This update for rekor fixes the following issues:
* CVE-2023-45288: rekor: golang.org/x/net/http2: Fixed close connections when
receiving too many headers (bsc#1236519)
* CVE-2024-6104: rekor: hashicorp/go-retryablehttp: Fixed sensitive
information disclosure inside log file (bsc#1227053)
* CVE-2025-22868: rekor: golang.org/x/oauth2/jws: Fixed unexpected memory
consumption during token parsing (bsc#1239191)
* CVE-2025-22869: rekor: golang.org/x/crypto/ssh: Fixed denial of service in
the Key Exchange (bsc#1239327)
* CVE-2025-27144: rekor: gopkg.in/go-jose/go-jose.v2,github.com/go-jose/go-
jose/v4,github.com/go-jose/go-jose/v3: Fixed denial of service in Go JOSE's
parsing (bsc#1237638)
* CVE-2025-30204: rekor: github.com/golang-jwt/jwt/v5: Fixed jwt-go allowing
excessive memory allocation during header parsing (bsc#1240468)
Other fixes:
* Update to version 1.3.10:
* Features
* Added --client-signing-algorithms flag (#1974)
* Fixes /...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-1332=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-1332=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1332=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1332=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1332=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1332=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1332=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* rekor-debuginfo-1.3.10-150400.4.25.1
* rekor-1.3.10-150400.4.25.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* rekor-debuginfo-1.3.10-150400.4.25.1
* rekor-1.3.10-150400.4.25.1
* Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* rekor-debuginfo-1.3.10-150400.4.25.1
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* rekor-1.3.10-150400.4.25.1
* SUSE...
Read the Full Advisory* bsc#1227053
* bsc#1236519
* bsc#1237638
* bsc#1239191
* bsc#1239327
* bsc#1240468
* jsc#SLE-23476
## References:
* https://www.suse.com/security/cve/CVE-2023-45288.html
* https://www.suse.com/security/cve/CVE-2024-6104.html
* https://www.suse.com/security/cve/CVE-2025-22868.html
* https://www.suse.com/security/cve/CVE-2025-22869.html
* https://www.suse.com/security/cve/CVE-2025-27144.html
* https://www.suse.com/security/cve/CVE-2025-30204.html
* https://bugzilla.suse.com/show_bug.cgi?id=1227053
* https://bugzilla.suse.com/show_bug.cgi?id=1236519
* https://bugzilla.suse.com/show_bug.cgi?id=1237638
* https://bugzilla.suse.com/show_bug.cgi?id=1239191
* https://bugzilla.suse.com/show_bug.cgi?id=1239327
* https://bugzilla.suse.com/show_bug.cgi?id=1240468
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FSLE-23476&page_caps=&user_role=
Get the latest Linux and open source security news straight to your inbox.