* bsc#1221242 * bsc#1221746 * bsc#1221747 Cross-References: . # Security update for gnutls Announcement ID: SUSE-SU-2025:20017-1 Release Date: 2025-02-03T08:48:39Z Rating: important References: * bsc#1221242 * bsc#1221746 * bsc#1221747 Cross-References: * CVE-2024-28834 * CVE-2024-28835 CVSS scores: * CVE-2024-28834 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-28834 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-28835 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-28835 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for gnutls fixes the following issues: * CVE-2024-28835: certtool crash when verifying a certificate chain (bsc#1221747) * CVE-2024-28834: Fixed side-channel in the deterministic ECDSA (bsc#1221746) * jitterentropy: Release the memory of the entropy collector when using jitterentropy with phtreads as there is also a pre-initialization done in the main thread. (bsc#1221242) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-25=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * gnutls-debugsource-3.8.3-2.1 * libgnutls30-debuginfo-3.8.3-2.1 * gnutls-debuginfo-3.8.3-2.1 * libgnutls30-3.8.3-2.1 * gnutls-3.8.3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-28834.html * https://www.suse.com/security/cve/CVE-2024-28835.html * https://bugzilla.suse.com/show_bug.cgi?id=1221242 * https://bugzilla.suse.com/show_bug.cgi?id=1221746 * https://bugzilla.suse.com/show_bug.cgi?id=1221747 . Uncover the crucial SUSE upgradethat addresses gnutls vulnerabilities and boosts overall system reliability and safety.. SUSE Linux Micro, gnutls update, security patch, important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2242-1 Container Tags : bci/bci-base:15.5 , bci/bci-base:15.5.36.5.10 , suse/sle15:15.5 , suse/sle15:15.5.36.5.10 Container Release : 36.5.10 Severity : moderate Type : security References : 1202234 1209565 1211261 1211261 1211418 1211419 1212187 1212187 1212222 1212222 CVE-2023-2602 CVE-2023-2603 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2742-1 Released: Fri Jun 30 11:40:56 2023 Summary: Recommended update for autoyast2, libzypp, yast2-pkg-bindings, yast2-update, zypper Type: recommended Severity: moderate References: 1202234,1209565,1211261,1212187,1212222 This update for yast2-pkg-bindings fixes the following issues: libzypp was updated to version 17.31.14 (22): - Curl: trim all custom headers (bsc#1212187) HTTP/2 RFC 9113 forbids fields ending with a space. So we make sure all custom headers are trimmed. This also includes headers returned by URL-Resolver plugins. - build: honor libproxy.pc's includedir (bsc#1212222) zypper was updated to version 1.14.61: - targetos: Add an error note if XPath:/product/register/target is not defined in /etc/products.d/baseproduct (bsc#1211261) - targetos: Update help and man page (bsc#1211261) yast2-pkg-bindings, autoyast: - Added a new option for rebuilding the RPM database (--rebuilddb) (bsc#1209565) - Selected products are not installed after resetting the package manager internally (bsc#1202234) yast2-update: - Rebuild the RPM database during upgrade (--rebuilddb)(bsc#1209565) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2765-1 Released: Mon Jul 3 20:28:14 2023 Summary: Security update for libcap Type: security Severity: moderate References: 1211418,1211419,CVE-2023-2602,CVE-2023-2603 This update for libcap fixes the following issues: - CVE-2023-2602: Fixed improper memory release in libcap/psx/psx.c:__wrap_pthread_create() (bsc#1211418). - CVE-2023-2603: Fixed an integer overflow or wraparound in libcap/cap_alloc.c:_libcap_strdup() (bsc#1211419). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2772-1 Released: Tue Jul 4 09:54:23 2023 Summary: Recommended update for libzypp, zypper Type: recommended Severity: moderate References: 1211261,1212187,1212222 This update for libzypp, zypper fixes the following issues: libzypp was updated to version 17.31.14 (22): - Curl: trim all custom headers (bsc#1212187) HTTP/2 RFC 9113 forbids fields ending with a space. So we make sure all custom headers are trimmed. This also includes headers returned by URL-Resolver plugins. - build: honor libproxy.pc's includedir (bsc#1212222) zypper was updated to version 1.14.61: - targetos: Add an error note if XPath:/product/register/target is not defined in /etc/products.d/baseproduct (bsc#1211261) - targetos: Update help and man page (bsc#1211261) The following package changes have been done: - libcap2-2.63-150400.3.3.1 updated - libprotobuf-lite20-3.9.2-150200.4.21.1 updated - libzypp-17.31.14-150400.3.35.1 updated - zypper-1.14.61-150400.3.24.1 updated . SUSE Container Security Bulletin for suse/sle15, tackling vulnerabilities of moderate risk and implementing crucial updates.. SUSE, Container Update, Security Patch, libcap, Memory Release. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.