Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE Leap 15.5: Security Advisory 2025:3943-1 CVE-2024-28885 Moderate

opensuse
Calendar Grey November 5, 2025
Dist Opensuse Esm H88
Update for openSUSE addressing three vulnerabilities in qatengine and qatlib enhancing system security effectively.
An update that solves three vulnerabilities can now be installed.

Description

This update for qatengine, qatlib fixes the following issues:

Note that the 1.6.1 release included in 1.7.0 fixes the following

vulnerabilities:

* bsc#1233363 (CVE-2024-28885)

* bsc#1233365 (CVE-2024-31074)

* bsc#1233366 (CVE-2024-33617)

Update to 1.7.0:

* ipp-crypto name change to cryptography-primitives

* QAT_SW GCM memory leak fix in cleanup function

* Update limitation section in README for v1.7.0 release

* Fix build with OPENSSL_NO_ENGINE

* Fix for build issues with qatprovider in qatlib

* Bug fixes and README updates to v1.7.0

* Remove qat_contig_mem driver support

* Add support for building QAT Engine ENGINE and PROVIDER modules with QuicTLS

3.x libraries

* Fix for DSA issue with openssl3.2

* Fix missing lower bounds check on index i

* Enabled SW Fallback support for FBSD

* Fix for segfault issue when SHIM config section is unavailable

* Fix for Coverity & Resource leak

* Fix for RSA failure with SVM enabled in openssl-3.2

* SM3...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch SUSE-2025-3943=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-3943=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-3943=1

* SUSE Linux Enterprise Server 15 SP5 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-3943=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-3943=1

Package List

* openSUSE Leap 15.5 (x86_64)

* libqatzip3-debuginfo-1.1.0-150500.3.2.1

* qatzip-devel-1.1.0-150500.3.2.1

* qatengine-debugsource-1.7.0-150500.3.3.1

* libqatzip3-1.1.0-150500.3.2.1

* libqat4-24.09.0-150500.3.3.1

* qatlib-debuginfo-24.09.0-150500.3.3.1

* qatzip-debuginfo-1.1.0-150500.3.2.1

* qatengine-1.7.0-150500.3.3.1

* qatlib-debugsource-24.09.0-150500.3.3.1

* qatlib-24.09.0-150500.3.3.1

* libusdm0-24.09.0-150500.3.3.1

* qatzip-1.1.0-150500.3.2.1

* libqat4-debuginfo-24.09.0-150500.3.3.1

* qatzip-debugsource-1.1.0-150500.3.2.1

* libusdm0-debuginfo-24.09.0-150500.3.3.1

* qatengine-debuginfo-1.7.0-150500.3.3.1

* qatlib-devel-24.09.0-150500.3.3.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)

* libusdm0-debuginfo-24.09.0-150500.3.3.1

* qatzip-devel-1.1.0-150500.3.2.1

* qatengine-debugsource-1.7.0-150500.3.3.1

* libqatzip3-1.1.0-150500.3.2.1

* libqat4-24.09.0-150500.3.3.1

* qatlib-debuginfo-24.09.0-150500.3.3.1

* qatzip-debuginfo-1.1.0-150500.3.2.1

* qatengine-1.7.0-150500.3.3.1

*...

Read the Full Advisory

References

* bsc#1233363

* bsc#1233365

* bsc#1233366

## References:

* https://www.suse.com/security/cve/CVE-2024-28885.html

* https://www.suse.com/security/cve/CVE-2024-31074.html

* https://www.suse.com/security/cve/CVE-2024-33617.html

* https://bugzilla.suse.com/show_bug.cgi?id=1233363

* https://bugzilla.suse.com/show_bug.cgi?id=1233365

* https://bugzilla.suse.com/show_bug.cgi?id=1233366

Announcement ID: SUSE-SU-2025:3943-1
Release Date: 2025-11-05T08:16:21Z
Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here