Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE 15-SP6: 2025:0021-1 important: gh remote code execution

opensuse
Calendar Grey January 22, 2025
Dist Opensuse Esm H88
openSUSE Security Patch addresses significant remote code execution vulnerability in gh, providing urgent installation guidance.
An update that fixes one vulnerability is now available

Description

This update for gh fixes the following issues:

- Update to version 2.65.0:

* Bump cli/go-gh for indirect security vulnerability

* Panic mustParseTrackingRef if format is incorrect

* Move trackingRef into pr create package

* Make tryDetermineTrackingRef tests more respective of reality

* Rework tryDetermineTrackingRef tests

* Avoid pointer return from determineTrackingBranch

* Doc determineTrackingBranch

* Don't use pointer for determineTrackingBranch branchConfig

* Panic if tracking ref can't be reconstructed

* Document and rework pr create tracking branch lookup

* Upgrade generated workflows

* Fixed test for stdout in non-tty use case of repo fork

* Fix test

* Alternative: remove LocalBranch from BranchConfig

* Set LocalBranch even if the git config fails

* Add test for permissions check for security and analysis edits (#1)

* print repo url to stdout

* Update pkg/cmd/auth/login/login.go

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP6:

zypper in -t patch openSUSE-2025-21=1

Package List

- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):

gh-2.65.0-bp156.2.17.1

gh-debuginfo-2.65.0-bp156.2.17.1

- openSUSE Backports SLE-15-SP6 (noarch):

gh-bash-completion-2.65.0-bp156.2.17.1

gh-fish-completion-2.65.0-bp156.2.17.1

gh-zsh-completion-2.65.0-bp156.2.17.1

References

https://www.suse.com/security/cve/CVE-2024-52308.html

https://bugzilla.suse.com/1233387

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:0021-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP6 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here