File _patchinfo of Package patchinfo.6593

<patchinfo incident="6593">
  <issue id="1029696" tracker="bnc">VUL-0: apparmor: "rcapparmor reload" unloads all LXD profiles</issue>
  <issue id="1016259" tracker="bnc">apparmor seems to start too early causing some failures when /usr is on a separate partition</issue>
  <issue id="1017260" tracker="bnc">apparmor.service missing in Leap</issue>
  <issue id="2017-6507" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <reboot_needed/>
  <packager>cboltz</packager>
  <description>
This update for apparmor fixes the following issues:

These security issues were fixed:

- CVE-2017-6507: Preserve unknown profiles when reloading apparmor.service (lp#1668892, boo#1029696)
- boo#1017260: Migration to apparmor.service accidently disable AppArmor.
  Note: This will re-enable AppArmor if it was disabled by the last update.
  You'll need to "rcapparmor reload" to actually load the profiles, and then
  check aa-status for programs that need to be restarted to apply the profiles.

These non-security issues were fixed:

- Fixed crash in aa-logprof on specific change_hat events
- boo#1016259: Added var.mount dependeny to apparmor.service

The aa-remove-unknown utility was added to unload unknown profiles (lp#1668892)
</description>
  <summary>Security update for apparmor</summary>
</patchinfo>
openSUSE Build Service is sponsored by