{"id":"SUSE-SU-2023:3662-1","summary":"Security update for gcc7","details":"This update for gcc7 fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).\n- CVE-2019-15847: Fixed POWER9 DARN miscompilation.  (bsc#1149145)\n- CVE-2019-14250: Includes fix for LTO linker plugin heap overflow.  (bsc#1142649)\n\nUpdate to GCC 7.5.0 release.\n\nOther changes:\n\n- Fixed KASAN kernel compile. (bsc#1205145)\n- Fixed ICE with C++17 code. (bsc#1204505)\n- Fixed altivec.h redefining bool in C++ which makes bool unusable (bsc#1195517):\n- Adjust gnats idea of the target, fixing the build of gprbuild.  [bsc#1196861]\n- Do not handle exceptions in std::thread (jsc#CAR-1182)\n- add -fpatchable-function-entry feature to gcc-7.\n- Fixed glibc namespace violation with getauxval. (bsc#1167939)\n- Backport aarch64 Straight Line Speculation mitigation [bsc#1172798, CVE-2020-13844]\n- Enable fortran for the nvptx offload compiler. \n- Update README.First-for.SuSE.packagers\n- Avoid assembler errors with AVX512 gather and scatter instructions when using -masm=intel.\n- Backport the aarch64 -moutline-atomics feature and accumulated fixes but not its\n  default enabling.  (jsc#SLE-12209, bsc#1167939)\n- Fixed memcpy miscompilation on aarch64.  (bsc#1178624, bsc#1178577)\n- Fixed debug line info for try/catch.  (bsc#1178614)\n- Fixed corruption of pass private -\u003eaux via DF. (gcc#94148)\n- Fixed debug information issue with inlined functions and passed by reference arguments. [gcc#93888]\n- Fixed register allocation issue with exception handling code on s390x.  (bsc#1161913)\n- Backport PR target/92692 to fix miscompilation of some atomic code on aarch64. (bsc#1150164)\n- Fixed miscompilation in vectorized code for s390x.  (bsc#1160086) [gcc#92950]\n- Fixed miscompilation with thread-safe local static initialization.  [gcc#85887]\n- Fixed debug info created for array definitions that complete an earlier declaration.  [bsc#1146475]\n- Fixed vector shift miscompilation on s390.  (bsc#1141897)\n- Add gcc7 -flive-patching patch.  [bsc#1071995, fate#323487]\n- Strip -flto from $optflags.\n- Disables switch jump-tables when retpolines are used.  (bsc#1131264, jsc#SLE-6738)\n- Fixed ICE compiling tensorflow on aarch64.  (bsc#1129389)\n- Fixed for aarch64 FMA steering pass use-after-free.  (bsc#1128794)\n- Fixed ICE compiling tensorflow.  (bsc#1129389)\n- Fixed s390x FP load-and-test issue.  (bsc#1124644)\n- Adjust gnat manual entries in the info directory.  (bsc#1114592)\n- Fixed to no longer try linking -lieee with -mieee-fp.  (bsc#1084842)\n","modified":"2026-03-11T07:24:44.054198Z","published":"2023-09-18T19:48:26Z","related":["CVE-2019-14250","CVE-2019-15847","CVE-2020-13844","CVE-2023-4039"],"upstream":["CVE-2019-14250","CVE-2019-15847","CVE-2020-13844","CVE-2023-4039"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1084842"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114592"},{"type":"REPORT","url":"https://bugzilla.suse.com/1124644"},{"type":"REPORT","url":"https://bugzilla.suse.com/1128794"},{"type":"REPORT","url":"https://bugzilla.suse.com/1129389"},{"type":"REPORT","url":"https://bugzilla.suse.com/1131264"},{"type":"REPORT","url":"https://bugzilla.suse.com/1141897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1142649"},{"type":"REPORT","url":"https://bugzilla.suse.com/1146475"},{"type":"REPORT","url":"https://bugzilla.suse.com/1148517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1149145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1150164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1160086"},{"type":"REPORT","url":"https://bugzilla.suse.com/1161913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178624"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178675"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196861"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14250"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-15847"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13844"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-4039"}],"affected":[{"package":{"name":"cross-nvptx-gcc7","ecosystem":"SUSE:Linux Enterprise Module for Toolchain 12","purl":"pkg:rpm/suse/cross-nvptx-gcc7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Toolchain%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0+r278197-13.1"}]}],"ecosystem_specific":{"binaries":[{"gcc7-ada":"7.5.0+r278197-13.1","libada7":"7.5.0+r278197-13.1","cross-nvptx-newlib7-devel":"7.5.0+r278197-13.1","gcc7":"7.5.0+r278197-13.1","libada7-32bit":"7.5.0+r278197-13.1","cpp7":"7.5.0+r278197-13.1","gcc7-ada-32bit":"7.5.0+r278197-13.1","gcc7-c++-32bit":"7.5.0+r278197-13.1","gcc7-c++":"7.5.0+r278197-13.1","gcc7-fortran":"7.5.0+r278197-13.1","gcc7-info":"7.5.0+r278197-13.1","libstdc++6-devel-gcc7-32bit":"7.5.0+r278197-13.1","libstdc++6-devel-gcc7":"7.5.0+r278197-13.1","gcc7-32bit":"7.5.0+r278197-13.1","gcc7-fortran-32bit":"7.5.0+r278197-13.1","gcc7-locale":"7.5.0+r278197-13.1","cross-nvptx-gcc7":"7.5.0+r278197-13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3662-1.json"}},{"package":{"name":"gcc7","ecosystem":"SUSE:Linux Enterprise Module for Toolchain 12","purl":"pkg:rpm/suse/gcc7&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Toolchain%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0+r278197-13.1"}]}],"ecosystem_specific":{"binaries":[{"gcc7-fortran":"7.5.0+r278197-13.1","libada7-32bit":"7.5.0+r278197-13.1","libstdc++6-devel-gcc7-32bit":"7.5.0+r278197-13.1","gcc7-ada-32bit":"7.5.0+r278197-13.1","gcc7-c++":"7.5.0+r278197-13.1","libstdc++6-devel-gcc7":"7.5.0+r278197-13.1","cross-nvptx-gcc7":"7.5.0+r278197-13.1","gcc7-32bit":"7.5.0+r278197-13.1","gcc7-info":"7.5.0+r278197-13.1","gcc7":"7.5.0+r278197-13.1","cpp7":"7.5.0+r278197-13.1","gcc7-locale":"7.5.0+r278197-13.1","libada7":"7.5.0+r278197-13.1","cross-nvptx-newlib7-devel":"7.5.0+r278197-13.1","gcc7-ada":"7.5.0+r278197-13.1","gcc7-c++-32bit":"7.5.0+r278197-13.1","gcc7-fortran-32bit":"7.5.0+r278197-13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3662-1.json"}},{"package":{"name":"gcc7","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/gcc7&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0+r278197-13.1"}]}],"ecosystem_specific":{"binaries":[{"libasan4-32bit":"7.5.0+r278197-13.1","libasan4":"7.5.0+r278197-13.1","libcilkrts5-32bit":"7.5.0+r278197-13.1","libcilkrts5":"7.5.0+r278197-13.1","libgfortran4-32bit":"7.5.0+r278197-13.1","libgfortran4":"7.5.0+r278197-13.1","libubsan0-32bit":"7.5.0+r278197-13.1","libubsan0":"7.5.0+r278197-13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3662-1.json"}},{"package":{"name":"gcc7","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/gcc7&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.5.0+r278197-13.1"}]}],"ecosystem_specific":{"binaries":[{"libcilkrts5-32bit":"7.5.0+r278197-13.1","libcilkrts5":"7.5.0+r278197-13.1","libgfortran4-32bit":"7.5.0+r278197-13.1","libgfortran4":"7.5.0+r278197-13.1","libubsan0-32bit":"7.5.0+r278197-13.1","libubsan0":"7.5.0+r278197-13.1","libasan4-32bit":"7.5.0+r278197-13.1","libasan4":"7.5.0+r278197-13.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3662-1.json"}}],"schema_version":"1.7.5"}