Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

openSUSE: rnp Moderate Security Update CVE-2025-13402,13470 2025-20116-1

opensuse
Calendar Grey November 28, 2025
Dist Opensuse Esm H88
openSUSE security update for rnp fixes two issues and a bug affecting Leap 16.0. Update recommended for better security.
An update that solves 2 vulnerabilities and has one bug fix can now be installed.

Description

This update for rnp fixes the following issues:

- update to 0.18.1:

* CVE-2025-13470: PKESK (public-key encrypted) session keys were

generated as all-zero, allowing trivial decryption of messages

encrypted with public keys only (boo#1253957, CVE-2025-13402)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-32=1

Patch

Package List

- openSUSE Leap 16.0:

librnp0-0.18.1-bp160.1.1

rnp-0.18.1-bp160.1.1

rnp-devel-0.18.1-bp160.1.1

References

* bsc#1253957

References:

* https://www.suse.com/security/cve/CVE-2025-13402.html

* https://www.suse.com/security/cve/CVE-2025-13470.html

Announcement ID: openSUSE-SU-2025-20116-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here