Sa-announce
Threads by month
- ----- 2025 -----
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
September 2023
- 1 participants
- 5 discussions
主题: openEuler update_20230927版本发布公告
Dear all,
经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3、openEuler-22.03-LTS、openEuler-22.03-LTS-SP1及openEuler-22.03-LTS-SP2 update版本满足版本出口质量,现进行发布公示。
本公示分为七部分:
1、openEuler-20.03-LTS-SP1 Update 20230927发布情况及待修复缺陷
2、openEuler-20.03-LTS-SP3 Update 20230927发布情况及待修复缺陷
3、openEuler-22.03-LTS Update 20230927发布情况及待修复缺陷
4、openEuler-22.03-LTS-SP1 Update 20230927发布情况及待修复缺陷
5、openEuler-22.03-LTS-SP2 Update 20230927发布情况及待修复缺陷
6、openEuler 关键组件待修复CVE 清单
7、openEuler 社区指导文档及开放平台链接
本次update版本发布后,下一个版本里程碑点(预计在2023/10/13)提供 update_20231011 版本。
openEuler-20.03-LTS-SP1 Update 20230927
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题1个,已知漏洞12个。目前版本分支剩余待修复缺陷21个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I84061?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2021-33635
iSulad
9.8
CVE-2021-33636
iSulad
9.8
CVE-2021-33637
iSulad
9.8
CVE-2021-33638
iSulad
9.8
CVE-2023-4504
cups
8.8
CVE-2023-4806
glibc
7.5
CVE-2023-3341
bind
7.5
CVE-2023-43642
snappy-java
7.5
CVE-2021-33634
lcr
6.3
CVE-2023-4813
glibc
5.9
CVE-2023-5156
glibc
3.7
CVE-2023-4641
shadow
3.3
Bugfix:
issue
仓库
#I830AI:【openEuler-1.0-LTS】加速器设备初始化之前需要进行一次复位操作
kernel
openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/docker_img/update/
openEuler CVE 及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03LTS SP1 update2103
I3E5C1
【20.03-SP1】【arm/x86】服务启动失败
主要
regression-failed
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I3E5C1
openEuler 20.03LTS SP1 update210901
I48GIM
【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败
主要
sig-oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I48GIM
openEuler 20.03-LTS-SP1
I4J0OY
【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常
主要
sig/sig-recycle
src-openEuler/libdap
https://gitee.com/open_euler/dashboard?issue_id=I4J0OY
openEuler 20.03-LTS-SP1
I4JMG4
【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251
主要
sig/sig-ROS
src-openEuler/python-robotframework
https://gitee.com/open_euler/dashboard?issue_id=I4JMG4
openEuler 20.03-LTS-SP1
I5DLX7
[20.03 22.03] 管理员指南操作文档mysql服务搭建指导文档有误
主要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I5DLX7
openEuler 20.03-LTS-SP1
I6VFAE
[20.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFAE
openEuler 20.03-LTS-SP1
I7ZOX9
【20.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOX9
openEuler-20.03-LTS-SP1
I3QGU7
系统不支持GB18030
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I3QGU7
openEuler 20.03LTS SP1 update210926
I4CMSV
【20.03-LTS-SP1】【arm/x86】搭建Kubernetes 集群缺少包etcd
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I4CMSV
openEuler 20.03-LTS-SP1
I4G4A5
Undefine-shift in _bfd_safe_read_leb128
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4A5
openEuler 20.03-LTS-SP1
I4G4B1
Integer overflow in print_vms_time
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4B1
openEuler 20.03-LTS-SP1
I4G4VY
memleak in parse_gnu_debugaltlink
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4VY
openEuler 20.03-LTS-SP1
I4G4WF
Heap-buffer-overflow in slurp_hppa_unwind_table
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WF
openEuler 20.03-LTS-SP1
I4G4WW
Use-after-free in make_qualified_name
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WW
openEuler 20.03-LTS-SP1
I4G4X6
memleak in byte_get_little_endian
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4X6
openEuler 20.03-LTS-SP1
I4G4XF
memleak in process_mips_specific
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4XF
openEuler 20.03-LTS-SP1
I4G4Y0
out-of-memory in vms_lib_read_index
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4Y0
openEuler 20.03-LTS-SP1
I4G4YJ
Heap-buffer-overflow in bfd_getl16
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YJ
openEuler 20.03-LTS-SP1
I4G4YV
Floating point exception in _bfd_vms_slurp_etir
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YV
openEuler 20.03LTS SP1 update220111
I4QV6N
【openEuler-20.03-LTS-SP1】flink命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV6N
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-20.03-LTS-SP3 Update 20230927
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问2个,已知漏洞17个。目前版本分支剩余待修复缺陷 7个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I84063?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2021-33635
iSulad
9.8
CVE-2021-33636
iSulad
9.8
CVE-2021-33637
iSulad
9.8
CVE-2021-33638
iSulad
9.8
CVE-2023-43115
ghostscript
9.8
CVE-2022-4515
ctags
7.8
CVE-2022-40023
python-mako
7.5
CVE-2023-3341
bind
7.5
CVE-2023-4806
glibc
7.5
CVE-2023-43642
snappy-java
7.5
CVE-2020-18651
exempi
6.5
CVE-2020-18652
exempi
6.5
CVE-2021-33634
lcr
6.3
CVE-2021-40732
exempi
6.1
CVE-2023-4813
glibc
5.9
CVE-2023-5156
glibc
3.7
CVE-2023-4641
shadow
3.3
Bugfix:
issue
仓库
#I830AI:【openEuler-1.0-LTS】加速器设备初始化之前需要进行一次复位操作
kernel
#I7PH6J:补丁回合
A-Tune-Collector
openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/docker_img/update/
openEuler CVE及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03-LTS-SP3
I5KXUY
【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I5KXUY
openEuler-20.03-LTS-SP3
I5KY4S
【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功
主要
sig/oVirt
src-openEuler/vdsm
https://gitee.com/open_euler/dashboard?issue_id=I5KY4S
openEuler-20.03-LTS-SP3
I6VFMI
[20.03 SP3] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFMI
openEuler-20.03-LTS-SP3
I72HWV
【20.03-lts-sp3】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72HWV
openEuler-20.03-LTS-SP3
I7QP67
[20.03-LTS-SP3]openssh自编译失败,提示缺少bc命令
次要
sig/Base-service
src-openEuler/openEuler-release
https://gitee.com/open_euler/dashboard?issue_id=I7QP67
openEuler-20.03-LTS-SP3
I7ZOZZ
【20.03 LTS SP3】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOZZ
openEuler 20.03LTS SP3 update220111
I4QV7S
【openEuler-20.03-LTS-SP3】flink run 命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV7S
openEuler-22.03-LTS Update 20230927
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题1个,已知漏洞14个。目前版本分支剩余待修复缺陷5个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I84064?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-41419
python-gevent
9.8
CVE-2021-33635
iSulad
9.8
CVE-2021-33636
iSulad
9.8
CVE-2021-33637
iSulad
9.8
CVE-2021-33638
iSulad
9.8
CVE-2023-4504
cups
8.8
CVE-2023-4806
glibc
7.5
CVE-2023-43642
snappy-java
7.5
CVE-2023-3341
bind
7.5
CVE-2021-33634
lcr
6.3
CVE-2023-4813
glibc
5.9
CVE-2018-2799
xerces-j2
5.3
CVE-2023-5156
glibc
3.7
CVE-2023-4641
shadow
3.3
Bugfix:
issue
仓库
#I82IXJ:22.03SP1版本网口绑定team的负载模式(loadbalance)后,单核CPU占用100%
libteam
openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/ob…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS update20230726
I7ORCE
【22.03 LTS update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败; cephadm卸载有异常打印
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7ORCE
openEuler-22.03-LTS
I596H5
openEuler官网中安全加固指南模块—>加固指导—>系统服务—>ssh加固项说明:加固建议中多添加了@符号
次要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I596H5
openEuler-22.03-LTS
I6VFRX
[22.03-LTS][x86/arm]mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFRX
openEuler-22.03-LTS
I72N5G
【22.03-lts】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72N5G
openEuler-22.03-LTS
I7ZP1J
【22.03 LTS】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP1J
openEuler-22.03-LTS-SP1 Update 20230927
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP1修复版本已知问题1个,已知漏洞15个。目前版本分支剩余待修复缺陷11个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I84060?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-41419
python-gevent
9.8
CVE-2021-33635
iSulad
9.8
CVE-2021-33636
iSulad
9.8
CVE-2021-33637
iSulad
9.8
CVE-2021-33638
iSulad
9.8
CVE-2023-4504
cups
8.8
CVE-2023-30362
dsoftbus
7.5
CVE-2023-43642
snappy-java
7.5
CVE-2023-4806
glibc
7.5
CVE-2023-3341
bind
7.5
CVE-2023-1999
firefox
7.5
CVE-2021-33634
lcr
6.3
CVE-2023-4813
glibc
5.9
CVE-2023-5156
glibc
3.7
CVE-2023-4641
shadow
3.3
Bugfix:
issue
仓库
#I82IXJ:22.03SP1版本网口绑定team的负载模式(loadbalance)后,单核CPU占用100%
libteam
openEuler-22.03-LTS SP1版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1:Ep…
openEuler-22.03-LTS SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 22.03-SP1
I6B4V1
【22.03 SP1 update 20230118】【arm】libhdfs在arm架构降级失败,x86正常
主要
sig/bigdata
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I6B4V1
openEuler-22.03-LTS-SP1
I7LW30
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in wide_int_to_tree_1, at tree.c:1575)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LW30
openEuler-22.03-LTS-SP1
I7LWCW
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:internal compiler error: Segmentation fault
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWCW
openEuler-22.03-LTS-SP1
I7LWK7
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4394)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWK7
openEuler-22.03-LTS-SP1
I7LWO1
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during RTL pass: expand(in convert_move, at expr.c:219)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWO1
openEuler-22.03-LTS-SP1
I7LX07
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4379)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LX07
openEuler-22.03-LTS-SP1 update20230726
I7OR2I
【22.03 LTS SP1 update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7OR2I
openEuler-22.03-LTS-SP1
I6VFV6
[22.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFV6
openEuler-22.03-LTS-SP1
I73CKF
【22.03-lts-sp1】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I73CKF
openEuler-22.03-LTS-SP1
I7ZP3M
【22.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP3M
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-22.03-LTS-SP2 Update 20230927
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP2修复版本已知问题1个,已知漏洞17个。目前版本分支剩余待修复缺陷3个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS-SP2 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I8405Y?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2021-33635
iSulad
9.8
CVE-2021-33636
iSulad
9.8
CVE-2021-33637
iSulad
9.8
CVE-2021-33638
iSulad
9.8
CVE-2023-41419
python-gevent
9.8
CVE-2023-43115<https://gitee.com/open_euler/dashboard?issue_id=I82DIG>
ghostscript
9.8
CVE-2023-4504
cups
8.8
CVE-2022-4515
ctags
7.8
CVE-2023-30362
dsoftbus
7.5
CVE-2023-43642
snappy-java
7.5
CVE-2023-4806
glibc
7.5
CVE-2023-3341
bind
7.5
CVE-2021-33634<https://gitee.com/open_euler/dashboard?issue_id=I842X9>
lcr
6.3
CVE-2021-40732
exempi
6.1
CVE-2023-4813
glibc
5.9
CVE-2023-5156
glibc
3.7
CVE-2023-4641<https://gitee.com/open_euler/dashboard?issue_id=I7XB8F>
shadow
3.3
Bugfix:
issue
仓库
#I82IXJ:22.03SP1版本网口绑定team的负载模式(loadbalance)后,单核CPU占用100%
libteam
openEuler-22.03-LTS SP2版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2:Ep…
openEuler-22.03-LTS SP2 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/hotpatch_update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
https://repo.openeuler.org/security/data/hotpatch_cvrf/
openEuler-22.03-LTS-SP2 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS-SP2-round-2
I795G3
【22.03-LTS-SP2 round2】本次转测源中出现多个版本的containers-common
主要
sig/sig-CloudNative
src-openEuler/skopeo
https://gitee.com/open_euler/dashboard?issue_id=I795G3
openEuler-22.03-LTS-SP2-SEC
I7AFIR
【22.03-LTS-SP2 round2】【x86/arm】libkae-1.2.10-6.oe2203sp2安全编译选项Rpath/Runpath不满足
主要
sig-AccLib
src-openEuler/libkae
https://gitee.com/open_euler/dashboard?issue_id=I7AFIR
openEuler-22.03-LTS-SP2
I7ZP4V
【22.03 LTS SP2】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP4V
社区待修复漏洞:
openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。
严重等级(Severity Rating)
漏洞修复时长
致命(Critical)
7天
高(High)
14天
中(Medium)
30天
低(Low)
30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE(9.28日数据):
漏洞编号
Issue ID
剩余天数
CVSS评分
软件包
责任SIG
CVE-2023-4574
I7WZ14
0.01
0.0
firefox
Application
CVE-2023-4584
I7WZ0C
0.01
0.0
firefox
Application
CVE-2023-4573
I7WZ06
0.01
0.0
firefox
Application
CVE-2023-4581
I7WYZD
0.01
0.0
firefox
Application
CVE-2023-4576
I7WYZB
0.01
0.0
firefox
Application
CVE-2023-41419
I84A04
4.65
9.8
python-gevent
Programming-language
CVE-2023-4863
I82PC7
5.23
8.8
firefox
Application
CVE-2023-3592
I7Z2PQ
7.76
0.0
mosquitto
Application
CVE-2023-41053
I7Z7QU
8.65
3.3
redis6
sig-bigdata
CVE-2023-41053
I7Z7QT
8.65
3.3
redis5
sig-bigdata
CVE-2023-5197
I84NFY
13.23
7.8
kernel
Kernel
CVE-2023-42753
I83QCZ
13.23
7.8
kernel
Kernel
CVE-2022-4318
I675RA
13.23
7.8
fence-agents
sig-Ha
CVE-2023-37154
I813NN
14.81
0.0
nagios-plugins
Networking
openEuler 社区指导文档及开放平台链接:
openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/master/%E7%A4%BE%E5%8C%BA%E7%89%88%E6%9…
社区QA 测试平台 radiates
https://radiatest.openeuler.org<https://radiatest.openeuler.org/>
1
0
主题: openEuler update_20230920版本发布公告
Dear all,
经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3、openEuler-22.03-LTS、openEuler-22.03-LTS-SP1及openEuler-22.03-LTS-SP2 update版本满足版本出口质量,现进行发布公示。
本公示分为七部分:
1、openEuler-20.03-LTS-SP1 Update 20230920发布情况及待修复缺陷
2、openEuler-20.03-LTS-SP3 Update 20230920发布情况及待修复缺陷
3、openEuler-22.03-LTS Update 20230920发布情况及待修复缺陷
4、openEuler-22.03-LTS-SP1 Update 20230920发布情况及待修复缺陷
5、openEuler-22.03-LTS-SP2 Update 20230920发布情况及待修复缺陷
6、openEuler 关键组件待修复CVE 清单
7、openEuler 社区指导文档及开放平台链接
本次update版本发布后,下一个版本里程碑点(预计在2023/09/28)提供 update_20230926 版本。
openEuler-20.03-LTS-SP1 Update 20230920
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题3个,已知漏洞13个。目前版本分支剩余待修复缺陷21个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I8234T?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4863
libwebp
9.6
CVE-2023-41915
pmix
8.1
CVE-2023-4921
kernel
7.8
CVE-2023-24537
skopeo
7.5
CVE-2023-4881
kernel
7.1
CVE-2023-21400
kernel
6.7
CVE-2023-4874
mutt
6.5
CVE-2023-41164
python-django
6.5
CVE-2023-4875
mutt
5.7
CVE-2023-20588
kernel
5.5
CVE-2023-39742
giflib
5.5
CVE-2023-40217
python3
5.3
CVE-2022-45887
kernel
4.7
Bugfix:
issue
仓库
#I82QEQ:在链接 glibc库场景下,当nsswitch工具动态加载一个包含容器内容的chroot库时,代码注入可能会发生。
iSulad
#I7XIHZ:安装libvirt*,ping操作提示“sendmsg: Operation not permitted”
ebtables
#I4YKIJ:【openEuler-1.0-LTS】加速器VF执行业务后或者当前正在执行业务,对PF进行FLR,均有可能触发QM的总线异常,需要驱动在复位之前停流踢cache
kernel
openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/docker_img/update/
openEuler CVE 及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03LTS SP1 update2103
I3E5C1
【20.03-SP1】【arm/x86】服务启动失败
主要
regression-failed
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I3E5C1
openEuler 20.03LTS SP1 update210901
I48GIM
【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败
主要
sig-oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I48GIM
openEuler 20.03-LTS-SP1
I4J0OY
【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常
主要
sig/sig-recycle
src-openEuler/libdap
https://gitee.com/open_euler/dashboard?issue_id=I4J0OY
openEuler 20.03-LTS-SP1
I4JMG4
【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251
主要
sig/sig-ROS
src-openEuler/python-robotframework
https://gitee.com/open_euler/dashboard?issue_id=I4JMG4
openEuler 20.03-LTS-SP1
I5DLX7
[20.03 22.03] 管理员指南操作文档mysql服务搭建指导文档有误
主要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I5DLX7
openEuler 20.03-LTS-SP1
I6VFAE
[20.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFAE
openEuler 20.03-LTS-SP1
I7ZOX9
【20.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOX9
openEuler-20.03-LTS-SP1
I3QGU7
系统不支持GB18030
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I3QGU7
openEuler 20.03LTS SP1 update210926
I4CMSV
【20.03-LTS-SP1】【arm/x86】搭建Kubernetes 集群缺少包etcd
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I4CMSV
openEuler 20.03-LTS-SP1
I4G4A5
Undefine-shift in _bfd_safe_read_leb128
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4A5
openEuler 20.03-LTS-SP1
I4G4B1
Integer overflow in print_vms_time
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4B1
openEuler 20.03-LTS-SP1
I4G4VY
memleak in parse_gnu_debugaltlink
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4VY
openEuler 20.03-LTS-SP1
I4G4WF
Heap-buffer-overflow in slurp_hppa_unwind_table
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WF
openEuler 20.03-LTS-SP1
I4G4WW
Use-after-free in make_qualified_name
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WW
openEuler 20.03-LTS-SP1
I4G4X6
memleak in byte_get_little_endian
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4X6
openEuler 20.03-LTS-SP1
I4G4XF
memleak in process_mips_specific
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4XF
openEuler 20.03-LTS-SP1
I4G4Y0
out-of-memory in vms_lib_read_index
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4Y0
openEuler 20.03-LTS-SP1
I4G4YJ
Heap-buffer-overflow in bfd_getl16
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YJ
openEuler 20.03-LTS-SP1
I4G4YV
Floating point exception in _bfd_vms_slurp_etir
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YV
openEuler 20.03LTS SP1 update220111
I4QV6N
【openEuler-20.03-LTS-SP1】flink命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV6N
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-20.03-LTS-SP3 Update 20230920
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问7个,已知漏洞15个。目前版本分支剩余待修复缺陷 7个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I8234X?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4863
libwebp
9.6
CVE-2023-41915
pmix
8.1
CVE-2023-4921
kernel
7.8
CVE-2023-24537
skopeo
7.5
CVE-2023-4785
grpc
7.5
CVE-2023-2977
opensc
7.1
CVE-2023-4881
kernel
7.1
CVE-2023-21400
kernel
6.7
CVE-2023-41164
python-django
6.5
CVE-2023-4874
mutt
6.5
CVE-2023-4875
mutt
5.7
CVE-2023-39742
giflib
5.5
CVE-2023-20588
kernel
5.5
CVE-2023-40217
python3
5.3
CVE-2022-45887
kernel
4.7
Bugfix:
issue
仓库
#I828IW:【openEuler-20.03-LTS-SP3】【arm/x86 】units_cur部分参数执行报错
units
#I82QJV:【20.03-lts-sp3_update 2023/09/19 release】update version to 2.0.18-13
iSulad
#I82AZ2:调用lxc二进制前为打开LXC_MEMFD_REXEC属性,存在安全风险
lcr
#I82QG4:clibcni中存在strerror函数调用,日志输出可能存在错误风险
clibcni
#I82QT2:设备mount地址错误
lxc
#I7XIHZ:安装libvirt*,ping操作提示“sendmsg: Operation not permitted”
ebtables
#I82LC6:【openEuler-1.0-LTS】关内核抢占场景,qm收包可能出现问题
kernel
openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/docker_img/update/
openEuler CVE及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03-LTS-SP3
I5KXUY
【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I5KXUY
openEuler-20.03-LTS-SP3
I5KY4S
【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功
主要
sig/oVirt
src-openEuler/vdsm
https://gitee.com/open_euler/dashboard?issue_id=I5KY4S
openEuler-20.03-LTS-SP3
I6VFMI
[20.03 SP3] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFMI
openEuler-20.03-LTS-SP3
I72HWV
【20.03-lts-sp3】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72HWV
openEuler-20.03-LTS-SP3
I7QP67
[20.03-LTS-SP3]openssh自编译失败,提示缺少bc命令
次要
sig/Base-service
src-openEuler/openEuler-release
https://gitee.com/open_euler/dashboard?issue_id=I7QP67
openEuler-20.03-LTS-SP3
I7ZOZZ
【20.03 LTS SP3】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOZZ
openEuler 20.03LTS SP3 update220111
I4QV7S
【openEuler-20.03-LTS-SP3】flink run 命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV7S
openEuler-22.03-LTS Update 20230920
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题7个,已知漏洞17个。目前版本分支剩余待修复缺陷5个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I82351?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4863
libwebp
9.6
CVE-2023-41915
pmix
8.1
CVE-2023-32253
kernel
8.1
CVE-2023-32249
kernel
8.1
CVE-2023-4921
kernel
7.8
CVE-2023-28366
mosquitto
7.5
CVE-2023-4785
grpc
7.5
CVE-2023-4881
kernel
7.1
CVE-2023-21400
kernel
6.7
CVE-2023-41164
python-django
6.5
CVE-2023-4874
mutt
6.5
CVE-2023-4875
mutt
5.7
CVE-2023-39742
giflib
5.5
CVE-2023-20588
kernel
5.5
CVE-2023-40217
python3
5.3
CVE-2022-45887
kernel
4.7
CVE-2023-32251
kernel
0.0
Bugfix:
issue
仓库
#I82AZ2:调用lxc二进制前为打开LXC_MEMFD_REXEC属性,存在安全风险
lcr
#I82QGO:【22.03-lts_update 2023/09/19 release】update version to 2.0.18-13
iSulad
#I82QG4:clibcni中存在strerror函数调用,日志输出可能存在错误风险
clibcni
#I82QT2:设备mount地址错误
lxc
#I7XIHZ:安装libvirt*,ping操作提示“sendmsg: Operation not permitted”
ebtables
#I80Y3R: grub2社区补丁回合 & SBAT元数据修正
grub2
#I828EV:日志重演EIO并发sync block_dev,数据丢失挂载仍然成功导致文件系统损坏
kernel
openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/ob…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS update20230726
I7ORCE
【22.03 LTS update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败; cephadm卸载有异常打印
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7ORCE
openEuler-22.03-LTS
I596H5
openEuler官网中安全加固指南模块—>加固指导—>系统服务—>ssh加固项说明:加固建议中多添加了@符号
次要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I596H5
openEuler-22.03-LTS
I6VFRX
[22.03-LTS][x86/arm]mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFRX
openEuler-22.03-LTS
I72N5G
【22.03-lts】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72N5G
openEuler-22.03-LTS
I7ZP1J
【22.03 LTS】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP1J
openEuler-22.03-LTS-SP1 Update 20230920
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP1修复版本已知问题10个,已知漏洞17个。目前版本分支剩余待修复缺陷11个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I8234M?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4863
libwebp
9.6
CVE-2023-41915
pmix
8.1
CVE-2023-32253
kernel
8.1
CVE-2023-32249
kernel
8.1
CVE-2023-4921
kernel
7.8
CVE-2023-4785
grpc
7.5
CVE-2023-24537
skopeo
7.5
CVE-2023-4881
kernel
7.1
CVE-2023-21400
kernel
6.7
CVE-2023-4874
mutt
6.5
CVE-2023-41164
python-django
6.5
CVE-2023-4875
mutt
5.7
CVE-2023-39742
giflib
5.5
CVE-2023-20588
kernel
5.5
CVE-2023-40217
python3
5.3
CVE-2022-45887
kernel
4.7
CVE-2023-32251
kernel
0.0
Bugfix:
issue
仓库
#I817RT:spec文件不完善,无法从rpm解压出源码
yaffs2
#I80WE9:BOLT优化Ceph报错
llvm-bolt
#I82DMH:Add tinytoml rpm
tinytoml
#I82QK2:【22.03-lts-sp1_update 2023/09/19 release】update version to 2.0.18-13
iSulad
#I82AZ2:调用lxc二进制前为打开LXC_MEMFD_REXEC属性,存在安全风险
lcr
#I82QMR:freezing状态的容器也应该设置为unfreeze
lxc
#I82QG4:clibcni中存在strerror函数调用,日志输出可能存在错误风险
clibcni
#I7XIHZ:安装libvirt*,ping操作提示“sendmsg: Operation not permitted”
ebtables
#I80Y3R: grub2社区补丁回合 & SBAT元数据修正
grub2
#I828EV:日志重演EIO并发sync block_dev,数据丢失挂载仍然成功导致文件系统损坏
kernel
openEuler-22.03-LTS SP1版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1:Ep…
openEuler-22.03-LTS SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 22.03-SP1
I6B4V1
【22.03 SP1 update 20230118】【arm】libhdfs在arm架构降级失败,x86正常
主要
sig/bigdata
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I6B4V1
openEuler-22.03-LTS-SP1
I7LW30
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in wide_int_to_tree_1, at tree.c:1575)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LW30
openEuler-22.03-LTS-SP1
I7LWCW
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:internal compiler error: Segmentation fault
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWCW
openEuler-22.03-LTS-SP1
I7LWK7
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4394)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWK7
openEuler-22.03-LTS-SP1
I7LWO1
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during RTL pass: expand(in convert_move, at expr.c:219)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWO1
openEuler-22.03-LTS-SP1
I7LX07
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4379)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LX07
openEuler-22.03-LTS-SP1 update20230726
I7OR2I
【22.03 LTS SP1 update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7OR2I
openEuler-22.03-LTS-SP1
I6VFV6
[22.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFV6
openEuler-22.03-LTS-SP1
I73CKF
【22.03-lts-sp1】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I73CKF
openEuler-22.03-LTS-SP1
I7ZP3M
【22.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP3M
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-22.03-LTS-SP2 Update 20230920
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP2修复版本已知问题6个,已知漏洞32个。目前版本分支剩余待修复缺陷3个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS-SP2 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I8234M?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4056
firefox
9.8
CVE-2023-4863
libwebp
9.6
CVE-2023-37201
firefox
8.8
CVE-2023-37202
firefox
8.8
CVE-2023-37211
firefox
8.8
CVE-2023-4047
firefox
8.8
CVE-2023-41915
pmix
8.1
CVE-2023-32253
kernel
8.1
CVE-2023-32249
kernel
8.1
CVE-2023-37208
firefox
7.8
CVE-2023-4921
kernel
7.8
CVE-2023-24537
skopeo
7.5
CVE-2023-4785
grpc
7.5
CVE-2023-4050
firefox
7.5
CVE-2023-4055
firefox
7.5
CVE-2023-4048
firefox
7.5
CVE-2023-2977
opensc
7.1
CVE-2023-4881
kernel
7.1
CVE-2023-21400
kernel
6.7
CVE-2023-4874
mutt
6.5
CVE-2023-41164
python-django
6.5
CVE-2023-37207
firefox
6.5
CVE-2023-4049
firefox
5.9
CVE-2023-4875
mutt
5.7
CVE-2023-39742
giflib
5.5
CVE-2023-4054
firefox
5.5
CVE-2023-20588
kernel
5.5
CVE-2023-40217
python3
5.3
CVE-2023-4045
firefox
5.3
CVE-2023-4046
firefox
5.3
CVE-2022-45887
kernel
4.7
CVE-2023-32251
kernel
0.0
Bugfix:
issue
仓库
#I7WHE3:修复组bond后,删除bond异常错误
kernel
#I82QKA:【22.03-lts-sp2_update 2023/09/19 release】update version to 2.1.3-6
iSulad
#I82AZ2:调用lxc二进制前为打开LXC_MEMFD_REXEC属性,存在安全风险
lcr
#I82QMR:freezing状态的容器也应该设置为unfreeze
lxc
#I80Y3R: grub2社区补丁回合 & SBAT元数据修正
grub2
#I828EV:日志重演EIO并发sync block_dev,数据丢失挂载仍然成功导致文件系统损坏
kernel
openEuler-22.03-LTS SP2版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2:Ep…
openEuler-22.03-LTS SP2 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/hotpatch_update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
https://repo.openeuler.org/security/data/hotpatch_cvrf/
openEuler-22.03-LTS-SP2 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS-SP2-round-2
I795G3
【22.03-LTS-SP2 round2】本次转测源中出现多个版本的containers-common
主要
sig/sig-CloudNative
src-openEuler/skopeo
https://gitee.com/open_euler/dashboard?issue_id=I795G3
openEuler-22.03-LTS-SP2-SEC
I7AFIR
【22.03-LTS-SP2 round2】【x86/arm】libkae-1.2.10-6.oe2203sp2安全编译选项Rpath/Runpath不满足
主要
sig-AccLib
src-openEuler/libkae
https://gitee.com/open_euler/dashboard?issue_id=I7AFIR
openEuler-22.03-LTS-SP2
I7ZP4V
【22.03 LTS SP2】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP4V
社区待修复漏洞:
openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。
严重等级(Severity Rating)
漏洞修复时长
致命(Critical)
7天
高(High)
14天
中(Medium)
30天
低(Low)
30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE(9.22日数据):
漏洞编号
Issue ID
剩余天数
CVSS评分
软件包
责任SIG
CVE-2023-43115
I82DIG
6.87
9.8
ghostscript
Base-service
CVE-2023-32215
I71R4G
5.79
8.8
firefox
Application
CVE-2023-32213
I71R3Y
5.79
8.8
firefox
Application
CVE-2023-32207
I71R3W
5.79
8.8
firefox
Application
CVE-2023-29536
I6UVEI
5.79
8.8
firefox
Application
CVE-2023-29541
I6UVDN
5.79
8.8
firefox
Application
CVE-2023-29539
I6UVDJ
5.79
8.8
firefox
Application
CVE-2023-29550
I6UVCU
5.79
8.8
firefox
Application
CVE-2023-4863
I82PC7
11.29
8.8
firefox
Application
CVE-2023-4504
I837XU
13.87
8.8
cups
Desktop
CVE-2023-30362
I81897
5.57
7.5
dsoftbus
distributed-middleware
CVE-2023-32214
I71R4A
5.79
7.5
firefox
Application
CVE-2023-1999
I6VVSM
5.79
7.5
firefox
Application
CVE-2023-4813
I80UPG
10.29
7.5
glibc
Computing
CVE-2023-3341
I832LT
12.29
7.5
bind
Networking
CVE-2023-4314
I80IPE
11.29
7.2
which
Base-service
CVE-2022-22753
I5TUFV
5.7
7.1
firefox
Application
CVE-2023-39615
I7XAOY
8.72
6.5
libxml2
Base-service
CVE-2023-32206
I71R4I
21.79
6.5
firefox
Application
CVE-2023-32211
I71R41
21.79
6.5
firefox
Application
CVE-2023-29545
I6UVEO
21.79
6.5
firefox
Application
CVE-2023-29535
I6UVDZ
21.79
6.5
firefox
Application
CVE-2023-29548
I6UVDO
21.79
6.5
firefox
Application
CVE-2023-4611
I7WZK1
9.7
6.3
kernel
Kernel
CVE-2020-18770
I7V70M
4.51
5.5
zziplib
Base-service
CVE-2020-18781
I7V6ZA
4.51
5.5
audiofile
Base-service
CVE-2023-4569
I7WN6T
9.29
5.5
kernel
Kernel
CVE-2023-42467
I809YE
21.29
5.5
qemu
Virt
CVE-2023-40612
I7VHLO
0.98
5.3
openstack-horizon
sig-openstack
CVE-2023-37453
I819LJ
21.61
4.6
kernel
Kernel
CVE-2023-32212
I71RAD
21.79
4.3
firefox
Application
CVE-2023-32205
I71R4D
21.79
4.3
firefox
Application
CVE-2023-29533
I6UVER
21.79
4.3
firefox
Application
CVE-2023-41053
I7Z7QU
14.7
3.3
redis6
sig-bigdata
CVE-2023-41053
I7Z7QT
14.7
3.3
redis5
sig-bigdata
CVE-2023-34414
I7BFX6
21.79
3.1
firefox
Application
CVE-2023-4732
I7Y1UL
10.17
0.0
kernel
Kernel
CVE-2023-3995
I7YIXN
12.19
0.0
kernel
Kernel
CVE-2023-3592
I7Z2PQ
13.82
0.0
mosquitto
Application
CVE-2023-4806
I80UPC
20.18
0.0
glibc
Computing
CVE-2023-37154
I813NN
20.86
0.0
nagios-plugins
Networking
CVE-2023-4421
I8155B
20.92
0.0
nss
sig-security-facility
CVE-2005-3660
I818Y1
21.59
0.0
kernel
Kernel
openEuler 社区指导文档及开放平台链接:
openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/master/%E7%A4%BE%E5%8C%BA%E7%89%88%E6%9…
社区QA 测试平台 radiates
https://radiatest.openeuler.org<https://radiatest.openeuler.org/>
1
0
主题: openEuler update_20230913版本发布公告
Dear all,
经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3、openEuler-22.03-LTS、openEuler-22.03-LTS-SP1及openEuler-22.03-LTS-SP2 update版本满足版本出口质量,现进行发布公示。
本公示分为七部分:
1、openEuler-20.03-LTS-SP1 Update 20230913发布情况及待修复缺陷
2、openEuler-20.03-LTS-SP3 Update 20230913发布情况及待修复缺陷
3、openEuler-22.03-LTS Update 20230913发布情况及待修复缺陷
4、openEuler-22.03-LTS-SP1 Update 20230913发布情况及待修复缺陷
5、openEuler-22.03-LTS-SP2 Update 20230913发布情况及待修复缺陷
6、openEuler 关键组件待修复CVE 清单
7、openEuler 社区指导文档及开放平台链接
本次update版本发布后,下一个版本里程碑点(预计在2023/09/22)提供 update_20230920 版本。
openEuler-20.03-LTS-SP1 Update 20230913
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题2个,已知漏洞73个。目前版本分支剩余待修复缺陷22个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I806HX?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-48566
python3
8.1
CVE-2023-4734
vim
7.8
CVE-2023-4735
vim
7.8
CVE-2023-4736
vim
7.8
CVE-2023-4738
vim
7.8
CVE-2023-4750
vim
7.8
CVE-2023-4752
vim
7.8
CVE-2023-4733
vim
7.8
CVE-2023-4781
vim
7.8
CVE-2023-4208
kernel
7.8
CVE-2023-4206
kernel
7.8
CVE-2023-4207
kernel
7.8
CVE-2023-4511
wireshark
7.5
CVE-2023-4513
wireshark
7.5
CVE-2022-40146
batik
7.5
CVE-2023-40589
freerdp
7.5
CVE-2023-39354
freerdp
7.5
CVE-2023-39351
freerdp
7.5
CVE-2023-39350
freerdp
7.5
CVE-2023-3354
qemu
7.5
CVE-2023-21930
openjdk-latest
7.4
CVE-2023-21930
openjdk-1.8.0
7.4
CVE-2022-44729
batik
7.1
CVE-2023-4622
kernel
7.0
CVE-2023-41040
python-GitPython
6.5
CVE-2023-2906
wireshark
6.5
CVE-2023-40186
freerdp
6.5
CVE-2023-40569
freerdp
6.5
CVE-2023-40567
freerdp
6.5
CVE-2021-46312
djvulibre
6.5
CVE-2021-46310
djvulibre
6.5
CVE-2023-41080
tomcat
6.1
CVE-2023-21954
openjdk-latest
5.9
CVE-2023-21967
openjdk-latest
5.9
CVE-2023-21954
openjdk-1.8.0
5.9
CVE-2023-21967
openjdk-1.8.0
5.9
CVE-2023-3649
wireshark
5.5
CVE-2020-21528
nasm
5.5
CVE-2022-21549
openjdk-latest
5.3
CVE-2023-21835
openjdk-latest
5.3
CVE-2023-21830
openjdk-latest
5.3
CVE-2023-21939
openjdk-latest
5.3
CVE-2022-38398
batik
5.3
CVE-2022-38648
batik
5.3
CVE-2023-39356
freerdp
5.3
CVE-2023-39352
freerdp
5.3
CVE-2023-39353
freerdp
5.3
CVE-2023-40181
freerdp
5.3
CVE-2023-40188
freerdp
5.3
CVE-2022-21549
openjdk-1.8.0
5.3
CVE-2023-21830
openjdk-1.8.0
5.3
CVE-2023-21939
openjdk-1.8.0
5.3
CVE-2023-22041
openjdk-latest
5.1
CVE-2022-44730
batik
4.4
CVE-2023-28938
mdadm
4.4
CVE-2022-40433
openjdk-latest
3.9
CVE-2022-40433
openjdk-1.8.0
3.9
CVE-2023-21843
openjdk-latest
3.7
CVE-2023-21968
openjdk-latest
3.7
CVE-2023-21938
openjdk-latest
3.7
CVE-2023-21937
openjdk-latest
3.7
CVE-2023-22045
openjdk-latest
3.7
CVE-2023-21843
openjdk-1.8.0
3.7
CVE-2023-21968
openjdk-1.8.0
3.7
CVE-2023-21938
openjdk-1.8.0
3.7
CVE-2023-21937
openjdk-1.8.0
3.7
CVE-2023-22045
openjdk-1.8.0
3.7
CVE-2023-22049
openjdk-1.8.0
3.7
CVE-2023-38037
rubygem-railties
3.3
CVE-2023-38037
rubygem-activesupport
3.3
CVE-2023-22006
openjdk-latest
3.1
Bugfix:
issue
仓库
#I7ZHZO:batik升级到1.17版本,fop依赖最新版本batik编译失败
fop
#I7TN3J:ext2_xattr_set流程和回写流程没有并发保护,导致内核BUG复位
kernel
openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/docker_img/update/
openEuler CVE 及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03LTS SP1 update2103
I3E5C1
【20.03-SP1】【arm/x86】服务启动失败
主要
regression-failed
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I3E5C1
openEuler 20.03LTS SP1 update210901
I48GIM
【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败
主要
sig-oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I48GIM
openEuler 20.03-LTS-SP1
I4J0OY
【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常
主要
sig/sig-recycle
src-openEuler/libdap
https://gitee.com/open_euler/dashboard?issue_id=I4J0OY
openEuler 20.03-LTS-SP1
I4JMG4
【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251
主要
sig/sig-ROS
src-openEuler/python-robotframework
https://gitee.com/open_euler/dashboard?issue_id=I4JMG4
openEuler 20.03-LTS-SP1
I5DLX7
[20.03 22.03] 管理员指南操作文档mysql服务搭建指导文档有误
主要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I5DLX7
openEuler 20.03-LTS-SP1
I6VFAE
[20.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFAE
openEuler 20.03-LTS-SP1
I7ZNHN
【openEuler-20.03-LTS-SP1 update0906】【arm/x86】在虚拟机中创建转测版本docker,安装selinux-policy(默认未安装),selinux状态由Disabled变为Permissive
次要
sig/sig-security-fac
src-openEuler/selinux-policy
https://gitee.com/open_euler/dashboard?issue_id=I7ZNHN
openEuler 20.03-LTS-SP1
I7ZOX9
【20.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOX9
openEuler-20.03-LTS-SP1
I3QGU7
系统不支持GB18030
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I3QGU7
openEuler 20.03LTS SP1 update210926
I4CMSV
【20.03-LTS-SP1】【arm/x86】搭建Kubernetes 集群缺少包etcd
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I4CMSV
openEuler 20.03-LTS-SP1
I4G4A5
Undefine-shift in _bfd_safe_read_leb128
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4A5
openEuler 20.03-LTS-SP1
I4G4B1
Integer overflow in print_vms_time
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4B1
openEuler 20.03-LTS-SP1
I4G4VY
memleak in parse_gnu_debugaltlink
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4VY
openEuler 20.03-LTS-SP1
I4G4WF
Heap-buffer-overflow in slurp_hppa_unwind_table
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WF
openEuler 20.03-LTS-SP1
I4G4WW
Use-after-free in make_qualified_name
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WW
openEuler 20.03-LTS-SP1
I4G4X6
memleak in byte_get_little_endian
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4X6
openEuler 20.03-LTS-SP1
I4G4XF
memleak in process_mips_specific
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4XF
openEuler 20.03-LTS-SP1
I4G4Y0
out-of-memory in vms_lib_read_index
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4Y0
openEuler 20.03-LTS-SP1
I4G4YJ
Heap-buffer-overflow in bfd_getl16
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YJ
openEuler 20.03-LTS-SP1
I4G4YV
Floating point exception in _bfd_vms_slurp_etir
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YV
openEuler 20.03LTS SP1 update220111
I4QV6N
【openEuler-20.03-LTS-SP1】flink命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV6N
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-20.03-LTS-SP3 Update 20230913
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问4个,已知漏洞56个。目前版本分支剩余待修复缺陷 7个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I806I1?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-48566
python3
8.1
CVE-2023-4734
vim
7.8
CVE-2023-4735
vim
7.8
CVE-2023-4736
vim
7.8
CVE-2023-4738
vim
7.8
CVE-2023-4750
vim
7.8
CVE-2023-4752
vim
7.8
CVE-2023-4733
vim
7.8
CVE-2023-4781
vim
7.8
CVE-2023-4208
kernel
7.8
CVE-2023-4206
kernel
7.8
CVE-2023-4207
kernel
7.8
CVE-2022-40146
batik
7.5
CVE-2023-4511
wireshark
7.5
CVE-2023-4513
wireshark
7.5
CVE-2023-3354
qemu
7.5
CVE-2023-40589
freerdp
7.5
CVE-2023-39354
freerdp
7.5
CVE-2023-39351
freerdp
7.5
CVE-2023-39350
freerdp
7.5
CVE-2023-21930
openjdk-1.8.0
7.4
CVE-2022-44729
batik
7.1
CVE-2023-4622
kernel
7.0
CVE-2023-41040
python-GitPython
6.5
CVE-2023-2906
wireshark
6.5
CVE-2023-40186
freerdp
6.5
CVE-2023-40569
freerdp
6.5
CVE-2023-40567
freerdp
6.5
CVE-2021-46312
djvulibre
6.5
CVE-2021-46310
djvulibre
6.5
CVE-2023-41080
tomcat
6.1
CVE-2023-21954
openjdk-1.8.0
5.9
CVE-2023-21967
openjdk-1.8.0
5.9
CVE-2023-3649
wireshark
5.5
CVE-2020-21528
nasm
5.5
CVE-2022-38398
batik
5.3
CVE-2022-38648
batik
5.3
CVE-2022-21549
openjdk-1.8.0
5.3
CVE-2023-21830
openjdk-1.8.0
5.3
CVE-2023-21939
openjdk-1.8.0
5.3
CVE-2023-39356
freerdp
5.3
CVE-2023-39352
freerdp
5.3
CVE-2023-39353
freerdp
5.3
CVE-2023-40181
freerdp
5.3
CVE-2023-40188
freerdp
5.3
CVE-2022-44730
batik
4.4
CVE-2023-28938
mdadm
4.4
CVE-2022-40433
openjdk-1.8.0
3.9
CVE-2023-21843
openjdk-1.8.0
3.7
CVE-2023-21968
openjdk-1.8.0
3.7
CVE-2023-21938
openjdk-1.8.0
3.7
CVE-2023-21937
openjdk-1.8.0
3.7
CVE-2023-22045
openjdk-1.8.0
3.7
CVE-2023-22049
openjdk-1.8.0
3.7
CVE-2023-38037
rubygem-activesupport
3.3
CVE-2023-38037
rubygem-railties
3.3
Bugfix:
issue
仓库
#I80WE9:BOLT优化Ceph报错
llvm-bolt
#I80YL3:回合PGO kernel特性以支持内核反馈优化
gcc
#I7TN3J:ext2_xattr_set流程和回写流程没有并发保护,导致内核BUG复位
kernel
#I7ZHZO:batik升级到1.17版本,fop依赖最新版本batik编译失败
fop
openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/docker_img/update/
openEuler CVE及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03-LTS-SP3
I5KXUY
【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I5KXUY
openEuler-20.03-LTS-SP3
I5KY4S
【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功
主要
sig/oVirt
src-openEuler/vdsm
https://gitee.com/open_euler/dashboard?issue_id=I5KY4S
openEuler-20.03-LTS-SP3
I6VFMI
[20.03 SP3] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFMI
openEuler-20.03-LTS-SP3
I72HWV
【20.03-lts-sp3】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72HWV
openEuler-20.03-LTS-SP3
I7QP67
[20.03-LTS-SP3]openssh自编译失败,提示缺少bc命令
次要
sig/Base-service
src-openEuler/openEuler-release
https://gitee.com/open_euler/dashboard?issue_id=I7QP67
openEuler-20.03-LTS-SP3
I7ZOZZ
【20.03 LTS SP3】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOZZ
openEuler 20.03LTS SP3 update220111
I4QV7S
【openEuler-20.03-LTS-SP3】flink run 命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV7S
openEuler-22.03-LTS Update 20230913
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题3个,已知漏洞65个。目前版本分支剩余待修复缺陷5个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I806I4?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4734
vim
7.8
CVE-2023-4735
vim
7.8
CVE-2023-4736
vim
7.8
CVE-2023-4738
vim
7.8
CVE-2023-4750
vim
7.8
CVE-2023-4752
vim
7.8
CVE-2023-4733
vim
7.8
CVE-2023-4781
vim
7.8
CVE-2023-3777
kernel
7.8
CVE-2023-4015
kernel
7.8
CVE-2023-4208
kernel
7.8
CVE-2023-4206
kernel
7.8
CVE-2023-4207
kernel
7.8
CVE-2022-40146
batik
7.5
CVE-2023-20900
open-vm-tools
7.5
CVE-2023-3354
qemu
7.5
CVE-2023-4511
wireshark
7.5
CVE-2023-4513
wireshark
7.5
CVE-2023-40589
freerdp
7.5
CVE-2023-39354
freerdp
7.5
CVE-2023-39351
freerdp
7.5
CVE-2023-39350
freerdp
7.5
CVE-2023-32247
kernel
7.5
CVE-2023-21930
openjdk-1.8.0
7.4
CVE-2022-44729
batik
7.1
CVE-2023-4622
kernel
7.0
CVE-2023-28736
mdadm
6.7
CVE-2023-41040
python-GitPython
6.5
CVE-2023-2906
wireshark
6.5
CVE-2023-40186
freerdp
6.5
CVE-2023-40569
freerdp
6.5
CVE-2023-40567
freerdp
6.5
CVE-2021-46312
djvulibre
6.5
CVE-2021-46310
djvulibre
6.5
CVE-2023-41080
tomcat
6.1
CVE-2023-21954
openjdk-1.8.0
5.9
CVE-2023-21967
openjdk-1.8.0
5.9
CVE-2020-21528
nasm
5.5
CVE-2023-3649
wireshark
5.5
CVE-2022-38398
batik
5.3
CVE-2022-38648
batik
5.3
CVE-2022-21549
openjdk-1.8.0
5.3
CVE-2023-21830
openjdk-1.8.0
5.3
CVE-2023-21939
openjdk-1.8.0
5.3
CVE-2023-39356
freerdp
5.3
CVE-2023-39352
freerdp
5.3
CVE-2023-39353
freerdp
5.3
CVE-2023-40181
freerdp
5.3
CVE-2023-40188
freerdp
5.3
CVE-2022-44730
batik
4.4
CVE-2023-28938
mdadm
4.4
CVE-2023-20867
open-vm-tools
3.9
CVE-2022-40433
openjdk-1.8.0
3.9
CVE-2023-21843
openjdk-1.8.0
3.7
CVE-2023-21968
openjdk-1.8.0
3.7
CVE-2023-21938
openjdk-1.8.0
3.7
CVE-2023-21937
openjdk-1.8.0
3.7
CVE-2023-22045
openjdk-1.8.0
3.7
CVE-2023-22049
openjdk-1.8.0
3.7
CVE-2023-38037
rubygem-activesupport
3.3
CVE-2023-38037
rubygem-railties
3.3
Bugfix:
issue
仓库
#I7ZHZO:batik升级到1.17版本,fop依赖最新版本batik编译失败
fop
#I80X18:PMC8222 Raid控制卡驱动升级
SmartHBA-2100-8i-driver
#I7Z434:【OLK-5.10】hns3网卡驱动PF下的多个VF设置相同mac地址后,VF收发包性能急剧下降
kernel
openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/ob…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS update20230726
I7ORCE
【22.03 LTS update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败; cephadm卸载有异常打印
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7ORCE
openEuler-22.03-LTS
I596H5
openEuler官网中安全加固指南模块—>加固指导—>系统服务—>ssh加固项说明:加固建议中多添加了@符号
次要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I596H5
openEuler-22.03-LTS
I6VFRX
[22.03-LTS][x86/arm]mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFRX
openEuler-22.03-LTS
I72N5G
【22.03-lts】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72N5G
openEuler-22.03-LTS
I7ZP1J
【22.03 LTS】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP1J
openEuler-22.03-LTS-SP1 Update 20230913
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP1修复版本已知问题3个,已知漏洞58个。目前版本分支剩余待修复缺陷11个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I806HW?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4781
vim
7.8
CVE-2023-4733
vim
7.8
CVE-2023-4752
vim
7.8
CVE-2023-4750
vim
7.8
CVE-2023-4738
vim
7.8
CVE-2023-4736
vim
7.8
CVE-2023-4735
vim
7.8
CVE-2023-4734
vim
7.8
CVE-2022-40146
batik
7.5
CVE-2023-40589
freerdp
7.5
CVE-2023-39354
freerdp
7.5
CVE-2023-39351
freerdp
7.5
CVE-2023-39350
freerdp
7.5
CVE-2023-4511
wireshark
7.5
CVE-2023-4513
wireshark
7.5
CVE-2023-20900
open-vm-tools
7.5
CVE-2023-3354
qemu
7.5
CVE-2023-21930
openjdk-1.8.0
7.4
CVE-2022-44729
batik
7.1
CVE-2023-40186
freerdp
6.5
CVE-2023-40569
freerdp
6.5
CVE-2023-40567
freerdp
6.5
CVE-2023-2906
wireshark
6.5
CVE-2023-41040
python-GitPython
6.5
CVE-2021-46312
djvulibre
6.5
CVE-2021-46310
djvulibre
6.5
CVE-2023-41080
tomcat
6.1
CVE-2023-21954
openjdk-1.8.0
5.9
CVE-2023-3649
wireshark
5.5
CVE-2020-21528
nasm
5.5
CVE-2022-38398
batik
5.3
CVE-2022-38648
batik
5.3
CVE-2023-39356
freerdp
5.3
CVE-2023-39352
freerdp
5.3
CVE-2023-32247
kernel
7.5
CVE-2023-39353
freerdp
5.3
CVE-2023-40181
freerdp
5.3
CVE-2023-40188
freerdp
5.3
CVE-2022-21549
openjdk-1.8.0
5.3
CVE-2023-3777
kernel
7.8
CVE-2023-4015
kernel
7.8
CVE-2023-4622
kernel
7.0
CVE-2023-21830
openjdk-1.8.0
5.3
CVE-2023-4208
kernel
7.8
CVE-2023-4206
kernel
7.8
CVE-2023-4207
kernel
7.8
CVE-2023-21939
openjdk-1.8.0
5.3
CVE-2022-44730
batik
4.4
CVE-2022-40433
openjdk-1.8.0
3.9
CVE-2023-20867
open-vm-tools
3.9
CVE-2023-21843
openjdk-1.8.0
3.7
CVE-2023-21968
openjdk-1.8.0
3.7
CVE-2023-21938
openjdk-1.8.0
3.7
CVE-2023-21937
openjdk-1.8.0
3.7
CVE-2023-22045
openjdk-1.8.0
3.7
CVE-2023-22049
openjdk-1.8.0
3.7
CVE-2023-38037
rubygem-activesupport
3.3
CVE-2023-38037
rubygem-railties
3.3
Bugfix:
issue
仓库
#I7I9W3:hbase shell执行报错
hbase
#I7Z434:【OLK-5.10】hns3网卡驱动PF下的多个VF设置相同mac地址后,VF收发包性能急剧下降
kernel
#I7ZHZO:batik升级到1.17版本,fop依赖最新版本batik编译失败
fop
openEuler-22.03-LTS SP1版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1:Ep…
openEuler-22.03-LTS SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 22.03-SP1
I6B4V1
【22.03 SP1 update 20230118】【arm】libhdfs在arm架构降级失败,x86正常
主要
sig/bigdata
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I6B4V1
openEuler-22.03-LTS-SP1
I7LW30
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in wide_int_to_tree_1, at tree.c:1575)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LW30
openEuler-22.03-LTS-SP1
I7LWCW
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:internal compiler error: Segmentation fault
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWCW
openEuler-22.03-LTS-SP1
I7LWK7
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4394)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWK7
openEuler-22.03-LTS-SP1
I7LWO1
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during RTL pass: expand(in convert_move, at expr.c:219)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWO1
openEuler-22.03-LTS-SP1
I7LX07
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4379)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LX07
openEuler-22.03-LTS-SP1 update20230726
I7OR2I
【22.03 LTS SP1 update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7OR2I
openEuler-22.03-LTS-SP1
I6VFV6
[22.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFV6
openEuler-22.03-LTS-SP1
I73CKF
【22.03-lts-sp1】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I73CKF
openEuler-22.03-LTS-SP1
I7ZP3M
【22.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP3M
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-22.03-LTS-SP2 Update 20230913
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP2修复版本已知问题4个,已知漏洞59个。目前版本分支剩余待修复缺陷3个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS-SP2 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I806HV?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-4734
vim
7.8
CVE-2023-4735
vim
7.8
CVE-2023-4736
vim
7.8
CVE-2023-4738
vim
7.8
CVE-2023-4750
vim
7.8
CVE-2023-4752
vim
7.8
CVE-2023-4733
vim
7.8
CVE-2023-4781
vim
7.8
CVE-2023-3777
kernel
7.8
CVE-2023-4015
kernel
7.8
CVE-2023-4208
kernel
7.8
CVE-2023-4206
kernel
7.8
CVE-2023-4207
kernel
7.8
CVE-2022-40146
batik
7.5
CVE-2023-20900
open-vm-tools
7.5
CVE-2023-4511
wireshark
7.5
CVE-2023-4513
wireshark
7.5
CVE-2023-3354
qemu
7.5
CVE-2023-40589
freerdp
7.5
CVE-2023-39354
freerdp
7.5
CVE-2023-39351
freerdp
7.5
CVE-2023-39350
freerdp
7.5
CVE-2023-32247
kernel
7.5
CVE-2023-28366
mosquitto
7.5
CVE-2023-21930
openjdk-1.8.0
7.4
CVE-2022-44729
batik
7.1
CVE-2023-4622
kernel
7.0
CVE-2023-2906
wireshark
6.5
CVE-2023-40186
freerdp
6.5
CVE-2023-40569
freerdp
6.5
CVE-2023-40567
freerdp
6.5
CVE-2023-41040
python-GitPython
6.5
CVE-2021-46312
djvulibre
6.5
CVE-2021-46310
djvulibre
6.5
CVE-2021-34431
mosquitto
6.5
CVE-2023-41080
tomcat
6.1
CVE-2023-21954
openjdk-1.8.0
5.9
CVE-2023-3649
wireshark
5.5
CVE-2020-21528
nasm
5.5
CVE-2022-38398
batik
5.3
CVE-2022-38648
batik
5.3
CVE-2023-39356
freerdp
5.3
CVE-2023-39352
freerdp
5.3
CVE-2023-39353
freerdp
5.3
CVE-2023-40181
freerdp
5.3
CVE-2023-40188
freerdp
5.3
CVE-2022-21549
openjdk-1.8.0
5.3
CVE-2023-21830
openjdk-1.8.0
5.3
CVE-2023-21939
openjdk-1.8.0
5.3
CVE-2022-44730
batik
4.4
CVE-2022-40433
openjdk-1.8.0
3.9
CVE-2023-21843
openjdk-1.8.0
3.7
CVE-2023-21968
openjdk-1.8.0
3.7
CVE-2023-21938
openjdk-1.8.0
3.7
CVE-2023-21937
openjdk-1.8.0
3.7
CVE-2023-22045
openjdk-1.8.0
3.7
CVE-2023-22049
openjdk-1.8.0
3.7
CVE-2023-38037
rubygem-activesupport
3.3
CVE-2023-38037
rubygem-railties
3.3
Bugfix:
issue
仓库
#I7I9W3:hbase shell执行报错
hbase
#I7ZHZO:batik升级到1.17版本,fop依赖最新版本batik编译失败
fop
#I80WE9:BOLT优化Ceph报错
llvm-bolt
#I7Z434:【OLK-5.10】hns3网卡驱动PF下的多个VF设置相同mac地址后,VF收发包性能急剧下降
kernel
openEuler-22.03-LTS SP2版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2:Ep…
openEuler-22.03-LTS SP2 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/hotpatch_update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
https://repo.openeuler.org/security/data/hotpatch_cvrf/
openEuler-22.03-LTS-SP2 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS-SP2-round-2
I795G3
【22.03-LTS-SP2 round2】本次转测源中出现多个版本的containers-common
主要
sig/sig-CloudNative
src-openEuler/skopeo
https://gitee.com/open_euler/dashboard?issue_id=I795G3
openEuler-22.03-LTS-SP2-SEC
I7AFIR
【22.03-LTS-SP2 round2】【x86/arm】libkae-1.2.10-6.oe2203sp2安全编译选项Rpath/Runpath不满足
主要
sig-AccLib
src-openEuler/libkae
https://gitee.com/open_euler/dashboard?issue_id=I7AFIR
openEuler-22.03-LTS-SP2
I7ZP4V
【22.03 LTS SP2】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP4V
社区待修复漏洞:
openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。
严重等级(Severity Rating)
漏洞修复时长
致命(Critical)
7天
高(High)
14天
中(Medium)
30天
低(Low)
30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE(9.15日数据):
漏洞编号
Issue ID
剩余天数
CVSS评分
软件包
责任SIG
CVE-2023-34416
I7BFX9
5.66
9.8
firefox
Application
CVE-2023-4863
I81TB4
6.99
9.6
libwebp
Desktop
CVE-2023-4759
I80TEU
11.16
8.8
eclipse-jgit
sig-Java
CVE-2023-4759
I80TEM
11.16
8.8
jgit
sig-Java
CVE-2020-19318
I80IPB
12.66
8.8
perl-version
sig-perl-modules
CVE-2023-32215
I71R4G
12.66
8.8
firefox
Application
CVE-2023-32213
I71R3Y
12.66
8.8
firefox
Application
CVE-2023-32207
I71R3W
12.66
8.8
firefox
Application
CVE-2023-29536
I6UVEI
12.66
8.8
firefox
Application
CVE-2023-29541
I6UVDN
12.66
8.8
firefox
Application
CVE-2023-29539
I6UVDJ
12.66
8.8
firefox
Application
CVE-2023-29550
I6UVCU
12.66
8.8
firefox
Application
CVE-2023-41915
I800WP
12.16
8.1
pmix
Base-service
CVE-2023-4921
I80USB
11.58
7.8
kernel
Kernel
CVE-2023-4807
I7ZULG
13.16
7.8
openssl
sig-security-facility
CVE-2023-28366
I7XXXJ
0.58
7.5
mosquitto
Application
CVE-2023-30362
I81897
12.44
7.5
dsoftbus
distributed-middleware
CVE-2023-4785
I816R7
12.66
7.5
grpc
Networking
CVE-2023-32214
I71R4A
12.66
7.5
firefox
Application
CVE-2023-1999
I6VVSM
12.66
7.5
firefox
Application
CVE-2022-22753
I5TUFV
12.58
7.1
firefox
Application
CVE-2023-4881
I80I0G
12.66
7.1
kernel
Kernel
CVE-2023-27470
I80IP2
12.66
7.0
at
Base-service
CVE-2020-18652
I7V70Y
11.38
6.5
exempi
Base-service
CVE-2020-18651
I7V70R
11.38
6.5
exempi
Base-service
CVE-2021-28429
I7SLVP
4.38
5.5
ffmpeg
sig-DDE
CVE-2020-22916
I7V72U
11.38
5.5
xz
Base-service
CVE-2020-21679
I7V72E
11.38
5.5
GraphicsMagick
Application
CVE-2020-18770
I7V70M
11.38
5.5
zziplib
Base-service
CVE-2020-18781
I7V6ZA
11.38
5.5
audiofile
Base-service
CVE-2023-4042
I7VH0W
13.16
5.5
ghostscript
Base-service
CVE-2023-40612
I7VHLO
7.85
5.3
openstack-horizon
sig-openstack
CVE-2023-40027
I7TI35
0.38
3.7
openstack-keystone
sig-openstack
CVE-2023-41175
I7WLRT
11.81
0.0
libtiff
Desktop
openEuler 社区指导文档及开放平台链接:
openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/master/%E7%A4%BE%E5%8C%BA%E7%89%88%E6%9…
社区QA 测试平台 radiates
https://radiatest.openeuler.org<https://radiatest.openeuler.org/>
1
0
主题: openEuler update_20230906版本发布公告
Dear all,
经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3、openEuler-22.03-LTS、openEuler-22.03-LTS-SP1及openEuler-22.03-LTS-SP2 update版本满足版本出口质量,现进行发布公示。
本公示分为七部分:
1、openEuler-20.03-LTS-SP1 Update 20230906发布情况及待修复缺陷
2、openEuler-20.03-LTS-SP3 Update 20230906发布情况及待修复缺陷
3、openEuler-22.03-LTS Update 20230906发布情况及待修复缺陷
4、openEuler-22.03-LTS-SP1 Update 20230906发布情况及待修复缺陷
5、openEuler-22.03-LTS-SP2 Update 20230906发布情况及待修复缺陷
6、openEuler 关键组件待修复CVE 清单
7、openEuler 社区指导文档及开放平台链接
本次update版本发布后,下一个版本里程碑点(预计在2023/09/16)提供 update_20230913 版本。
openEuler-20.03-LTS-SP1 Update 20230906
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题4个,已知漏洞16个。目前版本分支剩余待修复缺陷24个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7Y6TN?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-28879
ghostscript
9.8
CVE-2023-36664
ghostscript
9.8
CVE-2022-48565
python3
9.8
CVE-2022-31631
php
8.8
CVE-2023-0568
php
8.1
CVE-2023-37369
qt5-qtbase
7.5
CVE-2023-0662
php
7.5
CVE-2022-40090
libtiff
6.5
CVE-2023-0567
php
6.2
CVE-2023-28711
hyperscan
5.5
CVE-2023-3823
php
5.5
CVE-2023-3824
php
5.5
CVE-2023-38559
ghostscript
5.5
CVE-2022-48064
binutils
5.5
CVE-2023-39128
gdb
5.5
CVE-2023-3247
php
3.0
Bugfix:
issue
仓库
#I7YPBI:openEuler 20.03 SP1、20.03 SP3、22.03 LTS和22.03 SP1版本配置metalink
openEuler-repos
#I7UVFT: 创建多个ipv6地址,使用nping命令coredump
nmap
#I7VU25:【20.03 LTS SP1 】poppler子包从0.67.0-8版本向0.90.0-2版本升级有冲突
poppler
#I7UG7O:wpebackend-fdo组件的changelog首行末尾版本号与release对应的版本号不符
wpebackend-fdo
openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/docker_img/update/
openEuler CVE 及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03LTS SP1 update2103
I3E5C1
【20.03-SP1】【arm/x86】服务启动失败
主要
regression-failed
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I3E5C1
openEuler 20.03LTS SP1 update210901
I48GIM
【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败
主要
sig-oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I48GIM
openEuler 20.03-LTS-SP1
I4J0OY
【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常
主要
sig/sig-recycle
src-openEuler/libdap
https://gitee.com/open_euler/dashboard?issue_id=I4J0OY
openEuler 20.03-LTS-SP1
I4JMG4
【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251
主要
sig/sig-ROS
src-openEuler/python-robotframework
https://gitee.com/open_euler/dashboard?issue_id=I4JMG4
openEuler 20.03-LTS-SP1
I5DLX7
[20.03 22.03] 管理员指南操作文档mysql服务搭建指导文档有误
主要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I5DLX7
openEuler-20.03-LTS-SP1
I7XX6A
【20.03 LTS SP1 update20230830】【arm\x86】java-latest-openjdk-headless和java-latest-openjdk-devel安装失败
主要
sig/Compiler
src-openEuler/openjdk-latest
https://gitee.com/open_euler/dashboard?issue_id=I7XX6A
openEuler-20.03-LTS-SP1 update20230906
I7ZHSX
【20.03 LTS SP1 update20230906】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7ZHSX
openEuler 20.03-LTS-SP1
I6VFAE
[20.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFAE
openEuler 20.03-LTS-SP1
I7ZNHN
【openEuler-20.03-LTS-SP1 update0906】【arm/x86】在虚拟机中创建转测版本docker,安装selinux-policy(默认未安装),selinux状态由Disabled变为Permissive
次要
sig/sig-security-fac
src-openEuler/selinux-policy
https://gitee.com/open_euler/dashboard?issue_id=I7ZNHN
openEuler 20.03-LTS-SP1
I7ZOX9
【20.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOX9
openEuler-20.03-LTS-SP1
I3QGU7
系统不支持GB18030
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I3QGU7
openEuler 20.03LTS SP1 update210926
I4CMSV
【20.03-LTS-SP1】【arm/x86】搭建Kubernetes 集群缺少包etcd
无优先级
sig/TC
openEuler/community
https://gitee.com/open_euler/dashboard?issue_id=I4CMSV
openEuler 20.03-LTS-SP1
I4G4A5
Undefine-shift in _bfd_safe_read_leb128
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4A5
openEuler 20.03-LTS-SP1
I4G4B1
Integer overflow in print_vms_time
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4B1
openEuler 20.03-LTS-SP1
I4G4VY
memleak in parse_gnu_debugaltlink
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4VY
openEuler 20.03-LTS-SP1
I4G4WF
Heap-buffer-overflow in slurp_hppa_unwind_table
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WF
openEuler 20.03-LTS-SP1
I4G4WW
Use-after-free in make_qualified_name
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4WW
openEuler 20.03-LTS-SP1
I4G4X6
memleak in byte_get_little_endian
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4X6
openEuler 20.03-LTS-SP1
I4G4XF
memleak in process_mips_specific
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4XF
openEuler 20.03-LTS-SP1
I4G4Y0
out-of-memory in vms_lib_read_index
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4Y0
openEuler 20.03-LTS-SP1
I4G4YJ
Heap-buffer-overflow in bfd_getl16
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YJ
openEuler 20.03-LTS-SP1
I4G4YV
Floating point exception in _bfd_vms_slurp_etir
无优先级
sig/Base-service
src-openEuler/binutils
https://gitee.com/open_euler/dashboard?issue_id=I4G4YV
openEuler 20.03LTS SP1 update220111
I4QV6N
【openEuler-20.03-LTS-SP1】flink命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV6N
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-20.03-LTS-SP3 Update 20230906
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问6个,已知漏洞37个。目前版本分支剩余待修复缺陷 8个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7Y6TP?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-28879
ghostscript
9.8
CVE-2023-36664
ghostscript
9.8
CVE-2022-48565
python3
9.8
CVE-2022-31631
php
8.8
CVE-2023-0568
php
8.1
CVE-2023-0662
php
7.5
CVE-2023-37369
qt5-qtbase
7.5
CVE-2020-23804
poppler
7.5
CVE-2023-21930
openjdk-latest
7.4
CVE-2022-31630
php
7.1
CVE-2022-40090
libtiff
6.5
CVE-2022-37051
poppler
6.5
CVE-2022-37050
poppler
6.5
CVE-2022-37052
poppler
6.5
CVE-2022-38349
poppler
6.5
CVE-2023-0567
php
6.2
CVE-2023-21954
openjdk-latest
5.9
CVE-2023-21967
openjdk-latest
5.9
CVE-2023-38559
ghostscript
5.5
CVE-2023-28711
hyperscan
5.5
CVE-2022-48064
binutils
5.5
CVE-2023-39128
gdb
5.5
CVE-2023-3824
php
5.5
CVE-2023-3823
php
5.5
CVE-2022-21549
openjdk-latest
5.3
CVE-2023-21835
openjdk-latest
5.3
CVE-2023-21830
openjdk-latest
5.3
CVE-2023-21939
openjdk-latest
5.3
CVE-2023-22041
openjdk-latest
5.1
CVE-2022-40433
openjdk-latest
3.9
CVE-2023-21843
openjdk-latest
3.7
CVE-2023-21968
openjdk-latest
3.7
CVE-2023-21938
openjdk-latest
3.7
CVE-2023-21937
openjdk-latest
3.7
CVE-2023-22045
openjdk-latest
3.7
CVE-2023-22006
openjdk-latest
3.1
CVE-2023-3247
php
3.0
Bugfix:
issue
仓库
#I7YPBI:openEuler 20.03 SP1、20.03 SP3、22.03 LTS和22.03 SP1版本配置metalink
openEuler-repos
#I7UVFT: 创建多个ipv6地址,使用nping命令coredump
nmap
#I7VU25:【20.03 LTS SP1 】poppler子包从0.67.0-8版本向0.90.0-2版本升级有冲突
poppler
#I7YXWB:【20.03 LTS SP3】llvm-bolt需要升级
llvm-bolt
#I7UG7O:wpebackend-fdo组件的changelog首行末尾版本号与release对应的版本号不符
wpebackend-fdo
#I7SHZP:【OLK-5.10】arm64 ci概率出现trace日志不记录
kernel
openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/docker_img/update/
openEuler CVE及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 20.03-LTS-SP3
I5KXUY
【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
src-openEuler/ovirt-cockpit-sso
https://gitee.com/open_euler/dashboard?issue_id=I5KXUY
openEuler-20.03-LTS-SP3
I5KY4S
【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功
主要
sig/oVirt
src-openEuler/vdsm
https://gitee.com/open_euler/dashboard?issue_id=I5KY4S
openEuler-20.03-LTS-SP3 update20230906
I7ZHTJ
【20.03 LTS SP3 update20230906】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7ZHTJ
openEuler-20.03-LTS-SP3
I6VFMI
[20.03 SP3] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFMI
openEuler-20.03-LTS-SP3
I72HWV
【20.03-lts-sp3】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72HWV
openEuler-20.03-LTS-SP3
I7QP67
[20.03-LTS-SP3]openssh自编译失败,提示缺少bc命令
次要
sig/Base-service
src-openEuler/openEuler-release
https://gitee.com/open_euler/dashboard?issue_id=I7QP67
openEuler-20.03-LTS-SP3
I7ZOZZ
【20.03 LTS SP3】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZOZZ
openEuler 20.03LTS SP3 update220111
I4QV7S
【openEuler-20.03-LTS-SP3】flink run 命令执行失败
无优先级
sig/sig-ai-bigdata
src-openEuler/flink
https://gitee.com/open_euler/dashboard?issue_id=I4QV7S
openEuler-22.03-LTS Update 20230906
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题6个,已知漏洞41个。目前版本分支剩余待修复缺陷6个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7Y6TQ?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-28879
ghostscript
9.8
CVE-2023-36664
ghostscript
9.8
CVE-2022-31631
php
8.8
CVE-2023-0568
php
8.1
CVE-2023-37369
qt5-qtbase
7.5
CVE-2020-23804
poppler
7.5
CVE-2023-0662
php
7.5
CVE-2023-21930
openjdk-latest
7.4
CVE-2023-3865
kernel
7.1
CVE-2023-4273
kernel
6.7
CVE-2022-37051
poppler
6.5
CVE-2022-37050
poppler
6.5
CVE-2022-37052
poppler
6.5
CVE-2022-38349
poppler
6.5
CVE-2022-40090
libtiff
6.5
CVE-2023-1972
binutils
6.5
CVE-2023-0567
php
6.2
CVE-2023-21954
openjdk-latest
5.9
CVE-2023-21967
openjdk-latest
5.9
CVE-2023-3866
kernel
5.9
CVE-2023-39128
gdb
5.5
CVE-2023-38559
ghostscript
5.5
CVE-2023-28711
hyperscan
5.5
CVE-2023-4132
kernel
5.5
CVE-2022-4285
binutils
5.5
CVE-2022-48064
binutils
5.5
CVE-2023-3824
php
5.5
CVE-2023-3823
php
5.5
CVE-2022-21549
openjdk-latest
5.3
CVE-2023-21835
openjdk-latest
5.3
CVE-2023-21830
openjdk-latest
5.3
CVE-2023-21939
openjdk-latest
5.3
CVE-2023-22041
openjdk-latest
5.1
CVE-2022-40433
openjdk-latest
3.9
CVE-2023-21843
openjdk-latest
3.7
CVE-2023-21968
openjdk-latest
3.7
CVE-2023-21938
openjdk-latest
3.7
CVE-2023-21937
openjdk-latest
3.7
CVE-2023-22045
openjdk-latest
3.7
CVE-2023-22006
openjdk-latest
3.1
CVE-2023-3247
php
3.0
Bugfix:
issue
仓库
#I7SOHC:上游社区补丁分析回合
grub2
#I7YPBI:openEuler 20.03 SP1、20.03 SP3、22.03 LTS和22.03 SP1版本配置metalink
openEuler-repos
#I7TFS0:edk2组件的各个子包在202011-12版本丢失changelog信息,202011-11版本存在changelog
edk2
#I7UVFT: 创建多个ipv6地址,使用nping命令coredump
nmap
#I7UG7O:wpebackend-fdo组件的changelog首行末尾版本号与release对应的版本号不符
wpebackend-fdo
#I7LJO8:【OLK 5.10】dm_pool_dec_data_range()默认返回值变化可能导致discard失败
kernel
openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/ob…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS update20230726
I7ORCE
【22.03 LTS update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败; cephadm卸载有异常打印
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7ORCE
openEuler-22.03-LTS
I7XWWC
【22.03 LTS update20230830】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7XWWC
openEuler-22.03-LTS
I596H5
openEuler官网中安全加固指南模块—>加固指导—>系统服务—>ssh加固项说明:加固建议中多添加了@符号
次要
sig/doc
openEuler/docs
https://gitee.com/open_euler/dashboard?issue_id=I596H5
openEuler-22.03-LTS
I6VFRX
[22.03-LTS][x86/arm]mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFRX
openEuler-22.03-LTS
I72N5G
【22.03-lts】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I72N5G
openEuler-22.03-LTS
I7ZP1J
【22.03 LTS】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP1J
openEuler-22.03-LTS-SP1 Update 20230906
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP1修复版本已知问题9个,已知漏洞52个。目前版本分支剩余待修复缺陷13个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7Y6TM?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-28879
ghostscript
9.8
CVE-2023-36664
ghostscript
9.8
CVE-2022-31631
php
8.8
CVE-2023-0568
php
8.1
CVE-2023-36328
libtommath
7.8
CVE-2023-37369
qt5-qtbase
7.5
CVE-2023-0662
php
7.5
CVE-2022-40433
openjdk-11
7.5
CVE-2023-21930
openjdk-latest
7.4
CVE-2023-3865
kernel
7.1
CVE-2023-4273
kernel
6.7
CVE-2023-1972
binutils
6.5
CVE-2022-40090
libtiff
6.5
CVE-2023-0567
php
6.2
CVE-2023-21954
openjdk-latest
5.9
CVE-2023-21967
openjdk-latest
5.9
CVE-2023-21954
openjdk-11
5.9
CVE-2023-21967
openjdk-11
5.9
CVE-2023-3866
kernel
5.9
CVE-2023-22043
openjdk-latest
5.9
CVE-2023-28711
hyperscan
5.5
CVE-2023-38559
ghostscript
5.5
CVE-2022-4285
binutils
5.5
CVE-2022-48064
binutils
5.5
CVE-2023-39128
gdb
5.5
CVE-2023-4132
kernel
5.5
CVE-2022-21549
openjdk-latest
5.3
CVE-2023-21835
openjdk-latest
5.3
CVE-2023-21830
openjdk-latest
5.3
CVE-2023-21939
openjdk-latest
5.3
CVE-2023-21835
openjdk-11
5.3
CVE-2023-21939
openjdk-11
5.3
CVE-2023-22041
openjdk-latest
5.1
CVE-2023-22041
openjdk-11
5.1
CVE-2022-40433
openjdk-latest
3.9
CVE-2023-21843
openjdk-latest
3.7
CVE-2023-21968
openjdk-latest
3.7
CVE-2023-21938
openjdk-latest
3.7
CVE-2023-21937
openjdk-latest
3.7
CVE-2023-22045
openjdk-latest
3.7
CVE-2023-21843
openjdk-11
3.7
CVE-2023-21968
openjdk-11
3.7
CVE-2023-21938
openjdk-11
3.7
CVE-2023-21937
openjdk-11
3.7
CVE-2023-22036
openjdk-11
3.7
CVE-2023-22045
openjdk-11
3.7
CVE-2023-22049
openjdk-11
3.7
CVE-2023-22044
openjdk-latest
3.7
CVE-2023-22049
openjdk-latest
3.7
CVE-2023-22036
openjdk-latest
3.7
CVE-2023-22006
openjdk-latest
3.1
CVE-2023-22006
openjdk-11
3.1
Bugfix:
issue
仓库
#I7SOHC:上游社区补丁分析回合
grub2
#I7YPBI:openEuler 20.03 SP1、20.03 SP3、22.03 LTS和22.03 SP1版本配置metalink
openEuler-repos
#I7UVFT: 创建多个ipv6地址,使用nping命令coredump
nmap
#I7YY7S:【22.03 LTS SP1】llvm-bolt需要升级
llvm-bolt
#I7UG7O:wpebackend-fdo组件的changelog首行末尾版本号与release对应的版本号不符
wpebackend-fdo
#I7VR9G:网络域开源组件json-c回合上游社区补丁
json-c
#I7JD72:crash工具无法正常解析ARM V8以上新增的指令集
crash
#I7XVQD:【OLK 5.10】并发创建使用dm设备触发空指针解引用
kernel
#I7UYMV:更新gazelle的1.0.2版本源码包
gazelle
openEuler-22.03-LTS SP1版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1:Ep…
openEuler-22.03-LTS SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler 22.03-SP1
I6B4V1
【22.03 SP1 update 20230118】【arm】libhdfs在arm架构降级失败,x86正常
主要
sig/bigdata
src-openEuler/hadoop
https://gitee.com/open_euler/dashboard?issue_id=I6B4V1
openEuler-22.03-LTS-SP1
I7LW30
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in wide_int_to_tree_1, at tree.c:1575)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LW30
openEuler-22.03-LTS-SP1
I7LWCW
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:internal compiler error: Segmentation fault
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWCW
openEuler-22.03-LTS-SP1
I7LWK7
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4394)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWK7
openEuler-22.03-LTS-SP1
I7LWO1
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during RTL pass: expand(in convert_move, at expr.c:219)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LWO1
openEuler-22.03-LTS-SP1
I7LX07
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4379)
主要
sig/Compiler
openEuler/gcc
https://gitee.com/open_euler/dashboard?issue_id=I7LX07
openEuler-22.03-LTS-SP1 update20230726
I7OR2I
【22.03 LTS SP1 update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败
主要
sig/sig-SDS
src-openEuler/ceph
https://gitee.com/open_euler/dashboard?issue_id=I7OR2I
openEuler-22.03-LTS-SP1
I7XWXQ
【22.03 LTS SP1 update20230830】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7XWXQ
openEuler-20.03-LTS-SP1 update20230906
I7ZHSX
【20.03 LTS SP1 update20230906】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7ZHSX
openEuler-22.03-LTS-SP1
I6VFV6
[22.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
src-openEuler/mariadb
https://gitee.com/open_euler/dashboard?issue_id=I6VFV6
openEuler-22.03-LTS-SP1
I73CKF
【22.03-lts-sp1】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
src-openEuler/php
https://gitee.com/open_euler/dashboard?issue_id=I73CKF
openEuler-22.03-LTS-SP1
I7ZP3M
【22.03 LTS SP1】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP3M
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
src-openEuler/mate-desktop
https://gitee.com/open_euler/dashboard?issue_id=I5Y99T
openEuler-22.03-LTS-SP2 Update 20230906
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP2修复版本已知问题6个,已知漏洞50个。目前版本分支剩余待修复缺陷4个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS-SP2 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7Y6TK?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2023-28879
ghostscript
9.8
CVE-2023-36664
ghostscript
9.8
CVE-2023-37369
qt5-qtbase
7.5
CVE-2020-23804
poppler
7.5
CVE-2022-40433
openjdk-11
7.5
CVE-2023-21930
openjdk-11
7.4
CVE-2023-3865
kernel
7.1
CVE-2023-4273
kernel
6.7
CVE-2022-37051
poppler
6.5
CVE-2022-37050
poppler
6.5
CVE-2022-37052
poppler
6.5
CVE-2022-38349
poppler
6.5
CVE-2022-40090
libtiff
6.5
CVE-2023-1972
binutils
6.5
CVE-2023-21954
openjdk-latest
5.9
CVE-2023-21954
openjdk-11
5.9
CVE-2023-21967
openjdk-11
5.9
CVE-2023-3866
kernel
5.9
CVE-2023-28711
hyperscan
5.5
CVE-2023-39128
gdb
5.5
CVE-2023-38559
ghostscript
5.5
CVE-2022-4285
binutils
5.5
CVE-2022-48064
binutils
5.5
CVE-2023-4132
kernel
5.5
CVE-2023-3824
php
5.5
CVE-2023-3823
php
5.5
CVE-2022-21549
openjdk-latest
5.3
CVE-2023-21835
openjdk-latest
5.3
CVE-2023-21830
openjdk-latest
5.3
CVE-2023-21939
openjdk-latest
5.3
CVE-2023-21835
openjdk-11
5.3
CVE-2023-21939
openjdk-11
5.3
CVE-2023-22041
openjdk-latest
5.1
CVE-2023-22041
openjdk-11
5.1
CVE-2022-40433
openjdk-latest
3.9
CVE-2023-21843
openjdk-latest
3.7
CVE-2023-21968
openjdk-latest
3.7
CVE-2023-21938
openjdk-latest
3.7
CVE-2023-21937
openjdk-latest
3.7
CVE-2023-22045
openjdk-latest
3.7
CVE-2023-21843
openjdk-11
3.7
CVE-2023-21968
openjdk-11
3.7
CVE-2023-21938
openjdk-11
3.7
CVE-2023-21937
openjdk-11
3.7
CVE-2023-22036
openjdk-11
3.7
CVE-2023-22045
openjdk-11
3.7
CVE-2023-22049
openjdk-11
3.7
CVE-2023-22006
openjdk-latest
3.1
CVE-2023-22006
openjdk-11
3.1
CVE-2023-3247
php
3.0
Bugfix:
issue
仓库
#I7SOHC:上游社区补丁分析回合
grub2
#I7XIHZ:安装libvirt*,ping操作提示“sendmsg: Operation not permitted”
ebtables
#I7UVFT: 创建多个ipv6地址,使用nping命令coredump
nmap
#I7YY6C:【22.03 LTS SP2】llvm-bolt需要升级
llvm-bolt
#I7UG7O:wpebackend-fdo组件的changelog首行末尾版本号与release对应的版本号不符
wpebackend-fdo
#I7VR9G:网络域开源组件json-c回合上游社区补丁
json-c
openEuler-22.03-LTS SP2版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2:Ep…
openEuler-22.03-LTS SP2 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/hotpatch_update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
https://repo.openeuler.org/security/data/hotpatch_cvrf/
openEuler-22.03-LTS-SP2 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
任务路径
openEuler-22.03-LTS-SP2-round-2
I795G3
【22.03-LTS-SP2 round2】本次转测源中出现多个版本的containers-common
主要
sig/sig-CloudNative
src-openEuler/skopeo
https://gitee.com/open_euler/dashboard?issue_id=I795G3
openEuler-22.03-LTS-SP2-SEC
I7AFIR
【22.03-LTS-SP2 round2】【x86/arm】libkae-1.2.10-6.oe2203sp2安全编译选项Rpath/Runpath不满足
主要
sig-AccLib
src-openEuler/libkae
https://gitee.com/open_euler/dashboard?issue_id=I7AFIR
openEuler-22.03-LTS-SP2
I7XWZ2
【22.03 LTS SP2 update20230830】【arm\x86】java-1.8.0-openjdk子包全量升级失败
主要
sig/Compiler
src-openEuler/openjdk-1.8.0
https://gitee.com/open_euler/dashboard?issue_id=I7XWZ2
openEuler-22.03-LTS-SP2
I7ZP4V
【22.03 LTS SP2】【arm/x86】 qdbuscpp2xml-qt5的help信息名称不一致
次要
sig/Programming-lang
src-openEuler/qt5-qtbase
https://gitee.com/open_euler/dashboard?issue_id=I7ZP4V
社区待修复漏洞:
openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。
严重等级(Severity Rating)
漏洞修复时长
致命(Critical)
7天
高(High)
14天
中(Medium)
30天
低(Low)
30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE(9.9日数据):
漏洞编号
Issue ID
剩余天数
CVSS评分
软件包
责任SIG
CVE-2023-41910
I7YQBU
6.24
9.8
nodejs-with
sig-nodejs
CVE-2020-24165
I7WY1L
6.24
8.8
qemu
Virt
CVE-2023-4738
I7Y1XF
7.74
7.8
vim
Base-service
CVE-2023-4736
I7Y1XB
7.74
7.8
vim
Base-service
CVE-2023-4734
I7Y1WZ
7.74
7.8
vim
Base-service
CVE-2023-4752
I7YIF7
9.24
7.8
vim
Base-service
CVE-2023-4750
I7YIF0
9.24
7.8
vim
Base-service
CVE-2023-4751
I7YETA
9.24
7.8
vim
Base-service
CVE-2023-4781
I7YV9Y
10.74
7.8
vim
Base-service
CVE-2023-4623
I7Z7CD
11.24
7.8
kernel
Kernel
CVE-2023-4208
I7Z7CC
11.24
7.8
kernel
Kernel
CVE-2023-4206
I7Z7CB
11.24
7.8
kernel
Kernel
CVE-2023-4622
I7Z7C9
11.24
7.8
kernel
Kernel
CVE-2023-4244
I7Z7C3
11.24
7.8
kernel
Kernel
CVE-2023-4207
I7Z7BQ
11.24
7.8
kernel
Kernel
CVE-2023-4015
I7YIXO
11.24
7.8
kernel
Kernel
CVE-2023-3777
I7YIXI
11.24
7.8
kernel
Kernel
CVE-2023-39810
I7WN64
12.24
7.8
busybox
sig-CloudNative
CVE-2022-33275
I7YQAQ
13.24
7.8
nodejs-is
sig-nodejs
CVE-2021-34193
I7WN56
2.9
7.5
opensc
Base-service
CVE-2022-34038
I7V70G
4.24
7.5
etcd
sig-CloudNative
CVE-2023-39663
I7WZIV
5.67
7.5
mathjax
sig-UKUI
CVE-2023-3354
I7GURP
9.24
7.5
qemu
Virt
CVE-2023-20900
I7XLKS
11.24
7.5
open-vm-tools
sig/Virt
CVE-2023-4733
I7YIF8
9.24
7.3
vim
Base-service
CVE-2020-21528
I7V71T
13.46
5.9
nasm
Programming-language
CVE-2021-28429
I7SLVP
10.46
5.5
ffmpeg
sig-DDE
CVE-2023-4459
I7UWI8
12.46
5.5
kernel
Kernel
CVE-2023-4385
I7TT9F
13.46
5.5
kernel
Kernel
CVE-2023-40612
I7VHLO
13.93
5.3
openstack-horizon
sig-openstack
CVE-2023-28938
I7V4BK
11.82
4.4
mdadm
Storage
CVE-2020-21686
I7VCVA
12.74
4.3
nasm
Programming-language
CVE-2023-40027
I7TI35
6.46
3.7
openstack-keystone
sig-openstack
openEuler 社区指导文档及开放平台链接:
openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/master/%E7%A4%BE%E5%8C%BA%E7%89%88%E6%9…
社区QA 测试平台 radiates
https://radiatest.openeuler.org<https://radiatest.openeuler.org/>
1
0
主题: openEuler update_20230830版本发布公告
Dear all,
经社区Release SIG、QA SIG及 CICD SIG 评估,openEuler-20.03-LTS-SP1、openEuler-20.03-LTS-SP3、openEuler-22.03-LTS、openEuler-22.03-LTS-SP1及openEuler-22.03-LTS-SP2 update版本满足版本出口质量,现进行发布公示。
本公示分为七部分:
1、openEuler-20.03-LTS-SP1 Update 20230830发布情况及待修复缺陷
2、openEuler-20.03-LTS-SP3 Update 20230830发布情况及待修复缺陷
3、openEuler-22.03-LTS Update 20230830发布情况及待修复缺陷
4、openEuler-22.03-LTS-SP1 Update 20230830发布情况及待修复缺陷
5、openEuler-22.03-LTS-SP2 Update 20230830发布情况(包含热补丁)及待修复缺陷
6、openEuler 关键组件待修复CVE 清单
7、openEuler 社区指导文档及开放平台链接
本次update版本发布后,下一个版本里程碑点(预计在2023/09/09)提供 update_20230906 版本。
openEuler-20.03-LTS-SP1 Update 20230830
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP1修复版本已知问题1个,已知漏洞39个。目前版本分支剩余待修复缺陷20个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7WBQV?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-48174
busybox
9.8
CVE-2020-22219
flac
9.8
CVE-2021-32292
json-c
9.8
CVE-2023-32002
nodejs
9.8
CVE-2023-32006
nodejs
8.8
CVE-2022-32212
nodejs
8.1
CVE-2023-40283
kernel
7.8
CVE-2023-40305
indent
7.8
CVE-2023-20197
clamav
7.5
CVE-2020-23804
poppler
7.5
CVE-2021-46174
binutils
7.5
CVE-2022-25881
nodejs
7.5
CVE-2023-23918
nodejs
7.5
CVE-2023-30589
nodejs
7.5
CVE-2023-30581
nodejs
7.5
CVE-2023-32559
nodejs
7.5
CVE-2022-37051
poppler
6.5
CVE-2022-37050
poppler
6.5
CVE-2022-37052
poppler
6.5
CVE-2022-38349
poppler
6.5
CVE-2023-38711
libreswan
6.5
CVE-2023-38710
libreswan
6.5
CVE-2023-38712
libreswan
6.5
CVE-2022-32213
nodejs
6.5
CVE-2022-32215
nodejs
6.5
CVE-2022-32214
nodejs
6.5
CVE-2022-35256
nodejs
6.5
CVE-2022-47008
binutils
6
CVE-2023-1206
kernel
5.7
CVE-2022-48554
file
5.5
CVE-2022-47011
binutils
5.5
CVE-2023-4194
kernel
5.5
CVE-2023-34319
kernel
5.5
CVE-2023-4385
kernel
5.5
CVE-2023-4459
kernel
5.5
CVE-2023-38633
librsvg2
5.5
CVE-2023-30590
nodejs
5.3
CVE-2023-23920
nodejs
4.2
CVE-2023-4156
gawk
3.3
Bugfix:
issue
仓库
#I7DX6V:海光2&3号服务器虚拟机拓扑结构与配置不一致
kernel
openEuler-20.03-LTS-SP1版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP1:Epol
openEuler-20.03-LTS-SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/EPOL/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP1/docker_img/update/
openEuler CVE 及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
openEuler 20.03-LTS-SP1
I4J0OY
【20.03 SP1】【arm/x86】安装好libdap后,getdap4命令的-i和-k参数使用异常
主要
sig/sig-recycle
libdap
openEuler 20.03-LTS-SP1
I4JMG4
【20.03 SP1】【arm/x86】robotframework包的三个命令:libdoc、rebot、robot执行--help/-h/-?/--version,查看帮助信息和版本信息,返回值为251
主要
sig/sig-ROS
python-robotframework
openEuler 20.03-LTS-SP1
I5DLX7
[20.03 22.03] 管理员指南操作文档mysql服务搭建指导文档有误
主要
sig/doc
docs
openEuler 20.03LTS SP1 update2103
I3E5C1
【20.03-SP1】【arm/x86】服务启动失败
主要
sig/bigdata
hadoop
openEuler 20.03LTS SP1 update210901
I48GIM
【20.03LTS SP1 update 210901】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
ovirt-cockpit-sso
openEuler 20.03-LTS-SP1
I6VFAE
[20.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
mariadb
openEuler 20.03-LTS-SP1
I4G4A5
Undefine-shift in _bfd_safe_read_leb128
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4B1
Integer overflow in print_vms_time
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4VY
memleak in parse_gnu_debugaltlink
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4WF
Heap-buffer-overflow in slurp_hppa_unwind_table
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4WW
Use-after-free in make_qualified_name
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4X6
memleak in byte_get_little_endian
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4XF
memleak in process_mips_specific
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4Y0
out-of-memory in vms_lib_read_index
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4YJ
Heap-buffer-overflow in bfd_getl16
无优先级
sig/Base-service
binutils
openEuler 20.03-LTS-SP1
I4G4YV
Floating point exception in _bfd_vms_slurp_etir
无优先级
sig/Base-service
binutils
openEuler 20.03LTS SP1 update210926
I4CMSV
【20.03-LTS-SP1】【arm/x86】搭建Kubernetes 集群缺少包etcd
无优先级
sig/TC
community
openEuler 20.03LTS SP1 update220111
I4QV6N
【openEuler-20.03-LTS-SP1】flink命令执行失败
无优先级
sig/sig-ai-bigdata
flink
openEuler-20.03-LTS-SP1
I3QGU7
系统不支持GB18030
无优先级
sig/TC
community
openEuler-20.03-LTS-SP1-dailybuild
I5Y99T
mate-desktop install problem in openEuler:20:03:LTS:SP1
无优先级
sig/sig-mate-desktop
mate-desktop
openEuler-20.03-LTS-SP3 Update 20230830
经各SIG及社区开发者贡献,本周openEuler-20.03-LTS-SP3修复版本已知问1个,已知漏洞34个。目前版本分支剩余待修复缺陷 7个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-20.03-LTS-SP3 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7WBQW?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-48174
busybox
9.8
CVE-2021-32292
json-c
9.8
CVE-2020-22219
flac
9.8
CVE-2023-32002
nodejs
9.8
CVE-2023-32006
nodejs
8.8
CVE-2022-32212
nodejs
8.1
CVE-2023-40283
kernel
7.8
CVE-2023-40305
indent
7.8
CVE-2023-20197
clamav
7.5
CVE-2021-46174
binutils
7.5
CVE-2022-25881
nodejs
7.5
CVE-2023-23918
nodejs
7.5
CVE-2023-30589
nodejs
7.5
CVE-2023-30581
nodejs
7.5
CVE-2023-32559
nodejs
7.5
CVE-2023-38711
libreswan
6.5
CVE-2023-38710
libreswan
6.5
CVE-2023-38712
libreswan
6.5
CVE-2022-32213
nodejs
6.5
CVE-2022-32215
nodejs
6.5
CVE-2022-32214
nodejs
6.5
CVE-2022-35256
nodejs
6.5
CVE-2022-47008
binutils
6
CVE-2023-1206
kernel
5.7
CVE-2022-48554
file
5.5
CVE-2022-47011
binutils
5.5
CVE-2023-4194
kernel
5.5
CVE-2023-34319
kernel
5.5
CVE-2023-4385
kernel
5.5
CVE-2023-4459
kernel
5.5
CVE-2023-38633
librsvg2
5.5
CVE-2023-30590
nodejs
5.3
CVE-2023-23920
nodejs
4.2
CVE-2023-4156
gawk
3.3
Bugfix:
issue
仓库
#I7DX6V:海光2&3号服务器虚拟机拓扑结构与配置不一致
kernel
openEuler-20.03-LTS-SP3版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3
https://build.openeuler.org/project/show/openEuler:20.03:LTS:SP3:Epol
openEuler-20.03-LTS-SP3 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/update/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/EPOL/update/main/
https://repo.openeuler.org/openEuler-20.03-LTS-SP3/docker_img/update/
openEuler CVE及安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-20.03-LTS-SP3 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
openEuler 20.03 LTS SP3 update20220801
I5LYJK
【20.03-sp3_update20220801】【x86】对内核版进行升级后,TCP_option_address安装异常
主要
sig/Kernel
TCP_option_address
openEuler 20.03-LTS-SP3
I5KXUY
【20.03 LTS SP3 update 20220803】【arm/x86】ovirt-cockpit-sso.service服务启动失败
主要
sig/oVirt
ovirt-cockpit-sso
openEuler-20.03-LTS-SP3
I5KY4S
【20.03 LTS SP3 update 20220803】【arm/x86】vdsmd.service服务启动失败,导致mom-vdsm.service服务无法启动成功
主要
sig/oVirt
vdsm
openEuler-20.03-LTS-SP3
I72EAT
【20.03 SP3】php相关包在20.03 LTS SP3降级失败
主要
sig/Base-service
php
openEuler 20.03LTS SP3 update220111
I4QV7S
【openEuler-20.03-LTS-SP3】flink run 命令执行失败
无优先级
sig/sig-ai-bigdata
flink
openEuler-20.03-LTS-SP3
I6VFMI
[20.03 SP3] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
mariadb
openEuler-20.03-LTS-SP3
I72HWV
【20.03-lts-sp3】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
php
openEuler-22.03-LTS Update 20230830
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS修复版本已知问题1个,已知漏洞44个。目前版本分支剩余待修复缺陷3个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7WBQX?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-48174
busybox
9.8
CVE-2020-22219
flac
9.8
CVE-2021-32292
json-c
9.8
CVE-2023-32002
nodejs
9.8
CVE-2023-38432
kernel
9.1
CVE-2023-39417
postgresql
8.8
CVE-2023-32006
nodejs
8.8
CVE-2023-39417
libpq
8.8
CVE-2022-32212
nodejs
8.1
CVE-2023-40305
indent
7.8
CVE-2023-40283
kernel
7.8
CVE-2023-20197
clamav
7.5
CVE-2021-46174
binutils
7.5
CVE-2022-25881
nodejs
7.5
CVE-2023-23918
nodejs
7.5
CVE-2023-30589
nodejs
7.5
CVE-2023-30581
nodejs
7.5
CVE-2023-32559
nodejs
7.5
CVE-2020-21469
libpq
7.5
CVE-2023-3867
kernel
7.3
CVE-2023-2454
libpq
7.2
CVE-2023-4389
kernel
7.1
CVE-2023-38711
libreswan
6.5
CVE-2023-38710
libreswan
6.5
CVE-2023-38712
libreswan
6.5
CVE-2022-32213
nodejs
6.5
CVE-2022-32215
nodejs
6.5
CVE-2022-32214
nodejs
6.5
CVE-2022-35256
nodejs
6.5
CVE-2022-48522
perl
6.3
CVE-2022-47008
binutils
6
CVE-2023-1206
kernel
5.7
CVE-2022-48554
file
5.5
CVE-2023-4194
kernel
5.5
CVE-2023-34319
kernel
5.5
CVE-2022-47011
binutils
5.5
CVE-2023-20593
kernel
5.5
CVE-2022-31628
php
5.5
CVE-2023-38633
librsvg2
5.5
CVE-2023-2455
libpq
5.4
CVE-2023-30590
nodejs
5.3
CVE-2023-39418
libpq
4.3
CVE-2023-23920
nodejs
4.2
CVE-2023-4156
gawk
3.3
Bugfix:
issue
仓库
#I7T755:【OLK-5.10】 KASAN: use-after-free Read in sock_xmit
kernel
openEuler-22.03-LTS版本编译构建信息查询链接:
https://build.openeuler.org/project/show/openEuler:22.03:LTS
https://build.openeuler.org/project/show/openEuler:22.03:LTS:Epol
openEuler-22.03-LTS Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/Op…
https://repo.openeuler.org/openEuler-22.03-LTS/EPOL/update/multi_version/ob…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
openEuler-22.03-LTS
I6VFRX
[22.03-LTS][x86/arm]mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
mariadb
openEuler-22.03-LTS
I72N5G
【22.03-lts】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
php
openEuler-22.03-LTS update20230726
I7ORCE
【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败; cephadm卸载有异常打印
主要
sig/SDS
ceph
openEuler-22.03-LTS-SP1 Update 20230830
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP1修复版本已知问题1个,已知漏洞53个。目前版本分支剩余待修复缺陷9个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS SP1 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7WBQT?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-47022
hwloc
9.8
CVE-2022-48174
busybox
9.8
CVE-2020-22219
flac
9.8
CVE-2023-32002
nodejs
9.8
CVE-2023-38432
kernel
9.1
CVE-2023-39417
postgresql
8.8
CVE-2023-32006
nodejs
8.8
CVE-2023-39417
libpq
8.8
CVE-2022-32212
nodejs
8.1
CVE-2023-40305
indent
7.8
CVE-2023-40283
kernel
7.8
CVE-2023-20197
clamav
7.5
CVE-2020-23804
poppler
7.5
CVE-2021-46174
binutils
7.5
CVE-2022-25881
nodejs
7.5
CVE-2023-23918
nodejs
7.5
CVE-2023-30589
nodejs
7.5
CVE-2023-30581
nodejs
7.5
CVE-2023-32559
nodejs
7.5
CVE-2020-21469
libpq
7.5
CVE-2023-3867
kernel
7.3
CVE-2023-2454
libpq
7.2
CVE-2022-33196
microcode_ctl
6.7
CVE-2023-36054
krb5
6.5
CVE-2023-38712
libreswan
6.5
CVE-2023-38710
libreswan
6.5
CVE-2023-38711
libreswan
6.5
CVE-2022-40982
microcode_ctl
6.5
CVE-2023-32573
qt
6.5
CVE-2022-37051
poppler
6.5
CVE-2022-37050
poppler
6.5
CVE-2022-37052
poppler
6.5
CVE-2022-38349
poppler
6.5
CVE-2022-32213
nodejs
6.5
CVE-2022-32215
nodejs
6.5
CVE-2022-32214
nodejs
6.5
CVE-2022-35256
nodejs
6.5
CVE-2022-48522
perl
6.3
CVE-2022-47008
binutils
6
CVE-2023-1206
kernel
5.7
CVE-2022-48554
file
5.5
CVE-2022-47011
binutils
5.5
CVE-2023-4194
kernel
5.5
CVE-2023-34319
kernel
5.5
CVE-2023-20593
kernel
5.5
CVE-2023-38633
librsvg2
5.5
CVE-2023-2455
libpq
5.4
CVE-2023-29409
golang
5.3
CVE-2023-30590
nodejs
5.3
CVE-2022-38090
microcode_ctl
4.4
CVE-2023-39418
libpq
4.3
CVE-2023-23920
nodejs
4.2
CVE-2023-4156
gawk
3.3
Bugfix:
issue
仓库
#I7T755:【OLK-5.10】 KASAN: use-after-free Read in sock_xmit
kernel
openEuler-22.03-LTS SP1版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP1:Ep…
openEuler-22.03-LTS SP1 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP1/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
openEuler-22.03-LTS-SP1 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
openEuler-22.03-LTS-SP1
I7LW30
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in wide_int_to_tree_1, at tree.c:1575)
主要
sig/Compiler
gcc
openEuler-22.03-LTS-SP1
I7LWCW
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:internal compiler error: Segmentation fault
主要
sig/Compiler
gcc
openEuler-22.03-LTS-SP1
I7LWK7
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4394)
主要
sig/Compiler
gcc
openEuler-22.03-LTS-SP1
I7LWO1
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during RTL pass: expand(in convert_move, at expr.c:219)
主要
sig/Compiler
gcc
openEuler-22.03-LTS-SP1
I7LX07
【arm】-O3 -flto-partition=one -fipa-struct-reorg -fwhole-program编译ICE:during IPA pass: struct_reorg(in get_type_field, at ipa-struct-reorg/ipa-struct-reorg.c:4379)
主要
sig/Compiler
gcc
openEuler 22.03-SP1
I6B4V1
【22.03 SP1 update 20230118】【arm】libhdfs在arm架构降级失败,x86正常
主要
sig/bigdata
hadoop
openEuler-22.03-LTS-SP1
I6VFV6
[22.03 SP1] [x86/arm] mariadb授权给远程用户,远程连接服务失败
次要
sig/DB
mariadb
openEuler-22.03-LTS-SP1
I73CKF
【22.03-lts-sp1】x86环境上同时安装php-fpm软件包和php-opcache软件包后会导致php-fpm.service服务启动失败
次要
sig/Base-service
php
openEuler-22.03-LTS-SP1 update20230726
I7OR2I
【22.03 LTS SP1 update20230726】【arm\x86】selinux-policy-base的版本不符合ceph子包的安装条件,ceph子包安装失败
主要
sig/SDS
ceph
openEuler-22.03-LTS-SP2 Update 20230830
经各SIG及社区开发者贡献,本周openEuler-22.03-LTS-SP2修复版本已知问题7个,已知漏洞45个,热补丁1个。目前版本分支剩余待修复缺陷2个,缺陷/漏洞统计详见清单,缺陷/漏洞问题详见各软件包源码仓库
openEuler-22.03-LTS-SP2 Update版本CVE修复 及Bugfix list公示链接:
https://gitee.com/openeuler/release-management/issues/I7WC1W?from=project-i…
CVE修复:
CVE
仓库
score
CVE-2022-47022
hwloc
9.8
CVE-2022-48174
busybox
9.8
CVE-2020-22219
flac
9.8
CVE-2023-32002
nodejs
9.8
CVE-2023-38432
kernel
9.1
CVE-2023-39417
postgresql
8.8
CVE-2023-32006
nodejs
8.8
CVE-2023-39417
libpq
8.8
CVE-2022-32212
nodejs
8.1
CVE-2023-40305
indent
7.8
CVE-2023-40283
kernel
7.8
CVE-2021-46174
binutils
7.5
CVE-2022-25881
nodejs
7.5
CVE-2023-23918
nodejs
7.5
CVE-2023-30589
nodejs
7.5
CVE-2023-30581
nodejs
7.5
CVE-2023-32559
nodejs
7.5
CVE-2020-21469
libpq
7.5
CVE-2023-3867
kernel
7.3
CVE-2023-2454
libpq
7.2
CVE-2022-33196
microcode_ctl
6.7
CVE-2023-38712
libreswan
6.5
CVE-2023-38710
libreswan
6.5
CVE-2023-38711
libreswan
6.5
CVE-2023-36054
krb5
6.5
CVE-2023-32573
qt
6.5
CVE-2022-40982
microcode_ctl
6.5
CVE-2022-32213
nodejs
6.5
CVE-2022-32215
nodejs
6.5
CVE-2022-32214
nodejs
6.5
CVE-2022-35256
nodejs
6.5
CVE-2022-48522
perl
6.3
CVE-2022-47008
binutils
6
CVE-2023-1206
kernel
5.7
CVE-2022-48554
file
5.5
CVE-2022-47011
binutils
5.5
CVE-2023-4194
kernel
5.5
CVE-2023-34319
kernel
5.5
CVE-2023-38633
librsvg2
5.5
CVE-2023-2455
libpq
5.4
CVE-2023-30590
nodejs
5.3
CVE-2022-38090
microcode_ctl
4.4
CVE-2023-39418
libpq
4.3
CVE-2023-23920
nodejs
4.2
CVE-2023-4156
gawk
3.3
Bugfix:
issue
仓库
#I7VP5K:同步主线HISI uncore UC PMU和uncore H60PA/PAv3 PMU驱动到OLK-5.10
kernel
#I7X29C:【22.03-LTS-SP2】update版本新增kv_store软件包
distributeddatamgr_kv_store
#I7X270:【22.03-LTS-SP2】update版本新增datamgr_service软件包
distributeddatamgr_datamgr_service
#I7X1KS:【22.03-LTS-SP2】update版本新增data_object的软件包
distributeddatamgr_data_object
#I7X243:【22.03-LTS-SP2】update版本新增relational_store软件包
distributeddatamgr_relational_store
#I7TJ43:回合bugfix补丁
A-Tune
#I7V300:补丁回合
A-Tune-Collector
热补丁:
热补丁issue ID
cve
issue ID
所属仓库
score
I7WT55
CVE-2023-3389
I7GVI5
kernel
7.8
openEuler-22.03-LTS SP2版本编译构建信息查询链接:
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2
https://build.openeuler.openatom.cn/project/show/openEuler:22.03:LTS:SP2:Ep…
openEuler-22.03-LTS SP2 Update版本 发布源链接:
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/main/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/hotpatch_update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/docker_img/update/
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
https://repo.openeuler.org/openEuler-22.03-LTS-SP2/EPOL/update/multi_versio…
openEuler CVE 及 安全公告公示链接:
https://www.openeuler.org/zh/security/cve/
https://www.openeuler.org/zh/security/safety-bulletin/
https://repo.openeuler.org/security/data/cvrf/
https://repo.openeuler.org/security/data/hotpatch_cvrf/
openEuler-22.03-LTS-SP2 Update版本待修复问题清单公示(任务ID标注红色的问题单优先级高):
里程碑
任务ID
任务标题
优先级
sig组
关联仓库
openEuler-22.03-LTS-SP2-round-2
I795G3
【22.03-LTS-SP2 round2】本次转测源中出现多个版本的containers-common
主要
sig/sig-CloudNative
skopeo
openEuler-22.03-LTS-SP2-SEC
I7AFIR
【22.03-LTS-SP2 round2】【x86/arm】libkae-1.2.10-6.oe2203sp2安全编译选项Rpath/Runpath不满足
主要
sig/sig-AccLib
libkae
社区待修复漏洞:
openEuler社区根据漏洞严重等级采取差异化的修复策略,请各个SIG 关注涉及CVE组件的修复情况。
严重等级(Severity Rating)
漏洞修复时长
致命(Critical)
7天
高(High)
14天
中(Medium)
30天
低(Low)
30天
可参考社区安全委员会漏洞:https://gitee.com/openeuler/security-committee/wikis/%E7%A4%BE…
近14天将超期CVE(9.2日数据):
漏洞编号
Issue ID
剩余天数
CVSS评分
软件包
责任SIG
CVE-2022-48565
I7V732
6.44
9.8
python3
Base-service
CVE-2023-39417
I7SB9T
1.66
8.8
postgresql
DB
CVE-2020-24293
I7V71N
8.66
8.8
freeimage
dev-utils
CVE-2020-24292
I7V70T
8.66
8.8
freeimage
dev-utils
CVE-2020-24295
I7V70O
8.66
8.8
freeimage
dev-utils
CVE-2021-40263
I7V70Z
10.1
8.8
freeimage
dev-utils
CVE-2022-46884
I7VS3B
10.44
8.8
firefox
Application
CVE-2020-24165
I7WY1L
13.44
8.8
qemu
Virt
CVE-2022-46751
I7UK86
12.44
8.2
apache-ivy
sig-Java
CVE-2022-48566
I7V71W
13.44
8.1
python3
Base-service
CVE-2023-40315
I7U431
5.13
8
openstack-horizon
sig-openstack
CVE-2020-21426
I7V71R
8.66
7.8
freeimage
dev-utils
CVE-2022-47069
I7V6ZI
8.66
7.8
p7zip
dev-utils
CVE-2020-21428
I7V6ZB
8.66
7.8
freeimage
dev-utils
CVE-2023-40590
I7WN52
10.1
7.8
python-GitPython
sig-python-modules
CVE-2023-40577
I7VTBW
5.71
7.5
alertmanager
sig-CloudNative
CVE-2023-37369
I7VV7A
5.77
7.5
qt
Runtime
CVE-2022-48571
I7V73M
8.66
7.5
memcached
Application
CVE-2022-48541
I7V72B
8.66
7.5
ImageMagick
Others
CVE-2020-22570
I7V70D
8.66
7.5
memcached
Application
CVE-2020-21469
I7V6ZE
8.66
7.5
postgresql
DB
CVE-2023-37369
I7P5OT
8.66
7.5
qt5-qtbase
Programming-language
CVE-2021-34193
I7WN56
10.1
7.5
opensc
Base-service
CVE-2023-20588
I7WY4J
10.44
7.5
kernel
Kernel
CVE-2022-34038
I7V70G
11.44
7.5
etcd
sig-CloudNative
CVE-2022-40433
I7V738
11.85
7.5
openjdk-11
Compiler
CVE-2022-43357
I7V72K
12.44
7.5
sassc
Others
CVE-2022-43357
I7V72I
12.44
7.5
libsass
Base-service
CVE-2023-39663
I7WZIV
12.87
7.5
mathjax
sig-UKUI
CVE-2023-41105
I7VE3T
13.44
7.5
python3
Base-service
CVE-2023-40187
I7XN6A
12.87
7.3
freerdp
Application
CVE-2023-3865
I7ST5T
9.66
7.1
kernel
Kernel
CVE-2023-39355
I7XN5F
12.87
7
freerdp
Application
CVE-2023-36941
I7OM5C
0.44
6.1
mysql5
DB
CVE-2023-3824
I7RSD5
5.93
5.5
php
Base-service
CVE-2023-3823
I7RSC7
5.93
5.5
php
Base-service
CVE-2023-4132
I7QE3A
12.75
5.5
kernel
Kernel
CVE-2023-38559
I7PRTF
12.75
5.5
ghostscript
Base-service
CVE-2023-38560
I7PRDQ
12.75
5.5
ghostscript
Base-service
CVE-2023-40027
I7TI35
13.66
3.7
openstack-keystone
sig-openstack
openEuler 社区指导文档及开放平台链接:
openEuler 版本分支维护规范:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E7%89%…
openEuler release-management 版本分支PR指导:
https://gitee.com/openeuler/release-management/blob/master/openEuler%E5%BC%…
社区QA 版本测试提单规范
https://gitee.com/openeuler/QA/blob/master/%E7%A4%BE%E5%8C%BA%E7%89%88%E6%9…
社区QA 测试平台 radiates
https://radiatest.openeuler.org<https://radiatest.openeuler.org/>
1
0