This update for aws-efs-utils fixes the following issues:
Update to version 2.3.3 (bsc#1240044).
Security issues fixed:
* CVE-2025-55159: slab: incorrect bounds check in `get_disjoint_mut` function
can lead to potential crash due to out-of-bounds access (bsc#1248055).
* CVE-2020-35881: traitobject: log4rs: out-of-bounds write due to fat pointer
layout assumptions (bsc#1249851).
Other issues fixed:
* Build and install efs-proxy binary (bsc#1240044).
* Fixed in version 2.3.3:
* Add environment variable support for AWS profiles and regions
* Regenerate Cargo.lock with rust 1.70.0
* Update circle-ci config
* Fix AWS Env Variable Test and Code Style Issue
* Remove CentOS 8 and Ubuntu 16.04 from verified Linux distribution list
* Fixed in version 2.3.2:
* Update version in amazon-efs-utils.spec to 2.3.1
* Fix incorrect package version
* Fixed in version 2.3.1:
* Fix backtrace version to resolve ubuntu and rhel build issues
* Pin Cargo.lock...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-3954=1 SUSE-2025-3954=1
* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2025-3954=1
* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2025-3954=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* aws-efs-utils-debuginfo-2.3.3-150600.17.6.1
* aws-efs-utils-2.3.3-150600.17.6.1
* Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* aws-efs-utils-2.3.3-150600.17.6.1
* Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* aws-efs-utils-2.3.3-150600.17.6.1
* bsc#1240044
* bsc#1248055
* bsc#1249851
## References:
* https://www.suse.com/security/cve/CVE-2020-35881.html
* https://www.suse.com/security/cve/CVE-2025-55159.html
* https://bugzilla.suse.com/show_bug.cgi?id=1240044
* https://bugzilla.suse.com/show_bug.cgi?id=1248055
* https://bugzilla.suse.com/show_bug.cgi?id=1249851
Get the latest Linux and open source security news straight to your inbox.