An update that solves one vulnerability can now be installed.. # Security update for python-tornado Announcement ID: SUSE-SU-2026:0838-1 Release Date: 2026-03-06T08:15:35Z Rating: moderate References: * bsc#1254903 Cross-References: * CVE-2025-67724 CVSS scores: * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-tornado fixes the following issue: * CVE-2025-67724: missing validation of the supplied reason phrase (bsc#1254903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-838=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-838=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-838=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-838=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patchSUSE-SLE-Micro-5.5-2026-838=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-838=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-838=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-838=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 *python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.16.1 * python-tornado-debugsource-4.5.3-150000.3.16.1 * python3-tornado-debuginfo-4.5.3-150000.3.16.1 * python3-tornado-4.5.3-150000.3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2025-67724.html * https://bugzilla.suse.com/show_bug.cgi?id=1254903 . Critical SUSE python-tornado security advisory addresses moderate risk issue. Update recommended for vulnerabilities present.. SUSE Linux Security, python-tornado Update, Patch Instructions. . LinuxSecurity.com Team
Update to 1.10.7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c555ce4089 2025-11-15 01:40:44.715722+00:00 -------------------------------------------------------------------------------- Name : opentofu Product : Fedora 41 Version : 1.10.7 Release : 1.fc41 URL : https://github.com/opentofu/opentofu Summary : OpenTofu lets you declaratively manage your cloud infrastructure Description : OpenTofu lets you declaratively manage your cloud infrastructure. -------------------------------------------------------------------------------- Update Information: Update to 1.10.7 -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 6 2025 Mikel Olasagasti Uranga - 1.10.7-1 - Update to 1.10.7 - Closes rhbz#2413156 * Fri Oct 10 2025 Alejandro Sez - 1.10.6-2 - rebuild * Thu Sep 4 2025 Mikel Olasagasti Uranga - 1.10.6-1 - Update to 1.10.6 - Closes rhbz#2385775 * Fri Aug 15 2025 Maxwell G - 1.10.3-2 - Rebuild for golang-1.25.0 * Sat Jul 26 2025 Mikel Olasagasti Uranga - 1.10.3-1 - Update to 1.10.3 - Closes rhbz#2380221 * Thu Jul 24 2025 Fedora Release Engineering - 1.10.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Thu Jun 26 2025 Mikel Olasagasti Uranga - 1.10.1-1 - Update to 1.10.1 - Closes rhbz#2374763 * Tue Jun 24 2025 Mikel Olasagasti Uranga - 1.10.0-1 - Update to 1.10.0 - Closes rhbz#2374600 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375615 - opentofu: mapstructure May Leak Sensitive Information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375615 [ 2 ] Bug #2384150 - opentofu: go-viper information leak [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384150 [ 3 ] Bug #2386297 - CVE-2025-8556 opentofu: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2386297 [ 4 ] Bug #2388884 - CVE-2025-8959 opentofu: HashiCorp go-getter Arbitrary File Read [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2388884 [ 5 ] Bug #2390857 - opentofu: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2390857 [ 6 ] Bug #2391634 - CVE-2025-58058 opentofu: github.com/ulikunitz/xz leaks memory [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2391634 [ 7 ] Bug #2398604 - CVE-2025-47910 opentofu: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398604 [ 8 ] Bug #2399268 - CVE-2025-47906 opentofu: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399268 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c555ce4089' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 41 update for OpenTofu version 1.10.7 addresses information leaks and validation issues.. OpenTofu 1.10.7, Fedora 41, information leak, arbitrary file read, software update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.