Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2025:01814-1 Release Date: 2025-06-04T14:11:09Z Rating: important References: * bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264 * CVE-2025-5265 * CVE-2025-5266 * CVE-2025-5267 * CVE-2025-5268 * CVE-2025-5269 CVSS scores: * CVE-2025-5263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5264 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5264 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5266 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5266 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5267 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5267 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5268 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5268 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP6 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSELinux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353): * MFSA-TMP-2025-0001: Double-free in libvpx encoder (bmo#1962421) * CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745) * CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001) * CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301) * CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628) * CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137) * CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634) * CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108) ## Patch Instructions: To install this SUSEupdate use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1814=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1814=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-1814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1814=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-1814=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1814=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-1814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1814=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-1814=1 ## Package List: * openSUSE Leap 15.6(aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-branding-upstream-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * openSUSE Leap 15.6 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * Desktop Applications Module 15-SP6 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) *MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) *MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 *MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * MozillaFirefox-translations-other-128.11.0-150200.152.185.1 * MozillaFirefox-translations-common-128.11.0-150200.152.185.1 * MozillaFirefox-128.11.0-150200.152.185.1 * MozillaFirefox-debuginfo-128.11.0-150200.152.185.1 * MozillaFirefox-debugsource-128.11.0-150200.152.185.1 * SUSE Enterprise Storage 7.1 (noarch) * MozillaFirefox-devel-128.11.0-150200.152.185.1 ## References: * https://www.suse.com/security/cve/CVE-2025-5263.html * https://www.suse.com/security/cve/CVE-2025-5264.html * https://www.suse.com/security/cve/CVE-2025-5265.html * https://www.suse.com/security/cve/CVE-2025-5266.html * https://www.suse.com/security/cve/CVE-2025-5267.html * https://www.suse.com/security/cve/CVE-2025-5268.html * https://www.suse.com/security/cve/CVE-2025-5269.html * https://bugzilla.suse.com/show_bug.cgi?id=1243353 . This significant notification outlines a security upgrade for Google Chrome, addressing severe remote code execution vulnerabilities and memory-related concerns.. SUSE Linux Enterprise, Mozilla Firefox Update, Security Patches, Application Security. . Severity: Critical. LinuxSecurity.comTeam
* bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2025:01769-1 Release Date: 2025-05-30T09:30:34Z Rating: important References: * bsc#1243353 Cross-References: * CVE-2025-5263 * CVE-2025-5264 * CVE-2025-5265 * CVE-2025-5266 * CVE-2025-5267 * CVE-2025-5268 * CVE-2025-5269 CVSS scores: * CVE-2025-5263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2025-5264 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5264 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5265 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2025-5266 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5266 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5267 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5267 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-5268 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5268 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-5269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353): * MFSA-TMP-2025-0001: Double-free in libvpxencoder (bmo#1962421) * CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745) * CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001) * CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301) * CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628) * CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137) * CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634) * CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1769=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1769=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-128.11.0-112.262.1 * MozillaFirefox-debuginfo-128.11.0-112.262.1 * MozillaFirefox-128.11.0-112.262.1 * MozillaFirefox-debugsource-128.11.0-112.262.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-128.11.0-112.262.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-translations-common-128.11.0-112.262.1 * MozillaFirefox-debuginfo-128.11.0-112.262.1 * MozillaFirefox-128.11.0-112.262.1 * MozillaFirefox-debugsource-128.11.0-112.262.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) *MozillaFirefox-devel-128.11.0-112.262.1 ## References: * https://www.suse.com/security/cve/CVE-2025-5263.html * https://www.suse.com/security/cve/CVE-2025-5264.html * https://www.suse.com/security/cve/CVE-2025-5265.html * https://www.suse.com/security/cve/CVE-2025-5266.html * https://www.suse.com/security/cve/CVE-2025-5267.html * https://www.suse.com/security/cve/CVE-2025-5268.html * https://www.suse.com/security/cve/CVE-2025-5269.html * https://bugzilla.suse.com/show_bug.cgi?id=1243353 . Essential patch for MozillaFirefox on SUSE, addressing several major vulnerabilities to strengthen overall system security.. MozillaFirefox Security Update, SUSE Security Patches, Important Bug Fixes. . Severity: Important. LinuxSecurity.com Team
Fabian Vogt discovered that the KDE session management server insufficiently restricted ICE connections from localhost, which could allow a local attacker to execute arbitrary code as another user on next boot. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5723-1
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6647-1 February 21, 2024 linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-4.15: Linux kernel for Microsoft Azure Cloud systems - linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-aws-hwe: Linux kernel for Amazon Web Services (AWS-HWE) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe: Linux hardware enablement (HWE) kernel Details: It was discovered that a race condition existed in the ATM (Asynchronous Transfer Mode) subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51780) It was discovered that a race condition existed in the Rose X.25 protocol implementation in the Linux kernel, leading to a use-after- free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51782) It was discovered that the netfilter connection tracker for netlink in the Linux kernel did not properly perform reference counting in some error conditions. A local attackercould possibly use this to cause a denial of service (memory exhaustion). (CVE-2023-7192) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-1128-oracle 4.15.0-1128.139 linux-image-4.15.0-1149-kvm 4.15.0-1149.154 linux-image-4.15.0-1159-gcp 4.15.0-1159.176 linux-image-4.15.0-1165-aws 4.15.0-1165.178 linux-image-4.15.0-1174-azure 4.15.0-1174.189 linux-image-4.15.0-222-generic 4.15.0-222.233 linux-image-4.15.0-222-lowlatency 4.15.0-222.233 linux-image-aws-lts-18.04 4.15.0.1165.163 linux-image-azure-lts-18.04 4.15.0.1174.142 linux-image-gcp-lts-18.04 4.15.0.1159.173 linux-image-generic 4.15.0.222.206 linux-image-kvm 4.15.0.1149.140 linux-image-lowlatency 4.15.0.222.206 linux-image-oracle-lts-18.04 4.15.0.1128.133 linux-image-virtual 4.15.0.222.206 Ubuntu 16.04 LTS (Available with Ubuntu Pro): linux-image-4.15.0-1128-oracle 4.15.0-1128.139~16.04.1 linux-image-4.15.0-1159-gcp 4.15.0-1159.176~16.04.1 linux-image-4.15.0-1165-aws 4.15.0-1165.178~16.04.1 linux-image-4.15.0-1174-azure 4.15.0-1174.189~16.04.1 linux-image-4.15.0-222-generic 4.15.0-222.233~16.04.1 linux-image-4.15.0-222-lowlatency 4.15.0-222.233~16.04.1 linux-image-aws-hwe 4.15.0.1165.148 linux-image-azure 4.15.0.1174.158 linux-image-gcp 4.15.0.1159.149 linux-image-generic-hwe-16.04 4.15.0.222.6 linux-image-gke 4.15.0.1159.149 linux-image-lowlatency-hwe-16.04 4.15.0.222.6 linux-image-oem 4.15.0.222.6 linux-image-oracle 4.15.0.1128.109 linux-image-virtual-hwe-16.04 4.15.0.222.6 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABIchange the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6647-1 CVE-2023-51780, CVE-2023-51782, CVE-2023-7192 . A series of kernel updates has been issued in Ubuntu Security Notice USN-6647-1 to resolve significant vulnerabilities.. Ubuntu Pro, Cloud Kernel Solutions, Kernel Security Fix. . Severity: Critical. LinuxSecurity.com Team
GNU C Library could be made to crash or run programs as an administrator if it handled a specially crafted request.. ========================================================================== Ubuntu Security Notice USN-6620-1 February 01, 2024 glibc vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 Summary: GNU C Library could be made to crash or run programs as an administrator if it handled a specially crafted request. Software Description: - glibc: GNU C Library Details: It was discovered that the GNU C Library incorrectly handled the syslog() function call. A local attacker could use this issue to execute arbitrary code and possibly escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libc6 2.38-1ubuntu6.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6620-1 CVE-2023-6246, CVE-2023-6779, CVE-2023-6780 Package Information: https://launchpad.net/ubuntu/+source/glibc/2.38-1ubuntu6.1 . Ubuntu Security Advisory USN-6620-1 pertains to vulnerabilities in glibc that may enable local users to gain elevated rights and run arbitrary code.. glibc vulnerabilities, local code execution, privilege escalation, Ubuntu security. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libnl3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3208-1 Rating: moderate References: #1020123 Cross-References: CVE-2017-0386 CVSS scores: CVE-2017-0386 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-0386 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libnl3 fixes the following issues: - CVE-2017-0386: Fixed an issue that could enable a local malicious application to execute arbitrary code within the context of a different process. This only affects setups were libnl is passed untrusted arguments. (bsc#1020123) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3208=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3208=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libnl3-debugsource-3.2.23-4.7.1 libnl3-devel-3.2.23-4.7.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libnl3-200-3.2.23-4.7.1 libnl3-200-debuginfo-3.2.23-4.7.1 libnl3-debugsource-3.2.23-4.7.1 - SUSE Linux EnterpriseServer 12-SP5 (s390x x86_64): libnl3-200-32bit-3.2.23-4.7.1 libnl3-200-debuginfo-32bit-3.2.23-4.7.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): libnl-config-3.2.23-4.7.1 References: https://www.suse.com/security/cve/CVE-2017-0386.html https://bugzilla.suse.com/1020123 . SUSE Security Patch for libnl3 addresses a significant flaw allowing local code execution, improving overall system safety.. SUSE Security Update, libnl3 fix, local code execution threat, software patch. . LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5265-1 February 03, 2022 linux, linux-aws, linux-aws-5.11, linux-aws-5.13, linux-gcp, linux-gcp-5.11, linux-hwe-5.13, linux-kvm, linux-oem-5.13, linux-oracle, linux-oracle-5.11, linux-raspi vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-aws-5.11: Linux kernel for Amazon Web Services (AWS) systems - linux-aws-5.13: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-5.11: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.13: Linux hardware enablement (HWE) kernel - linux-oem-5.13: Linux kernel for OEM systems - linux-oracle-5.11: Linux kernel for Oracle Cloud systems Details: Jeremy Cline discovered a use-after-free in the nouveau graphics driver of the Linux kernel during device removal. A privileged or physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2020-27820) It was discovered that the Bluetooth subsystem in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3640) Likang Luo discovered that a race condition existed in the Bluetooth subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly executearbitrary code. (CVE-2021-3752) It was discovered that the SCTP protocol implementation in the Linux kernel did not properly verify VTAGs in some situations. A remote attacker could possibly use this to cause a denial of service (connection disassociation). (CVE-2021-3772) It was discovered that the eBPF implementation in the Linux kernel contained a race condition around read-only maps. A privileged attacker could use this to modify read-only maps. (CVE-2021-4001) It was discovered that the NFS server implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4090) Felix Wilhelm discovered that the KVM implementation in the Linux kernel did not properly handle exit events from AMD Secure Encrypted Virtualization-Encrypted State (SEV-ES) guest VMs. An attacker in a guest VM could use this to cause a denial of service (host kernel crash) or possibly execute arbitrary code in the host kernel. (CVE-2021-4093) Lin Ma discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4202) It was discovered that the AMD Radeon GPU driver in the Linux kernel did not properly validate writes in the debugfs file system. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-42327) Luo Likang discovered that the FireDTV Firewire driver in the Linux kernel did not properly perform bounds checking in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-42739) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: linux-image-5.13.0-1011-kvm 5.13.0-1011.12 linux-image-5.13.0-1012-aws 5.13.0-1012.13 linux-image-5.13.0-1013-gcp 5.13.0-1013.16 linux-image-5.13.0-1016-oracle 5.13.0-1016.20 linux-image-5.13.0-1016-raspi 5.13.0-1016.18 linux-image-5.13.0-1016-raspi-nolpae 5.13.0-1016.18 linux-image-5.13.0-28-generic 5.13.0-28.31 linux-image-5.13.0-28-generic-64k 5.13.0-28.31 linux-image-5.13.0-28-generic-lpae 5.13.0-28.31 linux-image-5.13.0-28-lowlatency 5.13.0-28.31 linux-image-aws 5.13.0.1012.13 linux-image-gcp 5.13.0.1013.12 linux-image-generic 5.13.0.28.38 linux-image-generic-64k 5.13.0.28.38 linux-image-generic-lpae 5.13.0.28.38 linux-image-gke 5.13.0.1013.12 linux-image-kvm 5.13.0.1011.11 linux-image-lowlatency 5.13.0.28.38 linux-image-oem-20.04 5.13.0.28.38 linux-image-oracle 5.13.0.1016.16 linux-image-raspi 5.13.0.1016.21 linux-image-raspi-nolpae 5.13.0.1016.21 linux-image-virtual 5.13.0.28.38 Ubuntu 20.04 LTS: linux-image-5.11.0-1028-oracle 5.11.0-1028.31~20.04.1 linux-image-5.11.0-1029-gcp 5.11.0-1029.33~20.04.3 linux-image-5.13.0-1029-oem 5.13.0-1029.36 linux-image-5.13.0-28-generic 5.13.0-28.31~20.04.1 linux-image-5.13.0-28-generic-64k 5.13.0-28.31~20.04.1 linux-image-5.13.0-28-generic-lpae 5.13.0-28.31~20.04.1 linux-image-5.13.0-28-lowlatency 5.13.0-28.31~20.04.1 linux-image-aws 5.11.0.1028.31~20.04.26 linux-image-gcp 5.11.0.1029.33~20.04.27 linux-image-generic-64k-hwe-20.04 5.13.0.28.31~20.04.15 linux-image-generic-hwe-20.04 5.13.0.28.31~20.04.15 linux-image-generic-lpae-hwe-20.04 5.13.0.28.31~20.04.15 linux-image-lowlatency-hwe-20.04 5.13.0.28.31~20.04.15 linux-image-oem-20.04c 5.13.0.1029.31 linux-image-oracle 5.11.0.1028.31~20.04.20 linux-image-virtual-hwe-20.04 5.13.0.28.31~20.04.15 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5265-1 CVE-2020-27820, CVE-2021-3640, CVE-2021-3752, CVE-2021-3772, CVE-2021-4001, CVE-2021-4090, CVE-2021-4093, CVE-2021-4202, CVE-2021-42327, CVE-2021-42739 Package Information: https://launchpad.net/ubuntu/+source/linux/5.13.0-28.31 https://launchpad.net/ubuntu/+source/linux-aws/5.13.0-1012.13 https://launchpad.net/ubuntu/+source/linux-gcp/5.13.0-1013.16 https://launchpad.net/ubuntu/+source/linux-kvm/5.13.0-1011.12 https://launchpad.net/ubuntu/+source/linux-oracle/5.13.0-1016.20 https://launchpad.net/ubuntu/+source/linux-raspi/5.13.0-1016.18 https://launchpad.net/ubuntu/+source/linux-aws-5.11/5.11.0-1028.31~20.04.1 https://launchpad.net/ubuntu/+source/linux-aws-5.13/5.13.0-1012.13~20.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.11/5.11.0-1029.33~20.04.3 https://launchpad.net/ubuntu/+source/linux-hwe-5.13/5.13.0-28.31~20.04.1 https://launchpad.net/ubuntu/+source/linux-oem-5.13/5.13.0-1029.36 https://launchpad.net/ubuntu/+source/linux-oracle-5.11/5.11.0-1028.31~20.04.1 . Various security issues in the Linux kernel are addressed, ensuring system stability against denial of service threats.. Ubuntu Kernel Update, Linux Security Advisory, Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1646-1 Rating: important References: #1171746 #1172437 Cross-References: CVE-2018-1000199 CVE-2020-10757 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Module for Live Patching 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-197_37 fixes several issues. The following security issues were fixed: - CVE-2020-10757: Fixed an issue where remaping hugepage DAX to anon mmap could have caused user PTE access (bsc#1172437). - CVE-2018-1000199: Fixed a potential local code execution via ptrace (bsc#1171746). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2020-1645=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1646=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1647=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1648=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1649=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1650=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-1651=1 - SUSE Linux Enterprise Module for Live Patching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2020-1665=1 SUSE-SLE-Module-Live-Patching-15-2020-1666=1 SUSE-SLE-Module-Live-Patching-15-2020-1667=1 SUSE-SLE-Module-Live-Patching-15-2020-1668=1 Package List: - SUSE Linux Enterprise Module for Live Patching15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_18-default-7-2.1 kernel-livepatch-4_12_14-197_21-default-7-2.1 kernel-livepatch-4_12_14-197_26-default-5-2.1 kernel-livepatch-4_12_14-197_29-default-5-2.1 kernel-livepatch-4_12_14-197_34-default-4-2.1 kernel-livepatch-4_12_14-197_37-default-4-2.1 kernel-livepatch-4_12_14-197_40-default-3-2.1 - SUSE Linux Enterprise Module for Live Patching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150_35-default-7-2.1 kernel-livepatch-4_12_14-150_35-default-debuginfo-7-2.1 kernel-livepatch-4_12_14-150_38-default-7-2.1 kernel-livepatch-4_12_14-150_38-default-debuginfo-7-2.1 kernel-livepatch-4_12_14-150_41-default-5-2.1 kernel-livepatch-4_12_14-150_41-default-debuginfo-5-2.1 kernel-livepatch-4_12_14-150_47-default-5-2.1 kernel-livepatch-4_12_14-150_47-default-debuginfo-5-2.1 References: https://www.suse.com/security/cve/CVE-2018-1000199.html https://www.suse.com/security/cve/CVE-2020-10757.html https://bugzilla.suse.com/1171746 https://bugzilla.suse.com/1172437 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.