Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for glibc Announcement ID: SUSE-SU-2025:01784-1 Release Date: 2025-05-30T16:10:21Z Rating: important References: * bsc#1234128 * bsc#1243317 Cross-References: * CVE-2025-4802 CVSS scores: * CVE-2025-4802 ( SUSE ): 9.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-4802 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-4802 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update thatsolves one vulnerability and has one security fix can now be installed. ## Description: This update for glibc fixes the following issues: Security issues fixed: * CVE-2025-4802: possible execution of attacker controlled code when statically linked setuid binaries using dlopen search for libraries to load in LD_LIBRARY_PATH (bsc#1243317). Other issues fixed: * Multi-threaded application hang due to deadlock when `pthread_cond_signal` fails to wake up `pthread_cond_wait` as a consequence of a bug related to stealing of signals (bsc#1234128). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1784=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1784=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1784=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1784=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1784=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-1784=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-1784=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1784=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1784=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1784=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1784=1 * SUSE Linux EnterpriseServer 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-1784=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1784=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-1784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1784=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-1784=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-1784=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-1784=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-1784=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-1784=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1784=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1784=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586 i686) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * glibc-extra-2.31-150300.95.1 *glibc-utils-src-debugsource-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * openSUSE Leap 15.3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-html-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * openSUSE Leap 15.3 (x86_64) * glibc-utils-32bit-debuginfo-2.31-150300.95.1 * glibc-profile-32bit-2.31-150300.95.1 * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-utils-32bit-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-devel-static-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * openSUSE Leap 15.3 (aarch64_ilp32) * glibc-64bit-2.31-150300.95.1 * glibc-devel-64bit-debuginfo-2.31-150300.95.1 * glibc-utils-64bit-debuginfo-2.31-150300.95.1 * glibc-64bit-debuginfo-2.31-150300.95.1 * glibc-profile-64bit-2.31-150300.95.1 * glibc-locale-base-64bit-debuginfo-2.31-150300.95.1 * glibc-devel-static-64bit-2.31-150300.95.1 * glibc-locale-base-64bit-2.31-150300.95.1 * glibc-utils-64bit-2.31-150300.95.1 * glibc-devel-64bit-2.31-150300.95.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 *glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux EnterpriseHigh Performance Computing LTSS 15 SP3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 *glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise HighPerformance Computing ESPOS 15 SP5 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 *glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 *glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE LinuxEnterprise Server for SAP Applications 15 SP3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 *glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Manager Proxy 4.3 (x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Manager Proxy 4.3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 *glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Manager Server 4.3 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Manager Server 4.3 (x86_64) * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * glibc-devel-debuginfo-2.31-150300.95.1 * glibc-extra-2.31-150300.95.1 * glibc-utils-src-debugsource-2.31-150300.95.1 * glibc-utils-2.31-150300.95.1 * glibc-devel-static-2.31-150300.95.1 * nscd-2.31-150300.95.1 * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 *glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-extra-debuginfo-2.31-150300.95.1 * glibc-utils-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * nscd-debuginfo-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * glibc-profile-2.31-150300.95.1 * SUSE Enterprise Storage 7.1 (noarch) * glibc-i18ndata-2.31-150300.95.1 * glibc-lang-2.31-150300.95.1 * glibc-info-2.31-150300.95.1 * SUSE Enterprise Storage 7.1 (x86_64) * glibc-devel-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.95.1 * glibc-devel-32bit-2.31-150300.95.1 * glibc-32bit-2.31-150300.95.1 * glibc-32bit-debuginfo-2.31-150300.95.1 * glibc-locale-base-32bit-2.31-150300.95.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.95.1 * glibc-devel-2.31-150300.95.1 * glibc-debuginfo-2.31-150300.95.1 * glibc-locale-base-2.31-150300.95.1 * glibc-locale-base-debuginfo-2.31-150300.95.1 * glibc-2.31-150300.95.1 * glibc-debugsource-2.31-150300.95.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4802.html * https://bugzilla.suse.com/show_bug.cgi?id=1234128 * https://bugzilla.suse.com/show_bug.cgi?id=1243317 . Essential patch for Fedoratackling a significant kernel vulnerability and operational defect. Prompt response advised.. openSUSE glibc patch security. . Severity: Critical. LinuxSecurity.com Team
AMD processors may allow an attacker to expose sensitive information due to a vector register speculative execution vulnerability.. ========================================================================== Ubuntu Security Notice USN-6244-1 July 25, 2023 amd64-microcode vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: AMD processors may allow an attacker to expose sensitive information due to a vector register speculative execution vulnerability. Software Description: - amd64-microcode: Processor microcode firmware for AMD CPUs Details: Tavis Ormandy discovered that some AMD processors did not properly handle speculative execution of certain vector register instructions. A local attacker could use this to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: amd64-microcode 3.20220411.1ubuntu3.1 Ubuntu 22.04 LTS: amd64-microcode 3.20191218.1ubuntu2.1 Ubuntu 20.04 LTS: amd64-microcode 3.20191218.1ubuntu1.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): amd64-microcode 3.20191021.1+really3.20181128.1~ubuntu0.18.04.1+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): amd64-microcode 3.20191021.1+really3.20180524.1~ubuntu0.16.04.2+esm1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6244-1 CVE-2023-20593 Package Information: https://launchpad.net/ubuntu/+source/amd64-microcode/3.20220411.1ubuntu3.1 https://launchpad.net/ubuntu/+source/amd64-microcode/3.20191218.1ubuntu2.1 https://launchpad.net/ubuntu/+source/amd64-microcode/3.20191218.1ubuntu1.1 . Intel CPUs suffer from a major security loophole that might leak confidential data. Linux patches now accessible.. AMD Processors Security, Ubuntu Microcode Update, Speculative Execution Attack. . Severity: Critical. LinuxSecurity.com Team
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when . MGASA-2022-0400 - Updated libreoffice packages fix security vulnerability Publication date: 28 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0400.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-3140 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. (CVE-2022-3140) References: - https://bugs.mageia.org/show_bug.cgi?id=30959 - - https://lists.debian.org/debian-security-announce/2022/msg00221.html - https://lists.fedoraproject.org/archives/list/
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measures . MGASA-2022-0339 - Updated redis packages fix security vulnerability Publication date: 21 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0339.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-24735, CVE-2022-24736 Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measures that prevent a script from creating side effects that persist and can affect the execution of the same, or different script, at a later time. Several weaknesses of these measures have been publicly known for a long time, but they had no security impact as the Redis security model did not endorse the concept of users or privileges. With the introduction of ACLs in Redis 6.0, these weaknesses can be exploited by a less privileged users to inject Lua code that will execute at a later time, when a privileged user executes a Lua script. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules. (CVE-2022-24735) Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed inRedis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules. (CVE-2022-24736) References: - https://bugs.mageia.org/show_bug.cgi?id=30393 - https://lists.fedoraproject.org/archives/list/
Multiple security issues have been discovered in the PostgreSQL database system, which could result in the execution of arbitrary code or disclosure of memory content. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2662-1
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 18 for SLE 15) ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0868-1 Rating: important References: #1178684 #1179616 #1179664 #1181553 Cross-References: CVE-2020-27786 CVE-2020-28374 CVE-2020-29368 CVE-2021-3347 CVSS scores: CVE-2020-27786 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-27786 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-28374 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-28374 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-29368 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-29368 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3347 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3347 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-150_52 fixes several issues. The following security issues were fixed: - CVE-2020-29368: Fixed an issue in copy-on-write implementation which could have granted unintended write access because of a race condition in a THP mapcount check (bsc#1179664). - CVE-2021-3347: Fixed a use-after-free in the PI futexes during fault handling, allowing local users to execute code in the kernel (bsc#1181553). - CVE-2020-27786: Fixed a potential user after freewhich could have led to memory corruption or privilege escalation (bsc#1179616). - CVE-2020-28374: Fixed insufficient identifier checking in the LIO SCSI target code which could have been used by remote attackers to read or write files via directory traversal in an XCOPY request (bsc#1178684). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2021-865=1 SUSE-SLE-Module-Live-Patching-15-2021-866=1 SUSE-SLE-Module-Live-Patching-15-2021-867=1 SUSE-SLE-Module-Live-Patching-15-2021-868=1 - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2021-822=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150_52-default-7-2.2 kernel-livepatch-4_12_14-150_52-default-debuginfo-7-2.2 kernel-livepatch-4_12_14-150_55-default-7-2.2 kernel-livepatch-4_12_14-150_55-default-debuginfo-7-2.2 kernel-livepatch-4_12_14-150_58-default-6-2.2 kernel-livepatch-4_12_14-150_58-default-debuginfo-6-2.2 kernel-livepatch-4_12_14-150_63-default-4-2.2 kernel-livepatch-4_12_14-150_63-default-debuginfo-4-2.2 - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le s390x x86_64): kgraft-patch-4_12_14-95_65-default-3-2.2 References: https://www.suse.com/security/cve/CVE-2020-27786.html https://www.suse.com/security/cve/CVE-2020-28374.html https://www.suse.com/security/cve/CVE-2020-29368.html https://www.suse.com/security/cve/CVE-2021-3347.html https://bugzilla.suse.com/1178684 https://bugzilla.suse.com/1179616 https://bugzilla.suse.com/1179664 https://bugzilla.suse.com/1181553 . Important SUSE upgrade addresses several vulnerabilities in the LinuxKernel (Live Patch 18) for business clients.. Kernel Patch, Security Update, Live Patching, SUSE Enterprise. . Severity: Important. LinuxSecurity.com Team
The package salt before version 3002.5-3 is vulnerable to multiple issues including access restriction bypass, arbitrary command execution, certificate verification bypass, cross-site scripting, insufficient validation, privilege escalation, directory traversal and information disclosure. . Arch Linux Security Advisory ASA-202102-33 ========================================= Severity: High Date : 2021-02-27 CVE-ID : CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3144 CVE-2021-3148 CVE-2021-3197 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 Package : salt Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1624 Summary ====== The package salt before version 3002.5-3 is vulnerable to multiple issues including access restriction bypass, arbitrary command execution, certificate verification bypass, cross-site scripting, insufficient validation, privilege escalation, directory traversal and information disclosure. Resolution ========= Upgrade to 3002.5-3. # pacman -Syu "salt> =3002.5-3" The problems have been fixed upstream in version 3002.5. Workaround ========= None. Description ========== - CVE-2020-28243 (privilege escalation) An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create files on the minion in a non-blacklisted directory. - CVE-2020-28972 (certificate verification bypass) In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate. - CVE-2020-35662 (certificate verification bypass) In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. - CVE-2021-3144 (insufficient validation) In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They mightbe used to run command against the salt master or minions.) - CVE-2021-3148 (arbitrary command execution) An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py. - CVE-2021-3197 (arbitrary command execution) An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. - CVE-2021-25281 (access restriction bypass) An issue was discovered in SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master. - CVE-2021-25282 (directory traversal) An issue was discovered in SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. - CVE-2021-25283 (cross-site scripting) An issue was discovered in SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. - CVE-2021-25284 (information disclosure) An issue was discovered in SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. Impact ===== A remote unauthenticated attacker could execute commands, bypass TLS verification, traverse directories and disclose credentials. References ========= https://security.archlinux.org/CVE-2020-28243 https://security.archlinux.org/CVE-2020-28972 https://security.archlinux.org/CVE-2020-35662 https://security.archlinux.org/CVE-2021-3144 https://security.archlinux.org/CVE-2021-3148 https://security.archlinux.org/CVE-2021-3197 https://security.archlinux.org/CVE-2021-25281 https://security.archlinux.org/CVE-2021-25282 https://security.archlinux.org/CVE-2021-25283 https://security.archlinux.org/CVE-2021-25284 . Arch Linux SecurityAdvisory ASA-202102-33 ========================================= Severity: High . package, version, vulnerable, restricti. . LinuxSecurity.com Team
Stephane Chauveau discovered that the graphics protocol implementation in Kitty, a GPU-based terminal emulator, did not sanitise a filename when returning an error message, which could result in the execution of arbitrary shell commands when displaying a file with cat. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4819-1
Get the latest Linux and open source security news straight to your inbox.