This update for himmelblau fixes the following issues:
- Update to version 0.9.23+git.0.9776141:
* CVE-2025-59044: Fixed GID collision of same-name groups allowing privilege escalation (bsc#1250687)
* deps(rust): bump the all-cargo-updates group
* CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249013)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-80=1
- openSUSE Leap 16.0:
himmelblau-0.9.23+git.0.9776141-160000.1.1
himmelblau-qr-greeter-0.9.23+git.0.9776141-160000.1.1
himmelblau-sshd-config-0.9.23+git.0.9776141-160000.1.1
himmelblau-sso-0.9.23+git.0.9776141-160000.1.1
libnss_himmelblau2-0.9.23+git.0.9776141-160000.1.1
pam-himmelblau-0.9.23+git.0.9776141-160000.1.1
* bsc#1249013
* bsc#1250687
References:
* https://www.suse.com/security/cve/CVE-2025-58160.html
* https://www.suse.com/security/cve/CVE-2025-59044.html
Get the latest Linux and open source security news straight to your inbox.