{"id":"SUSE-SU-2017:0379-1","summary":"Security update for gcc48","details":"\nThis update for gcc48 to version 4.8.5 fixes several issues.\n\nThis security issue was fixed:\n\n- CVE-2015-5276: The std::random_device class in libstdc++ did not properly handle short reads from blocking sources, which made it easier for context-dependent attackers to predict the random values via unspecified vectors (bsc#945842).\n\nThese non-security issues were fixed:\n\n- Provide missing libasan0-32bit and other multilibs via the updated product description [bsc#951644]\n- Fixed libffi issue for armv7l [bsc#988274]\n- Fixed libffi issue for armv7l [bsc#988274]\n- Fixed a kernel miscompile on aarch64 [bnc#981311]\n- Fixed a ppc64le ICE. [bnc#976627]\n- Fixed issue with using gcov and #pragma pack [bsc#977654]\n- Fixed samba build on AARCH64 [bsc#970009]\n- Fixed HTM builtins on powerpc [bsc#955382]\n- Fixed build of SLOF [bsc#949000]\n- Fixed libffi issues on aarch64 [bsc#948168]\n- Fixed no_instrument_function attribute handling on PPC64 with -mprofile-kernel [bsc#947791]\n- Fixed bogus integer overflow in constant expression [bsc#934689]\n- Fixed ICE with atomics on aarch64 [bsc#930176]\n- Fixed -imacros bug [bsc#917169]\n- Fixed incorrect -Warray-bounds warnings [bsc#919274]\n- Updated -mhotpatch for s390x [bsc#924525]\n- Fixed ppc64le issue with doubleword vector extract [bsc#924687]\n- Fixed reload issue on S390.\n- Keep functions leaf when they are instrumented for profiling on s390[x] [bsc#899871]\n- Avoid accessing invalid memory when passing aggregates by value [bsc#922534]\n- Rework of the memory allocator for C++ exceptions used in OOM situations [bsc#889990]\n","modified":"2026-02-04T03:20:59.629271Z","published":"2017-02-03T17:46:46Z","related":["CVE-2015-5276"],"upstream":["CVE-2015-5276"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20170379-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1011348"},{"type":"REPORT","url":"https://bugzilla.suse.com/889990"},{"type":"REPORT","url":"https://bugzilla.suse.com/899871"},{"type":"REPORT","url":"https://bugzilla.suse.com/917169"},{"type":"REPORT","url":"https://bugzilla.suse.com/919274"},{"type":"REPORT","url":"https://bugzilla.suse.com/922534"},{"type":"REPORT","url":"https://bugzilla.suse.com/924525"},{"type":"REPORT","url":"https://bugzilla.suse.com/924687"},{"type":"REPORT","url":"https://bugzilla.suse.com/930176"},{"type":"REPORT","url":"https://bugzilla.suse.com/934689"},{"type":"REPORT","url":"https://bugzilla.suse.com/945842"},{"type":"REPORT","url":"https://bugzilla.suse.com/947772"},{"type":"REPORT","url":"https://bugzilla.suse.com/947791"},{"type":"REPORT","url":"https://bugzilla.suse.com/948168"},{"type":"REPORT","url":"https://bugzilla.suse.com/949000"},{"type":"REPORT","url":"https://bugzilla.suse.com/951644"},{"type":"REPORT","url":"https://bugzilla.suse.com/955382"},{"type":"REPORT","url":"https://bugzilla.suse.com/970009"},{"type":"REPORT","url":"https://bugzilla.suse.com/976627"},{"type":"REPORT","url":"https://bugzilla.suse.com/977654"},{"type":"REPORT","url":"https://bugzilla.suse.com/981311"},{"type":"REPORT","url":"https://bugzilla.suse.com/988274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5276"}],"affected":[{"package":{"name":"gcc48","ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","purl":"pkg:rpm/suse/gcc48&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.8.5-4.2"}]}],"ecosystem_specific":{"binaries":[{"gcc48":"4.8.5-4.2","libasan0":"4.8.5-4.2","libstdc++48-devel-32bit":"4.8.5-4.2","gcc48-fortran":"4.8.5-4.2","gcc48-info":"4.8.5-4.2","libasan0-32bit":"4.8.5-4.2","libstdc++48-devel":"4.8.5-4.2","cpp48":"4.8.5-4.2","gcc48-32bit":"4.8.5-4.2","gcc48-c++":"4.8.5-4.2","gcc48-fortran-32bit":"4.8.5-4.2","gcc48-locale":"4.8.5-4.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0379-1.json"}}],"schema_version":"1.7.3"}