{"id":"openSUSE-SU-2020:2301-1","summary":"Security update for gcc7","details":"This update for gcc7 fixes the following issues:\n\n- CVE-2020-13844: Added mitigation for aarch64 Straight Line Speculation issue (bsc#1172798)\n- Enable fortran for the nvptx offload compiler. \n- Update README.First-for.SuSE.packagers\n- avoid assembler errors with AVX512 gather and scatter instructions when using -masm=intel.\n- Backport the aarch64 -moutline-atomics feature and accumulated fixes but not its\n  default enabling.  [jsc#SLE-12209, bsc#1167939]\n- Fixed 32bit libgnat.so link.  [bsc#1178675]\n- Fixed memcpy miscompilation on aarch64. [bsc#1178624, bsc#1178577]\n- Fixed debug line info for try/catch.  [bsc#1178614]\n- Remove -mbranch-protection=standard (aarch64 flag) when gcc7 is used to build gcc7 (ie when ada is enabled)\n- Fixed corruption of pass private -\u003eaux via DF. [gcc#94148]\n- Fixed debug information issue with inlined functions and passed by reference arguments.  [gcc#93888]\n- Fixed binutils release date detection issue.\n- Fixed register allocation issue with exception handling code on s390x.  [bsc#1161913] \n- Fixed miscompilation of some atomic code on aarch64. [bsc#1150164]\n\nThis update was imported from the SUSE:SLE-15:Update update project.","modified":"2026-02-04T02:41:30.995938Z","published":"2020-12-20T17:23:53Z","related":["CVE-2020-13844"],"upstream":["CVE-2020-13844"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OIESM64GYREKLMRLTSQUIOYAUT6QG6A2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1150164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1161913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178624"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13844"}],"affected":[{"package":{"name":"gcc7","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/gcc7&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0+r278197-lp152.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"libasan4-32bit":"7.5.0+r278197-lp152.3.3.1","libgo11-32bit":"7.5.0+r278197-lp152.3.3.1","libubsan0":"7.5.0+r278197-lp152.3.3.1","cpp7":"7.5.0+r278197-lp152.3.3.1","gcc7-c++":"7.5.0+r278197-lp152.3.3.1","gcc7-go-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-locale":"7.5.0+r278197-lp152.3.3.1","gcc7":"7.5.0+r278197-lp152.3.3.1","libgfortran4-32bit":"7.5.0+r278197-lp152.3.3.1","libgo11":"7.5.0+r278197-lp152.3.3.1","gcc7-go":"7.5.0+r278197-lp152.3.3.1","gcc7-obj-c++-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-objc":"7.5.0+r278197-lp152.3.3.1","gcc7-fortran-32bit":"7.5.0+r278197-lp152.3.3.1","libcilkrts5-32bit":"7.5.0+r278197-lp152.3.3.1","libstdc++6-devel-gcc7":"7.5.0+r278197-lp152.3.3.1","libcilkrts5":"7.5.0+r278197-lp152.3.3.1","gcc7-objc-32bit":"7.5.0+r278197-lp152.3.3.1","libasan4":"7.5.0+r278197-lp152.3.3.1","libgfortran4":"7.5.0+r278197-lp152.3.3.1","libubsan0-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-info":"7.5.0+r278197-lp152.3.3.1","libada7":"7.5.0+r278197-lp152.3.3.1","libstdc++6-devel-gcc7-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-ada-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-ada":"7.5.0+r278197-lp152.3.3.1","gcc7-fortran":"7.5.0+r278197-lp152.3.3.1","gcc7-obj-c++":"7.5.0+r278197-lp152.3.3.1","libada7-32bit":"7.5.0+r278197-lp152.3.3.1","gcc7-c++-32bit":"7.5.0+r278197-lp152.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:2301-1.json"}}],"schema_version":"1.7.3"}