Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE: git-bug Important Update 2025-20143-1 CVE-2025-47911 DoS

opensuse
Calendar Grey December 5, 2025
Dist Opensuse Esm H88
An important update for git-bug on openSUSE addresses 7 vulnerabilities and includes various bug fixes.
An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description

This update for git-bug fixes the following issues:

Changes in git-bug:

- Revendor to include fixed version of depending libraries:

- GO-2025-4116 (CVE-2025-47913, bsc#1253506) upgrade

golang.org/x/crypto to v0.43.0

- GO-2025-3900 (GHSA-2464-8j7c-4cjm) upgrade

github.com/go-viper/mapstructure/v2 to v2.4.0

- GO-2025-3787 (GHSA-fv92-fjc5-jj9h) included in the previous

- GO-2025-3754 (GHSA-2x5j-vhc8-9cwm) upgrade

github.com/cloudflare/circl to v1.6.1

- GO-2025-4134 (CVE-2025-58181, bsc#1253930) upgrade

golang.org/x/crypto/ssh to v0.45.0

- GO-2025-4135 (CVE-2025-47914, bsc#1254084) upgrade

golang.org/x/crypto/ssh/agent to v0.45.0

- Revendor to include golang.org/x/net/html v 0.45.0 to prevent

possible DoS by various algorithms with quadratic complexity

when parsing HTML documents (bsc#1251463, CVE-2025-47911 and

bsc#1251664, CVE-2025-58190).

Update to version 0.10.1:

- cli: ignore missing sections when removing configuration (ddb22a2f)

Update...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

git-bug-0.10.1-bp160.1.1

git-bug-bash-completion-0.10.1-bp160.1.1

git-bug-fish-completion-0.10.1-bp160.1.1

git-bug-zsh-completion-0.10.1-bp160.1.1

References

* bsc#1234565

* bsc#1239494

* bsc#1251463

* bsc#1251664

* bsc#1253506

* bsc#1253930

* bsc#1254084

References:

* https://www.suse.com/security/cve/CVE-2024-45337.html

* https://www.suse.com/security/cve/CVE-2025-22869.html

* https://www.suse.com/security/cve/CVE-2025-47911.html

* https://www.suse.com/security/cve/CVE-2025-47913.html

* https://www.suse.com/security/cve/CVE-2025-47914.html

* https://www.suse.com/security/cve/CVE-2025-58181.html

* https://www.suse.com/security/cve/CVE-2025-58190.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025-20143-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here