Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
100

SUSE: 2020:0948-2 Moderate: Fixes for gmp and gnutls DTLS Issue

An update that solves one vulnerability, contains one feature and has three fixes is now available. . SUSE Security Update: Security update for gmp, gnutls, libnettle ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0948-2 Rating: moderate References: #1152692 #1155327 #1166881 #1168345 SLE-9518 Cross-References: CVE-2020-11501 CVSS scores: CVE-2020-11501 (NVD) : 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2020-11501 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Linux Enterprise Module for Certifications 15-SP3 ______________________________________________________________________________ An update that solves one vulnerability, contains one feature and has three fixes is now available. Description: This update for gmp, gnutls, libnettle fixes the following issues: Security issue fixed: - CVE-2020-11501: Fixed zero random value in DTLS client hello (bsc#1168345) FIPS related bugfixes: - FIPS: Install checksums for binary integrity verification which are required when running in FIPS mode (bsc#1152692, jsc#SLE-9518) - FIPS: Fixed a cfb8 decryption issue, no longer truncate output IV if input is shorter than block size. (bsc#1166881) - FIPS: Added Diffie Hellman public key verification test. (bsc#1155327) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Certifications 15-SP3: zypper in -t patch SUSE-SLE-Module-Certifications-15-SP3-2022-2391=1 Package List: - SUSE Linux Enterprise Module for Certifications 15-SP3 (aarch64 ppc64le s390x x86_64): gmp-debugsource-6.1.2-4.3.1 gmp-devel-6.1.2-4.3.1 libgmp10-6.1.2-4.3.1 libgmp10-debuginfo-6.1.2-4.3.1 libgmpxx4-6.1.2-4.3.1 libgmpxx4-debuginfo-6.1.2-4.3.1 libhogweed4-3.4.1-4.12.1 libhogweed4-debuginfo-3.4.1-4.12.1 libnettle-debugsource-3.4.1-4.12.1 libnettle-devel-3.4.1-4.12.1 libnettle6-3.4.1-4.12.1 libnettle6-debuginfo-3.4.1-4.12.1 nettle-3.4.1-4.12.1 nettle-debuginfo-3.4.1-4.12.1 - SUSE Linux Enterprise Module for Certifications 15-SP3 (x86_64): gmp-devel-32bit-6.1.2-4.3.1 libgmp10-32bit-6.1.2-4.3.1 libgmp10-32bit-debuginfo-6.1.2-4.3.1 libgmpxx4-32bit-6.1.2-4.3.1 libgmpxx4-32bit-debuginfo-6.1.2-4.3.1 libhogweed4-32bit-3.4.1-4.12.1 libhogweed4-32bit-debuginfo-3.4.1-4.12.1 libnettle-devel-32bit-3.4.1-4.12.1 libnettle6-32bit-3.4.1-4.12.1 libnettle6-32bit-debuginfo-3.4.1-4.12.1 References: https://www.suse.com/security/cve/CVE-2020-11501.html https://bugzilla.suse.com/1152692 https://bugzilla.suse.com/1155327 https://bugzilla.suse.com/1166881 https://bugzilla.suse.com/1168345 . An update addresses a DTLS vulnerability in SUSE Linux. It includes moderate security improvements and patches for gmp and gnutls.. SUSE Security Update,gmp gnutls libnettle,cryptography issues. . LinuxSecurity.com Team

Calendar%202 Jul 13, 2022 SuSE
202

openSUSE Leap 15.3: 2021:2143-1 Critical: libnettle Denial of Service

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2143-1 Rating: important References: #1187060 Cross-References: CVE-2021-3580 CVSS scores: CVE-2021-3580 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnettle fixes the following issues: - CVE-2021-3580: Fixed a remote denial of service in the RSA decryption via manipulated ciphertext (bsc#1187060). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2143=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 nettle-3.4.1-4.18.1 nettle-debuginfo-3.4.1-4.18.1 - openSUSE Leap 15.3 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle-devel-32bit-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 References: https://www.suse.com/security/cve/CVE-2021-3580.html https://bugzilla.suse.com/1187060 . A new update for openSUSE addressing a vital denial of service vulnerability in libnettle has just been released, accompanied by key information.. openSUSE, libnettle, security update,important patch, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 11, 2021 Important OpenSUSE
202

OpenSUSE Leap 15.2: 2021:0906-1 Important Libnettle Remote DoS Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0906-1 Rating: important References: #1187060 Cross-References: CVE-2021-3580 CVSS scores: CVE-2021-3580 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnettle fixes the following issues: - CVE-2021-3580: Fixed a remote denial of service in the RSA decryption via manipulated ciphertext (bsc#1187060). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-906=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libhogweed4-3.4.1-lp152.4.6.1 libhogweed4-debuginfo-3.4.1-lp152.4.6.1 libnettle-debugsource-3.4.1-lp152.4.6.1 libnettle-devel-3.4.1-lp152.4.6.1 libnettle6-3.4.1-lp152.4.6.1 libnettle6-debuginfo-3.4.1-lp152.4.6.1 nettle-3.4.1-lp152.4.6.1 nettle-debuginfo-3.4.1-lp152.4.6.1 - openSUSE Leap 15.2 (x86_64): libhogweed4-32bit-3.4.1-lp152.4.6.1 libhogweed4-32bit-debuginfo-3.4.1-lp152.4.6.1 libnettle-devel-32bit-3.4.1-lp152.4.6.1 libnettle6-32bit-3.4.1-lp152.4.6.1 libnettle6-32bit-debuginfo-3.4.1-lp152.4.6.1 References: https://www.suse.com/security/cve/CVE-2021-3580.html https://bugzilla.suse.com/1187060 . The latest openSUSE patch resolves a significant vulnerability in libnettle,helping to avert potential remote denial of service attacks. Update promptly!. Remote DoS Fix, libnettle Security, openSUSE Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2021 Important OpenSUSE
100

SUSE: 2021:2143-1 Important: libnettle Remote DoS Critical Threat

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2143-1 Rating: important References: #1187060 Cross-References: CVE-2021-3580 CVSS scores: CVE-2021-3580 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE MicroOS 5.0 SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnettle fixes the following issues: - CVE-2021-3580: Fixed a remote denial of service in the RSA decryption via manipulated ciphertext (bsc#1187060). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-2143=1 - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2143=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2143=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2143=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2143=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2021-2143=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2143=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2143=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2021-2143=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-2143=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-2143=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2143=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2143=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2143=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2021-2143=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2143=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects newupdates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Manager Server 4.0 (ppc64le s390x x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Manager Server 4.0 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Manager Proxy 4.0 (x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server for SAP 15 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 - SUSE Enterprise Storage 6 (x86_64): libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 - SUSE CaaS Platform 4.0 (x86_64): libhogweed4-3.4.1-4.18.1 libhogweed4-32bit-3.4.1-4.18.1 libhogweed4-32bit-debuginfo-3.4.1-4.18.1 libhogweed4-debuginfo-3.4.1-4.18.1 libnettle-debugsource-3.4.1-4.18.1 libnettle-devel-3.4.1-4.18.1 libnettle6-3.4.1-4.18.1 libnettle6-32bit-3.4.1-4.18.1 libnettle6-32bit-debuginfo-3.4.1-4.18.1 libnettle6-debuginfo-3.4.1-4.18.1 References: https://www.suse.com/security/cve/CVE-2021-3580.html https://bugzilla.suse.com/1187060 . Solutions for SUSE's critical libnettle vulnerability patch. Detailed guidance for applying updates across different platforms.. SUSE Update, Libnettle Fix, Remote Attack, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2021 Important SuSE
100

SUSE: 2021:2135-1 Critical Security Advisory for libnettle Remote DoS

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2135-1 Rating: important References: #1187060 Cross-References: CVE-2021-3580 CVSS scores: CVE-2021-3580 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnettle fixes the following issues: - CVE-2021-3580: Fixed a remote denial of service in the RSA decryption via manipulated ciphertext (bsc#1187060). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-2135=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-2135=1 - SUSE OpenStack Cloud 9: zypper in -t patchSUSE-OpenStack-Cloud-9-2021-2135=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-2135=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-2135=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-2135=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-2135=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-2135=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-2135=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-2135=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-2135=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-2135=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-2135=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE OpenStack Cloud 9 (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE OpenStack Cloud 8 (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnettle-debugsource-2.7.1-13.6.1 libnettle-devel-2.7.1-13.6.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 - HPE Helion Openstack 8 (x86_64): libhogweed2-2.7.1-13.6.1 libhogweed2-32bit-2.7.1-13.6.1 libhogweed2-debuginfo-2.7.1-13.6.1 libhogweed2-debuginfo-32bit-2.7.1-13.6.1 libnettle-debugsource-2.7.1-13.6.1 libnettle4-2.7.1-13.6.1 libnettle4-32bit-2.7.1-13.6.1 libnettle4-debuginfo-2.7.1-13.6.1 libnettle4-debuginfo-32bit-2.7.1-13.6.1 References: https://www.suse.com/security/cve/CVE-2021-3580.html https://bugzilla.suse.com/1187060 . Critical SUSE Security Patch for libnettle resolves a remote denial of service vulnerability. Update immediately!. libnettle Fix, SUSE Security Update, Remote Service Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2021 Important SuSE
100

SUSE: 2021:137-1 Important Security Update for SUSE/SLE15 Container

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:137-1 Container Tags : suse/sle15:15.0 , suse/sle15:15.0.4.22.385 Container Release : 4.22.385 Severity : important Type : security References : 1184401 CVE-2021-20305 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1412-1 Released: Wed Apr 28 17:09:28 2021 Summary: Security update for libnettle Type: security Severity: important References: 1184401,CVE-2021-20305 This update for libnettle fixes the following issues: - CVE-2021-20305: Fixed the multiply function which was being called with out-of-range scalars (bsc#1184401). . SUSE Software Patch Notification includes vital security updates for suse/sle15, targeting severe vulnerabilities.. SUSE Container, Container Update, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 05, 2021 Important SuSE
202

openSUSE Leap 15.2: 2021:0635-1 Important: libnettle Out-Of-Range Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libnettle ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0635-1 Rating: important References: #1184401 Cross-References: CVE-2021-20305 CVSS scores: CVE-2021-20305 (NVD) : 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-20305 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnettle fixes the following issues: - CVE-2021-20305: Fixed the multiply function which was being called with out-of-range scalars (bsc#1184401). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-635=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libhogweed4-3.4.1-lp152.4.3.1 libhogweed4-debuginfo-3.4.1-lp152.4.3.1 libnettle-debugsource-3.4.1-lp152.4.3.1 libnettle-devel-3.4.1-lp152.4.3.1 libnettle6-3.4.1-lp152.4.3.1 libnettle6-debuginfo-3.4.1-lp152.4.3.1 nettle-3.4.1-lp152.4.3.1 nettle-debuginfo-3.4.1-lp152.4.3.1 - openSUSE Leap 15.2 (x86_64): libhogweed4-32bit-3.4.1-lp152.4.3.1 libhogweed4-32bit-debuginfo-3.4.1-lp152.4.3.1 libnettle-devel-32bit-3.4.1-lp152.4.3.1 libnettle6-32bit-3.4.1-lp152.4.3.1 libnettle6-32bit-debuginfo-3.4.1-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2021-20305.html https://bugzilla.suse.com/1184401 . Important patch released for openSUSE Leap 15.2 tackling libnettle flaw CVE-2021-20305. Take action to safeguard your system.. libnettle Update, openSUSE Vulnerability Fixes, Linux Security Patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 30, 2021 Important OpenSUSE
100

SUSE: 2022:256-3 Important: Libcap and Libnettle Security Patch

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2021:128-1 Container Tags : suse/sle15:15.2 , suse/sle15:15.2.8.2.899 Container Release : 8.2.899 Severity : important Type : security References : 1184401 1184690 CVE-2021-20305 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:1407-1 Released: Wed Apr 28 15:49:02 2021 Summary: Recommended update for libcap Type: recommended Severity: important References: 1184690 This update for libcap fixes the following issues: - Add explicit dependency on 'libcap2' with version to 'libcap-progs' and 'pam_cap'. (bsc#1184690) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1412-1 Released: Wed Apr 28 17:09:28 2021 Summary: Security update for libnettle Type: security Severity: important References: 1184401,CVE-2021-20305 This update for libnettle fixes the following issues: - CVE-2021-20305: Fixed the multiply function which was being called with out-of-range scalars (bsc#1184401). . Recent SUSE patches for sle15 address critical security issues concerning libcap and libnettle, ensuring improved system stability and protection.. SUSE Updates, Libcap Security, Libnettle Fixes, Container Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 29, 2021 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200