An update that solves one vulnerability can now be installed.. # Security update for python-maturin Announcement ID: SUSE-SU-2026:20335-1 Release Date: 2026-02-05T20:51:59Z Rating: moderate References: * bsc#1249011 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-maturin fixes the following issues: * CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-246=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-246=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * python313-maturin-1.8.7-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249011 . A security update for python-maturin resolves a log pollution issue in SUSE Linux. Update recommended for users.. python-maturin update,SUSE security patch,log pollution issue,moderate severity,security update. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for python-maturin Announcement ID: SUSE-SU-2026:20235-1 Release Date: 2026-02-05T20:50:45Z Rating: moderate References: * bsc#1249011 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for python-maturin fixes the following issues: * CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-246=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249011 . Moderate security update for python-maturin addresses log pollution issue in SUSE Linux Micro.. SUSE Linux Micro, python-maturin, log pollution, CVE-2025-58160. . LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for python-maturin ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20180-1 Rating: moderate References: * bsc#1249011 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for python-maturin fixes the following issues: - CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249011) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-246=1 Package List: - openSUSE Leap 16.0: python313-maturin-1.8.7-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-58160.html . An openSUSE update for python-maturin addresses log pollution and ensures system integrity.. python-maturin security update, openSUSE patch management, log pollution vulnerability. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for python-uv Announcement ID: SUSE-SU-2026:20077-1 Release Date: 2026-01-13T12:48:04Z Rating: important References: * bsc#1249011 * bsc#1252399 Cross-References: * CVE-2025-58160 * CVE-2025-62518 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62518 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-62518 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-62518 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-uv fixes the following issues: * CVE-2025-62518: astral-tokio-tar: Fixed boundary parsing issue allowing attackers to smuggle additional archive entries (bsc#1252399) * CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249011) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-135=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-135=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-uv-0.7.18-160000.3.1 * python-uv-debugsource-0.7.18-160000.3.1 *python313-uv-debuginfo-0.7.18-160000.3.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * python313-uv-0.7.18-160000.3.1 * python-uv-debugsource-0.7.18-160000.3.1 * python313-uv-debuginfo-0.7.18-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2025-62518.html * https://bugzilla.suse.com/show_bug.cgi?id=1249011 * https://bugzilla.suse.com/show_bug.cgi?id=1252399 . SUSE's important security update resolves critical issues in python-uv affecting server operations and security.. SUSE Python-UV Update, Security Fix, Server Applications. . Severity: Important. LinuxSecurity.com Team
* bsc#1249013 * bsc#1250687 Cross-References: * CVE-2025-58160 . # Security update for himmelblau Announcement ID: SUSE-SU-2025:21158-1 Release Date: 2025-11-27T20:16:29Z Rating: important References: * bsc#1249013 * bsc#1250687 Cross-References: * CVE-2025-58160 * CVE-2025-59044 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-59044 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-59044 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for himmelblau fixes the following issues: * Update to version 0.9.23+git.0.9776141: * CVE-2025-59044: Fixed GID collision of same-name groups allowing privilege escalation (bsc#1250687) * deps(rust): bump the all-cargo-updates group * CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249013) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-80=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-80=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * pam-himmelblau-0.9.23+git.0.9776141-160000.1.1 * himmelblau-debuginfo-0.9.23+git.0.9776141-160000.1.1 * himmelblau-0.9.23+git.0.9776141-160000.1.1 * himmelblau-qr-greeter-0.9.23+git.0.9776141-160000.1.1 * himmelblau-sso-debuginfo-0.9.23+git.0.9776141-160000.1.1 * himmelblau-sso-0.9.23+git.0.9776141-160000.1.1 * libnss_himmelblau2-0.9.23+git.0.9776141-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * himmelblau-sshd-config-0.9.23+git.0.9776141-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (x86_64) * pam-himmelblau-0.9.23+git.0.9776141-160000.1.1 * himmelblau-debuginfo-0.9.23+git.0.9776141-160000.1.1 * himmelblau-0.9.23+git.0.9776141-160000.1.1 * himmelblau-qr-greeter-0.9.23+git.0.9776141-160000.1.1 * himmelblau-sso-debuginfo-0.9.23+git.0.9776141-160000.1.1 * himmelblau-sso-0.9.23+git.0.9776141-160000.1.1 * libnss_himmelblau2-0.9.23+git.0.9776141-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (noarch) * himmelblau-sshd-config-0.9.23+git.0.9776141-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2025-59044.html * https://bugzilla.suse.com/show_bug.cgi?id=1249013 * https://bugzilla.suse.com/show_bug.cgi?id=1250687 . Update it now to fix important issues like privilege escalation and log pollution for SUSE Himmelblau security.. SUSE security update, himmelblau issues, privilege escalation fix, Linux patch instructions, SUSE vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for himmelblau ------------------------------------------------------------- Announcement ID: openSUSE-SU-2025-20114-1 Rating: important References: * bsc#1249013 * bsc#1250687 Cross-References: * CVE-2025-58160 * CVE-2025-59044 CVSS scores: * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-59044 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for himmelblau fixes the following issues: - Update to version 0.9.23+git.0.9776141: * CVE-2025-59044: Fixed GID collision of same-name groups allowing privilege escalation (bsc#1250687) * deps(rust): bump the all-cargo-updates group * CVE-2025-58160: tracing-subscriber: Fixed log pollution (bsc#1249013) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-80=1 Package List: - openSUSE Leap 16.0: himmelblau-0.9.23+git.0.9776141-160000.1.1 himmelblau-qr-greeter-0.9.23+git.0.9776141-160000.1.1 himmelblau-sshd-config-0.9.23+git.0.9776141-160000.1.1 himmelblau-sso-0.9.23+git.0.9776141-160000.1.1 libnss_himmelblau2-0.9.23+git.0.9776141-160000.1.1 pam-himmelblau-0.9.23+git.0.9776141-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2025-59044.html . Critical openSUSE update fixes two issues in himmelblau with important severity. Installrecommended patches now.. openSUSE updates, himmelblau security, privilege escalation fix, log pollution vulnerability. . Severity: Important. LinuxSecurity.com Team
Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ee9b86c6d9 2025-10-01 15:00:59.894563+00:00 -------------------------------------------------------------------------------- Name : ntpd-rs Product : Fedora 41 Version : 1.6.2 Release : 1.fc41 URL : https://github.com/pendulum-project/ntpd-rs Summary : Full-featured implementation of NTP with NTS support Description : Full-featured implementation of NTP with NTS support. -------------------------------------------------------------------------------- Update Information: Update to version 1.6.2. Includes fixes for CVE-2025-58066 (potential DoS in the ntpd-rs server) and CVE-2025-58160 (potential tracing log pollution). -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 22 2025 Fabio Valentini - 1.6.2-1 - Update to version 1.6.2; Fixes RHBZ#2375009 * Thu Jul 24 2025 Fedora Release Engineering - 1.5.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2391951 - CVE-2025-58066 ntpd-rs: DoS Vulnerability in ntpd-rs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2391951 [ 2 ] Bug #2392003 - CVE-2025-58160 ntpd-rs: Tracing log pollution [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392003 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ee9b86c6d9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update niri to version 25.08 and xwayland-satellite to version 0.7. Notably, niri now supports xwayland out-of-the-box without manual configuration, and reading keyboard layout from org.freedesktop.locale1. Release notes: https://github.com/niri-wm/niri/releases/tag/v25.08. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2bcbe8b09c 2025-09-13 02:42:15.995376+00:00 -------------------------------------------------------------------------------- Name : niri Product : Fedora 41 Version : 25.08 Release : 1.fc41 URL : https://github.com/niri-wm/niri Summary : Scrollable-tiling Wayland compositor Description : A scrollable-tiling Wayland compositor. -------------------------------------------------------------------------------- Update Information: Update niri to version 25.08 and xwayland-satellite to version 0.7. Notably, niri now supports xwayland out-of-the-box without manual configuration, and reading keyboard layout from org.freedesktop.locale1. Release notes: https://github.com/niri-wm/niri/releases/tag/v25.08 https://github.com/Supreeeme/xwayland-satellite/releases/tag/v0.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 4 2025 Fabio Valentini - 25.08-1 - Update to version 25.08; Fixes RHBZ#2392152 * Thu Jul 24 2025 Fedora Release Engineering - 25.05.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2392002 - CVE-2025-58160 niri: Tracing log pollution [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2392002 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2bcbe8b09c' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.