Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 50 articles for you...
89

Fedora 41: gh 2.79.0 Important Info Leak Advisory FEDORA-2025-24e111e6f1

Update to 2.79.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-24e111e6f1 2025-09-19 01:15:50.104017+00:00 -------------------------------------------------------------------------------- Name : gh Product : Fedora 41 Version : 2.79.0 Release : 1.fc41 URL : https://github.com/cli/cli Summary : GitHub's official command line tool Description : A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. -------------------------------------------------------------------------------- Update Information: Update to 2.79.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 9 2025 Packit - 2.79.0-1 - Update to 2.79.0 upstream release - Resolves: rhbz#2385309 * Tue Sep 9 2025 Mikel Olasagasti Uranga - 2.76.1-5 - Integrate Packit with Go Vendor Tools * Fri Aug 15 2025 Maxwell G - 2.76.1-4 - Rebuild for golang-1.25.0 * Fri Aug 15 2025 Maxwell G - 2.76.1-3 - Revert "Rebuild for golang-1.25.0" * Fri Aug 15 2025 Maxwell G - 2.76.1-2 - Rebuild for golang-1.25.0 * Tue Jul 29 2025 Mikel Olasagasti Uranga - 2.76.1-1 - Update to 2.76.1 - Closes rhbz#2380061 * Wed Jul 23 2025 Fedora Release Engineering - 2.75.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Wed Jul 9 2025 Mikel Olasagasti Uranga - 2.75.0-1 - Update to 2.75.0 - Closes rhbz#2371496 rhbz#2375605 rhbz#2375620 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2384115 - gh: Host Header Injection in github.com/go-chi/chi [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384115 [ 2 ] Bug #2384138 - gh: go-viper information leak [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384138 [ 3 ] Bug #2390842 - gh: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2390842 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-24e111e6f1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Upgrading to gh 2.79.0 on Fedora 41 resolves significant security vulnerabilities and improves terminal functionalities.. Fedora 41, GitHub CLI, security advisory, command line tool. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 19, 2025 Important Fedora
202

openSUSE 2025:01864-1 important: libsoup2 denial of service issues

An update that solves eight vulnerabilities can now be installed.. # Security update for libsoup2 Announcement ID: SUSE-SU-2025:01864-1 Release Date: 2025-06-10T14:05:02Z Rating: important References: * bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 * bsc#1241263 * bsc#1243332 * bsc#1243423 Cross-References: * CVE-2025-32906 * CVE-2025-32909 * CVE-2025-32910 * CVE-2025-32911 * CVE-2025-32912 * CVE-2025-32913 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-32906 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-32906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32909 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32909 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32910 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32910 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32910 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32911 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32911 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-32912 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32912 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-32906: Fixed out of bounds reads in soup_headers_parse_request() (bsc#1241263) * CVE-2025-32909: Fixed NULL pointer dereference in the sniff_mp4 function in soup-content-sniffer.c (bsc#1241226) * CVE-2025-32910: Fixed null pointer deference on client when server omits the realm parameter in an Unauthorized response with Digest authentication (bsc#1241252) * CVE-2025-32911: Fixed double free on soup_message_headers_get_content_disposition() via "params".(bsc#1241238) * CVE-2025-32912: Fixed NULL pointer dereference in SoupAuthDigest (bsc#1241214) * CVE-2025-32913: Fixed NULL pointer dereference in soup_message_headers_get_content_disposition (bsc#1241162) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-1864=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-1864=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1864=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1864=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1864=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1864=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1864=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-1864=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1864=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1864=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1864=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1864=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1864=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1864=1 * SUSE Linux Enterprise Server for SAPApplications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1864=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1864=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-1864=1 ## Package List: * SUSE Manager Retail Branch Server 4.3 (x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Manager Server 4.3 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * openSUSE Leap 15.4 (x86_64) * libsoup2-devel-32bit-2.74.2-150400.3.9.1 * libsoup-2_4-1-32bit-debuginfo-2.74.2-150400.3.9.1 * libsoup-2_4-1-32bit-2.74.2-150400.3.9.1 * openSUSE Leap 15.4 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoup-2_4-1-64bit-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-64bit-2.74.2-150400.3.9.1 * libsoup-2_4-1-64bit-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Micro 5.3 (aarch64s390x x86_64) * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSELinux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 * SUSEManager Proxy 4.3 (x86_64) * libsoup-2_4-1-debuginfo-2.74.2-150400.3.9.1 * libsoup2-devel-2.74.2-150400.3.9.1 * libsoup-2_4-1-2.74.2-150400.3.9.1 * libsoup2-debugsource-2.74.2-150400.3.9.1 * typelib-1_0-Soup-2_4-2.74.2-150400.3.9.1 * SUSE Manager Proxy 4.3 (noarch) * libsoup2-lang-2.74.2-150400.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32906.html * https://www.suse.com/security/cve/CVE-2025-32909.html * https://www.suse.com/security/cve/CVE-2025-32910.html * https://www.suse.com/security/cve/CVE-2025-32911.html * https://www.suse.com/security/cve/CVE-2025-32912.html * https://www.suse.com/security/cve/CVE-2025-32913.html * https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1241162 * https://bugzilla.suse.com/show_bug.cgi?id=1241214 * https://bugzilla.suse.com/show_bug.cgi?id=1241226 * https://bugzilla.suse.com/show_bug.cgi?id=1241238 * https://bugzilla.suse.com/show_bug.cgi?id=1241252 * https://bugzilla.suse.com/show_bug.cgi?id=1241263 * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . Crucial patch for libsoup tackling various vulnerabilities in openSUSE, improving overall system robustness and protection.. libsoup update, openSUSE security, SUSE vulnerabilities, system administration, package management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2025 Important OpenSUSE
100

SUSE Linux Enterprise: 2025:01817-1 important: libsoup DoS fixes

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References: . # Security update for libsoup Announcement ID: SUSE-SU-2025:01817-1 Release Date: 2025-06-05T06:52:43Z Rating: important References: * bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References: * CVE-2025-4476 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-4476 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-4476 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-4476 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update forlibsoup fixes the following issues: * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4476: Fixed NULL pointer dereference may lead to denial of service (bsc#1243422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1817=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1817=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1817=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-1817=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-1817=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-1817=1 ## Package List: *openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * openSUSE Leap 15.4 (x86_64) * libsoup-3_0-0-32bit-debuginfo-3.0.4-150400.3.10.1 * libsoup-3_0-0-32bit-3.0.4-150400.3.10.1 * libsoup-devel-32bit-3.0.4-150400.3.10.1 * openSUSE Leap 15.4 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoup-devel-64bit-3.0.4-150400.3.10.1 * libsoup-3_0-0-64bit-3.0.4-150400.3.10.1 * libsoup-3_0-0-64bit-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15SP5 (aarch64 x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Manager Proxy 4.3 (x86_64) *typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Manager Proxy 4.3 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * typelib-1_0-Soup-3_0-3.0.4-150400.3.10.1 * libsoup-debugsource-3.0.4-150400.3.10.1 * libsoup-devel-3.0.4-150400.3.10.1 * libsoup-3_0-0-3.0.4-150400.3.10.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.10.1 * SUSE Manager Server 4.3 (noarch) * libsoup-lang-3.0.4-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4476.html * https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243422 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . SUSE patch resolves significant libsoup vulnerabilities, tackling both denial of service and information exposure risks.. libsoup Security Update, SUSE Linux Update, Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 05, 2025 Important SuSE
100

SUSE 15 SP6 & SP7: 2025:01812-1 important: libsoup denial of service

* bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References: . # Security update for libsoup Announcement ID: SUSE-SU-2025:01812-1 Release Date: 2025-06-04T10:12:19Z Rating: important References: * bsc#1243332 * bsc#1243422 * bsc#1243423 Cross-References: * CVE-2025-4476 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-4476 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-4476 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-4476 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4476: Fixed NULL pointer dereference may lead to denial of service (bsc#1243422) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1812=1 openSUSE-SLE-15.6-2025-1812=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1812=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-1812=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.10.1 * libsoup-3_0-0-3.4.4-150600.3.10.1 * libsoup-debugsource-3.4.4-150600.3.10.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.10.1 * libsoup-devel-3.4.4-150600.3.10.1 * openSUSE Leap 15.6 (x86_64) * libsoup-devel-32bit-3.4.4-150600.3.10.1 * libsoup-3_0-0-32bit-3.4.4-150600.3.10.1 * libsoup-3_0-0-32bit-debuginfo-3.4.4-150600.3.10.1 * openSUSE Leap 15.6 (noarch) * libsoup-lang-3.4.4-150600.3.10.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-devel-64bit-3.4.4-150600.3.10.1 * libsoup-3_0-0-64bit-debuginfo-3.4.4-150600.3.10.1 * libsoup-3_0-0-64bit-3.4.4-150600.3.10.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.10.1 * libsoup-3_0-0-3.4.4-150600.3.10.1 * libsoup-debugsource-3.4.4-150600.3.10.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.10.1 * libsoup-devel-3.4.4-150600.3.10.1 * Basesystem Module 15-SP6 (noarch) * libsoup-lang-3.4.4-150600.3.10.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.10.1 * libsoup-3_0-0-3.4.4-150600.3.10.1 * libsoup-debugsource-3.4.4-150600.3.10.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.10.1 * libsoup-devel-3.4.4-150600.3.10.1 * Basesystem Module 15-SP7 (noarch) * libsoup-lang-3.4.4-150600.3.10.1 ## References: *https://www.suse.com/security/cve/CVE-2025-4476.html * https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243422 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . The latest update for libsoup addresses critical vulnerabilities, effectively mitigating risks associated with service disruptions and data exposure.. libsoup vulnerabilities, SUSE security, important libsoup update, denial of service fix, info leak resolution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important SuSE
100

SUSE Linux Micro 6.0: 2025:20122-1 critical: rsync security update

* bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 . # Security update for rsync Announcement ID: SUSE-SU-2025:20122-1 Release Date: 2025-02-04T08:59:16Z Rating: critical References: * bsc#1234100 * bsc#1234101 * bsc#1234102 * bsc#1234103 * bsc#1234104 * bsc#1235475 Cross-References: * CVE-2024-12084 * CVE-2024-12085 * CVE-2024-12086 * CVE-2024-12087 * CVE-2024-12088 * CVE-2024-12747 CVSS scores: * CVE-2024-12084 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12084 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-12085 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12085 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-12085 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-12086 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-12086 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-12086 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2024-12087 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-12087 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-12087 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-12088 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12088 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2024-12747 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2024-12747 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2024-12747 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: *SUSE Linux Micro 6.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for rsync fixes the following issues: * CVE-2024-12084: Fixed Heap Buffer Overflow in Checksum Parsing (bsc#1234100). * CVE-2024-12085: Fixed Info Leak via uninitialized Stack contents defeating ASLR (bsc#1234101). * CVE-2024-12086: Fixed server leaking arbitrary client files (bsc#1234102). * CVE-2024-12087: Fixed server use of symbolic links to make client write files outside of destination directory (bsc#1234103). * CVE-2024-12088: Fixed --safe-links bypass (bsc#1234104). * CVE-2024-12747: Fixed Race Condition in rsync Handling Symbolic Links (bsc#1235475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-203=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * rsync-debuginfo-3.2.7-4.1 * rsync-3.2.7-4.1 * rsync-debugsource-3.2.7-4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12084.html * https://www.suse.com/security/cve/CVE-2024-12085.html * https://www.suse.com/security/cve/CVE-2024-12086.html * https://www.suse.com/security/cve/CVE-2024-12087.html * https://www.suse.com/security/cve/CVE-2024-12088.html * https://www.suse.com/security/cve/CVE-2024-12747.html * https://bugzilla.suse.com/show_bug.cgi?id=1234100 * https://bugzilla.suse.com/show_bug.cgi?id=1234101 * https://bugzilla.suse.com/show_bug.cgi?id=1234102 * https://bugzilla.suse.com/show_bug.cgi?id=1234103 * https://bugzilla.suse.com/show_bug.cgi?id=1234104 * https://bugzilla.suse.com/show_bug.cgi?id=1235475 . Important SUSE patch for rsync fixes several vulnerabilities, featuring a buffer overflow and a data exposure. Update your system immediately!. rsync update,SUSE critical,security fix,bufferoverflow,info leak. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Critical SuSE
202

openSUSE: 2025:01802-1 important: libsoup2 denial of service

An update that solves eight vulnerabilities can now be installed.. # Security update for libsoup2 Announcement ID: SUSE-SU-2025:01802-1 Release Date: 2025-06-03T01:15:23Z Rating: important References: * bsc#1241162 * bsc#1241214 * bsc#1241226 * bsc#1241238 * bsc#1241252 * bsc#1241263 * bsc#1243332 * bsc#1243423 Cross-References: * CVE-2025-32906 * CVE-2025-32909 * CVE-2025-32910 * CVE-2025-32911 * CVE-2025-32912 * CVE-2025-32913 * CVE-2025-4948 * CVE-2025-4969 CVSS scores: * CVE-2025-32906 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-32906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32909 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-32909 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-32909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-32910 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32910 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32910 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32911 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-32911 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-32912 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32912 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-32913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-4948 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-4969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2025-4969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2025-4969 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2025-4948: Fixed integer underflow in soup_multipart_new_from_message() leading to denial of service (bsc#1243332) * CVE-2025-4969: Fixed off-by-one out-of-bounds read may lead to infoleak (bsc#1243423) * CVE-2025-32906: Fixed out of bounds reads in soup_headers_parse_request() (bsc#1241263) * CVE-2025-32909: Fixed NULL pointer dereference in the sniff_mp4 function in soup-content-sniffer.c (bsc#1241226) * CVE-2025-32910: Fixed null pointer deference on client when server omits the realm parameter in an Unauthorized response with Digest authentication (bsc#1241252) * CVE-2025-32911: Fixed double free on soup_message_headers_get_content_disposition() via "params". (bsc#1241238) * CVE-2025-32912: Fixed NULL pointer dereference in SoupAuthDigest (bsc#1241214) * CVE-2025-32913: Fixed NULL pointer dereference in soup_message_headers_get_content_disposition (bsc#1241162) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1802=1 SUSE-2025-1802=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1802=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-1802=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (x86_64) * libsoup2-devel-32bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-32bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-32bit-debuginfo-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-2_4-1-64bit-debuginfo-2.74.3-150600.4.9.1 * libsoup2-devel-64bit-2.74.3-150600.4.9.1 * libsoup-2_4-1-64bit-2.74.3-150600.4.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * Basesystem Module 15-SP6 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150600.4.9.1 * libsoup-2_4-1-2.74.3-150600.4.9.1 * libsoup2-debugsource-2.74.3-150600.4.9.1 * libsoup2-devel-2.74.3-150600.4.9.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.9.1 * Basesystem Module 15-SP7 (noarch) * libsoup2-lang-2.74.3-150600.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-32906.html * https://www.suse.com/security/cve/CVE-2025-32909.html * https://www.suse.com/security/cve/CVE-2025-32910.html * https://www.suse.com/security/cve/CVE-2025-32911.html * https://www.suse.com/security/cve/CVE-2025-32912.html * https://www.suse.com/security/cve/CVE-2025-32913.html *https://www.suse.com/security/cve/CVE-2025-4948.html * https://www.suse.com/security/cve/CVE-2025-4969.html * https://bugzilla.suse.com/show_bug.cgi?id=1241162 * https://bugzilla.suse.com/show_bug.cgi?id=1241214 * https://bugzilla.suse.com/show_bug.cgi?id=1241226 * https://bugzilla.suse.com/show_bug.cgi?id=1241238 * https://bugzilla.suse.com/show_bug.cgi?id=1241252 * https://bugzilla.suse.com/show_bug.cgi?id=1241263 * https://bugzilla.suse.com/show_bug.cgi?id=1243332 * https://bugzilla.suse.com/show_bug.cgi?id=1243423 . A crucial patch for libsoup in openSUSE tackles severe vulnerabilities and various flaws, providing necessary resolutions.. libsoup update, openSUSE security, important fixes, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2025 Important OpenSUSE
217

Oracle Linux 8 ELSA-2025-0325 critical: rsync info leak fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0325 http://linux.oracle.com/errata/ELSA-2025-0325.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: rsync-3.1.3-20.el8_10.x86_64.rpm rsync-daemon-3.1.3-20.el8_10.noarch.rpm aarch64: rsync-3.1.3-20.el8_10.aarch64.rpm rsync-daemon-3.1.3-20.el8_10.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//rsync-3.1.3-20.el8_10.src.rpm Related CVEs: CVE-2024-12085 Description of changes: [3.1.3-20] - Resolves: RHEL-70157 - Info Leak via Uninitialized Stack Contents _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Oracle Linux Security Advisory ELSA-2025-0325 provides important updates for the rsync utility, targeting vulnerabilities associated with data exposure.. Oracle Linux Update, rsync Security, rpm Advisory, Oracle Security Fix, Linux Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 17, 2025 Critical Oracle
172

Ubuntu 23.10 USN-6812-1 Critical: OpenJDK 17 DoS and Info Leak

Several security issues were fixed in OpenJDK 17.. ========================================================================== Ubuntu Security Notice USN-6812-1 June 06, 2024 openjdk-17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenJDK 17. Software Description: - openjdk-17: Open Source Java implementation Details: It was discovered that the Hotspot component of OpenJDK 17 incorrectly handled certain exceptions with specially crafted long messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-21011) It was discovered that OpenJDK 17 incorrectly performed reverse DNS query under certain circumstances in the Networking/HTTP client component. An attacker could possibly use this issue to obtain sensitive information. (CVE-2024-21012) Vladimir Kondratyev discovered that the Hotspot component of OpenJDK 17 incorrectly handled address offset calculations in the C1 compiler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-21068) It was discovered that the Hotspot component of OpenJDK 17 incorrectly handled array accesses in the C2 compiler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-21094) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10 openjdk-17-jdk 17.0.11+9-1~23.10.1 openjdk-17-jdk-headless 17.0.11+9-1~23.10.1 openjdk-17-jre 17.0.11+9-1~23.10.1 openjdk-17-jre-headless 17.0.11+9-1~23.10.1 openjdk-17-jre-zero 17.0.11+9-1~23.10.1 Ubuntu 22.04 LTS openjdk-17-jdk 17.0.11+9-1~22.04.1 openjdk-17-jdk-headless 17.0.11+9-1~22.04.1 openjdk-17-jre 17.0.11+9-1~22.04.1 openjdk-17-jre-headless 17.0.11+9-1~22.04.1 openjdk-17-jre-zero 17.0.11+9-1~22.04.1 Ubuntu 20.04 LTS openjdk-17-jdk 17.0.11+9-1~20.04.2 openjdk-17-jdk-headless 17.0.11+9-1~20.04.2 openjdk-17-jre 17.0.11+9-1~20.04.2 openjdk-17-jre-headless 17.0.11+9-1~20.04.2 openjdk-17-jre-zero 17.0.11+9-1~20.04.2 Ubuntu 18.04 LTS openjdk-17-jdk 17.0.11+9-1~18.04.1 Available with Ubuntu Pro openjdk-17-jdk-headless 17.0.11+9-1~18.04.1 Available with Ubuntu Pro openjdk-17-jre 17.0.11+9-1~18.04.1 Available with Ubuntu Pro openjdk-17-jre-headless 17.0.11+9-1~18.04.1 Available with Ubuntu Pro openjdk-17-jre-zero 17.0.11+9-1~18.04.1 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6812-1 CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21094 Package Information: https://launchpad.net/ubuntu/+source/openjdk-17/17.0.11+9-1~23.10.1 https://launchpad.net/ubuntu/+source/openjdk-17/17.0.11+9-1~22.04.1 https://launchpad.net/ubuntu/+source/openjdk-17/17.0.11+9-1~20.04.2 . Multiple vulnerabilities in OpenJDK 17 have been resolved for Ubuntu systems. It's crucial to upgrade promptly to maintain security.. openjdk Updates, Security Issues, Java Vulnerabilities, Ubuntu Patches, Dos Attacks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 06, 2024 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200