Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: Critical Path Sanitization DoS Vulnerability in 4.3 Manager Server

suse
Calendar Grey October 28, 2025
Dist Suse Esm H88
Update released for SUSE Manager Proxy and Server 4.3 LTS to address key issues and improve security functionalities.
* bsc#1227577 * bsc#1246277 * bsc#1246439 * bsc#1250911 * jsc#MSQA-1026

Summary

### This update fixes the following issues: susemanager-build-keys: * Update SUSE GPG key and make it available for Salt (bsc#1250911) susemanager-tftpsync-recv: * Version 4.3.11-0 with security fix: * CVE-2025-53880: Sanitize path in sync-proxy script (bsc#1246277) rhnlib: * Version 4.3.7-0: * Use more secure defusedxml parser (bsc#1227577) spacewalk-backend: * Version 4.3.34-0: * Use more secure defusedxml parser (bsc#1227577) spacewalk-web: * Version 4.3.46-0: * Bumped the WebUI version to 4.3.16.1 proxy-helm, proxy-httpd-image, proxy-salt-broker-image, proxy-squid-image, proxy-ssh-image, proxy-tftpd-image: * Images rebuilt to the newest version with updated dependencies How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy or Retail Branch Server.

References

* bsc#1227577

* bsc#1246277

* bsc#1246439

* bsc#1250911

* jsc#MSQA-1026

Cross-

* CVE-2025-53880

* CVE-2025-53883

CVSS scores:

* CVE-2025-53880 ( SUSE ): 8.7

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2025-53880 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Manager Proxy 4.3

* SUSE Manager Proxy 4.3 LTS

* SUSE Manager Retail Branch Server 4.3

* SUSE Manager Server 4.3

* SUSE Manager Server 4.3 LTS

An update that solves two vulnerabilities, contains one feature and has two

security fixes can now be installed.

## Security update 4.3.16.1 for SUSE Manager Proxy and Retail Branch 4.3 LTS

##

* https://www.suse.com/security/cve/CVE-2025-53880.html

* https://www.suse.com/security/cve/CVE-2025-53883.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:3826-1
Release Date: 2025-10-28T07:26:47Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here