Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE Linux Enterprise: flake-pilot Moderate CVE-2025-55159 Advisory

suse
Calendar Grey November 6, 2025
Dist Suse Esm H88
Update for flake-pilot addresses an issue. Follow SUSE update methods for installation and security compliance.
* bsc#1248004 Cross-References: * CVE-2025-55159

Summary

## This update for flake-pilot fixes the following issues: Update version to 3.1.22. * Fixes to use flakes as normal user Running a flake is a container based instance provisioning and startup. Some part of this process requires root permissions for example mounting the container instance store for the provisioning step. This commit fixes the required calls to be properly managed by sudo. * seed from entropy * Fix assignment of random sequence number We should use a seed for the sequence as described in random.github.io/book/guide-seeding.html#a-simple-number In addition the logic when a random sequence number should be used was wrong and needed a fix regarding resume and attach type flakes which must not use a random sequence * Pass --init option for resume type flakes

References

* bsc#1248004

Cross-

* CVE-2025-55159

CVSS scores:

* CVE-2025-55159 ( SUSE ): 5.8

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

* CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H

* CVE-2025-55159 ( NVD ): 5.1

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* SUSE Linux Enterprise Server 16.0

* SUSE Linux Enterprise Server for SAP Applications 16.0

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-55159.html

* https://bugzilla.suse.com/show_bug.cgi?id=1248004

Announcement ID: SUSE-SU-2025:20921-1
Release Date: 2025-10-15T12:01:21Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here