MGASA-2026-0021 - Updated iperf packages fix security vulnerabilities. MGASA-2026-0021 - Updated iperf packages fix security vulnerabilities Publication date: 27 Jan 2026 URL: https://advisories.mageia.org/MGASA-2026-0021.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-54349, CVE-2025-54350 Description: In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. (CVE-2025-54349) In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. (CVE-2025-54350) References: - https://bugs.mageia.org/show_bug.cgi?id=35047 - https://ubuntu.com/security/notices/USN-7970-1 - https://www.cve.org/CVERecord?id=CVE-2025-54349 - https://www.cve.org/CVERecord?id=CVE-2025-54350 SRPMS: - 9/core/iperf-3.18-1.1.mga9 . Updated iperf packages in Mageia fix critical security issues including buffer overflows and authentication errors.. iperf security update,mageia vulnerability patch,buffer overflow fix,authentication error patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_8 Announcement ID: SUSE-SU-2025:20830-1 Release Date: 2025-10-07T15:38:32Z Rating: important References: * bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 * CVE-2025-38477 CVSS scores: * CVE-2025-38089 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38089 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38477 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38477 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_8 fixes the following issues: * CVE-2025-38089: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (bsc#1245509) * CVE-2025-38477: net/sched: sch_qfq: Fix race condition on qfq_aggregate (bsc#1247315) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-147=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-6-1.2 * kernel-livepatch-6_4_0-31-rt-6-1.2 * kernel-livepatch-6_4_0-31-rt-debuginfo-6-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38089.html * https://www.suse.com/security/cve/CVE-2025-38477.html * https://bugzilla.suse.com/show_bug.cgi?id=1245509 * https://bugzilla.suse.com/show_bug.cgi?id=1247315 . Two important vulnerabilities fixed in SUSE Linux Micro 6.0 kernel-livepatch update. Ensure your systems are secure and protected.. kernel livepatch, SUSE Linuxupdates, Linux security issues. . Severity: Important. LinuxSecurity.com Team
* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_9 Announcement ID: SUSE-SU-2025:20831-1 Release Date: 2025-10-07T15:38:32Z Rating: important References: * bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 * CVE-2025-38477 CVSS scores: * CVE-2025-38089 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38089 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38477 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38477 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_9 fixes the following issues: * CVE-2025-38089: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (bsc#1245509) * CVE-2025-38477: net/sched: sch_qfq: Fix race condition on qfq_aggregate (bsc#1247315) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-148=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-33-rt-debuginfo-5-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-5-1.2 * kernel-livepatch-6_4_0-33-rt-5-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38089.html * https://www.suse.com/security/cve/CVE-2025-38477.html * https://bugzilla.suse.com/show_bug.cgi?id=1245509 * https://bugzilla.suse.com/show_bug.cgi?id=1247315 . Address critical security updates including authentication errors and race conditions for SUSE Linux Micro 6.0.. SUSE Security Update, Kernel Livepatch Fix,Authentication Issues, Race Condition Resolution, Vulnerability Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 . # Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:03567-1 Release Date: 2025-10-12T08:04:03Z Rating: important References: * bsc#1245509 * bsc#1247315 Cross-References: * CVE-2025-38089 * CVE-2025-38477 CVSS scores: * CVE-2025-38089 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38089 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38477 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38477 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_53 fixes several issues. The following security issues were fixed: * CVE-2025-38477: net/sched: sch_qfq: Fix race condition on qfq_aggregate (bsc#1247315). * CVE-2025-38089: sunrpc: handle SVC_GARBAGE during svc auth processing as auth error (bsc#1245509). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3567=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-3567=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-6-150600.2.1 * SUSELinux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-6-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38089.html * https://www.suse.com/security/cve/CVE-2025-38477.html * https://bugzilla.suse.com/show_bug.cgi?id=1245509 * https://bugzilla.suse.com/show_bug.cgi?id=1247315 . SUSE’s important kernel update addresses two critical security issues, requiring immediate attention and patching.. Linux Kernel, security update, SUSE patch, CVE-2025-38089, CVE-2025-38477. . Severity: Important. LinuxSecurity.com Team
Zhuowei Zhang discovered a bug in the EAP authentication client code of strongSwan, an IKE/IPsec suite, that may allow to bypass the client and in some scenarios even the server authentication, or could lead to a denial-of-service attack. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5056-1
An update that solves one vulnerability and has one errata is now available. . Caution: This email originated from outside the organization. Do not click links or open attachments unless you have verified this email is legitimate. SUSE Security Update: Security update for libssh2_org ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1060-1 Rating: important References: #1130103 #1133528 Cross-References: CVE-2019-3859 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 SUSE Enterprise Storage 4 SUSE CaaS Platform ALL SUSE CaaS Platform 3.0 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libssh2_org fixes the following issues: - Incorrect upstream fix for CVE-2019-3859 broke public key authentication [bsc#1133528, bsc#1130103] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1060=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-1060=1 - SUSE Linux Enterprise Software Development Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-1060=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-1060=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-1060=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-1060=1 - SUSE Linux Enterprise Server 12-SP3: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-1060=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-1060=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-1060=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1060=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-1060=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-1060=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-1060=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-1060=1 - SUSE CaaS Platform ALL: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. - SUSE CaaS Platform 3.0: To install this update, use the SUSE CaaS Platform Velum dashboard. It will inform you if it detects new updates and let youthen trigger updating of the complete cluster in a controlled way. - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-1060=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libssh2-devel-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libssh2-devel-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP4 (s390x x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP3 (aarch64 ppc64le s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP3 (s390x x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Server 12-LTSS (s390x x86_64): libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE Enterprise Storage 4 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-32bit-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2-1-debuginfo-32bit-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE CaaS Platform ALL (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - SUSE CaaS Platform 3.0 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): libssh2-1-1.4.3-20.6.1 libssh2-1-debuginfo-1.4.3-20.6.1 libssh2_org-debugsource-1.4.3-20.6.1 References: https://www.suse.com/security/cve/CVE-2019-3859.html https://bugzilla.suse.com/1130103 https://bugzilla.suse.com/1133528 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.