Bugzilla – Bug 1173786
php-fpm in php7 package lacks /run/php for socket
Last modified: 2021-09-14 12:51:51 UTC
php-fpm should provide a tmpdir.d entry to allow adding sockets for fpm. This way, it can talk to e.g. nginx without using a TCP socket.
Please also apply this to the next sle15 maintenance update (sr#819078)
This is an autogenerated message for OBS integration: This bug (1173786) was mentioned in https://build.opensuse.org/request/show/819153 Factory / php7
This is an autogenerated message for OBS integration: This bug (1173786) was mentioned in https://build.opensuse.org/request/show/819741 Factory / php7
This is an autogenerated message for OBS integration: This bug (1173786) was mentioned in https://build.opensuse.org/request/show/819887 Factory / php7
Submitted for TW/php7 and 15sp2/php7. If anything is missing, let me know.
(Thanks Daniel for Factory submit.)
SUSE-RU-2020:2162-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1173786 CVE References: JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): php7-7.4.6-3.3.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (src): php7-7.4.6-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Hi Petr, can you send this fix for SLE-15:Update too? Thanks.
Zsolt, done.
openSUSE-RU-2020:1195-1: An update that has one recommended fix can now be installed. Category: recommended (moderate) Bug References: 1173786 CVE References: JIRA References: Sources used: openSUSE Leap 15.2 (src): php7-7.4.6-lp152.2.3.2, php7-test-7.4.6-lp152.2.3.2
SUSE-SU-2020:2455-1: An update that solves one vulnerability and has two fixes is now available. Category: security (moderate) Bug References: 1173786,1174010,1175223 CVE References: CVE-2020-7068 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 15-SP1 (src): php7-7.2.5-4.61.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (src): php7-7.2.5-4.61.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:1354-1: An update that solves one vulnerability and has two fixes is now available. Category: security (moderate) Bug References: 1173786,1174010,1175223 CVE References: CVE-2020-7068 JIRA References: Sources used: openSUSE Leap 15.1 (src): php7-7.2.5-lp151.6.32.1, php7-test-7.2.5-lp151.6.32.1
I'd say so. Doesn't hurt and provides consistency and it seems that tmpfiles.d is already provided with the systemd versions provided in SLE12-SP3/4 (according to https://documentation.suse.com/sles/12-SP4/html/SLES-all/cha-systemd.html)
Submitted also for 12/php74, 12/php72, 12/php7.
SUSE-SU-2020:2896-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1173786,1177351,1177352 CVE References: CVE-2020-7069,CVE-2020-7070 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): php74-7.4.6-1.13.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php74-7.4.6-1.13.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:2920-1: An update that solves one vulnerability and has one errata is now available. Category: security (important) Bug References: 1173786,1177352 CVE References: CVE-2020-7070 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): php7-7.0.7-50.102.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php7-7.0.7-50.102.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:2943-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1173786,1177351,1177352 CVE References: CVE-2020-7069,CVE-2020-7070 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): php72-7.2.5-1.54.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): php72-7.2.5-1.54.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2020:2997-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1173786,1177351,1177352 CVE References: CVE-2020-7069,CVE-2020-7070 JIRA References: Sources used: SUSE Linux Enterprise Server for SAP 15 (src): php7-7.2.5-4.67.2 SUSE Linux Enterprise Server 15-LTSS (src): php7-7.2.5-4.67.2 SUSE Linux Enterprise Module for Web Scripting 15-SP1 (src): php7-7.2.5-4.67.2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (src): php7-7.2.5-4.67.2 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): php7-7.2.5-4.67.2 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): php7-7.2.5-4.67.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:1767-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1173786,1177351,1177352 CVE References: CVE-2020-7069,CVE-2020-7070 JIRA References: Sources used: openSUSE Leap 15.1 (src): php7-7.2.5-lp151.6.36.7, php7-test-7.2.5-lp151.6.36.7