Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
# Security update for pcr-oracle Announcement ID: SUSE-SU-2026:22459-1 Release Date: 2026-06-30T23:03:29Z Rating: moderate References:. # Security update for pcr-oracle Announcement ID: SUSE-SU-2026:22459-1 Release Date: 2026-06-30T23:03:29Z Rating: moderate References: * bsc#1265042 * bsc#1265871 Affected Products: * SUSE Linux Micro 6.1 An update that has two fixes can now be installed. ## Description: This update for pcr-oracle fixes the following issues Update to 0.6.3: Security issue: * integer underflow vulnerability in `parse_sbatlevel_section()` (bsc#1265042). Non security issue: * Lockout Authorization error for libvirt-emulated TPM (bsc#1265871). Changes for pcr-oracle: * Relax TPM self-test attribute checks (bsc#1265871) * Update the SBAT offset boundary check (bsc#1265042) * Advance the comparison event pointer after comparison * Partially support shim extra files * Locate shim extra files * Synthesize shim extra events * Fix various issues from review by Claude Code and introduce adversarial testing ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-606=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * pcr-oracle-debugsource-0.6.3-slfo.1.1_1.1 * pcr-oracle-0.6.3-slfo.1.1_1.1 * pcr-oracle-debuginfo-0.6.3-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265042 * https://bugzilla.suse.com/show_bug.cgi?id=1265871 . SUSE's security update for pcr-oracle addresses an integer underflow issue, enhancing system reliability and safety.. SUSE security update, pcr-oracle patch, integer underflow fix, Linux system update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for python-Mako Announcement ID: SUSE-SU-2026:1820-1 Release Date: 2026-05-12T08:00:01Z Rating: important References: * bsc#1262716 Cross-References: * CVE-2026-41205 CVSS scores: * CVE-2026-41205 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41205 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41205 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-Mako fixes the following issue: * CVE-2026-41205: Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal (bsc#1262716). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSELinux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1820=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1820=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1820=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1820=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1820=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1820=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1820=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1820=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-Mako-1.0.7-150000.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-Mako-1.0.7-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41205.html * https://bugzilla.suse.com/show_bug.cgi?id=1262716 . Updateavailable for Python Mako in SUSE addressing important path traversal issue. Install recommended patches promptly.. SUSE python-Mako patch security update. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21524-1 Release Date: 2026-05-05T20:01:32Z Rating: important References: * bsc#1261630 * bsc#1261845 * bsc#1263689 Cross-References: * CVE-2026-23437 * CVE-2026-31406 * CVE-2026-31431 CVSS scores: * CVE-2026-23437 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23437 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23437 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31406 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). * CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-693=1 ## PackageList: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_7-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-2-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23437.html * https://www.suse.com/security/cve/CVE-2026-31406.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1261630 * https://bugzilla.suse.com/show_bug.cgi?id=1261845 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . SUSE Linux kernel update fixes important security issues with installation instructions for Micro 6.2.. SUSE Linux Kernel, Important Kernel Update, Security Fix January 2026, SUSE Enterprise Security. . Severity: Important. LinuxSecurity.com Team
An update that solves various issues can now be installed.. openSUSE security update: security update for container-suseconnect ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20628-1 Rating: moderate Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves various issues can now be installed. Description: This update for container-suseconnect fixes the following issues: Changes in container-suseconnect: - switch to build with go 1.25 Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-644=1 Package List: - openSUSE Leap 16.0: container-suseconnect-2.5.6-160000.2.1 . Update for openSUSE Leap 16.0 addresses issues in container-suseconnect with moderate severity. Install instructions included.. openSUSE security patch, container-suseconnect issues, moderate severity fix, system update instructions. . LinuxSecurity.com Team
An update that can now be installed.. # Security update for containerd Announcement ID: SUSE-SU-2026:1105-1 Release Date: 2026-03-27T07:03:56Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for containerd rebuilds it against the current go 1.25 security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-1105=1 * SUSELinux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1105=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1105=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1105=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1105=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1105=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1105=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1105=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1105=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1105=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1105=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1105=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1105=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1105=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1105=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-1105=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1105=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-1105=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patchSUSE-SLE-Micro-5.5-2026-1105=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1105=1 ## Package List: * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * containerd-devel-1.7.29-150000.130.1 *containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.130.1 * containerd-1.7.29-150000.130.1 * containerd-ctr-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.130.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.130.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.130.1 . Update for containerd in openSUSE addresses important security concerns; ensure your systems are patched and secure.. openSUSE, containerd, security update, important patch, SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team
An update that contains one feature can now be installed.. # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2026:0292-1 Release Date: 2026-01-26T11:11:53Z Rating: moderate References: * jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 An update that contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: Update to version 0.0.20260123T022811 2026-01-23T02:28:11Z (jsc#PED-11136). Go CVE Numbering Authority IDs added or updated with aliases: * GO-2025-3764 CVE-2024-44905 GHSA-6xp3-p59p-q4fj * GO-2025-4188 CVE-2025-65637 GHSA-4f99-4q7p-p3gh * GO-2025-4252 CVE-2025-68383 GHSA-2mj3-6grc-px38 * GO-2025-4253 CVE-2025-68388 GHSA-fj69-23m4-ccvv * GO-2026-4310 CVE-2026-22689 GHSA-524m-q5m7-79mm * GO-2026-4311 CVE-2026-22772 GHSA-59jp-pj84-45mr * GO-2026-4312 CVE-2026-22771 GHSA-xrwg-mqj6-6m22 * GO-2026-4313 CVE-2026-22786 GHSA-3558-j79f-vvm6 * GO-2026-4314 CVE-2026-22868 GHSA-mq3p-rrmp-79jg * GO-2026-4315 CVE-2026-22862 GHSA-mr7q-c9w9-wh4h * GO-2026-4316 GHSA-mqqf-5wvp-8fh8 * GO-2026-4317 CVE-2017-18892 GHSA-wj5w-qghh-gvqp * GO-2026-4318 CVE-2025-66292 GHSA-vh2x-fw87-4fxq * GO-2026-4319 CVE-2026-23511 GHSA-pvm5-9frx-264r * GO-2026-4320 CVE-2026-23520 GHSA-gjqq-6r35-w3r8 * GO-2026-4321 CVE-2025-68671 GHSA-f2ph-gc9m-q55f * GO-2026-4322 CVE-2026-22045 GHSA-cwjm-3f7h-9hwq ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-292=1 ## Package List: * openSUSE Leap 15.6 (noarch) * govulncheck-vulndb-0.0.20260123T022811-150000.1.140.1 ## References: * https://jira.suse.com/browse/PED-11136 . An openSUSE update for govulncheck-vulndb addresses moderate severity issues with installation instructions.. openSUSE, govulncheck-vulndb, update,moderate severity, security patch. . LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for ImageMagick Announcement ID: SUSE-SU-2026:0073-1 Release Date: 2026-01-08T13:22:44Z Rating: moderate References: * bsc#1255821 * bsc#1255822 * bsc#1255823 Cross-References: * CVE-2025-68618 * CVE-2025-68950 * CVE-2025-69204 CVSS scores: * CVE-2025-68618 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-68618 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-68618 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68618 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-68950 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-68950 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-68950 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-68950 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-69204 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-69204 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-69204 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-69204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2025-68618: read a malicious SVG file may result in a DoS attack (bsc#1255821). * CVE-2025-68950: check for circular references in mvg files may lead to stack overflow (bsc#1255822). * CVE-2025-69204: an integer overflow canlead to a DoS attack (bsc#1255823). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-73=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-73=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-PerlMagick-7.1.1.43-150700.3.30.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.30.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.30.1 * ImageMagick-debugsource-7.1.1.43-150700.3.30.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-devel-7.1.1.43-150700.3.30.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.30.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.30.1 * libMagick++-devel-7.1.1.43-150700.3.30.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.30.1 * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.30.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.30.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.30.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.30.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.30.1 * ImageMagick-debugsource-7.1.1.43-150700.3.30.1 * ImageMagick-7.1.1.43-150700.3.30.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.30.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.30.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.30.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68618.html * https://www.suse.com/security/cve/CVE-2025-68950.html * https://www.suse.com/security/cve/CVE-2025-69204.html * https://bugzilla.suse.com/show_bug.cgi?id=1255821 * https://bugzilla.suse.com/show_bug.cgi?id=1255822 * https://bugzilla.suse.com/show_bug.cgi?id=1255823 . Update for ImageMagick released by SUSE fixes three moderate vulnerabilities. Installation instructions included.. ImageMagick security, SUSE update, vulnerability patch. . LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 56 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:03529-1 Release Date: 2025-10-10T15:03:55Z Rating: important References: * bsc#1240744 * bsc#1243650 * bsc#1247315 Cross-References: * CVE-2024-53168 * CVE-2025-21791 * CVE-2025-38477 CVSS scores: * CVE-2024-53168 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53168 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53168 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53168 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21791 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-21791 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21791 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21791 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38477 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38477 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_201 fixes several issues. The following security issues were fixed: * CVE-2024-53168: sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket (bsc#1243650). * CVE-2025-38477: net/sched: sch_qfq: Fix race condition on qfq_aggregate (bsc#1247315). * CVE-2025-21791: vrf: use RCU protection inl3mdev_l3_out() (bsc#1240744). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-3529=1 SUSE-SLE- Module-Live-Patching-15-SP3-2025-3532=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-3532=1 SUSE-2025-3529=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_56-debugsource-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_201-default-debuginfo-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_201-default-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_198-default-9-150300.2.1 * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_201-default-7-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_56-debugsource-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_198-default-debuginfo-9-150300.2.1 * kernel-livepatch-5_3_18-150300_59_201-default-debuginfo-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_198-default-9-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_55-debugsource-9-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_198-preempt-9-150300.2.1 * kernel-livepatch-5_3_18-150300_59_198-preempt-debuginfo-9-150300.2.1 * kernel-livepatch-5_3_18-150300_59_201-preempt-7-150300.2.1 * kernel-livepatch-5_3_18-150300_59_201-preempt-debuginfo-7-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-53168.html * https://www.suse.com/security/cve/CVE-2025-21791.html * https://www.suse.com/security/cve/CVE-2025-38477.html * https://bugzilla.suse.com/show_bug.cgi?id=1240744 * https://bugzilla.suse.com/show_bug.cgi?id=1243650 * https://bugzilla.suse.com/show_bug.cgi?id=1247315 . An update is available for the openSUSE kernel that fixesimportant security issues, providing guidance for installation.. openSUSE Kernel Update Instructions Important Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.