Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE: 2025:01989-1 moderate: Multi-Linux Manager Client Tools

opensuse
Calendar Grey June 18, 2025
Dist Opensuse Esm H88
Security patch released for Unified-Linux Manager Client Applications addressing several vulnerabilities with a medium severity classification.
An update that solves eight vulnerabilities, contains four features and has six security fixes can now be installed.

Description

This update fixes the following issues:

golang-github-prometheus-prometheus was updated to version 2.53.4:

* Security issues fixed:

* CVE-2023-45288: Require Go >= 1.23 for building (bsc#1236516)

* CVE-2025-22870: Bumped golang.org/x/net to version 0.39.0 (bsc#1238686)

* Other bugs fixes from version 2.53.4:

* Runtime: fixed GOGC being set to 0 when installed with empty prometheus.yml

file resulting high cpu usage

* Scrape: fixed dropping valid metrics after previous scrape failed

prometheus-blackbox_exporter was updated from version 0.24.0 to 0.26.0

(jsc#PED-12872):

* Security issues fixed:

* CVE-2025-22870: Fixed proxy bypassing using IPv6 zone IDs (bsc#1238680)

* CVE-2023-45288: Fixed closing connections when receiving too many headers

(bsc#1236515)

* Other changes from version 0.26.0:

* Changes:

* Replace go-kit/log with log/slog module.

* Features:

* Add metric to record tls ciphersuite negotiated during handshake.

* Add a way...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Manager Client Tools for SLE Micro 5

zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2025-1989=1

* SUSE Manager Proxy 4.3 Module

zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2025-1989=1

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2025-1989=1

* SUSE Manager Client Tools for SLE 15

zypper in -t patch SUSE-SLE-Manager-Tools-15-2025-1989=1

Package List

* SUSE Manager Client Tools for SLE Micro 5 (aarch64 s390x x86_64)

* prometheus-blackbox_exporter-0.26.0-150000.1.27.1

* SUSE Manager Proxy 4.3 Module (aarch64 ppc64le s390x x86_64)

* prometheus-blackbox_exporter-0.26.0-150000.1.27.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* prometheus-blackbox_exporter-0.26.0-150000.1.27.1

* SUSE Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64)

* grafana-11.5.5-150000.1.79.1

* firewalld-prometheus-config-0.1-150000.3.62.2

* golang-github-prometheus-prometheus-2.53.4-150000.3.62.2

* prometheus-blackbox_exporter-0.26.0-150000.1.27.1

* grafana-debuginfo-11.5.5-150000.1.79.1

References

* bsc#1208752

* bsc#1231844

* bsc#1233343

* bsc#1236510

* bsc#1236515

* bsc#1236516

* bsc#1238680

* bsc#1238686

* bsc#1238703

* bsc#1241683

* bsc#1241687

* bsc#1241809

* bsc#1243672

* bsc#1243714

* jsc#MSQA-992

* jsc#PED-11740

* jsc#PED-12872

* jsc#PED-12918

## References:

* https://www.suse.com/security/cve/CVE-2023-45288.html

* https://www.suse.com/security/cve/CVE-2024-9264.html

* https://www.suse.com/security/cve/CVE-2024-9476.html

* https://www.suse.com/security/cve/CVE-2025-22870.html

* https://www.suse.com/security/cve/CVE-2025-22872.html

* https://www.suse.com/security/cve/CVE-2025-2703.html

* https://www.suse.com/security/cve/CVE-2025-29923.html

* https://www.suse.com/security/cve/CVE-2025-3454.html

* https://bugzilla.suse.com/show_bug.cgi?id=1208752

* https://bugzilla.suse.com/show_bug.cgi?id=1231844

* https://bugzilla.suse.com/show_bug.cgi?id=1233343

* https://bugzilla.suse.com/show_bug.cgi?id=1236510

* https://bugzilla.suse.com/show_bug.cgi?id=1236515

* https://bugzilla.suse.com/show_bug.cgi?id=1236516

*...

Read the Full Advisory

Announcement ID: SUSE-SU-2025:01989-1
Release Date: 2025-06-18T02:11:30Z
Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Client Tools for SLE 15 * SUSE Manager Client Tools for SLE Micro 5 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 Module * SUSE Manager Retail Branch Server 4.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here