An update that solves three vulnerabilities can now be installed.. # Security update for iperf Announcement ID: SUSE-SU-2026:20311-1 Release Date: 2025-09-05T12:57:05Z Rating: important References: * bsc#1247519 * bsc#1247520 * bsc#1247522 Cross-References: * CVE-2025-54349 * CVE-2025-54350 * CVE-2025-54351 CVSS scores: * CVE-2025-54349 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-54349 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-54349 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-54350 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-54350 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-54350 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-54351 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-54351 ( NVD ): 8.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2025-54351 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for iperf fixes the following issues: Update to 3.19.1: * CVE-2025-54349: Fixed off-by-one error and resultant heap-based buffer overflow (bsc#1247519). * CVE-2025-54350: Fixed Base64Decode assertion failure and application exit upon a malformed authentication attempt (bsc#1247520). * CVE-2025-54351: Fixed buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv) (bsc#1247522). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-448=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 ppc64le s390x x86_64) *libiperf0-debuginfo-3.19.1-1.1 * iperf-3.19.1-1.1 * libiperf0-3.19.1-1.1 * iperf-debuginfo-3.19.1-1.1 * iperf-debugsource-3.19.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54349.html * https://www.suse.com/security/cve/CVE-2025-54350.html * https://www.suse.com/security/cve/CVE-2025-54351.html * https://bugzilla.suse.com/show_bug.cgi?id=1247519 * https://bugzilla.suse.com/show_bug.cgi?id=1247520 * https://bugzilla.suse.com/show_bug.cgi?id=1247522 . Update for iperf fixes several important issues including buffer overflows and application exit flaws. Essential for security.. iperf update,SUSE security,linux patch,buffer overflow fix,application exit flaw. . Severity: Important. LinuxSecurity.com Team
atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop. (CVE-2025-31160) . MGASA-2025-0129 - Updated atop packages fix security vulnerability Publication date: 10 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0129.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-31160 atop through 2.11.0 allows local users to cause a denial of service (e.g., assertion failure and application exit) or possibly have unspecified other impact by running certain types of unprivileged processes while a different user runs atop. (CVE-2025-31160) References: - https://bugs.mageia.org/show_bug.cgi?id=34139 - https://www.openwall.com/lists/oss-security/2025/03/26/2 - https://www.openwall.com/lists/oss-security/2025/03/26/3 - - https://news.ycombinator.com/item?id=43485980 - https://news.ycombinator.com/item?id=43477057 - https://www.openwall.com/lists/oss-security/2025/03/29/1 - - https://lists.debian.org/debian-security-announce/2025/msg00054.html - https://www.cve.org/CVERecord?id=CVE-2025-31160 SRPMS: - 9/core/atop-2.8.1-1.1.mga9 . Users in the area may take advantage of atop versions prior to 2.11.0, resulting in potential Denial of Service or other unintended consequences. Recommended remedy provided in the notice.. Mageia advisory, atop security issue, denial of service threat, local user exploit. . LinuxSecurity.com Team
The updated packages fix a security vulnerability: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace. (CVE-2023-34194) . MGASA-2024-0014 - Updated tinyxml packages fix a security vulnerability Publication date: 17 Jan 2024 URL: https://advisories.mageia.org/MGASA-2024-0014.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-34194 The updated packages fix a security vulnerability: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace. (CVE-2023-34194) References: - https://bugs.mageia.org/show_bug.cgi?id=32703 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.