Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE Linux Micro: Moderate Integer Overflow Vulnerability Identified

suse
Calendar Grey August 4, 2025
Dist Suse Esm H88
Patch for jq mitigates potential signed integer overflow vulnerabilities in SUSE environments, with comprehensive guidance on implementing updates included.
* bsc#1243450 Cross-References: * CVE-2024-23337

Summary

## This update for jq fixes the following issues: * CVE-2024-23337: Fixed signed integer overflow in jv.c:jvp_array_write (bsc#1243450) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-393=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libjq1-1.6-4.1 * libjq1-debuginfo-1.6-4.1 * jq-debugsource-1.6-4.1 * jq-1.6-4.1 * jq-debuginfo-1.6-4.1

References

* bsc#1243450

Cross-

* CVE-2024-23337

CVSS scores:

* CVE-2024-23337 ( SUSE ): 6.7

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2024-23337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-23337 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2024-23337 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* SUSE Linux Micro 6.0

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-23337.html

* https://bugzilla.suse.com/show_bug.cgi?id=1243450

Announcement ID: SUSE-SU-2025:20506-1
Release Date: 2025-07-24T11:41:20Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here