This update for varnish fixes the following issues:
- Update to release 7.7.1
* VSV-16: Resolve request smuggling attack
- Update to release 7.7.0
* The `linux` jail gained control of transparent huge pages settings.
* An issue has been fixed which could cause a crash when varnishd
receives an invalid Content-Range header from a backend.
* Timestamping for HTTP/2 requests (when idle period begins) has been
switched to be more in line with HTTP/1.
* VSV-15: The client connection is now always closed when a malformed
request is received. [CVE-2025-30346, boo#1239892]
- Update to release 7.6.0
* The Varnish Delivery Processor (VDP) filter API has been generalized
to also accommodate future use for backend request bodies.
* VDPs with no vdp_bytes_f function are now supported if the vdp_init_f
returns a value greater than zero to signify that the filter is not to
be added to the chain. This is...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2025-179=1
- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):
libvarnishapi3-7.7.1-bp156.2.3.1
varnish-7.7.1-bp156.2.3.1
varnish-devel-7.7.1-bp156.2.3.1
https://www.suse.com/security/cve/CVE-2013-4484.html
https://www.suse.com/security/cve/CVE-2023-44487.html
https://www.suse.com/security/cve/CVE-2024-30156.html
https://www.suse.com/security/cve/CVE-2025-30346.html
https://bugzilla.suse.com/1216123
https://bugzilla.suse.com/1221942
https://bugzilla.suse.com/1239892
Get the latest Linux and open source security news straight to your inbox.