Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE Linux Micro 6.0: 2025:20453-1 important: libsoup update

suse
Calendar Grey July 4, 2025
Dist Suse Esm H88
Identify and fix critical security vulnerabilities in Libsoup for SUSE Micro 6.0 to ensure application integrity and safeguard data confidentiality
* bsc#1243314 * bsc#1243332 * bsc#1243422 * bsc#1243423

Summary

## This update for libsoup fixes the following issues: * CVE-2025-4476: Fixed null pointer dereference that may lead to denial of service (bsc#1243422) * CVE-2025-4948: Fixed Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup (bsc#1243332) * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-4945: Fixed Integer Overflow in Cookie Expiration Date Handling in libsoup (bsc#1243314) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-368=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64)

References

* bsc#1243314

* bsc#1243332

* bsc#1243422

* bsc#1243423

Cross-

* CVE-2025-4476

* CVE-2025-4945

* CVE-2025-4948

* CVE-2025-4969

CVSS scores:

* CVE-2025-4476 ( SUSE ): 2.1

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-4476 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-4476 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-4945 ( SUSE ): 2.3

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2025-4945 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2025-4945 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2025-4948 ( SUSE ): 8.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:20453-1
Release Date: 2025-06-28T05:47:23Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here