An update that solves one vulnerability can now be installed.. # gdm-48.0-10.1 on GA media Announcement ID: openSUSE-SU-2025:15219-1 Rating: moderate Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the gdm-48.0-10.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * gdm 48.0-10.1 * gdm-branding-upstream 48.0-10.1 * gdm-devel 48.0-10.1 * gdm-lang 48.0-10.1 * gdm-schema 48.0-10.1 * gdm-systemd 48.0-10.1 * gdm-xdm-integration 48.0-10.1 * gdmflexiserver 48.0-10.1 * libgdm1 48.0-10.1 * typelib-1_0-Gdm-1_0 48.0-10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html . A recent patch for gdm in openSUSE Tumbleweed mitigates a moderate vulnerability related to CVE-2025-6018. Discover further details here.. openSUSE, gdm security, CVE-2025-6018, Linux updates, moderate vulnerability. . LinuxSecurity.com Team
* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for gdm Announcement ID: SUSE-SU-2025:02015-1 Release Date: 2025-06-19T07:14:13Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: pam.d: removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2015=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2015=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2015=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2015=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * gdm-3.34.1-150200.8.26.1 * typelib-1_0-Gdm-1_0-3.34.1-150200.8.26.1 * libgdm1-debuginfo-3.34.1-150200.8.26.1 * gdm-debugsource-3.34.1-150200.8.26.1 * libgdm1-3.34.1-150200.8.26.1 * gdm-debuginfo-3.34.1-150200.8.26.1 *gdm-devel-3.34.1-150200.8.26.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * gdmflexiserver-3.34.1-150200.8.26.1 * gdm-systemd-3.34.1-150200.8.26.1 * gdm-lang-3.34.1-150200.8.26.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * gdm-3.34.1-150200.8.26.1 * typelib-1_0-Gdm-1_0-3.34.1-150200.8.26.1 * libgdm1-debuginfo-3.34.1-150200.8.26.1 * gdm-debugsource-3.34.1-150200.8.26.1 * libgdm1-3.34.1-150200.8.26.1 * gdm-debuginfo-3.34.1-150200.8.26.1 * gdm-devel-3.34.1-150200.8.26.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * gdmflexiserver-3.34.1-150200.8.26.1 * gdm-systemd-3.34.1-150200.8.26.1 * gdm-lang-3.34.1-150200.8.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * gdm-3.34.1-150200.8.26.1 * typelib-1_0-Gdm-1_0-3.34.1-150200.8.26.1 * libgdm1-debuginfo-3.34.1-150200.8.26.1 * gdm-debugsource-3.34.1-150200.8.26.1 * libgdm1-3.34.1-150200.8.26.1 * gdm-debuginfo-3.34.1-150200.8.26.1 * gdm-devel-3.34.1-150200.8.26.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * gdmflexiserver-3.34.1-150200.8.26.1 * gdm-systemd-3.34.1-150200.8.26.1 * gdm-lang-3.34.1-150200.8.26.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * gdm-3.34.1-150200.8.26.1 * typelib-1_0-Gdm-1_0-3.34.1-150200.8.26.1 * libgdm1-debuginfo-3.34.1-150200.8.26.1 * gdm-debugsource-3.34.1-150200.8.26.1 * libgdm1-3.34.1-150200.8.26.1 * gdm-debuginfo-3.34.1-150200.8.26.1 * gdm-devel-3.34.1-150200.8.26.1 * SUSE Enterprise Storage 7.1 (noarch) * gdmflexiserver-3.34.1-150200.8.26.1 * gdm-systemd-3.34.1-150200.8.26.1 * gdm-lang-3.34.1-150200.8.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . An important SUSE patch to address CVE-2025-6018 in gdm enhances system security for affected users.. SUSE, gdm, security, update,CVE-2025-6018. . Severity: Important. LinuxSecurity.com Team
* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for gdm Announcement ID: SUSE-SU-2025:02002-1 Release Date: 2025-06-18T11:21:43Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: pam.d: removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-2002=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2002=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gdm-3.10.0.1-54.23.1 * libgdm1-3.10.0.1-54.23.1 * libgdm1-debuginfo-3.10.0.1-54.23.1 * gdm-debuginfo-3.10.0.1-54.23.1 * gdm-debugsource-3.10.0.1-54.23.1 * gdm-devel-3.10.0.1-54.23.1 * typelib-1_0-Gdm-1_0-3.10.0.1-54.23.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gdmflexiserver-3.10.0.1-54.23.1 * gdm-lang-3.10.0.1-54.23.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gdm-3.10.0.1-54.23.1 * libgdm1-3.10.0.1-54.23.1 *libgdm1-debuginfo-3.10.0.1-54.23.1 * gdm-debuginfo-3.10.0.1-54.23.1 * gdm-debugsource-3.10.0.1-54.23.1 * gdm-devel-3.10.0.1-54.23.1 * typelib-1_0-Gdm-1_0-3.10.0.1-54.23.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gdmflexiserver-3.10.0.1-54.23.1 * gdm-lang-3.10.0.1-54.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Essential Debian patch for gdm resolves CVE-2025-6019. Make certain your servers are up-to-date with the newest protections.. SUSE, gdm, security update, authentication. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gdm Announcement ID: SUSE-SU-2025:02003-1 Release Date: 2025-06-18T11:21:56Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-2003=1 openSUSE-SLE-15.6-2025-2003=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-2003=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libgdm1-debuginfo-45.0.1-150600.6.8.1 * gdm-devel-45.0.1-150600.6.8.1 * gdm-debuginfo-45.0.1-150600.6.8.1 * typelib-1_0-Gdm-1_0-45.0.1-150600.6.8.1 * libgdm1-45.0.1-150600.6.8.1 * gdm-debugsource-45.0.1-150600.6.8.1 * gdm-45.0.1-150600.6.8.1 * openSUSE Leap 15.6 (noarch) * gdm-systemd-45.0.1-150600.6.8.1 * gdm-lang-45.0.1-150600.6.8.1 * gdm-branding-upstream-45.0.1-150600.6.8.1 * gdmflexiserver-45.0.1-150600.6.8.1 * gdm-schema-45.0.1-150600.6.8.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) *libgdm1-debuginfo-45.0.1-150600.6.8.1 * gdm-devel-45.0.1-150600.6.8.1 * gdm-debuginfo-45.0.1-150600.6.8.1 * typelib-1_0-Gdm-1_0-45.0.1-150600.6.8.1 * libgdm1-45.0.1-150600.6.8.1 * gdm-debugsource-45.0.1-150600.6.8.1 * gdm-45.0.1-150600.6.8.1 * Desktop Applications Module 15-SP6 (noarch) * gdm-schema-45.0.1-150600.6.8.1 * gdm-systemd-45.0.1-150600.6.8.1 * gdmflexiserver-45.0.1-150600.6.8.1 * gdm-lang-45.0.1-150600.6.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Essential patch for gdm on openSUSE released, impacting several versions, tackling a major security flaw.. openSUSE security, gdm update, authentication risks, security patch, CVE-2025-6018. . Severity: Important. LinuxSecurity.com Team
* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for gdm Announcement ID: SUSE-SU-2025:02003-1 Release Date: 2025-06-18T11:21:56Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-2003=1 openSUSE-SLE-15.6-2025-2003=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-2003=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libgdm1-debuginfo-45.0.1-150600.6.8.1 * gdm-devel-45.0.1-150600.6.8.1 * gdm-debuginfo-45.0.1-150600.6.8.1 * typelib-1_0-Gdm-1_0-45.0.1-150600.6.8.1 * libgdm1-45.0.1-150600.6.8.1 * gdm-debugsource-45.0.1-150600.6.8.1 * gdm-45.0.1-150600.6.8.1 * openSUSE Leap 15.6 (noarch) * gdm-systemd-45.0.1-150600.6.8.1 * gdm-lang-45.0.1-150600.6.8.1 * gdm-branding-upstream-45.0.1-150600.6.8.1 * gdmflexiserver-45.0.1-150600.6.8.1 * gdm-schema-45.0.1-150600.6.8.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) *libgdm1-debuginfo-45.0.1-150600.6.8.1 * gdm-devel-45.0.1-150600.6.8.1 * gdm-debuginfo-45.0.1-150600.6.8.1 * typelib-1_0-Gdm-1_0-45.0.1-150600.6.8.1 * libgdm1-45.0.1-150600.6.8.1 * gdm-debugsource-45.0.1-150600.6.8.1 * gdm-45.0.1-150600.6.8.1 * Desktop Applications Module 15-SP6 (noarch) * gdm-schema-45.0.1-150600.6.8.1 * gdm-systemd-45.0.1-150600.6.8.1 * gdmflexiserver-45.0.1-150600.6.8.1 * gdm-lang-45.0.1-150600.6.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Important notice regarding gdm patch resolves CVE-2025-6018 on SUSE Linux platforms. Prompt application is essential to minimize vulnerability.. SUSE gdm update important security issue CVE-2025-6018. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for gdm Announcement ID: SUSE-SU-2025:02004-1 Release Date: 2025-06-18T11:22:29Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2004=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patchSUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2004=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2004=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2004=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * openSUSE Leap 15.4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-branding-upstream-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 *libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 *gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Significant advancement for gdm on openSUSE, tackling CVE-2025-6018 with essential rectification guidelines.. openSUSE,gdm,security update,auth stack issue. . Severity: Important. LinuxSecurity.com Team
* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for gdm Announcement ID: SUSE-SU-2025:02004-1 Release Date: 2025-06-18T11:22:29Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2004=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patchSUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2004=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2004=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2004=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2004=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * openSUSE Leap 15.4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-branding-upstream-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 *libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 *gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * typelib-1_0-Gdm-1_0-41.3-150400.4.14.1 * gdm-debugsource-41.3-150400.4.14.1 * gdm-41.3-150400.4.14.1 * libgdm1-debuginfo-41.3-150400.4.14.1 * gdm-debuginfo-41.3-150400.4.14.1 * gdm-devel-41.3-150400.4.14.1 * libgdm1-41.3-150400.4.14.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gdm-lang-41.3-150400.4.14.1 * gdm-systemd-41.3-150400.4.14.1 * gdm-schema-41.3-150400.4.14.1 * gdmflexiserver-41.3-150400.4.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . Important patch released for gdm in SUSE deals with security flaw CVE-2025-6018 impacting multiple distributions.. SUSE gdm update CVE-2025-6018 security patch installation. . Severity: Important. LinuxSecurity.com Team
* bsc#1243226 Cross-References: * CVE-2025-6018 . # Security update for gdm Announcement ID: SUSE-SU-2025:02005-1 Release Date: 2025-06-18T11:22:45Z Rating: important References: * bsc#1243226 Cross-References: * CVE-2025-6018 CVSS scores: * CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gdm fixes the following issues: * CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2005=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgdm1-debuginfo-45.0.1-150700.12.5.1 * typelib-1_0-Gdm-1_0-45.0.1-150700.12.5.1 * gdm-debuginfo-45.0.1-150700.12.5.1 * gdm-devel-45.0.1-150700.12.5.1 * gdm-debugsource-45.0.1-150700.12.5.1 * libgdm1-45.0.1-150700.12.5.1 * gdm-45.0.1-150700.12.5.1 * Desktop Applications Module 15-SP7 (noarch) * gdmflexiserver-45.0.1-150700.12.5.1 * gdm-systemd-45.0.1-150700.12.5.1 * gdm-lang-45.0.1-150700.12.5.1 * gdm-schema-45.0.1-150700.12.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6018.html * https://bugzilla.suse.com/show_bug.cgi?id=1243226 . A critical security patch for gdm tackles a flaw, improving desktop application safety throughoutSUSE environments.. SUSE Security Update, gdm Security Patch, Linux Desktop Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.