An update that solves three vulnerabilities can now be installed.. # Security update for erlang Announcement ID: SUSE-SU-2026:0661-1 Release Date: 2026-02-26T15:10:16Z Rating: moderate References: * bsc#1249469 * bsc#1249470 * bsc#1249472 Cross-References: * CVE-2025-48038 * CVE-2025-48039 * CVE-2025-48040 CVSS scores: * CVE-2025-48038 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48038 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48038 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48039 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48039 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48039 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48040 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48040 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-48040 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux EnterpriseServer 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for erlang fixes the following issues: * CVE-2025-48039:Fixed an excessive use of system resources. (bsc#1249469) * CVE-2025-48038:Fixed an excessive use of system resources. (bsc#1249470) * CVE-2025-48040:Fixed an excessive resource consumption. (bsc#1249472) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-661=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-661=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-661=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * erlang-src-23.3.4.19-150300.3.29.1 * erlang-et-23.3.4.19-150300.3.29.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.29.1 * erlang-jinterface-23.3.4.19-150300.3.29.1 * erlang-diameter-23.3.4.19-150300.3.29.1 * erlang-epmd-23.3.4.19-150300.3.29.1 * erlang-wx-23.3.4.19-150300.3.29.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.29.1 * erlang-debugger-23.3.4.19-150300.3.29.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.29.1 * erlang-reltool-23.3.4.19-150300.3.29.1 * erlang-wx-src-23.3.4.19-150300.3.29.1 * erlang-23.3.4.19-150300.3.29.1 * erlang-observer-23.3.4.19-150300.3.29.1 * erlang-reltool-src-23.3.4.19-150300.3.29.1 * erlang-diameter-src-23.3.4.19-150300.3.29.1 * erlang-debugsource-23.3.4.19-150300.3.29.1 * erlang-et-src-23.3.4.19-150300.3.29.1 * erlang-doc-23.3.4.19-150300.3.29.1 * erlang-debuginfo-23.3.4.19-150300.3.29.1 * erlang-debugger-src-23.3.4.19-150300.3.29.1 * erlang-jinterface-src-23.3.4.19-150300.3.29.1 *erlang-dialyzer-23.3.4.19-150300.3.29.1 * erlang-dialyzer-src-23.3.4.19-150300.3.29.1 * erlang-observer-src-23.3.4.19-150300.3.29.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * erlang-src-23.3.4.19-150300.3.29.1 * erlang-et-23.3.4.19-150300.3.29.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.29.1 * erlang-jinterface-23.3.4.19-150300.3.29.1 * erlang-diameter-23.3.4.19-150300.3.29.1 * erlang-epmd-23.3.4.19-150300.3.29.1 * erlang-wx-23.3.4.19-150300.3.29.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.29.1 * erlang-debugger-23.3.4.19-150300.3.29.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.29.1 * erlang-reltool-23.3.4.19-150300.3.29.1 * erlang-wx-src-23.3.4.19-150300.3.29.1 * erlang-23.3.4.19-150300.3.29.1 * erlang-observer-23.3.4.19-150300.3.29.1 * erlang-reltool-src-23.3.4.19-150300.3.29.1 * erlang-diameter-src-23.3.4.19-150300.3.29.1 * erlang-debugsource-23.3.4.19-150300.3.29.1 * erlang-et-src-23.3.4.19-150300.3.29.1 * erlang-doc-23.3.4.19-150300.3.29.1 * erlang-debuginfo-23.3.4.19-150300.3.29.1 * erlang-debugger-src-23.3.4.19-150300.3.29.1 * erlang-jinterface-src-23.3.4.19-150300.3.29.1 * erlang-dialyzer-23.3.4.19-150300.3.29.1 * erlang-dialyzer-src-23.3.4.19-150300.3.29.1 * erlang-observer-src-23.3.4.19-150300.3.29.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * erlang-debuginfo-23.3.4.19-150300.3.29.1 * erlang-23.3.4.19-150300.3.29.1 * erlang-epmd-23.3.4.19-150300.3.29.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.29.1 * erlang-debugsource-23.3.4.19-150300.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48038.html * https://www.suse.com/security/cve/CVE-2025-48039.html * https://www.suse.com/security/cve/CVE-2025-48040.html * https://bugzilla.suse.com/show_bug.cgi?id=1249469 * https://bugzilla.suse.com/show_bug.cgi?id=1249470 * https://bugzilla.suse.com/show_bug.cgi?id=1249472 . This update resolves three identifiedissues in erlang, addressing excessive resource use. Install it now for improved stability.. openSUSE erlang system resources security update patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for python-py ______________________________________________________________________________ Announcement ID: SUSE-SU-2023:0161-1 Rating: moderate References: #1204364 Cross-References: CVE-2022-42969 CVSS scores: CVE-2022-42969 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-42969 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Micro 5.2 SUSE Linux Enterprise Micro 5.3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 openSUSE Leap Micro 5.2 openSUSE Leap Micro 5.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-py fixes the following issues: - CVE-2022-42969: Fixed an excessive resource consumption that could be triggered when interacting with a Subversion repository containing crated data (bsc#1204364). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap Micro 5.3: zypper in -tpatch openSUSE-Leap-Micro-5.3-2023-161=1 - openSUSE Leap Micro 5.2: zypper in -t patch openSUSE-Leap-Micro-5.2-2023-161=1 - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2023-161=1 - SUSE Linux Enterprise Realtime Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-RT-15-SP3-2023-161=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-161=1 - SUSE Linux Enterprise Micro 5.3: zypper in -t patch SUSE-SLE-Micro-5.3-2023-161=1 - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-161=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-161=1 Package List: - openSUSE Leap Micro 5.3 (noarch): python3-py-1.10.0-150100.5.12.1 - openSUSE Leap Micro 5.2 (noarch): python3-py-1.10.0-150100.5.12.1 - openSUSE Leap 15.4 (noarch): python3-py-1.10.0-150100.5.12.1 - SUSE Linux Enterprise Realtime Extension 15-SP3 (noarch): python3-py-1.10.0-150100.5.12.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (noarch): python3-py-1.10.0-150100.5.12.1 - SUSE Linux Enterprise Micro 5.3 (noarch): python3-py-1.10.0-150100.5.12.1 - SUSE Linux Enterprise Micro 5.2 (noarch): python3-py-1.10.0-150100.5.12.1 - SUSE Linux Enterprise Micro 5.1 (noarch): python3-py-1.10.0-150100.5.12.1 References: https://www.suse.com/security/cve/CVE-2022-42969.html https://bugzilla.suse.com/1204364 . Correction notice issued for python-py over high resource usage security flaw in openSUSE and SUSE Linux Enterprise distributions.. openSUSE Python Update,SUSE Security Advisory,Resource Consumption Fix,Python-Py Vulnerability,SUSE Linux Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.