* bsc#1239197 Cross-References: * CVE-2025-22868 . # Security update for google-guest-agent Announcement ID: SUSE-SU-2025:1005-1 Release Date: 2025-03-25T08:43:38Z Rating: important References: * bsc#1239197 Cross-References: * CVE-2025-22868 CVSS scores: * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2025-22868: golang.org/x/oauth2/jws: Fixed unexpected memory consumption during token parsing (bsc#1239197) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2025-1005=1 * openSUSELeap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1005=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-1005=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2025-1005=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2025-1005=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2025-1005=1 ## Package List: * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250116.00-150000.1.57.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22868.html * https://bugzilla.suse.com/show_bug.cgi?id=1239197 . Important security advisory for google-guest-agent fixes memory consumption issue in openSUSE and SUSE Linux. Immediate action recommended.. bsc#1239197, cross-references, cve-2025-22868, security, update, google-guest-agent, announceme. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for grpc Announcement ID: SUSE-SU-2024:4436-1 Release Date: 2024-12-30T13:23:26Z Rating: moderate References: * bsc#1228919 * bsc#1233821 Cross-References: * CVE-2024-11407 * CVE-2024-7246 CVSS scores: * CVE-2024-11407 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:X/RE:L/U:Green * CVE-2024-11407 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2024-11407 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:X/RE:L/U:Green * CVE-2024-7246 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2024-7246 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for grpc fixes the following issues: * CVE-2024-7246: HPACK table poisoning by gRPC clients communicating with a HTTP/2 proxy. (bsc#1228919) * CVE-2024-11407: data corruption on servers with transmit zero copy enabled. (bsc#1233821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-4436=1 openSUSE-SLE-15.5-2024-4436=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-4436=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-4436=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * grpc-devel-1.60.0-150500.11.8.1 * libupb37-1.60.0-150500.11.8.1 * libgrpc++1_60-1.60.0-150500.11.8.1 * libgrpc++1_60-debuginfo-1.60.0-150500.11.8.1 * libgrpc37-debuginfo-1.60.0-150500.11.8.1 * libgrpc1_60-1.60.0-150500.11.8.1 * upb-devel-1.60.0-150500.11.8.1 * libgrpc1_60-debuginfo-1.60.0-150500.11.8.1 * libupb37-debuginfo-1.60.0-150500.11.8.1 * grpc-devel-debuginfo-1.60.0-150500.11.8.1 * grpc-debuginfo-1.60.0-150500.11.8.1 * libgrpc37-1.60.0-150500.11.8.1 * grpc-debugsource-1.60.0-150500.11.8.1 * openSUSE Leap 15.5 (noarch) * grpc-source-1.60.0-150500.11.8.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * grpc-devel-1.60.0-150500.11.8.1 * libupb37-1.60.0-150500.11.8.1 * libgrpc++1_60-1.60.0-150500.11.8.1 * libgrpc++1_60-debuginfo-1.60.0-150500.11.8.1 * libgrpc37-debuginfo-1.60.0-150500.11.8.1 * libgrpc1_60-1.60.0-150500.11.8.1 * libgrpc1_60-debuginfo-1.60.0-150500.11.8.1 * libupb37-debuginfo-1.60.0-150500.11.8.1 * grpc-debuginfo-1.60.0-150500.11.8.1 * libgrpc37-1.60.0-150500.11.8.1 * grpc-debugsource-1.60.0-150500.11.8.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libupb37-1.60.0-150500.11.8.1 * libgrpc37-debuginfo-1.60.0-150500.11.8.1 * libgrpc1_60-1.60.0-150500.11.8.1 * libgrpc1_60-debuginfo-1.60.0-150500.11.8.1 * libupb37-debuginfo-1.60.0-150500.11.8.1 * grpc-debuginfo-1.60.0-150500.11.8.1 * libgrpc37-1.60.0-150500.11.8.1 * grpc-debugsource-1.60.0-150500.11.8.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11407.html * https://www.suse.com/security/cve/CVE-2024-7246.html * https://bugzilla.suse.com/show_bug.cgi?id=1228919 * https://bugzilla.suse.com/show_bug.cgi?id=1233821 . Red Hat issued a patch notice for istio, addressing key vulnerabilities related to malformed requests and unexpected traffic injection risks.. grpc security update, openSUSE updates, SUSE security advisory. . LinuxSecurity.com Team
* bsc#1218501 Cross-References: * CVE-2023-50711 . # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2024:1984-1 Rating: moderate References: * bsc#1218501 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues: * CVE-2023-50711: Fixed out of bounds memory accesses in embedded vmm-sys-util (bsc#1218501). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1984=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1984=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-1984=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-1984=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64) * aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debugsource-1.3.0~git1.db34c02-150400.3.6.1 *aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * system-group-ne-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-1.3.0~git1.db34c02-150400.3.6.1 * openSUSE Leap 15.5 (aarch64 x86_64) * aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debugsource-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * system-group-ne-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-1.3.0~git1.db34c02-150400.3.6.1 * Public Cloud Module 15-SP4 (aarch64 x86_64) * aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debugsource-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * system-group-ne-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-1.3.0~git1.db34c02-150400.3.6.1 * Public Cloud Module 15-SP5 (aarch64 x86_64) * aws-nitro-enclaves-cli-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debugsource-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-cli-debuginfo-1.3.0~git1.db34c02-150400.3.6.1 * system-group-ne-1.3.0~git1.db34c02-150400.3.6.1 * aws-nitro-enclaves-binaryblobs-upstream-1.3.0~git1.db34c02-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218501 . A security patch for the aws-nitro-enclaves-cli addresses vulnerabilities classified as moderate risk. Implement this update for improved safety.. aws-nitro-enclaves-cli security update, openSUSE Leap patch, SUSE cloudmodule advisory. . LinuxSecurity.com Team
* bsc#1203171 * bsc#1225997 * jsc#PED-7982 * jsc#PED-8018 . # Security update for rmt-server Announcement ID: SUSE-SU-2024:1974-1 Rating: moderate References: * bsc#1203171 * bsc#1225997 * jsc#PED-7982 * jsc#PED-8018 Cross-References: * CVE-2024-28103 CVSS scores: * CVE-2024-28103 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Server Applications Module 15-SP5 * Server Applications Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability, contains two features and has one security fix can now be installed. ## Description: This update for rmt-server fixes the following issues: * Update to version 2.17 * CVE-2024-28103: Fixed Permissions-Policy that was only served on responses with an HTML related Content-Type. (bsc#1225997) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1974=1 openSUSE-SLE-15.5-2024-1974=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-1974=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-1974=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2024-1974=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-1974=1 * Server Applications Module 15-SP6 zypper in-t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-1974=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * rmt-server-2.17-150500.3.16.1 * rmt-server-pubcloud-2.17-150500.3.16.1 * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-config-2.17-150500.3.16.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * rmt-server-2.17-150500.3.16.1 * rmt-server-pubcloud-2.17-150500.3.16.1 * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-config-2.17-150500.3.16.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-pubcloud-2.17-150500.3.16.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-pubcloud-2.17-150500.3.16.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * rmt-server-2.17-150500.3.16.1 * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-config-2.17-150500.3.16.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * rmt-server-2.17-150500.3.16.1 * rmt-server-debuginfo-2.17-150500.3.16.1 * rmt-server-debugsource-2.17-150500.3.16.1 * rmt-server-config-2.17-150500.3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-28103.html * https://bugzilla.suse.com/show_bug.cgi?id=1203171 * https://bugzilla.suse.com/show_bug.cgi?id=1225997 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-7982&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-8018&page_caps=&user_role= . Stay informed about the rmt-server security advisory for SUSE systems, highlighting a moderate vulnerabilityneeding timely updates to ensure safety. rmt-server updates, SUSE security patch, openSUSE security, moderate vulnerability advisory. . LinuxSecurity.com Team
* bsc#1219563 * bsc#1220568 * bsc#1221677 Cross-References: . # Security update for buildah Announcement ID: SUSE-SU-2024:1144-1 Rating: important References: * bsc#1219563 * bsc#1220568 * bsc#1221677 Cross-References: * CVE-2024-1753 CVSS scores: * CVE-2024-1753 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * Public Cloud Module 15-SP2 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.1 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Server 4.1 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for buildah fixes the following issues: * CVE-2024-1753: Fixed an issue to prevent a full container escapeat build time. (bsc#1221677) * Update to version 1.34.1 for compatibility with Docker 25.0 (which is not in SLES yet, but will eventually be) (bsc#1219563). See the corresponding release notes: * https://github.com/containers/buildah/releases/tag/v1.34.1 * https://github.com/containers/buildah/releases/tag/v1.34.0 * https://github.com/containers/buildah/releases/tag/v1.33.0 * https://github.com/containers/buildah/releases/tag/v1.32.0 * https://github.com/containers/buildah/releases/tag/v1.31.0 * https://github.com/containers/buildah/releases/tag/v1.30.0 * Require cni-plugins (bsc#1220568) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1144=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1144=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1144=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1144=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1144=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1144=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1144=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2024-1144=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-1144=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-1144=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-1144=1 * SUSE Linux Enterprise High PerformanceComputing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-1144=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-1144=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-1144=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-1144=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-1144=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-1144=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-1144=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-1144=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-1144=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1144=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1144=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * buildah-1.34.1-150400.3.27.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390xx86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * buildah-1.34.1-150400.3.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * buildah-1.34.1-150400.3.27.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * buildah-1.34.1-150400.3.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * buildah-1.34.1-150400.3.27.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390xx86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.22.3 * cni-0.7.1-150100.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2024-1753.html * https://bugzilla.suse.com/show_bug.cgi?id=1219563 * https://bugzilla.suse.com/show_bug.cgi?id=1220568 * https://bugzilla.suse.com/show_bug.cgi?id=1221677 . Essential patch for buildah in SUSE addressing a comprehensive container breach vulnerability spanning various platforms.. Buildah Security Update, Container Escape Fix, SUSE Vulnerability Alert. . Severity: Important. LinuxSecurity.com Team
* bsc#1217782 * bsc#1220535 Cross-References: * CVE-2024-27099 . # Security update for python-uamqp Announcement ID: SUSE-SU-2024:0947-1 Rating: important References: * bsc#1217782 * bsc#1220535 Cross-References: * CVE-2024-27099 CVSS scores: * CVE-2024-27099 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python-uamqp fixes the following issues: * CVE-2024-27099: Fixed potential double-free in link_frame_received() (bsc#1220535). Bug fixes: * Fixed compatibility with OpenSSL 3.x (bsc#1217782) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patchopenSUSE-SLE-15.5-2024-947=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2024-947=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2024-947=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-947=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-947=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python3-uamqp-debuginfo-1.5.3-150100.4.18.1 * python-uamqp-debugsource-1.5.3-150100.4.18.1 * python3-uamqp-1.5.3-150100.4.18.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * python3-uamqp-debuginfo-1.5.3-150100.4.18.1 * python-uamqp-debugsource-1.5.3-150100.4.18.1 * python3-uamqp-1.5.3-150100.4.18.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * python3-uamqp-debuginfo-1.5.3-150100.4.18.1 * python-uamqp-debugsource-1.5.3-150100.4.18.1 * python3-uamqp-1.5.3-150100.4.18.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-uamqp-debuginfo-1.5.3-150100.4.18.1 * python-uamqp-debugsource-1.5.3-150100.4.18.1 * python3-uamqp-1.5.3-150100.4.18.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-uamqp-debuginfo-1.5.3-150100.4.18.1 * python-uamqp-debugsource-1.5.3-150100.4.18.1 * python3-uamqp-1.5.3-150100.4.18.1 ## References: * https://www.suse.com/security/cve/CVE-2024-27099.html * https://bugzilla.suse.com/show_bug.cgi?id=1217782 * https://bugzilla.suse.com/show_bug.cgi?id=1220535 . Tackled critical vulnerability concerns in python-uamqp throughout SUSE platforms for improved defense.. python-uamqp Update, Security Patch SUSE, Double-Free Fix, OpenSSL 3 Compatibility, SUSE Security Update. . Severity: Important. LinuxSecurity.com Team
* bsc#1216588 Cross-References: * CVE-2023-46137 . # Security update for python-Twisted Announcement ID: SUSE-SU-2023:4830-1 Rating: moderate References: * bsc#1216588 Cross-References: * CVE-2023-46137 CVSS scores: * CVE-2023-46137 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-46137 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Public Cloud Module 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Manager Proxy 4.0 * SUSE Manager Retail Branch Server 4.0 * SUSE Manager Server 4.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-Twisted fixes the following issues: * CVE-2023-46137: Fixed issue inside serializing pipelined HTTP requests. (bsc#1216588) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP1 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP1-2023-4830=1 ## Package List: * Public Cloud Module 15-SP1 (aarch64 ppc64le s390x x86_64) * python3-Twisted-17.9.0-150000.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46137.html * https://bugzilla.suse.com/show_bug.cgi?id=1216588 . Critical Python-Twisted update mitigates CVE-2023-46137 for various SUSE distributions. Install the update promptly to enhance your security posture.. SUSE Linux, Python-Twisted Patch, Security Update. . LinuxSecurity.com Team
* bsc#1212475 * bsc#1216006 Affected Products: * Containers Module 15-SP4 . # Security update for cni-plugins Announcement ID: SUSE-SU-2023:4127-1 Rating: important References: * bsc#1212475 * bsc#1216006 Affected Products: * Containers Module 15-SP4 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP1 * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.0 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.0 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.0 * SUSEManager Server 4.1 * SUSE Manager Server 4.3 An update that has two security fixes can now be installed. ## Description: This update of cni-plugins fixes the following issues: * rebuild the package with the go 1.21 security release (bsc#1212475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4127=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4127=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4127=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4127=1 * Containers Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2023-4127=1 * Public Cloud Module 15-SP1 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP1-2023-4127=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2023-4127=1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4127=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4127=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4127=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4127=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4127=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4127=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4127=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4127=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4127=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4127=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4127=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4127=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4127=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4127=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * Containers Module 15-SP4 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * Public Cloud Module 15-SP1 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) *cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE CaaS Platform 4.0 (x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * cni-plugins-0.8.6-150100.3.20.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1212475 * https://bugzilla.suse.com/show_bug.cgi?id=1216006 . SUSE release tackles critical vulnerabilities in cni-plugins, reinforcing system security and optimizing operational efficiency.. cni-plugins update,SUSE security advisory,threat management,software patches. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.