An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:0710-1 Release Date: 2026-02-28T15:33:45Z Rating: important References: * bsc#1255845 Cross-References: * CVE-2022-50717 CVSS scores: * CVE-2022-50717 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-50717 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 4.12.14-122.290 fixes one security issue The following security issue was fixed: * CVE-2022-50717: nvmet-tcp: add bounds check on Transfer Tag (bsc#1255845). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-710=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_290-default-2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-50717.html * https://bugzilla.suse.com/show_bug.cgi?id=1255845 . New important update for SUSE Linux Enterprise kernel resolves security issue with bounds check on Transfer Tag.. SUSE kernel update, Live Patching, security fix, SUSE Linux Enterprise, important advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1248502 Cross-References: * CVE-2025-8067 . # Security update for udisks2 Announcement ID: SUSE-SU-2025:03016-1 Release Date: 2025-08-29T08:28:28Z Rating: important References: * bsc#1248502 Cross-References: * CVE-2025-8067 CVSS scores: * CVE-2025-8067 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2025-8067 ( NVD ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for udisks2 fixes the following issues: * CVE-2025-8067: Fixed missing bounds check can lead to out-of-bounds read in udisks daemon (bsc#1248502) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3016=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3016=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3016=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3016=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * udisks2-debugsource-2.8.1-150200.3.6.1 * libudisks2-0-2.8.1-150200.3.6.1 * typelib-1_0-UDisks-2_0-2.8.1-150200.3.6.1 * udisks2-debuginfo-2.8.1-150200.3.6.1 * libudisks2-0-debuginfo-2.8.1-150200.3.6.1 * udisks2-2.8.1-150200.3.6.1 * libudisks2-0-devel-2.8.1-150200.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * udisks2-lang-2.8.1-150200.3.6.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * udisks2-debugsource-2.8.1-150200.3.6.1 * libudisks2-0-2.8.1-150200.3.6.1 * typelib-1_0-UDisks-2_0-2.8.1-150200.3.6.1 * udisks2-debuginfo-2.8.1-150200.3.6.1 * libudisks2-0-debuginfo-2.8.1-150200.3.6.1 * udisks2-2.8.1-150200.3.6.1 * libudisks2-0-devel-2.8.1-150200.3.6.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * udisks2-lang-2.8.1-150200.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * udisks2-debugsource-2.8.1-150200.3.6.1 * libudisks2-0-2.8.1-150200.3.6.1 * typelib-1_0-UDisks-2_0-2.8.1-150200.3.6.1 * udisks2-debuginfo-2.8.1-150200.3.6.1 * libudisks2-0-debuginfo-2.8.1-150200.3.6.1 * udisks2-2.8.1-150200.3.6.1 * libudisks2-0-devel-2.8.1-150200.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * udisks2-lang-2.8.1-150200.3.6.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * udisks2-debugsource-2.8.1-150200.3.6.1 * libudisks2-0-2.8.1-150200.3.6.1 * typelib-1_0-UDisks-2_0-2.8.1-150200.3.6.1 * udisks2-debuginfo-2.8.1-150200.3.6.1 * libudisks2-0-debuginfo-2.8.1-150200.3.6.1 * udisks2-2.8.1-150200.3.6.1 * libudisks2-0-devel-2.8.1-150200.3.6.1 * SUSE Enterprise Storage 7.1 (noarch) * udisks2-lang-2.8.1-150200.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8067.html * https://bugzilla.suse.com/show_bug.cgi?id=1248502 . SUSE releases patch for udisks2 addressing CVE-2025-8067, impacting multiple platforms with critical threat levels. Immediate update advised.. SUSE Linux, udisks2, CVE-2025-8067, security update, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1248006 Cross-References: * CVE-2025-55159 . # Security update for rust-keylime Announcement ID: SUSE-SU-2025:02957-1 Release Date: 2025-08-22T07:56:12Z Rating: moderate References: * bsc#1248006 Cross-References: * CVE-2025-55159 CVSS scores: * CVE-2025-55159 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-55159 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves one vulnerability can now be installed. ## Description: This update for rust-keylime fixes the following issues: * Update slab to version 0.4.11: * CVE-2025-55159: Fixed incorrect bounds check in get_disjoint_mut function (bsc#1248006) * Update to version 0.2.8+12: * build(deps): bump actions/checkout from 4 to 5 * build(deps): bump cfg-if from 1.0.0 to 1.0.1 * build(deps): bump openssl from 0.10.72 to 0.10.73 * build(deps): bump clap from 4.5.39 to 4.5.45 * build(deps): bump pest from 2.8.0 to 2.8.1 * Fix clippy warnings * Use verifier-provided interval for continuous attestation timing * Add meta object with seconds_to_next_attestation to evidence response * Fix boot time retrieval * Fix IMA log format (it must be ['text/plain']) (#1073) * Remove unnecessary configuration fields * cargo: Bump retry-policies to version 0.4.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2957=1 * SUSE Linux Enterprise Micro 5.3 zypper in-t patch SUSE-SLE-Micro-5.3-2025-2957=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.8+12-150400.3.10.1 * rust-keylime-debuginfo-0.2.8+12-150400.3.10.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.8+12-150400.3.10.1 * rust-keylime-debuginfo-0.2.8+12-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55159.html * https://bugzilla.suse.com/show_bug.cgi?id=1248006 . SUSE enhances rust-keylime to address a moderate severity vulnerability linked to improper boundary checks, which could result in potential exploit scenarios.. SUSE rust-keylime moderate advisory security fix. . LinuxSecurity.com Team
A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability (CVE-2021-3504). . MGASA-2021-0320 - Updated hivex packages fix a security vulnerability Publication date: 08 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0320.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-3504 A flaw was found in the hivex library. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is to system availability (CVE-2021-3504). References: - https://bugs.mageia.org/show_bug.cgi?id=28925 - https://lists.fedoraproject.org/archives/list/
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for hivex ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0806-1 Rating: moderate References: #1185013 Cross-References: CVE-2021-3504 CVSS scores: CVE-2021-3504 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L CVE-2021-3504 (SUSE): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for hivex fixes the following issues: - CVE-2021-3504: hivex: missing bounds check within hivex_open() (bsc#1185013) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-806=1 Package List: - openSUSE Leap 15.2 (x86_64): hivex-1.3.14-lp152.4.3.1 hivex-debuginfo-1.3.14-lp152.4.3.1 hivex-debugsource-1.3.14-lp152.4.3.1 hivex-devel-1.3.14-lp152.4.3.1 libhivex0-1.3.14-lp152.4.3.1 libhivex0-debuginfo-1.3.14-lp152.4.3.1 ocaml-hivex-1.3.14-lp152.4.3.1 ocaml-hivex-debuginfo-1.3.14-lp152.4.3.1 ocaml-hivex-devel-1.3.14-lp152.4.3.1 perl-Win-Hivex-1.3.14-lp152.4.3.1 perl-Win-Hivex-debuginfo-1.3.14-lp152.4.3.1 python-hivex-1.3.14-lp152.4.3.1 python-hivex-debuginfo-1.3.14-lp152.4.3.1 - openSUSE Leap 15.2 (noarch): hivex-lang-1.3.14-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2021-3504.html https://bugzilla.suse.com/1185013 . Urgent securitynotice for openSUSE Leap 15.2 targeting hivex overflow vulnerability. Prompt update advised.. openSUSE,hivex,security update,software patch,system security. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for hivex ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1761-1 Rating: moderate References: #1185013 Cross-References: CVE-2021-3504 CVSS scores: CVE-2021-3504 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVE-2021-3504 (SUSE): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for hivex fixes the following issues: - CVE-2021-3504: hivex: missing bounds check within hivex_open() (bsc#1185013) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-1761=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2021-1761=1 - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-1761=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-1761=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1761=1 Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): hivex-debuginfo-1.3.14-5.3.1 hivex-debugsource-1.3.14-5.3.1 libhivex0-1.3.14-5.3.1 libhivex0-debuginfo-1.3.14-5.3.1 perl-Win-Hivex-1.3.14-5.3.1 perl-Win-Hivex-debuginfo-1.3.14-5.3.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 ppc64le s390x x86_64): hivex-debuginfo-1.3.14-5.3.1 hivex-debugsource-1.3.14-5.3.1 ocaml-hivex-1.3.14-5.3.1 ocaml-hivex-debuginfo-1.3.14-5.3.1 ocaml-hivex-devel-1.3.14-5.3.1 - SUSE Linux Enterprise Module for Development Tools 15-SP2 (aarch64 ppc64le s390x x86_64): hivex-debuginfo-1.3.14-5.3.1 hivex-debugsource-1.3.14-5.3.1 ocaml-hivex-1.3.14-5.3.1 ocaml-hivex-debuginfo-1.3.14-5.3.1 ocaml-hivex-devel-1.3.14-5.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): hivex-debuginfo-1.3.14-5.3.1 hivex-debugsource-1.3.14-5.3.1 hivex-devel-1.3.14-5.3.1 libhivex0-1.3.14-5.3.1 libhivex0-debuginfo-1.3.14-5.3.1 perl-Win-Hivex-1.3.14-5.3.1 perl-Win-Hivex-debuginfo-1.3.14-5.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): hivex-debuginfo-1.3.14-5.3.1 hivex-debugsource-1.3.14-5.3.1 hivex-devel-1.3.14-5.3.1 libhivex0-1.3.14-5.3.1 libhivex0-debuginfo-1.3.14-5.3.1 perl-Win-Hivex-1.3.14-5.3.1 perl-Win-Hivex-debuginfo-1.3.14-5.3.1 References: https://www.suse.com/security/cve/CVE-2021-3504.html https://bugzilla.suse.com/1185013 . SUSE Security Announcement addresses a moderate vulnerability in hivex under Advisory ID: SUSE-SU-2021:1872-1, along with guidelines for installation.. SUSE Update,Hivex Fix,Linux Patch,Security Advisory,Software Update. . LinuxSecurity.com Team
New upstream version 1.3.20. Fixes CVE-2021-3504 missing bounds check in hivex_open.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-da76643229 2021-05-19 01:30:18.295275 --------------------------------------------------------------------------------Name : hivex Product : Fedora 33 Version : 1.3.20 Release : 1.fc33 URL : https://libguestfs.org/ Summary : Read and write Windows Registry binary hive files Description : Hive files are the undocumented binary files that Windows uses to store the Windows Registry on disk. Hivex is a library that can read and write to these files. 'hivexsh' is a shell you can use to interactively navigate a hive binary file. 'hivexregedit' (in perl-hivex) lets you export and merge to the textual regedit format. 'hivexml' can be used to convert a hive file to a more useful XML format. In order to get access to the hive files themselves, you can copy them from a Windows machine. They are usually found in %systemroot%\system32\config. For virtual machines we recommend using libguestfs or guestfish to copy out these files. libguestfs also provides a useful high-level tool called 'virt-win-reg' (based on hivex technology) which can be used to query specific registry keys in an existing Windows VM. For OCaml bindings, see 'ocaml-hivex-devel'. For Perl bindings, see 'perl-hivex'. For Python 3 bindings, see 'python3-hivex'. For Ruby bindings, see 'ruby-hivex'. --------------------------------------------------------------------------------Update Information: New upstream version 1.3.20. Fixes CVE-2021-3504 missing bounds check in hivex_open. --------------------------------------------------------------------------------ChangeLog: * Mon May 3 2021 Richard W.M. Jones - 1.3.20-1 - New upstream version 1.3.20. - Fixes CVE-2021-3504 missing bounds check inhivex_open. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-da76643229' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2 [More...]. Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: SLSA-2020:1508-1 Issue Date: 2020-04-21 CVE Numbers: None -- Security Fix(es): * OpenJDK: Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803) * OpenJDK: Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805) * OpenJDK: Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773) * OpenJDK: Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2781) * OpenJDK: CRLF injection into HTTP headers in HttpServer (Lightweight HTTP Server, 8234825) (CVE-2020-2800) * OpenJDK: Regular expression DoS in Scanner (Concurrency, 8236201) (CVE-2020-2830) * OpenJDK: Incorrect handling of references to uninitialized class descriptors during deserialization (Serialization, 8224541) (CVE-2020-2756) * OpenJDK: Uncaught InstantiationError exception in ObjectStreamClass (Serialization, 8224549) (CVE-2020-2757) -- SL6 x86_64 java-1.7.0-openjdk-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm java-1.7.0-openjdk-src-1.7.0.261-2.6.22.1.el6_10.x86_64.rpm i386 java-1.7.0-openjdk-1.7.0.261-2.6.22.1.el6_10.i686.rpm java-1.7.0-openjdk-debuginfo-1.7.0.261-2.6.22.1.el6_10.i686.rpm java-1.7.0-openjdk-devel-1.7.0.261-2.6.22.1.el6_10.i686.rpm java-1.7.0-openjdk-demo-1.7.0.261-2.6.22.1.el6_10.i686.rpm java-1.7.0-openjdk-src-1.7.0.261-2.6.22.1.el6_10.i686.rpm noarch java-1.7.0-openjdk-javadoc-1.7.0.261-2.6.22.1.el6_10.noarch.rpm - Scientific Linux Development Team . Significant revision for java-1.7.0-openjdk tackles several vulnerabilities and introduces crucial repairs for SL6.x platforms.. Java Security, OpenJDK Update, SL6.x Security, Scientific Linux Advisory, Important Java Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.