Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

openSUSE shibboleth-sp Important SQL Injection Patch 2026-21418-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
Updates for openSUSE address a critical SQL injection issue in shibboleth-sp with necessary patch instructions.
openSUSE has released a security update for shibboleth-sp addressing a SQL injection vulnerability (CVE-2025-9943) affecting Leap 16.0, along with one bug fix.

Description

This update for shibboleth-sp fixes the following issue

- CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth

Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1329=1

Patch

Package List

- openSUSE Leap 16.0:

libshibsp-lite12-3.5.0-160000.3.1

libshibsp12-3.5.0-160000.3.1

shibboleth-sp-3.5.0-160000.3.1

shibboleth-sp-devel-3.5.0-160000.3.1

References

* bsc#1249394

References:

* https://www.suse.com/security/cve/CVE-2025-9943.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21418-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.