Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: rust-keylime Important Issues Fix Advisory 2025:02811-1

suse
Calendar Grey August 15, 2025
Dist Suse Esm H88
Essential security patch for python-synergy tackles buffer overflow and privilege escalation vulnerabilities in Debian.
* bsc#1210344 * bsc#1223234 * bsc#1229952 * bsc#1230029 * bsc#1242623

Summary

## This update for rust-keylime fixes the following issues: * Update to version 0.2.7+141: * CVE-2025-58266: shlex: Fixed command injection (bsc#1247193) * Update to version 0.2.7+117: * CVE-2023-26964: rust-keylime: hyper,h2: stream stacking when H2 processing HTTP2 RST_STREAM frames (bsc#1210344). * CVE-2024-12224: rust-keylime: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243861). * CVE-2024-32650: rust-keylime: rust-rustls: Infinite loop in rustls::conn::ConnectionCommon:complete_io() with proper client input (bsc#1223234). * CVE-2024-43806: rust-keylime: rustix: rustix::fs::Dir iterator with the linux_raw backend can cause memory explosion (bsc#1229952). * CVE-2025-3416: rust-keylime: openssl: Use-After-Free in Md::fetch and

References

* bsc#1210344

* bsc#1223234

* bsc#1229952

* bsc#1230029

* bsc#1242623

* bsc#1243861

* bsc#1247193

Cross-

* CVE-2023-26964

* CVE-2024-12224

* CVE-2024-32650

* CVE-2024-43806

* CVE-2025-3416

* CVE-2025-58266

CVSS scores:

* CVE-2023-26964 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-12224 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

* CVE-2024-12224 ( NVD ): 5.1

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:02811-1
Release Date: 2025-08-15T12:51:55Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here