SUSE-SU-2019:3061-1
Dashboard / Vulnerabilities / SUSE-SU-2019:3061-1
SUSE-SU-2019:3061-1
Summary: Security update for gcc9
Details: This update includes the GNU Compiler Collection 9. A full changelog is provided by the GCC team on: https://www.gnu.org/software/gcc/gcc-9/changes.html The base system compiler libraries libgcc_s1, libstdc++6 and others are now built by the gcc 9 packages. To use it, install 'gcc9' or 'gcc9-c++' or other compiler brands and use CC=gcc-9 / CXX=g++-9 during configuration for using it. Security issues fixed: - CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145) - CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649) Non-security issues fixed: - Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254) - Fixed miscompilation for vector shift on s390. (bsc#1141897)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20193061-1/, https://bugzilla.suse.com/1114592, https://bugzilla.suse.com/1135254, https://bugzilla.suse.com/1141897, https://bugzilla.suse.com/1142649, https://bugzilla.suse.com/1142654, https://bugzilla.suse.com/1148517, https://bugzilla.suse.com/1149145, https://www.suse.com/security/cve/CVE-2019-14250, https://www.suse.com/security/cve/CVE-2019-15847, https://bugzilla.suse.com/SLE-6533, https://bugzilla.suse.com/SLE-6536
Affected packages
Package
Name: gcc9
Purl: pkg:rpm/suse/gcc9&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
Affected ranges
Type: ECOSYSTEM
Events:
