Oval Definition:oval:org.opensuse.security:def:63821
Revision Date:2020-12-01Version:1
Title:Security update for libseccomp (Moderate)
Description:

This update for libseccomp fixes the following issues:

Update to new upstream release 2.4.1:

Fix a BPF generation bug where the optimizer mistakenly identified duplicate BPF code blocks.

Updated to 2.4.0 (bsc#1128828 CVE-2019-9893):

Update the syscall table for Linux v5.0-rc5 * Added support for the SCMP_ACT_KILL_PROCESS action * Added support for the SCMP_ACT_LOG action and SCMP_FLTATR_CTL_LOG attribute * Added explicit 32-bit (SCMP_AX_32(...)) and 64-bit (SCMP_AX_64(...)) argument comparison macros to help protect against unexpected sign extension * Added support for the parisc and parisc64 architectures * Added the ability to query and set the libseccomp API level via seccomp_api_get(3) and seccomp_api_set(3) * Return -EDOM on an endian mismatch when adding an architecture to a filter * Renumber the pseudo syscall number for subpage_prot() so it no longer conflicts with spu_run() * Fix PFC generation when a syscall is prioritized, but no rule exists * Numerous fixes to the seccomp-bpf filter generation code * Switch our internal hashing function to jhash/Lookup3 to MurmurHash3 * Numerous tests added to the included test suite, coverage now at ~92% * Update our Travis CI configuration to use Ubuntu 16.04 * Numerous documentation fixes and updates

Update to release 2.3.3:

Updated the syscall table for Linux v4.15-rc7

Update to release 2.3.2:

Achieved full compliance with the CII Best Practices program * Added Travis CI builds to the GitHub repository * Added code coverage reporting with the '--enable-code-coverage' configure flag and added Coveralls to the GitHub repository * Updated the syscall tables to match Linux v4.10-rc6+ * Support for building with Python v3.x * Allow rules with the -1 syscall if the SCMP\_FLTATR\_API\_TSKIP attribute is set to true * Several small documentation fixes

- ignore make check error for ppc64/ppc64le, bypass bsc#1142614
Family:unixClass:patch
Status:Reference(s):1048942
1051510
1078248
1082318
1082635
1089644
1091041
1108043
1113722
1114279
1117169
1118832
1119396
1126711
1126713
1126821
1126823
1126827
1127122
1128722
1128828
1128883
1128886
1128887
1128889
1128892
1129032
1131107
1132837
1132838
1133534
1134322
1135114
1138039
1140948
1141861
1141862
1142614
1143706
1144333
1146098
1146105
1146107
1149448
1149943
1149944
1150466
1151548
1151900
1152782
1153628
1153681
1153811
1154043
1154058
1154124
1154212
1154355
1154526
1154804
1154805
1154956
1155021
1155198
1155205
1155298
1155678
1155689
1155692
1155819
1155836
1155897
1155921
1155982
1156158
1156187
1156258
1156429
1156466
1156471
1156494
1156609
1156700
1156729
1156882
1157038
1157042
1157070
1157143
1157145
1157158
1157162
1157171
1157173
1157178
1157180
1157182
1157183
1157184
1157191
1157193
1157197
1157298
1157307
1157324
1157333
1157377
1157424
1157463
1157499
1157678
1157698
1157778
1157908
1158049
1158063
1158064
1158065
1158066
1158067
1158068
1158082
1158442
1158763
1159105
1160398
1160520
1160522
1160523
1160524
1160525
1160526
1160527
1169511
1177351
1177352
1178588
CVE-2018-19935
CVE-2018-20783
CVE-2019-11034
CVE-2019-11035
CVE-2019-11036
CVE-2019-14895
CVE-2019-15916
CVE-2019-16231
CVE-2019-17055
CVE-2019-18660
CVE-2019-18683
CVE-2019-18805
CVE-2019-18809
CVE-2019-18900
CVE-2019-19049
CVE-2019-19052
CVE-2019-19056
CVE-2019-19057
CVE-2019-19058
CVE-2019-19060
CVE-2019-19062
CVE-2019-19063
CVE-2019-19065
CVE-2019-19067
CVE-2019-19068
CVE-2019-19073
CVE-2019-19074
CVE-2019-19075
CVE-2019-19077
CVE-2019-19227
CVE-2019-2933
CVE-2019-2945
CVE-2019-2962
CVE-2019-2964
CVE-2019-2973
CVE-2019-2978
CVE-2019-2981
CVE-2019-2983
CVE-2019-2989
CVE-2019-2992
CVE-2019-2999
CVE-2019-9020
CVE-2019-9021
CVE-2019-9022
CVE-2019-9023
CVE-2019-9024
CVE-2019-9637
CVE-2019-9638
CVE-2019-9639
CVE-2019-9640
CVE-2019-9641
CVE-2019-9675
CVE-2019-9848
CVE-2019-9849
CVE-2019-9850
CVE-2019-9851
CVE-2019-9852
CVE-2019-9854
CVE-2019-9855
CVE-2019-9893
CVE-2020-26950
CVE-2020-2754
CVE-2020-2755
CVE-2020-2756
CVE-2020-2757
CVE-2020-2773
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2020-6609
CVE-2020-6610
CVE-2020-6611
CVE-2020-6612
CVE-2020-6613
CVE-2020-6614
CVE-2020-6615
CVE-2020-7069
CVE-2020-7070
openSUSE-SU-2019:1572-1
openSUSE-SU-2019:2183-1
openSUSE-SU-2020:0096-1
openSUSE-SU-2020:0255-1
openSUSE-SU-2020:1703-1
SUSE-SU-2019:2941-1
SUSE-SU-2019:3371-1
SUSE-SU-2020:0051-1
SUSE-SU-2020:0102-1
SUSE-SU-2020:1686-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • apache2-mod_php7-7.2.5-lp151.6.3 is installed
  • OR php7-7.2.5-lp151.6.3 is installed
  • OR php7-bcmath-7.2.5-lp151.6.3 is installed
  • OR php7-bz2-7.2.5-lp151.6.3 is installed
  • OR php7-calendar-7.2.5-lp151.6.3 is installed
  • OR php7-ctype-7.2.5-lp151.6.3 is installed
  • OR php7-curl-7.2.5-lp151.6.3 is installed
  • OR php7-dba-7.2.5-lp151.6.3 is installed
  • OR php7-devel-7.2.5-lp151.6.3 is installed
  • OR php7-dom-7.2.5-lp151.6.3 is installed
  • OR php7-embed-7.2.5-lp151.6.3 is installed
  • OR php7-enchant-7.2.5-lp151.6.3 is installed
  • OR php7-exif-7.2.5-lp151.6.3 is installed
  • OR php7-fastcgi-7.2.5-lp151.6.3 is installed
  • OR php7-fileinfo-7.2.5-lp151.6.3 is installed
  • OR php7-firebird-7.2.5-lp151.6.3 is installed
  • OR php7-fpm-7.2.5-lp151.6.3 is installed
  • OR php7-ftp-7.2.5-lp151.6.3 is installed
  • OR php7-gd-7.2.5-lp151.6.3 is installed
  • OR php7-gettext-7.2.5-lp151.6.3 is installed
  • OR php7-gmp-7.2.5-lp151.6.3 is installed
  • OR php7-iconv-7.2.5-lp151.6.3 is installed
  • OR php7-intl-7.2.5-lp151.6.3 is installed
  • OR php7-json-7.2.5-lp151.6.3 is installed
  • OR php7-ldap-7.2.5-lp151.6.3 is installed
  • OR php7-mbstring-7.2.5-lp151.6.3 is installed
  • OR php7-mysql-7.2.5-lp151.6.3 is installed
  • OR php7-odbc-7.2.5-lp151.6.3 is installed
  • OR php7-opcache-7.2.5-lp151.6.3 is installed
  • OR php7-openssl-7.2.5-lp151.6.3 is installed
  • OR php7-pcntl-7.2.5-lp151.6.3 is installed
  • OR php7-pdo-7.2.5-lp151.6.3 is installed
  • OR php7-pear-7.2.5-lp151.6.3 is installed
  • OR php7-pear-Archive_Tar-7.2.5-lp151.6.3 is installed
  • OR php7-pgsql-7.2.5-lp151.6.3 is installed
  • OR php7-phar-7.2.5-lp151.6.3 is installed
  • OR php7-posix-7.2.5-lp151.6.3 is installed
  • OR php7-readline-7.2.5-lp151.6.3 is installed
  • OR php7-shmop-7.2.5-lp151.6.3 is installed
  • OR php7-snmp-7.2.5-lp151.6.3 is installed
  • OR php7-soap-7.2.5-lp151.6.3 is installed
  • OR php7-sockets-7.2.5-lp151.6.3 is installed
  • OR php7-sodium-7.2.5-lp151.6.3 is installed
  • OR php7-sqlite-7.2.5-lp151.6.3 is installed
  • OR php7-sysvmsg-7.2.5-lp151.6.3 is installed
  • OR php7-sysvsem-7.2.5-lp151.6.3 is installed
  • OR php7-sysvshm-7.2.5-lp151.6.3 is installed
  • OR php7-testresults-7.2.5-lp151.6.3 is installed
  • OR php7-tidy-7.2.5-lp151.6.3 is installed
  • OR php7-tokenizer-7.2.5-lp151.6.3 is installed
  • OR php7-wddx-7.2.5-lp151.6.3 is installed
  • OR php7-xmlreader-7.2.5-lp151.6.3 is installed
  • OR php7-xmlrpc-7.2.5-lp151.6.3 is installed
  • OR php7-xmlwriter-7.2.5-lp151.6.3 is installed
  • OR php7-xsl-7.2.5-lp151.6.3 is installed
  • OR php7-zip-7.2.5-lp151.6.3 is installed
  • OR php7-zlib-7.2.5-lp151.6.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • apache2-mod_php7-7.4.6-lp152.2.9 is installed
  • OR php7-7.4.6-lp152.2.9 is installed
  • OR php7-bcmath-7.4.6-lp152.2.9 is installed
  • OR php7-bz2-7.4.6-lp152.2.9 is installed
  • OR php7-calendar-7.4.6-lp152.2.9 is installed
  • OR php7-ctype-7.4.6-lp152.2.9 is installed
  • OR php7-curl-7.4.6-lp152.2.9 is installed
  • OR php7-dba-7.4.6-lp152.2.9 is installed
  • OR php7-devel-7.4.6-lp152.2.9 is installed
  • OR php7-dom-7.4.6-lp152.2.9 is installed
  • OR php7-embed-7.4.6-lp152.2.9 is installed
  • OR php7-enchant-7.4.6-lp152.2.9 is installed
  • OR php7-exif-7.4.6-lp152.2.9 is installed
  • OR php7-fastcgi-7.4.6-lp152.2.9 is installed
  • OR php7-fileinfo-7.4.6-lp152.2.9 is installed
  • OR php7-firebird-7.4.6-lp152.2.9 is installed
  • OR php7-fpm-7.4.6-lp152.2.9 is installed
  • OR php7-ftp-7.4.6-lp152.2.9 is installed
  • OR php7-gd-7.4.6-lp152.2.9 is installed
  • OR php7-gettext-7.4.6-lp152.2.9 is installed
  • OR php7-gmp-7.4.6-lp152.2.9 is installed
  • OR php7-iconv-7.4.6-lp152.2.9 is installed
  • OR php7-intl-7.4.6-lp152.2.9 is installed
  • OR php7-json-7.4.6-lp152.2.9 is installed
  • OR php7-ldap-7.4.6-lp152.2.9 is installed
  • OR php7-mbstring-7.4.6-lp152.2.9 is installed
  • OR php7-mysql-7.4.6-lp152.2.9 is installed
  • OR php7-odbc-7.4.6-lp152.2.9 is installed
  • OR php7-opcache-7.4.6-lp152.2.9 is installed
  • OR php7-openssl-7.4.6-lp152.2.9 is installed
  • OR php7-pcntl-7.4.6-lp152.2.9 is installed
  • OR php7-pdo-7.4.6-lp152.2.9 is installed
  • OR php7-pgsql-7.4.6-lp152.2.9 is installed
  • OR php7-phar-7.4.6-lp152.2.9 is installed
  • OR php7-posix-7.4.6-lp152.2.9 is installed
  • OR php7-readline-7.4.6-lp152.2.9 is installed
  • OR php7-shmop-7.4.6-lp152.2.9 is installed
  • OR php7-snmp-7.4.6-lp152.2.9 is installed
  • OR php7-soap-7.4.6-lp152.2.9 is installed
  • OR php7-sockets-7.4.6-lp152.2.9 is installed
  • OR php7-sodium-7.4.6-lp152.2.9 is installed
  • OR php7-sqlite-7.4.6-lp152.2.9 is installed
  • OR php7-sysvmsg-7.4.6-lp152.2.9 is installed
  • OR php7-sysvsem-7.4.6-lp152.2.9 is installed
  • OR php7-sysvshm-7.4.6-lp152.2.9 is installed
  • OR php7-test-7.4.6-lp152.2.9 is installed
  • OR php7-tidy-7.4.6-lp152.2.9 is installed
  • OR php7-tokenizer-7.4.6-lp152.2.9 is installed
  • OR php7-xmlreader-7.4.6-lp152.2.9 is installed
  • OR php7-xmlrpc-7.4.6-lp152.2.9 is installed
  • OR php7-xmlwriter-7.4.6-lp152.2.9 is installed
  • OR php7-xsl-7.4.6-lp152.2.9 is installed
  • OR php7-zip-7.4.6-lp152.2.9 is installed
  • OR php7-zlib-7.4.6-lp152.2.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libseccomp-2.4.1-11.3 is installed
  • OR libseccomp2-2.4.1-11.3 is installed
  • OR libseccomp2-32bit-2.4.1-11.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • MozillaFirefox-78.4.1-112.32 is installed
  • OR MozillaFirefox-devel-78.4.1-112.32 is installed
  • OR MozillaFirefox-translations-common-78.4.1-112.32 is installed
  • BACK