* bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 . # Security update for kernel-livepatch-MICRO-6-0_Update_10 Announcement ID: SUSE-SU-2025:20941-1 Release Date: 2025-11-05T16:11:04Z Rating: important References: * bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 * CVE-2025-38664 CVSS scores: * CVE-2025-38618 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38618 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_10 fixes the following issues: * CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631) * CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-189=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-32-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38618.html * https://www.suse.com/security/cve/CVE-2025-38664.html * https://bugzilla.suse.com/show_bug.cgi?id=1248631 * https://bugzilla.suse.com/show_bug.cgi?id=1249207 . SUSE's kernel-livepatch update addresses important issues with vulnerabilities involving null pointer dereference and binding.. kernel livepatch, SUSE Linux, security update. .Severity: Important. LinuxSecurity.com Team
* bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 . # Security update for kernel-livepatch-MICRO-6-0_Update_10 Announcement ID: SUSE-SU-2025:20972-1 Release Date: 2025-11-05T16:12:05Z Rating: important References: * bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 * CVE-2025-38664 CVSS scores: * CVE-2025-38618 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38618 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_10 fixes the following issues: * CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631) * CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-189=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-32-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38618.html * https://www.suse.com/security/cve/CVE-2025-38664.html * https://bugzilla.suse.com/show_bug.cgi?id=1248631 * https://bugzilla.suse.com/show_bug.cgi?id=1249207 . Updates available for SUSE Linux Micro kernel-livepatch-MICRO-6-0 addressing critical bug fixes with important severity.. kernel livepatch suse security patch critical updates.. Severity: Important. LinuxSecurity.com Team
* bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_11 Announcement ID: SUSE-SU-2025:20986-1 Release Date: 2025-11-05T16:16:55Z Rating: important References: * bsc#1248631 * bsc#1249207 Cross-References: * CVE-2025-38618 * CVE-2025-38664 CVSS scores: * CVE-2025-38618 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38618 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_11 fixes the following issues: * CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631) * CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-190=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-35-rt-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-3-1.1 * kernel-livepatch-6_4_0-35-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38618.html * https://www.suse.com/security/cve/CVE-2025-38664.html * https://bugzilla.suse.com/show_bug.cgi?id=1248631 * https://bugzilla.suse.com/show_bug.cgi?id=1249207 . Kernel Livepatch Security Update for SUSE Linux Micro 6.1 addresses critical issues to enhance system safety.. SUSE Linux Micro, kernel patch, security update, important issues,system vulnerabilities. . Severity: Important. LinuxSecurity.com Team
It was discovered that there was a race condition in Tang, a network-based cryptographic binding server. This flaw resulted in a small time window whereby newly-generated private keys were readable by other processes on the same machine. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3648-1
Unprivileged pod may bind mount any privileged regular file on disk (CVE-2021-43816) References: - https://bugs.mageia.org/show_bug.cgi?id=30050 . MGASA-2022-0071 - Updated docker-containerd packages fix security vulnerability Publication date: 18 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0071.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43816 Unprivileged pod may bind mount any privileged regular file on disk (CVE-2021-43816) References: - https://bugs.mageia.org/show_bug.cgi?id=30050 - https://lists.fedoraproject.org/archives/list/
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for bind ______________________________________________________________________________ Announcement ID: SUSE-SU-2016:0174-1 Rating: important References: #962189 Cross-References: CVE-2015-8704 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP1 SUSE Linux Enterprise Server 12-SP1 SUSE Linux Enterprise Desktop 12-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bind fixes the following issues: - CVE-2015-8704: Specific APL data allowed remote attacker to trigger a crash in certain configurations (bsc#962189) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP1: zypper in -t patch SUSE-SLE-SDK-12-SP1-2016-114=1 - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-114=1 - SUSE Linux Enterprise Desktop 12-SP1: zypper in -t patch SUSE-SLE-DESKTOP-12-SP1-2016-114=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12-SP1 (ppc64le s390x x86_64): bind-debuginfo-9.9.6P1-35.1 bind-debugsource-9.9.6P1-35.1 bind-devel-9.9.6P1-35.1 - SUSE Linux Enterprise Server 12-SP1 (ppc64le s390x x86_64): bind-9.9.6P1-35.1 bind-chrootenv-9.9.6P1-35.1 bind-debuginfo-9.9.6P1-35.1 bind-debugsource-9.9.6P1-35.1 bind-libs-9.9.6P1-35.1 bind-libs-debuginfo-9.9.6P1-35.1 bind-utils-9.9.6P1-35.1 bind-utils-debuginfo-9.9.6P1-35.1 - SUSE Linux Enterprise Server 12-SP1 (s390x x86_64): bind-libs-32bit-9.9.6P1-35.1 bind-libs-debuginfo-32bit-9.9.6P1-35.1 - SUSE Linux Enterprise Server 12-SP1 (noarch): bind-doc-9.9.6P1-35.1 - SUSE Linux Enterprise Desktop 12-SP1 (x86_64): bind-debuginfo-9.9.6P1-35.1 bind-debugsource-9.9.6P1-35.1 bind-libs-32bit-9.9.6P1-35.1 bind-libs-9.9.6P1-35.1 bind-libs-debuginfo-32bit-9.9.6P1-35.1 bind-libs-debuginfo-9.9.6P1-35.1 bind-utils-9.9.6P1-35.1 bind-utils-debuginfo-9.9.6P1-35.1 References: https://www.suse.com/security/cve/CVE-2015-8704.html https://bugzilla.suse.com/show_bug.cgi?id=962189 . This latest SUSE patch resolves a critical linkage problem aimed at averting remote system failures. Review specifications for installation.. SUSE Security Update, binding issue, remote crash fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.