Security update for supportutils

Announcement ID: SUSE-SU-2023:3803-1
Rating: moderate
References:
Cross-References:
CVSS scores:
  • CVE-2022-45154 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE-2022-45154 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Affected Products:
  • SUSE CaaS Platform 4.0
  • SUSE Enterprise Storage 7
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP2
  • SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
  • SUSE Linux Enterprise Server 15 SP2
  • SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2

An update that solves one vulnerability, contains one feature and has 14 security fixes can now be installed.

Description:

This update for supportutils fixes the following issues:

Security Fixes:

  • CVE-2022-45154: Removed iSCSI passwords (bsc#1207598).

Other fixes:

  • Changes in version 3.1.26
  • powerpc plugin to collect the slots and active memory (bsc#1210950)
  • A Cleartext Storage of Sensitive Information vulnerability CVE-2022-45154
  • supportconfig: collect BPF information (pr#154)
  • Added additional iscsi information (pr#155)

  • Added run time detection (bsc#1213127)

  • Changes for supportutils version 3.1.25

  • Removed iSCSI passwords CVE-2022-45154 (bsc#1207598)
  • powerpc: Collect lsslot,amsstat, and opal elogs (pr#149)
  • powerpc: collect invscout logs (pr#150)
  • powerpc: collect RMC status logs (pr#151)
  • Added missing nvme nbft commands (bsc#1211599)
  • Fixed invalid nvme commands (bsc#1211598)
  • Added missing podman information (PED-1703, bsc#1181477)
  • Removed dependency on sysfstools
  • Check for systool use (bsc#1210015)
  • Added selinux checking (bsc#1209979)
  • Updated SLES_VER matrix

  • Fixed missing status detail for apparmor (bsc#1196933)

  • Corrected invalid argument list in docker.txt (bsc#1206608)
  • Applies limit equally to sar data and text files (bsc#1207543)
  • Collects hwinfo hardware logs (bsc#1208928)
  • Collects lparnumascore logs (issue#148)

  • Add dependency to numactl on ppc64le and s390x, this enforces that numactl --hardware data is provided in supportconfigs

  • Changes to supportconfig.rc version 3.1.11-35

  • Corrected _sanitize_file to include iscsi.conf and others (bsc#1206402)

  • Changes to supportconfig version 3.1.11-46.4

  • Added plymouth_info

  • Changes to getappcore version 1.53.02

  • The location of chkbin was updated earlier. This documents that change (bsc#1205533, bsc#1204942)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Enterprise Storage 7
    zypper in -t patch SUSE-Storage-7-2023-3803=1
  • SUSE CaaS Platform 4.0
    To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way.
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-3803=1
  • SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3803=1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-3803=1
  • SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-3803=1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-3803=1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-3803=1

Package List:

  • SUSE Enterprise Storage 7 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE CaaS Platform 4.0 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch)
    • supportutils-3.1.26-150000.5.50.1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch)
    • supportutils-3.1.26-150000.5.50.1

References: