An update that solves one vulnerability can now be installed.. # Security update for avahi Announcement ID: SUSE-SU-2026:20027-1 Release Date: 2026-01-11T16:54:00Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: Fixed DNS spoofing (bsc#1233421) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-127=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-127=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * avahi-autoipd-0.8-160000.3.1 * libavahi-gobject0-debuginfo-0.8-160000.3.1 * python313-avahi-0.8-160000.3.1 * avahi-autoipd-debuginfo-0.8-160000.3.1 * avahi-0.8-160000.3.1 * libavahi-core7-debuginfo-0.8-160000.3.1 * libavahi-glib1-debuginfo-0.8-160000.3.1 * libavahi-core7-0.8-160000.3.1 * avahi-utils-debuginfo-0.8-160000.3.1 * avahi-debuginfo-0.8-160000.3.1 * avahi-utils-0.8-160000.3.1 * libavahi-ui-gtk3-0-0.8-160000.3.1 * libavahi-devel-0.8-160000.3.1 * libavahi-client3-debuginfo-0.8-160000.3.1 * libavahi-common3-0.8-160000.3.1 * typelib-1_0-Avahi-0_6-0.8-160000.3.1 * libavahi-common3-debuginfo-0.8-160000.3.1 *libhowl0-debuginfo-0.8-160000.3.1 * libdns_sd-debuginfo-0.8-160000.3.1 * avahi-glib2-debugsource-0.8-160000.3.1 * avahi-utils-gtk-debuginfo-0.8-160000.3.1 * libavahi-glib1-0.8-160000.3.1 * libavahi-client3-0.8-160000.3.1 * avahi-compat-mDNSResponder-devel-0.8-160000.3.1 * libhowl0-0.8-160000.3.1 * python3-avahi-gtk-0.8-160000.3.1 * libavahi-libevent1-0.8-160000.3.1 * avahi-utils-gtk-0.8-160000.3.1 * libavahi-libevent1-debuginfo-0.8-160000.3.1 * libdns_sd-0.8-160000.3.1 * libavahi-gobject-devel-0.8-160000.3.1 * avahi-debugsource-0.8-160000.3.1 * libavahi-gobject0-0.8-160000.3.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.3.1 * libavahi-glib-devel-0.8-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * avahi-lang-0.8-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * avahi-autoipd-0.8-160000.3.1 * libavahi-gobject0-debuginfo-0.8-160000.3.1 * python313-avahi-0.8-160000.3.1 * avahi-autoipd-debuginfo-0.8-160000.3.1 * avahi-0.8-160000.3.1 * libavahi-core7-debuginfo-0.8-160000.3.1 * libavahi-glib1-debuginfo-0.8-160000.3.1 * libavahi-core7-0.8-160000.3.1 * avahi-utils-debuginfo-0.8-160000.3.1 * avahi-debuginfo-0.8-160000.3.1 * avahi-utils-0.8-160000.3.1 * libavahi-ui-gtk3-0-0.8-160000.3.1 * libavahi-devel-0.8-160000.3.1 * libavahi-client3-debuginfo-0.8-160000.3.1 * libavahi-common3-0.8-160000.3.1 * typelib-1_0-Avahi-0_6-0.8-160000.3.1 * libavahi-common3-debuginfo-0.8-160000.3.1 * libhowl0-debuginfo-0.8-160000.3.1 * libdns_sd-debuginfo-0.8-160000.3.1 * avahi-glib2-debugsource-0.8-160000.3.1 * avahi-utils-gtk-debuginfo-0.8-160000.3.1 * libavahi-glib1-0.8-160000.3.1 * libavahi-client3-0.8-160000.3.1 * avahi-compat-mDNSResponder-devel-0.8-160000.3.1 * libhowl0-0.8-160000.3.1 * python3-avahi-gtk-0.8-160000.3.1 * libavahi-libevent1-0.8-160000.3.1 * avahi-utils-gtk-0.8-160000.3.1 *libavahi-libevent1-debuginfo-0.8-160000.3.1 * libdns_sd-0.8-160000.3.1 * libavahi-gobject-devel-0.8-160000.3.1 * avahi-debugsource-0.8-160000.3.1 * libavahi-gobject0-0.8-160000.3.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.3.1 * libavahi-glib-devel-0.8-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * avahi-lang-0.8-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . A moderate security update for SUSE's avahi addresses DNS spoofing vulnerability (CVE-2024-52615) with patch instructions.. SUSE Security Update, Avahi DNS Spoofing, Linux Patch Instructions. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for avahi Announcement ID: SUSE-SU-2026:20070-1 Release Date: 2026-01-11T16:54:42Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: Fixed DNS spoofing (bsc#1233421) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-127=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libavahi-common3-debuginfo-0.8-160000.3.1 * avahi-debuginfo-0.8-160000.3.1 * libavahi-client3-debuginfo-0.8-160000.3.1 * libavahi-client3-0.8-160000.3.1 * avahi-debugsource-0.8-160000.3.1 * libavahi-common3-0.8-160000.3.1 * avahi-0.8-160000.3.1 * libavahi-core7-debuginfo-0.8-160000.3.1 * libavahi-core7-0.8-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . SUSE has released an update for avahi to address a DNS spoofing issue, classified with a moderate severity alert to enhance security. SUSE Linux, avahi, DNS spoofing, security update. . LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for avahi ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20013-1 Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for avahi fixes the following issues: - CVE-2024-52615: Fixed DNS spoofing (bsc#1233421) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-127=1 Package List: - openSUSE Leap 16.0: avahi-0.8-160000.3.1 avahi-autoipd-0.8-160000.3.1 avahi-compat-howl-devel-0.8-160000.3.1 avahi-compat-mDNSResponder-devel-0.8-160000.3.1 avahi-lang-0.8-160000.3.1 avahi-utils-0.8-160000.3.1 avahi-utils-gtk-0.8-160000.3.1 libavahi-client3-0.8-160000.3.1 libavahi-common3-0.8-160000.3.1 libavahi-core7-0.8-160000.3.1 libavahi-devel-0.8-160000.3.1 libavahi-glib-devel-0.8-160000.3.1 libavahi-glib1-0.8-160000.3.1 libavahi-gobject-devel-0.8-160000.3.1 libavahi-gobject0-0.8-160000.3.1 libavahi-libevent1-0.8-160000.3.1 libavahi-qt6-1-0.8-160000.3.1 libavahi-qt6-devel-0.8-160000.3.1 libavahi-ui-gtk3-0-0.8-160000.3.1 libdns_sd-0.8-160000.3.1 libhowl0-0.8-160000.3.1 python3-avahi-gtk-0.8-160000.3.1 python313-avahi-0.8-160000.3.1 typelib-1_0-Avahi-0_6-0.8-160000.3.1 References: *https://www.suse.com/security/cve/CVE-2024-52615.html . openSUSE releases a moderate security update for avahi to fix DNS spoofing vulnerability CVE-2024-52615. Install promptly.. openSUSE security avahi DNS spoofing. . LinuxSecurity.com Team
Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-10c407da27 2025-10-30 04:19:29.232276+00:00 -------------------------------------------------------------------------------- Name : bind-dyndb-ldap Product : Fedora 41 Version : 11.10 Release : 35.fc41 URL : https://releases.pagure.org/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. -------------------------------------------------------------------------------- Update Information: Update to 9.18.41 (rhbz#2405786) Security fixes: DNSSEC validation fails if matching but invalid DNSKEY is found. (CVE-2025-8677) Address various spoofing attacks. (CVE-2025-40778) Cache-poisoning due to weak pseudo-random number generator. (CVE-2025-40780) New Features: Support for parsing HHIT and BRID records has been added. Removed Features: Deprecate the "tkey-domain" statement. Deprecate the "tkey-gssapi-credential" statement. Bug Fixes: Prevent spurious SERVFAILs for certain 0-TTL resource records. Missing DNSSEC information when CD bit is set in query. https://downloads.isc.org/isc/bind9/9.18.41/doc/arm/html/notes.html#notes-for- bind-9-18-41 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Petr Men\u0161k - 11.10-35 - Rebuilt for BIND 9.18.41 (rhbz#2405786) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2405786 - bind-9.18.41 is available https://bugzilla.redhat.com/show_bug.cgi?id=2405786 [ 2 ] Bug#2405831 - CVE-2025-8677 CVE-2025-40778 CVE-2025-40780 bind: various flaws [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2405831 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-10c407da27' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41: bind-dyndb-ldap update for critical security issues including DNSSEC flaws and cache poison risks.. Bind Dyndb Ldap Security Fedora Update DNSSEC Cache Poisoning. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for avahi Announcement ID: SUSE-SU-2025:03331-1 Release Date: 2025-09-24T06:54:28Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3331=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3331=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3331=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3331=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3331=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3331=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * avahi-qt5-debugsource-0.8-150400.7.23.1 * libavahi-glib1-debuginfo-0.8-150400.7.23.1 * avahi-autoipd-debuginfo-0.8-150400.7.23.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-gobject0-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-glib-devel-0.8-150400.7.23.1 * avahi-compat-howl-devel-0.8-150400.7.23.1 * libavahi-devel-0.8-150400.7.23.1 * libavahi-qt5-1-0.8-150400.7.23.1 * libavahi-qt5-1-debuginfo-0.8-150400.7.23.1 * libavahi-libevent1-0.8-150400.7.23.1 * libhowl0-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * avahi-utils-0.8-150400.7.23.1 *libavahi-qt5-devel-0.8-150400.7.23.1 * avahi-compat-mDNSResponder-devel-0.8-150400.7.23.1 * libavahi-ui-gtk3-0-0.8-150400.7.23.1 * libhowl0-0.8-150400.7.23.1 * libavahi-gobject0-debuginfo-0.8-150400.7.23.1 * avahi-debuginfo-0.8-150400.7.23.1 * libdns_sd-debuginfo-0.8-150400.7.23.1 * avahi-glib2-debugsource-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libdns_sd-0.8-150400.7.23.1 * typelib-1_0-Avahi-0_6-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * avahi-utils-debuginfo-0.8-150400.7.23.1 * avahi-autoipd-0.8-150400.7.23.1 * libavahi-gobject-devel-0.8-150400.7.23.1 * python3-avahi-gtk-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-utils-gtk-0.8-150400.7.23.1 * libavahi-libevent1-debuginfo-0.8-150400.7.23.1 * avahi-utils-gtk-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-0.8-150400.7.23.1 * python3-avahi-0.8-150400.7.23.1 * openSUSE Leap 15.4 (x86_64) * libdns_sd-32bit-0.8-150400.7.23.1 * libavahi-common3-32bit-0.8-150400.7.23.1 * libavahi-client3-32bit-0.8-150400.7.23.1 * avahi-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-common3-32bit-debuginfo-0.8-150400.7.23.1 * libdns_sd-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-client3-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-32bit-0.8-150400.7.23.1 * openSUSE Leap 15.4 (noarch) * avahi-lang-0.8-150400.7.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libavahi-client3-64bit-0.8-150400.7.23.1 * avahi-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-client3-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-common3-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-64bit-0.8-150400.7.23.1 * libavahi-common3-64bit-0.8-150400.7.23.1 * libdns_sd-64bit-0.8-150400.7.23.1 * libdns_sd-64bit-debuginfo-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . The latest avahi update resolves a significant DNS spoofing vulnerability in openSUSE 15.4, thereby improving the overall security posture of the system.. openSUSE, avahi, security update, DNS spoofing, CVE-2024-52615. . LinuxSecurity.com Team
* bsc#1233421 Cross-References: * CVE-2024-52615 . # Security update for avahi Announcement ID: SUSE-SU-2025:03331-1 Release Date: 2025-09-24T06:54:28Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3331=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3331=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3331=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3331=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3331=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3331=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 *libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * avahi-qt5-debugsource-0.8-150400.7.23.1 * libavahi-glib1-debuginfo-0.8-150400.7.23.1 * avahi-autoipd-debuginfo-0.8-150400.7.23.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-gobject0-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-glib-devel-0.8-150400.7.23.1 * avahi-compat-howl-devel-0.8-150400.7.23.1 * libavahi-devel-0.8-150400.7.23.1 * libavahi-qt5-1-0.8-150400.7.23.1 * libavahi-qt5-1-debuginfo-0.8-150400.7.23.1 * libavahi-libevent1-0.8-150400.7.23.1 * libhowl0-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * avahi-utils-0.8-150400.7.23.1 *libavahi-qt5-devel-0.8-150400.7.23.1 * avahi-compat-mDNSResponder-devel-0.8-150400.7.23.1 * libavahi-ui-gtk3-0-0.8-150400.7.23.1 * libhowl0-0.8-150400.7.23.1 * libavahi-gobject0-debuginfo-0.8-150400.7.23.1 * avahi-debuginfo-0.8-150400.7.23.1 * libdns_sd-debuginfo-0.8-150400.7.23.1 * avahi-glib2-debugsource-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libdns_sd-0.8-150400.7.23.1 * typelib-1_0-Avahi-0_6-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * avahi-utils-debuginfo-0.8-150400.7.23.1 * avahi-autoipd-0.8-150400.7.23.1 * libavahi-gobject-devel-0.8-150400.7.23.1 * python3-avahi-gtk-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-utils-gtk-0.8-150400.7.23.1 * libavahi-libevent1-debuginfo-0.8-150400.7.23.1 * avahi-utils-gtk-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-0.8-150400.7.23.1 * python3-avahi-0.8-150400.7.23.1 * openSUSE Leap 15.4 (x86_64) * libdns_sd-32bit-0.8-150400.7.23.1 * libavahi-common3-32bit-0.8-150400.7.23.1 * libavahi-client3-32bit-0.8-150400.7.23.1 * avahi-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-common3-32bit-debuginfo-0.8-150400.7.23.1 * libdns_sd-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-client3-32bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-32bit-0.8-150400.7.23.1 * openSUSE Leap 15.4 (noarch) * avahi-lang-0.8-150400.7.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libavahi-client3-64bit-0.8-150400.7.23.1 * avahi-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-client3-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-common3-64bit-debuginfo-0.8-150400.7.23.1 * libavahi-glib1-64bit-0.8-150400.7.23.1 * libavahi-common3-64bit-0.8-150400.7.23.1 * libdns_sd-64bit-0.8-150400.7.23.1 * libdns_sd-64bit-debuginfo-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * avahi-debuginfo-0.8-150400.7.23.1 * avahi-0.8-150400.7.23.1 * libavahi-core7-debuginfo-0.8-150400.7.23.1 * libavahi-common3-0.8-150400.7.23.1 * libavahi-client3-debuginfo-0.8-150400.7.23.1 * libavahi-client3-0.8-150400.7.23.1 * avahi-debugsource-0.8-150400.7.23.1 * libavahi-common3-debuginfo-0.8-150400.7.23.1 * libavahi-core7-0.8-150400.7.23.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . SUSE releases critical security notice for avahi related to DNS impersonation flaw CVE-2024-52615. Apply patches immediately!. SUSE security advisory,avahi DNS exploit,security updates. . Severity: Important. LinuxSecurity.com Team
* bsc#1233421 Cross-References: * CVE-2024-52615 . # Security update for avahi Announcement ID: SUSE-SU-2025:03332-1 Release Date: 2025-09-24T06:54:39Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-3332=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * avahi-compat-howl-devel-0.6.32-32.33.1 * libavahi-client3-debuginfo-0.6.32-32.33.1 * libavahi-core7-0.6.32-32.33.1 * libavahi-common3-32bit-0.6.32-32.33.1 * libavahi-common3-debuginfo-0.6.32-32.33.1 * avahi-utils-0.6.32-32.33.1 * libavahi-core7-debuginfo-0.6.32-32.33.1 * libavahi-devel-0.6.32-32.33.1 * avahi-debuginfo-32bit-0.6.32-32.33.1 * libavahi-client3-debuginfo-32bit-0.6.32-32.33.1 * libavahi-common3-0.6.32-32.33.1 * libavahi-common3-debuginfo-32bit-0.6.32-32.33.1 * libdns_sd-debuginfo-32bit-0.6.32-32.33.1 *avahi-debuginfo-0.6.32-32.33.1 * libdns_sd-debuginfo-0.6.32-32.33.1 * avahi-0.6.32-32.33.1 * libdns_sd-0.6.32-32.33.1 * libavahi-client3-32bit-0.6.32-32.33.1 * avahi-debugsource-0.6.32-32.33.1 * avahi-utils-debuginfo-0.6.32-32.33.1 * libavahi-client3-0.6.32-32.33.1 * avahi-compat-mDNSResponder-devel-0.6.32-32.33.1 * libdns_sd-32bit-0.6.32-32.33.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * avahi-lang-0.6.32-32.33.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . This Fedora advisory outlines a critical patch for systemd tackling potential attack vectors linked to CVE-2024-52730.. SUSE, Avahi, DNS Spoofing. . LinuxSecurity.com Team
* bsc#1233421 Cross-References: * CVE-2024-52615 . # Security update for avahi Announcement ID: SUSE-SU-2025:03333-1 Release Date: 2025-09-24T06:55:39Z Rating: moderate References: * bsc#1233421 Cross-References: * CVE-2024-52615 CVSS scores: * CVE-2024-52615 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-52615 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-52615 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3333=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-3333=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-3333=1 * openSUSE Leap 15.6 zypper in -t patchSUSE-2025-3333=1 openSUSE-SLE-15.6-2025-3333=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-3333=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3333=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-3333=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libavahi-gobject-devel-0.8-150600.15.9.1 * avahi-glib2-debugsource-0.8-150600.15.9.1 * avahi-utils-gtk-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * avahi-debuginfo-0.8-150600.15.9.1 * avahi-autoipd-debuginfo-0.8-150600.15.9.1 * avahi-utils-gtk-debuginfo-0.8-150600.15.9.1 * avahi-autoipd-0.8-150600.15.9.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * avahi-debuginfo-0.8-150600.15.9.1 * python3-avahi-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * avahi-debuginfo-0.8-150600.15.9.1 * python3-avahi-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libavahi-glib-devel-0.8-150600.15.9.1 * avahi-utils-0.8-150600.15.9.1 * libavahi-common3-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-debuginfo-0.8-150600.15.9.1 * avahi-0.8-150600.15.9.1 * libavahi-devel-0.8-150600.15.9.1 * libhowl0-debuginfo-0.8-150600.15.9.1 * libavahi-core7-0.8-150600.15.9.1 * libavahi-qt5-devel-0.8-150600.15.9.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.9.1 * avahi-compat-howl-devel-0.8-150600.15.9.1 * python3-avahi-gtk-0.8-150600.15.9.1 * libdns_sd-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * avahi-debuginfo-0.8-150600.15.9.1 * libavahi-glib1-0.8-150600.15.9.1 * libavahi-qt5-1-0.8-150600.15.9.1 * libavahi-core7-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-0.8-150600.15.9.1 *libavahi-ui-gtk3-0-0.8-150600.15.9.1 * avahi-autoipd-0.8-150600.15.9.1 * libdns_sd-debuginfo-0.8-150600.15.9.1 * libavahi-gobject0-0.8-150600.15.9.1 * avahi-compat-mDNSResponder-devel-0.8-150600.15.9.1 * avahi-qt5-debugsource-0.8-150600.15.9.1 * avahi-utils-gtk-0.8-150600.15.9.1 * avahi-utils-gtk-debuginfo-0.8-150600.15.9.1 * libavahi-qt5-1-debuginfo-0.8-150600.15.9.1 * libavahi-gobject0-debuginfo-0.8-150600.15.9.1 * libavahi-common3-0.8-150600.15.9.1 * libavahi-client3-debuginfo-0.8-150600.15.9.1 * avahi-utils-debuginfo-0.8-150600.15.9.1 * libavahi-gobject-devel-0.8-150600.15.9.1 * libhowl0-0.8-150600.15.9.1 * python3-avahi-0.8-150600.15.9.1 * avahi-glib2-debugsource-0.8-150600.15.9.1 * libavahi-glib1-debuginfo-0.8-150600.15.9.1 * libavahi-client3-0.8-150600.15.9.1 * avahi-autoipd-debuginfo-0.8-150600.15.9.1 * typelib-1_0-Avahi-0_6-0.8-150600.15.9.1 * openSUSE Leap 15.6 (x86_64) * libavahi-common3-32bit-0.8-150600.15.9.1 * libavahi-client3-32bit-debuginfo-0.8-150600.15.9.1 * avahi-32bit-debuginfo-0.8-150600.15.9.1 * libavahi-client3-32bit-0.8-150600.15.9.1 * libdns_sd-32bit-debuginfo-0.8-150600.15.9.1 * libavahi-glib1-32bit-debuginfo-0.8-150600.15.9.1 * libdns_sd-32bit-0.8-150600.15.9.1 * libavahi-glib1-32bit-0.8-150600.15.9.1 * libavahi-common3-32bit-debuginfo-0.8-150600.15.9.1 * openSUSE Leap 15.6 (noarch) * avahi-lang-0.8-150600.15.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libavahi-client3-64bit-0.8-150600.15.9.1 * libdns_sd-64bit-debuginfo-0.8-150600.15.9.1 * libdns_sd-64bit-0.8-150600.15.9.1 * libavahi-glib1-64bit-debuginfo-0.8-150600.15.9.1 * avahi-64bit-debuginfo-0.8-150600.15.9.1 * libavahi-glib1-64bit-0.8-150600.15.9.1 * libavahi-common3-64bit-0.8-150600.15.9.1 * libavahi-common3-64bit-debuginfo-0.8-150600.15.9.1 * libavahi-client3-64bit-debuginfo-0.8-150600.15.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) *libavahi-glib-devel-0.8-150600.15.9.1 * avahi-utils-0.8-150600.15.9.1 * libavahi-common3-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-debuginfo-0.8-150600.15.9.1 * avahi-0.8-150600.15.9.1 * libavahi-devel-0.8-150600.15.9.1 * libhowl0-debuginfo-0.8-150600.15.9.1 * libavahi-core7-0.8-150600.15.9.1 * libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.9.1 * avahi-compat-howl-devel-0.8-150600.15.9.1 * libdns_sd-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * avahi-debuginfo-0.8-150600.15.9.1 * libavahi-glib1-0.8-150600.15.9.1 * libavahi-core7-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-0.8-150600.15.9.1 * libavahi-ui-gtk3-0-0.8-150600.15.9.1 * libavahi-gobject0-0.8-150600.15.9.1 * libdns_sd-debuginfo-0.8-150600.15.9.1 * avahi-compat-mDNSResponder-devel-0.8-150600.15.9.1 * libavahi-gobject0-debuginfo-0.8-150600.15.9.1 * libavahi-common3-0.8-150600.15.9.1 * libavahi-client3-debuginfo-0.8-150600.15.9.1 * avahi-utils-debuginfo-0.8-150600.15.9.1 * libhowl0-0.8-150600.15.9.1 * avahi-glib2-debugsource-0.8-150600.15.9.1 * libavahi-glib1-debuginfo-0.8-150600.15.9.1 * libavahi-client3-0.8-150600.15.9.1 * typelib-1_0-Avahi-0_6-0.8-150600.15.9.1 * Basesystem Module 15-SP6 (noarch) * avahi-lang-0.8-150600.15.9.1 * Basesystem Module 15-SP6 (x86_64) * libavahi-common3-32bit-0.8-150600.15.9.1 * libavahi-client3-32bit-debuginfo-0.8-150600.15.9.1 * avahi-32bit-debuginfo-0.8-150600.15.9.1 * libavahi-client3-32bit-0.8-150600.15.9.1 * libavahi-common3-32bit-debuginfo-0.8-150600.15.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libavahi-glib-devel-0.8-150600.15.9.1 * avahi-utils-0.8-150600.15.9.1 * libavahi-common3-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-debuginfo-0.8-150600.15.9.1 * avahi-0.8-150600.15.9.1 * libavahi-devel-0.8-150600.15.9.1 * libhowl0-debuginfo-0.8-150600.15.9.1 * libavahi-core7-0.8-150600.15.9.1 *libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.9.1 * avahi-compat-howl-devel-0.8-150600.15.9.1 * libdns_sd-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * avahi-debuginfo-0.8-150600.15.9.1 * libavahi-glib1-0.8-150600.15.9.1 * libavahi-core7-debuginfo-0.8-150600.15.9.1 * libavahi-libevent1-0.8-150600.15.9.1 * libavahi-ui-gtk3-0-0.8-150600.15.9.1 * libavahi-gobject0-0.8-150600.15.9.1 * libdns_sd-debuginfo-0.8-150600.15.9.1 * avahi-compat-mDNSResponder-devel-0.8-150600.15.9.1 * libavahi-gobject0-debuginfo-0.8-150600.15.9.1 * libavahi-common3-0.8-150600.15.9.1 * libavahi-client3-debuginfo-0.8-150600.15.9.1 * avahi-utils-debuginfo-0.8-150600.15.9.1 * libhowl0-0.8-150600.15.9.1 * avahi-glib2-debugsource-0.8-150600.15.9.1 * libavahi-glib1-debuginfo-0.8-150600.15.9.1 * libavahi-client3-0.8-150600.15.9.1 * typelib-1_0-Avahi-0_6-0.8-150600.15.9.1 * Basesystem Module 15-SP7 (noarch) * avahi-lang-0.8-150600.15.9.1 * Basesystem Module 15-SP7 (x86_64) * libavahi-common3-32bit-0.8-150600.15.9.1 * libavahi-client3-32bit-debuginfo-0.8-150600.15.9.1 * avahi-32bit-debuginfo-0.8-150600.15.9.1 * libavahi-client3-32bit-0.8-150600.15.9.1 * libavahi-common3-32bit-debuginfo-0.8-150600.15.9.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libavahi-gobject-devel-0.8-150600.15.9.1 * avahi-glib2-debugsource-0.8-150600.15.9.1 * avahi-utils-gtk-0.8-150600.15.9.1 * avahi-debugsource-0.8-150600.15.9.1 * avahi-debuginfo-0.8-150600.15.9.1 * avahi-autoipd-debuginfo-0.8-150600.15.9.1 * avahi-utils-gtk-debuginfo-0.8-150600.15.9.1 * avahi-autoipd-0.8-150600.15.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-52615.html * https://bugzilla.suse.com/show_bug.cgi?id=1233421 . An advisory for avahi services has unveiled a serious DNS spoofing vulnerability, CVE-2024-52615, on SUSE distributions. Prompt action is advised to mitigate associated risks.. avahi securityupdate, SUSE Linux advisory, DNS spoofing risk, avahi vulnerability, moderate security patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.