Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
100

SUSE Multi-Linux Manager 5.0 Important Update for CVE-2024-29371

An update that solves one vulnerability, contains one feature and has 41 security fixes can now be installed.. # Maintenance update for Multi-Linux Manager 5.0: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:1010-1 Release Date: 2026-03-25T10:10:03Z Rating: important References: * bsc#1220899 * bsc#1237181 * bsc#1244177 * bsc#1246315 * bsc#1247544 * bsc#1247722 * bsc#1248783 * bsc#1249041 * bsc#1249425 * bsc#1250561 * bsc#1251865 * bsc#1251995 * bsc#1252098 * bsc#1252388 * bsc#1252638 * bsc#1252665 * bsc#1252908 * bsc#1252937 * bsc#1253174 * bsc#1253197 * bsc#1253249 * bsc#1253285 * bsc#1253322 * bsc#1253501 * bsc#1253659 * bsc#1253660 * bsc#1253711 * bsc#1253712 * bsc#1253773 * bsc#1254251 * bsc#1255089 * bsc#1255176 * bsc#1255298 * bsc#1255634 * bsc#1255653 * bsc#1255743 * bsc#1255857 * bsc#1256991 * bsc#1257255 * bsc#1257538 * bsc#1257992 * bsc#1259057 * jsc#MSQA-1045 Cross-References: * CVE-2024-29371 CVSS scores: * CVE-2024-29371 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-29371 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-29371 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Manager Proxy 5.0 Extension * SUSE Manager Retail Branch Server 5.0 Extension * SUSE Manager Server 5.0 Extension An update that solves one vulnerability, contains one feature and has 41 security fixes can now be installed. ## Security update 5.0.7 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to arotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars * use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 * Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons(bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir (bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list of supported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size of column 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Security update 5.0.7 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to a rotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars * use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 *Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons (bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir (bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list ofsupported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size of column 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Security update 5.0.7 for Multi-Linux Manager Server ### Description: This update fixes the following issues: branch-network-formula: * Update to version 1.1.0 * Enable containers on SLE15SP7 * Exclude podman interfaces from sysctl setting cobbler: * Compatibility fixes for tftpboot directory setup inter-server-sync: * Version 0.3.10-0 * Write log to a rotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars *use correct hostname detection for 5.x servers (bsc#1253322) jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.2 * Add option to prevent logo packages from being installed spacecmd: * Version 5.0.15-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Convert cached IDs to int (bsc#1251995) * Fix spacecmd binary file upload (bsc#1253659) spacewalk-backend: * Version 5.0.17-0 * Fix reposync mediaproduct fetch when URL contains auth token (bsc#1252388) spacewalk-certs-tools: * Version 5.0.13-0 * Fix bootstrap script for SLM 6.2 (bsc#1257992) * Fix failing bootstrap with bootstrap script on SLES 16 and SL Micro 6.2 (bsc#1256991) spacewalk-client-tools: * Version 5.0.12-0 * Update translation strings spacewalk-config: * Version 5.0.9-0 * Enable HSTS in Apache config (bsc#1255176) * Force SameSite=Lax on all Set-Cookie headers (bsc#1253711) spacewalk-java: * Version 5.0.31-0 * Commit DB changes before refreshing pillar for SSH push minions (bsc#1253712) * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Fix crash in ubuntu errata sync on deleted channel ids (bsc#1250561) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Add details on config channels and state order in UI (bsc#1253285) * fix reposync crashing at metadata generation (bsc#1257538) * Block multiple versions of the same package from being locked (bsc#1246315) * Use PackageEvr instead of string for fix_version (bsc#1252638) * Add multi-thread support for message queue (bsc#1247722) * Fix ungrouped systems list menu item (bsc#1254251) spacewalk-proxy: * Version 5.0.8-0 * Disable listing the content of /icons (bsc#1247544) spacewalk-proxy-installer: * Version 5.0.3-0 * Configure squid replacement policy properly before cache dir(bsc#1253773) spacewalk-web: * Version 5.0.26-0 * Update web UI dependencies * Add details on config channels and state order in UI (bsc#1253285) susemanager: * Version 5.0.17-0 * Fix the product ids of client tools channels * Fixed the package name to correct one (bsc#1255089) susemanager-build-keys: * Add openSUSE Backports for SUSE Linux 16 key (bsc#1257255) susemanager-docs_en: * Updated the screenshots in multiple sections in Installation and Upgrade Guide * Reformatted storage-scripts table to use plain paragraphs instead of bullet lists to fix po4a extraction issue causing missing bullets in CJK translations * Added a warning for all instances where mgradm upgrade podman is used * Added section about container-based Kiwi image build support to Administration guide (bsc#1251865) * Included global GPG decryption for pillar data in specialized guide (bsc#1255743) * CIS removed from list of supported OpenSCAP profiles * Changes example for the third-party repository GPG keys (bsc#1255857) * Added SLE16 and openSUSE Leap 16 as supported clients * Explained how to generate the proxy certificates on a peripheral server (bsc#1249425) * Improved procedure formatting for better clarity in Administration Guide (bsc#1253660) * Added links to man pages for createrepo_c and reprepro to Administration Guide (bsc#1237181) * Added missing options to command example in Installation and Upgrade Guide (bsc#1252908) * Added non-SUSE URLs to requirements in installation and Upgrade Guide (bsc#1252665) * Fixed typo for command options in Reference Guide (bsc#1253174) * Added additional step for client deletion in Client Configuration Guide (bsc#1253249) * Clarified server config option for spacemd in Refrence Guide (bsc#1253197) * Changed the installation instructions to use product instead of packages (bsc#1249041) susemanager-schema: * Version 5.0.18-0 * Refactor oval related tables (bsc#1252638) * Increase size ofcolumn 'context' on tables 'suseappstream' and 'suseserverappstream' (bsc#1255653) * Add leftovers of partially missing ARMHF for Debian (bsc#1248783) susemanager-sls: * Version 5.0.21-0 * Fix error on shutdown for sles 12 (bsc#1255634) * Fix bootstrap for SLM 6.2 and newer (bsc#1257992) * Make mgr_events salt engine non-blocking on reading events * Avoid losing the events on DB connection issues (bsc#1252098) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Proxy 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Proxy-5.0-2026-1010=1 * SUSE Manager Retail Branch Server 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Retail-Branch-Server-5.0-2026-1010=1 * SUSE Manager Server 5.0 Extension zypper in -t patch SUSE-SUSE-Manager-Server-5.0-2026-1010=1 ## Package List: * SUSE Manager Proxy 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-aarch64-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-aarch64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-aarch64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-aarch64-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-ppc64le-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-ppc64le-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-ppc64le-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-ppc64le-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (s390x) * suse-manager-5.0-s390x-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-s390x-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-s390x-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-s390x-proxy-salt-broker-image-5.0.7-7.32.15 *suse-manager-5.0-s390x-proxy-ssh-image-5.0.7-7.30.5 * SUSE Manager Proxy 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-x86_64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-x86_64-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-httpd-image-5.0.7-7.30.13 * SUSE Manager Retail Branch Server 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-aarch64-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-aarch64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-aarch64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-aarch64-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-ppc64le-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-ppc64le-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-ppc64le-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-ppc64le-proxy-tftpd-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (s390x) * suse-manager-5.0-s390x-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-s390x-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-s390x-proxy-httpd-image-5.0.7-7.30.13 * suse-manager-5.0-s390x-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-s390x-proxy-ssh-image-5.0.7-7.30.5 * SUSE Manager Retail Branch Server 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-proxy-squid-image-5.0.7-7.30.6 * suse-manager-5.0-x86_64-proxy-ssh-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-salt-broker-image-5.0.7-7.32.15 * suse-manager-5.0-x86_64-proxy-tftpd-image-5.0.7-7.30.5 * suse-manager-5.0-x86_64-proxy-httpd-image-5.0.7-7.30.13 * SUSE Manager Server 5.0 Extension (aarch64) * suse-manager-5.0-aarch64-server-hub-xmlrpc-api-image-5.0.7-6.30.7 *suse-manager-5.0-aarch64-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-aarch64-server-image-5.0.7-7.37.12 * suse-manager-5.0-aarch64-server-migration-14-16-image-5.0.7-7.30.7 * SUSE Manager Server 5.0 Extension (ppc64le) * suse-manager-5.0-ppc64le-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-ppc64le-server-image-5.0.7-7.37.12 * suse-manager-5.0-ppc64le-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-ppc64le-server-hub-xmlrpc-api-image-5.0.7-6.30.7 * SUSE Manager Server 5.0 Extension (s390x) * suse-manager-5.0-s390x-server-image-5.0.7-7.37.12 * suse-manager-5.0-s390x-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-s390x-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-s390x-server-hub-xmlrpc-api-image-5.0.7-6.30.7 * SUSE Manager Server 5.0 Extension (x86_64) * suse-manager-5.0-x86_64-server-image-5.0.7-7.37.12 * suse-manager-5.0-x86_64-server-migration-14-16-image-5.0.7-7.30.7 * suse-manager-5.0-x86_64-server-attestation-image-5.0.7-6.34.5 * suse-manager-5.0-x86_64-server-hub-xmlrpc-api-image-5.0.7-6.30.7 ## References: * https://www.suse.com/security/cve/CVE-2024-29371.html * https://bugzilla.suse.com/show_bug.cgi?id=1220899 * https://bugzilla.suse.com/show_bug.cgi?id=1237181 * https://bugzilla.suse.com/show_bug.cgi?id=1244177 * https://bugzilla.suse.com/show_bug.cgi?id=1246315 * https://bugzilla.suse.com/show_bug.cgi?id=1247544 * https://bugzilla.suse.com/show_bug.cgi?id=1247722 * https://bugzilla.suse.com/show_bug.cgi?id=1248783 * https://bugzilla.suse.com/show_bug.cgi?id=1249041 * https://bugzilla.suse.com/show_bug.cgi?id=1249425 * https://bugzilla.suse.com/show_bug.cgi?id=1250561 * https://bugzilla.suse.com/show_bug.cgi?id=1251865 * https://bugzilla.suse.com/show_bug.cgi?id=1251995 * https://bugzilla.suse.com/show_bug.cgi?id=1252098 * https://bugzilla.suse.com/show_bug.cgi?id=1252388 * https://bugzilla.suse.com/show_bug.cgi?id=1252638 *https://bugzilla.suse.com/show_bug.cgi?id=1252665 * https://bugzilla.suse.com/show_bug.cgi?id=1252908 * https://bugzilla.suse.com/show_bug.cgi?id=1252937 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1253197 * https://bugzilla.suse.com/show_bug.cgi?id=1253249 * https://bugzilla.suse.com/show_bug.cgi?id=1253285 * https://bugzilla.suse.com/show_bug.cgi?id=1253322 * https://bugzilla.suse.com/show_bug.cgi?id=1253501 * https://bugzilla.suse.com/show_bug.cgi?id=1253659 * https://bugzilla.suse.com/show_bug.cgi?id=1253660 * https://bugzilla.suse.com/show_bug.cgi?id=1253711 * https://bugzilla.suse.com/show_bug.cgi?id=1253712 * https://bugzilla.suse.com/show_bug.cgi?id=1253773 * https://bugzilla.suse.com/show_bug.cgi?id=1254251 * https://bugzilla.suse.com/show_bug.cgi?id=1255089 * https://bugzilla.suse.com/show_bug.cgi?id=1255176 * https://bugzilla.suse.com/show_bug.cgi?id=1255298 * https://bugzilla.suse.com/show_bug.cgi?id=1255634 * https://bugzilla.suse.com/show_bug.cgi?id=1255653 * https://bugzilla.suse.com/show_bug.cgi?id=1255743 * https://bugzilla.suse.com/show_bug.cgi?id=1255857 * https://bugzilla.suse.com/show_bug.cgi?id=1256991 * https://bugzilla.suse.com/show_bug.cgi?id=1257255 * https://bugzilla.suse.com/show_bug.cgi?id=1257538 * https://bugzilla.suse.com/show_bug.cgi?id=1257992 * https://bugzilla.suse.com/show_bug.cgi?id=1259057 * https://jira.suse.com/browse/MSQA-1045 . Update for SUSE Multi-Linux Manager 5.0 addresses one important vulnerability and introduces 41 security fixes.. SUSE Multi-Linux Manager, Important Update, Security Fixes, CVE-2024-29371. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2026 Important SuSE
202

openSUSE Tumbleweed chromedriver Moderate Vulnerabilities 2026-10296-1

An update that solves 10 vulnerabilities can now be installed.. # chromedriver-145.0.7632.159-1.1 on GA media Announcement ID: openSUSE-SU-2026:10296-1 Rating: moderate Cross-References: * CVE-2026-3536 * CVE-2026-3537 * CVE-2026-3538 * CVE-2026-3539 * CVE-2026-3540 * CVE-2026-3541 * CVE-2026-3542 * CVE-2026-3543 * CVE-2026-3544 * CVE-2026-3545 Affected Products: * openSUSE Tumbleweed An update that solves 10 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the chromedriver-145.0.7632.159-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * chromedriver 145.0.7632.159-1.1 * chromium 145.0.7632.159-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3536.html * https://www.suse.com/security/cve/CVE-2026-3537.html * https://www.suse.com/security/cve/CVE-2026-3538.html * https://www.suse.com/security/cve/CVE-2026-3539.html * https://www.suse.com/security/cve/CVE-2026-3540.html * https://www.suse.com/security/cve/CVE-2026-3541.html * https://www.suse.com/security/cve/CVE-2026-3542.html * https://www.suse.com/security/cve/CVE-2026-3543.html * https://www.suse.com/security/cve/CVE-2026-3544.html * https://www.suse.com/security/cve/CVE-2026-3545.html . Update for openSUSE Tumbleweed resolves moderate issues in chromedriver, ensuring enhanced security and performance.. openSUSE Tumbleweed, chromedriver security update, application vulnerabilities, security management. . LinuxSecurity.com Team

Calendar%202 Mar 08, 2026 OpenSUSE
89

Fedora 43: kubernetes1.33 Important Security Update 2025-298add9246

Update to release v1.33.6 Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-298add9246 2025-11-24 01:24:44.272902+00:00 -------------------------------------------------------------------------------- Name : kubernetes1.33 Product : Fedora 43 Version : 1.33.6 Release : 1.fc43 URL : https://github.com/kubernetes/kubernetes Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Production-Grade Container Scheduling and Management. Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update to release v1.33.6 Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478, rhbz#2410739 Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589 Resolves: rhbz#2412804 Upstream fixes -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 13 2025 Bradley G Smith - 1.33.6-1 - Update to release v1.33.6 - Resolves: rhbz#2398588, rhbz#2398849, rhbz#2399250, rhbz#2399523 - Resolves: rhbz#2407789, rhbz#2408059, rhbz#2408316, rhbz#2408610 - Resolves: rhbz#2408673, rhbz#2408731, rhbz#2409238, rhbz#2409528 - Resolves: rhbz#2409789, rhbz#2410203, rhbz#2410478,rhbz#2410739 - Resolves: rhbz#2411118, rhbz#2411377, rhbz#2412570, rhbz#2412589 - Resolves: rhbz#2412804 - Upstream fixes * Fri Oct 10 2025 Maxwell G - 1.33.5-4 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398588 - CVE-2025-47910 kubernetes1.33: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398588 [ 2 ] Bug #2398849 - CVE-2025-47910 kubernetes1.33: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398849 [ 3 ] Bug #2399250 - CVE-2025-47906 kubernetes1.33: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399250 [ 4 ] Bug #2399523 - CVE-2025-47906 kubernetes1.33: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399523 [ 5 ] Bug #2407789 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2407789 [ 6 ] Bug #2408059 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408059 [ 7 ] Bug #2408316 - CVE-2025-58189 kubernetes1.33: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408316 [ 8 ] Bug #2408610 - CVE-2025-61725 kubernetes1.33: Excessive CPU consumption in ParseAddress in net/mail [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2408610 [ 9 ] Bug #2408673 - CVE-2025-61725 kubernetes1.33: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408673 [ 10 ] Bug #2408731 - CVE-2025-61725 kubernetes1.33: Excessive CPUconsumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408731 [ 11 ] Bug #2409238 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2409238 [ 12 ] Bug #2409528 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409528 [ 13 ] Bug #2409789 - CVE-2025-61723 kubernetes1.33: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409789 [ 14 ] Bug #2410203 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2410203 [ 15 ] Bug #2410478 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410478 [ 16 ] Bug #2410739 - CVE-2025-58185 kubernetes1.33: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410739 [ 17 ] Bug #2411118 - CVE-2025-58188 kubernetes1.33: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2411118 [ 18 ] Bug #2411377 - CVE-2025-58188 kubernetes1.33: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411377 [ 19 ] Bug #2412570 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2412570 [ 20 ] Bug #2412589 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412589 [ 21 ] Bug #2412804 - CVE-2025-58183 kubernetes1.33: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412804 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-298add9246' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Critical updates for kubernetes in Fedora 43 resolve multiple security issues and enhance performance of container applications.. kubernetes Fedora updates container scheduling security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 24, 2025 Important Fedora
89

Fedora 43: Critical Update for Kubernetes 1.31 Scheduling Issues

Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5a4555eabc 2025-11-22 01:28:46.754123+00:00 -------------------------------------------------------------------------------- Name : kubernetes1.31 Product : Fedora 43 Version : 1.31.14 Release : 1.fc43 URL : https://github.com/kubernetes/kubernetes Summary : Open Source Production-Grade Container Scheduling And Management Platform Description : Production-Grade Container Scheduling and Management. Installs kubelet, the kubernetes agent on each machine in a cluster. The kubernetes-client sub-package, containing kubectl, is recommended but not strictly required. The kubernetes-client sub-package should be installed on control plane machines. -------------------------------------------------------------------------------- Update Information: Update to release v1.31.14 Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201 Resolves: rhbz#2410476, rhbz#2410737, rhbz#2411116, rhbz#2411375 Resolves: rhbz#2411633, rhbz#2412568, rhbz#2412587, rhbz#2412802 Upstream fixes. Likely last release of Kubernetes 1.31 -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 12 2025 Bradley G Smith - 1.31.14-1 - Update to release v1.31.14 - Resolves: rhbz#2398586, rhbz#2398847, rhbz#2399248, rhbz#2399521 - Resolves: rhbz#2399702, rhbz#2399720, rhbz#2407787, rhbz#2408057 - Resolves: rhbz#2408314, rhbz#2408608, rhbz#2408671, rhbz#2408729 -Resolves: rhbz#2409236, rhbz#2409526, rhbz#2409787, rhbz#2410201 - Resolves: rhbz#2410476, rhbz#2410737, rhbz#2411116, rhbz#2411375 - Resolves: rhbz#2411633, rhbz#2412568, rhbz#2412587, rhbz#2412802 - Upstream fixes. - Likely last release of Kubernetes 1.31 * Fri Oct 10 2025 Alejandro Sez - 1.31.13-2 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398586 - CVE-2025-47910 kubernetes1.31: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398586 [ 2 ] Bug #2398847 - CVE-2025-47910 kubernetes1.31: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398847 [ 3 ] Bug #2399248 - CVE-2025-47906 kubernetes1.31: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399248 [ 4 ] Bug #2399521 - CVE-2025-47906 kubernetes1.31: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399521 [ 5 ] Bug #2399702 - CVE-2025-11065 kubernetes1.31: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399702 [ 6 ] Bug #2399720 - CVE-2025-11065 kubernetes1.31: Go-viper's mapstructure May Leak Sensitive Information in Logs in github.com/go-viper/mapstructure [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399720 [ 7 ] Bug #2407787 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2407787 [ 8 ] Bug #2408057 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408057 [ 9 ] Bug #2408314 - CVE-2025-58189 kubernetes1.31: go crypto/tls ALPN negotiation errorcontains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408314 [ 10 ] Bug #2408608 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2408608 [ 11 ] Bug #2408671 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408671 [ 12 ] Bug #2408729 - CVE-2025-61725 kubernetes1.31: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408729 [ 13 ] Bug #2409236 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2409236 [ 14 ] Bug #2409526 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409526 [ 15 ] Bug #2409787 - CVE-2025-61723 kubernetes1.31: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409787 [ 16 ] Bug #2410201 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2410201 [ 17 ] Bug #2410476 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410476 [ 18 ] Bug #2410737 - CVE-2025-58185 kubernetes1.31: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410737 [ 19 ] Bug #2411116 - CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2411116 [ 20 ] Bug #2411375 -CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411375 [ 21 ] Bug #2411633 - CVE-2025-58188 kubernetes1.31: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411633 [ 22 ] Bug #2412568 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2412568 [ 23 ] Bug #2412587 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412587 [ 24 ] Bug #2412802 - CVE-2025-58183 kubernetes1.31: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412802 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5a4555eabc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Kubernetes 1.31.14 resolves critical issues in Fedora 43, ensuring stable container management and scheduling.. Kubernetes update, Fedora security, container management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 22, 2025 Critical Fedora
89

Fedora 43: opentofu Update 1.10.7 Advisory FEDORA-2025-21b93506d5

Update to 1.10.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-21b93506d5 2025-11-15 00:51:07.993138+00:00 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 43 Version : 1.10.7 Release : 1.fc43 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.10.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 6 2025 Mikel Olasagasti Uranga - 1.10.7-1 - Update to 1.10.7 - Closes rhbz#2413156 * Fri Oct 10 2025 Alejandro Sez - 1.10.6-2 - rebuild * Thu Sep 4 2025 Mikel Olasagasti Uranga - 1.10.6-1 - Update to 1.10.6 - Closes rhbz#2385775 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-21b93506d5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . OpenTofu version 1.10.7 released for Fedora 43, enhancing your cloud infrastructure management capabilities. Update now!. Fedora opentofu cloud management update. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Nov 15, 2025 Informational Fedora
100

SUSE Linux 12 SP5: 2025:1524-1 important: java-1_8_0-openjdk

* bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References: . # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2025:1524-1 Release Date: 2025-05-09T11:29:11Z Rating: important References: * bsc#1241274 * bsc#1241275 * bsc#1241276 Cross-References: * CVE-2025-21587 * CVE-2025-30691 * CVE-2025-30698 CVSS scores: * CVE-2025-21587 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-21587 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-21587 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-30691 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-30691 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30691 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-30698 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-30698 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-30698 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u452 (icedtea-3.35.0) Security issues fixed: * CVE-2025-21587: unauthorized creation, deletion or modification of critical data through the JSSE component. (bsc#1241274) * CVE-2025-30691: unauthorized update, insert or delete access to a subset of Oracle Java SE data through the Compiler component. (bsc#1241275) * CVE-2025-30698: unauthorized access to Oracle Java SE data and unauthorized ability to cause partialDoS through the 2D component. (bsc#1241276) Non-security issues fixed: * JDK-8212096: javax/net/ssl/ServerName/SSLEngineExplorerMatchedSNI.java failed intermittently due to SSLException: Tag mismatch. * JDK-8261020: wrong format parameter in create_emergency_chunk_path. * JDK-8266881: enable debug log for SSLEngineExplorerMatchedSNI.java. * JDK-8268457: XML Transformer outputs Unicode supplementary character incorrectly to HTML. * JDK-8309841: Jarsigner should print a warning if an entry is removed. * JDK-8337494: clarify JarInputStream behavior. * JDK-8339637: (tz) update Timezone Data to 2024b. * JDK-8339644: improve parsing of Day/Month in tzdata rules * JDK-8339810: clean up the code in sun.tools.jar.Main to properly close resources and use ZipFile during extract. * JDK-8340552: harden TzdbZoneRulesCompiler against missing zone names. * JDK-8342562: enhance Deflater operations. * JDK-8346587: distrust TLS server certificates anchored by Camerfirma Root CAs. * JDK-8347847: enhance jar file support. * JDK-8347965: (tz) update Timezone Data to 2025a. * JDK-8348211: [8u] sun/management/jmxremote/startstop/JMXStartStopTest.java fails after backport of JDK-8066708. * JDK-8350816: [8u] update TzdbZoneRulesCompiler to ignore HST/EST/MST links. * JDK-8352097: (tz) zone.tab update missed in 2025a backport. * JDK-8353433: XCG currency code not recognized in JDK 8u. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1524=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1524=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) *java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-demo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-1_8_0-openjdk-demo-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-demo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-1.8.0.452-27.114.1 * java-1_8_0-openjdk-devel-1.8.0.452-27.114.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.452-27.114.1 * java-1_8_0-openjdk-debugsource-1.8.0.452-27.114.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21587.html * https://www.suse.com/security/cve/CVE-2025-30691.html * https://www.suse.com/security/cve/CVE-2025-30698.html * https://bugzilla.suse.com/show_bug.cgi?id=1241274 * https://bugzilla.suse.com/show_bug.cgi?id=1241275 * https://bugzilla.suse.com/show_bug.cgi?id=1241276 . Crucial security patch available for Java in SUSE addressing severe vulnerabilities in various modules.. Java Security, SUSE Update, Security Patch, Data Access Issues, DoS Protections. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 09, 2025 Important SuSE
217

Oracle Linux 9 ELSA-2025-1262 important: kernel security update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1262 http://linux.oracle.com/errata/ELSA-2025-1262.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.4.0-503.23.2.el9_5.x86_64.rpm kernel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-abi-stablelists-5.14.0-503.23.2.el9_5.noarch.rpm kernel-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-devel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-devel-matched-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-modules-extra-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-debug-uki-virt-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-devel-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-devel-matched-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-doc-5.14.0-503.23.2.el9_5.noarch.rpm kernel-headers-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-core-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-modules-extra-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-libs-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-uki-virt-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-uki-virt-addons-5.14.0-503.23.2.el9_5.x86_64.rpm perf-5.14.0-503.23.2.el9_5.x86_64.rpm python3-perf-5.14.0-503.23.2.el9_5.x86_64.rpm rtla-5.14.0-503.23.2.el9_5.x86_64.rpm rv-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-cross-headers-5.14.0-503.23.2.el9_5.x86_64.rpm kernel-tools-libs-devel-5.14.0-503.23.2.el9_5.x86_64.rpm libperf-5.14.0-503.23.2.el9_5.x86_64.rpm aarch64: bpftool-7.4.0-503.23.2.el9_5.aarch64.rpm kernel-headers-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-libs-5.14.0-503.23.2.el9_5.aarch64.rpm perf-5.14.0-503.23.2.el9_5.aarch64.rpm python3-perf-5.14.0-503.23.2.el9_5.aarch64.rpm rtla-5.14.0-503.23.2.el9_5.aarch64.rpm rv-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-cross-headers-5.14.0-503.23.2.el9_5.aarch64.rpm kernel-tools-libs-devel-5.14.0-503.23.2.el9_5.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//kernel-5.14.0-503.23.2.el9_5.src.rpm Related CVEs: CVE-2024-53104 Description of changes: - [5.14.0-503.23.2.el9_5.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64

Calendar%202 Feb 13, 2025 Important Oracle
98

Red Hat: RHSA-2023:1437-01 Critical: OpenSSL Type Confusion

An update for openssl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openssl security update Advisory ID: RHSA-2023:1437-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1437 Issue date: 2023-03-23 CVE Names: CVE-2023-0286 ==================================================================== 1. Summary: An update for openssl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed(https://bugzilla.redhat.com/): 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName 6. Package List: Red Hat Enterprise Linux BaseOS E4S (v. 8.1): Source: openssl-1.1.1c-6.el8_1.src.rpm aarch64: openssl-1.1.1c-6.el8_1.aarch64.rpm openssl-debuginfo-1.1.1c-6.el8_1.aarch64.rpm openssl-debugsource-1.1.1c-6.el8_1.aarch64.rpm openssl-devel-1.1.1c-6.el8_1.aarch64.rpm openssl-libs-1.1.1c-6.el8_1.aarch64.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.aarch64.rpm openssl-perl-1.1.1c-6.el8_1.aarch64.rpm ppc64le: openssl-1.1.1c-6.el8_1.ppc64le.rpm openssl-debuginfo-1.1.1c-6.el8_1.ppc64le.rpm openssl-debugsource-1.1.1c-6.el8_1.ppc64le.rpm openssl-devel-1.1.1c-6.el8_1.ppc64le.rpm openssl-libs-1.1.1c-6.el8_1.ppc64le.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.ppc64le.rpm openssl-perl-1.1.1c-6.el8_1.ppc64le.rpm s390x: openssl-1.1.1c-6.el8_1.s390x.rpm openssl-debuginfo-1.1.1c-6.el8_1.s390x.rpm openssl-debugsource-1.1.1c-6.el8_1.s390x.rpm openssl-devel-1.1.1c-6.el8_1.s390x.rpm openssl-libs-1.1.1c-6.el8_1.s390x.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.s390x.rpm openssl-perl-1.1.1c-6.el8_1.s390x.rpm x86_64: openssl-1.1.1c-6.el8_1.x86_64.rpm openssl-debuginfo-1.1.1c-6.el8_1.i686.rpm openssl-debuginfo-1.1.1c-6.el8_1.x86_64.rpm openssl-debugsource-1.1.1c-6.el8_1.i686.rpm openssl-debugsource-1.1.1c-6.el8_1.x86_64.rpm openssl-devel-1.1.1c-6.el8_1.i686.rpm openssl-devel-1.1.1c-6.el8_1.x86_64.rpm openssl-libs-1.1.1c-6.el8_1.i686.rpm openssl-libs-1.1.1c-6.el8_1.x86_64.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.i686.rpm openssl-libs-debuginfo-1.1.1c-6.el8_1.x86_64.rpm openssl-perl-1.1.1c-6.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZBxs7dzjgjWX9erEAQj2fBAAonoENVQK1z0o1faaI5kJcpcjudplrNTx CWn5Q1bA7ZOU+8F4kocdGWUHfF7IIFHmcV/bfkz0pyOEx14pHdi4gbfp7DHMg+vh TnJBtCqCJVGWmoDu4qUzm81w96lSgRTFweoMdk8DZL8GBfPF7ZW4q46A8oBCxkXC jQ1gAhHZEfeDKCSsQ+JJvtjSZdAKCf3iDimy6FMFHDLg9hqXns+UXZ+7mJD3UpLP gqfzM8a1+YonxtC1piovlY7KaWV7EpgufVCzILjwXiLeKivfUo4SGDdw+fsv5rzr ex1qOKg9mucu3nq5eoZaOomtrvhFW9P8igS1aZVWNcdhv/nbYBkhUZ04U9wwnOru t5936OJzyl5gQxKTA3RCX45z4qs6TUE07DB4LYSrmXj1yQXZcwahJIB5/N63ttbn pqt04m9xLybFsn2+8TCOiBwfZUkrKsoepjBVrqcC05yfL41fsoZao7ZwLSiptByZ UO5Xy4wUQjOIRCqUkquE2GidOhVdIvQhrjOj2tsaW3vHSXsYLICBxru5fOTKsNdz fKdIDy0S62gU2QQeSWBukCIZTnWw7sfxWZJ1p4M//JgbA5njA59iBTv+zNSQ93pr I/GPiwNZInjgIWFPaUkrvn0O5VejKPb+i6Mz5ACd8GJPWOFxjxDCbnarqAlaMi7D s7TQu68jDN4=cfEA -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical patch for openssl has been released for users of Red Hat Enterprise Linux, impacting key operations.. OpenSSL Security Update, Red Hat Enterprise Linux, Security Advisory, Critical Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 23, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200