* bsc#1244471 Affected Products: * Containers Module 15-SP6 * Containers Module 15-SP7 . # Security update for distribution Announcement ID: SUSE-SU-2025:02066-1 Release Date: 2025-06-23T10:49:03Z Rating: important References: * bsc#1244471 Affected Products: * Containers Module 15-SP6 * Containers Module 15-SP7 * openSUSE Leap 15.4 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for distribution fixes the following issues: The package is rebuild with more recent go go1.24, fixing respective security issues (bsc#1244471) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2066=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2066=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2025-2066=1 *Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2025-2066=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2066=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2066=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-2066=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-2066=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2066=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2066=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2066=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2066=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * distribution-registry-2.8.3-150400.9.27.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.27.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.27.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise High Performance Computing LTSS15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.27.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1244471 . SUSE distributions receive a critical security update addressing vulnerabilities in Containers and High Performance Computing components.. SUSE Security Update, Linux Containers Update, High Performance Computing Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1237429 Cross-References: * CVE-2025-26595 . # Security update for libxkbfile Announcement ID: SUSE-SU-2025:0818-1 Release Date: 2025-03-10T13:59:50Z Rating: moderate References: * bsc#1237429 Cross-References: * CVE-2025-26595 CVSS scores: * CVE-2025-26595 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-26595 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2025-26595 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libxkbfile fixes the following issues: * CVE-2025-26595: Fixed buffer overflow in XkbVModMaskText() (bsc#1237429). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-818=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-818=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxkbfile-devel-1.0.8-12.3.1 * libxkbfile1-debuginfo-1.0.8-12.3.1 * libxkbfile1-1.0.8-12.3.1 * libxkbfile-debugsource-1.0.8-12.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libxkbfile1-32bit-1.0.8-12.3.1 * libxkbfile1-debuginfo-32bit-1.0.8-12.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libxkbfile-devel-1.0.8-12.3.1 * libxkbfile1-1.0.8-12.3.1 *libxkbfile-debugsource-1.0.8-12.3.1 * libxkbfile1-debuginfo-1.0.8-12.3.1 * libxkbfile1-32bit-1.0.8-12.3.1 * libxkbfile1-debuginfo-32bit-1.0.8-12.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26595.html * https://bugzilla.suse.com/show_bug.cgi?id=1237429 . Patch addresses vulnerability in libxkbfile impacting SUSE platforms, improving overall system security.. libxkbfile security update, SUSE security advisory, buffer overflow fix, patch instructions, SUSE Linux vulnerabilities. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for podman Announcement ID: SUSE-SU-2025:0786-1 Release Date: 2025-03-05T13:06:45Z Rating: important References: * bsc#1237641 Cross-References: * CVE-2025-27144 CVSS scores: * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for podman fixes the following issues: * CVE-2025-27144: Fixed denial of service in parsing function of embedded library Go JOSE (bsc#1237641) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-786=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-786=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-786=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patchSUSE-SLE-Micro-5.4-2025-786=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-786=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-786=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-786=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-786=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-786=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * podman-remote-4.9.5-150400.4.41.1 * podman-debuginfo-4.9.5-150400.4.41.1 * podmansh-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * openSUSE Leap 15.4 (noarch) * podman-docker-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * podman-docker-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * podman-debuginfo-4.9.5-150400.4.41.1 * podman-remote-4.9.5-150400.4.41.1 * podman-4.9.5-150400.4.41.1 * podman-remote-debuginfo-4.9.5-150400.4.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.41.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27144.html * https://bugzilla.suse.com/show_bug.cgi?id=1237641 . Essential podman patch resolves denial of service vulnerability, providing crucial updates for SUSE variants on designated releases.. Podman Update, SUSE Security Advisory, Denial of Service Fix, Podman Patch, Linux Security. . Severity: Important. LinuxSecurity.com Team
* bsc#1237084 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 . # Security update for ovmf Announcement ID: SUSE-SU-2025:0690-1 Release Date: 2025-02-24T13:06:15Z Rating: important References: * bsc#1237084 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has one security fix can now be installed. ## Description: This update for ovmf fixes the following issues: * PXE boot is failing due to patches applied to fix CVE-2023-45236 and CVE-2023-45237 (bsc#1237084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-690=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-690=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-690=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-690=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-690=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-690=1 * SUSE Linux Enterprise Micro5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-690=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-690=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-690=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-690=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-690=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-690=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Manager Proxy 4.3 (x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Manager Proxy 4.3 (noarch) * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Manager Server 4.3 (x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Manager Server 4.3 (noarch) * qemu-ovmf-x86_64-202202-150400.5.18.1 * openSUSE Leap 15.4 (aarch64 x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * openSUSE Leap 15.4 (noarch) * qemu-ovmf-x86_64-202202-150400.5.18.1 * qemu-ovmf-ia32-202202-150400.5.18.1 * qemu-uefi-aarch32-202202-150400.5.18.1 * qemu-uefi-aarch64-202202-150400.5.18.1 * openSUSE Leap 15.4 (x86_64) * qemu-ovmf-x86_64-debug-202202-150400.5.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 *qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * ovmf-tools-202202-150400.5.18.1 * ovmf-202202-150400.5.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * qemu-uefi-aarch64-202202-150400.5.18.1 * qemu-ovmf-x86_64-202202-150400.5.18.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1237084 . Crucial security patch released for ovmf tackling significant vulnerabilities affecting various SUSE versions, alongside detailed guidelines.. ovmf Security Update, SUSE Linux Patch, openSUSE Security Advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1220110 * bsc#1225637 * bsc#1237040 Cross-References: . # Security update for openssh Announcement ID: SUSE-SU-2025:0659-1 Release Date: 2025-02-23T12:03:56Z Rating: moderate References: * bsc#1220110 * bsc#1225637 * bsc#1237040 Cross-References: * CVE-2025-26465 CVSS scores: * CVE-2025-26465 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-26465 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for openssh fixes the following issues: * CVE-2025-26465: Fixed a MitM attack against OpenSSH's VerifyHostKeyDNS- enabled client (bsc#1237040). * Add a s390 specific ioctl for ECC hardware support (bsc#1225637): * for migration to openssh 8.4: write active/enabled switch over files only if not yet present (bsc#1220110) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-659=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-659=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openssh-fips-7.2p2-81.26.1 * openssh-7.2p2-81.26.1 * openssh-askpass-gnome-debuginfo-7.2p2-81.26.1 * openssh-debugsource-7.2p2-81.26.1 * openssh-debuginfo-7.2p2-81.26.1 * openssh-helpers-debuginfo-7.2p2-81.26.1 *openssh-helpers-7.2p2-81.26.1 * openssh-askpass-gnome-7.2p2-81.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * openssh-fips-7.2p2-81.26.1 * openssh-7.2p2-81.26.1 * openssh-askpass-gnome-debuginfo-7.2p2-81.26.1 * openssh-debugsource-7.2p2-81.26.1 * openssh-debuginfo-7.2p2-81.26.1 * openssh-helpers-debuginfo-7.2p2-81.26.1 * openssh-helpers-7.2p2-81.26.1 * openssh-askpass-gnome-7.2p2-81.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26465.html * https://bugzilla.suse.com/show_bug.cgi?id=1220110 * https://bugzilla.suse.com/show_bug.cgi?id=1225637 * https://bugzilla.suse.com/show_bug.cgi?id=1237040 . SUSE issues security bulletin SUSE-SU-2025:0660-1 for openssl addressing a significant flaw in key management that may lead to information leakage.. openssh security update, SUSE advisory, MitM attack fix, moderate security patch, SUSE Linux updates. . LinuxSecurity.com Team
* bsc#1237084 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 . # Security update for ovmf Announcement ID: SUSE-SU-2025:0609-1 Release Date: 2025-02-21T10:33:48Z Rating: important References: * bsc#1237084 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one security fix can now be installed. ## Description: This update for ovmf fixes the following issues: * PXE boot is failing due to patches applied to fix CVE-2023-45236 and CVE-2023-45237 (bsc#1237084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-609=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-609=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-609=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-609=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-609=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-609=1 ## Package List: * openSUSE Leap 15.5 (aarch64 x86_64) * ovmf-tools-202208-150500.6.9.1 * ovmf-202208-150500.6.9.1 * openSUSE Leap 15.5 (noarch) * qemu-uefi-aarch32-202208-150500.6.9.1 *qemu-ovmf-ia32-202208-150500.6.9.1 * qemu-uefi-aarch64-202208-150500.6.9.1 * qemu-ovmf-x86_64-202208-150500.6.9.1 * openSUSE Leap 15.5 (x86_64) * qemu-ovmf-x86_64-debug-202208-150500.6.9.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * qemu-uefi-aarch64-202208-150500.6.9.1 * qemu-ovmf-x86_64-202208-150500.6.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * ovmf-tools-202208-150500.6.9.1 * ovmf-202208-150500.6.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * qemu-uefi-aarch64-202208-150500.6.9.1 * qemu-ovmf-x86_64-202208-150500.6.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * ovmf-tools-202208-150500.6.9.1 * ovmf-202208-150500.6.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * qemu-uefi-aarch64-202208-150500.6.9.1 * qemu-ovmf-x86_64-202208-150500.6.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * ovmf-tools-202208-150500.6.9.1 * ovmf-202208-150500.6.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * qemu-uefi-aarch64-202208-150500.6.9.1 * qemu-ovmf-x86_64-202208-150500.6.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ovmf-tools-202208-150500.6.9.1 * ovmf-202208-150500.6.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * qemu-ovmf-x86_64-202208-150500.6.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1237084 . Critical security enhancements for ovmf affecting various SUSE releases, detailing significant vulnerabilities and installation instructions.. ovmf security update, high performance computing patch, SUSE update guidance. . Severity: Important. LinuxSecurity.com Team
* bsc#1234068 Cross-References: * CVE-2024-11053 . # Security update for curl Announcement ID: SUSE-SU-2024:4359-1 Release Date: 2024-12-17T13:19:51Z Rating: moderate References: * bsc#1234068 Cross-References: * CVE-2024-11053 CVSS scores: * CVE-2024-11053 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-11053 ( NVD ): 3.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2024-11053: Fixed password leak in curl used for the first host to the followed-to host under certain circumstances (bsc#1234068) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4359=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4359=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-4359=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-4359=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-4359=1 * openSUSE Leap Micro 5.5 zypper in -t patch openSUSE-Leap-Micro-5.5-2024-4359=1 * openSUSELeap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4359=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2024-4359=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2024-4359=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2024-4359=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2024-4359=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4359=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4359=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * libcurl-devel-8.0.1-150400.5.59.1 * Basesystem Module 15-SP5 (x86_64) * libcurl4-32bit-debuginfo-8.0.1-150400.5.59.1 * libcurl4-32bit-8.0.1-150400.5.59.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * libcurl-devel-8.0.1-150400.5.59.1 * openSUSE Leap 15.4 (x86_64) * libcurl-devel-32bit-8.0.1-150400.5.59.1 * libcurl4-32bit-debuginfo-8.0.1-150400.5.59.1 * libcurl4-32bit-8.0.1-150400.5.59.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libcurl4-64bit-debuginfo-8.0.1-150400.5.59.1 * libcurl4-64bit-8.0.1-150400.5.59.1 * libcurl-devel-64bit-8.0.1-150400.5.59.1 * openSUSE Leap Micro 5.5 (aarch64 s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * libcurl-devel-8.0.1-150400.5.59.1 * openSUSE Leap 15.5 (x86_64) * libcurl-devel-32bit-8.0.1-150400.5.59.1 * libcurl4-32bit-debuginfo-8.0.1-150400.5.59.1 * libcurl4-32bit-8.0.1-150400.5.59.1 * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 * curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * curl-debuginfo-8.0.1-150400.5.59.1 *curl-8.0.1-150400.5.59.1 * curl-debugsource-8.0.1-150400.5.59.1 * libcurl4-debuginfo-8.0.1-150400.5.59.1 * libcurl4-8.0.1-150400.5.59.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11053.html * https://bugzilla.suse.com/show_bug.cgi?id=1234068 . SUSE Linux has issued a vital update for curl to address a vulnerability related to password exposure, urging users to apply patches promptly for better security. curl security, SUSE updates, password leak fix, SUSE Linux, curl vulnerability. . LinuxSecurity.com Team
* bsc#1229122 Affected Products: * Containers Module 15-SP5 * Containers Module 15-SP6 . # Security update for kubernetes1.27 Announcement ID: SUSE-SU-2024:3455-1 Rating: important References: * bsc#1229122 Affected Products: * Containers Module 15-SP5 * Containers Module 15-SP6 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update of kubernetes1.27 fixes the following issues: * rebuild the package with the current go 1.23 security release (bsc#1229122). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-3455=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3455=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3455=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2024-3455=1 * Containers Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Containers-15-SP6-2024-3455=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patchSUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3455=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3455=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3455=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3455=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-kubelet-1.27.16-150400.9.12.1 * kubernetes1.27-scheduler-1.27.16-150400.9.12.1 * kubernetes1.27-kubelet-common-1.27.16-150400.9.12.1 * kubernetes1.27-kubeadm-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * kubernetes1.27-apiserver-1.27.16-150400.9.12.1 * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-controller-manager-1.27.16-150400.9.12.1 * kubernetes1.27-proxy-1.27.16-150400.9.12.1 * openSUSE Leap 15.4 (noarch) * kubernetes1.27-client-fish-completion-1.27.16-150400.9.12.1 * kubernetes1.27-client-bash-completion-1.27.16-150400.9.12.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-kubelet-1.27.16-150400.9.12.1 * kubernetes1.27-scheduler-1.27.16-150400.9.12.1 * kubernetes1.27-kubelet-common-1.27.16-150400.9.12.1 * kubernetes1.27-kubeadm-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * kubernetes1.27-apiserver-1.27.16-150400.9.12.1 * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-controller-manager-1.27.16-150400.9.12.1 * kubernetes1.27-proxy-1.27.16-150400.9.12.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.27-client-fish-completion-1.27.16-150400.9.12.1 * kubernetes1.27-client-bash-completion-1.27.16-150400.9.12.1 * Containers Module15-SP5 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * Containers Module 15-SP6 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kubernetes1.27-client-1.27.16-150400.9.12.1 * kubernetes1.27-client-common-1.27.16-150400.9.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1229122 . Kubernetes 1.28 security patch for Fedora Linux & CentOS introduces critical improvements pertinent to various components and releases.. SUSE Linux,kubernetes update,containers module,security fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.