Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

openSUSE: 2025:0003-1 important: etcd advisory update for 5 issues

opensuse
Calendar Grey January 7, 2025
Dist Opensuse Esm H88
In openSUSE, etcd faces critical security vulnerabilities needing urgent fixes. Here are five notable issues with required updates to enhance security
An update that fixes 5 vulnerabilities is now available

Description

This update for etcd fixes the following issues:

Update to version 3.5.12:

* Bump golang.org/x/crypto to v0.17+ to address CVE-2023-48795

* test: fix TestHashKVWhenCompacting: ensure all goroutine finished

* print error log when creating peer listener failed

* mvcc: Printing etcd backend database related metrics inside

scheduleCompaction function

* dependency: update go version to 1.20.13

* commit bbolt transaction if there is any pending deleting operations

* add tests to test tx delete consistency.

* Don't flock snapshot files

* Backport adding digest for etcd base image.

* Add a unit tests and missing flags in etcd help.

* Add missing flag in etcd help.

* Backport testutils.ExecuteUntil to 3.5 branch

* member replace e2e test

* Check if be is nil to avoid panic when be is overriden with nil by

recoverSnapshotBackend on line 517

* Don't redeclare err and snapshot variable, fixing...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-3=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 ppc64le s390x x86_64):

etcd-3.5.12-bp156.4.3.1

etcdctl-3.5.12-bp156.4.3.1

etcdutl-3.5.12-bp156.4.3.1

References

https://www.suse.com/security/cve/CVE-2019-11254.html

https://www.suse.com/security/cve/CVE-2020-15106.html

https://www.suse.com/security/cve/CVE-2021-28235.html

https://www.suse.com/security/cve/CVE-2023-47108.html

https://www.suse.com/security/cve/CVE-2023-48795.html

https://bugzilla.suse.com/1174951

https://bugzilla.suse.com/1181400

https://bugzilla.suse.com/1183703

https://bugzilla.suse.com/1199031

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:0003-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here