Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE Leap 16.0: Cheat Important Security Update 2025:20177-1

opensuse
Calendar Grey December 23, 2025
Dist Opensuse Esm H88
Security update for openSUSE fixing 8 issues in cheat with critical patches recommended. Urgent installation advised.
An update that solves 8 vulnerabilities and has 4 bug fixes can now be installed.

Description

This update for cheat fixes the following issues:

- Security:

* CVE-2025-47913: Fix client process termination (bsc#1253593)

* CVE-2025-58181: Fix potential unbounded memory consumption (bsc#1253922)

* CVE-2025-47914: Fix panic due to an out of bounds read (bsc#1254051)

* Replace golang.org/x/crypto=golang.org/x/crypto@v0.45.0

* Replace golang.org/x/net=golang.org/x/net@v0.47.0

* Replace golang.org/x/sys=golang.org/x/sys@v0.38.0

- Packaging improvements:

* Drop Requires: golang-packaging. The recommended Go toolchain

dependency expression is BuildRequires: golang(API) >= 1.x or

optionally the metapackage BuildRequires: go

* Use BuildRequires: golang(API) >= 1.19 matching go.mod

* Build PIE with pattern that may become recommended procedure:

%%ifnarch ppc64 GOFLAGS="-buildmode=pie" %%endif go build

A go toolchain buildmode default config would be preferable

but none exist at this time.

* Drop mod=vendor, go1.14+ will detect vendor dir and...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

cheat-4.4.2-bp160.2.1

References

* bsc#1247629

* bsc#1253593

* bsc#1253922

* bsc#1254051

References:

* https://www.suse.com/security/cve/CVE-2023-48795.html

* https://www.suse.com/security/cve/CVE-2025-21613.html

* https://www.suse.com/security/cve/CVE-2025-21614.html

* https://www.suse.com/security/cve/CVE-2025-22869.html

* https://www.suse.com/security/cve/CVE-2025-22870.html

* https://www.suse.com/security/cve/CVE-2025-47913.html

* https://www.suse.com/security/cve/CVE-2025-47914.html

* https://www.suse.com/security/cve/CVE-2025-58181.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2025:20177-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here