<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for gcc7</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2023:3662-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2023-09-18T19:48:26Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2023-09-18T19:48:26Z</InitialReleaseDate>
    <CurrentReleaseDate>2023-09-18T19:48:26Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for gcc7</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for gcc7 fixes the following issues:

Security issues fixed:

- CVE-2023-4039: Fixed incorrect stack protector for C99 VLAs on Aarch64 (bsc#1214052).
- CVE-2019-15847: Fixed POWER9 DARN miscompilation.  (bsc#1149145)
- CVE-2019-14250: Includes fix for LTO linker plugin heap overflow.  (bsc#1142649)

Update to GCC 7.5.0 release.

Other changes:

- Fixed KASAN kernel compile. (bsc#1205145)
- Fixed ICE with C++17 code. (bsc#1204505)
- Fixed altivec.h redefining bool in C++ which makes bool unusable (bsc#1195517):
- Adjust gnats idea of the target, fixing the build of gprbuild.  [bsc#1196861]
- Do not handle exceptions in std::thread (jsc#CAR-1182)
- add -fpatchable-function-entry feature to gcc-7.
- Fixed glibc namespace violation with getauxval. (bsc#1167939)
- Backport aarch64 Straight Line Speculation mitigation [bsc#1172798, CVE-2020-13844]
- Enable fortran for the nvptx offload compiler. 
- Update README.First-for.SuSE.packagers
- Avoid assembler errors with AVX512 gather and scatter instructions when using -masm=intel.
- Backport the aarch64 -moutline-atomics feature and accumulated fixes but not its
  default enabling.  (jsc#SLE-12209, bsc#1167939)
- Fixed memcpy miscompilation on aarch64.  (bsc#1178624, bsc#1178577)
- Fixed debug line info for try/catch.  (bsc#1178614)
- Fixed corruption of pass private -&gt;aux via DF. (gcc#94148)
- Fixed debug information issue with inlined functions and passed by reference arguments. [gcc#93888]
- Fixed register allocation issue with exception handling code on s390x.  (bsc#1161913)
- Backport PR target/92692 to fix miscompilation of some atomic code on aarch64. (bsc#1150164)
- Fixed miscompilation in vectorized code for s390x.  (bsc#1160086) [gcc#92950]
- Fixed miscompilation with thread-safe local static initialization.  [gcc#85887]
- Fixed debug info created for array definitions that complete an earlier declaration.  [bsc#1146475]
- Fixed vector shift miscompilation on s390.  (bsc#1141897)
- Add gcc7 -flive-patching patch.  [bsc#1071995, fate#323487]
- Strip -flto from $optflags.
- Disables switch jump-tables when retpolines are used.  (bsc#1131264, jsc#SLE-6738)
- Fixed ICE compiling tensorflow on aarch64.  (bsc#1129389)
- Fixed for aarch64 FMA steering pass use-after-free.  (bsc#1128794)
- Fixed ICE compiling tensorflow.  (bsc#1129389)
- Fixed s390x FP load-and-test issue.  (bsc#1124644)
- Adjust gnat manual entries in the info directory.  (bsc#1114592)
- Fixed to no longer try linking -lieee with -mieee-fp.  (bsc#1084842)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES12-SP5-SAP-Azure-LI-BYOS-Production-2023-3662,Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production-2023-3662,SUSE-2023-3662,SUSE-SLE-Module-Toolchain-12-2023-3662,SUSE-SLE-SERVER-12-SP5-2023-3662</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/</URL>
      <Description>Link for SUSE-SU-2023:3662-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2024-February/018047.html</URL>
      <Description>E-Mail link for SUSE-SU-2023:3662-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1071995</URL>
      <Description>SUSE Bug 1071995</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1084842</URL>
      <Description>SUSE Bug 1084842</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1114592</URL>
      <Description>SUSE Bug 1114592</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1124644</URL>
      <Description>SUSE Bug 1124644</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1128794</URL>
      <Description>SUSE Bug 1128794</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1129389</URL>
      <Description>SUSE Bug 1129389</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1131264</URL>
      <Description>SUSE Bug 1131264</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1141897</URL>
      <Description>SUSE Bug 1141897</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1142649</URL>
      <Description>SUSE Bug 1142649</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1146475</URL>
      <Description>SUSE Bug 1146475</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1148517</URL>
      <Description>SUSE Bug 1148517</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1149145</URL>
      <Description>SUSE Bug 1149145</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1150164</URL>
      <Description>SUSE Bug 1150164</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1160086</URL>
      <Description>SUSE Bug 1160086</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1161913</URL>
      <Description>SUSE Bug 1161913</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1167939</URL>
      <Description>SUSE Bug 1167939</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172798</URL>
      <Description>SUSE Bug 1172798</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178577</URL>
      <Description>SUSE Bug 1178577</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178614</URL>
      <Description>SUSE Bug 1178614</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178624</URL>
      <Description>SUSE Bug 1178624</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178675</URL>
      <Description>SUSE Bug 1178675</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181618</URL>
      <Description>SUSE Bug 1181618</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195517</URL>
      <Description>SUSE Bug 1195517</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196861</URL>
      <Description>SUSE Bug 1196861</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1204505</URL>
      <Description>SUSE Bug 1204505</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1205145</URL>
      <Description>SUSE Bug 1205145</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1214052</URL>
      <Description>SUSE Bug 1214052</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-14250/</URL>
      <Description>SUSE CVE CVE-2019-14250 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-15847/</URL>
      <Description>SUSE CVE CVE-2019-15847 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13844/</URL>
      <Description>SUSE CVE CVE-2020-13844 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-4039/</URL>
      <Description>SUSE CVE CVE-2023-4039 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Toolchain 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Toolchain 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12" CPE="cpe:/o:suse:sle-module-toolchain:12">SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="cpp7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cpp7-7.5.0+r278197-13.1">cpp7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-7.5.0+r278197-13.1">gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libasan4-7.5.0+r278197-13.1">
      <FullProductName ProductID="libasan4-7.5.0+r278197-13.1">libasan4-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcilkrts5-7.5.0+r278197-13.1">
      <FullProductName ProductID="libcilkrts5-7.5.0+r278197-13.1">libcilkrts5-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libubsan0-7.5.0+r278197-13.1">
      <FullProductName ProductID="libubsan0-7.5.0+r278197-13.1">libubsan0-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-aarch64-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-aarch64-gcc7-7.5.0+r278197-13.1">cross-aarch64-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-aarch64-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-aarch64-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-aarch64-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-arm-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-arm-gcc7-7.5.0+r278197-13.1">cross-arm-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-arm-none-gcc7-bootstrap-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-arm-none-gcc7-bootstrap-7.5.0+r278197-13.1">cross-arm-none-gcc7-bootstrap-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-avr-gcc7-bootstrap-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-avr-gcc7-bootstrap-7.5.0+r278197-13.1">cross-avr-gcc7-bootstrap-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-hppa-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-hppa-gcc7-7.5.0+r278197-13.1">cross-hppa-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-hppa-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-hppa-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-hppa-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-i386-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-i386-gcc7-7.5.0+r278197-13.1">cross-i386-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-i386-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-i386-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-i386-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-m68k-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-m68k-gcc7-7.5.0+r278197-13.1">cross-m68k-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-m68k-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-m68k-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-m68k-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-mips-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-mips-gcc7-7.5.0+r278197-13.1">cross-mips-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-mips-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-mips-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-mips-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-nvptx-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-nvptx-gcc7-7.5.0+r278197-13.1">cross-nvptx-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-nvptx-newlib7-devel-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-nvptx-newlib7-devel-7.5.0+r278197-13.1">cross-nvptx-newlib7-devel-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-ppc64-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-ppc64-gcc7-7.5.0+r278197-13.1">cross-ppc64-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-ppc64-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-ppc64-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-ppc64-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-ppc64le-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-ppc64le-gcc7-7.5.0+r278197-13.1">cross-ppc64le-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-ppc64le-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-ppc64le-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-ppc64le-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-s390x-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-s390x-gcc7-7.5.0+r278197-13.1">cross-s390x-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-s390x-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-s390x-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-s390x-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-sparc-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-sparc-gcc7-7.5.0+r278197-13.1">cross-sparc-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-sparc64-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-sparc64-gcc7-7.5.0+r278197-13.1">cross-sparc64-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-sparc64-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-sparc64-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-sparc64-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-sparcv9-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-sparcv9-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-sparcv9-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-x86_64-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-x86_64-gcc7-7.5.0+r278197-13.1">cross-x86_64-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cross-x86_64-gcc7-icecream-backend-7.5.0+r278197-13.1">
      <FullProductName ProductID="cross-x86_64-gcc7-icecream-backend-7.5.0+r278197-13.1">cross-x86_64-gcc7-icecream-backend-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-32bit-7.5.0+r278197-13.1">gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-ada-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-ada-7.5.0+r278197-13.1">gcc7-ada-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-ada-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-ada-32bit-7.5.0+r278197-13.1">gcc7-ada-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-c++-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-c++-7.5.0+r278197-13.1">gcc7-c++-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-c++-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-c++-32bit-7.5.0+r278197-13.1">gcc7-c++-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-fortran-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-fortran-7.5.0+r278197-13.1">gcc7-fortran-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-fortran-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-fortran-32bit-7.5.0+r278197-13.1">gcc7-fortran-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-go-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-go-7.5.0+r278197-13.1">gcc7-go-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-go-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-go-32bit-7.5.0+r278197-13.1">gcc7-go-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-info-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-info-7.5.0+r278197-13.1">gcc7-info-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-locale-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-locale-7.5.0+r278197-13.1">gcc7-locale-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-obj-c++-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-obj-c++-7.5.0+r278197-13.1">gcc7-obj-c++-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-obj-c++-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-obj-c++-32bit-7.5.0+r278197-13.1">gcc7-obj-c++-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-objc-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-objc-7.5.0+r278197-13.1">gcc7-objc-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-objc-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-objc-32bit-7.5.0+r278197-13.1">gcc7-objc-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gcc7-testresults-7.5.0+r278197-13.1">
      <FullProductName ProductID="gcc7-testresults-7.5.0+r278197-13.1">gcc7-testresults-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libada7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libada7-7.5.0+r278197-13.1">libada7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libada7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libada7-32bit-7.5.0+r278197-13.1">libada7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libasan4-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libasan4-32bit-7.5.0+r278197-13.1">libasan4-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libatomic1-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libatomic1-gcc7-7.5.0+r278197-13.1">libatomic1-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libatomic1-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libatomic1-gcc7-32bit-7.5.0+r278197-13.1">libatomic1-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libcilkrts5-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libcilkrts5-32bit-7.5.0+r278197-13.1">libcilkrts5-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgcc_s1-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgcc_s1-gcc7-7.5.0+r278197-13.1">libgcc_s1-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgcc_s1-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgcc_s1-gcc7-32bit-7.5.0+r278197-13.1">libgcc_s1-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgfortran4-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgfortran4-7.5.0+r278197-13.1">libgfortran4-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgfortran4-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgfortran4-32bit-7.5.0+r278197-13.1">libgfortran4-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgo11-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgo11-7.5.0+r278197-13.1">libgo11-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgo11-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgo11-32bit-7.5.0+r278197-13.1">libgo11-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgomp1-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgomp1-gcc7-7.5.0+r278197-13.1">libgomp1-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgomp1-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libgomp1-gcc7-32bit-7.5.0+r278197-13.1">libgomp1-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libitm1-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libitm1-gcc7-7.5.0+r278197-13.1">libitm1-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libitm1-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libitm1-gcc7-32bit-7.5.0+r278197-13.1">libitm1-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="liblsan0-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="liblsan0-gcc7-7.5.0+r278197-13.1">liblsan0-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmpx2-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libmpx2-gcc7-7.5.0+r278197-13.1">libmpx2-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmpx2-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libmpx2-gcc7-32bit-7.5.0+r278197-13.1">libmpx2-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmpxwrappers2-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libmpxwrappers2-gcc7-7.5.0+r278197-13.1">libmpxwrappers2-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmpxwrappers2-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libmpxwrappers2-gcc7-32bit-7.5.0+r278197-13.1">libmpxwrappers2-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libobjc4-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libobjc4-gcc7-7.5.0+r278197-13.1">libobjc4-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libobjc4-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libobjc4-gcc7-32bit-7.5.0+r278197-13.1">libobjc4-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libquadmath0-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libquadmath0-gcc7-7.5.0+r278197-13.1">libquadmath0-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libquadmath0-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libquadmath0-gcc7-32bit-7.5.0+r278197-13.1">libquadmath0-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-devel-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libstdc++6-devel-gcc7-7.5.0+r278197-13.1">libstdc++6-devel-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1">libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libstdc++6-gcc7-7.5.0+r278197-13.1">libstdc++6-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-gcc7-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libstdc++6-gcc7-32bit-7.5.0+r278197-13.1">libstdc++6-gcc7-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libstdc++6-gcc7-locale-7.5.0+r278197-13.1">
      <FullProductName ProductID="libstdc++6-gcc7-locale-7.5.0+r278197-13.1">libstdc++6-gcc7-locale-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libtsan0-gcc7-7.5.0+r278197-13.1">
      <FullProductName ProductID="libtsan0-gcc7-7.5.0+r278197-13.1">libtsan0-gcc7-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libubsan0-32bit-7.5.0+r278197-13.1">
      <FullProductName ProductID="libubsan0-32bit-7.5.0+r278197-13.1">libubsan0-32bit-7.5.0+r278197-13.1</FullProductName>
    </Branch>
    <Relationship ProductReference="cpp7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:cpp7-7.5.0+r278197-13.1">cpp7-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:gcc7-7.5.0+r278197-13.1">gcc7-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libasan4-7.5.0+r278197-13.1">libasan4-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1">libcilkrts5-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libubsan0-7.5.0+r278197-13.1">libubsan0-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="cpp7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:cpp7-7.5.0+r278197-13.1">cpp7-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:gcc7-7.5.0+r278197-13.1">gcc7-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libasan4-7.5.0+r278197-13.1">libasan4-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1">libcilkrts5-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libubsan0-7.5.0+r278197-13.1">libubsan0-7.5.0+r278197-13.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="cpp7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:cpp7-7.5.0+r278197-13.1">cpp7-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="cross-nvptx-gcc7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-gcc7-7.5.0+r278197-13.1">cross-nvptx-gcc7-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="cross-nvptx-newlib7-devel-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-newlib7-devel-7.5.0+r278197-13.1">cross-nvptx-newlib7-devel-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-7.5.0+r278197-13.1">gcc7-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-32bit-7.5.0+r278197-13.1">gcc7-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-ada-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-7.5.0+r278197-13.1">gcc7-ada-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-ada-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-32bit-7.5.0+r278197-13.1">gcc7-ada-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-c++-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-7.5.0+r278197-13.1">gcc7-c++-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-c++-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-32bit-7.5.0+r278197-13.1">gcc7-c++-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-fortran-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-7.5.0+r278197-13.1">gcc7-fortran-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-fortran-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-32bit-7.5.0+r278197-13.1">gcc7-fortran-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-info-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-info-7.5.0+r278197-13.1">gcc7-info-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="gcc7-locale-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:gcc7-locale-7.5.0+r278197-13.1">gcc7-locale-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libada7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:libada7-7.5.0+r278197-13.1">libada7-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libada7-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:libada7-32bit-7.5.0+r278197-13.1">libada7-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libstdc++6-devel-gcc7-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-7.5.0+r278197-13.1">libstdc++6-devel-gcc7-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Toolchain 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1">libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Module for Toolchain 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libasan4-7.5.0+r278197-13.1">libasan4-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libasan4-32bit-7.5.0+r278197-13.1">libasan4-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libcilkrts5-7.5.0+r278197-13.1">libcilkrts5-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1">libcilkrts5-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgfortran4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libgfortran4-7.5.0+r278197-13.1">libgfortran4-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgfortran4-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1">libgfortran4-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libubsan0-7.5.0+r278197-13.1">libubsan0-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1">libubsan0-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-7.5.0+r278197-13.1">libasan4-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libasan4-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-32bit-7.5.0+r278197-13.1">libasan4-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-7.5.0+r278197-13.1">libcilkrts5-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libcilkrts5-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1">libcilkrts5-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgfortran4-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-7.5.0+r278197-13.1">libgfortran4-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgfortran4-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1">libgfortran4-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-7.5.0+r278197-13.1">libubsan0-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libubsan0-32bit-7.5.0+r278197-13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1">libubsan0-32bit-7.5.0+r278197-13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2019-14250</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-newlib7-devel-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-info-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-locale-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-14250.html</URL>
        <Description>CVE-2019-14250</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1142649</URL>
        <Description>SUSE Bug 1142649</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.</Note>
    </Notes>
    <CVE>CVE-2019-15847</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-newlib7-devel-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-info-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-locale-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.2</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-15847.html</URL>
        <Description>CVE-2019-15847</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149145</URL>
        <Description>SUSE Bug 1149145</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."</Note>
    </Notes>
    <CVE>CVE-2020-13844</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-newlib7-devel-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-info-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-locale-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13844.html</URL>
        <Description>CVE-2020-13844</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172798</URL>
        <Description>SUSE Bug 1172798</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** 

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains 
that target AArch64 allows an attacker to exploit an existing buffer 
overflow in dynamically-sized local variables in your application 
without this being detected. This stack-protector failure only applies 
to C99-style dynamically-sized local variables or those created using 
alloca(). The stack-protector operates as intended for statically-sized 
local variables.

The default behavior when the stack-protector 
detects an overflow is to terminate your application, resulting in 
controlled loss of availability. An attacker who can exploit a buffer 
overflow without triggering the stack-protector might be able to change 
program flow control to cause an uncontrolled loss of availability or to
 go further and affect confidentiality or integrity. NOTE: The GCC project argues that this is a missed hardening bug and not a vulnerability by itself.





</Note>
    </Notes>
    <CVE>CVE-2023-4039</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cpp7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:cross-nvptx-newlib7-devel-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-ada-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-c++-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-fortran-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-info-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:gcc7-locale-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libada7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Toolchain 12:libstdc++6-devel-gcc7-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libasan4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libcilkrts5-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libgfortran4-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-32bit-7.5.0+r278197-13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:libubsan0-7.5.0+r278197-13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>8.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233662-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-4039.html</URL>
        <Description>CVE-2023-4039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1214052</URL>
        <Description>SUSE Bug 1214052</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1228298</URL>
        <Description>SUSE Bug 1228298</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
