Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability, contains one feature and has 41 security fixes can now be installed.. # Maintenance update for Multi-Linux Manager 5.0: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:1010-1 Release Date: 2026-03-25T10:10:03Z Rating: important References: * bsc#1220899 * bsc#1237181 * bsc#1244177 * bsc#1246315 * bsc#1247544 * bsc#1247722 * bsc#1248783 * bsc#1249041 * bsc#1249425 * bsc#1250561 * bsc#1251865 * bsc#1251995 * bsc#1252098 * bsc#1252388 * bsc#1252638 * bsc#1252665 * bsc#1252908 * bsc#1252937 * bsc#1253174 * bsc#1253197 * bsc#1253249 * bsc#1253285 * bsc#1253322 * bsc#1253501 * bsc#1253659 * bsc#1253660 * bsc#1253711 * bsc#1253712 * bsc#1253773 * bsc#1254251 * bsc#1255089 * bsc#1255176 * bsc#1255298 * bsc#1255634 * bsc#1255653 * bsc#1255743 * bsc#1255857 * bsc#1256991 * bsc#1257255 * bsc#1257538 * bsc#1257992 * bsc#1259057 * jsc#MSQA-1045 Cross-References: * CVE-2024-29371 CVSS scores: * CVE-2024-29371 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-29371 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-29371 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Manager Proxy 5.0 Extension * SUSE Manager Retail Branch Server 5.0 Extension * SUSE Manager Server 5.0 Extension An update that solves one vulnerability, contains one feature and has 41 security fixes can now be installed. ## Security update 5.0.7 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to arotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars * use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 * Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons(bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir (bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list of supported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size of column 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Security update 5.0.7 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to a rotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars * use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 *Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons (bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir (bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list ofsupported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size of column 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Security update 5.0.7 for Multi-Linux Manager Server ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to a rotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars *use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 * Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons (bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir(bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list of supported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size ofcolumn 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Proxy 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Proxy-5.0-2026-1010=1 * SUSE Manager Retail Branch Server 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Retail-Branch-Server-5.0-2026-1010=1 * SUSE Manager Server 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Server-5.0-2026-1010=1 ## Package List: * SUSE Manager Proxy 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-aarch64-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-aarch64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-aarch64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-aarch64-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-ppc64le-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-ppc64le-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-ppc64le-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-ppc64le-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (s390x) * suse-manager-5.0-s390x-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-s390x-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-s390x-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-s390x-proxy-salt-broker-image-5.0.7-7.32.15 *suse-manager-5.0-s390x-proxy-ssh-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-x86_64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-x86_64-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-httpd-image-5.0.7-7.30.13 * SUSE Manager Retail Branch Server 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-aarch64-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-aarch64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-aarch64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-aarch64-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-ppc64le-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-ppc64le-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-ppc64le-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-ppc64le-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (s390x) * suse-manager-5.0-s390x-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-s390x-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-s390x-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-s390x-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-s390x-proxy-ssh-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-x86_64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-x86_64-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-httpd-image-5.0.7-7.30.13 * SUSE Manager Server 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-server-hub-xmlrpc-api-image-5.0.7-6.30.7 *suse-manager-5.0-aarch64-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-aarch64-server-image-5.0.7-7.37.12 * suse-manager-5.0-aarch64-server-migration-14-16-image-5.0.7-7.30.7 * SUSE Manager Server 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-ppc64le-server-image-5.0.7-7.37.12 * suse-manager-5.0-ppc64le-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-ppc64le-server-hub-xmlrpc-api-image-5.0.7-6.30.7 * SUSE Manager Server 5.0 Extension (s390x) * suse-manager-5.0-s390x-server-image-5.0.7-7.37.12 * suse-manager-5.0-s390x-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-s390x-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-s390x-server-hub-xmlrpc-api-image-5.0.7-6.30.7 * SUSE Manager Server 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-server-image-5.0.7-7.37.12 * suse-manager-5.0-x86_64-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-x86_64-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-x86_64-server-hub-xmlrpc-api-image-5.0.7-6.30.7 ## References: * https://www.suse.com/security/cve/CVE-2024-29371.html * https://bugzilla.suse.com/show_bug.cgi?id=1220899 * https://bugzilla.suse.com/show_bug.cgi?id=1237181 * https://bugzilla.suse.com/show_bug.cgi?id=1244177 * https://bugzilla.suse.com/show_bug.cgi?id=1246315 * https://bugzilla.suse.com/show_bug.cgi?id=1247544 * https://bugzilla.suse.com/show_bug.cgi?id=1247722 * https://bugzilla.suse.com/show_bug.cgi?id=1248783 * https://bugzilla.suse.com/show_bug.cgi?id=1249041 * https://bugzilla.suse.com/show_bug.cgi?id=1249425 * https://bugzilla.suse.com/show_bug.cgi?id=1250561 * https://bugzilla.suse.com/show_bug.cgi?id=1251865 * https://bugzilla.suse.com/show_bug.cgi?id=1251995 * https://bugzilla.suse.com/show_bug.cgi?id=1252098 * https://bugzilla.suse.com/show_bug.cgi?id=1252388 * https://bugzilla.suse.com/show_bug.cgi?id=1252638 *https://bugzilla.suse.com/show_bug.cgi?id=1252665 * https://bugzilla.suse.com/show_bug.cgi?id=1252908 * https://bugzilla.suse.com/show_bug.cgi?id=1252937 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1253197 * https://bugzilla.suse.com/show_bug.cgi?id=1253249 * https://bugzilla.suse.com/show_bug.cgi?id=1253285 * https://bugzilla.suse.com/show_bug.cgi?id=1253322 * https://bugzilla.suse.com/show_bug.cgi?id=1253501 * https://bugzilla.suse.com/show_bug.cgi?id=1253659 * https://bugzilla.suse.com/show_bug.cgi?id=1253660 * https://bugzilla.suse.com/show_bug.cgi?id=1253711 * https://bugzilla.suse.com/show_bug.cgi?id=1253712 * https://bugzilla.suse.com/show_bug.cgi?id=1253773 * https://bugzilla.suse.com/show_bug.cgi?id=1254251 * https://bugzilla.suse.com/show_bug.cgi?id=1255089 * https://bugzilla.suse.com/show_bug.cgi?id=1255176 * https://bugzilla.suse.com/show_bug.cgi?id=1255298 * https://bugzilla.suse.com/show_bug.cgi?id=1255634 * https://bugzilla.suse.com/show_bug.cgi?id=1255653 * https://bugzilla.suse.com/show_bug.cgi?id=1255743 * https://bugzilla.suse.com/show_bug.cgi?id=1255857 * https://bugzilla.suse.com/show_bug.cgi?id=1256991 * https://bugzilla.suse.com/show_bug.cgi?id=1257255 * https://bugzilla.suse.com/show_bug.cgi?id=1257538 * https://bugzilla.suse.com/show_bug.cgi?id=1257992 * https://bugzilla.suse.com/show_bug.cgi?id=1259057 * https://jira.suse.com/browse/MSQA-1045 . Update for SUSE Multi-Linux Manager 5.0 addresses one important vulnerability and introduces 41 security fixes.. SUSE Multi-Linux Manager, Important Update, Security Fixes, CVE-2024-29371. . Severity: Important. LinuxSecurity.com Team
An update that solves 10 vulnerabilities can now be installed.. # chromedriver-145.0.7632.159-1.1 on GA media Announcement ID: openSUSE-SU-2026:10296-1 Rating: moderate Cross-References: * CVE-2026-3536 * CVE-2026-3537 * CVE-2026-3538 * CVE-2026-3539 * CVE-2026-3540 * CVE-2026-3541 * CVE-2026-3542 * CVE-2026-3543 * CVE-2026-3544 * CVE-2026-3545 Affected Products: * openSUSE Tumbleweed An update that solves 10 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the chromedriver-145.0.7632.159-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * chromedriver 145.0.7632.159-1.1 * chromium 145.0.7632.159-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3536.html * https://www.suse.com/security/cve/CVE-2026-3537.html * https://www.suse.com/security/cve/CVE-2026-3538.html * https://www.suse.com/security/cve/CVE-2026-3539.html * https://www.suse.com/security/cve/CVE-2026-3540.html * https://www.suse.com/security/cve/CVE-2026-3541.html * https://www.suse.com/security/cve/CVE-2026-3542.html * https://www.suse.com/security/cve/CVE-2026-3543.html * https://www.suse.com/security/cve/CVE-2026-3544.html * https://www.suse.com/security/cve/CVE-2026-3545.html . Update for openSUSE Tumbleweed resolves moderate issues in chromedriver, ensuring enhanced security and performance.. openSUSE Tumbleweed, chromedriver security update, application vulnerabilities, security management. . LinuxSecurity.com Team
Update to release v1.33.6 Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-298add9246 2025-11-24 01:24:44.272902+00:00 -------------------------------------------------------------------------------- Name : kubernetes1.33 Product : Fedora 43 Version : 1.33.6 Release : 1.fc43 URL : https://github.com/kubernetes/kubernetes Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Production-Grade Container Scheduling and Management. Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update to release v1.33.6 Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739 Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589 Resolves: rhbz#2412804 Upstream fixes -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 13 2025 Bradley G Smith - 1.33.6-1 - Update to release v1.33.6 - Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 - Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 - Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 - Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478,rhbz#2410739 - Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589 - Resolves: rhbz#2412804 - Upstream fixes * Fri Oct 10 2025 Maxwell G - 1.33.5-4 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398588 - CVE-2025-47910 kubernetes1.33: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398588 [ 2 ] Bug #2398849 - CVE-2025-47910 kubernetes1.33: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398849 [ 3 ] Bug #2399250 - CVE-2025-47906 kubernetes1.33: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399250 [ 4 ] Bug #2399523 - CVE-2025-47906 kubernetes1.33: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399523 [ 5 ] Bug #2407789 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2407789 [ 6 ] Bug #2408059 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408059 [ 7 ] Bug #2408316 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408316 [ 8 ] Bug #2408610 - CVE-2025-61725 kubernetes1.33: Excessive CPU consumption in ParseAddress in net/mail [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2408610 [ 9 ] Bug #2408673 - CVE-2025-61725 kubernetes1.33: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408673 [ 10 ] Bug #2408731 - CVE-2025-61725 kubernetes1.33: Excessive CPUconsumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408731 [ 11 ] Bug #2409238 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2409238 [ 12 ] Bug #2409528 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409528 [ 13 ] Bug #2409789 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409789 [ 14 ] Bug #2410203 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2410203 [ 15 ] Bug #2410478 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410478 [ 16 ] Bug #2410739 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410739 [ 17 ] Bug #2411118 - CVE-2025-58188 kubernetes1.33: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2411118 [ 18 ] Bug #2411377 - CVE-2025-58188 kubernetes1.33: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411377 [ 19 ] Bug #2412570 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2412570 [ 20 ] Bug #2412589 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412589 [ 21 ] Bug #2412804 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412804 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-298add9246' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5a4555eabc 2025-11-22 01:28:46.754123+00:00 -------------------------------------------------------------------------------- Name : kubernetes1.31 Product : Fedora 43 Version : 1.31.14 Release : 1.fc43 URL : https://github.com/kubernetes/kubernetes Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Production-Grade Container Scheduling and Management. Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201 Resolves: rhbz#2410476, rhbz#2410737, rhbz#2411116, rhbz#2411375 Resolves: rhbz#2411633, rhbz#2412568, rhbz#2412587, rhbz#2412802 Upstream fixes. Likely last release of Kubernetes 1.31 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 12 2025 Bradley G Smith - 1.31.14-1 - Update to release v1.31.14 - Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 - Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 - Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 -Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201 - Resolves: rhbz#2410476, rhbz#2410737, rhbz#2411116, rhbz#2411375 - Resolves: rhbz#2411633, rhbz#2412568, rhbz#2412587, rhbz#2412802 - Upstream fixes. - Likely last release of Kubernetes 1.31 * Fri Oct 10 2025 Alejandro Sez - 1.31.13-2 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398586 - CVE-2025-47910 kubernetes1.31: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398586 [ 2 ] Bug #2398847 - CVE-2025-47910 kubernetes1.31: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398847 [ 3 ] Bug #2399248 - CVE-2025-47906 kubernetes1.31: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399248 [ 4 ] Bug #2399521 - CVE-2025-47906 kubernetes1.31: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399521 [ 5 ] Bug #2399702 - CVE-2025-11065 kubernetes1.31: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399702 [ 6 ] Bug #2399720 - CVE-2025-11065 kubernetes1.31: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399720 [ 7 ] Bug #2407787 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2407787 [ 8 ] Bug #2408057 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408057 [ 9 ] Bug #2408314 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation errorcontains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408314 [ 10 ] Bug #2408608 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2408608 [ 11 ] Bug #2408671 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408671 [ 12 ] Bug #2408729 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408729 [ 13 ] Bug #2409236 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2409236 [ 14 ] Bug #2409526 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409526 [ 15 ] Bug #2409787 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409787 [ 16 ] Bug #2410201 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2410201 [ 17 ] Bug #2410476 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410476 [ 18 ] Bug #2410737 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410737 [ 19 ] Bug #2411116 - CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2411116 [ 20 ] Bug #2411375 -CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411375 [ 21 ] Bug #2411633 - CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411633 [ 22 ] Bug #2412568 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2412568 [ 23 ] Bug #2412587 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412587 [ 24 ] Bug #2412802 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412802 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5a4555eabc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Kubernetes 1.31.14 resolves critical issues in Fedora 43, ensuring stable container management and scheduling.. Kubernetes update, Fedora security, container management. . Severity: Critical. LinuxSecurity.com Team
Update to 1.10.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-21b93506d5 2025-11-15 00:51:07.993138+00:00 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 43 Version : 1.10.7 Release : 1.fc43 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.10.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 6 2025 Mikel Olasagasti Uranga - 1.10.7-1 - Update to 1.10.7 - Closes rhbz#2413156 * Fri Oct 10 2025 Alejandro Sez - 1.10.6-2 - rebuild * Thu Sep 4 2025 Mikel Olasagasti Uranga - 1.10.6-1 - Update to 1.10.6 - Closes rhbz#2385775 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-21b93506d5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . OpenTofu version 1.10.7 released for Fedora 43, enhancing your cloud infrastructure management capabilities. Update now!. Fedora opentofu cloud management update. . Severity: Informational. LinuxSecurity.com Team
* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References: . # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2025:1524-1 Release Date: 2025-05-09T11:29:11Z Rating: important References: * bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References: * CVE-2025-21587 * CVE-2025-30691 * CVE-2025-30698 CVSS scores: * CVE-2025-21587 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-21587 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-21587 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-30691 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-30691 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30691 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30698 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-30698 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-30698 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u452 (icedtea-3.35.0) Security issues fixed: * CVE-2025-21587: unauthorized creation, deletion or modification of critical data through the JSSE component. (bsc#1241274) * CVE-2025-30691: unauthorized update, insert or delete access to a subset of Oracle Java SE data through the Compiler component. (bsc#1241275) * CVE-2025-30698: unauthorized access to Oracle Java SE data and unauthorized ability to cause partialDoS through the 2D component. (bsc#1241276) Non-security issues fixed: * JDK-8212096: javax/net/ssl/ServerName/SSLEngineExplorerMatchedSNI.java failed intermittently due to SSLException: Tag mismatch. * JDK-8261020: wrong format parameter in create_emergency_chunk_path. * JDK-8266881: enable debug log for SSLEngineExplorerMatchedSNI.java. * JDK-8268457: XML Transformer outputs Unicode supplementary character incorrectly to HTML. * JDK-8309841: Jarsigner should print a warning if an entry is removed. * JDK-8337494: clarify JarInputStream behavior. * JDK-8339637: (tz) update Timezone Data to 2024b. * JDK-8339644: improve parsing of Day/Month in tzdata rules * JDK-8339810: clean up the code in sun.tools.jar.Main to properly close resources and use ZipFile during extract. * JDK-8340552: harden TzdbZoneRulesCompiler against missing zone names. * JDK-8342562: enhance Deflater operations. * JDK-8346587: distrust TLS server certificates anchored by Camerfirma Root CAs. * JDK-8347847: enhance jar file support. * JDK-8347965: (tz) update Timezone Data to 2025a. * JDK-8348211: [8u] sun/management/jmxremote/startstop/JMXStartStopTest.java fails after backport of JDK-8066708. * JDK-8350816: [8u] update TzdbZoneRulesCompiler to ignore HST/EST/MST links. * JDK-8352097: (tz) zone.tab update missed in 2025a backport. * JDK-8353433: XCG currency code not recognized in JDK 8u. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1524=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1524=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) *java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-demo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-demo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21587.html * https://www.suse.com/security/cve/CVE-2025-30691.html * https://www.suse.com/security/cve/CVE-2025-30698.html * https://bugzilla.suse.com/show_bug.cgi?id=1241274 * https://bugzilla.suse.com/show_bug.cgi?id=1241275 * https://bugzilla.suse.com/show_bug.cgi?id=1241276 . Crucial security patch available for Java in SUSE addressing severe vulnerabilities in various modules.. Java Security, SUSE Update, Security Patch, Data Access Issues, DoS Protections. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1262 http://linux.oracle.com/errata/ELSA-2025-1262.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.4.0-503.23.2.el9_5.x86_64.rpm kernel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-abi-stablelists-5.14.0-503.23.2.el9_5.noarch.rpm kernel-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-devel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-devel-matched-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-extra-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-uki-virt-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-devel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-devel-matched-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-doc-5.14.0-503.23.2.el9_5.noarch.rpm kernel-headers-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-extra-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-libs-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-uki-virt-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-uki-virt-addons-5.14.0-503.23.2.el9_5.x86_64.rpm perf-5.14.0-503.23.2.el9_5.x86_64.rpm python3-perf-5.14.0-503.23.2.el9_5.x86_64.rpm rtla-5.14.0-503.23.2.el9_5.x86_64.rpm rv-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-cross-headers-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-libs-devel-5.14.0-503.23.2.el9_5.x86_64.rpm libperf-5.14.0-503.23.2.el9_5.x86_64.rpm aarch64: bpftool-7.4.0-503.23.2.el9_5.aarch64.rpm kernel-headers-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-libs-5.14.0-503.23.2.el9_5.aarch64.rpm perf-5.14.0-503.23.2.el9_5.aarch64.rpm python3-perf-5.14.0-503.23.2.el9_5.aarch64.rpm rtla-5.14.0-503.23.2.el9_5.aarch64.rpm rv-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-cross-headers-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-libs-devel-5.14.0-503.23.2.el9_5.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//kernel-5.14.0-503.23.2.el9_5.src.rpm Related CVEs: CVE-2024-53104 Description of changes: - [5.14.0-503.23.2.el9_5.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
An update for openssl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openssl security update Advisory ID: RHSA-2023:1437-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1437 Issue date: 2023-03-23 CVE Names: CVE-2023-0286 ==================================================================== 1. Summary: An update for openssl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed(https://bugzilla.redhat.com/): 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName 6. Package List: Red Hat Enterprise Linux BaseOS E4S (v. 8.1): Source: openssl-1.1.1c-6.el8_1.src.rpm aarch64: openssl-1.1.1c-6.el8_1.aarch64.rpm openssl-debuginfo-1.1.1c-6.el8_1.aarch64.rpm openssl-debugsource-1.1.1c-6.el8_1.aarch64.rpm openssl-devel-1.1.1c-6.el8_1.aarch64.rpm openssl-libs-1.1.1c-6.el8_1.aarch64.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.aarch64.rpm openssl-perl-1.1.1c-6.el8_1.aarch64.rpm ppc64le: openssl-1.1.1c-6.el8_1.ppc64le.rpm openssl-debuginfo-1.1.1c-6.el8_1.ppc64le.rpm openssl-debugsource-1.1.1c-6.el8_1.ppc64le.rpm openssl-devel-1.1.1c-6.el8_1.ppc64le.rpm openssl-libs-1.1.1c-6.el8_1.ppc64le.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.ppc64le.rpm openssl-perl-1.1.1c-6.el8_1.ppc64le.rpm s390x: openssl-1.1.1c-6.el8_1.s390x.rpm openssl-debuginfo-1.1.1c-6.el8_1.s390x.rpm openssl-debugsource-1.1.1c-6.el8_1.s390x.rpm openssl-devel-1.1.1c-6.el8_1.s390x.rpm openssl-libs-1.1.1c-6.el8_1.s390x.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.s390x.rpm openssl-perl-1.1.1c-6.el8_1.s390x.rpm x86_64: openssl-1.1.1c-6.el8_1.x86_64.rpm openssl-debuginfo-1.1.1c-6.el8_1.i686.rpm openssl-debuginfo-1.1.1c-6.el8_1.x86_64.rpm openssl-debugsource-1.1.1c-6.el8_1.i686.rpm openssl-debugsource-1.1.1c-6.el8_1.x86_64.rpm openssl-devel-1.1.1c-6.el8_1.i686.rpm openssl-devel-1.1.1c-6.el8_1.x86_64.rpm openssl-libs-1.1.1c-6.el8_1.i686.rpm openssl-libs-1.1.1c-6.el8_1.x86_64.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.i686.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.x86_64.rpm openssl-perl-1.1.1c-6.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZBxs7dzjgjWX9erEAQj2fBAAonoENVQK1z0o1faaI5kJcpcjudplrNTx CWn5Q1bA7ZOU+8F4kocdGWUHfF7IIFHmcV/bfkz0pyOEx14pHdi4gbfp7DHMg+vh TnJBtCqCJVGWmoDu4qUzm81w96lSgRTFweoMdk8DZL8GBfPF7ZW4q46A8oBCxkXC jQ1gAhHZEfeDKCSsQ+JJvtjSZdAKCf3iDimy6FMFHDLg9hqXns+UXZ+7mJD3UpLP gqfzM8a1+YonxtC1piovlY7KaWV7EpgufVCzILjwXiLeKivfUo4SGDdw+fsv5rzr ex1qOKg9mucu3nq5eoZaOomtrvhFW9P8igS1aZVWNcdhv/nbYBkhUZ04U9wwnOru t5936OJzyl5gQxKTA3RCX45z4qs6TUE07DB4LYSrmXj1yQXZcwahJIB5/N63ttbn pqt04m9xLybFsn2+8TCOiBwfZUkrKsoepjBVrqcC05yfL41fsoZao7ZwLSiptByZ UO5Xy4wUQjOIRCqUkquE2GidOhVdIvQhrjOj2tsaW3vHSXsYLICBxru5fOTKsNdz fKdIDy0S62gU2QQeSWBukCIZTnWw7sfxWZJ1p4M//JgbA5njA59iBTv+zNSQ93pr I/GPiwNZInjgIWFPaUkrvn0O5VejKPb+i6Mz5ACd8GJPWOFxjxDCbnarqAlaMi7D s7TQu68jDN4=cfEA -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.