SUSE 5146 Published by

A hdf5 security update has been released for SUSE Linux Enterprise and openSUSE Leap 15.3/15.4.



SUSE-SU-2022:1912-1: important: Security update for hdf5


SUSE Security Update: Security update for hdf5
______________________________________________________________________________

Announcement ID: SUSE-SU-2022:1912-1
Rating: important
References: #1093657 #1101471 #1101474 #1102175 #1109167 #1109168 #1109564 #1109565 #1109566 #1109568 #1109569 #1109570 #1167401 #1167404 #1167405 #1179521 #1196682
Cross-References: CVE-2018-11206 CVE-2018-14032 CVE-2018-14033 CVE-2018-14460 CVE-2018-17234 CVE-2018-17237 CVE-2018-17432 CVE-2018-17433 CVE-2018-17434 CVE-2018-17436 CVE-2018-17437 CVE-2018-17438 CVE-2020-10809 CVE-2020-10810 CVE-2020-10811
CVSS scores:
CVE-2018-11206 (NVD) : 8.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CVE-2018-11206 (SUSE): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CVE-2018-14032 (SUSE): 4 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVE-2018-14033 (NVD) : 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2018-14033 (SUSE): 4 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVE-2018-14460 (NVD) : 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2018-14460 (SUSE): 3.6 CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
CVE-2018-17234 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17234 (SUSE): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17237 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17237 (SUSE): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17432 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17432 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17433 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17433 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17434 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17434 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17436 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17436 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17437 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17437 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2018-17438 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2018-17438 (SUSE): 6.5 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2020-10809 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2020-10809 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
CVE-2020-10810 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2020-10810 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2020-10811 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2020-10811 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:
SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for HPC 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3
SUSE Linux Enterprise Server 15-SP3
SUSE Linux Enterprise Server for SAP Applications 15-SP3SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
openSUSE Leap 15.3
openSUSE Leap 15.4
______________________________________________________________________________

An update that solves 15 vulnerabilities and has two fixes is now available.

Description:

This update for hdf5 fixes the following issues:

Security issues fixed:

- CVE-2020-10811: Fixed heap-based buffer over-read in the function H5O__layout_decode() located in H5Olayout.c (bsc#1167405). - CVE-2020-10810: Fixed NULL pointer dereference in the function H5AC_unpin_entry() located in H5AC.c (bsc#1167401).
- CVE-2020-10809: Fixed heap-based buffer overflow in the function Decompress() located in decompress.c (bsc#1167404).
- CVE-2018-17438: Fixed SIGFPE signal raise in the function H5D__select_io() of H5Dselect.c (bsc#1109570).
- CVE-2018-17437: Fixed memory leak in the H5O_dtype_decode_helper() function in H5Odtype.c. (bsc#1109569).
- CVE-2018-17436: Fixed issue in ReadCode() in decompress.c that allowed attackers to cause a denial of service via a crafted HDF5 file (bsc#1109568).
- CVE-2018-17434: Fixed SIGFPE signal raise in function apply_filters() of
h5repack_filters.c (bsc#1109566).
- CVE-2018-17433: Fixed heap-based buffer overflow in ReadGifImageDesc() in gifread.c (bsc#1109565).
- CVE-2018-17432: Fixed NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c (bsc#1109564).
- CVE-2018-17237: Fixed SIGFPE signal raise in the function H5D__chunk_set_info_real() (bsc#1109168).
- CVE-2018-17234: Fixed memory leak in the H5O__chunk_deserialize() function in H5Ocache.c (bsc#1109167).
- CVE-2018-14460: Fixed heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c (bsc#1102175).
- CVE-2018-14033: Fixed heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c (bsc#1101471).
- CVE-2018-14032: Fixed heap-based buffer over-read in the function H5O_fill_new_decode in H5Ofill.c (bsc#1101474).
- CVE-2018-11206: Fixed out of bounds read in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c (bsc#1093657).

Bugfixes:

- Fix python-h5py packages built against out-of-date version of HDF5 (bsc#1196682).
- Fix netcdf-cxx4 packages built against out-of-date version of HDF5 (bsc#1179521).

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:

zypper in -t patch openSUSE-SLE-15.4-2022-1912=1

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-1912=1

- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3:
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-1912=1

- SUSE Linux Enterprise Module for HPC 15-SP3:

zypper in -t patch SUSE-SLE-Module-HPC-15-SP3-2022-1912=1

Package List:

- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):

libhdf5-gnu-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 libhdf5_hl_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 libhdf5_hl_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
- openSUSE Leap 15.4 (noarch):

hdf5-gnu-hpc-1.10.8-150300.4.3.1
hdf5-gnu-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
hdf5-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
hdf5-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2
hdf5-hpc-examples-1.10.8-150300.4.3.1

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

libhdf5-gnu-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 libhdf5_hl_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 libhdf5_hl_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
- openSUSE Leap 15.3 (noarch):

hdf5-gnu-hpc-1.10.8-150300.4.3.1
hdf5-gnu-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
hdf5-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
hdf5-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2
hdf5-hpc-examples-1.10.8-150300.4.3.1

- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (ppc64le s390x):

libhdf5-gnu-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 libhdf5_hl_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 libhdf5_hl_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (noarch):

hdf5-gnu-hpc-1.10.8-150300.4.3.1
hdf5-gnu-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
hdf5-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
hdf5-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2
hdf5-hpc-examples-1.10.8-150300.4.3.1

- SUSE Linux Enterprise Module for HPC 15-SP3 (aarch64 x86_64):
libhdf5-gnu-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
libhdf5_hl_cpp-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
libhdf5_hl_cpp-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-hpc-1.10.8-150300.4.3.1
libhdf5_hl_fortran-gnu-mpich-hpc-1.10.8-150300.4.3.2
libhdf5_hl_fortran-gnu-mvapich2-hpc-1.10.8-150300.4.3.1 libhdf5_hl_fortran-gnu-openmpi3-hpc-1.10.8-150300.4.3.2 libhdf5_hl_fortran-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
- SUSE Linux Enterprise Module for HPC 15-SP3 (noarch):

hdf5-gnu-hpc-1.10.8-150300.4.3.1
hdf5-gnu-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-mpich-hpc-1.10.8-150300.4.3.2
hdf5-gnu-mpich-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-mvapich2-hpc-1.10.8-150300.4.3.1
hdf5-gnu-mvapich2-hpc-devel-1.10.8-150300.4.3.1
hdf5-gnu-openmpi3-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi3-hpc-devel-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-1.10.8-150300.4.3.2
hdf5-gnu-openmpi4-hpc-devel-1.10.8-150300.4.3.2
hdf5-hpc-examples-1.10.8-150300.4.3.1

References:

  https://www.suse.com/security/cve/CVE-2018-11206.html
  https://www.suse.com/security/cve/CVE-2018-14032.html
  https://www.suse.com/security/cve/CVE-2018-14033.html
  https://www.suse.com/security/cve/CVE-2018-14460.html
  https://www.suse.com/security/cve/CVE-2018-17234.html
  https://www.suse.com/security/cve/CVE-2018-17237.html
  https://www.suse.com/security/cve/CVE-2018-17432.html
  https://www.suse.com/security/cve/CVE-2018-17433.html
  https://www.suse.com/security/cve/CVE-2018-17434.html
  https://www.suse.com/security/cve/CVE-2018-17436.html
  https://www.suse.com/security/cve/CVE-2018-17437.html
  https://www.suse.com/security/cve/CVE-2018-17438.html
  https://www.suse.com/security/cve/CVE-2020-10809.html
  https://www.suse.com/security/cve/CVE-2020-10810.html
  https://www.suse.com/security/cve/CVE-2020-10811.html
  https://bugzilla.suse.com/1093657
  https://bugzilla.suse.com/1101471
  https://bugzilla.suse.com/1101474
  https://bugzilla.suse.com/1102175
  https://bugzilla.suse.com/1109167
  https://bugzilla.suse.com/1109168
  https://bugzilla.suse.com/1109564
  https://bugzilla.suse.com/1109565
  https://bugzilla.suse.com/1109566
  https://bugzilla.suse.com/1109568
  https://bugzilla.suse.com/1109569
  https://bugzilla.suse.com/1109570
  https://bugzilla.suse.com/1167401
  https://bugzilla.suse.com/1167404
  https://bugzilla.suse.com/1167405
  https://bugzilla.suse.com/1179521
  https://bugzilla.suse.com/1196682