Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE Leap 15.6: SUSE-SU-2025:01591-1 moderate: python-maturin update

opensuse
Calendar Grey May 20, 2025
Dist Opensuse Esm H88
A release update for python-maturin has been issued to address memory management problems and vulnerabilities related to crossbeam, which became available on May 19, 2025.
An update that solves two vulnerabilities can now be installed.

Description

This update for python-maturin fixes the following issues:

* CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch`

when `Some(...)` value passed as `properties` argument to either function

(bsc#1242631).

* CVE-2025-4574: crossbeam-channel: double-free leading to possible memory

corruption in `Channel::drop` when dropping a channel (bsc#1243177).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2025-1591=1 openSUSE-SLE-15.6-2025-1591=1

Package List

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)

* python311-maturin-1.4.0-150600.3.6.1

References

* bsc#1242631

* bsc#1243177

## References:

* https://www.suse.com/security/cve/CVE-2025-3416.html

* https://www.suse.com/security/cve/CVE-2025-4574.html

* https://bugzilla.suse.com/show_bug.cgi?id=1242631

* https://bugzilla.suse.com/show_bug.cgi?id=1243177

Announcement ID: SUSE-SU-2025:01591-1
Release Date: 2025-05-19T21:24:50Z
Affected Products: * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here