fixes PR27587.
- Do not run make TARGET-bfd=headers separately.
- Bump 2.36 branch diff (includes fix for PR27441 aka bsc#1182252).
- Bump 2.36 branch diff.
- Update 2.36 branch diff which should fix PR27311 completely.<br>It fixes also PR27284.<br>- Remove temporary fix 0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.
- Add temporary upstream fix for PR27311<br>0001-PR27311-ld.bfd-symbol-from-plugin-undefined-referenc.patch.<br>- Update to binutils 2.36:<br>New features in the Assembler:  
    General:<br>- When setting the link order attribute of ELF sections, it is now<br>possible to use a numeric section index instead of symbol name.<br>- Added a .nop directive to generate a single no-op instruction in<br>a target neutral manner.  This instruction does have an effect on  
    DWARF line number generation, if that is active.<br>- Removed --reduce-memory-overheads and --hash-size as gas now<br>uses hash tables that can be expand and shrink automatically.  
    X86/x86_64:<br>- Add support for AVX VNNI, HRESET, UINTR, TDX, AMX and Key<br>Locker instructions.<br>- Support non-absolute segment values for lcall and ljmp.
- Add {disp16} pseudo prefix to x86 assembler.
- Configure with --enable-x86-used-note by default for Linux/x86.<br>ARM/AArch64:<br>- Add support for Cortex-A78, Cortex-A78AE and Cortex-X1,<br>Cortex-R82, Neoverse V1, and Neoverse N2 cores.<br>- Add support for ETMv4 (Embedded Trace Macrocell), ETE (Embedded<br>Trace Extension), TRBE (Trace Buffer Extension), CSRE (Call  
    Stack Recorder Extension) and BRBE (Branch Record Buffer  
    Extension) system registers.<br>- Add support for Armv8-R and Armv8.7-A ISA extensions.
- Add support for DSB memory nXS barrier, WFET and WFIT<br>instruction for Armv8.7.<br>- Add support for +csre feature for -march. Add CSR PDEC<br>instruction for CSRE feature in AArch64.<br>- Add support for +flagm feature for -march in Armv8.4 AArch64.
- Add support for +ls64 feature for -march in Armv8.7<br>AArch64. Add atomic 64-byte load/store instructions for this  
    feature.<br>- Add support for +pauth (Pointer Authentication) feature for
- march in AArch64.<br>New features in the Linker:<br>- Add --error-handling-script=&lt;NAME&gt; command line option to allow<br>a helper script to be invoked when an undefined symbol or a  
    missing library is encountered.  This option can be suppressed  
    via the configure time switch: --enable-error-handling-script=no.<br>- Add -z x86-64-{baseline|v[234]} to the x86 ELF linker to mark<br>x86-64-{baseline|v[234]} ISA level as needed.<br>- Add -z unique-symbol to avoid duplicated local symbol names.
- The creation of PE format DLLs now defaults to using a more<br>secure set of DLL characteristics.<br>- The linker now deduplicates the types in .ctf sections.  The new<br>command-line option --ctf-share-types describes how to do this:  
    its default value, share-unconflicted, produces the most compact  
    output.<br>- The linker now omits the &quot;/variable section&quot;/ from .ctf sections<br>by default, saving space.  This is almost certainly what you  
    want unless you are working on a project that has its own  
    analogue of symbol tables that are not reflected in the ELF  
    symtabs.  
  New features in other binary tools:<br>- The ar tool's previously unused l modifier is now used for<br>specifying dependencies of a static library. The arguments of  
    this option (or --record-libdeps long form option) will be  
    stored verbatim in the __.LIBDEP member of the archive, which  
    the linker may read at link time.<br>- Readelf can now display the contents of LTO symbol table<br>sections when asked to do so via the --lto-syms command line  
    option.<br>- Readelf now accepts the -C command line option to enable the<br>demangling of symbol names.  In addition the --demangle=&lt;style&gt;,<br>- -no-demangle, --recurse-limit and --no-recurse-limit options<br>are also now availale.<br>- Includes fixes for these CVEs:<br>bnc#1179898 aka CVE-2020-16590 aka PR25821  
  bnc#1179899 aka CVE-2020-16591 aka PR25822  
  bnc#1179900 aka CVE-2020-16592 aka PR25823  
  bnc#1179901 aka CVE-2020-16593 aka PR25827  
  bnc#1179902 aka CVE-2020-16598 aka PR25840  
  bnc#1179903 aka CVE-2020-16599 aka PR25842  
  bnc#1180451 aka CVE-2020-35493 aka PR25307  
  bnc#1180454 aka CVE-2020-35496 aka PR25308  
  bnc#1180461 aka CVE-2020-35507 aka PR25308<br>- Rebase the following patches:
- binutils-fix-relax.diff
- binutils-revert-nm-symversion.diff
- binutils-revert-plt32-in-branches.diff
- Add missing dependency on bc (ld.gold testsuite uses it).
- Use --enable-obsolete for cross builds as ia64 is deprecated now.
- Add binutils-2.36-branch.diff.gz.
- Add binutils-fix-relax.diff to fix linking relaxation problems<br>with old object files hitting some enterprise software. [bsc#1179341]<br>- Update binutils-2.35-branch.diff.gz to commit 1c5243df:
- Fixes PR26520, aka [bsc#1179036], a problem in addr2line with<br>certain DWARF variable descriptions.<br>- Also fixes PR26711, PR26656, PR26655, PR26929, PR26808, PR25878,<br>PR26740, PR26778, PR26763, PR26685, PR26699, PR26902, PR26869,  
    PR26711<br>- The above includes fixes for dwo files produced by modern dwp,<br>fixing several problems in the DWARF reader.<br>- Reapply spec file cleanup from format_spec_file
- Remove a SLE10 version check
- Update to 2.35.1 and rebased branch diff:
- This is a point release over the previous 2.35 version, containing bug<br>fixes, and as an exception to the usual rule, one new feature.  The  
  new feature is the support for a new directive in the assembler:  
  &quot;/.nop&quot;/.  This directive creates a single no-op instruction in whatever  
  encoding is correct for the target architecture.  Unlike the .space or  
  .fill this is a real instruction, and it does affect the generation of  
  DWARF line number tables, should they be enabled.<br>- Update binutils-2.35-branch.diff.gz to commit 23f268a0:
- Add xBPF target
- Fix various problems with DWARF 5 support in gas
- Toolchain module update for SLE15 [jsc#ECO-2373]
- Includes changes that were SLE-only in binutils-add-z15-name.diff<br>for [bsc#1160590, jsc#SLE-7903 aka jsc#SLE-7464]<br>- Amend binutils-revert-plt32-in-branches.diff to adjust also new<br>testcases.<br>- Add binutils-2.35-branch.diff.gz: it includes fix for<br>nm -B for objects compiled with -flto and -fcommon.<br>- Add binutils-revert-nm-symversion.diff to be compatible with old<br>output of nm relied on in scripts.<br>- Add binutils-fix-abierrormsg.diff to work around an eager (new)<br>error message occuring without inputs and as-needed (affects  
  nvme-cli build).<br>- Update to binutils 2.35:
- The asseembler can now produce DWARF-5 format line number tables.
- Readelf now has a &quot;/lint&quot;/ mode to enable extra checks of the files it is processing.
- Readelf will now display &quot;/[...]&quot;/ when it has to truncate a symbol name.<br>The old behaviour - of displaying as many characters as possible, up to  
    the 80 column limit - can be restored by the use of the --silent-truncation  
    option.<br>- The linker can now produce a dependency file listing the inputs that it<br>has processed, much like the -M -MP option supported by the compiler.<br>- Regenerate add-ulp-section.diff with -p1 due to a fuzzing issue.
- Remove binutils-2.34-branch.diff.gz.
- Regenerate binutils-build-as-needed.diff due to a fuzzing issue.
- Regenerate binutils-fix-invalid-op-errata.diff as one hunk was upstreamed.
- Remove upstreamed patch binutils-pr25593.diff.
- Regenerate unit-at-a-time.patch due to a fuzzing issue.
- Regenerate binutils-revert-plt32-in-branches.diff.
- Update binutils-2.34-branch.diff.gz.
- Remove fix-try_load_plugin.patch as it is part<br>of the updated binutils-2.34-branch.diff.gz patch.<br>- Add binutils-pr25593.diff to fix DT_NEEDED order with -flto<br>[bsc#1163744]<br>- Update fix-try_load_plugin.patch to latest version.
- Add fix-try_load_plugin.patch in order to fix fallback caused<br>by backport for PR25355.<br>- Update to binutils 2.34:
- The disassembler (objdump --disassemble) now has an option to<br>generate ascii art thats show the arcs between that start and end  
    points of control flow instructions.<br>- The binutils tools now have support for debuginfod.  Debuginfod is a<br>HTTP service for distributing ELF/DWARF debugging information as  
    well as source code.  The tools can now connect to debuginfod  
    servers in order to download debug information about the files that  
    they are processing.<br>- The assembler and linker now support the generation of ELF format<br>files for the Z80 architecture.<br>- Rename and get binutils-2.34-branch.diff.gz (boo#1160254).
- Rebase add-ulp-section.diff, binutils-revert-plt32-in-branches.diff,<br>cross-avr-size.patch and binutils-skip-rpaths.patch.<br>- Add new subpackages for libctf and libctf-nobfd.
- Disable LTO due to boo#1163333.
- Includes fixes for these CVEs:<br>bnc#1153768 aka CVE-2019-17451 aka PR25070  
  bnc#1153770 aka CVE-2019-17450 aka PR25078<br>- Disable LTO during testsuite run
- Add binutils-fix-invalid-op-errata.diff to fix various<br>build fails on aarch64 (PR25210, bsc#1157755).<br>- Add add-ulp-section.diff for user space live patching.
- Update to binutils 2.33.1:
- Adds support for the Arm Scalable Vector Extension version 2<br>(SVE2) instructions, the Arm Transactional Memory Extension (TME)  
    instructions and the Armv8.1-M Mainline and M-profile Vector  
    Extension (MVE) instructions.<br>- Adds support for the Arm Cortex-A76AE, Cortex-A77 and Cortex-M35P<br>processors and the AArch64 Cortex-A34, Cortex-A65, Cortex-A65AE,  
    Cortex-A76AE, and Cortex-A77 processors.<br>- Adds a .float16 directive for both Arm and AArch64 to allow<br>encoding of 16-bit floating point literals.<br>- For MIPS, Add -m[no-]fix-loongson3-llsc option to fix (or not)<br>Loongson3 LLSC Errata.  Add a --enable-mips-fix-loongson3-llsc=[yes|no]  
    configure time option to set the default behavior. Set the default  
    if the configure option is not used to &quot;/no&quot;/.<br>- The Cortex-A53 Erratum 843419 workaround now supports a choice of<br>which workaround to use.  The option --fix-cortex-a53-843419 now  
    takes an optional argument --fix-cortex-a53-843419[=full|adr|adrp]  
    which can be used to force a particular workaround to be used.  
    See --help for AArch64 for more details.<br>- Add support for GNU_PROPERTY_AARCH64_FEATURE_1_BTI and<br>GNU_PROPERTY_AARCH64_FEATURE_1_PAC  in ELF GNU program properties  
    in the AArch64 ELF linker.<br>- Add -z force-bti for AArch64 to enable GNU_PROPERTY_AARCH64_FEATURE_1_BTI<br>on output while warning about missing GNU_PROPERTY_AARCH64_FEATURE_1_BTI  
    on inputs and use PLTs protected with BTI.<br>- Add -z pac-plt for AArch64 to pick PAC enabled PLTs.
- Add --source-comment[=&lt;txt&gt;] option to objdump which if present,<br>provides a prefix to source code lines displayed in a disassembly.<br>- Add --set-section-alignment &lt;section-name&gt;=&lt;power-of-2-align&gt;<br>option to objcopy to allow the changing of section alignments.<br>- Add --verilog-data-width option to objcopy for verilog targets to<br>control width of data elements in verilog hex format.<br>- The separate debug info file options of readelf (--debug-dump=links<br>and --debug-dump=follow) and objdump (--dwarf=links and<br>- -dwarf=follow-links) will now display and/or follow multiple<br>links if more than one are present in a file.  (This usually  
    happens when gcc's -gsplit-dwarf option is used).  
    In addition objdump's --dwarf=follow-links now also affects its  
    other display options, so that for example, when combined with<br>- -syms it will cause the symbol tables in any linked debug info<br>files to also be displayed.  In addition when combined with<br>- -disassemble the --dwarf= follow-links option will ensure that<br>any symbol tables in the linked files are read and used when  
    disassembling code in the main file.<br>- Add support for dumping types encoded in the Compact Type Format<br>to objdump and readelf.<br>- Includes fixes for these CVEs:<br>bnc#1126826 aka CVE-2019-9077 aka PR1126826  
  bnc#1126829 aka CVE-2019-9075 aka PR1126829  
  bnc#1126831 aka CVE-2019-9074 aka PR24235  
  bnc#1140126 aka CVE-2019-12972 aka PR23405  
  bnc#1143609 aka CVE-2019-14444 aka PR24829  
  bnc#1142649 aka CVE-2019-14250 aka PR90924<br>- Remove patches that are now included in the release:<br>binutils-2.32-branch.diff.gz, binutils-fix-ld-segv.diff,  
  binutils-pr24486.patch, riscv-abi-check.patch,  
  rx-gas-padding-pr24464.patch.<br>- Add binutils-2.33-branch.diff.gz patch.
- Rebase binutils-revert-plt32-in-branches.diff and<br>cross-avr-size.patch patch.<br>Package bzip2 was updated:<br>- Implement %check, bsc#1191648- Remove bzip2-faster.patch, it causes a crash with libarchive and<br>valgrind points out uninitialized memory. See  
  [https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576](https://github.com/libarchive/libarchive/issues/637#issuecomment-170612576)  
  Required for bsc#1188891<br>- Fix basisms in bzgrep and bznew
- bzip2-1.0.6-fix-bashisms.patch<br>Package ca-certificates-mozilla was updated:<br>- remove the DST_Root_CA_X3.pem trust, as it expires september 30th 2021.  (bsc#1190858)<br>Package cairo was updated:<br>- Add cairo-fix-infinite-loop-bsc1122321-CVE-2019-6462.patch: This  fixes a potentially infinite loop (bsc#1122321, CVE-2019-6462,<br>glfo#cairo/cairo#155).<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package cloud-netconfig was updated:<br>- Update to version 1.6:  + Ignore proxy when accessing metadata (bsc#1187939)<br>+ Print warning in case metadata is not accessible  
  + Documentation update<br>Package cloud-regionsrv-client was updated:<br>- Update to version 9.3.0 (jsc#PCT-130)  + Support AHB-v3<br>+ Support registration of BYOS instances against the update infrastructure  
  + Properly extract the region for local zones in AWS to ensure instances  
    get connected to the proper update servers  
  + Azure addon service and executable rename  
  + Support non SLE repos  
  + Fix handling of regionservers configured with DNS names<br>- Avoid race confition with ca-certificates (bsc#1189362)<br>+ Make the service run after ca-sertificates is done  
  + Attempt multiple times to update the trust chain<br>- New package to enable/disable access due to AHB<br>This references bsc#1182026, (jsc#SLE-21246, jsc#SLE-21247, jsc#SLE-21248, jsc#SLE-21249, jsc#SLE-21250)<br>- Update to version 9.2.0 (bsc#1029162)<br>+ Support IPv6 as best-effort, with fallback to IPv4<br>- Update to version 9.1.5 (bsc#1182779, bsc#1185234, bsc#1185198)<br>+ Another startup process may run zypper before the registration process  
    if zypper is still running we cannot get the lock and as such  
    the installed products cannot be determined. Wait for the lock to be  
    released for up to 30 seconds.  
  + On any error durring product list generation return a list to avoid  
    a traceback by trying to iterate over None<br>Package compat-openssl098 was updated:<br>- Other OpenSSL functions that print ASN.1 data have been found to assume that  the ASN1_STRING byte array will be NUL terminated, even though this is not<br>guaranteed for strings that have been directly constructed. Where an application  
  requests an ASN.1 structure to be printed, and where that ASN.1 structure  
  contains ASN1_STRINGs that have been directly constructed by the application  
  without NUL terminating the &quot;/data&quot;/ field, then a read buffer overrun can occur.<br>- CVE-2021-3712 continued
- bsc#1189521
- Add CVE-2021-3712-other-ASN1_STRING-issues.patch
- Sourced from openssl-CVE-2021-3712.tar.bz2 posted on bsc-1189521<br>2021-08-24 00:47 PDT by Marcus Meissner<br>- The function X509_CERT_AUX_print() has a bug which may cause a read buffer overrun<br>when printing certificate details. A malicious actor could construct a  
  certificate to deliberately hit this bug, which may result in a crash of the  
  application (causing a Denial of Service attack).<br>- CVE-2021-3712
- bsc#1189521
- Add CVE-2021-3712-Fix-read-buffer-overrun-in-X509_CERT_AUX_print.patch
- Security fixes:
- Integer overflow in CipherUpdate: Incorrect SSLv2 rollback<br>protection [bsc#1182333, CVE-2021-23840]<br>- Null pointer deref in X509_issuer_and_serial_hash()<br>[bsc#1182331, CVE-2021-23841]<br>- Add openssl-CVE-2021-23840.patch openssl-CVE-2021-23841.patch<br>Package corosync was updated:<br>- bsc#1191419, Update cancel_token_hold_on_retransmit_option patch, fix parsing of the option in corosync-2.3.6  Modified: bsc#1189680-cancel_token_hold_on_retransmit-option.patch
- corosync totem: bsc#1189680, Add cancel_token_hold_on_retransmit config option<br>Added: bsc#1189680-cancel_token_hold_on_retransmit-option.patch<br>- Fix bsc#1166899, return value of &quot;/corosync-quorumtool -s&quot;/ was not correct<br>Added: bug-1166899-quorumtool-Fix-exit-status-codes.patch<br>- totempg: Fix memory leak (bsc#1083030)<br>Package cpio was updated:<br>- Fix segmentation fault caused by a regression (bsc#1189465)  * fix-CVE-2021-38185_4.patch
- Add another patch to fix regression (bsc#1189465)
- fix-CVE-2021-38185_3.patch
- Fix regression in last update (bsc#1189465)
- fix-CVE-2021-38185_2.patch
- Fix CVE-2021-38185 Remote code execution caused by an integer overflow in ds_fgetstr<br>(CVE-2021-38185, bsc#1189206)<br>- fix-CVE-2021-38185.patch<br>Package cracklib was updated:<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package crmsh was updated:<br>- Update to version 4.1.1+git.1642405877.e4f905fc:  * Fix: ui_resource: Parse node and lifetime correctly (bsc#1192618)
- Fix: ui_resource: Parse lifetime option correctly (bsc#1191508)
- Fix: utils: Improve detect_cloud function and support non-Hyper-V in Azure
- Update to version 4.1.1+git.1630047134.803a70f2:
- Fix: hb_report: Using python way to collect ra trace files (bsc#1189641)
- Fix: history: use utils.mkdirp instead of system mkdir command(bsc#1179999, CVE-2020-35459)
- Remove patch:
- 0001-Fix-history-use-utils.mkdirp-instead-of-system-mkdir.patch
- Update to version 4.1.1+git.1625191010.47a3ee14:
- Dev: crash_test: Add big warnings to have users' attention to potential failover
- Dev: crash_test: rename preflight_check as crash_test (jsc#SLE-18367 for ECO jsc#SLE-18374)
- Fix: completers: return complete start/stop resource id list correctly(bsc#1180137)
- Medium: integrate preflight_check into crmsh
- Fix: help: show help message from argparse(bsc#1175982)
- Fix: resource: make untrace consistent with trace (bsc#1187396)
- Fix: parse: shouldn't allow property setting with an empty value(bsc#1185423)
- Update to version 4.1.0+git.1620355744.c0b5142f:
- Fix: bootstrap: change StrictHostKeyChecking=no as a constants(bsc#1185437)
- Dev: bootstrap: disable unnecessary warnings (bsc#1178118)
- Fix: bootstrap: raise warning when configuring diskless SBD with node's count less than 3(bsc#1181907)
- Fix: bootstrap: sync corosync.conf before finished joining(bsc#1183359)
- Fix: bootstrap: parse space in sbd device correctly(bsc#1183883)
- Fix: bootstrap: get the peer node name correctly (bsc#1183654)
- Fix: update verion and author (bsc#1183689)
- Fix: ui_resource: change return code and error to warning for some unharmful actions(bsc#1180332)
- Fix: ui_configure: raise error when params not exist(bsc#1180126)
- Update to version 4.1.0+git.1614156984.f4f5e146:
- Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Dev: utils: change default file mod as 644 for str2file function
- Dev: lock: give more specific error message when raise ClaimLockError
- Dev: hb_report: Detect if any ocfs2 partitions exist
- Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688)
- Dev: corosync: change the permission of corosync.conf to 644
- Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869)
- Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)<br>Package cronie was updated:<br>- Increase limit of allowed entries in crontab files to fix bsc#1187508  * cronie-1.4.11-increase_crontab_limit.patch<br>Package csync2 was updated:<br>- VUL-1: CVE-2019-15522: csync2: daemon fails to enforce TLS  (bsc#1147137)
- VUL-1: CVE-2019-15523: csync2: incorrect TLS handshake error handling<br>(bsc#1147139)  
  Apply upstream patch:  
  0001-fail-HELLO-command-when-SSL-is-required.patch  
  0002-repeat-gnutls_handshake-call-in-case-of-warnings.patch<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- libssh: do not let libssh create socket [bsc#1192790]  * Fixes sftp over a proxy failure in curl with error:<br>Failure establishing ssh session<br>- Add curl-libssh-socket.patch
- MIME: Properly check Content-Type even if it has parameters
- Add curl-check-content-type.patch [bsc#1190153]
- Security fix: [bsc#1190374, CVE-2021-22947]
- STARTTLS protocol injection via MITM
- Add curl-CVE-2021-22947.patch
- Security fix: [bsc#1190373, CVE-2021-22946]
- Protocol downgrade required TLS bypassed
- Add curl-CVE-2021-22946.patch
- Security fix: [bsc#1188220, CVE-2021-22925]
- TELNET stack contents disclosure again
- Add curl-CVE-2021-22925.patch
- Security fix: [bsc#1188219, CVE-2021-22924]
- Bad connection reuse due to flawed path name checks
- Add curl-CVE-2021-22924.patch
- Security fix: Disable the metalink feature:
- Insufficiently Protected Credentials [bsc#1188218, CVE-2021-22923]
- Wrong content via metalink not discarded [bsc#1188217, CVE-2021-22922]
- Security fix: [bsc#1186114, CVE-2021-22898]
- TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch
- Fix: SFTP uploads result in empty uploaded files [bsc#1177976]
- Add curl-fix-O_APPEND.patch
- Security fix: [bsc#1179593, CVE-2020-8286]
- Inferior OCSP verification: libcurl offers &quot;/OCSP stapling&quot;/ via<br>the 'CURLOPT_SSL_VERIFYSTATUS' option that, when set, verifies  
    the OCSP response that a server responds with as part of the TLS  
    handshake. It then aborts the TLS negotiation if something is  
    wrong with the response. The same feature can be enabled with  
    '--cert-status' using the curl tool.<br>- As part of the OCSP response verification, a client should verify<br>that the response is indeed set out for the correct certificate.  
    This step was not performed by libcurl when built or told to use  
    OpenSSL as TLS backend.<br>- Add curl-CVE-2020-8286.patch
- Security fix: [bsc#1179399, CVE-2020-8285]
- FTP wildcard stack o | 2022-03-25 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-sap-v20220126/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp4-sap-v20220126/) |
| SUSE Image SUSE-IU-2021:452-1 | suse | SUSE-IU-2021:452-1 | This image update for google/sles-12-sp5-byos-v20210604 contains the following changes:  
Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bsc1177369.patch to fix bsc#1177369  * tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Some debugs were still in the patch for bsc#1181495.  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]
- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- Security fix: [bsc#1186114, CVE-2021-22898]  * TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Allow partial chain verification [jsc#SLE-17954]
- Have intermediate certificates in the trust store be treated<br>as trust-anchors, in the same way as self-signed root CA  
    certificates are. This allows users to verify servers using  
    the intermediate cert only, instead of needing the whole chain.<br>- Set FLAG_TRUSTED_FIRST unconditionally.
- Do not check partial chains with CRL check.
- Add curl-X509_V_FLAG_PARTIAL_CHAIN.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch<br>Package dhcp was updated:<br>- CVE-2021-25217, bsc#1186382, dhcp-CVE-2021-25217.patch: A buffer  overrun in lease file parsing code can be used to exploit a<br>common vulnerability shared by dhcpd and dhclient.<br>Package dracut was updated:<br>- fix(shutdown): add timeout to umount calls (bsc#1178219)  * add 0624-shutdown-guard-against-read-only-run.patch
- add 0625-shutdown-sleep-a-little-if-a-process-was-killed.patch
- add 0626-fix-shutdown-add-timeout-to-umount-calls.patch
- support network setup on infiniband devices (bsc#996146)
- add 0623-net-lib.sh-support-infiniband-network-mac-addresses.patch<br>Package gcc10 was updated:<br>- SLE12 only, adjust gcc10-rpmlintrc to ignore bogus  libgcc_s1-gcc10.s390x: E: invalid-license (Badness: 100000)<br>GPL-3.0 WITH GCC-exception-3.1  [bsc#1185337]<br>- Update to GCC 10.3.0 release (63fa67847628e5f358e7e2e7e), git1587
- Disable nvptx offloading for aarch64 again since it doesn't work
- Update to gcc-10 branch head (892024d4af83b258801ff7484), git1574
- Includes GCC 10.3 RC1
- Update to gcc-10 branch head (592388d4f6e8a6adb470428fe), git1450
- Update to gcc-10 branch head (85977f624a34eac309f9d77a5), git1331
- Includes fix for [bsc#1182016]
- The 32bit nvptx libgomp plugin is no longer built, do not attempt<br>to package it.<br>- Remove include-fixed/pthread.h
- Change GCC exception licenses to SPDX format
- Update to gcc-10 branch head (e563687cf9d3d1278f45aaebd), git1030
- Includes fix for firefox build [gcc#97918]
- Do not specify alternate offload compiler location at<br>configure time.<br>- Update README.First-for.SuSE.packagers
- Install offload compilers for gcc10-testresults build
- Enable fortran for offload compilers.
- Add gcc10-amdgcn-llvm-as.patch to fix build of amdgcn offload<br>compiler with llvm11.<br>- Update to gcc-10 branch head (98ba03ffe0b9f37b4916ce6238), git958.
- Includes fix for memcpy miscompilation on aarch64.<br>[bsc#1178624, bsc#1178577]<br>- Fix 32bit libgnat.so link.  [bsc#1178675]
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it<br>stays /%lib. (boo#1029961)<br>- Update to gcc-10 branch head (a78cd759754c92cecbf235ac9b), git872.
- Build complete set of multilibs for arm-none target [bsc#1106014]
- Fixes inadvertant mixture of ARM and Thumb instructions in linker output<br>Package glib2 was updated:<br>- Add glib2-CVE-2021-27218.patch: g_byte_array_new_take takes a  gsize as length but stores in a guint, this patch will refuse if<br>the length is larger than guint. (bsc#1182328,  
  glgo#GNOME/glib!1944)<br>- Add glib2-CVE-2021-27219-add-g_memdup2.patch: g_memdup takes a<br>guint as parameter and sometimes leads into an integer overflow,  
  so add a g_memdup2 function which uses gsize to replace it.  
  (bsc#1182362, glgo#GNOME/glib!1927, glgo#GNOME/glib!1933,  
  glgo#GNOME/glib!1943)<br>Package glibc was updated:<br>- s390-memmove-ifunc-selector-arch13.patch: S390: Also check vector  support in memmove ifunc-selector (bsc#1184034, BZ #27511)
- iconv-redundant-shift.patch: iconv: Accept redundant shift sequences in<br>IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)<br>- iconv-ucs4-loop-bounds.patch: iconv: Fix incorrect UCS4 inner loop<br>bounds (CVE-2020-29562, bsc#1179694, BZ #26923)<br>- printf-long-double-non-normal.patch: x86: Harden printf against<br>non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649)<br>Package google-guest-agent was updated:<br>- Update to version 20210414.00 (bsc#1185848, bsc#1185849)  * start sshd (#106)
- Add systemd-networkd.service restart dependency. (#104)
- Update error message for handleHealthCheckRequest. (#105)
- Update to version 20210223.01 (bsc#1183414, bsc#1183415)
- add a match block to sshd_config for SAs (#99)
- add ipv6 forwarded ip support (#101)
- call restorecon on ssh host keys (#98)
- Include startup and shutdown in preset (#96)
- set metadata URL earlier (#94)
- Fix activation logic of systemd services (bsc#1182793)
- Update to version 20201211.00
- Require snapshot scripts to live under /etc/google/snapshots (#90)
- Adding support for Windows user account password lengths<br>between 15 and 255 characters. (#91)<br>- Adding bkatyl to OWNERS (#92)<br>Package google-guest-configs was updated:<br>- Update to version 20210317.00 (bsc#1183414, bsc#1183415)  * dracut.conf wants spaces around values (#19)
- make the same change for debian (#18)
- change path back for google_nvme_id (#17)
- move google_nvme_id to /usr/bin (#16)
- correct udev rule syntax (#15)
- prune el6 spec (#13)
- Updated udev rules (#11)
- Remove empty %{_sbindir} from %install and %files section
- Remove service files (bsc#1180304)<br>+ google-optimize-local-ssd.service, google-set-multiqueue.service  
    scripts are called from within the guest agent<br>Package google-guest-oslogin was updated:<br>- Update to version 20210429.00 (bsc#1185848, bsc#1185849)  * correct pagetoken in groupsforuser (#59)
- resolve self groups last (#58)
- support empty groups (#57)
- no paginating to find groups (#56)
- clear users vector (#55)
- correct usage of pagetoken (#54)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- call correct function in pwenthelper (#53)
- Update to version 20210108.00
- Update logic in the cache_refresh binary (#52)
- remove old unused workflow files (#49)<br>Package google-osconfig-agent was updated:<br>- Update to version 20210506.00 (bsc#1185848, bsc#1185849)  * Add more os policy assignment examples (#348)
- e2e_tests: enable stable tests for OSPolicies (#347)
- Align start and end task logs (#346)
- ConfigTask: add additional info logs (#345)
- e2e_tests: add validation tests (#344)
- Config Task: make sure agent respects policy mode (#343)
- update
- e2e_tests: readd retries to OSPolicies
- Set minWaitDuration as a string instead of object (#341)
- e2e_tests: Fix a few SUSE tests (#339)
- Remove pre-release flag from config (#340)
- e2e_tests: fixup OSPolicy tests (#338)
- e2e_tests: unlock mutex for CreatePolicies as soon as create finishes (#337)
- e2e_tests: Don't retry failed OSPolicy tests, fix msi test (#336)
- Examples for os policy assignments (#334)
- e2e_tests: increase the deadline for OSPolicy tests and only start after a zone has been secured (#335)
- Fix panic when installing MSI (#332)
- e2e_tests: Add test cases of installing dbe, rpm and msi packages (#333)
- e2e_tests: add more logging
- e2e_tests: (#330)
- e2e_test: Add timouts to OSPolicy tests so we don't wait forever (#329)
- Create top level directories for gcloud and console for os policy assignment examples (#328)
- e2e_tests: Move api from an internal directory (#327)
- Make sure we use the same test name for reruns (#326)
- Add CONFIG_V1 capability (#325)
- e2e_tests: reduce size of instances, use pd-balanced, rerun failed tests once (#324)
- Only report installed packages for dpkg (#322)
- e2e_tests: fix windows package and repository tests (#323)
- Add top level directories for os policy examples (#321)
- e2e_tests: move to using inventory api for inventory reporting (#320)
- e2e_tests: add ExecResource tests (#319)
- ExecResource: make sure we set permissions correctly for downloaded files (#318)
- Config task: only run post check on resources that have already been evaluated (#317)
- e2e_test: reorganize OSPolicy tests to be per Resource type (#316)
- Set custom user agent (#299)
- e2e_tests: check InstanceOSPoliciesCompliance for each test case, add LocalPath FileResource test (#314)
- PackageResource: make sure to run AptUpdate prior to package install (#315)
- Fix bugs/add more logging for OSPolicies (#313)
- Change metadata http client to ignore http proxies (#312)
- e2e_test: add tests for FileResource (#311)
- Add task_type context logging (#310)
- Fix e2e_test typo (#309)
- Fix e2e_tests (#308)
- Disable OSPolicies by default since it is an unreleased feature (#307)
- e2e_tests: Add more OSPolicies package and repo tests (#306)
- Do not enforce repo_gpgcheck in guestpolicies (#305)
- Gather inventory 3-5min after agent start (#303)
- e2e_tests: add OSPolicies tests for package install (#302)
- Add helpful error log if a service account is missing (#304)
- OSPolicies: correct apt repo extension, remove yum/zypper gpgcheck override (#301)
- Update cos library to parse new version of packages file (#300)
- config_task: Rework config step logic (#296)
- e2e_test: enable serial logs in cos to support ReportInventory test (#297)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- ExecResource: fix bug in return code handling (#295)
- Fix ExecResource permissions, add logs to fetcher (#294)
- e2e_tests: Fix ubuntu proposed family (#293)
- e2e_tests: add proposed debian images to head tests (#292)
- Fix exec_resource for config task, add minimal unit test (#291)
- Change util.WriteFile to AtomicWriteFileStream (#289)
- Merge development branch into master (#288)
- Create util.TempFile to work nicely with Windows (#287)
- Fix copy step write (#286)
- Fix error on linux lock (#285)
- Ensure we cleanup on error in AtomicWrite (#284)
- Make writes atomic, add unused &quot;/allowDowngrades&quot;/ option<br>to apt, fix a few recipe issues (#283)<br>- update reviewers (#282)
- update apt package lists before running installs (#281)
- Simplify build tags for COS package (#280)
- Update to version 20210112.00
- Fix builds for ppc and s390x (#274)
- Minor updates to tests and additional debug logging (#272)
- Add Ubuntu 2004 to tests (#271)
- Make sure we stop tickers (#270)
- Drop Windows 1903 and CentOS 6 from tests (#269)
- Pin el6 tests to last published image as it is EOL (#267)
- support cos (#266)
- Update to version 20201117.00 (bsc#1179031, bsc#1179032)
- Ignore Unavailable erros on stream receive (#260)
- Update test Windows images (#259)
- update ReportInventory e2e test regexes (#255)
- Don't return on a windows update error (#254)
- use retryutil for ReportInventory calls (#253)
- add additional debug logging for ReportInventory request payload for e2e tests (#252)
- stop logging instance identity token as part of ReportInventory request and remove<br>feature-flag setting in OSInventoryReporting e2e tests (#251)<br>- complete ExecTask as no-op when the ExecStepConfig doesn't match the OS (#250)
- Add software recipe tests for COS (#249)
- remove feature flag for inventory reporting (#243)
- Force yum to never colorize output (#247)
- Add sleep after Unavailable errors for agentendpoint (#241)
- Ensure we record epoch for rpm packages (#242)
- Make inventory WUAUpdates call spawn a new process,<br>retry on metadata unmarshal error (#239)<br>- add debug logging for report inventory response (#240)
- add initial e2e tests for inventory reporting (#237)
- Report installed packages on COS (#236)<br>Package grub2 was updated:<br>- Fix executable stack in grub-emu (bsc#1181696)  * 0001-emu-fix-executable-stack-marking.patch<br>Package gzip was updated:<br>- fix DFLTCC segfault [bsc#1177047]- added patches<br>fix [https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc](https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc)  
  + gzip-1.10-fix-DFLTCC-segfault.patch<br>- gzip.spec: move %patch10 from the ifarch condition (mistake)
- add gzip-1.10-fix_count_of_lines_to_skip.patch to fix count<br>of lines to skip [bsc#1180713]<br>Package irqbalance was updated:<br>- Increase size of procinterrupts line readings by factor 32 (bsc#1184592)  A procinterrupts_read_buffer_increase.patch
- Use _fillupdir in spec file to also build against latest distros<br>which could be useful for comparing versions in case we get yet  
  another bug.<br>- not balancing interrupts in Xen guests (bsc#1178477, bsc#1183405)<br>A procinterrupts-check-xen-dyn-event-more-flexible.patch<br>Package kernel-default was updated:<br>- smsc95xx: avoid memory leak in smsc95xx_bind (git-fixes).- commit 1640fc2
- smsc95xx: check return value of smsc95xx_reset (git-fixes).
- commit 00f3661
- net: cxgb4: fix return error value in t4_prep_fw (git-fixes).
- commit 6c63ec6
- net: bcmgenet: use hardware padding of runt frames (git-fixes).
- commit 20467c9
- blacklist.conf: Add fe6bdfc8e1e1 mm: fix oom_kill event handling
- commit 016ac3f
- blacklist.conf: Add e81bf9793b18 mem_cgroup: make sure moving_account, move_lock_task and stat_cpu in the same cacheline
- commit 0632aad
- Don't drop out of segments RST if tcp_be_liberal is set<br>(bsc#1183947).<br>- Avoid potentially erroneos RST drop (bsc#1183947).
- commit 4727a1c
- Update<br>patches.suse/net-fix-race-condition-in-__inet_lookup_established.patch  
  (bsc#1151794 bsc#1180624).<br>- handle also the opposite type of race condition
- commit 7737da1
- powerpc/perf: Fix PMU constraint check for EBB events<br>(bsc#1065729).<br>- powerpc/64s: Fix pte update for kernel memory on radix<br>(bsc#1055117 git-fixes).<br>- powerpc/asm-offsets: GPR14 is not needed either (bsc#1065729).
- powerpc/prom: Mark identical_pvr_fixup as __init (bsc#1065729).
- powerpc/fadump: Mark fadump_calculate_reserve_size as __init<br>(bsc#1065729).<br>- stop_machine: mark helpers __always_inline (bsc#1087405<br>git-fixes).<br>- commit 25e3769
- ibmvnic: queue reset work in system_long_wq (bsc#1152457<br>ltc#174432 git-fixes).<br>- ibmvnic: improve failover sysfs entry (bsc#1043990 ltc#155681<br>git-fixes).<br>- ibmvnic: print adapter state as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: print reset reason as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: clean up the remaining debugfs data structures<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in open function<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in do_reset<br>function (bsc#1065729).<br>- ibmvnic: avoid calling napi_disable() twice (bsc#1065729).
- commit 46cbce7
- KVM: Add proper lockdep assertion in I/O bus unregister<br>(CVE-2020-36312 bsc#1184509).<br>- KVM: Stop looking for coalesced MMIO zones if the bus is<br>destroyed (CVE-2020-36312 bsc#1184509).<br>- KVM: Destroy I/O bus devices on unregister failure _after_<br>sync'ing SRCU (CVE-2020-36312 bsc#1184509).<br>- commit bc1f707
- btrfs: fix qgroup data rsv leak caused by falloc failure<br>(bsc#1185549).<br>- commit e1218ad
- btrfs: track qgroup released data in own variable in<br>insert_prealloc_file_extent (bsc#1185549).<br>- commit bf772b7
- Refresh<br>patches.suse/ibmvnic-Use-skb_frag_address-instead-of-hand-coding-.patch.<br>- Refresh<br>patches.suse/scsi-ibmvfc-Fix-invalid-state-machine-BUG_ON.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Change-wording-of-invalid-pci-reset-log-me.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Correct-function-header-comments-related-t.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-ADISC-handling-that-never-frees-nodes.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-FLOGI-failure-due-to-accessing-a-freed.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-PLOGI-ACC-to-be-transmit-after-REG_LOG.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-crash-caused-by-switch-reboot.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-dropped-FLOGI-during-pt2pt-discovery-r.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-incorrect-dbde-assignment-when-buildin.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-lpfc_els_retry-possible-null-pointer-d.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-nodeinfo-debugfs-output.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-null-pointer-dereference-in-lpfc_prep_.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-connection-does-not-recover-afte.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-state-transition-causing-rmmod-h.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-reftag-generation-sizing-errors.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-stale-node-accesses-on-stale-RRQ-reque.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-status-returned-in-lpfc_els_retry-erro.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-unnecessary-null-check-in-lpfc_release.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-use-after-free-in-lpfc_els_free_iocb.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-vport-indices-in-lpfc_find_vport_by_vp.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Reduce-LOG_TRACE_EVENT-logging-for-vports.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-copyrights-for-12.8.0.7-and-12.8.0..patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-lpfc-version-to-12.8.0.8.patch.<br>- commit d057148
- scsi: qla2xxx: Reserve extra IRQ vectors (bsc#1185491).
- scsi: qla2xxx: Reuse existing error handling path (bsc#1185491).
- scsi: qla2xxx: Remove unneeded if-null-free check (bsc#1185491).
- scsi: qla2xxx: Update version to 10.02.00.106-k (bsc#1185491).
- scsi: qla2xxx: Do logout even if fabric scan retries got<br>exhausted (bsc#1185491).<br>- scsi: qla2xxx: Update default AER debug mask (bsc#1185491).
- scsi: qla2xxx: Fix mailbox recovery during PCIe error<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix crash in PCIe error handling (bsc#1185491).
- scsi: qla2xxx: Fix RISC RESET completion polling (bsc#1185491).
- scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix use after free in bsg (bsc#1185491).
- scsi: qla2xxx: Consolidate zio threshold setting for both FCP &amp;<br>NVMe (bsc#1185491).<br>- scsi: qla2xxx: Fix stuck session (bsc#1185491).
- scsi: qla2xxx: Add H:C:T info in the log message for fc ports<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix IOPS drop seen in some adapters<br>(bsc#1185491).<br>- scsi: qla2xxx: Check kzalloc() return value (bsc#1185491).
- scsi: qla2xxx: Always check the return value of<br>qla24xx_get_isp_stats() (bsc#1185491).<br>- scsi: qla2xxx: Simplify qla8044_minidump_process_control()<br>(bsc#1185491).<br>- scsi: qla2xxx: Suppress Coverity complaints about dseg_r*<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix endianness annotations (bsc#1185491).
- scsi: qla2xxx: Constify struct qla_tgt_func_tmpl (bsc#1185491).
- scsi: qla2xxx: Use dma_pool_zalloc() (bsc#1185491).
- scsi: qla2xxx: Fix a couple of misdocumented functions<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix incorrectly named function<br>qla8044_check_temp() (bsc#1185491).<br>- scsi: qla2xxx: Fix a couple of misnamed functions (bsc#1185491).
- scsi: qla2xxx: Fix some incorrect formatting/spelling issues<br>(bsc#1185491).<br>- scsi: qla2xxx: Replace __qla2x00_marker()'s missing underscores<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix broken #endif placement (bsc#1185491).
- scsi: qla2xxx: Simplify if statement (bsc#1185491).
- scsi: qla2xxx: Simplify the calculation of variables<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix some memory corruption (bsc#1185491).
- scsi: qla2xxx: Remove redundant NULL check (bsc#1185491).
- scsi: qla2xxx: Remove unnecessary NULL check (bsc#1185491).
- scsi: qla2xxx: Assign boolean values to a bool variable<br>(bsc#1185491).<br>- scsi: qla2xxx: fc_remote_port_chkready() returns a SCSI result<br>value (bsc#1185491).<br>- scsi: qla2xxx: Update version to 10.02.00.105-k (bsc#1185491).
- scsi: qla2xxx: Enable NVMe CONF (BIT_7) when enabling SLER<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix mailbox Ch erroneous error (bsc#1185491).
- scsi: qla2xxx: Wait for ABTS response on I/O timeouts for NVMe<br>(bsc#1185491).<br>- scsi: qla2xxx: Move some messages from debug to normal log level<br>(bsc#1185491).<br>- scsi: qla2xxx: Add error counters to debugfs node (bsc#1185491).
- scsi: qla2xxx: Implementation to get and manage host, target<br>stats and initiator port (bsc#1185491).<br>- commit 9add63f
- blacklist.conf: kthread: Fixes debugging of the life cycle of work struct.<br>Broken for ages. Disabled in our configuration.<br>- commit 4600ed3
- scsi: lpfc: Fix DMA virtual address ptr assignment in bsg<br>(bsc#1185365).<br>- scsi: lpfc: Fix illegal memory access on Abort IOCBs<br>(bsc#1183203).<br>- scsi: lpfc: Copyright updates for 12.8.0.9 patches<br>(bsc#1185472).<br>- scsi: lpfc: Update lpfc version to 12.8.0.9 (bsc#1185472).
- scsi: lpfc: Eliminate use of LPFC_DRIVER_NAME in lpfc_attr.c<br>(bsc#1185472).<br>- scsi: lpfc: Standardize discovery object logging format<br>(bsc#1185472).<br>- scsi: lpfc: Fix various trivial errors in comments and log<br>messages (bsc#1185472).<br>- scsi: lpfc: Remove unsupported mbox PORT_CAPABILITIES logic<br>(bsc#1185472).<br>- scsi: lpfc: Fix lpfc_hdw_queue attribute being ignored<br>(bsc#1185472).<br>- scsi: lpfc: Fix missing FDMI registrations after Mgmt Svc login<br>(bsc#1185472).<br>- scsi: lpfc: Fix silent memory allocation failure in<br>lpfc_sli4_bsg_link_diag_test() (bsc#1185472).<br>- scsi: lpfc: Fix use-after-free on unused nodes after port swap<br>(bsc#1185472).<br>- scsi: lpfc: Fix error handling for mailboxes completed in<br>MBX_POLL mode (bsc#1185472).<br>- scsi: lpfc: Fix lack of device removal on port swaps with PRLIs<br>(bsc#1185472).<br>- scsi: lpfc: Fix NMI crash during rmmod due to circular hbalock<br>dependency (bsc#1185472).<br>- scsi: lpfc: Fix reference counting errors in lpfc_cmpl_els_rsp()<br>(bsc#1185472).<br>- scsi: lpfc: Fix crash when a REG_RPI mailbox fails triggering<br>a LOGO response (bsc#1185472).<br>- scsi: lpfc: Fix rmmod crash due to bad ring pointers to<br>abort_iotag (bsc#1185472).<br>- scsi: lpfc: Fix gcc -Wstringop-overread warning (bsc#1185472).
- scsi: lpfc: Fix a typo (bsc#1185472).
- scsi: lpfc: Fix kernel-doc formatting issue (bsc#1185472).
- scsi: lpfc: Fix a few incorrectly named functions (bsc#1185472).
- scsi: lpfc: Fix incorrectly documented function<br>lpfc_debugfs_commonxripools_data() (bsc#1185472).<br>- scsi: lpfc: Fix a bunch of misnamed functions (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc misdemeanours<br>(bsc#1185472).<br>- scsi: lpfc: Fix incorrect naming of __lpfc_update_fcf_record()<br>(bsc#1185472).<br>- scsi: lpfc: Fix formatting and misspelling issues (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc issues (bsc#1185472).
- scsi: lpfc: Fix some error codes in debugfs (bsc#1185472).
- commit 9b1fc9d
- blacklist.conf: 6840a150b9da x86/platform/uv: Set section block size for hubless architectures
- commit 69952b3
- scsi: smartpqi: Update version to 1.2.16-012 (bsc#1178089).
- scsi: smartpqi: Correct pqi_sas_smp_handler busy condition<br>(bsc#1178089).<br>- scsi: smartpqi: Correct driver removal with HBA disks<br>(bsc#1178089).<br>- commit b86c984
- x86/microcode: Check for offline CPUs before requesting new<br>microcode (bsc#1114648).<br>- commit 0e9f5a9
- x86/crash: Fix crash_setup_memmap_entries() out-of-bounds access<br>(bsc#1114648).<br>- commit 560878d
- blacklist.conf: cosmetic fix
- commit 6fee0e9
- blacklist.conf: breaks kABI
- commit ee91288
- blacklist.conf: breaks kABI
- commit 505df6e
- USB: CDC-ACM: fix poison/unpoison imbalance (bsc#1184984).
- commit 7e0d30e
- ext4: find old entry again if failed to rename whiteout<br>(bsc#1184742).<br>- commit 78ebad3
- blacklist.conf: Blacklist 163f0ec1df33
- commit 720273a
- struct usbip_device kABI fixup (git-fixes).
- commit 0fd7372
- mm: fix memory_failure() handling of dax-namespace metadata<br>(bsc#1185335).<br>- commit ee11ea2
- isofs: release buffer head before return (bsc#1182613).
- commit 77a0f46
- ext4: fix potential error in ext4_do_update_inode (bsc#1184731).
- commit a3b0213
- Refresh patches.suse/kabi-nvme-fix-fast_io_fail_tmo.patch.
- commit fd1b885
- Refresh patches.kabi/kABI-powerpc-pseries-Add-shutdown-to-vio_driver-and-.patch.<br>Remove unused variables.<br>- commit 5afb3a3
- netfilter: x_tables: Use correct memory barriers (bsc#1184208<br>CVE-2021-29650).<br>- commit 719c6a8
- libnvdimm/label: Return -ENXIO for no slot in __blk_label_update<br>(bsc#1185269).<br>- libnvdimm/namespace: Fix reaping of invalidated<br>block-window-namespace labels (bsc#1185269).<br>- libnvdimm/security: ensure sysfs poll thread woke up and fetch<br>updated attr (FATE#325581 git-fixes).<br>- commit a0e750c
- usbip: synchronize event handler with sysfs code paths<br>(git-fixes).<br>- commit acf38ba
- usbip: stub-dev synchronize sysfs code paths (git-fixes).
- commit 823e744
- usbip: add sysfs_lock to synchronize sysfs code paths<br>(git-fixe).<br>- commit 50a6377
- locking/qrwlock: Fix ordering in queued_write_lock_slowpath() (bsc#1185041).
- commit 10fa764
- rpm/macros.kernel-source: fix KMP failure in %install (bsc#1185244)
- commit 52805ed
- video: hyperv_fb: Fix a double free in hvfb_probe (bsc#1175306, git-fixes).
- commit 6525186
- kabi: nvme: fix fast_io_fail_tmo (bsc#1181161).
- commit 946c302
- nvme-fabrics: reject I/O to offline device (bsc#1181161).
- commit f350de4
- nvme-rdma: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 483532f
- nvme-tcp: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 9cbcf79
- nvme-tcp: avoid request double completion for concurrent<br>nvme_tcp_timeout (bsc#1181161).<br>- commit 5d7efff
- nvme-rdma: avoid request double completion for concurrent<br>nvme_rdma_timeout (bsc#1181161).<br>- commit 874ba7a
- nvme-tcp: avoid repeated request completion (bsc#1181161).
- commit d03513c
- nvme-rdma: avoid repeated request completion (bsc#1181161).
- commit f966c6f
- nvme-tcp: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 0d3fdc1
- nvme-rdma: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 86d008a
- nvme: introduce nvme_sync_io_queues (bsc#1181161).
- commit e825cc9
- nvme-fabrics: allow to queue requests for live queues<br>(bsc#1181161).<br>- commit 34580bf
- nvme-rdma: fix timeout handler (bsc#1181161).
- commit eb26c44
- Rename patches.suse/nvme-tcp-fix-timeout-handler-0475a8dcbce.patch<br>to patches.suse/nvme-tcp-fix-timeout-handler-236187c4ed1.patch  
  Fix commit hash.<br>- commit eab5e6c
- nvme-rdma: serialize controller teardown sequences<br>(bsc#1181161).<br>- commit 3224558
- nvme-tcp: fix timeout handler (bsc#1181161).
- commit ad9445b
- nvme-tcp: serialize controller teardown sequences (bsc#1181161).
- commit 6512d6e
- nvme-fabrics: don't check state NVME_CTRL_NEW for request<br>acceptance (bsc#1181161).<br>- commit 75ddcf5
- nvme-rdma: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 3af85d2
- nvme-tcp: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 05f5595
- nvme: unlink head after removing last namespace (bsc#1181161).
- commit 7c6236e
- nvme: prevent warning triggered by nvme_stop_keep_alive<br>(bsc#1181161).<br>- commit 185de02
- nvme: introduce &quot;/Command Aborted By host&quot;/ status code<br>(bsc#1181161).<br>- commit 60e88a4
- nvme: include admin_q sync with nvme_sync_queues (bsc#1181161).
- commit 7b513f6
- kabi: Fix nvmet error log definitions (bsc#1181161).
- commit a418644
- kabi: Fix breakage in NVMe driver (bsc#1181161).<br>Fix to the changes introduced by patch  
  patches.suse/nvme-make-fabrics-command-run-on-a-separate-request-.patch<br>- commit 43484f2
- nvme: make fabrics command run on a separate request queue<br>(bsc#1181161).<br>- Refresh<br>patches.suse/nvme-fc-set-max_segments-to-lldd-max-value.patch.  
  Context adjustment in refreshed patch.<br>- commit e6ded5f
- nvme: introduce nvme_is_fabrics to check fabrics cmd<br>(bsc#1181161).<br>- commit d199d08
- nvme-pci: Sync queues on reset (bsc#1181161).
- commit de40441
- nvmet: add error log support for fabrics-cmd (bsc#1181161).
- commit 79b998d
- nvmet: add error-log definitions (bsc#1181161).
- commit f930c73
- nvme: add error log page slot definition (bsc#1181161).
- commit c79088e
- nvme: Restart request timers in resetting state (bsc#1181161).
- commit 15193d1
- x86/mm: Fix NX bit clearing issue in kernel_map_pages_in_pgd<br>(bsc#1114648).<br>- commit 7f932b3
- fs: direct-io: fix missing sdio-&gt;boundary (bsc#1184736).
- commit 8d88c09
- reiserfs: update reiserfs_xattrs_initialized() condition<br>(bsc#1184737).<br>- commit 4fcda8e
- ocfs2: fix deadlock between setattr and dio_end_io_write<br>(bsc#1185197).<br>- commit eef2905
- ocfs2: fix a use after free on error (bsc#1184738).
- commit f94368e
- block: recalculate segment count for multi-segment discards<br>correctly (bsc#1184724).<br>- commit 4b986d3
- blk-settings: align max_sectors on &quot;/logical_block_size&quot;/ boundary<br>(bsc#1185195).<br>- commit e5a6cd7
- rpm/kernel-obs-build.spec.in: Include essiv with dm-crypt (boo#1183063).<br>Previously essiv was part of dm-crypt but now it is separate.  
  Include the module in kernel-obs-build when available.  
  Fixes: 7cf5b9e26d87 (&quot;/rpm/kernel-obs-build.spec.in: add dm-crypt for building with cryptsetup&quot;/)<br>- commit fe15b78
- kABI: powerpc/pseries: Add shutdown() to vio_driver and vio_bus<br>(bsc#1184209 ltc#190917).<br>- commit 52ce711
- mmc: sdhci-of-esdhc: set the sd clock divisor value above 3 (git-fixes).
- commit b715781
- iopoll: introduce read_poll_timeout macro (git-fixes).
- commit 0ee886a
- scsi: libsas: docs: Remove notify_ha_event() (git-fixes).
- rtc: pcf2127: fix pcf2127_nvmem_read/write() returns (git-fixes).
- gpio: mvebu: update Armada XP per-CPU comment (git-fixes).
- dpaa_eth: copy timestamp fields to new skb in A-050385 workaround (git-fixes).
- mmc: sdhci-of-esdhc: make sure delay chain locked for HS400 (git-fixes).
- netsec: ignore 'phy-mode' device property on ACPI systems (git-fixes).
- drivers/perf: thunderx2_pmu: Fix memory resource error handling (git-fixes).
- spi: spi-fs | 2021-06-08 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-byos-v20210604/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-byos-v20210604/) |
| SUSE Image SUSE-IU-2021:453-1 | suse | SUSE-IU-2021:453-1 | This image update for google/sles-12-sp5-sap-byos-v20210604 contains the following changes:  
Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bsc1177369.patch to fix bsc#1177369  * tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Some debugs were still in the patch for bsc#1181495.  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]
- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package compat-openssl098 was updated:<br>- Security fixes:  * Integer overflow in CipherUpdate: Incorrect SSLv2 rollback<br>protection [bsc#1182333, CVE-2021-23840]<br>- Null pointer deref in X509_issuer_and_serial_hash()<br>[bsc#1182331, CVE-2021-23841]<br>- Add openssl-CVE-2021-23840.patch openssl-CVE-2021-23841.patch<br>Package corosync was updated:<br>- Fix bsc#1166899, return value of &quot;/corosync-quorumtool -s&quot;/ was not correct  Added: bug-1166899-quorumtool-Fix-exit-status-codes.patch
- totempg: Fix memory leak (bsc#1083030)<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package crmsh was updated:<br>- Update to version 4.1.0+git.1614156984.f4f5e146:  * Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Dev: utils: change default file mod as 644 for str2file function
- Dev: lock: give more specific error message when raise ClaimLockError
- Dev: hb_report: Detect if any ocfs2 partitions exist
- Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688)
- Dev: corosync: change the permission of corosync.conf to 644
- Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869)
- Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- Security fix: [bsc#1186114, CVE-2021-22898]  * TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Allow partial chain verification [jsc#SLE-17954]
- Have intermediate certificates in the trust store be treated<br>as trust-anchors, in the same way as self-signed root CA  
    certificates are. This allows users to verify servers using  
    the intermediate cert only, instead of needing the whole chain.<br>- Set FLAG_TRUSTED_FIRST unconditionally.
- Do not check partial chains with CRL check.
- Add curl-X509_V_FLAG_PARTIAL_CHAIN.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch<br>Package dhcp was updated:<br>- CVE-2021-25217, bsc#1186382, dhcp-CVE-2021-25217.patch: A buffer  overrun in lease file parsing code can be used to exploit a<br>common vulnerability shared by dhcpd and dhclient.<br>Package dracut was updated:<br>- fix(shutdown): add timeout to umount calls (bsc#1178219)  * add 0624-shutdown-guard-against-read-only-run.patch
- add 0625-shutdown-sleep-a-little-if-a-process-was-killed.patch
- add 0626-fix-shutdown-add-timeout-to-umount-calls.patch
- support network setup on infiniband devices (bsc#996146)
- add 0623-net-lib.sh-support-infiniband-network-mac-addresses.patch<br>Package drbd was updated:<br>- bsc#1183970, disconnect when invalid dual primaries  Add patch disconnect-invalid-two-primaries.patch
- bsc#1178388, build error with -Wreturn-type<br>Add patch fix-err-of-wrong-return-type.patch<br>Package fence-agents was updated:<br>- bsc#1180518 [15sp3 FEAT] Product-HA / High Availability Extension:  Add IBM Z LPAR fence agent fence_ibmz to Pacemaker (kvm) (fence-agents)<br>Package gcc10 was updated:<br>- SLE12 only, adjust gcc10-rpmlintrc to ignore bogus  libgcc_s1-gcc10.s390x: E: invalid-license (Badness: 100000)<br>GPL-3.0 WITH GCC-exception-3.1  [bsc#1185337]<br>- Update to GCC 10.3.0 release (63fa67847628e5f358e7e2e7e), git1587
- Disable nvptx offloading for aarch64 again since it doesn't work
- Update to gcc-10 branch head (892024d4af83b258801ff7484), git1574
- Includes GCC 10.3 RC1
- Update to gcc-10 branch head (592388d4f6e8a6adb470428fe), git1450
- Update to gcc-10 branch head (85977f624a34eac309f9d77a5), git1331
- Includes fix for [bsc#1182016]
- The 32bit nvptx libgomp plugin is no longer built, do not attempt<br>to package it.<br>- Remove include-fixed/pthread.h
- Change GCC exception licenses to SPDX format
- Update to gcc-10 branch head (e563687cf9d3d1278f45aaebd), git1030
- Includes fix for firefox build [gcc#97918]
- Do not specify alternate offload compiler location at<br>configure time.<br>- Update README.First-for.SuSE.packagers
- Install offload compilers for gcc10-testresults build
- Enable fortran for offload compilers.
- Add gcc10-amdgcn-llvm-as.patch to fix build of amdgcn offload<br>compiler with llvm11.<br>- Update to gcc-10 branch head (98ba03ffe0b9f37b4916ce6238), git958.
- Includes fix for memcpy miscompilation on aarch64.<br>[bsc#1178624, bsc#1178577]<br>- Fix 32bit libgnat.so link.  [bsc#1178675]
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it<br>stays /%lib. (boo#1029961)<br>- Update to gcc-10 branch head (a78cd759754c92cecbf235ac9b), git872.
- Build complete set of multilibs for arm-none target [bsc#1106014]
- Fixes inadvertant mixture of ARM and Thumb instructions in linker output<br>Package glib2 was updated:<br>- Add glib2-CVE-2021-27218.patch: g_byte_array_new_take takes a  gsize as length but stores in a guint, this patch will refuse if<br>the length is larger than guint. (bsc#1182328,  
  glgo#GNOME/glib!1944)<br>- Add glib2-CVE-2021-27219-add-g_memdup2.patch: g_memdup takes a<br>guint as parameter and sometimes leads into an integer overflow,  
  so add a g_memdup2 function which uses gsize to replace it.  
  (bsc#1182362, glgo#GNOME/glib!1927, glgo#GNOME/glib!1933,  
  glgo#GNOME/glib!1943)<br>Package glibc was updated:<br>- s390-memmove-ifunc-selector-arch13.patch: S390: Also check vector  support in memmove ifunc-selector (bsc#1184034, BZ #27511)
- iconv-redundant-shift.patch: iconv: Accept redundant shift sequences in<br>IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)<br>- iconv-ucs4-loop-bounds.patch: iconv: Fix incorrect UCS4 inner loop<br>bounds (CVE-2020-29562, bsc#1179694, BZ #26923)<br>- printf-long-double-non-normal.patch: x86: Harden printf against<br>non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649)<br>Package google-guest-agent was updated:<br>- Update to version 20210414.00 (bsc#1185848, bsc#1185849)  * start sshd (#106)
- Add systemd-networkd.service restart dependency. (#104)
- Update error message for handleHealthCheckRequest. (#105)
- Update to version 20210223.01 (bsc#1183414, bsc#1183415)
- add a match block to sshd_config for SAs (#99)
- add ipv6 forwarded ip support (#101)
- call restorecon on ssh host keys (#98)
- Include startup and shutdown in preset (#96)
- set metadata URL earlier (#94)
- Fix activation logic of systemd services (bsc#1182793)
- Update to version 20201211.00
- Require snapshot scripts to live under /etc/google/snapshots (#90)
- Adding support for Windows user account password lengths<br>between 15 and 255 characters. (#91)<br>- Adding bkatyl to OWNERS (#92)<br>Package google-guest-configs was updated:<br>- Update to version 20210317.00 (bsc#1183414, bsc#1183415)  * dracut.conf wants spaces around values (#19)
- make the same change for debian (#18)
- change path back for google_nvme_id (#17)
- move google_nvme_id to /usr/bin (#16)
- correct udev rule syntax (#15)
- prune el6 spec (#13)
- Updated udev rules (#11)
- Remove empty %{_sbindir} from %install and %files section
- Remove service files (bsc#1180304)<br>+ google-optimize-local-ssd.service, google-set-multiqueue.service  
    scripts are called from within the guest agent<br>Package google-guest-oslogin was updated:<br>- Update to version 20210429.00 (bsc#1185848, bsc#1185849)  * correct pagetoken in groupsforuser (#59)
- resolve self groups last (#58)
- support empty groups (#57)
- no paginating to find groups (#56)
- clear users vector (#55)
- correct usage of pagetoken (#54)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- call correct function in pwenthelper (#53)
- Update to version 20210108.00
- Update logic in the cache_refresh binary (#52)
- remove old unused workflow files (#49)<br>Package google-osconfig-agent was updated:<br>- Update to version 20210506.00 (bsc#1185848, bsc#1185849)  * Add more os policy assignment examples (#348)
- e2e_tests: enable stable tests for OSPolicies (#347)
- Align start and end task logs (#346)
- ConfigTask: add additional info logs (#345)
- e2e_tests: add validation tests (#344)
- Config Task: make sure agent respects policy mode (#343)
- update
- e2e_tests: readd retries to OSPolicies
- Set minWaitDuration as a string instead of object (#341)
- e2e_tests: Fix a few SUSE tests (#339)
- Remove pre-release flag from config (#340)
- e2e_tests: fixup OSPolicy tests (#338)
- e2e_tests: unlock mutex for CreatePolicies as soon as create finishes (#337)
- e2e_tests: Don't retry failed OSPolicy tests, fix msi test (#336)
- Examples for os policy assignments (#334)
- e2e_tests: increase the deadline for OSPolicy tests and only start after a zone has been secured (#335)
- Fix panic when installing MSI (#332)
- e2e_tests: Add test cases of installing dbe, rpm and msi packages (#333)
- e2e_tests: add more logging
- e2e_tests: (#330)
- e2e_test: Add timouts to OSPolicy tests so we don't wait forever (#329)
- Create top level directories for gcloud and console for os policy assignment examples (#328)
- e2e_tests: Move api from an internal directory (#327)
- Make sure we use the same test name for reruns (#326)
- Add CONFIG_V1 capability (#325)
- e2e_tests: reduce size of instances, use pd-balanced, rerun failed tests once (#324)
- Only report installed packages for dpkg (#322)
- e2e_tests: fix windows package and repository tests (#323)
- Add top level directories for os policy examples (#321)
- e2e_tests: move to using inventory api for inventory reporting (#320)
- e2e_tests: add ExecResource tests (#319)
- ExecResource: make sure we set permissions correctly for downloaded files (#318)
- Config task: only run post check on resources that have already been evaluated (#317)
- e2e_test: reorganize OSPolicy tests to be per Resource type (#316)
- Set custom user agent (#299)
- e2e_tests: check InstanceOSPoliciesCompliance for each test case, add LocalPath FileResource test (#314)
- PackageResource: make sure to run AptUpdate prior to package install (#315)
- Fix bugs/add more logging for OSPolicies (#313)
- Change metadata http client to ignore http proxies (#312)
- e2e_test: add tests for FileResource (#311)
- Add task_type context logging (#310)
- Fix e2e_test typo (#309)
- Fix e2e_tests (#308)
- Disable OSPolicies by default since it is an unreleased feature (#307)
- e2e_tests: Add more OSPolicies package and repo tests (#306)
- Do not enforce repo_gpgcheck in guestpolicies (#305)
- Gather inventory 3-5min after agent start (#303)
- e2e_tests: add OSPolicies tests for package install (#302)
- Add helpful error log if a service account is missing (#304)
- OSPolicies: correct apt repo extension, remove yum/zypper gpgcheck override (#301)
- Update cos library to parse new version of packages file (#300)
- config_task: Rework config step logic (#296)
- e2e_test: enable serial logs in cos to support ReportInventory test (#297)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- ExecResource: fix bug in return code handling (#295)
- Fix ExecResource permissions, add logs to fetcher (#294)
- e2e_tests: Fix ubuntu proposed family (#293)
- e2e_tests: add proposed debian images to head tests (#292)
- Fix exec_resource for config task, add minimal unit test (#291)
- Change util.WriteFile to AtomicWriteFileStream (#289)
- Merge development branch into master (#288)
- Create util.TempFile to work nicely with Windows (#287)
- Fix copy step write (#286)
- Fix error on linux lock (#285)
- Ensure we cleanup on error in AtomicWrite (#284)
- Make writes atomic, add unused &quot;/allowDowngrades&quot;/ option<br>to apt, fix a few recipe issues (#283)<br>- update reviewers (#282)
- update apt package lists before running installs (#281)
- Simplify build tags for COS package (#280)
- Update to version 20210112.00
- Fix builds for ppc and s390x (#274)
- Minor updates to tests and additional debug logging (#272)
- Add Ubuntu 2004 to tests (#271)
- Make sure we stop tickers (#270)
- Drop Windows 1903 and CentOS 6 from tests (#269)
- Pin el6 tests to last published image as it is EOL (#267)
- support cos (#266)
- Update to version 20201117.00 (bsc#1179031, bsc#1179032)
- Ignore Unavailable erros on stream receive (#260)
- Update test Windows images (#259)
- update ReportInventory e2e test regexes (#255)
- Don't return on a windows update error (#254)
- use retryutil for ReportInventory calls (#253)
- add additional debug logging for ReportInventory request payload for e2e tests (#252)
- stop logging instance identity token as part of ReportInventory request and remove<br>feature-flag setting in OSInventoryReporting e2e tests (#251)<br>- complete ExecTask as no-op when the ExecStepConfig doesn't match the OS (#250)
- Add software recipe tests for COS (#249)
- remove feature flag for inventory reporting (#243)
- Force yum to never colorize output (#247)
- Add sleep after Unavailable errors for agentendpoint (#241)
- Ensure we record epoch for rpm packages (#242)
- Make inventory WUAUpdates call spawn a new process,<br>retry on metadata unmarshal error (#239)<br>- add debug logging for report inventory response (#240)
- add initial e2e tests for inventory reporting (#237)
- Report installed packages on COS (#236)<br>Package graphviz was updated:<br>- Added graphviz-out-of-bounds-write.patch to fix CVE-2020-18032  (bsc#1185833)<br>Package graphviz-plugins was updated:<br>- Added graphviz-out-of-bounds-write.patch to fix CVE-2020-18032  (bsc#1185833)<br>Package grub2 was updated:<br>- Fix executable stack in grub-emu (bsc#1181696)  * 0001-emu-fix-executable-stack-marking.patch<br>Package gzip was updated:<br>- fix DFLTCC segfault [bsc#1177047]- added patches<br>fix [https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc](https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc)  
  + gzip-1.10-fix-DFLTCC-segfault.patch<br>- gzip.spec: move %patch10 from the ifarch condition (mistake)
- add gzip-1.10-fix_count_of_lines_to_skip.patch to fix count<br>of lines to skip [bsc#1180713]<br>Package hawk2 was updated:<br>- Update to version 2.6.4:  * Fix wizards ui (bsc#1184274)
- Update to version 2.6.3:
- Remove hawk_invoke and use capture3 instead of runas (bsc#1179999)(CVE-2020-35459)
- Remove unnecessary chmod (bsc#1182166)(CVE-2021-25314)
- Sanitize filename to contains whitelist of alphanumeric (bsc#1182165)<br>Package irqbalance was updated:<br>- Increase size of procinterrupts line readings by factor 32 (bsc#1184592)  A procinterrupts_read_buffer_increase.patch
- Use _fillupdir in spec file to also build against latest distros<br>which could be useful for comparing versions in case we get yet  
  another bug.<br>- not balancing interrupts in Xen guests (bsc#1178477, bsc#1183405)<br>A procinterrupts-check-xen-dyn-event-more-flexible.patch<br>Package kernel-default was updated:<br>- smsc95xx: avoid memory leak in smsc95xx_bind (git-fixes).- commit 1640fc2
- smsc95xx: check return value of smsc95xx_reset (git-fixes).
- commit 00f3661
- net: cxgb4: fix return error value in t4_prep_fw (git-fixes).
- commit 6c63ec6
- net: bcmgenet: use hardware padding of runt frames (git-fixes).
- commit 20467c9
- blacklist.conf: Add fe6bdfc8e1e1 mm: fix oom_kill event handling
- commit 016ac3f
- blacklist.conf: Add e81bf9793b18 mem_cgroup: make sure moving_account, move_lock_task and stat_cpu in the same cacheline
- commit 0632aad
- Don't drop out of segments RST if tcp_be_liberal is set<br>(bsc#1183947).<br>- Avoid potentially erroneos RST drop (bsc#1183947).
- commit 4727a1c
- Update<br>patches.suse/net-fix-race-condition-in-__inet_lookup_established.patch  
  (bsc#1151794 bsc#1180624).<br>- handle also the opposite type of race condition
- commit 7737da1
- powerpc/perf: Fix PMU constraint check for EBB events<br>(bsc#1065729).<br>- powerpc/64s: Fix pte update for kernel memory on radix<br>(bsc#1055117 git-fixes).<br>- powerpc/asm-offsets: GPR14 is not needed either (bsc#1065729).
- powerpc/prom: Mark identical_pvr_fixup as __init (bsc#1065729).
- powerpc/fadump: Mark fadump_calculate_reserve_size as __init<br>(bsc#1065729).<br>- stop_machine: mark helpers __always_inline (bsc#1087405<br>git-fixes).<br>- commit 25e3769
- ibmvnic: queue reset work in system_long_wq (bsc#1152457<br>ltc#174432 git-fixes).<br>- ibmvnic: improve failover sysfs entry (bsc#1043990 ltc#155681<br>git-fixes).<br>- ibmvnic: print adapter state as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: print reset reason as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: clean up the remaining debugfs data structures<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in open function<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in do_reset<br>function (bsc#1065729).<br>- ibmvnic: avoid calling napi_disable() twice (bsc#1065729).
- commit 46cbce7
- KVM: Add proper lockdep assertion in I/O bus unregister<br>(CVE-2020-36312 bsc#1184509).<br>- KVM: Stop looking for coalesced MMIO zones if the bus is<br>destroyed (CVE-2020-36312 bsc#1184509).<br>- KVM: Destroy I/O bus devices on unregister failure _after_<br>sync'ing SRCU (CVE-2020-36312 bsc#1184509).<br>- commit bc1f707
- btrfs: fix qgroup data rsv leak caused by falloc failure<br>(bsc#1185549).<br>- commit e1218ad
- btrfs: track qgroup released data in own variable in<br>insert_prealloc_file_extent (bsc#1185549).<br>- commit bf772b7
- Refresh<br>patches.suse/ibmvnic-Use-skb_frag_address-instead-of-hand-coding-.patch.<br>- Refresh<br>patches.suse/scsi-ibmvfc-Fix-invalid-state-machine-BUG_ON.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Change-wording-of-invalid-pci-reset-log-me.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Correct-function-header-comments-related-t.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-ADISC-handling-that-never-frees-nodes.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-FLOGI-failure-due-to-accessing-a-freed.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-PLOGI-ACC-to-be-transmit-after-REG_LOG.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-crash-caused-by-switch-reboot.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-dropped-FLOGI-during-pt2pt-discovery-r.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-incorrect-dbde-assignment-when-buildin.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-lpfc_els_retry-possible-null-pointer-d.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-nodeinfo-debugfs-output.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-null-pointer-dereference-in-lpfc_prep_.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-connection-does-not-recover-afte.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-state-transition-causing-rmmod-h.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-reftag-generation-sizing-errors.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-stale-node-accesses-on-stale-RRQ-reque.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-status-returned-in-lpfc_els_retry-erro.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-unnecessary-null-check-in-lpfc_release.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-use-after-free-in-lpfc_els_free_iocb.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-vport-indices-in-lpfc_find_vport_by_vp.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Reduce-LOG_TRACE_EVENT-logging-for-vports.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-copyrights-for-12.8.0.7-and-12.8.0..patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-lpfc-version-to-12.8.0.8.patch.<br>- commit d057148
- scsi: qla2xxx: Reserve extra IRQ vectors (bsc#1185491).
- scsi: qla2xxx: Reuse existing error handling path (bsc#1185491).
- scsi: qla2xxx: Remove unneeded if-null-free check (bsc#1185491).
- scsi: qla2xxx: Update version to 10.02.00.106-k (bsc#1185491).
- scsi: qla2xxx: Do logout even if fabric scan retries got<br>exhausted (bsc#1185491).<br>- scsi: qla2xxx: Update default AER debug mask (bsc#1185491).
- scsi: qla2xxx: Fix mailbox recovery during PCIe error<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix crash in PCIe error handling (bsc#1185491).
- scsi: qla2xxx: Fix RISC RESET completion polling (bsc#1185491).
- scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix use after free in bsg (bsc#1185491).
- scsi: qla2xxx: Consolidate zio threshold setting for both FCP &amp;<br>NVMe (bsc#1185491).<br>- scsi: qla2xxx: Fix stuck session (bsc#1185491).
- scsi: qla2xxx: Add H:C:T info in the log message for fc ports<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix IOPS drop seen in some adapters<br>(bsc#1185491).<br>- scsi: qla2xxx: Check kzalloc() return value (bsc#1185491).
- scsi: qla2xxx: Always check the return value of<br>qla24xx_get_isp_stats() (bsc#1185491).<br>- scsi: qla2xxx: Simplify qla8044_minidump_process_control()<br>(bsc#1185491).<br>- scsi: qla2xxx: Suppress Coverity complaints about dseg_r*<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix endianness annotations (bsc#1185491).
- scsi: qla2xxx: Constify struct qla_tgt_func_tmpl (bsc#1185491).
- scsi: qla2xxx: Use dma_pool_zalloc() (bsc#1185491).
- scsi: qla2xxx: Fix a couple of misdocumented functions<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix incorrectly named function<br>qla8044_check_temp() (bsc#1185491).<br>- scsi: qla2xxx: Fix a couple of misnamed functions (bsc#1185491).
- scsi: qla2xxx: Fix some incorrect formatting/spelling issues<br>(bsc#1185491).<br>- scsi: qla2xxx: Replace __qla2x00_marker()'s missing underscores<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix broken #endif placement (bsc#1185491).
- scsi: qla2xxx: Simplify if statement (bsc#1185491).
- scsi: qla2xxx: Simplify the calculation of variables<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix some memory corruption (bsc#1185491).
- scsi: qla2xxx: Remove redundant NULL check (bsc#1185491).
- scsi: qla2xxx: Remove unnecessary NULL check (bsc#1185491).
- scsi: qla2xxx: Assign boolean values to a bool variable<br>(bsc#1185491).<br>- scsi: qla2xxx: fc_remote_port_chkready() returns a SCSI result<br>value (bsc#1185491).<br>- scsi: qla2xxx: Update version to 10.02.00.105-k (bsc#1185491).
- scsi: qla2xxx: Enable NVMe CONF (BIT_7) when enabling SLER<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix mailbox Ch erroneous error (bsc#1185491).
- scsi: qla2xxx: Wait for ABTS response on I/O timeouts for NVMe<br>(bsc#1185491).<br>- scsi: qla2xxx: Move some messages from debug to normal log level<br>(bsc#1185491).<br>- scsi: qla2xxx: Add error counters to debugfs node (bsc#1185491).
- scsi: qla2xxx: Implementation to get and manage host, target<br>stats and initiator port (bsc#1185491).<br>- commit 9add63f
- blacklist.conf: kthread: Fixes debugging of the life cycle of work struct.<br>Broken for ages. Disabled in our configuration.<br>- commit 4600ed3
- scsi: lpfc: Fix DMA virtual address ptr assignment in bsg<br>(bsc#1185365).<br>- scsi: lpfc: Fix illegal memory access on Abort IOCBs<br>(bsc#1183203).<br>- scsi: lpfc: Copyright updates for 12.8.0.9 patches<br>(bsc#1185472).<br>- scsi: lpfc: Update lpfc version to 12.8.0.9 (bsc#1185472).
- scsi: lpfc: Eliminate use of LPFC_DRIVER_NAME in lpfc_attr.c<br>(bsc#1185472).<br>- scsi: lpfc: Standardize discovery object logging format<br>(bsc#1185472).<br>- scsi: lpfc: Fix various trivial errors in comments and log<br>messages (bsc#1185472).<br>- scsi: lpfc: Remove unsupported mbox PORT_CAPABILITIES logic<br>(bsc#1185472).<br>- scsi: lpfc: Fix lpfc_hdw_queue attribute being ignored<br>(bsc#1185472).<br>- scsi: lpfc: Fix missing FDMI registrations after Mgmt Svc login<br>(bsc#1185472).<br>- scsi: lpfc: Fix silent memory allocation failure in<br>lpfc_sli4_bsg_link_diag_test() (bsc#1185472).<br>- scsi: lpfc: Fix use-after-free on unused nodes after port swap<br>(bsc#1185472).<br>- scsi: lpfc: Fix error handling for mailboxes completed in<br>MBX_POLL mode (bsc#1185472).<br>- scsi: lpfc: Fix lack of device removal on port swaps with PRLIs<br>(bsc#1185472).<br>- scsi: lpfc: Fix NMI crash during rmmod due to circular hbalock<br>dependency (bsc#1185472).<br>- scsi: lpfc: Fix reference counting errors in lpfc_cmpl_els_rsp()<br>(bsc#1185472).<br>- scsi: lpfc: Fix crash when a REG_RPI mailbox fails triggering<br>a LOGO response (bsc#1185472).<br>- scsi: lpfc: Fix rmmod crash due to bad ring pointers to<br>abort_iotag (bsc#1185472).<br>- scsi: lpfc: Fix gcc -Wstringop-overread warning (bsc#1185472).
- scsi: lpfc: Fix a typo (bsc#1185472).
- scsi: lpfc: Fix kernel-doc formatting issue (bsc#1185472).
- scsi: lpfc: Fix a few incorrectly named functions (bsc#1185472).
- scsi: lpfc: Fix incorrectly documented function<br>lpfc_debugfs_commonxripools_data() (bsc#1185472).<br>- scsi: lpfc: Fix a bunch of misnamed functions (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc misdemeanours<br>(bsc#1185472).<br>- scsi: lpfc: Fix incorrect naming of __lpfc_update_fcf_record()<br>(bsc#1185472).<br>- scsi: lpfc: Fix formatting and misspelling issues (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc issues (bsc#1185472).
- scsi: lpfc: Fix some error codes in debugfs (bsc#1185472).
- commit 9b1fc9d
- blacklist.conf: 6840a150b9da x86/platform/uv: Set section block size for hubless architectures
- commit 69952b3
- scsi: smartpqi: Update version to 1.2.16-012 (bsc#1178089).
- scsi: smartpqi: Correct pqi_sas_smp_handler busy condition<br>(bsc#1178089).<br>- scsi: smartpqi: Correct driver removal with HBA disks<br>(bsc#1178089).<br>- commit b86c984
- x86/microcode: Check for offline CPUs before requesting new<br>microcode (bsc#1114648).<br>- commit 0e9f5a9
- x86/crash: Fix crash_setup_memmap_entries() out-of-bounds access<br>(bsc#1114648).<br>- commit 560878d
- blacklist.conf: cosmetic fix
- commit 6fee0e9
- blacklist.conf: breaks kABI
- commit ee91288
- blacklist.conf: breaks kABI
- commit 505df6e
- USB: CDC-ACM: fix poison/unpoison imbalance (bsc#1184984).
- commit 7e0d30e
- ext4: find old entry again if failed to rename whiteout<br>(bsc#1184742).<br>- commit 78ebad3
- blacklist.conf: Blacklist 163f0ec1df33
- commit 720273a
- struct usbip_device kABI fixup (git-fixes).
- commit 0fd7372
- mm: fix memory_failure() handling of dax-namespace metadata<br>(bsc#1185335).<br>- commit ee11ea2
- isofs: release buffer head before return (bsc#1182613).
- commit 77a0f46
- ext4: fix potential error in ext4_do_update_inode (bsc#1184731).
- commit a3b0213
- Refresh patches.suse/kabi-nvme-fix-fast_io_fail_tmo.patch.
- commit fd1b885
- Refresh patches.kabi/kABI-powerpc-pseries-Add-shutdown-to-vio_driver-and-.patch.<br>Remove unused variables.<br>- commit 5afb3a3
- netfilter: x_tables: Use correct memory barriers (bsc#1184208<br>CVE-2021-29650).<br>- commit 719c6a8
- libnvdimm/label: Return -ENXIO for no slot in __blk_label_update<br>(bsc#1185269).<br>- libnvdimm/namespace: Fix reaping of invalidated<br>block-window-namespace labels (bsc#1185269).<br>- libnvdimm/security: ensure sysfs poll thread woke up and fetch<br>updated attr (FATE#325581 git-fixes).<br>- commit a0e750c
- usbip: synchronize event handler with sysfs code paths<br>(git-fixes).<br>- commit acf38ba
- usbip: stub-dev synchronize sysfs code paths (git-fixes).
- commit 823e744
- usbip: add sysfs_lock to synchronize sysfs code paths<br>(git-fixe).<br>- commit 50a6377
- locking/qrwlock: Fix ordering in queued_write_lock_slowpath() (bsc#1185041).
- commit 10fa764
- rpm/macros.kernel-source: fix KMP failure in %install (bsc#1185244)
- commit 52805ed
- video: hyperv_fb: Fix a double free in hvfb_probe (bsc#1175306, git-fixes).
- commit 6525186
- kabi: nvme: fix fast_io_fail_tmo (bsc#1181161).
- commit 946c302
- nvme-fabrics: reject I/O to offline device (bsc#1181161).
- commit f350de4
- nvme-rdma: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 483532f
- nvme-tcp: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 9cbcf79
- nvme-tcp: avoid request double completion for concurrent<br>nvme_tcp_timeout (bsc#1181161).<br>- commit 5d7efff
- nvme-rdma: avoid request double completion for concurrent<br>nvme_rdma_timeout (bsc#1181161).<br>- commit 874ba7a
- nvme-tcp: avoid repeated request completion (bsc#1181161).
- commit d03513c
- nvme-rdma: avoid repeated request completion (bsc#1181161).
- commit f966c6f
- nvme-tcp: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 0d3fdc1
- nvme-rdma: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 86d008a
- nvme: introduce nvme_sync_io_queues (bsc#1181161).
- commit e825cc9
- nvme-fabrics: allow to queue requests for live queues<br>(bsc#1181161).<br>- commit 34580bf
- nvme-rdma: fix timeout handler (bsc#1181161).
- commit eb26c44
- Rename patches.suse/nvme-tcp-fix-timeout-handler-0475a8dcbce.patch<br>to patches.suse/nvme-tcp-fix-timeout-handler-236187c4ed1.patch  
  Fix commit hash.<br>- commit eab5e6c
- nvme-rdma: serialize controller teardown sequences<br>(bsc#1181161).<br>- commit 3224558
- nvme-tcp: fix timeout handler (bsc#1181161).
- commit ad9445b
- nvme-tcp: serialize controller teardown sequences (bsc#1181161).
- commit 6512d6e
- nvme-fabrics: don't check state NVME_CTRL_NEW for request<br>acceptance (bsc#1181161).<br>- commit 75ddcf5
- nvme-rdma: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 3af85d2
- nvme-tcp: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 05f5595
- nvme: unlink head after removing last namespace (bsc#1181161).
- commit 7c6236e
- nvme: prevent warning triggered by nvme_stop_keep_alive<br>(bsc#1181161).<br>- commit 185de02
- nvme: introduce &quot;/Command Aborted By host&quot;/ status code<br>(bsc#1181161).<br>- commit 60e88a4
- nvme: include admin_q sync with nvme_sync_queues (bsc#1181161).
- commit 7b513f6
- kabi: Fix nvmet error log definitions (bsc#1181161).
- commit a418644
- kabi: Fix breakage in NVMe driver (bsc#1181161).<br>Fix to the changes introduced by patch  
  patches.suse/nvme-make-fabrics-command-run-on-a-separate-request-.patch<br>- commit 43484f2
- nvme: make fabrics command run on a separate request queue<br>(bsc#1181161).<br>- R | 2021-06-08 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-sap-byos-v20210604/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-sap-byos-v20210604/) |
| SUSE Image SUSE-IU-2021:464-1 | suse | SUSE-IU-2021:464-1 | This image update for google/sles-12-sp5-sap-v20210604 contains the following changes:  
Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bsc1177369.patch to fix bsc#1177369  * tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Some debugs were still in the patch for bsc#1181495.  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]
- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package cloud-regionsrv-client was updated:<br>- Update to version 9.1.5 (bsc#1182779, bsc#1185234, bsc#1185198)  + Another startup process may run zypper before the registration process<br>if zypper is still running we cannot get the lock and as such  
    the installed products cannot be determined. Wait for the lock to be  
    released for up to 30 seconds.  
  + On any error durring product list generation return a list to avoid  
    a traceback by trying to iterate over None<br>Package compat-openssl098 was updated:<br>- Security fixes:  * Integer overflow in CipherUpdate: Incorrect SSLv2 rollback<br>protection [bsc#1182333, CVE-2021-23840]<br>- Null pointer deref in X509_issuer_and_serial_hash()<br>[bsc#1182331, CVE-2021-23841]<br>- Add openssl-CVE-2021-23840.patch openssl-CVE-2021-23841.patch<br>Package corosync was updated:<br>- Fix bsc#1166899, return value of &quot;/corosync-quorumtool -s&quot;/ was not correct  Added: bug-1166899-quorumtool-Fix-exit-status-codes.patch
- totempg: Fix memory leak (bsc#1083030)<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package crmsh was updated:<br>- Update to version 4.1.0+git.1614156984.f4f5e146:  * Fix: hb_report: walk through hb_report process under hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459, bsc#1179999; CVE-2021-3020, bsc#1180571)
- Dev: utils: change default file mod as 644 for str2file function
- Dev: lock: give more specific error message when raise ClaimLockError
- Dev: hb_report: Detect if any ocfs2 partitions exist
- Fix: hb_report: run lsof with specific ocfs2 device(bsc#1180688)
- Dev: corosync: change the permission of corosync.conf to 644
- Fix: bootstrap: Use class Watchdog to simplify watchdog config(bsc#1154927, bsc#1178869)
- Fix: bootstrap: make sure sbd device UUID was the same between nodes(bsc#1178454)<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- Security fix: [bsc#1186114, CVE-2021-22898]  * TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Allow partial chain verification [jsc#SLE-17954]
- Have intermediate certificates in the trust store be treated<br>as trust-anchors, in the same way as self-signed root CA  
    certificates are. This allows users to verify servers using  
    the intermediate cert only, instead of needing the whole chain.<br>- Set FLAG_TRUSTED_FIRST unconditionally.
- Do not check partial chains with CRL check.
- Add curl-X509_V_FLAG_PARTIAL_CHAIN.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch<br>Package dhcp was updated:<br>- CVE-2021-25217, bsc#1186382, dhcp-CVE-2021-25217.patch: A buffer  overrun in lease file parsing code can be used to exploit a<br>common vulnerability shared by dhcpd and dhclient.<br>Package dracut was updated:<br>- fix(shutdown): add timeout to umount calls (bsc#1178219)  * add 0624-shutdown-guard-against-read-only-run.patch
- add 0625-shutdown-sleep-a-little-if-a-process-was-killed.patch
- add 0626-fix-shutdown-add-timeout-to-umount-calls.patch
- support network setup on infiniband devices (bsc#996146)
- add 0623-net-lib.sh-support-infiniband-network-mac-addresses.patch<br>Package drbd was updated:<br>- bsc#1183970, disconnect when invalid dual primaries  Add patch disconnect-invalid-two-primaries.patch
- bsc#1178388, build error with -Wreturn-type<br>Add patch fix-err-of-wrong-return-type.patch<br>Package fence-agents was updated:<br>- bsc#1180518 [15sp3 FEAT] Product-HA / High Availability Extension:  Add IBM Z LPAR fence agent fence_ibmz to Pacemaker (kvm) (fence-agents)<br>Package gcc10 was updated:<br>- SLE12 only, adjust gcc10-rpmlintrc to ignore bogus  libgcc_s1-gcc10.s390x: E: invalid-license (Badness: 100000)<br>GPL-3.0 WITH GCC-exception-3.1  [bsc#1185337]<br>- Update to GCC 10.3.0 release (63fa67847628e5f358e7e2e7e), git1587
- Disable nvptx offloading for aarch64 again since it doesn't work
- Update to gcc-10 branch head (892024d4af83b258801ff7484), git1574
- Includes GCC 10.3 RC1
- Update to gcc-10 branch head (592388d4f6e8a6adb470428fe), git1450
- Update to gcc-10 branch head (85977f624a34eac309f9d77a5), git1331
- Includes fix for [bsc#1182016]
- The 32bit nvptx libgomp plugin is no longer built, do not attempt<br>to package it.<br>- Remove include-fixed/pthread.h
- Change GCC exception licenses to SPDX format
- Update to gcc-10 branch head (e563687cf9d3d1278f45aaebd), git1030
- Includes fix for firefox build [gcc#97918]
- Do not specify alternate offload compiler location at<br>configure time.<br>- Update README.First-for.SuSE.packagers
- Install offload compilers for gcc10-testresults build
- Enable fortran for offload compilers.
- Add gcc10-amdgcn-llvm-as.patch to fix build of amdgcn offload<br>compiler with llvm11.<br>- Update to gcc-10 branch head (98ba03ffe0b9f37b4916ce6238), git958.
- Includes fix for memcpy miscompilation on aarch64.<br>[bsc#1178624, bsc#1178577]<br>- Fix 32bit libgnat.so link.  [bsc#1178675]
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it<br>stays /%lib. (boo#1029961)<br>- Update to gcc-10 branch head (a78cd759754c92cecbf235ac9b), git872.
- Build complete set of multilibs for arm-none target [bsc#1106014]
- Fixes inadvertant mixture of ARM and Thumb instructions in linker output<br>Package glib2 was updated:<br>- Add glib2-CVE-2021-27218.patch: g_byte_array_new_take takes a  gsize as length but stores in a guint, this patch will refuse if<br>the length is larger than guint. (bsc#1182328,  
  glgo#GNOME/glib!1944)<br>- Add glib2-CVE-2021-27219-add-g_memdup2.patch: g_memdup takes a<br>guint as parameter and sometimes leads into an integer overflow,  
  so add a g_memdup2 function which uses gsize to replace it.  
  (bsc#1182362, glgo#GNOME/glib!1927, glgo#GNOME/glib!1933,  
  glgo#GNOME/glib!1943)<br>Package glibc was updated:<br>- s390-memmove-ifunc-selector-arch13.patch: S390: Also check vector  support in memmove ifunc-selector (bsc#1184034, BZ #27511)
- iconv-redundant-shift.patch: iconv: Accept redundant shift sequences in<br>IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)<br>- iconv-ucs4-loop-bounds.patch: iconv: Fix incorrect UCS4 inner loop<br>bounds (CVE-2020-29562, bsc#1179694, BZ #26923)<br>- printf-long-double-non-normal.patch: x86: Harden printf against<br>non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649)<br>Package google-guest-agent was updated:<br>- Update to version 20210414.00 (bsc#1185848, bsc#1185849)  * start sshd (#106)
- Add systemd-networkd.service restart dependency. (#104)
- Update error message for handleHealthCheckRequest. (#105)
- Update to version 20210223.01 (bsc#1183414, bsc#1183415)
- add a match block to sshd_config for SAs (#99)
- add ipv6 forwarded ip support (#101)
- call restorecon on ssh host keys (#98)
- Include startup and shutdown in preset (#96)
- set metadata URL earlier (#94)
- Fix activation logic of systemd services (bsc#1182793)
- Update to version 20201211.00
- Require snapshot scripts to live under /etc/google/snapshots (#90)
- Adding support for Windows user account password lengths<br>between 15 and 255 characters. (#91)<br>- Adding bkatyl to OWNERS (#92)<br>Package google-guest-configs was updated:<br>- Update to version 20210317.00 (bsc#1183414, bsc#1183415)  * dracut.conf wants spaces around values (#19)
- make the same change for debian (#18)
- change path back for google_nvme_id (#17)
- move google_nvme_id to /usr/bin (#16)
- correct udev rule syntax (#15)
- prune el6 spec (#13)
- Updated udev rules (#11)
- Remove empty %{_sbindir} from %install and %files section
- Remove service files (bsc#1180304)<br>+ google-optimize-local-ssd.service, google-set-multiqueue.service  
    scripts are called from within the guest agent<br>Package google-guest-oslogin was updated:<br>- Update to version 20210429.00 (bsc#1185848, bsc#1185849)  * correct pagetoken in groupsforuser (#59)
- resolve self groups last (#58)
- support empty groups (#57)
- no paginating to find groups (#56)
- clear users vector (#55)
- correct usage of pagetoken (#54)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- call correct function in pwenthelper (#53)
- Update to version 20210108.00
- Update logic in the cache_refresh binary (#52)
- remove old unused workflow files (#49)<br>Package google-osconfig-agent was updated:<br>- Update to version 20210506.00 (bsc#1185848, bsc#1185849)  * Add more os policy assignment examples (#348)
- e2e_tests: enable stable tests for OSPolicies (#347)
- Align start and end task logs (#346)
- ConfigTask: add additional info logs (#345)
- e2e_tests: add validation tests (#344)
- Config Task: make sure agent respects policy mode (#343)
- update
- e2e_tests: readd retries to OSPolicies
- Set minWaitDuration as a string instead of object (#341)
- e2e_tests: Fix a few SUSE tests (#339)
- Remove pre-release flag from config (#340)
- e2e_tests: fixup OSPolicy tests (#338)
- e2e_tests: unlock mutex for CreatePolicies as soon as create finishes (#337)
- e2e_tests: Don't retry failed OSPolicy tests, fix msi test (#336)
- Examples for os policy assignments (#334)
- e2e_tests: increase the deadline for OSPolicy tests and only start after a zone has been secured (#335)
- Fix panic when installing MSI (#332)
- e2e_tests: Add test cases of installing dbe, rpm and msi packages (#333)
- e2e_tests: add more logging
- e2e_tests: (#330)
- e2e_test: Add timouts to OSPolicy tests so we don't wait forever (#329)
- Create top level directories for gcloud and console for os policy assignment examples (#328)
- e2e_tests: Move api from an internal directory (#327)
- Make sure we use the same test name for reruns (#326)
- Add CONFIG_V1 capability (#325)
- e2e_tests: reduce size of instances, use pd-balanced, rerun failed tests once (#324)
- Only report installed packages for dpkg (#322)
- e2e_tests: fix windows package and repository tests (#323)
- Add top level directories for os policy examples (#321)
- e2e_tests: move to using inventory api for inventory reporting (#320)
- e2e_tests: add ExecResource tests (#319)
- ExecResource: make sure we set permissions correctly for downloaded files (#318)
- Config task: only run post check on resources that have already been evaluated (#317)
- e2e_test: reorganize OSPolicy tests to be per Resource type (#316)
- Set custom user agent (#299)
- e2e_tests: check InstanceOSPoliciesCompliance for each test case, add LocalPath FileResource test (#314)
- PackageResource: make sure to run AptUpdate prior to package install (#315)
- Fix bugs/add more logging for OSPolicies (#313)
- Change metadata http client to ignore http proxies (#312)
- e2e_test: add tests for FileResource (#311)
- Add task_type context logging (#310)
- Fix e2e_test typo (#309)
- Fix e2e_tests (#308)
- Disable OSPolicies by default since it is an unreleased feature (#307)
- e2e_tests: Add more OSPolicies package and repo tests (#306)
- Do not enforce repo_gpgcheck in guestpolicies (#305)
- Gather inventory 3-5min after agent start (#303)
- e2e_tests: add OSPolicies tests for package install (#302)
- Add helpful error log if a service account is missing (#304)
- OSPolicies: correct apt repo extension, remove yum/zypper gpgcheck override (#301)
- Update cos library to parse new version of packages file (#300)
- config_task: Rework config step logic (#296)
- e2e_test: enable serial logs in cos to support ReportInventory test (#297)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- ExecResource: fix bug in return code handling (#295)
- Fix ExecResource permissions, add logs to fetcher (#294)
- e2e_tests: Fix ubuntu proposed family (#293)
- e2e_tests: add proposed debian images to head tests (#292)
- Fix exec_resource for config task, add minimal unit test (#291)
- Change util.WriteFile to AtomicWriteFileStream (#289)
- Merge development branch into master (#288)
- Create util.TempFile to work nicely with Windows (#287)
- Fix copy step write (#286)
- Fix error on linux lock (#285)
- Ensure we cleanup on error in AtomicWrite (#284)
- Make writes atomic, add unused &quot;/allowDowngrades&quot;/ option<br>to apt, fix a few recipe issues (#283)<br>- update reviewers (#282)
- update apt package lists before running installs (#281)
- Simplify build tags for COS package (#280)
- Update to version 20210112.00
- Fix builds for ppc and s390x (#274)
- Minor updates to tests and additional debug logging (#272)
- Add Ubuntu 2004 to tests (#271)
- Make sure we stop tickers (#270)
- Drop Windows 1903 and CentOS 6 from tests (#269)
- Pin el6 tests to last published image as it is EOL (#267)
- support cos (#266)
- Update to version 20201117.00 (bsc#1179031, bsc#1179032)
- Ignore Unavailable erros on stream receive (#260)
- Update test Windows images (#259)
- update ReportInventory e2e test regexes (#255)
- Don't return on a windows update error (#254)
- use retryutil for ReportInventory calls (#253)
- add additional debug logging for ReportInventory request payload for e2e tests (#252)
- stop logging instance identity token as part of ReportInventory request and remove<br>feature-flag setting in OSInventoryReporting e2e tests (#251)<br>- complete ExecTask as no-op when the ExecStepConfig doesn't match the OS (#250)
- Add software recipe tests for COS (#249)
- remove feature flag for inventory reporting (#243)
- Force yum to never colorize output (#247)
- Add sleep after Unavailable errors for agentendpoint (#241)
- Ensure we record epoch for rpm packages (#242)
- Make inventory WUAUpdates call spawn a new process,<br>retry on metadata unmarshal error (#239)<br>- add debug logging for report inventory response (#240)
- add initial e2e tests for inventory reporting (#237)
- Report installed packages on COS (#236)<br>Package graphviz was updated:<br>- Added graphviz-out-of-bounds-write.patch to fix CVE-2020-18032  (bsc#1185833)<br>Package graphviz-plugins was updated:<br>- Added graphviz-out-of-bounds-write.patch to fix CVE-2020-18032  (bsc#1185833)<br>Package grub2 was updated:<br>- Fix executable stack in grub-emu (bsc#1181696)  * 0001-emu-fix-executable-stack-marking.patch<br>Package gzip was updated:<br>- fix DFLTCC segfault [bsc#1177047]- added patches<br>fix [https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc](https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc)  
  + gzip-1.10-fix-DFLTCC-segfault.patch<br>- gzip.spec: move %patch10 from the ifarch condition (mistake)
- add gzip-1.10-fix_count_of_lines_to_skip.patch to fix count<br>of lines to skip [bsc#1180713]<br>Package hawk2 was updated:<br>- Update to version 2.6.4:  * Fix wizards ui (bsc#1184274)
- Update to version 2.6.3:
- Remove hawk_invoke and use capture3 instead of runas (bsc#1179999)(CVE-2020-35459)
- Remove unnecessary chmod (bsc#1182166)(CVE-2021-25314)
- Sanitize filename to contains whitelist of alphanumeric (bsc#1182165)<br>Package irqbalance was updated:<br>- Increase size of procinterrupts line readings by factor 32 (bsc#1184592)  A procinterrupts_read_buffer_increase.patch
- Use _fillupdir in spec file to also build against latest distros<br>which could be useful for comparing versions in case we get yet  
  another bug.<br>- not balancing interrupts in Xen guests (bsc#1178477, bsc#1183405)<br>A procinterrupts-check-xen-dyn-event-more-flexible.patch<br>Package kernel-default was updated:<br>- smsc95xx: avoid memory leak in smsc95xx_bind (git-fixes).- commit 1640fc2
- smsc95xx: check return value of smsc95xx_reset (git-fixes).
- commit 00f3661
- net: cxgb4: fix return error value in t4_prep_fw (git-fixes).
- commit 6c63ec6
- net: bcmgenet: use hardware padding of runt frames (git-fixes).
- commit 20467c9
- blacklist.conf: Add fe6bdfc8e1e1 mm: fix oom_kill event handling
- commit 016ac3f
- blacklist.conf: Add e81bf9793b18 mem_cgroup: make sure moving_account, move_lock_task and stat_cpu in the same cacheline
- commit 0632aad
- Don't drop out of segments RST if tcp_be_liberal is set<br>(bsc#1183947).<br>- Avoid potentially erroneos RST drop (bsc#1183947).
- commit 4727a1c
- Update<br>patches.suse/net-fix-race-condition-in-__inet_lookup_established.patch  
  (bsc#1151794 bsc#1180624).<br>- handle also the opposite type of race condition
- commit 7737da1
- powerpc/perf: Fix PMU constraint check for EBB events<br>(bsc#1065729).<br>- powerpc/64s: Fix pte update for kernel memory on radix<br>(bsc#1055117 git-fixes).<br>- powerpc/asm-offsets: GPR14 is not needed either (bsc#1065729).
- powerpc/prom: Mark identical_pvr_fixup as __init (bsc#1065729).
- powerpc/fadump: Mark fadump_calculate_reserve_size as __init<br>(bsc#1065729).<br>- stop_machine: mark helpers __always_inline (bsc#1087405<br>git-fixes).<br>- commit 25e3769
- ibmvnic: queue reset work in system_long_wq (bsc#1152457<br>ltc#174432 git-fixes).<br>- ibmvnic: improve failover sysfs entry (bsc#1043990 ltc#155681<br>git-fixes).<br>- ibmvnic: print adapter state as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: print reset reason as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: clean up the remaining debugfs data structures<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in open function<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in do_reset<br>function (bsc#1065729).<br>- ibmvnic: avoid calling napi_disable() twice (bsc#1065729).
- commit 46cbce7
- KVM: Add proper lockdep assertion in I/O bus unregister<br>(CVE-2020-36312 bsc#1184509).<br>- KVM: Stop looking for coalesced MMIO zones if the bus is<br>destroyed (CVE-2020-36312 bsc#1184509).<br>- KVM: Destroy I/O bus devices on unregister failure _after_<br>sync'ing SRCU (CVE-2020-36312 bsc#1184509).<br>- commit bc1f707
- btrfs: fix qgroup data rsv leak caused by falloc failure<br>(bsc#1185549).<br>- commit e1218ad
- btrfs: track qgroup released data in own variable in<br>insert_prealloc_file_extent (bsc#1185549).<br>- commit bf772b7
- Refresh<br>patches.suse/ibmvnic-Use-skb_frag_address-instead-of-hand-coding-.patch.<br>- Refresh<br>patches.suse/scsi-ibmvfc-Fix-invalid-state-machine-BUG_ON.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Change-wording-of-invalid-pci-reset-log-me.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Correct-function-header-comments-related-t.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-ADISC-handling-that-never-frees-nodes.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-FLOGI-failure-due-to-accessing-a-freed.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-PLOGI-ACC-to-be-transmit-after-REG_LOG.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-crash-caused-by-switch-reboot.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-dropped-FLOGI-during-pt2pt-discovery-r.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-incorrect-dbde-assignment-when-buildin.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-lpfc_els_retry-possible-null-pointer-d.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-nodeinfo-debugfs-output.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-null-pointer-dereference-in-lpfc_prep_.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-connection-does-not-recover-afte.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-state-transition-causing-rmmod-h.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-reftag-generation-sizing-errors.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-stale-node-accesses-on-stale-RRQ-reque.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-status-returned-in-lpfc_els_retry-erro.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-unnecessary-null-check-in-lpfc_release.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-use-after-free-in-lpfc_els_free_iocb.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-vport-indices-in-lpfc_find_vport_by_vp.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Reduce-LOG_TRACE_EVENT-logging-for-vports.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-copyrights-for-12.8.0.7-and-12.8.0..patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-lpfc-version-to-12.8.0.8.patch.<br>- commit d057148
- scsi: qla2xxx: Reserve extra IRQ vectors (bsc#1185491).
- scsi: qla2xxx: Reuse existing error handling path (bsc#1185491).
- scsi: qla2xxx: Remove unneeded if-null-free check (bsc#1185491).
- scsi: qla2xxx: Update version to 10.02.00.106-k (bsc#1185491).
- scsi: qla2xxx: Do logout even if fabric scan retries got<br>exhausted (bsc#1185491).<br>- scsi: qla2xxx: Update default AER debug mask (bsc#1185491).
- scsi: qla2xxx: Fix mailbox recovery during PCIe error<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix crash in PCIe error handling (bsc#1185491).
- scsi: qla2xxx: Fix RISC RESET completion polling (bsc#1185491).
- scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix use after free in bsg (bsc#1185491).
- scsi: qla2xxx: Consolidate zio threshold setting for both FCP &amp;<br>NVMe (bsc#1185491).<br>- scsi: qla2xxx: Fix stuck session (bsc#1185491).
- scsi: qla2xxx: Add H:C:T info in the log message for fc ports<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix IOPS drop seen in some adapters<br>(bsc#1185491).<br>- scsi: qla2xxx: Check kzalloc() return value (bsc#1185491).
- scsi: qla2xxx: Always check the return value of<br>qla24xx_get_isp_stats() (bsc#1185491).<br>- scsi: qla2xxx: Simplify qla8044_minidump_process_control()<br>(bsc#1185491).<br>- scsi: qla2xxx: Suppress Coverity complaints about dseg_r*<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix endianness annotations (bsc#1185491).
- scsi: qla2xxx: Constify struct qla_tgt_func_tmpl (bsc#1185491).
- scsi: qla2xxx: Use dma_pool_zalloc() (bsc#1185491).
- scsi: qla2xxx: Fix a couple of misdocumented functions<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix incorrectly named function<br>qla8044_check_temp() (bsc#1185491).<br>- scsi: qla2xxx: Fix a couple of misnamed functions (bsc#1185491).
- scsi: qla2xxx: Fix some incorrect formatting/spelling issues<br>(bsc#1185491).<br>- scsi: qla2xxx: Replace __qla2x00_marker()'s missing underscores<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix broken #endif placement (bsc#1185491).
- scsi: qla2xxx: Simplify if statement (bsc#1185491).
- scsi: qla2xxx: Simplify the calculation of variables<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix some memory corruption (bsc#1185491).
- scsi: qla2xxx: Remove redundant NULL check (bsc#1185491).
- scsi: qla2xxx: Remove unnecessary NULL check (bsc#1185491).
- scsi: qla2xxx: Assign boolean values to a bool variable<br>(bsc#1185491).<br>- scsi: qla2xxx: fc_remote_port_chkready() returns a SCSI result<br>value (bsc#1185491).<br>- scsi: qla2xxx: Update version to 10.02.00.105-k (bsc#1185491).
- scsi: qla2xxx: Enable NVMe CONF (BIT_7) when enabling SLER<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix mailbox Ch erroneous error (bsc#1185491).
- scsi: qla2xxx: Wait for ABTS response on I/O timeouts for NVMe<br>(bsc#1185491).<br>- scsi: qla2xxx: Move some messages from debug to normal log level<br>(bsc#1185491).<br>- scsi: qla2xxx: Add error counters to debugfs node (bsc#1185491).
- scsi: qla2xxx: Implementation to get and manage host, target<br>stats and initiator port (bsc#1185491).<br>- commit 9add63f
- blacklist.conf: kthread: Fixes debugging of the life cycle of work struct.<br>Broken for ages. Disabled in our configuration.<br>- commit 4600ed3
- scsi: lpfc: Fix DMA virtual address ptr assignment in bsg<br>(bsc#1185365).<br>- scsi: lpfc: Fix illegal memory access on Abort IOCBs<br>(bsc#1183203).<br>- scsi: lpfc: Copyright updates for 12.8.0.9 patches<br>(bsc#1185472).<br>- scsi: lpfc: Update lpfc version to 12.8.0.9 (bsc#1185472).
- scsi: lpfc: Eliminate use of LPFC_DRIVER_NAME in lpfc_attr.c<br>(bsc#1185472).<br>- scsi: lpfc: Standardize discovery object logging format<br>(bsc#1185472).<br>- scsi: lpfc: Fix various trivial errors in comments and log<br>messages (bsc#1185472).<br>- scsi: lpfc: Remove unsupported mbox PORT_CAPABILITIES logic<br>(bsc#1185472).<br>- scsi: lpfc: Fix lpfc_hdw_queue attribute being ignored<br>(bsc#1185472).<br>- scsi: lpfc: Fix missing FDMI registrations after Mgmt Svc login<br>(bsc#1185472).<br>- scsi: lpfc: Fix silent memory allocation failure in<br>lpfc_sli4_bsg_link_diag_test() (bsc#1185472).<br>- scsi: lpfc: Fix use-after-free on unused nodes after port swap<br>(bsc#1185472).<br>- scsi: lpfc: Fix error handling for mailboxes completed in<br>MBX_POLL mode (bsc#1185472).<br>- scsi: lpfc: Fix lack of device removal on port swaps with PRLIs<br>(bsc#1185472).<br>- scsi: lpfc: Fix NMI crash during rmmod due to circular hbalock<br>dependency (bsc#1185472).<br>- scsi: lpfc: Fix reference counting errors in lpfc_cmpl_els_rsp()<br>(bsc#1185472).<br>- scsi: lpfc: Fix crash when a REG_RPI mailbox fails triggering<br>a LOGO response (bsc#1185472).<br>- scsi: lpfc: Fix rmmod crash due to bad ring pointers to<br>abort_iotag (bsc#1185472).<br>- scsi: lpfc: Fix gcc -Wstringop-overread warning (bsc#1185472).
- scsi: lpfc: Fix a typo (bsc#1185472).
- scsi: lpfc: Fix kernel-doc formatting issue (bsc#1185472).
- scsi: lpfc: Fix a few incorrectly named functions (bsc#1185472).
- scsi: lpfc: Fix incorrectly documented function<br>lpfc_debugfs_commonxripools_data() (bsc#1185472).<br>- scsi: lpfc: Fix a bunch of misnamed functions (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc misdemeanours<br>(bsc#1185472).<br>- scsi: lpfc: Fix incorrect naming of __lpfc_update_fcf_record()<br>(bsc#1185472).<br>- scsi: lpfc: Fix formatting and misspelling issues (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc issues (bsc#1185472).
- scsi: lpfc: Fix some error codes in debugfs (bsc#1185472).
- commit 9b1fc9d
- blacklist.conf: 6840a150b9da x86/platform/uv: Set section block size for hubless architectures
- commit 69952b3
- scsi: smartpqi: Update version to 1.2.16-012 (bsc#1178089).
- scsi: smartpqi: Correct pqi_sas_smp_handler busy condition<br>(bsc#1178089).<br>- scsi: smartpqi: Correct driver removal with HBA disks<br>(bsc#1178089).<br>- commit b86c984
- x86/microcode: Check for offline CPUs before requesting new<br>microcode (bsc#1114648).<br>- commit 0e9f5a9
- x86/crash: Fix crash_setup_memmap_entries() out-of-bounds access<br>(bsc#1114648).<br>- commit 560878d
- blacklist.conf: cosmetic fix
- commit 6fee0e9
- blacklist.conf: breaks kABI
- commit ee91288
- blacklist.conf: breaks kABI
- commit 505df6e
- USB: CDC-ACM: fix poison/unpoison imbalance (bsc#1184984).
- commit 7e0d30e
- ext4: find old entry again if failed to rename whiteout<br>(bsc#1184742).<br>- commit 78ebad3
- blacklist.conf: Blacklist 163f0ec1df33
- commit 720273a
- struct usbip_device kABI fixup (git-fixes).
- commit 0fd7372
- mm: fix memory_failure() handling of dax-namespace metadata<br>(bsc#1185335).<br>- commit ee11ea2
- isofs: release buffer head before return (bsc#1182613).
- commit 77a0f46
- ext4: fix potential error in ext4_do_update_inode (bsc#1184731).
- commit a3b0213
- Refresh patches.suse/kabi-nvme-fix-fast_io_fail_tmo.patch.
- commit fd1b885
- Refresh patches.kabi/kABI-powerpc-pseries-Add-shutdown-to-vio_driver-and-.patch.<br>Remove unused variables.<br>- commit 5afb3a3
- netfilter: x_tables: Use correct memory barriers (bsc#1184208<br>CVE-2021-29650).<br>- commit 719c6a8
- libnvdimm/label: Return -ENXIO for no slot in __blk_label_update<br>(bsc#1185269).<br>- libnvdimm/namespace: Fix reaping of invalidated<br>block-window-namespace labels (bsc#1185269).<br>- libnvdimm/security: ensure sysfs poll thread woke up and fetch<br>updated attr (FATE#325581 git-fixes).<br>- commit a0e750c
- usbip: synchronize event handler with sysfs code paths<br>(git-fixes).<br>- commit acf38ba
- usbip: stub-dev synchronize sysfs code paths (git-fixes).
- commit 823e744
- usbip: add sysfs_lock to synchronize sysfs code paths<br>(git-fixe).<br>- commit 50a6377
- locking/qrwlock: Fix ordering in queued_write_lock_slowpath() (bsc#1185041).
- commit 10fa764
- rpm/macros.kernel-source: fix KMP failure in %install (bsc#1185244)
- commit 52805ed
- video: hyperv_fb: Fix a double free in hvfb_probe (bsc#1175306, git-fixes).
- commit 6525186
- kabi: nvme: fix fast_io_fail_tmo (bsc#1181161).
- commit 946c302
- nvme-fabrics: reject I/O to offline device (bsc#1181161).
- commit f350de4
- nvme-rdma: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 483532f
- nvme-tcp: fix possible hang when failing to set io queues<br>(bsc#1181161).<br>- commit 9cbcf79
- nvme-tcp: avoid request double completion for concurrent<br>nvme_tcp_timeout (bsc#1181161).<br>- commit 5d7efff
- nvme-rdma: avoid request double completion for concurrent<br>nvme_rdma_timeout (bsc#1181161).<br>- commit 874ba7a
- nvme-tcp: avoid repeated request completion (bsc#1181161).
- commit d03513c
- nvme-rdma: avoid repeated request completion (bsc#1181161).
- commit f966c6f
- nvme-tcp: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 0d3fdc1
- nvme-rdma: avoid race between time out and tear down<br>(bsc#1181161).<br>- commit 86d008a
- nvme: introduce nvme_sync_io_queues (bsc#1181161).
- commit e825cc9
- nvme-fabrics: allow to queue requests for live queues<br>(bsc#1181161).<br>- commit 34580bf
- nvme-rdma: fix timeout handler (bsc#1181161).
- commit eb26c44
- Rename patches.suse/nvme-tcp-fix-timeout-handler-0475a8dcbce.patch<br>to patches.suse/nvme-tcp-fix-timeout-handler-236187c4ed1.patch  
  Fix commit hash.<br>- commit eab5e6c
- nvme-rdma: serialize controller teardown sequences<br>(bsc#1181161).<br>- commit 3224558
- nvme-tcp: fix timeout handler (bsc#1181161).
- commit ad9445b
- nvme-tcp: serialize controller teardown sequences (bsc#1181161).
- commit 6512d6e
- nvme-fabrics: don't check state NVME_CTRL_NEW for request<br>acceptance (bsc#1181161).<br>- commit 75ddcf5
- nvme-rdma: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 3af85d2
- nvme-tcp: fix controller reset hang during traffic<br>(bsc#1181161).<br>- commit 05f5595
- nvme: unlink head after removing last namespace (bsc#1181161).
- commit 7c6236e
- nvme: prevent warning triggered by nvme_stop_keep_alive<br>(bsc#1181161).<br>- commit 185de02
- nvme: introduce &quot;/Command Aborted By hos | 2021-06-10 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-sap-v20210604/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-sap-v20210604/) |
| SUSE Image SUSE-IU-2021:465-1 | suse | SUSE-IU-2021:465-1 | This image update for google/sles-12-sp5-v20210605 contains the following changes:  
Package apparmor was updated:<br>- apparmor-profiles-add-sssd-to-nameservice.patch: Enable access  to sssd fast cache for nameservice users (bsc#1183599)
- add-ld.so.preload-to-abstraction_base.patch: Add ld.so.preload to<br>abstraction/base (bsc#1181728)<br>Package audit was updated:<br>Package audit-secondary was updated:<br>Package avahi was updated:<br>- Add avahi-CVE-2021-3468.patch: avoid infinite loop by handling  HUP event in client_work (boo#1184521 CVE-2021-3468).<br>[https://github.com/lathiat/avahi/pull/330](https://github.com/lathiat/avahi/pull/330)<br>- Update avahi-daemon-check-dns-suse.patch: needed rebase against<br>the updated avahi-daemon-check-dns.sh.<br>Package bash was updated:<br>- Add patch bsc1177369.patch to fix bsc#1177369  * tailf command does destroy terminal/console settings<br>Package bind was updated:<br>- Some debugs were still in the patch for bsc#1181495.  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]
- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- An assertion check can fail while answering queries<br>for DNAME records that require the DNAME to be processed to resolve  
    itself  
    [CVE-2021-25215, bind-CVE-2021-25215.patch]<br>- A second vulnerability in BIND's GSSAPI security<br>policy negotiation can be targeted by a buffer overflow attack  
    This does not affect this package as the affected code is  
    disabled.  
    [CVE-2021-25216]  
  [bsc#1185345]<br>- * A broken inbound incremental zone update (IXFR)<br>can cause named to terminate unexpectedly  
    [CVE-2021-25214, bind-CVE-2021-25214.patch]<br>- When FIPS mode is enabled, the named tools will complain that<br>MD5 is enabled. This is now checked, MD5 is ignored and a  
  warning is shown.  
  [bsc#1181495, bind-bsc1181495-disable-md5-when-in-fips-mode.patch]<br>Package cifs-utils was updated:<br>- cifs.upcall: fix regression in kerberos mount; (bsc#1184815).  * add 0015-cifs.upcall-fix-regression-in-kerberos-mount.patch
- CVE-2021-20208: cifs-utils: cifs.upcall kerberos auth leak in<br>container; (bsc#1183239); CVE-2021-20208.<br>Package cloud-regionsrv-client was updated:<br>- Update to version 9.1.5 (bsc#1182779, bsc#1185234, bsc#1185198)  + Another startup process may run zypper before the registration process<br>if zypper is still running we cannot get the lock and as such  
    the installed products cannot be determined. Wait for the lock to be  
    released for up to 30 seconds.  
  + On any error durring product list generation return a list to avoid  
    a traceback by trying to iterate over None<br>Package containerd was updated:<br>- Drop long-since upstreamed patch, originally needed to fix i386 builds on  SLES:
- 0001-makefile-remove-emoji.patch
- Update to containerd v1.4.4, to fix CVE-2021-21334.
- Update to handle the docker-runc removal, and drop the -kubic flavour.<br>bsc#1181677 bsc#1181749<br>- Update to containerd v1.4.3, which is needed for Docker v20.10.2-ce.<br>bsc#1181594<br>- Install the containerd-shim* binaries and stop creating<br>docker-containerd-shim because that isn't used by Docker anymore.  
  bsc#1183024<br>Package crash was updated:<br>- Fix crash utility is taking forever to initialize a vmcore from large config  system (bsc#1178827 ltc#189279).<br>crash-task.c-avoid-unnecessary-cpu-cycles-in-stkptr_to_tas.patch<br>Package cups was updated:<br>- When cupsd creates directories with specific owner group  and permissions (usually owner is 'root' and group matches<br>&quot;/configure --with-cups-group=lp&quot;/) specify same owner group and  
  permissions in the RPM spec file to ensure those directories  
  are installed by RPM with the right settings because if those  
  directories were installed by RPM with different settings then  
  cupsd would use them as is and not adjust its specific owner  
  group and permissions which could lead to privilege escalation  
  from 'lp' user to 'root' via symlink attacks e.g. if owner is  
  falsely 'lp' instead of 'root' CVE-2021-25317 (bsc#1184161)<br>Package curl was updated:<br>- Security fix: [bsc#1186114, CVE-2021-22898]  * TELNET stack contents disclosure
- Add curl-CVE-2021-22898.patch
- Allow partial chain verification [jsc#SLE-17954]
- Have intermediate certificates in the trust store be treated<br>as trust-anchors, in the same way as self-signed root CA  
    certificates are. This allows users to verify servers using  
    the intermediate cert only, instead of needing the whole chain.<br>- Set FLAG_TRUSTED_FIRST unconditionally.
- Do not check partial chains with CRL check.
- Add curl-X509_V_FLAG_PARTIAL_CHAIN.patch
- Security fix: [bsc#1183933, CVE-2021-22876]
- The automatic referer leaks credentials
- Add curl-CVE-2021-22876-URL-API.patch curl-CVE-2021-22876.patch<br>Package dhcp was updated:<br>- CVE-2021-25217, bsc#1186382, dhcp-CVE-2021-25217.patch: A buffer  overrun in lease file parsing code can be used to exploit a<br>common vulnerability shared by dhcpd and dhclient.<br>Package docker was updated:<br>- Update to Docker 20.10.6-ce. See upstream changelog in the packaged  /usr/share/doc/packages/docker/CHANGELOG.md. bsc#1184768
- Rebase patches:
- 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
- 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
- 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
- 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
- Backport upstream fix &lt;[https://github.com/moby/moby/pull/42273&gt;](https://github.com/moby/moby/pull/42273&gt;) for btrfs<br>quotas being removed by Docker regularly. bsc#1183855 bsc#1175081  
  + 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch<br>- Update to Docker 20.10.5-ce. See upstream changelog in the packaged<br>/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1182947<br>- Update runc dependency to 1.0.0~rc93.
- Remove upstreamed patches:
- cli-0001-Rename-bin-md2man-to-bin-go-md2man.patch
- Rebase patches:
- 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
- 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
- 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
- 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
- Switch version to use -ce suffix rather than _ce to avoid confusing other<br>tools. boo#1182476  
[NOTE: This update was only ever released in SLES and Leap.]<br>- It turns out the boo#1178801 libnetwork patch is also broken on Leap, so drop<br>the patch entirely. bsc#1180401 bsc#1182168<br>- boo1178801-0001-Add-docker-interfaces-to-firewalld-docker-zone.patch
- Fix incorrect cast in SUSE secrets patches causing warnings on SLES.
- 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
- Update to Docker 20.10.3-ce. See upstream changelog in the packaged<br>/usr/share/doc/packages/docker/CHANGELOG.md. Fixes bsc#1181732  
  (CVE-2021-21284) and bsc#1181730 (CVE-2021-21285).<br>- Rebase patches on top of 20.10.3-ce.
- 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch<br>+ 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch<br>- 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch<br>+ 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch<br>- 0004-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch<br>+ 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch<br>- 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch<br>+ 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch<br>- Drop docker-runc, docker-test and docker-libnetwork packages. We now just use<br>the upstream runc package (it's stable enough and Docker no longer pins git  
  versions). docker-libnetwork is so unstable that it doesn't have any  
  versioning scheme and so it really doesn't make sense to maintain the project  
  as a separate package. bsc#1181641 bsc#1181677<br>- Remove no-longer-needed patch for packaging now that we've dropped<br>docker-runc and docker-libnetwork.<br>- 0001-PACKAGING-revert-Remove-docker-prefix-for-containerd.patch
- Update to Docker 20.10.2-ce. See upstream changelog in the packaged<br>/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1181594<br>- Remove upstreamed patches:
- bsc1122469-0001-apparmor-allow-readby-and-tracedby.patch
- boo1178801-0001-Add-docker-interfaces-to-firewalld-docker-zone.patch
- Add patches to fix build:<br>+ cli-0001-Rename-bin-md2man-to-bin-go-md2man.patch<br>- Since upstream has changed their source repo (again) we have to rebase all of<br>our patches. While doing this, I've collapsed all patches into one branch  
  per-release and thus all the patches are now just one series:<br>- packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch<br>+ 0001-PACKAGING-revert-Remove-docker-prefix-for-containerd.patch<br>- secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch<br>+ 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch<br>- secrets-0002-SUSE-implement-SUSE-container-secrets.patch<br>+ 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch<br>- private-registry-0001-Add-private-registry-mirror-support.patch<br>+ 0004-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch<br>- bsc1073877-0001-apparmor-clobber-docker-default-profile-on-start.patch<br>+ 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch<br>Package dracut was updated:<br>- fix(shutdown): add timeout to umount calls (bsc#1178219)  * add 0624-shutdown-guard-against-read-only-run.patch
- add 0625-shutdown-sleep-a-little-if-a-process-was-killed.patch
- add 0626-fix-shutdown-add-timeout-to-umount-calls.patch
- support network setup on infiniband devices (bsc#996146)
- add 0623-net-lib.sh-support-infiniband-network-mac-addresses.patch<br>Package gcc10 was updated:<br>- SLE12 only, adjust gcc10-rpmlintrc to ignore bogus  libgcc_s1-gcc10.s390x: E: invalid-license (Badness: 100000)<br>GPL-3.0 WITH GCC-exception-3.1  [bsc#1185337]<br>- Update to GCC 10.3.0 release (63fa67847628e5f358e7e2e7e), git1587
- Disable nvptx offloading for aarch64 again since it doesn't work
- Update to gcc-10 branch head (892024d4af83b258801ff7484), git1574
- Includes GCC 10.3 RC1
- Update to gcc-10 branch head (592388d4f6e8a6adb470428fe), git1450
- Update to gcc-10 branch head (85977f624a34eac309f9d77a5), git1331
- Includes fix for [bsc#1182016]
- The 32bit nvptx libgomp plugin is no longer built, do not attempt<br>to package it.<br>- Remove include-fixed/pthread.h
- Change GCC exception licenses to SPDX format
- Update to gcc-10 branch head (e563687cf9d3d1278f45aaebd), git1030
- Includes fix for firefox build [gcc#97918]
- Do not specify alternate offload compiler location at<br>configure time.<br>- Update README.First-for.SuSE.packagers
- Install offload compilers for gcc10-testresults build
- Enable fortran for offload compilers.
- Add gcc10-amdgcn-llvm-as.patch to fix build of amdgcn offload<br>compiler with llvm11.<br>- Update to gcc-10 branch head (98ba03ffe0b9f37b4916ce6238), git958.
- Includes fix for memcpy miscompilation on aarch64.<br>[bsc#1178624, bsc#1178577]<br>- Fix 32bit libgnat.so link.  [bsc#1178675]
- prepare usrmerge: Install libgcc_s into %_libdir. ABI wise it<br>stays /%lib. (boo#1029961)<br>- Update to gcc-10 branch head (a78cd759754c92cecbf235ac9b), git872.
- Build complete set of multilibs for arm-none target [bsc#1106014]
- Fixes inadvertant mixture of ARM and Thumb instructions in linker output<br>Package glib2 was updated:<br>- Add glib2-CVE-2021-27218.patch: g_byte_array_new_take takes a  gsize as length but stores in a guint, this patch will refuse if<br>the length is larger than guint. (bsc#1182328,  
  glgo#GNOME/glib!1944)<br>- Add glib2-CVE-2021-27219-add-g_memdup2.patch: g_memdup takes a<br>guint as parameter and sometimes leads into an integer overflow,  
  so add a g_memdup2 function which uses gsize to replace it.  
  (bsc#1182362, glgo#GNOME/glib!1927, glgo#GNOME/glib!1933,  
  glgo#GNOME/glib!1943)<br>Package glibc was updated:<br>- s390-memmove-ifunc-selector-arch13.patch: S390: Also check vector  support in memmove ifunc-selector (bsc#1184034, BZ #27511)
- iconv-redundant-shift.patch: iconv: Accept redundant shift sequences in<br>IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224)<br>- iconv-ucs4-loop-bounds.patch: iconv: Fix incorrect UCS4 inner loop<br>bounds (CVE-2020-29562, bsc#1179694, BZ #26923)<br>- printf-long-double-non-normal.patch: x86: Harden printf against<br>non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649)<br>Package google-guest-agent was updated:<br>- Update to version 20210414.00 (bsc#1185848, bsc#1185849)  * start sshd (#106)
- Add systemd-networkd.service restart dependency. (#104)
- Update error message for handleHealthCheckRequest. (#105)
- Update to version 20210223.01 (bsc#1183414, bsc#1183415)
- add a match block to sshd_config for SAs (#99)
- add ipv6 forwarded ip support (#101)
- call restorecon on ssh host keys (#98)
- Include startup and shutdown in preset (#96)
- set metadata URL earlier (#94)
- Fix activation logic of systemd services (bsc#1182793)
- Update to version 20201211.00
- Require snapshot scripts to live under /etc/google/snapshots (#90)
- Adding support for Windows user account password lengths<br>between 15 and 255 characters. (#91)<br>- Adding bkatyl to OWNERS (#92)<br>Package google-guest-configs was updated:<br>- Update to version 20210317.00 (bsc#1183414, bsc#1183415)  * dracut.conf wants spaces around values (#19)
- make the same change for debian (#18)
- change path back for google_nvme_id (#17)
- move google_nvme_id to /usr/bin (#16)
- correct udev rule syntax (#15)
- prune el6 spec (#13)
- Updated udev rules (#11)
- Remove empty %{_sbindir} from %install and %files section
- Remove service files (bsc#1180304)<br>+ google-optimize-local-ssd.service, google-set-multiqueue.service  
    scripts are called from within the guest agent<br>Package google-guest-oslogin was updated:<br>- Update to version 20210429.00 (bsc#1185848, bsc#1185849)  * correct pagetoken in groupsforuser (#59)
- resolve self groups last (#58)
- support empty groups (#57)
- no paginating to find groups (#56)
- clear users vector (#55)
- correct usage of pagetoken (#54)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- call correct function in pwenthelper (#53)
- Update to version 20210108.00
- Update logic in the cache_refresh binary (#52)
- remove old unused workflow files (#49)<br>Package google-osconfig-agent was updated:<br>- Update to version 20210506.00 (bsc#1185848, bsc#1185849)  * Add more os policy assignment examples (#348)
- e2e_tests: enable stable tests for OSPolicies (#347)
- Align start and end task logs (#346)
- ConfigTask: add additional info logs (#345)
- e2e_tests: add validation tests (#344)
- Config Task: make sure agent respects policy mode (#343)
- update
- e2e_tests: readd retries to OSPolicies
- Set minWaitDuration as a string instead of object (#341)
- e2e_tests: Fix a few SUSE tests (#339)
- Remove pre-release flag from config (#340)
- e2e_tests: fixup OSPolicy tests (#338)
- e2e_tests: unlock mutex for CreatePolicies as soon as create finishes (#337)
- e2e_tests: Don't retry failed OSPolicy tests, fix msi test (#336)
- Examples for os policy assignments (#334)
- e2e_tests: increase the deadline for OSPolicy tests and only start after a zone has been secured (#335)
- Fix panic when installing MSI (#332)
- e2e_tests: Add test cases of installing dbe, rpm and msi packages (#333)
- e2e_tests: add more logging
- e2e_tests: (#330)
- e2e_test: Add timouts to OSPolicy tests so we don't wait forever (#329)
- Create top level directories for gcloud and console for os policy assignment examples (#328)
- e2e_tests: Move api from an internal directory (#327)
- Make sure we use the same test name for reruns (#326)
- Add CONFIG_V1 capability (#325)
- e2e_tests: reduce size of instances, use pd-balanced, rerun failed tests once (#324)
- Only report installed packages for dpkg (#322)
- e2e_tests: fix windows package and repository tests (#323)
- Add top level directories for os policy examples (#321)
- e2e_tests: move to using inventory api for inventory reporting (#320)
- e2e_tests: add ExecResource tests (#319)
- ExecResource: make sure we set permissions correctly for downloaded files (#318)
- Config task: only run post check on resources that have already been evaluated (#317)
- e2e_test: reorganize OSPolicy tests to be per Resource type (#316)
- Set custom user agent (#299)
- e2e_tests: check InstanceOSPoliciesCompliance for each test case, add LocalPath FileResource test (#314)
- PackageResource: make sure to run AptUpdate prior to package install (#315)
- Fix bugs/add more logging for OSPolicies (#313)
- Change metadata http client to ignore http proxies (#312)
- e2e_test: add tests for FileResource (#311)
- Add task_type context logging (#310)
- Fix e2e_test typo (#309)
- Fix e2e_tests (#308)
- Disable OSPolicies by default since it is an unreleased feature (#307)
- e2e_tests: Add more OSPolicies package and repo tests (#306)
- Do not enforce repo_gpgcheck in guestpolicies (#305)
- Gather inventory 3-5min after agent start (#303)
- e2e_tests: add OSPolicies tests for package install (#302)
- Add helpful error log if a service account is missing (#304)
- OSPolicies: correct apt repo extension, remove yum/zypper gpgcheck override (#301)
- Update cos library to parse new version of packages file (#300)
- config_task: Rework config step logic (#296)
- e2e_test: enable serial logs in cos to support ReportInventory test (#297)
- Update to version 20210316.00 (bsc#1183414, bsc#1183415)
- ExecResource: fix bug in return code handling (#295)
- Fix ExecResource permissions, add logs to fetcher (#294)
- e2e_tests: Fix ubuntu proposed family (#293)
- e2e_tests: add proposed debian images to head tests (#292)
- Fix exec_resource for config task, add minimal unit test (#291)
- Change util.WriteFile to AtomicWriteFileStream (#289)
- Merge development branch into master (#288)
- Create util.TempFile to work nicely with Windows (#287)
- Fix copy step write (#286)
- Fix error on linux lock (#285)
- Ensure we cleanup on error in AtomicWrite (#284)
- Make writes atomic, add unused &quot;/allowDowngrades&quot;/ option<br>to apt, fix a few recipe issues (#283)<br>- update reviewers (#282)
- update apt package lists before running installs (#281)
- Simplify build tags for COS package (#280)
- Update to version 20210112.00
- Fix builds for ppc and s390x (#274)
- Minor updates to tests and additional debug logging (#272)
- Add Ubuntu 2004 to tests (#271)
- Make sure we stop tickers (#270)
- Drop Windows 1903 and CentOS 6 from tests (#269)
- Pin el6 tests to last published image as it is EOL (#267)
- support cos (#266)
- Update to version 20201117.00 (bsc#1179031, bsc#1179032)
- Ignore Unavailable erros on stream receive (#260)
- Update test Windows images (#259)
- update ReportInventory e2e test regexes (#255)
- Don't return on a windows update error (#254)
- use retryutil for ReportInventory calls (#253)
- add additional debug logging for ReportInventory request payload for e2e tests (#252)
- stop logging instance identity token as part of ReportInventory request and remove<br>feature-flag setting in OSInventoryReporting e2e tests (#251)<br>- complete ExecTask as no-op when the ExecStepConfig doesn't match the OS (#250)
- Add software recipe tests for COS (#249)
- remove feature flag for inventory reporting (#243)
- Force yum to never colorize output (#247)
- Add sleep after Unavailable errors for agentendpoint (#241)
- Ensure we record epoch for rpm packages (#242)
- Make inventory WUAUpdates call spawn a new process,<br>retry on metadata unmarshal error (#239)<br>- add debug logging for report inventory response (#240)
- add initial e2e tests for inventory reporting (#237)
- Report installed packages on COS (#236)<br>Package grub2 was updated:<br>- Fix executable stack in grub-emu (bsc#1181696)  * 0001-emu-fix-executable-stack-marking.patch<br>Package gzip was updated:<br>- fix DFLTCC segfault [bsc#1177047]- added patches<br>fix [https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc](https://git.savannah.gnu.org/cgit/gzip.git/commit/?id=be0a534ba2b6e77da289de8da79e70843b1028cc)  
  + gzip-1.10-fix-DFLTCC-segfault.patch<br>- gzip.spec: move %patch10 from the ifarch condition (mistake)
- add gzip-1.10-fix_count_of_lines_to_skip.patch to fix count<br>of lines to skip [bsc#1180713]<br>Package irqbalance was updated:<br>- Increase size of procinterrupts line readings by factor 32 (bsc#1184592)  A procinterrupts_read_buffer_increase.patch
- Use _fillupdir in spec file to also build against latest distros<br>which could be useful for comparing versions in case we get yet  
  another bug.<br>- not balancing interrupts in Xen guests (bsc#1178477, bsc#1183405)<br>A procinterrupts-check-xen-dyn-event-more-flexible.patch<br>Package kernel-default was updated:<br>- smsc95xx: avoid memory leak in smsc95xx_bind (git-fixes).- commit 1640fc2
- smsc95xx: check return value of smsc95xx_reset (git-fixes).
- commit 00f3661
- net: cxgb4: fix return error value in t4_prep_fw (git-fixes).
- commit 6c63ec6
- net: bcmgenet: use hardware padding of runt frames (git-fixes).
- commit 20467c9
- blacklist.conf: Add fe6bdfc8e1e1 mm: fix oom_kill event handling
- commit 016ac3f
- blacklist.conf: Add e81bf9793b18 mem_cgroup: make sure moving_account, move_lock_task and stat_cpu in the same cacheline
- commit 0632aad
- Don't drop out of segments RST if tcp_be_liberal is set<br>(bsc#1183947).<br>- Avoid potentially erroneos RST drop (bsc#1183947).
- commit 4727a1c
- Update<br>patches.suse/net-fix-race-condition-in-__inet_lookup_established.patch  
  (bsc#1151794 bsc#1180624).<br>- handle also the opposite type of race condition
- commit 7737da1
- powerpc/perf: Fix PMU constraint check for EBB events<br>(bsc#1065729).<br>- powerpc/64s: Fix pte update for kernel memory on radix<br>(bsc#1055117 git-fixes).<br>- powerpc/asm-offsets: GPR14 is not needed either (bsc#1065729).
- powerpc/prom: Mark identical_pvr_fixup as __init (bsc#1065729).
- powerpc/fadump: Mark fadump_calculate_reserve_size as __init<br>(bsc#1065729).<br>- stop_machine: mark helpers __always_inline (bsc#1087405<br>git-fixes).<br>- commit 25e3769
- ibmvnic: queue reset work in system_long_wq (bsc#1152457<br>ltc#174432 git-fixes).<br>- ibmvnic: improve failover sysfs entry (bsc#1043990 ltc#155681<br>git-fixes).<br>- ibmvnic: print adapter state as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: print reset reason as a string (bsc#1152457 ltc#174432<br>git-fixes).<br>- ibmvnic: clean up the remaining debugfs data structures<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in open function<br>(bsc#1065729).<br>- ibmvnic: remove duplicate napi_schedule call in do_reset<br>function (bsc#1065729).<br>- ibmvnic: avoid calling napi_disable() twice (bsc#1065729).
- commit 46cbce7
- KVM: Add proper lockdep assertion in I/O bus unregister<br>(CVE-2020-36312 bsc#1184509).<br>- KVM: Stop looking for coalesced MMIO zones if the bus is<br>destroyed (CVE-2020-36312 bsc#1184509).<br>- KVM: Destroy I/O bus devices on unregister failure _after_<br>sync'ing SRCU (CVE-2020-36312 bsc#1184509).<br>- commit bc1f707
- btrfs: fix qgroup data rsv leak caused by falloc failure<br>(bsc#1185549).<br>- commit e1218ad
- btrfs: track qgroup released data in own variable in<br>insert_prealloc_file_extent (bsc#1185549).<br>- commit bf772b7
- Refresh<br>patches.suse/ibmvnic-Use-skb_frag_address-instead-of-hand-coding-.patch.<br>- Refresh<br>patches.suse/scsi-ibmvfc-Fix-invalid-state-machine-BUG_ON.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Change-wording-of-invalid-pci-reset-log-me.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Correct-function-header-comments-related-t.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-ADISC-handling-that-never-frees-nodes.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-FLOGI-failure-due-to-accessing-a-freed.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-PLOGI-ACC-to-be-transmit-after-REG_LOG.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-crash-caused-by-switch-reboot.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-dropped-FLOGI-during-pt2pt-discovery-r.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-incorrect-dbde-assignment-when-buildin.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-lpfc_els_retry-possible-null-pointer-d.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-nodeinfo-debugfs-output.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-null-pointer-dereference-in-lpfc_prep_.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-connection-does-not-recover-afte.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-pt2pt-state-transition-causing-rmmod-h.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-reftag-generation-sizing-errors.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-stale-node-accesses-on-stale-RRQ-reque.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-status-returned-in-lpfc_els_retry-erro.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-unnecessary-null-check-in-lpfc_release.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-use-after-free-in-lpfc_els_free_iocb.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Fix-vport-indices-in-lpfc_find_vport_by_vp.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Reduce-LOG_TRACE_EVENT-logging-for-vports.patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-copyrights-for-12.8.0.7-and-12.8.0..patch.<br>- Refresh<br>patches.suse/scsi-lpfc-Update-lpfc-version-to-12.8.0.8.patch.<br>- commit d057148
- scsi: qla2xxx: Reserve extra IRQ vectors (bsc#1185491).
- scsi: qla2xxx: Reuse existing error handling path (bsc#1185491).
- scsi: qla2xxx: Remove unneeded if-null-free check (bsc#1185491).
- scsi: qla2xxx: Update version to 10.02.00.106-k (bsc#1185491).
- scsi: qla2xxx: Do logout even if fabric scan retries got<br>exhausted (bsc#1185491).<br>- scsi: qla2xxx: Update default AER debug mask (bsc#1185491).
- scsi: qla2xxx: Fix mailbox recovery during PCIe error<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix crash in PCIe error handling (bsc#1185491).
- scsi: qla2xxx: Fix RISC RESET completion polling (bsc#1185491).
- scsi: qla2xxx: Fix crash in qla2xxx_mqueuecommand()<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix use after free in bsg (bsc#1185491).
- scsi: qla2xxx: Consolidate zio threshold setting for both FCP &amp;<br>NVMe (bsc#1185491).<br>- scsi: qla2xxx: Fix stuck session (bsc#1185491).
- scsi: qla2xxx: Add H:C:T info in the log message for fc ports<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix IOPS drop seen in some adapters<br>(bsc#1185491).<br>- scsi: qla2xxx: Check kzalloc() return value (bsc#1185491).
- scsi: qla2xxx: Always check the return value of<br>qla24xx_get_isp_stats() (bsc#1185491).<br>- scsi: qla2xxx: Simplify qla8044_minidump_process_control()<br>(bsc#1185491).<br>- scsi: qla2xxx: Suppress Coverity complaints about dseg_r*<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix endianness annotations (bsc#1185491).
- scsi: qla2xxx: Constify struct qla_tgt_func_tmpl (bsc#1185491).
- scsi: qla2xxx: Use dma_pool_zalloc() (bsc#1185491).
- scsi: qla2xxx: Fix a couple of misdocumented functions<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix incorrectly named function<br>qla8044_check_temp() (bsc#1185491).<br>- scsi: qla2xxx: Fix a couple of misnamed functions (bsc#1185491).
- scsi: qla2xxx: Fix some incorrect formatting/spelling issues<br>(bsc#1185491).<br>- scsi: qla2xxx: Replace __qla2x00_marker()'s missing underscores<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix broken #endif placement (bsc#1185491).
- scsi: qla2xxx: Simplify if statement (bsc#1185491).
- scsi: qla2xxx: Simplify the calculation of variables<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix some memory corruption (bsc#1185491).
- scsi: qla2xxx: Remove redundant NULL check (bsc#1185491).
- scsi: qla2xxx: Remove unnecessary NULL check (bsc#1185491).
- scsi: qla2xxx: Assign boolean values to a bool variable<br>(bsc#1185491).<br>- scsi: qla2xxx: fc_remote_port_chkready() returns a SCSI result<br>value (bsc#1185491).<br>- scsi: qla2xxx: Update version to 10.02.00.105-k (bsc#1185491).
- scsi: qla2xxx: Enable NVMe CONF (BIT_7) when enabling SLER<br>(bsc#1185491).<br>- scsi: qla2xxx: Fix mailbox Ch erroneous error (bsc#1185491).
- scsi: qla2xxx: Wait for ABTS response on I/O timeouts for NVMe<br>(bsc#1185491).<br>- scsi: qla2xxx: Move some messages from debug to normal log level<br>(bsc#1185491).<br>- scsi: qla2xxx: Add error counters to debugfs node (bsc#1185491).
- scsi: qla2xxx: Implementation to get and manage host, target<br>stats and initiator port (bsc#1185491).<br>- commit 9add63f
- blacklist.conf: kthread: Fixes debugging of the life cycle of work struct.<br>Broken for ages. Disabled in our configuration.<br>- commit 4600ed3
- scsi: lpfc: Fix DMA virtual address ptr assignment in bsg<br>(bsc#1185365).<br>- scsi: lpfc: Fix illegal memory access on Abort IOCBs<br>(bsc#1183203).<br>- scsi: lpfc: Copyright updates for 12.8.0.9 patches<br>(bsc#1185472).<br>- scsi: lpfc: Update lpfc version to 12.8.0.9 (bsc#1185472).
- scsi: lpfc: Eliminate use of LPFC_DRIVER_NAME in lpfc_attr.c<br>(bsc#1185472).<br>- scsi: lpfc: Standardize discovery object logging format<br>(bsc#1185472).<br>- scsi: lpfc: Fix various trivial errors in comments and log<br>messages (bsc#1185472).<br>- scsi: lpfc: Remove unsupported mbox PORT_CAPABILITIES logic<br>(bsc#1185472).<br>- scsi: lpfc: Fix lpfc_hdw_queue attribute being ignored<br>(bsc#1185472).<br>- scsi: lpfc: Fix missing FDMI registrations after Mgmt Svc login<br>(bsc#1185472).<br>- scsi: lpfc: Fix silent memory allocation failure in<br>lpfc_sli4_bsg_link_diag_test() (bsc#1185472).<br>- scsi: lpfc: Fix use-after-free on unused nodes after port swap<br>(bsc#1185472).<br>- scsi: lpfc: Fix error handling for mailboxes completed in<br>MBX_POLL mode (bsc#1185472).<br>- scsi: lpfc: Fix lack of device removal on port swaps with PRLIs<br>(bsc#1185472).<br>- scsi: lpfc: Fix NMI crash during rmmod due to circular hbalock<br>dependency (bsc#1185472).<br>- scsi: lpfc: Fix reference counting errors in lpfc_cmpl_els_rsp()<br>(bsc#1185472).<br>- scsi: lpfc: Fix crash when a REG_RPI mailbox fails triggering<br>a LOGO response (bsc#1185472).<br>- scsi: lpfc: Fix rmmod crash due to bad ring pointers to<br>abort_iotag (bsc#1185472).<br>- scsi: lpfc: Fix gcc -Wstringop-overread warning (bsc#1185472).
- scsi: lpfc: Fix a typo (bsc#1185472).
- scsi: lpfc: Fix kernel-doc formatting issue (bsc#1185472).
- scsi: lpfc: Fix a few incorrectly named functions (bsc#1185472).
- scsi: lpfc: Fix incorrectly documented function<br>lpfc_debugfs_commonxripools_data() (bsc#1185472).<br>- scsi: lpfc: Fix a bunch of misnamed functions (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc misdemeanours<br>(bsc#1185472).<br>- scsi: lpfc: Fix incorrect naming of __lpfc_update_fcf_record()<br>(bsc#1185472).<br>- scsi: lpfc: Fix formatting and misspelling issues (bsc#1185472).
- scsi: lpfc: Fix a bunch of kernel-doc issues (bsc#1185472).
- scsi: lpfc: Fix some error codes in debugfs (bsc#1185472).
- commit 9b1fc9d
- blacklist.conf: 6840a150b9da x86/platform/uv: Set section block size for hubless architectures
- commit 69952b3
- scsi: smartpqi: Update version to 1.2.16-012 (bsc#1178089).
- scsi: smartpqi: Correct pqi_sas_smp_handler busy condition<br>(bsc#1178089).<br>- scsi: smartpqi: Correct driver removal with HBA disks<br>(bsc#1178089).<br>- commit b86c984
- x86/microcode: Check for offline CPUs before requesting new<br>microcode (bsc#1114648).<br>- commit 0e9f5a9
- x86/crash: Fix crash_setup_memmap_entries() out-of-bounds access<br>(bsc#1114648).<br>- commit 560878d
- blacklist.conf: cosmetic fix
- commit 6fee0e9
- blacklist.conf: breaks kABI
- commit ee91288
- blacklist.conf: breaks kABI
- commit 505df6e
- USB: CDC-ACM: fix poison/unpoison imbalance (bsc#1184984).
- commit 7e0d30e
- ext4: find old entry again if failed to rename whiteout<br>(bsc#1184742).<br>- commit 78ebad3
- blacklist.conf: Blacklist 163f0ec1df33
- commit 720273a
- struct usbip_device kABI fixup (git-fixes).
- commit 0fd7372
- mm: fix memory_failure() handling of dax-namespace metadata<br>(bsc#1185335).<br>- commit ee11ea2
- isofs: release buffer head before return (bsc#1182613).
- commit 77a0f46
- ext4: fix potential error in ext4_do_update_inode (bsc#1184731).
- commit a3b0213
- Refresh patches.suse/kabi-nvme-fix-fast_io_fail_tmo.patch.
- commit fd1b885
- Refresh patches.kabi/kABI-powerpc-pseries-Add-shutdown-to-vio_driver-and-.patch.<br>Remove unused variables.<br>- commit 5afb3a3
- netfilter: x_tables: Use correct memory barriers (bsc#1184208<br>CVE-2021-29650).<br>- commit 719c6a8
- libnvdimm/label: Return -ENXIO for no slot in __blk_label_update<br>(bsc#1185269).<br>- libnvdimm/namespace: Fix reaping of invalidated<br>block-window-namespace labels (bsc#1185269).<br>- libnvdimm/security: ensure sysfs poll thread woke up and fetch<br>updated attr (FATE#325581 git-fixes).<br>- commit a0e750c
- usbip: synchronize event handler with sysfs code paths<br>(git-fixes).<br>- commit acf38ba
- usbip: stub-dev synchronize sy | 2021-06-10 | [https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-v20210605/](https://publiccloudimagechangeinfo.suse.com/google/sles-12-sp5-v20210605/) |
| SUSE Image SUSE-IU-2021:606-1 | suse | SUSE-IU-2021:606-1 | This image update for google/sles-15-sp3-chost-byos-v20210729 contains the following changes:  
Package SUSEConnect was updated:<br>- Update to 0.3.29- replace env ruby path with native ruby path during build phase
- Recognize more formats when parsing .curlrc for proxy credentials (bsc#1155027)
- Add rpmlintrc to filter false-positive warning about patch not applied
- Update to 0.3.27
- SUSEConnect now ensures that it writes its configuration when it<br>encounters errors. This helps in the situation where SUSEConnect  
  announces itself, but fails during a later step. Without the saved  
  configuration, a system could have credentials, but be unsure which  
  registration proxy they're valid for.<br>- Update to 0.3.26
- Extend the YaST API in order to access to the package search<br>functionality (jsc#SLE-9109)<br>- Don't fail de-activation when '-release' package already got removed
- Update to 0.3.25
- Fix cloud_provider detection on AWS large instances (bsc#1160007)
- Update to 0.3.24
- Forbid de-registration for on-demand Public Cloud instances (bsc#1155911)
- 0.3.23<br>fix .spec file to correctly apply switch_server_cert_location_to_etc.patch to SLE15SP2+ (bsc#1130864)<br>- Update to 0.3.22<br>switch_server_cert_location_to_etc.patch: add patch to switch server cert path for SLE15.2+ to /etc (bsc#1130864)<br>- Update to 0.3.21<br>Fix error on first activation of packagehub extension (bsc#1124318)<br>- Update to 0.3.20
- Fix getting the list of installed products when zypper plugins are<br>present (bsc#1143635)<br>- Update to 0.3.19
- Fix failing on registered system without arguments (bsc#1144020)
- Update to 0.3.18
- Fix base product service removal during de-registration in public clouds (bsc#1136752)
- Update to 0.3.17
- Don't try to remove a service during migration if a zypper service<br>plugin already exists (bsc#1128969)<br>- Replace --no-ri --no-rdoc with --no-document - these options<br>are obsolete since at least ruby 2.1 - and finally removed in  
  ruby 2.6<br>- Only overwrite --bindir on fedora, it will overwrite --buildroot<br>(which needs to be combined on newer fedoras)<br>- Update to 0.3.16
- Show non-enabled extensions with a remark about availability
- Update to 0.3.15
- Output information about registration and de-registration progress
- Output proper message when SUSEConnect is called without parameters (bsc#959561)
- Default to https URI when no protocol prefix is provided for --url
- Support transactional-update systems (fate#326482)
- Changed &quot;/openssl&quot;/ recommendation to &quot;/openssl(cli)&quot;/<br>on SLE 12 SP3+ and SLE 15+ (bsc#1101470).<br>- Update to 0.3.14
- Fix s390 activation fails due to unavailable 'dmidecode' bsc#1112702
- Update to 0.3.13
- Fix migration targets sorting (bsc#1104183)
- Update to 0.3.12
- Detect if system is in cloud provider (AWS/Google/Azure)<br>(fate#320935)<br>- Don't fail when trying to parse an empty body. Fixes bsc#1098220
- Don't install release packages if they are already present
- Fix .spec file for running SUSEConnect on Fedora28
- Weaken dependencies of rmt-client-setup script to Recommends:<br>(bsc#1094348)<br>- Enhance error message generation
- Add not supported operation exception to PackageSearch API
- Update to 0.3.11
- Add dependencies needed by the rmt-client-setup script. bsc#1093658
- Prevent the automatic registration of recommended products that<br>are not mirrored by the registration proxy.<br>- Update to 0.3.10
- Fix rollback mechanism on SLE15 systems (bsc#1089320)
- Update to 0.3.9
- Enable access to package search via gem
- Don't try to delete directory of nonexistent service files<br>(bsc#1086420)<br>- Update to 0.3.8
- Fix list-extensions to show the full SLE 15 tree (bsc#1064264)
- Enable automatic activation of recommended extensions/modules
- Automatically deregister all installed extensions/modules when<br>deregistering a system<br>- Repackage gem
- Remove unnecessary .gz files
- Update to 0.3.7
- virt-create-rootfs connects to SMT server without breaking (bsc#914297)
- Update to 0.3.6
- Make target_base_product parameter mandatory.
- Update to 0.3.5
- Add YaST.system_offline_migrations
- Update to version 0.3.4:
- Packaging improvements (bsc#964013)
- Update to version 0.3.3:
- Fix SLE15 build
- Properly refresh zypper services when deactivating a product on SMT (bsc#1047153)
- Update to 0.3.2:
- Fix --namespace parameter persistence (bsc#1044493)
- Update to 0.3.1:
- Fix license auto-agree issue (bsc#1037783)
- Add missing archs to SLE 12 SP3 build target
- Update to 0.3.0:
- Single product deactivation feature (fate#320572)
- Update to 0.2.43:
- RPM spec fix for openSUSE:Factory rpmlint compliance (bsc#1028660)
- Update to 0.2.42:
- Better error message for network request failure (bsc#982630)
- Fix error message for --product with malformed identifier (bsc#1018190)
- Fix some errors and formatting in manpages and help output
- Update to 0.2.41:
- Better error message for --list-extensions on unregistered systems
- Update to 0.2.40:
- Update man page to include the --list-extensions option (bsc#998583)
- Update to 0.2.39:
- Fix for bnc#990475: support for aarch64 hardware info
- Update to 0.2.38:
- Fix for bnc#975484: better error message if SMT is too old
- Update to 0.2.37:
- Add method to YaST class to get Installer-Updates repositories (fate#319716).
- Update to 0.2.36:
- Fix for bnc#973851: More flexible exit codes handling in internal zypper calls
- Update to 0.2.35:
- Fix for bnc#973315: Direct update from &lt;=0.2.27 does not remove /usr/bin symlink
- Update to 0.2.34:
- Fix for bnc#963996: Do not crash on --list-extensions when connected to SMT
- Fix for bnc#968245: Do not let zypper attempt to read products from remote locations
- Update to 0.2.33:
- Re-add SUSEConnect binary to /usr/sbin (bnc#963080)
- Use `--match-exact` when searching for a product (bnc#952804)
- Fix fonts on xterm (bnc#957354)
- Update to version 0.2.32: Remove unneeded link in %post which caused a warning (bnc#946183)
- Update to version 0.2.31 (bnc#946183)
- Drop url-implies-writeconfig.diff; it is included in upstream since commit 2ef5aa
- Correct RPM group
- Include SCCcredentials file as a ghost entry
- Further packaging improvements
- Update to version 0.2.30
- New packaging spec. One `SUSEConnect` package to rule them all (bnc#951671)
- Update manpages to match the latest CLI options
- Update to version 0.2.29
- bnc#954266 Silently ignore malformed lscpu lines instead of failing
- Update to version 0.2.28
- Properly handle empty repository lists from zypper (bnc#951566)
- Update to version 0.2.27
- Do not install recommended dependencies when installing the product release package (bnc#945462)
- Addd --rollback option (fate#319114)
- Update to version 0.2.26
- zypper migration extremly slow with lot of modules and extensions registered (bnc#945462)
- Update to version 0.2.25
- Solves Allow registration without system uid (dmidecode fails on qemu system) (bnc#934582)
- bnc#949424 ensure version of SUSEConnect is bumped in order to be<br>able to distinct requests from affected YaST version in SCC API<br>- Update to version 0.2.24
- Bug 943451 - [Migration] failure when &quot;/zypper search&quot;/ returns empty list
- Bug 946488 - Synchronization API call returns &quot;/no implicit conversion of Symbol into Integer&quot;/ error
- Bug 941565 - zypper migration not using --releasever
- Bug 945462 - zypper migration extremly slow with lot of modules and extensions registered
- Update to version 0.2.23
- Improve hwinfo detection on physical s390 systems
- Bug 939293 - [S390] Error: Registration failed. Undefined method 'strip' for nil:NilClass (bnc#939293)
- Update to version 0.2.22
- Migration rollback (fate#319114)
- [Migration rollback] zypper migrate: baseproduct mismatch (bnc#941303)
- Update to version 0.2.21
- Escape parameters of remove and add_repository methods
- Update to version 0.2.20
- Add find_products method to migration abstraction layer fate#319140
- Fix add_service method which also creates the credentials files
- Update to version 0.2.19
- Introduction of migration abstraction layer for migration script
- Clean up and re-factoring of yast abstraction layer
- Update to version 0.2.18
- Improve SUSEConnect error messages
- New --cleanup option (remove old system credentials and all zypper services installed by SUSEConnect)
- New --namespace option (forward SMT staging environment to proxy registration server)
- Update to version 0.2.17
- Added migrations endpoint support for Yast
- Use C locale for all the syscalls (solves output parsing issues in some locales)
- Stripping UUID from SCC API calls if it is not settable
- Moved examples from gist to project
- Update to version 0.2.16
- In case of wrong regcode provide meaningful message back to<br>the user (Wrong regcode in that case).<br>- Update to version 0.2.15
- Always write config file when --url parameter used (bnc#900689)<br>Package aaa_base was updated:<br>- Add patch git-33-d12420cc66e6d26a9dff6c0e86e00de232151c82.patch  * Avoid semicolon within (t)csh login script on S/390.<br>(bsc#1179431)<br>- Add patch git-21-0064ecd132c30a939125acbc5b9a1c7bcd180fa0.patch
- add screen.xterm-256color to DIR_COLORS
- Add patch git-22-f5e90d70d119b6aa12d019947029f9337aec378d.patch
- check for Packages.db and use this instead of Packages<br>(boo#1171762)<br>- Add patch git-23-8f1fe28287466235ade9c62fa5995eba9e642660.patch
- Rename path() to _path() to avoid using a general name.
- Add patch git-24-2de52ae391e2963eb1913183a6b0530c7e781b55.patch
- DIR_COLORS add TERM rxvt-unicode-256color (bug#1006973)
- Add patch git-25-287cf7cb851c0636fa46a610015d2d22ad36acea.patch
- sort TERM entries in etc/DIR_COLORS
- Add patch git-26-0c2f2340cc6ebb51f20b36e550adc517a6b2ae42.patch
- DIR_COLORS: merge TERM entries with list from (bug#1006973)
- Add patch git-27-abf7927eebbd4d7f47a362d49ae7856520682c49.patch
- refresh_initrd call modprobe as /sbin/modprobe (bug#1011548)
- Add patch git-28-3351bcc9613ba022503103e7e4ffd01e7bd8e0fd.patch
- etc/profile add some missing ;; in case esac statements
- Add patch git-29-5220a5f6ba250503ccda326e65ca069d245a5ebe.patch
- profile and csh.login: on s390x set TERM to dumb on serial console<br>for sclp_line0 and ttyS0 console (bug#1153946)<br>- Add patch git-30-b9dd70f33a124556f16dbbafc89585a82218ad61.patch
- backup-rpmdb: exit if zypp.pid is there and running<br>(bug#1161239)<br>- Add patch git-31-52dc403d54f2c926ee5cc892d1a8a830a45d7412.patch
- also add color alias for ip command, jira#sle-9880, bsc#1153943
- Add patch git-32-0ee79834ea9ebf6573a7b903f374c21e53a56c14.patch
- alias.bash check if ip command knows color=auto (jsc#SLE-7679)
- Add patch git-19-1149066a54a372b30b7cbd79cd222e11d96dc984.patch
- Not all XTerm based emulators do have an terminfo entry (boo#1087982)
- Add patch git-20-6452441f2054b4b290c089ce6269889993b95fc1.patch
- Better support of Midnight Commander (bsc#1170527)
- Add patch git-16-ed897a1090cafb678f75dbed8802bd671d3c1921.patch<br>get_kernel_version: fix for current kernel on s390x (from azouhr)  
  (bsc#1151023) (bsc#1139939)<br>- Add patch git-17-fe967bddbd74af9aba435900878397c0c7ea0b0b.patch<br>added &quot;/-h&quot;//&quot;/--help&quot;/ to &quot;/old&quot;/ command (from Bernhard Lang)<br>- Add patch git-18-bb11f02d5dd940803c08d25b0cfd3650d9de7d41.patch<br>change feedback url from [http://www.suse.de/feedback](http://www.suse.de/feedback) to  
  [https://github.com/openSUSE/aaa_base/issues](https://github.com/openSUSE/aaa_base/issues)<br>- Add patch git-15-27e2c6180a45cca63d71ffa5de7b32dec749d2cd.patch<br>change rp_filter to 2 to follow the current default (bsc#1160735)<br>- Add patch git-14-12023f2e8aae5b2ac3a895301945566b9f5eb9c3.patch<br>drop dev.cdrom.autoclose = 0 from sysctl config (bsc#1160970)<br>- Clear broken ghost entry in patch<br>git-13-14003c19eaa863ae9d80a0ebb9b5cab6273a5a9e.patch  
  which breaks (lib)readline (bsc#1157278)<br>- Add patch git-13-14003c19eaa863ae9d80a0ebb9b5cab6273a5a9e.patch<br>Use official key binding functions in inputrc  
  that is replace up-history with previous-history, down-history with  
  next-history and backward-delete-word with backward-kill-word  
  (bsc#1084934).  Add some missed key escape sequences for urxvt-unicode  
  terminal as well (boo#1007715).<br>- Add patch git-12-80d14205f913cc67a98c562f988ea700a56c369b.patch
- service: check if there is a second argument before using it<br>(bsc#1051143)<br>- Add patch git-11-b20083a930f766939f47dddc66d089c9fee5d38a.patch
- check if variables can be set before modifying them<br>to avoid warnings on login with a restricted shell  
    (bsc#1138869)<br>- Add patch git-08-9875dffab3ddda0c3e8399f935f059246c961f2a.patch
- Add s390x compressed kernel support (bsc#1151023)
- Add git-09-c6cd010dd8b6efddd71c30f00a923d8f2537584c.patch
- Fix LC_NAME and LC_ADDRESS in sh.ssh
- Add patch git-10-43091e644ff54997468a215b891dcaa75173f133.patch
- fix string test to arithmetic test in /etc/profile.d/wsl.sh
- Add patch git-07-82a17f1689e8957635c8ccaae7c9b3bff7f94d49.patch
- add sysctl.d/51-network.conf to tighten network security a bit<br>see also (boo#1146866) (jira#SLE-9132)<br>- Add patch git-06-8640f848c6677f1149b9765a8c86135956604007.patch
- Make systemd detection cgroup oblivious (bsc#1140647)<br>systemd can work in three exclusive cgroup modes: legacy, hybrid and  
    unified. The mode affects where and what cgroup hierarchies are mounted.  
    detect running systemd as systemd itself does it  
    (src/libsystemd/sd-daemon/sd-daemon.c, function sd_booted)<br>- Add patch git-05-ae2a49183ba0ad9dff6b8c1efd4de076bd34ab0f.patch
- /etc/profile does not work in AppArmor-confined containers<br>(bsc#1096191)<br>- Add patch git-04-b66cf03e673e84902ce0330f88f84f4fbdc8c9e9.patch
- Restore old position of ssh/sudo source of profile<br>for bug bsc#1118364 but hopefully do not reintroduce  
    bug boo#1088524<br>- Add patch git-03-00d332a443062395957f422c89eaed9d0979ec00.patch
- update logic for JRE_HOME env variable (bsc#1128246)
- Add patch git-01-61c106aac03930e03935172eaf94d92c02a343bd.patch<br>Let bash.bashrc work even for (m)ksh (boo#1104531)<br>- Add patch git-02-4e5fe2a6ec5690b51a369d2134a1119962438fd1.patch<br>No error at login if java system directory is empty (bsc#1102310)<br>- Update to version 84.87+git20180409.04c9dae:
- In bash.bashrc move ssh/sudo source of profile to avoid removing<br>the `is' variable before last use (boo#1088524).<br>- Avoid the shell code checker stumble over `function' keys word<br>in ls.bash (git#54).<br>- Use %license (boo#1082318)
- Update to version 84.87+git20180208.8eeab90:
- Don't call fillup for removed sysconfig.news
- Adjust path for script converting sysctl config
- For ksh use builtin keyword 'function' to make sure that the<br>keyword 'typeset' really set the variable IFS to be local within  
    the function _ls.<br>- Update to version 84.87+git20180205.2d2832f:
- Move /lib/aaa_base/convert_sysctl to /usr/lib/base-scripts/convert_sysctl<br>to cleanup filesystem.<br>- Don't create /etc/init.d/{boot.local,after.local,halt.local} in<br>aaa_base.pre section.<br>- Remove dead code from pre/post install sections.
- Add /var/adm/backup subdirectories to aaa_base-extras, they are<br>only needed by this package.<br>- Update to version 84.87+git20180204.875cba8:
- Move sysconfig.backup into extra subpackage, where all the<br>scripts using it are, too.<br>- Create systemd timer for the cron.daily scripts for backup-rpmdb,<br>backup-sysconfig and check-battery. Move scripts to  
    /usr/lib/base-scripts.<br>- Remove suse.de-cron-local. If somebody really still has a<br>/root/cron.daily.local file, he can move it to /etc/cron.daily.<br>- Don't modify data in root's home directory
- Don't create userdel.local, this isn't in use since many years
- Update to version 84.87+git20180130.ae1f262:
- Really remove /usr/sbin/Check, obsolete since 8 years
- Remove ChangeSymlinks, 90% are obsolete, the rest is dangerous
- Remove 14 year old outdated documentation and dummy scripts for<br>Java<br>- Update to version 84.87+git20180130.36ea161:
- Remove obsolete/outdated manual pages (route.conf.5,init.d.7,<br>quick_halt.8)<br>- Cleanup PreReq and move some parts to Requires(post), so that<br>we can deinstall them if we no longer need them<br>- Update to version 84.87+git20171201.65000be:
- Revert changes on sysconfig language and make lang.(c)sh<br>to use sysconfig language as fallback or better use  
    locale.conf as default. See discussion in bsc#1069971  
    and FATE#319454 as well<br>- Update to version 84.87+git20171130.974ac5c:
- Better parsing of sh variable settings in lang.csh
- Update to version 84.87+git20171129.a45b936:
- Remove RC_* variables from language sysconf template<br>(bsc#1069971 as well as FATE#319454)<br>- Update to version 84.87+git20171128.945b960:
- lang.(c)sh: catch if ROOT_USES_LANG becomes not set
- Update to version 84.87+git20171128.aa232d3:
- Add wsl specific code to profile.d/wsl.csh
- move wsl specific code from profile into profile.d/wsl.sh
- Remove obsolete &quot;/make package&quot;/
- Update to version 84.87+git20171128.a6752e8:
- lang.(c)sh: handle locale.conf if sysconfig does not
- lang.(c)sh: handle locale.conf if sysconfig does not provide<br>default locale (bsc#1069971, FATE#319454)<br>- Update to version 84.87+git20171128.17ae554:
- Check for /proc/version before using it
- Remove legacy code for /proc/iSeries
- Move fillup-templates to /usr/share (boo#1069468)
- Fix installation of fillup-templates.
- Replace references to /var/adm/fillup-templates with new<br>%_fillupdir macro (boo#1069468)<br>- use TW versioning, 13.2 is misleading
- Update to version 84.87+git20171120.d36b8b1:
- Fix double sourcing of /etc/bash_completion.d
- create wsl.sh in /etc/profile.d to set umask in WSL
- Add support for /usr/bin/fish (boo#1068840)
- Get mixed use case of service wrapper script straight (bsc#1040613)
- Update to version 13.2+git20170828.8f12a9e:
- profile: don't override PATH in WSL
- Remove passwd, group and shadow files. Remove %ghost entry for<br>/run/utmp, /var/log/wtmp and /var/log/btmp, systemd is taking  
    care of them<br>- Remove run/utmp, too.
- Update to version 13.2+git20170814.cc9e34e:
- Unset id in csh.cshrc instead of profile.csh (bsc#1049577)
- Restore the is variable within /etc/profile
- Update to version 13.2+git20170731.c10ca77:
- Fix csh.cshrc as tcsh does not handle stderr
- Do not set alias cwdcmd for experts (boo#1045889)
- unset unused variables on profile files (bsc#1049577)
- Deprecate DEFAULT_WM in sysconfig.windowmanager
- Fix csh.cshrc as tcsh does not handle stderr messages within {}<br>well (boo#1044876)<br>- Fix copy+paste error in /etc/csh.login boo#1043560
- Support changing PS1 even for mksh and user root (bsc#1036895)
- Be aware that on s390/s390x the ttyS0 is misused
- Reset extended screen TERM variables if no terminfo
- Better status line support even for tcsh
- Modernize /etc/ttytype as tset of ncurses use it
- Off application keypad (keyboard transmit) mode
- Missed a meta prefix in new inputrs.keys
- More 8bit key escape control sequences for XTerm
- Do not set INPUTRC as readline does know personal as well as system<br>inputrc also make /etc/inputrc do set know sequences for both vi  
  line editing modes as well as for emacs line editing mode.<br>- Do remove patch aaa_base-13.2+git20170308.c0ecf2e.dif not<br>only from package but also from spec file<br>- Update to version 13.2+git20170425.47e703a:
- Add Enlightenment to the list of windowmanagers
- Add a number of audio/video formats to be colorized
- Revert &quot;/Avoid NAT on Bridges. Bridges are L2 devices, really.&quot;/
- aaa_base.pre: drop some system users from aaa_base and create them in the respective packages: bin,daemon,news,uucp,games,man
- Remove /var/log/faillog, there no application using this left [bsc#980484]
- Remove users and groups sys, mail, lp, wwwrun, ftp and nobody
- Make lang.csh work again (bsc#1025673)
- Update to version 13.2+git20170306.3deb627:
- aaa_base.pre: drop some system users from aaa_base and create<br>them in the respective packages: bin,daemon,news,uucp,games,man<br>- Update to version 13.2+git20160915.106a00d:
- enhance comment for NO_PROXY variable (bsc#990254)
- Fix spelling of SUSE (skipped copyright statements - they need more thoughts)
- fix regression introduced by fix for bnc#971567 (bnc#996442)
- Correct logic error in usage of variable restricted (boo#994111)
- enhance comment for NO_PROXY variable (bsc#990254)
- Update to version 13.2+git20160807.7f4c8c4:
- switch IPv6 privacy extensions (use_tempaddr) back to 1
- history see bsc#678066,bsc#752842,bsc#988023,bsc#990838
- Do not use the = sign for setenv in /etc/profile.d/lang.csh
- Follow the bash manual page that is respect --norc and --noprofile
- Update to version 13.2+git20160609.bf76b13:
- Mark scripts /etc/init.d/{boot.,after-,halt.}local as deprecated
- lang.sh, lang.csh: if GDM_LANG equals system LANG then use system defaults
- Update to version 13.2+git20160530.bd5210c:<br>+ Let the ~/.i18n values parsed as well if GDM_LANG is set (boo#958295)  
  + Remove spurious assignment to unknown variable term from /etc/inputrc  
  + chkconfig: return 1 trying to list unknown service (bnc#971567)  
  + chckconfig: add --no-systemctl option  
  + fix typo in last patch (no-systemctl support for chkconfig)  
  + lang.sh, lang.csh: allow GDM to override locale  
  + There is no kde4 anymore  
  + Removed '/usr/bin/X11' from PATH (boo #982185)<br>- fix typo in last patch (no-systemctl support for chkconfig)
- chckconfig: add --no-systemctl option
- chkconfig: return 1 trying to list unknown service (bnc#971567)
- Merge pull request #26 from andreas-schwab/master
- Remove spurious assignment to unknown variable term from /etc/inputrc
- Let the ~/.i18n values parsed as well if GDM_LANG is set (boo#567324)
- Update to version 13.2+git20151221.244f2a3:<br>+ drop old dns6 hack migration from 2002  
  + remove more dropped variables  
  + make chkconfig -a/-d work (bsc#926539)  
  + avoid recursion if systemd call chkconfig back for sysv units  
  + fix non-working line breaks<br>- make _service generate .changes
- Replace UNICODE double dash with simple ASCII single dash (boo#954909)
- Use the `+' for find's -exec option as this also respects white<br>spaces in files names but is more like xargs.  Respect status  
  of screen sessions.<br>- suse.de-backup-rc.config: trigger also if only files changed<br>that have spaces in their name (bnc#915259)<br>- sysconf_addword: do not insert spaces at start of string (bnc#932456)
- Merge pull request #19 from super7ramp/cleaning-references-to-suseconfig
- drop references to sysconfig/suseconfig
- drop SCANNER_TYPE variable
- Merge pull request #25 from ptesarik/master
- Enable SysRq dump by default
- Revert &quot;/fix /etc/init.d/foo status return code (bnc#931388)&quot;/
- Merge pull request #23 from bmwiedemann/master
- fix /etc/init.d/foo status return code (bnc#931388)
- xdg-environment: reduce list in /opt/* to gnome,kde4,kde3 (bnc#910904)
- add SOCKS5_SERVER and socks_proxy to proxy settings (bnc#928398)
- Simplify version check
- Handle also command lines starting with the env command<br>as this is used by gnome xsessions (bsc#921172)<br>- Correct the boolean in /etc/profile.d/lang.sh
- Even if GDM has done language setup the personal ~/.i18n should<br>be sourced (boo#567324)<br>- Remove the official patch for fate#314974 as now part of systemd
- Merge pull request #21 from arvidjaar/bnc/907873
- Avoid sourcing /etc/bash_completion.d twice
- Fix spelling of SUSE
- Add the official patch for Fate#314974 (bnc#903009)<br>Package acl was updated:<br>- test: Add helper library to fake passwd/group files- quote: escape literal backslashes (bsc#953659).
- Added patch:
- 0001-test-Add-helper-library-to-fake-passwd-group-files.patch
- 0002-quote-escape-literal-backslashes.patch
- refresh acl-2.2.52-tests.patch to work with perl 5.26
- BuildRequires gettext-tools-mini instead of gettext-tools: as<br>acl is part of the bootstrap, we want to try to keep the dep  
  chain as small as possible.<br>- Remove --with-pic that's just for static libraries.
- Replace %__-type macro indirections.<br>Replace old $RPM_ by their macro equivalents for consistency.  
  Make the macro style consistent across the file again.<br>- reenable full Larg File Support for i586
- Make it possible to disable tests (for Ring0)
- Add BuildRequires: system-user-daemon for the testsuite
- Add BuildRequires for system user bin needed by test suite
- Update to git snapshot dated 21 Sep 2015.
- Added:
- 0001-Install-the-libraries-to-the-appropriate-directory.patch
- 0002-setfacl.1-fix-typo-inclu-de-include.patch
- 0003-test-fix-insufficient-quoting-of.patch
- 0004-Makefile-rename-configure.in-to-configure.ac.patch
- 0005-Bad-markup-in-acl.5-page.patch
- 0006-.gitignore-ignore-and-config.h.in.patch
- 0007-Use-autoreconf-rather-than-autoconf-to-regenerate-th.patch
- 0008-libacl-Make-sure-that-acl_from_text-always-sets-errn.patch
- 0009-libacl-fix-SIGSEGV-of-getfacl-e-on-overly-long-group.patch
- 0010-punt-debian-rpm-packaging-logic.patch
- 0011-move-gettext-logic-into-misc.h.patch
- 0012-test-make-running-parallel-out-of-tree-safe.patch
- 0013-modernize-build-system.patch
- 0014-po-regenerate-files-after-move.patch
- 0015-build-drop-aclincludedir-use-pkgincludedir.patch
- 0016-build-make-use-of-an-aux-dir-to-stow-away-helper-scr.patch
- 0017-build-ship-a-pkgconfig-file-for-libacl.patch
- 0018-read_acl_-comments-seq-rename-line-to-lineno.patch
- 0019-read_acl_-comments-seq-switch-to-next_line.patch
- 0020-telldir-return-value-and-seekdir-second-parameters-a.patch
- 0021-mark-libmisc-funcs-as-hidden-so-they-are-not-exporte.patch
- 0022-add-__acl_-prefixes-to-internal-symbols.patch
- 0023-cp.test-Check-permissions-of-the-right-file.patch
- 0024-libacl-acl_set_file-Remove-unnecesary-racy-check.patch
- 0025-fix-compilation-with-latest-xattr-git.patch
- 0026-getfacl-Fix-memory-leak.patch
- 0027-Fix-the-display-block-nesting-in-acl.5.patch
- 0028-setfacl-man-page-Minor-wording-improvements.patch
- 0029-getfacl-Fix-minor-resource-leak.patch
- 0030-Do-not-export-symbols-that-are-not-supposed-to-be-ex.patch
- 0031-walk_tree-mark-internal-variables-as-static.patch
- 0032-ignore-configure.lineno.patch
- Signficant spec file restructuring due to 0013-modernize-build-system.patch
- removed builddefs.in.diff
- Reduce size of filelist by using wildcards;<br>remove %doc (some locations are always %doc),  
  remove %attr (files already have proper permissions)<br>- add acl-2.2.52-tests.patch and enable tests, check section taken<br>from Fedora package<br>- remove gpg-offline calls from bootstrap package
- Update to new upstream release 2.2.52
- This release fixes a few build system issues that were found and<br>merges in a tree walking bug fix.<br>- Remove acl-fiximplicit.patch (merged upstream),<br>config-guess-sub-update.diff (no longer applies)<br>- Sync baselibs.conf with in-.spec obsoletes/provides.
- add gpg checking
- use source url
- Add config-guess-sub-update.diff:<br>update config.guess/sub to latest state for AArch64<br>- Use OS byteswapping routines, application already Includes<br>&quot;/endian.h&quot;/ but then goes ahead defining ad-hoc equivalent  
  functionality (0001-Use-OS-byteswapping-macros.patch)<br>- remove useless automake deps
- patch license to follow [spdx.org](http://spdx.org) standard
- license update: GPL-2.0+;LGPL-2.1+<br>SPDX format<br>- add automake as buildrequire to avoid implicit dependency
- Fix provides/Obsoletes
- Implement shlib package (libacl1)
- Enable libacl-devel on all baselib arches
- upgrade to 2.2.51
- Test fixes
- upgrade to 2.2.50
- OPTIONS in man pages should be a section heading, not a subsection heading
- Fix a typo in the setfacl man page
- setfacl: Clarify that removing a non-existent acl entry is not an error
- Prevent setfacl --restore from SIGSEGV on malformed restore file
- setfacl: make sure that -R only calls stat(2) on symlinks when it needs to
- libacl: fix potential null pointer dereference
- setfacl: fix restore crash on malformed input
- setfacl: print useful error from read_acl_comments
- setfacl: changing owner and when S_ISUID should be set --restore fix
- use %_smp_mflags
- add baselibs.conf as a source
- adjust baselibs.conf for SPARC
- readded incorrectly removed libattr-devel requires in -devel
- fixed implicit strchr() usage.
- do not package static libraries
- fix -devel package dependencies
- Version bump to 2.2.48
- Document the new flags comments
- Include the S_ISUID, S_ISGID, S_ISVTX flags in the getfacl output, and restore them with &quot;/setfacl --restore=file&quot;/.
- Make sure that getfacl -R only calls stat(2) on symlinks when it needs to
- Stop quoting nonprintable characters in the getfacl output
- Avoid unnecessary but destructive chown calls
- Clarify license notice<br>Package apparmor was updated:<br>- update to AppArmor 2.13.6  - fix utils hotkey conflicts in some languages
- aa-autodep: load abstractions on start (boo#1178527)
- add usr.lib.dovecot.script-login profile
- minor additions in abstractions/X and the dovecot profile
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.6](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.6)<br>for the detailed upstream changelog<br>- drop upstreamed patch libapparmor-so-number.diff
- update to AppArmor 2.13.5
- add missing permissions to several profiles and abstractions
- bugfixes in parser and tools
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5)<br>for the detailed upstream changelog<br>- remove upstream(ed) patches
- changes-since-2.13.4.diff
- abstractions-X-xauth-mr582.diff
- sevdb-caps-mr589.diff
- libvirt-leaseshelper.patch
- cap_checkpoint_restore.diff
- add libapparmor-so-number.diff to fix libapparmor so version (!658)
- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656,<br>cap_checkpoint_restore.diff)<br>- %service_del_postun_without_restart only works for Tumbleweed,<br>keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x<br>- Make use of %service_del_postun_without_restart<br>And stop using DISABLE_RESTART_ON_UPDATE as this interface is  
  obsolete.<br>- libvirt-leaseshelper.patch: add /usr/libexec as a path to the<br>libvirt leaseshelper script (jsc#SLE-14253)<br>- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON<br>to severity.db (lp#1890547)<br>- add abstractions-X-xauth-mr582.diff to allow reading the xauth file<br>from its new sddm location (boo#1174290, boo#1174293)<br>- add changes-since-2.13.4.diff with upstream changes and fixes<br>since 2.13.4 up to 5f61bd4c:<br>- add several abstractions related to xdg-open:<br>dbus-network-manager-strict, exo-open, gio-open, gvfs-open,  
    kde-open5, xdg-open<br>- introduce @{run} variable
- update dnsmasq and winbindd profile
- update mdns, mesa and nameservice abstraction
- some bugfixes in the aa-* tools, including a remote bugfix in the<br>YaST AppArmor module (boo#1171315)<br>- drop upstream(ed) patches (now part of changes-since-2.13.4.diff):
- make-4.3-capabilities.diff
- make-4.3-capabilities-vim.diff
- make-4.3-fix-utils-network-test.diff
- make-4.3-network.diff
- abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch
- apply usr-etc-abstractions-base-nameservice.diff only for<br>Tumbleweed, but not for Leap 15.x where it's not needed<br>- refresh usr-etc-abstractions-base-nameservice.diff
- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch<br>(bsc#1168306)<br>- fix build with make 4.3 by backporting some commits from upstream<br>master (boo#1167953):<br>- make-4.3-capabilities.diff
- make-4.3-capabilities-vim.diff
- make-4.3-network.diff
- make-4.3-fix-utils-network-test.diff
- update to AppArmor 2.13.4
- several abstraction updates (including boo#1153162)
- disallow writing to fontconfig cache in abstractions/fonts
- some bugfixes in the aa-* tools
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4)<br>for the detailed upstream changelog<br>- drop upstreamed patches:
- abstractions-ssl-certbot-paths.diff
- apparmor-krb5-conf-d.diff
- libapparmor-python3.8.diff
- usr-etc-abstractions-authentification.diff
- refresh usr-etc-abstractions-base-nameservice.diff
- add usr-etc-abstractions-base-nameservice.diff to adjust<br>abstractions/base and nameservice for /usr/etc/ (boo#1161756)<br>- Properly pull in full python3 interpreter
- add libapparmor-python3.8.diff to fix building the libapparmor python<br>bindings (deb#943657)<br>- add usr-etc-abstractions-authentification.diff to allow reading<br>/usr/etc/pam.d/* and some other authentification-related | 2021-08-25 | [https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp3-chost-byos-v20210729](https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp3-chost-byos-v20210729) |
| SUSE Image SUSE-IU-2021:621-1 | suse | SUSE-IU-2021:621-1 | This image update for google/sles-15-sp3-chost-byos-v20210827 contains the following changes:  
Package SUSEConnect was updated:<br>- Update to 0.3.29- replace env ruby path with native ruby path during build phase
- Recognize more formats when parsing .curlrc for proxy credentials (bsc#1155027)
- Add rpmlintrc to filter false-positive warning about patch not applied
- Update to 0.3.27
- SUSEConnect now ensures that it writes its configuration when it<br>encounters errors. This helps in the situation where SUSEConnect  
  announces itself, but fails during a later step. Without the saved  
  configuration, a system could have credentials, but be unsure which  
  registration proxy they're valid for.<br>- Update to 0.3.26
- Extend the YaST API in order to access to the package search<br>functionality (jsc#SLE-9109)<br>- Don't fail de-activation when '-release' package already got removed
- Update to 0.3.25
- Fix cloud_provider detection on AWS large instances (bsc#1160007)
- Update to 0.3.24
- Forbid de-registration for on-demand Public Cloud instances (bsc#1155911)
- 0.3.23<br>fix .spec file to correctly apply switch_server_cert_location_to_etc.patch to SLE15SP2+ (bsc#1130864)<br>- Update to 0.3.22<br>switch_server_cert_location_to_etc.patch: add patch to switch server cert path for SLE15.2+ to /etc (bsc#1130864)<br>- Update to 0.3.21<br>Fix error on first activation of packagehub extension (bsc#1124318)<br>- Update to 0.3.20
- Fix getting the list of installed products when zypper plugins are<br>present (bsc#1143635)<br>- Update to 0.3.19
- Fix failing on registered system without arguments (bsc#1144020)
- Update to 0.3.18
- Fix base product service removal during de-registration in public clouds (bsc#1136752)
- Update to 0.3.17
- Don't try to remove a service during migration if a zypper service<br>plugin already exists (bsc#1128969)<br>- Replace --no-ri --no-rdoc with --no-document - these options<br>are obsolete since at least ruby 2.1 - and finally removed in  
  ruby 2.6<br>- Only overwrite --bindir on fedora, it will overwrite --buildroot<br>(which needs to be combined on newer fedoras)<br>- Update to 0.3.16
- Show non-enabled extensions with a remark about availability
- Update to 0.3.15
- Output information about registration and de-registration progress
- Output proper message when SUSEConnect is called without parameters (bsc#959561)
- Default to https URI when no protocol prefix is provided for --url
- Support transactional-update systems (fate#326482)
- Changed &quot;/openssl&quot;/ recommendation to &quot;/openssl(cli)&quot;/<br>on SLE 12 SP3+ and SLE 15+ (bsc#1101470).<br>- Update to 0.3.14
- Fix s390 activation fails due to unavailable 'dmidecode' bsc#1112702
- Update to 0.3.13
- Fix migration targets sorting (bsc#1104183)
- Update to 0.3.12
- Detect if system is in cloud provider (AWS/Google/Azure)<br>(fate#320935)<br>- Don't fail when trying to parse an empty body. Fixes bsc#1098220
- Don't install release packages if they are already present
- Fix .spec file for running SUSEConnect on Fedora28
- Weaken dependencies of rmt-client-setup script to Recommends:<br>(bsc#1094348)<br>- Enhance error message generation
- Add not supported operation exception to PackageSearch API
- Update to 0.3.11
- Add dependencies needed by the rmt-client-setup script. bsc#1093658
- Prevent the automatic registration of recommended products that<br>are not mirrored by the registration proxy.<br>- Update to 0.3.10
- Fix rollback mechanism on SLE15 systems (bsc#1089320)
- Update to 0.3.9
- Enable access to package search via gem
- Don't try to delete directory of nonexistent service files<br>(bsc#1086420)<br>- Update to 0.3.8
- Fix list-extensions to show the full SLE 15 tree (bsc#1064264)
- Enable automatic activation of recommended extensions/modules
- Automatically deregister all installed extensions/modules when<br>deregistering a system<br>- Repackage gem
- Remove unnecessary .gz files
- Update to 0.3.7
- virt-create-rootfs connects to SMT server without breaking (bsc#914297)
- Update to 0.3.6
- Make target_base_product parameter mandatory.
- Update to 0.3.5
- Add YaST.system_offline_migrations
- Update to version 0.3.4:
- Packaging improvements (bsc#964013)
- Update to version 0.3.3:
- Fix SLE15 build
- Properly refresh zypper services when deactivating a product on SMT (bsc#1047153)
- Update to 0.3.2:
- Fix --namespace parameter persistence (bsc#1044493)
- Update to 0.3.1:
- Fix license auto-agree issue (bsc#1037783)
- Add missing archs to SLE 12 SP3 build target
- Update to 0.3.0:
- Single product deactivation feature (fate#320572)
- Update to 0.2.43:
- RPM spec fix for openSUSE:Factory rpmlint compliance (bsc#1028660)
- Update to 0.2.42:
- Better error message for network request failure (bsc#982630)
- Fix error message for --product with malformed identifier (bsc#1018190)
- Fix some errors and formatting in manpages and help output
- Update to 0.2.41:
- Better error message for --list-extensions on unregistered systems
- Update to 0.2.40:
- Update man page to include the --list-extensions option (bsc#998583)
- Update to 0.2.39:
- Fix for bnc#990475: support for aarch64 hardware info
- Update to 0.2.38:
- Fix for bnc#975484: better error message if SMT is too old
- Update to 0.2.37:
- Add method to YaST class to get Installer-Updates repositories (fate#319716).
- Update to 0.2.36:
- Fix for bnc#973851: More flexible exit codes handling in internal zypper calls
- Update to 0.2.35:
- Fix for bnc#973315: Direct update from &lt;=0.2.27 does not remove /usr/bin symlink
- Update to 0.2.34:
- Fix for bnc#963996: Do not crash on --list-extensions when connected to SMT
- Fix for bnc#968245: Do not let zypper attempt to read products from remote locations
- Update to 0.2.33:
- Re-add SUSEConnect binary to /usr/sbin (bnc#963080)
- Use `--match-exact` when searching for a product (bnc#952804)
- Fix fonts on xterm (bnc#957354)
- Update to version 0.2.32: Remove unneeded link in %post which caused a warning (bnc#946183)
- Update to version 0.2.31 (bnc#946183)
- Drop url-implies-writeconfig.diff; it is included in upstream since commit 2ef5aa
- Correct RPM group
- Include SCCcredentials file as a ghost entry
- Further packaging improvements
- Update to version 0.2.30
- New packaging spec. One `SUSEConnect` package to rule them all (bnc#951671)
- Update manpages to match the latest CLI options
- Update to version 0.2.29
- bnc#954266 Silently ignore malformed lscpu lines instead of failing
- Update to version 0.2.28
- Properly handle empty repository lists from zypper (bnc#951566)
- Update to version 0.2.27
- Do not install recommended dependencies when installing the product release package (bnc#945462)
- Addd --rollback option (fate#319114)
- Update to version 0.2.26
- zypper migration extremly slow with lot of modules and extensions registered (bnc#945462)
- Update to version 0.2.25
- Solves Allow registration without system uid (dmidecode fails on qemu system) (bnc#934582)
- bnc#949424 ensure version of SUSEConnect is bumped in order to be<br>able to distinct requests from affected YaST version in SCC API<br>- Update to version 0.2.24
- Bug 943451 - [Migration] failure when &quot;/zypper search&quot;/ returns empty list
- Bug 946488 - Synchronization API call returns &quot;/no implicit conversion of Symbol into Integer&quot;/ error
- Bug 941565 - zypper migration not using --releasever
- Bug 945462 - zypper migration extremly slow with lot of modules and extensions registered
- Update to version 0.2.23
- Improve hwinfo detection on physical s390 systems
- Bug 939293 - [S390] Error: Registration failed. Undefined method 'strip' for nil:NilClass (bnc#939293)
- Update to version 0.2.22
- Migration rollback (fate#319114)
- [Migration rollback] zypper migrate: baseproduct mismatch (bnc#941303)
- Update to version 0.2.21
- Escape parameters of remove and add_repository methods
- Update to version 0.2.20
- Add find_products method to migration abstraction layer fate#319140
- Fix add_service method which also creates the credentials files
- Update to version 0.2.19
- Introduction of migration abstraction layer for migration script
- Clean up and re-factoring of yast abstraction layer
- Update to version 0.2.18
- Improve SUSEConnect error messages
- New --cleanup option (remove old system credentials and all zypper services installed by SUSEConnect)
- New --namespace option (forward SMT staging environment to proxy registration server)
- Update to version 0.2.17
- Added migrations endpoint support for Yast
- Use C locale for all the syscalls (solves output parsing issues in some locales)
- Stripping UUID from SCC API calls if it is not settable
- Moved examples from gist to project
- Update to version 0.2.16
- In case of wrong regcode provide meaningful message back to<br>the user (Wrong regcode in that case).<br>- Update to version 0.2.15
- Always write config file when --url parameter used (bnc#900689)<br>Package aaa_base was updated:<br>- Add patch git-33-d12420cc66e6d26a9dff6c0e86e00de232151c82.patch  * Avoid semicolon within (t)csh login script on S/390.<br>(bsc#1179431)<br>- Add patch git-21-0064ecd132c30a939125acbc5b9a1c7bcd180fa0.patch
- add screen.xterm-256color to DIR_COLORS
- Add patch git-22-f5e90d70d119b6aa12d019947029f9337aec378d.patch
- check for Packages.db and use this instead of Packages<br>(boo#1171762)<br>- Add patch git-23-8f1fe28287466235ade9c62fa5995eba9e642660.patch
- Rename path() to _path() to avoid using a general name.
- Add patch git-24-2de52ae391e2963eb1913183a6b0530c7e781b55.patch
- DIR_COLORS add TERM rxvt-unicode-256color (bug#1006973)
- Add patch git-25-287cf7cb851c0636fa46a610015d2d22ad36acea.patch
- sort TERM entries in etc/DIR_COLORS
- Add patch git-26-0c2f2340cc6ebb51f20b36e550adc517a6b2ae42.patch
- DIR_COLORS: merge TERM entries with list from (bug#1006973)
- Add patch git-27-abf7927eebbd4d7f47a362d49ae7856520682c49.patch
- refresh_initrd call modprobe as /sbin/modprobe (bug#1011548)
- Add patch git-28-3351bcc9613ba022503103e7e4ffd01e7bd8e0fd.patch
- etc/profile add some missing ;; in case esac statements
- Add patch git-29-5220a5f6ba250503ccda326e65ca069d245a5ebe.patch
- profile and csh.login: on s390x set TERM to dumb on serial console<br>for sclp_line0 and ttyS0 console (bug#1153946)<br>- Add patch git-30-b9dd70f33a124556f16dbbafc89585a82218ad61.patch
- backup-rpmdb: exit if zypp.pid is there and running<br>(bug#1161239)<br>- Add patch git-31-52dc403d54f2c926ee5cc892d1a8a830a45d7412.patch
- also add color alias for ip command, jira#sle-9880, bsc#1153943
- Add patch git-32-0ee79834ea9ebf6573a7b903f374c21e53a56c14.patch
- alias.bash check if ip command knows color=auto (jsc#SLE-7679)
- Add patch git-19-1149066a54a372b30b7cbd79cd222e11d96dc984.patch
- Not all XTerm based emulators do have an terminfo entry (boo#1087982)
- Add patch git-20-6452441f2054b4b290c089ce6269889993b95fc1.patch
- Better support of Midnight Commander (bsc#1170527)
- Add patch git-16-ed897a1090cafb678f75dbed8802bd671d3c1921.patch<br>get_kernel_version: fix for current kernel on s390x (from azouhr)  
  (bsc#1151023) (bsc#1139939)<br>- Add patch git-17-fe967bddbd74af9aba435900878397c0c7ea0b0b.patch<br>added &quot;/-h&quot;//&quot;/--help&quot;/ to &quot;/old&quot;/ command (from Bernhard Lang)<br>- Add patch git-18-bb11f02d5dd940803c08d25b0cfd3650d9de7d41.patch<br>change feedback url from [http://www.suse.de/feedback](http://www.suse.de/feedback) to  
  [https://github.com/openSUSE/aaa_base/issues](https://github.com/openSUSE/aaa_base/issues)<br>- Add patch git-15-27e2c6180a45cca63d71ffa5de7b32dec749d2cd.patch<br>change rp_filter to 2 to follow the current default (bsc#1160735)<br>- Add patch git-14-12023f2e8aae5b2ac3a895301945566b9f5eb9c3.patch<br>drop dev.cdrom.autoclose = 0 from sysctl config (bsc#1160970)<br>- Clear broken ghost entry in patch<br>git-13-14003c19eaa863ae9d80a0ebb9b5cab6273a5a9e.patch  
  which breaks (lib)readline (bsc#1157278)<br>- Add patch git-13-14003c19eaa863ae9d80a0ebb9b5cab6273a5a9e.patch<br>Use official key binding functions in inputrc  
  that is replace up-history with previous-history, down-history with  
  next-history and backward-delete-word with backward-kill-word  
  (bsc#1084934).  Add some missed key escape sequences for urxvt-unicode  
  terminal as well (boo#1007715).<br>- Add patch git-12-80d14205f913cc67a98c562f988ea700a56c369b.patch
- service: check if there is a second argument before using it<br>(bsc#1051143)<br>- Add patch git-11-b20083a930f766939f47dddc66d089c9fee5d38a.patch
- check if variables can be set before modifying them<br>to avoid warnings on login with a restricted shell  
    (bsc#1138869)<br>- Add patch git-08-9875dffab3ddda0c3e8399f935f059246c961f2a.patch
- Add s390x compressed kernel support (bsc#1151023)
- Add git-09-c6cd010dd8b6efddd71c30f00a923d8f2537584c.patch
- Fix LC_NAME and LC_ADDRESS in sh.ssh
- Add patch git-10-43091e644ff54997468a215b891dcaa75173f133.patch
- fix string test to arithmetic test in /etc/profile.d/wsl.sh
- Add patch git-07-82a17f1689e8957635c8ccaae7c9b3bff7f94d49.patch
- add sysctl.d/51-network.conf to tighten network security a bit<br>see also (boo#1146866) (jira#SLE-9132)<br>- Add patch git-06-8640f848c6677f1149b9765a8c86135956604007.patch
- Make systemd detection cgroup oblivious (bsc#1140647)<br>systemd can work in three exclusive cgroup modes: legacy, hybrid and  
    unified. The mode affects where and what cgroup hierarchies are mounted.  
    detect running systemd as systemd itself does it  
    (src/libsystemd/sd-daemon/sd-daemon.c, function sd_booted)<br>- Add patch git-05-ae2a49183ba0ad9dff6b8c1efd4de076bd34ab0f.patch
- /etc/profile does not work in AppArmor-confined containers<br>(bsc#1096191)<br>- Add patch git-04-b66cf03e673e84902ce0330f88f84f4fbdc8c9e9.patch
- Restore old position of ssh/sudo source of profile<br>for bug bsc#1118364 but hopefully do not reintroduce  
    bug boo#1088524<br>- Add patch git-03-00d332a443062395957f422c89eaed9d0979ec00.patch
- update logic for JRE_HOME env variable (bsc#1128246)
- Add patch git-01-61c106aac03930e03935172eaf94d92c02a343bd.patch<br>Let bash.bashrc work even for (m)ksh (boo#1104531)<br>- Add patch git-02-4e5fe2a6ec5690b51a369d2134a1119962438fd1.patch<br>No error at login if java system directory is empty (bsc#1102310)<br>- Update to version 84.87+git20180409.04c9dae:
- In bash.bashrc move ssh/sudo source of profile to avoid removing<br>the `is' variable before last use (boo#1088524).<br>- Avoid the shell code checker stumble over `function' keys word<br>in ls.bash (git#54).<br>- Use %license (boo#1082318)
- Update to version 84.87+git20180208.8eeab90:
- Don't call fillup for removed sysconfig.news
- Adjust path for script converting sysctl config
- For ksh use builtin keyword 'function' to make sure that the<br>keyword 'typeset' really set the variable IFS to be local within  
    the function _ls.<br>- Update to version 84.87+git20180205.2d2832f:
- Move /lib/aaa_base/convert_sysctl to /usr/lib/base-scripts/convert_sysctl<br>to cleanup filesystem.<br>- Don't create /etc/init.d/{boot.local,after.local,halt.local} in<br>aaa_base.pre section.<br>- Remove dead code from pre/post install sections.
- Add /var/adm/backup subdirectories to aaa_base-extras, they are<br>only needed by this package.<br>- Update to version 84.87+git20180204.875cba8:
- Move sysconfig.backup into extra subpackage, where all the<br>scripts using it are, too.<br>- Create systemd timer for the cron.daily scripts for backup-rpmdb,<br>backup-sysconfig and check-battery. Move scripts to  
    /usr/lib/base-scripts.<br>- Remove suse.de-cron-local. If somebody really still has a<br>/root/cron.daily.local file, he can move it to /etc/cron.daily.<br>- Don't modify data in root's home directory
- Don't create userdel.local, this isn't in use since many years
- Update to version 84.87+git20180130.ae1f262:
- Really remove /usr/sbin/Check, obsolete since 8 years
- Remove ChangeSymlinks, 90% are obsolete, the rest is dangerous
- Remove 14 year old outdated documentation and dummy scripts for<br>Java<br>- Update to version 84.87+git20180130.36ea161:
- Remove obsolete/outdated manual pages (route.conf.5,init.d.7,<br>quick_halt.8)<br>- Cleanup PreReq and move some parts to Requires(post), so that<br>we can deinstall them if we no longer need them<br>- Update to version 84.87+git20171201.65000be:
- Revert changes on sysconfig language and make lang.(c)sh<br>to use sysconfig language as fallback or better use  
    locale.conf as default. See discussion in bsc#1069971  
    and FATE#319454 as well<br>- Update to version 84.87+git20171130.974ac5c:
- Better parsing of sh variable settings in lang.csh
- Update to version 84.87+git20171129.a45b936:
- Remove RC_* variables from language sysconf template<br>(bsc#1069971 as well as FATE#319454)<br>- Update to version 84.87+git20171128.945b960:
- lang.(c)sh: catch if ROOT_USES_LANG becomes not set
- Update to version 84.87+git20171128.aa232d3:
- Add wsl specific code to profile.d/wsl.csh
- move wsl specific code from profile into profile.d/wsl.sh
- Remove obsolete &quot;/make package&quot;/
- Update to version 84.87+git20171128.a6752e8:
- lang.(c)sh: handle locale.conf if sysconfig does not
- lang.(c)sh: handle locale.conf if sysconfig does not provide<br>default locale (bsc#1069971, FATE#319454)<br>- Update to version 84.87+git20171128.17ae554:
- Check for /proc/version before using it
- Remove legacy code for /proc/iSeries
- Move fillup-templates to /usr/share (boo#1069468)
- Fix installation of fillup-templates.
- Replace references to /var/adm/fillup-templates with new<br>%_fillupdir macro (boo#1069468)<br>- use TW versioning, 13.2 is misleading
- Update to version 84.87+git20171120.d36b8b1:
- Fix double sourcing of /etc/bash_completion.d
- create wsl.sh in /etc/profile.d to set umask in WSL
- Add support for /usr/bin/fish (boo#1068840)
- Get mixed use case of service wrapper script straight (bsc#1040613)
- Update to version 13.2+git20170828.8f12a9e:
- profile: don't override PATH in WSL
- Remove passwd, group and shadow files. Remove %ghost entry for<br>/run/utmp, /var/log/wtmp and /var/log/btmp, systemd is taking  
    care of them<br>- Remove run/utmp, too.
- Update to version 13.2+git20170814.cc9e34e:
- Unset id in csh.cshrc instead of profile.csh (bsc#1049577)
- Restore the is variable within /etc/profile
- Update to version 13.2+git20170731.c10ca77:
- Fix csh.cshrc as tcsh does not handle stderr
- Do not set alias cwdcmd for experts (boo#1045889)
- unset unused variables on profile files (bsc#1049577)
- Deprecate DEFAULT_WM in sysconfig.windowmanager
- Fix csh.cshrc as tcsh does not handle stderr messages within {}<br>well (boo#1044876)<br>- Fix copy+paste error in /etc/csh.login boo#1043560
- Support changing PS1 even for mksh and user root (bsc#1036895)
- Be aware that on s390/s390x the ttyS0 is misused
- Reset extended screen TERM variables if no terminfo
- Better status line support even for tcsh
- Modernize /etc/ttytype as tset of ncurses use it
- Off application keypad (keyboard transmit) mode
- Missed a meta prefix in new inputrs.keys
- More 8bit key escape control sequences for XTerm
- Do not set INPUTRC as readline does know personal as well as system<br>inputrc also make /etc/inputrc do set know sequences for both vi  
  line editing modes as well as for emacs line editing mode.<br>- Do remove patch aaa_base-13.2+git20170308.c0ecf2e.dif not<br>only from package but also from spec file<br>- Update to version 13.2+git20170425.47e703a:
- Add Enlightenment to the list of windowmanagers
- Add a number of audio/video formats to be colorized
- Revert &quot;/Avoid NAT on Bridges. Bridges are L2 devices, really.&quot;/
- aaa_base.pre: drop some system users from aaa_base and create them in the respective packages: bin,daemon,news,uucp,games,man
- Remove /var/log/faillog, there no application using this left [bsc#980484]
- Remove users and groups sys, mail, lp, wwwrun, ftp and nobody
- Make lang.csh work again (bsc#1025673)
- Update to version 13.2+git20170306.3deb627:
- aaa_base.pre: drop some system users from aaa_base and create<br>them in the respective packages: bin,daemon,news,uucp,games,man<br>- Update to version 13.2+git20160915.106a00d:
- enhance comment for NO_PROXY variable (bsc#990254)
- Fix spelling of SUSE (skipped copyright statements - they need more thoughts)
- fix regression introduced by fix for bnc#971567 (bnc#996442)
- Correct logic error in usage of variable restricted (boo#994111)
- enhance comment for NO_PROXY variable (bsc#990254)
- Update to version 13.2+git20160807.7f4c8c4:
- switch IPv6 privacy extensions (use_tempaddr) back to 1
- history see bsc#678066,bsc#752842,bsc#988023,bsc#990838
- Do not use the = sign for setenv in /etc/profile.d/lang.csh
- Follow the bash manual page that is respect --norc and --noprofile
- Update to version 13.2+git20160609.bf76b13:
- Mark scripts /etc/init.d/{boot.,after-,halt.}local as deprecated
- lang.sh, lang.csh: if GDM_LANG equals system LANG then use system defaults
- Update to version 13.2+git20160530.bd5210c:<br>+ Let the ~/.i18n values parsed as well if GDM_LANG is set (boo#958295)  
  + Remove spurious assignment to unknown variable term from /etc/inputrc  
  + chkconfig: return 1 trying to list unknown service (bnc#971567)  
  + chckconfig: add --no-systemctl option  
  + fix typo in last patch (no-systemctl support for chkconfig)  
  + lang.sh, lang.csh: allow GDM to override locale  
  + There is no kde4 anymore  
  + Removed '/usr/bin/X11' from PATH (boo #982185)<br>- fix typo in last patch (no-systemctl support for chkconfig)
- chckconfig: add --no-systemctl option
- chkconfig: return 1 trying to list unknown service (bnc#971567)
- Merge pull request #26 from andreas-schwab/master
- Remove spurious assignment to unknown variable term from /etc/inputrc
- Let the ~/.i18n values parsed as well if GDM_LANG is set (boo#567324)
- Update to version 13.2+git20151221.244f2a3:<br>+ drop old dns6 hack migration from 2002  
  + remove more dropped variables  
  + make chkconfig -a/-d work (bsc#926539)  
  + avoid recursion if systemd call chkconfig back for sysv units  
  + fix non-working line breaks<br>- make _service generate .changes
- Replace UNICODE double dash with simple ASCII single dash (boo#954909)
- Use the `+' for find's -exec option as this also respects white<br>spaces in files names but is more like xargs.  Respect status  
  of screen sessions.<br>- suse.de-backup-rc.config: trigger also if only files changed<br>that have spaces in their name (bnc#915259)<br>- sysconf_addword: do not insert spaces at start of string (bnc#932456)
- Merge pull request #19 from super7ramp/cleaning-references-to-suseconfig
- drop references to sysconfig/suseconfig
- drop SCANNER_TYPE variable
- Merge pull request #25 from ptesarik/master
- Enable SysRq dump by default
- Revert &quot;/fix /etc/init.d/foo status return code (bnc#931388)&quot;/
- Merge pull request #23 from bmwiedemann/master
- fix /etc/init.d/foo status return code (bnc#931388)
- xdg-environment: reduce list in /opt/* to gnome,kde4,kde3 (bnc#910904)
- add SOCKS5_SERVER and socks_proxy to proxy settings (bnc#928398)
- Simplify version check
- Handle also command lines starting with the env command<br>as this is used by gnome xsessions (bsc#921172)<br>- Correct the boolean in /etc/profile.d/lang.sh
- Even if GDM has done language setup the personal ~/.i18n should<br>be sourced (boo#567324)<br>- Remove the official patch for fate#314974 as now part of systemd
- Merge pull request #21 from arvidjaar/bnc/907873
- Avoid sourcing /etc/bash_completion.d twice
- Fix spelling of SUSE
- Add the official patch for Fate#314974 (bnc#903009)<br>Package acl was updated:<br>- test: Add helper library to fake passwd/group files- quote: escape literal backslashes (bsc#953659).
- Added patch:
- 0001-test-Add-helper-library-to-fake-passwd-group-files.patch
- 0002-quote-escape-literal-backslashes.patch
- refresh acl-2.2.52-tests.patch to work with perl 5.26
- BuildRequires gettext-tools-mini instead of gettext-tools: as<br>acl is part of the bootstrap, we want to try to keep the dep  
  chain as small as possible.<br>- Remove --with-pic that's just for static libraries.
- Replace %__-type macro indirections.<br>Replace old $RPM_ by their macro equivalents for consistency.  
  Make the macro style consistent across the file again.<br>- reenable full Larg File Support for i586
- Make it possible to disable tests (for Ring0)
- Add BuildRequires: system-user-daemon for the testsuite
- Add BuildRequires for system user bin needed by test suite
- Update to git snapshot dated 21 Sep 2015.
- Added:
- 0001-Install-the-libraries-to-the-appropriate-directory.patch
- 0002-setfacl.1-fix-typo-inclu-de-include.patch
- 0003-test-fix-insufficient-quoting-of.patch
- 0004-Makefile-rename-configure.in-to-configure.ac.patch
- 0005-Bad-markup-in-acl.5-page.patch
- 0006-.gitignore-ignore-and-config.h.in.patch
- 0007-Use-autoreconf-rather-than-autoconf-to-regenerate-th.patch
- 0008-libacl-Make-sure-that-acl_from_text-always-sets-errn.patch
- 0009-libacl-fix-SIGSEGV-of-getfacl-e-on-overly-long-group.patch
- 0010-punt-debian-rpm-packaging-logic.patch
- 0011-move-gettext-logic-into-misc.h.patch
- 0012-test-make-running-parallel-out-of-tree-safe.patch
- 0013-modernize-build-system.patch
- 0014-po-regenerate-files-after-move.patch
- 0015-build-drop-aclincludedir-use-pkgincludedir.patch
- 0016-build-make-use-of-an-aux-dir-to-stow-away-helper-scr.patch
- 0017-build-ship-a-pkgconfig-file-for-libacl.patch
- 0018-read_acl_-comments-seq-rename-line-to-lineno.patch
- 0019-read_acl_-comments-seq-switch-to-next_line.patch
- 0020-telldir-return-value-and-seekdir-second-parameters-a.patch
- 0021-mark-libmisc-funcs-as-hidden-so-they-are-not-exporte.patch
- 0022-add-__acl_-prefixes-to-internal-symbols.patch
- 0023-cp.test-Check-permissions-of-the-right-file.patch
- 0024-libacl-acl_set_file-Remove-unnecesary-racy-check.patch
- 0025-fix-compilation-with-latest-xattr-git.patch
- 0026-getfacl-Fix-memory-leak.patch
- 0027-Fix-the-display-block-nesting-in-acl.5.patch
- 0028-setfacl-man-page-Minor-wording-improvements.patch
- 0029-getfacl-Fix-minor-resource-leak.patch
- 0030-Do-not-export-symbols-that-are-not-supposed-to-be-ex.patch
- 0031-walk_tree-mark-internal-variables-as-static.patch
- 0032-ignore-configure.lineno.patch
- Signficant spec file restructuring due to 0013-modernize-build-system.patch
- removed builddefs.in.diff
- Reduce size of filelist by using wildcards;<br>remove %doc (some locations are always %doc),  
  remove %attr (files already have proper permissions)<br>- add acl-2.2.52-tests.patch and enable tests, check section taken<br>from Fedora package<br>- remove gpg-offline calls from bootstrap package
- Update to new upstream release 2.2.52
- This release fixes a few build system issues that were found and<br>merges in a tree walking bug fix.<br>- Remove acl-fiximplicit.patch (merged upstream),<br>config-guess-sub-update.diff (no longer applies)<br>- Sync baselibs.conf with in-.spec obsoletes/provides.
- add gpg checking
- use source url
- Add config-guess-sub-update.diff:<br>update config.guess/sub to latest state for AArch64<br>- Use OS byteswapping routines, application already Includes<br>&quot;/endian.h&quot;/ but then goes ahead defining ad-hoc equivalent  
  functionality (0001-Use-OS-byteswapping-macros.patch)<br>- remove useless automake deps
- patch license to follow [spdx.org](http://spdx.org) standard
- license update: GPL-2.0+;LGPL-2.1+<br>SPDX format<br>- add automake as buildrequire to avoid implicit dependency
- Fix provides/Obsoletes
- Implement shlib package (libacl1)
- Enable libacl-devel on all baselib arches
- upgrade to 2.2.51
- Test fixes
- upgrade to 2.2.50
- OPTIONS in man pages should be a section heading, not a subsection heading
- Fix a typo in the setfacl man page
- setfacl: Clarify that removing a non-existent acl entry is not an error
- Prevent setfacl --restore from SIGSEGV on malformed restore file
- setfacl: make sure that -R only calls stat(2) on symlinks when it needs to
- libacl: fix potential null pointer dereference
- setfacl: fix restore crash on malformed input
- setfacl: print useful error from read_acl_comments
- setfacl: changing owner and when S_ISUID should be set --restore fix
- use %_smp_mflags
- add baselibs.conf as a source
- adjust baselibs.conf for SPARC
- readded incorrectly removed libattr-devel requires in -devel
- fixed implicit strchr() usage.
- do not package static libraries
- fix -devel package dependencies
- Version bump to 2.2.48
- Document the new flags comments
- Include the S_ISUID, S_ISGID, S_ISVTX flags in the getfacl output, and restore them with &quot;/setfacl --restore=file&quot;/.
- Make sure that getfacl -R only calls stat(2) on symlinks when it needs to
- Stop quoting nonprintable characters in the getfacl output
- Avoid unnecessary but destructive chown calls
- Clarify license notice<br>Package apparmor was updated:<br>- update to AppArmor 2.13.6  - fix utils hotkey conflicts in some languages
- aa-autodep: load abstractions on start (boo#1178527)
- add usr.lib.dovecot.script-login profile
- minor additions in abstractions/X and the dovecot profile
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.6](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.6)<br>for the detailed upstream changelog<br>- drop upstreamed patch libapparmor-so-number.diff
- update to AppArmor 2.13.5
- add missing permissions to several profiles and abstractions
- bugfixes in parser and tools
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5)<br>for the detailed upstream changelog<br>- remove upstream(ed) patches
- changes-since-2.13.4.diff
- abstractions-X-xauth-mr582.diff
- sevdb-caps-mr589.diff
- libvirt-leaseshelper.patch
- cap_checkpoint_restore.diff
- add libapparmor-so-number.diff to fix libapparmor so version (!658)
- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656,<br>cap_checkpoint_restore.diff)<br>- %service_del_postun_without_restart only works for Tumbleweed,<br>keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x<br>- Make use of %service_del_postun_without_restart<br>And stop using DISABLE_RESTART_ON_UPDATE as this interface is  
  obsolete.<br>- libvirt-leaseshelper.patch: add /usr/libexec as a path to the<br>libvirt leaseshelper script (jsc#SLE-14253)<br>- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON<br>to severity.db (lp#1890547)<br>- add abstractions-X-xauth-mr582.diff to allow reading the xauth file<br>from its new sddm location (boo#1174290, boo#1174293)<br>- add changes-since-2.13.4.diff with upstream changes and fixes<br>since 2.13.4 up to 5f61bd4c:<br>- add several abstractions related to xdg-open:<br>dbus-network-manager-strict, exo-open, gio-open, gvfs-open,  
    kde-open5, xdg-open<br>- introduce @{run} variable
- update dnsmasq and winbindd profile
- update mdns, mesa and nameservice abstraction
- some bugfixes in the aa-* tools, including a remote bugfix in the<br>YaST AppArmor module (boo#1171315)<br>- drop upstream(ed) patches (now part of changes-since-2.13.4.diff):
- make-4.3-capabilities.diff
- make-4.3-capabilities-vim.diff
- make-4.3-fix-utils-network-test.diff
- make-4.3-network.diff
- abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch
- apply usr-etc-abstractions-base-nameservice.diff only for<br>Tumbleweed, but not for Leap 15.x where it's not needed<br>- refresh usr-etc-abstractions-base-nameservice.diff
- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch<br>(bsc#1168306)<br>- fix build with make 4.3 by backporting some commits from upstream<br>master (boo#1167953):<br>- make-4.3-capabilities.diff
- make-4.3-capabilities-vim.diff
- make-4.3-network.diff
- make-4.3-fix-utils-network-test.diff
- update to AppArmor 2.13.4
- several abstraction updates (including boo#1153162)
- disallow writing to fontconfig cache in abstractions/fonts
- some bugfixes in the aa-* tools
- see [https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4](https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4)<br>for the detailed upstream changelog<br>- drop upstreamed patches:
- abstractions-ssl-certbot-paths.diff
- apparmor-krb5-conf-d.diff
- libapparmor-python3.8.diff
- usr-etc-abstractions-authentification.diff
- refresh usr-etc-abstractions-base-nameservice.diff
- add usr-etc-abstractions-base-nameservice.diff to adjust<br>abstractions/base and nameservice for /usr/etc/ (boo#1161756)<br>- Properly pull in full python3 interpreter
- add libapparmor-python3.8.diff to fix building the libapparmor python<br>bindings (deb#943657)<br>- add usr-etc-abstractions-authentification.diff to allow reading<br>/usr/etc/pam.d/* and some other authentification-related | 2021-09-09 | [https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp3-chost-byos-v20210827](https://publiccloudimagechangeinfo.suse.com/google/sles-15-sp3-chost-byos-v20210827) |
| usn-4099-1 | canonical | nginx vulnerabilities | Jonathan Looney discovered that nginx incorrectly handled the HTTP/2  
implementation. A remote attacker could possibly use this issue to consume  
resources, leading to a denial of service. | 2020-07-29 | [https://ubuntu.com/security/notices/USN-4099-1](https://ubuntu.com/security/notices/USN-4099-1) |
| DSA-4511 | debian | DSA-4511-1 nghttp2 -- security update | Two vulnerabilities were discovered in the HTTP/2 code of the nghttp2  
HTTP server, which could result in denial of service.  
For the oldstable distribution (stretch), these problems have been fixed  
in version 1.18.1-1+deb9u1.  
For the stable distribution (buster), these problems have been fixed in  
version 1.36.0-2+deb10u1.  
We recommend that you upgrade your nghttp2 packages.  
For the detailed security status of nghttp2 please refer to  
its security tracker page at:  
[https://security-tracker.debian.org/tracker/nghttp2](https://security-tracker.debian.org/tracker/nghttp2) | 2020-10-10 | [https://www.debian.org/security/2019/dsa-4511](https://www.debian.org/security/2019/dsa-4511) |
| SUSE-SU-2019:14246-1 | suse | Security update for Mozilla Firefox | This update contains the Mozilla Firefox ESR 68.2 release.<br>Mozilla Firefox was updated to ESR 68.2 release:<br>- Enterprise: New administrative policies were added. More<br>information and templates are available at the Policy  
  Templates page.<br>- Various security fixes:<br>MFSA 2019-33 (bsc#1154738)<br>- CVE-2019-15903: Heap overflow in expat library in XML_GetCurrentLineNumber
- CVE-2019-11757: Use-after-free when creating index updates in IndexedDB
- CVE-2019-11758: Potentially exploitable crash due to 360 Total Security
- CVE-2019-11759: Stack buffer overflow in HKDF output
- CVE-2019-11760: Stack buffer overflow in WebRTC networking
- CVE-2019-11761: Unintended access to a privileged JSONView object
- CVE-2019-11762: document.domain-based origin isolation has same-origin- property violation
- CVE-2019-11763: Incorrect HTML parsing results in XSS bypass technique
- CVE-2019-11764: Memory safety bugs fixed in Firefox 70 and Firefox ESR 68.2<br>Other Issues resolved:<br>- [bsc#1104841] Newer versions of firefox have a dependency on<br>GLIBCXX_3.4.20<br>- [bsc#1074235] MozillaFirefox: background tab crash reports sent<br>inadvertently without user opt-in<br>- [bsc#1043008] Firefox hangs randomly when browsing and<br>scrolling<br>- [bsc#1025108] Firefox stops loading page until mouse is moved
- [bsc#905528]  Firefox malfunctions due to broken omni.ja<br>archives | 2019-12-12 | [https://www.suse.com/support/update/announcement/2019/suse-su-201914246-1/](https://www.suse.com/support/update/announcement/2019/suse-su-201914246-1/) |
| SUSE-SU-2019:2254-1 | suse | Security update for nodejs10 | This update for nodejs10 to version 10.16.3 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093). | 2019-08-31 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192254-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192254-1/) |
| SUSE-SU-2019:2259-1 | suse | Security update for nodejs10 | This update for nodejs10 to version 10.16.3 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093). | 2020-09-25 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192259-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192259-1/) |
| SUSE-SU-2019:2260-1 | suse | Security update for nodejs8 | This update for nodejs8 to version 8.16.1 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146091).
- CVE-2019-9512: Fixed HTTP/2 flood using PING frames results in unbounded memory growth (bsc#1146099).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service. (bsc#1146094).
- CVE-2019-9514: Fixed HTTP/2 implementation that is vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed HTTP/2 flood using SETTINGS frames results in unbounded memory growth (bsc#1146100).
- CVE-2019-9516: Fixed HTTP/2 implementation that is vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed HTTP/2 implementations that are vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed HTTP/2 implementation that is vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).<br>Bug fixes:<br>- Fixed that npm resolves its default config file like in all other versions, as /etc/nodejs/npmrc (bsc#1144919). | 2020-09-25 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192260-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192260-1/) |
| SUSE-SU-2019:2309-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582).
- CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015).
- CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022).
- CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025). | 2019-09-06 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192309-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192309-1/) |
| SUSE-SU-2019:2473-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#11461).<br>Bug fixes and enhancements:<br>- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Feature: Add W&S module (FATE#326776, bsc#1112438) | 2019-09-27 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192473-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192473-1/) |
| SUSE-SU-2019:2559-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>Security issues fixed:<br>- CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579).
- CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580).
- CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582). | 2019-10-05 | [https://www.suse.com/support/update/announcement/2019/suse-su-20192559-1/](https://www.suse.com/support/update/announcement/2019/suse-su-20192559-1/) |
| SUSE-SU-2020:0059-1 | suse | Security update for nodejs12 | This update for nodejs12 fixes the following issues:<br>Update to LTS release 12.13.0 (jsc#SLE-8947).<br>Security issues fixed:<br>- CVE-2019-9511: Fixed the HTTP/2 implementation that was vulnerable to window size manipulations (bsc#1146091).
- CVE-2019-9512: Fixed the HTTP/2 implementation that was vulnerable to floods using PING frames (bsc#1146099).
- CVE-2019-9513: Fixed the HTTP/2 implementation that was vulnerable to resource loops, potentially leading to a denial of service (bsc#1146094).
- CVE-2019-9514: Fixed the HTTP/2 implementation that was vulnerable to a reset flood, potentially leading to a denial of service (bsc#1146095).
- CVE-2019-9515: Fixed the HTTP/2 implementation that was vulnerable to a SETTINGS frame flood (bsc#1146100).
- CVE-2019-9516: Fixed the HTTP/2 implementation that was vulnerable to a header leak, potentially leading to a denial of service (bsc#1146090).
- CVE-2019-9517: Fixed the HTTP/2 implementation that was vulnerable to unconstrained interal data buffering (bsc#1146097).
- CVE-2019-9518: Fixed the HTTP/2 implementation that was vulnerable to a flood of empty frames, potentially leading to a denial of service (bsc#1146093).
- CVE-2019-13173: Fixed a file overwrite in the fstream.DirWriter() function (bsc#1140290). | 2020-01-17 | [https://www.suse.com/support/update/announcement/2020/suse-su-20200059-1/](https://www.suse.com/support/update/announcement/2020/suse-su-20200059-1/) |
| SUSE-SU-2021:0932-1 | suse | Security update for nghttp2 | This update for nghttp2 fixes the following issues:<br>Security issues fixed:<br>- CVE-2020-11080: HTTP/2 Large Settings Frame DoS (bsc#1181358).
- CVE-2019-9513: Fixed HTTP/2 implementation that is vulnerable to resource loops, potentially leading to a denial of service (bsc#1146184).
- CVE-2019-9511: Fixed HTTP/2 implementations that are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service (bsc#1146182).
- CVE-2018-1000168: Fixed ALTSVC frame client side denial of service (bsc#1088639).
- CVE-2016-1544: Fixed out of memory due to unlimited incoming HTTP header fields (bsc#966514).<br>Bug fixes and enhancements:<br>- Packages must not mark license files as %doc (bsc#1082318)
- Typo in description of libnghttp2_asio1 (bsc#962914)
- Fixed mistake in spec file (bsc#1125689)
- Fixed build issue with boost 1.70.0 (bsc#1134616)
- Fixed build issue with GCC 6 (bsc#964140)
- Feature: Add W&S module (FATE#326776, bsc#1112438) | 2021-03-27 | [https://www.suse.com/support/update/announcement/2021/suse-su-20210932-1/](https://www.suse.com/support/update/announcement/2021/suse-su-20210932-1/) |