SUSE-SU-2022:1128-1

Source
https://www.suse.com/support/update/announcement/2022/suse-su-20221128-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1128-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2022:1128-1
Published
2022-04-07T14:19:28Z
Modified
2022-04-07T14:19:28Z
Summary
Security update for libsolv, libzypp
Details

This update for libsolv, libzypp fixes the following issues:

libsolv to 0.6.39:

  • fix memory leaks in SWIG generated code
  • fix misparsing of '&' in attributes with libxml2
  • try to keep packages from a cycle close togther in the transaction order (bsc#1189622)
  • fix split provides not working if the update includes a forbidden vendor change (bsc#1195485)
  • fix segfault on conflict resolution when using bindings
  • do not replace noarch problem rules with arch dependent ones in problem reporting
  • fix and simplify pool_vendor2mask implementation
  • bump version to 0.6.39

libzypp to 16.22.4:

  • Hint on ptf resolver conflicts (bsc#1194848)
  • Fix package signature check (bsc#1184501) Pay attention that header and payload are secured by a valid signature and report more detailed which signature is missing.
  • Set ZYPP_RPM_DEBUG=1 to capture verbose rpm command output.
References

Affected packages

SUSE:Linux Enterprise Server 12 SP2-BCL / libsolv

Package

Name
libsolv
Purl
pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.39-2.27.32.2

Ecosystem specific

{
    "binaries":  [
        {
            "libsolv-devel":  "0.6.39-2.27.32.2",
            "libsolv-tools":  "0.6.39-2.27.32.2",
            "libzypp":  "16.22.4-27.85.2",
            "libzypp-devel":  "16.22.4-27.85.2",
            "perl-solv":  "0.6.39-2.27.32.2",
            "python-solv":  "0.6.39-2.27.32.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1128-1.json"

SUSE:Linux Enterprise Server 12 SP2-BCL / libzypp

Package

Name
libzypp
Purl
pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.22.4-27.85.2

Ecosystem specific

{
    "binaries":  [
        {
            "libsolv-devel":  "0.6.39-2.27.32.2",
            "libsolv-tools":  "0.6.39-2.27.32.2",
            "libzypp":  "16.22.4-27.85.2",
            "libzypp-devel":  "16.22.4-27.85.2",
            "perl-solv":  "0.6.39-2.27.32.2",
            "python-solv":  "0.6.39-2.27.32.2"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1128-1.json"