SUSE-SU-2020:0394-1
Dashboard / Vulnerabilities / SUSE-SU-2020:0394-1
SUSE-SU-2020:0394-1
Summary: Security update for gcc9
Details: This update for gcc9 fixes the following issues: The GNU Compiler Collection is shipped in version 9. A detailed changelog on what changed in GCC 9 is available at https://gcc.gnu.org/gcc-9/changes.html The compilers have been added to the SUSE Linux Enterprise Toolchain Module. To use these compilers, install e.g. gcc9, gcc9-c++ and build with CC=gcc-9 CXX=g++-9 set. For SUSE Linux Enterprise base products, the libstdc++6, libgcc_s1 and other compiler libraries have been switched from their gcc8 variants to their gcc9 variants. Security issues fixed: - CVE-2019-15847: Fixed a miscompilation in the POWER9 back end, that optimized multiple calls of the __builtin_darn intrinsic into a single call. (bsc#1149145) - CVE-2019-14250: Fixed a heap overflow in the LTO linker. (bsc#1142649) Non-security issues fixed: - Split out libstdc++ pretty-printers into a separate package supplementing gdb and the installed runtime. (bsc#1135254) - Fixed miscompilation for vector shift on s390. (bsc#1141897)
References: https://www.suse.com/support/update/announcement/2020/suse-su-20200394-1/, https://bugzilla.suse.com/1114592, https://bugzilla.suse.com/1135254, https://bugzilla.suse.com/1141897, https://bugzilla.suse.com/1142649, https://bugzilla.suse.com/1142654, https://bugzilla.suse.com/1148517, https://bugzilla.suse.com/1149145, https://www.suse.com/security/cve/CVE-2019-14250, https://www.suse.com/security/cve/CVE-2019-15847
Affected packages
Package
Name: gcc9
Purl: pkg:rpm/suse/gcc9&distro=HPE%20Helion%20OpenStack%208
Affected ranges
Type: ECOSYSTEM
Events:
