{"id":"SUSE-SU-2022:1157-2","summary":"Security update for libsolv, libzypp, zypper","details":"This update for libsolv, libzypp, zypper fixes the following issues:\n\nSecurity relevant fix:\n\n- Harden package signature checks (bsc#1184501).\n\nlibsolv update to 0.7.22:\n\n- reworked choice rule generation to cover more usecases\n- support SOLVABLE_PREREQ_IGNOREINST in the ordering code (bsc#1196514)\n- support parsing of Debian's Multi-Arch indicator\n- fix segfault on conflict resolution when using bindings\n- fix split provides not working if the update includes a forbidden vendor change\n- support strict repository priorities\n  new solver flag: SOLVER_FLAG_STRICT_REPO_PRIORITY\n- support zstd compressed control files in debian packages\n- add an ifdef allowing to rename Solvable dependency members ('requires' is a keyword in C++20)\n- support setting/reading userdata in solv files\n  new functions: repowriter_set_userdata, solv_read_userdata\n- support queying of the custom vendor check function\n  new function: pool_get_custom_vendorcheck\n- support solv files with an idarray block\n- allow accessing the toolversion at runtime\n\nlibzypp update to 17.30.0:\n\n- ZConfig: Update solver settings if target changes (bsc#1196368)\n- Fix possible hang in singletrans mode (bsc#1197134)\n- Do 2 retries if mount is still busy.\n- Fix package signature check (bsc#1184501)\n  Pay attention that header and payload are secured by a valid\n  signature and report more detailed which signature is missing.\n- Retry umount if device is busy (bsc#1196061, closes #381)\n  A previously released ISO image may need a bit more time to\n  release it's loop device. So we wait a bit and retry.\n- Fix serializing/deserializing type mismatch in zypp-rpm protocol (bsc#1196925)\n- Fix handling of ISO media in releaseAll (bsc#1196061)\n- Hint on common ptf resolver conflicts (bsc#1194848)\n- Hint on ptf\u003c\u003epatch resolver conflicts (bsc#1194848)\n\nzypper update to 1.14.52:\n\n- info: print the packages upstream URL if available (fixes #426)\n- info: Fix SEGV with not installed PTFs (bsc#1196317)\n- Don't prevent less restrictive umasks (bsc#1195999)\n","modified":"2022-07-14T09:34:28Z","published":"2022-07-14T09:34:28Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20221157-2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196061"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196368"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196514"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197134"}],"affected":[{"package":{"name":"libsolv","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/libsolv&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.22-150200.12.1"}]}],"ecosystem_specific":{"binaries":[{"libsolv-tools":"0.7.22-150200.12.1","libzypp":"17.30.0-150200.36.1","zypper-needs-restarting":"1.14.52-150200.30.2","zypper":"1.14.52-150200.30.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1157-2.json"}},{"package":{"name":"libzypp","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/libzypp&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.30.0-150200.36.1"}]}],"ecosystem_specific":{"binaries":[{"libsolv-tools":"0.7.22-150200.12.1","libzypp":"17.30.0-150200.36.1","zypper-needs-restarting":"1.14.52-150200.30.2","zypper":"1.14.52-150200.30.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1157-2.json"}},{"package":{"name":"zypper","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/zypper&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.52-150200.30.2"}]}],"ecosystem_specific":{"binaries":[{"libsolv-tools":"0.7.22-150200.12.1","libzypp":"17.30.0-150200.36.1","zypper-needs-restarting":"1.14.52-150200.30.2","zypper":"1.14.52-150200.30.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:1157-2.json"}}],"schema_version":"1.7.3"}