Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves three vulnerabilities can now be installed.. # Security update for xen Announcement ID: SUSE-SU-2026:1657-1 Release Date: 2026-04-29T11:06:54Z Rating: important References: * bsc#1262178 * bsc#1262180 * bsc#1262428 Cross-References: * CVE-2025-54505 * CVE-2026-23557 * CVE-2026-23558 CVSS scores: * CVE-2025-54505 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-54505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-54505 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23557 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-23558 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23558 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2025-54505: floating point divider state sampling on AMD CPUs AMD- SN-7053 (bsc#1262428). * CVE-2026-23557: Xenstored DoS via XS_RESET_WATCHES command (bsc#1262178). * CVE-2026-23558: grant table v2 race in status page mapping (bsc#1262180). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or"zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1657=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-1657=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1657=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1657=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1657=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1657=1 ## Package List: * openSUSE Leap 15.5 (aarch64 x86_64 i586) * xen-debugsource-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-tools-domU-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-domU-4.17.6_08-150500.3.65.1 * xen-devel-4.17.6_08-150500.3.65.1 * openSUSE Leap 15.5 (x86_64) * xen-libs-32bit-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-32bit-4.17.6_08-150500.3.65.1 * openSUSE Leap 15.5 (aarch64 x86_64) * xen-doc-html-4.17.6_08-150500.3.65.1 * xen-4.17.6_08-150500.3.65.1 * xen-tools-4.17.6_08-150500.3.65.1 * xen-tools-debuginfo-4.17.6_08-150500.3.65.1 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_08-150500.3.65.1 * openSUSE Leap 15.5 (aarch64_ilp32) * xen-libs-64bit-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-64bit-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-debugsource-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * xen-debugsource-4.17.6_08-150500.3.65.1 * xen-tools-4.17.6_08-150500.3.65.1 * xen-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-tools-domU-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-domU-4.17.6_08-150500.3.65.1 * xen-devel-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * xen-debugsource-4.17.6_08-150500.3.65.1 * xen-tools-4.17.6_08-150500.3.65.1 * xen-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-tools-domU-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-domU-4.17.6_08-150500.3.65.1 * xen-devel-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * xen-debugsource-4.17.6_08-150500.3.65.1 * xen-tools-4.17.6_08-150500.3.65.1 * xen-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-tools-domU-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-domU-4.17.6_08-150500.3.65.1 * xen-devel-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * xen-debugsource-4.17.6_08-150500.3.65.1 * xen-tools-4.17.6_08-150500.3.65.1 * xen-4.17.6_08-150500.3.65.1 * xen-libs-4.17.6_08-150500.3.65.1 * xen-tools-domU-debuginfo-4.17.6_08-150500.3.65.1 * xen-libs-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-debuginfo-4.17.6_08-150500.3.65.1 * xen-tools-domU-4.17.6_08-150500.3.65.1 *xen-devel-4.17.6_08-150500.3.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_08-150500.3.65.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54505.html * https://www.suse.com/security/cve/CVE-2026-23557.html * https://www.suse.com/security/cve/CVE-2026-23558.html * https://bugzilla.suse.com/show_bug.cgi?id=1262178 * https://bugzilla.suse.com/show_bug.cgi?id=1262180 * https://bugzilla.suse.com/show_bug.cgi?id=1262428 . Critical update for openSUSE resolves important issues in Xen, enhancing system safety against multiple threats.. openSUSE security update, xen vulnerabilities, important updates, DoS threats. . Severity: Important. LinuxSecurity.com Team
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function. . MGASA-2025-0152 - Updated transfig packages fix security vulnerabilities Publication date: 11 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0152.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-31162, CVE-2025-31163, CVE-2025-31164 Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. (CVE-2025-31162) Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patternarc function. (CVE-2025-31163) Heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_line_with_spline. (CVE-2025-31164) References: - https://bugs.mageia.org/show_bug.cgi?id=34260 - - https://www.cve.org/CVERecord?id=CVE-2025-31162 - https://www.cve.org/CVERecord?id=CVE-2025-31163 - https://www.cve.org/CVERecord?id=CVE-2025-31164 SRPMS: - 9/core/transfig-3.2.9a-1.mga9 . Mageia's security advisory addresses critical vulnerabilities in input handling within the transfig package, urging users to apply patches swiftly to reduce risk. Mageia transfig vulnerabilities, local input manipulation, security patches. . Severity: Critical. LinuxSecurity.com Team
* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 . # Security update for poppler Announcement ID: SUSE-SU-2025:1339-1 Release Date: 2025-04-17T11:02:49Z Rating: moderate References: * bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 * CVE-2025-32365 CVSS scores: * CVE-2025-32364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32364 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32364 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32365 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-32364: Fixed a floating point exception. (bsc#1240880) * CVE-2025-32365: Fixed the isOk check in JBIG2Bitmap::combine function in JBIG2Stream.cc. (bsc#1240881) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1339=1 ## Package List: * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libpoppler89-debuginfo-0.79.0-150200.3.38.1 * libpoppler89-0.79.0-150200.3.38.1 * poppler-debugsource-0.79.0-150200.3.38.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32364.html *https://www.suse.com/security/cve/CVE-2025-32365.html * https://bugzilla.suse.com/show_bug.cgi?id=1240880 * https://bugzilla.suse.com/show_bug.cgi?id=1240881 . Enhance poppler on SUSE to rectify floating-point errors and bolster security protocols.. poppler update, SUSE security, floating point exception fix, JBIG2 check fix, moderate severity update. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for poppler Announcement ID: SUSE-SU-2025:1172-1 Release Date: 2025-04-08T13:36:26Z Rating: moderate References: * bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 * CVE-2025-32365 CVSS scores: * CVE-2025-32364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32364 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32364 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32365 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-32364: Fixed a floating point exception. (bsc#1240880) * CVE-2025-32365: Fixed the isOk check in JBIG2Bitmap::combine function in JBIG2Stream.cc. (bsc#1240881) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1172=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libpoppler-qt6-3-22.01.0-150400.3.28.1 * poppler-debugsource-22.01.0-150400.3.28.1 * libpoppler-cpp0-22.01.0-150400.3.28.1 * libpoppler-glib-devel-22.01.0-150400.3.28.1 * typelib-1_0-Poppler-0_18-22.01.0-150400.3.28.1 * libpoppler-qt6-3-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-debuginfo-22.01.0-150400.3.28.1 * poppler-tools-22.01.0-150400.3.28.1 * poppler-tools-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-22.01.0-150400.3.28.1 * libpoppler-qt6-devel-22.01.0-150400.3.28.1 * libpoppler117-22.01.0-150400.3.28.1 * libpoppler117-debuginfo-22.01.0-150400.3.28.1 * libpoppler-glib8-22.01.0-150400.3.28.1 * libpoppler-glib8-debuginfo-22.01.0-150400.3.28.1 * poppler-qt5-debugsource-22.01.0-150400.3.28.1 * poppler-qt6-debugsource-22.01.0-150400.3.28.1 * libpoppler-qt5-devel-22.01.0-150400.3.28.1 * libpoppler-qt5-1-debuginfo-22.01.0-150400.3.28.1 * libpoppler-devel-22.01.0-150400.3.28.1 * openSUSE Leap 15.4 (x86_64) * libpoppler117-32bit-22.01.0-150400.3.28.1 * libpoppler-glib8-32bit-22.01.0-150400.3.28.1 * libpoppler117-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-32bit-22.01.0-150400.3.28.1 * libpoppler-glib8-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-32bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-cpp0-32bit-22.01.0-150400.3.28.1 * libpoppler-qt5-1-32bit-debuginfo-22.01.0-150400.3.28.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpoppler117-64bit-22.01.0-150400.3.28.1 * libpoppler-qt5-1-64bit-22.01.0-150400.3.28.1 * libpoppler-cpp0-64bit-22.01.0-150400.3.28.1 * libpoppler-cpp0-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-qt5-1-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler117-64bit-debuginfo-22.01.0-150400.3.28.1 * libpoppler-glib8-64bit-22.01.0-150400.3.28.1 * libpoppler-glib8-64bit-debuginfo-22.01.0-150400.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32364.html * https://www.suse.com/security/cve/CVE-2025-32365.html * https://bugzilla.suse.com/show_bug.cgi?id=1240880 * https://bugzilla.suse.com/show_bug.cgi?id=1240881 . Revise location specifics to address intermediary problems within poppler, aimed at bolstering security measures on openSUSE platforms.. openSUSE update, poppler security, moderate severity issue. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for poppler Announcement ID: SUSE-SU-2025:1173-1 Release Date: 2025-04-08T13:36:38Z Rating: moderate References: * bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 * CVE-2025-32365 CVSS scores: * CVE-2025-32364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32364 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32364 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32365 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.5 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-32364: Fixed a floating point exception. (bsc#1240880) * CVE-2025-32365: Fixed the isOk check in JBIG2Bitmap::combine function in JBIG2Stream.cc. (bsc#1240881) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-1173=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libpoppler-qt5-1-23.01.0-150500.3.17.1 * libpoppler126-23.01.0-150500.3.17.1 * poppler-tools-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-debuginfo-23.01.0-150500.3.17.1 * poppler-debugsource-23.01.0-150500.3.17.1 * libpoppler-glib8-23.01.0-150500.3.17.1 * libpoppler-qt5-devel-23.01.0-150500.3.17.1 * poppler-qt5-debugsource-23.01.0-150500.3.17.1 * libpoppler-qt6-3-debuginfo-23.01.0-150500.3.17.1 *libpoppler-qt5-1-debuginfo-23.01.0-150500.3.17.1 * typelib-1_0-Poppler-0_18-23.01.0-150500.3.17.1 * libpoppler-qt6-devel-23.01.0-150500.3.17.1 * libpoppler126-debuginfo-23.01.0-150500.3.17.1 * poppler-qt6-debugsource-23.01.0-150500.3.17.1 * libpoppler-cpp0-23.01.0-150500.3.17.1 * poppler-tools-23.01.0-150500.3.17.1 * libpoppler-cpp0-debuginfo-23.01.0-150500.3.17.1 * libpoppler-qt6-3-23.01.0-150500.3.17.1 * libpoppler-glib-devel-23.01.0-150500.3.17.1 * libpoppler-devel-23.01.0-150500.3.17.1 * openSUSE Leap 15.5 (x86_64) * libpoppler126-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-qt5-1-32bit-23.01.0-150500.3.17.1 * libpoppler-cpp0-32bit-23.01.0-150500.3.17.1 * libpoppler126-32bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-cpp0-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-32bit-23.01.0-150500.3.17.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libpoppler-glib8-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-cpp0-64bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-64bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-64bit-23.01.0-150500.3.17.1 * libpoppler126-64bit-23.01.0-150500.3.17.1 * libpoppler-cpp0-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler126-64bit-debuginfo-23.01.0-150500.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32364.html * https://www.suse.com/security/cve/CVE-2025-32365.html * https://bugzilla.suse.com/show_bug.cgi?id=1240880 * https://bugzilla.suse.com/show_bug.cgi?id=1240881 . A new patch for poppler resolves two critical bugs: an integer overflow issue and a bitmap compression error. Safeguard your software now!. Poppler Update, openSUSE Security, OpenSUSE Patch, Security Advisory. . LinuxSecurity.com Team
* bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 . # Security update for poppler Announcement ID: SUSE-SU-2025:1173-1 Release Date: 2025-04-08T13:36:38Z Rating: moderate References: * bsc#1240880 * bsc#1240881 Cross-References: * CVE-2025-32364 * CVE-2025-32365 CVSS scores: * CVE-2025-32364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32364 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32364 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-32365 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32365 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.5 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2025-32364: Fixed a floating point exception. (bsc#1240880) * CVE-2025-32365: Fixed the isOk check in JBIG2Bitmap::combine function in JBIG2Stream.cc. (bsc#1240881) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-1173=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libpoppler-qt5-1-23.01.0-150500.3.17.1 * libpoppler126-23.01.0-150500.3.17.1 * poppler-tools-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-debuginfo-23.01.0-150500.3.17.1 * poppler-debugsource-23.01.0-150500.3.17.1 * libpoppler-glib8-23.01.0-150500.3.17.1 * libpoppler-qt5-devel-23.01.0-150500.3.17.1 * poppler-qt5-debugsource-23.01.0-150500.3.17.1 * libpoppler-qt6-3-debuginfo-23.01.0-150500.3.17.1 *libpoppler-qt5-1-debuginfo-23.01.0-150500.3.17.1 * typelib-1_0-Poppler-0_18-23.01.0-150500.3.17.1 * libpoppler-qt6-devel-23.01.0-150500.3.17.1 * libpoppler126-debuginfo-23.01.0-150500.3.17.1 * poppler-qt6-debugsource-23.01.0-150500.3.17.1 * libpoppler-cpp0-23.01.0-150500.3.17.1 * poppler-tools-23.01.0-150500.3.17.1 * libpoppler-cpp0-debuginfo-23.01.0-150500.3.17.1 * libpoppler-qt6-3-23.01.0-150500.3.17.1 * libpoppler-glib-devel-23.01.0-150500.3.17.1 * libpoppler-devel-23.01.0-150500.3.17.1 * openSUSE Leap 15.5 (x86_64) * libpoppler126-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-qt5-1-32bit-23.01.0-150500.3.17.1 * libpoppler-cpp0-32bit-23.01.0-150500.3.17.1 * libpoppler126-32bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-cpp0-32bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-32bit-23.01.0-150500.3.17.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libpoppler-glib8-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-cpp0-64bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-64bit-23.01.0-150500.3.17.1 * libpoppler-qt5-1-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler-glib8-64bit-23.01.0-150500.3.17.1 * libpoppler126-64bit-23.01.0-150500.3.17.1 * libpoppler-cpp0-64bit-debuginfo-23.01.0-150500.3.17.1 * libpoppler126-64bit-debuginfo-23.01.0-150500.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32364.html * https://www.suse.com/security/cve/CVE-2025-32365.html * https://bugzilla.suse.com/show_bug.cgi?id=1240880 * https://bugzilla.suse.com/show_bug.cgi?id=1240881 . A security patch for Ghostscript resolves several vulnerabilities impacting Fedora installations, categorized with medium severity levels.. poppler update, security patch, openSUSE vulnerabilities. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gifsicle ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0146-1 Rating: important References: #1216403 Cross-References: CVE-2023-46009 CVSS scores: CVE-2023-46009 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gifsicle fixes the following issues: Update to version 1.95: - CVE-2023-46009: Fixed floating point exception vulnerability via resize_stream at src/xform.c (boo#1216403) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-146=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): gifsicle-1.95-bp155.3.6.1 References: https://www.suse.com/security/cve/CVE-2023-46009.html https://bugzilla.suse.com/1216403 . A critical security patch for Gifsicle is out, addressing vulnerabilities in openSUSE. Users must update immediately to safeguard their systems. gifsicle update, openSUSE security, important fix, software patch. . Severity: Important. LinuxSecurity.com Team
Some isses have been found in gst-plugins-base0.10, a package that provides GStreamer plugins from the "base" set. All issues are related to crafted ico-files that could result in an . Package : gst-plugins-base0.10 Version : 0.10.36-2+deb8u2 CVE ID : CVE-2016-9811 CVE-2017-5837 CVE-2017-5844 Some isses have been found in gst-plugins-base0.10, a package that provides GStreamer plugins from the "base" set. All issues are related to crafted ico-files that could result in an out-of-bounds read or crafted video- and ASDF-files that could produce floating point exceptions, which could cause a denial of service. For Debian 8 "Jessie", these problems have been fixed in version 0.10.36-2+deb8u2. We recommend that you upgrade your gst-plugins-base0.10 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Explore the latest patch DLA-2150-2 concerning urgent vulnerabilities in gst-plugins-base0.10 designed for Debian 8.. gst-plugins-base, Debian security, denial of service, software update, floating point exceptions. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.