Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
* bsc#922903 Cross-References: * CVE-2015-1379 . # Security update for socat Announcement ID: SUSE-SU-2025:0726-1 Release Date: 2025-02-26T13:37:01Z Rating: moderate References: * bsc#922903 Cross-References: * CVE-2015-1379 CVSS scores: * CVE-2015-1379 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for socat fixes the following issues: * CVE-2015-1379: lack of async-signal-safe signal handlers can lead to crashes or freezing of socat processes (bsc#922903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-726=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * socat-debuginfo-1.7.2.4-4.6.1 * socat-debugsource-1.7.2.4-4.6.1 * socat-1.7.2.4-4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2015-1379.html * https://bugzilla.suse.com/show_bug.cgi?id=922903 . This notification outlines the security enhancement for socat in SUSE SE 12 SP5 addressing a medium-severity vulnerability recognized for inducing system failures.. socat security update, SUSE advisory, installation instructions, moderate advisory, fix instructions. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # libprotobuf-lite28_3_0-28.3-15.1 on GA media Announcement ID: openSUSE-SU-2025:14832-1 Rating: moderate Cross-References: * CVE-2024-7254 CVSS scores: * CVE-2024-7254 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the libprotobuf-lite28_3_0-28.3-15.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libprotobuf-lite28_3_0 28.3-15.1 * libprotobuf-lite28_3_0-32bit 28.3-15.1 * libprotobuf28_3_0 28.3-15.1 * libprotobuf28_3_0-32bit 28.3-15.1 * libprotoc28_3_0 28.3-15.1 * libprotoc28_3_0-32bit 28.3-15.1 * libutf8_range-28_3_0 28.3-15.1 * libutf8_range-28_3_0-32bit 28.3-15.1 * protobuf-devel 28.3-15.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7254.html . The recent update addresses several moderate security vulnerabilities found in the libprotobuf-lite package for openSUSE Tumbleweed, including a particular weakness.. openSUSE Tumbleweed, libprotobuf-lite, security update, software advisory. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # kubernetes1.32-apiserver-1.32.2-1.1 on GA media Announcement ID: openSUSE-SU-2025:14819-1 Rating: moderate Cross-References: * CVE-2025-0426 CVSS scores: * CVE-2025-0426 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-0426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the kubernetes1.32-apiserver-1.32.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * kubernetes1.32-apiserver 1.32.2-1.1 * kubernetes1.32-client 1.32.2-1.1 * kubernetes1.32-client-bash-completion 1.32.2-1.1 * kubernetes1.32-client-common 1.32.2-1.1 * kubernetes1.32-client-fish-completion 1.32.2-1.1 * kubernetes1.32-controller-manager 1.32.2-1.1 * kubernetes1.32-kubeadm 1.32.2-1.1 * kubernetes1.32-kubelet 1.32.2-1.1 * kubernetes1.32-kubelet-common 1.32.2-1.1 * kubernetes1.32-proxy 1.32.2-1.1 * kubernetes1.32-scheduler 1.32.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0426.html . Kubernetes 1.32.2-1.1 security patch for openSUSE addresses a moderate threat concern. Upgrade your installation today.. Kubernetes Security, openSUSE Tumbleweed, Update Advisory, Security Patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # python311-pydantic-2.10.6-1.1 on GA media Announcement ID: openSUSE-SU-2025:14712-1 Rating: moderate Cross-References: * CVE-2020-10735 CVSS scores: * CVE-2020-10735 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the python311-pydantic-2.10.6-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * python311-pydantic 2.10.6-1.1 * python312-pydantic 2.10.6-1.1 * python313-pydantic 2.10.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2020-10735.html . Patch applied for python311-pydantic-2.10.6-1.1 on openSUSE, resolving moderate-severity vulnerabilities.. python311, openSUSE, security fix, software update, moderate advisory. . LinuxSecurity.com Team
* bsc#1232241 * bsc#1233307 Cross-References: * CVE-2024-11168 . # Security update for python39 Announcement ID: SUSE-SU-2025:0047-1 Release Date: 2025-01-09T15:36:42Z Rating: moderate References: * bsc#1232241 * bsc#1233307 Cross-References: * CVE-2024-11168 * CVE-2024-9287 CVSS scores: * CVE-2024-11168 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-11168 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-9287 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green * CVE-2024-9287 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2024-9287 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 An update that solves two vulnerabilities can now be installed. ## Description: This update for python39 fixes the following issue: * Update to 3.9.21 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-47=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-47=1 ## Package List: * openSUSE Leap 15.3 (aarch64ppc64le s390x x86_64 i586) * python39-doc-devhelp-3.9.21-150300.4.61.1 * python39-testsuite-debuginfo-3.9.21-150300.4.61.1 * python39-core-debugsource-3.9.21-150300.4.61.1 * python39-curses-debuginfo-3.9.21-150300.4.61.1 * python39-testsuite-3.9.21-150300.4.61.1 * python39-tools-3.9.21-150300.4.61.1 * python39-base-debuginfo-3.9.21-150300.4.61.1 * python39-idle-3.9.21-150300.4.61.1 * python39-tk-3.9.21-150300.4.61.1 * python39-debugsource-3.9.21-150300.4.61.1 * python39-tk-debuginfo-3.9.21-150300.4.61.1 * python39-dbm-3.9.21-150300.4.61.1 * python39-3.9.21-150300.4.61.1 * python39-dbm-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-3.9.21-150300.4.61.1 * libpython3_9-1_0-debuginfo-3.9.21-150300.4.61.1 * python39-doc-3.9.21-150300.4.61.1 * python39-debuginfo-3.9.21-150300.4.61.1 * python39-base-3.9.21-150300.4.61.1 * python39-curses-3.9.21-150300.4.61.1 * python39-devel-3.9.21-150300.4.61.1 * openSUSE Leap 15.3 (x86_64) * python39-base-32bit-debuginfo-3.9.21-150300.4.61.1 * python39-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-3.9.21-150300.4.61.1 * python39-base-32bit-3.9.21-150300.4.61.1 * python39-32bit-3.9.21-150300.4.61.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.21-150300.4.61.1 * libpython3_9-1_0-64bit-3.9.21-150300.4.61.1 * python39-64bit-debuginfo-3.9.21-150300.4.61.1 * python39-base-64bit-3.9.21-150300.4.61.1 * libpython3_9-1_0-64bit-debuginfo-3.9.21-150300.4.61.1 * python39-base-64bit-debuginfo-3.9.21-150300.4.61.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python39-doc-devhelp-3.9.21-150300.4.61.1 * python39-testsuite-debuginfo-3.9.21-150300.4.61.1 * python39-core-debugsource-3.9.21-150300.4.61.1 * python39-curses-debuginfo-3.9.21-150300.4.61.1 * python39-testsuite-3.9.21-150300.4.61.1 * python39-tools-3.9.21-150300.4.61.1 *python39-base-debuginfo-3.9.21-150300.4.61.1 * python39-idle-3.9.21-150300.4.61.1 * python39-tk-3.9.21-150300.4.61.1 * python39-debugsource-3.9.21-150300.4.61.1 * python39-tk-debuginfo-3.9.21-150300.4.61.1 * python39-dbm-3.9.21-150300.4.61.1 * python39-3.9.21-150300.4.61.1 * python39-dbm-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-3.9.21-150300.4.61.1 * libpython3_9-1_0-debuginfo-3.9.21-150300.4.61.1 * python39-doc-3.9.21-150300.4.61.1 * python39-debuginfo-3.9.21-150300.4.61.1 * python39-base-3.9.21-150300.4.61.1 * python39-curses-3.9.21-150300.4.61.1 * python39-devel-3.9.21-150300.4.61.1 * openSUSE Leap 15.6 (x86_64) * python39-base-32bit-debuginfo-3.9.21-150300.4.61.1 * python39-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-3.9.21-150300.4.61.1 * python39-base-32bit-3.9.21-150300.4.61.1 * python39-32bit-3.9.21-150300.4.61.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11168.html * https://www.suse.com/security/cve/CVE-2024-9287.html * https://bugzilla.suse.com/show_bug.cgi?id=1232241 * https://bugzilla.suse.com/show_bug.cgi?id=1233307 . Python39 security patch released for SUSE systems. Detailed release notes and installation guidelines for impacted products are available.. python39 update, SUSE patches, openSUSE security, package vulnerabilities. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4243 http://linux.oracle.com/errata/ELSA-2024-4243.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3.12-3.12.3-2.el8_10.x86_64.rpm python3.12-devel-3.12.3-2.el8_10.i686.rpm python3.12-devel-3.12.3-2.el8_10.x86_64.rpm python3.12-libs-3.12.3-2.el8_10.i686.rpm python3.12-libs-3.12.3-2.el8_10.x86_64.rpm python3.12-rpm-macros-3.12.3-2.el8_10.noarch.rpm python3.12-tkinter-3.12.3-2.el8_10.x86_64.rpm python3.12-3.12.3-2.el8_10.i686.rpm python3.12-debug-3.12.3-2.el8_10.i686.rpm python3.12-debug-3.12.3-2.el8_10.x86_64.rpm python3.12-idle-3.12.3-2.el8_10.i686.rpm python3.12-idle-3.12.3-2.el8_10.x86_64.rpm python3.12-test-3.12.3-2.el8_10.i686.rpm python3.12-test-3.12.3-2.el8_10.x86_64.rpm python3.12-tkinter-3.12.3-2.el8_10.i686.rpm aarch64: python3.12-3.12.3-2.el8_10.aarch64.rpm python3.12-devel-3.12.3-2.el8_10.aarch64.rpm python3.12-libs-3.12.3-2.el8_10.aarch64.rpm python3.12-rpm-macros-3.12.3-2.el8_10.noarch.rpm python3.12-tkinter-3.12.3-2.el8_10.aarch64.rpm python3.12-debug-3.12.3-2.el8_10.aarch64.rpm python3.12-idle-3.12.3-2.el8_10.aarch64.rpm python3.12-test-3.12.3-2.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//python3.12-3.12.3-2.el8_10.src.rpm Related CVEs: CVE-2024-0450 Description of changes: [3.12.3-2] - Enable importing of hash-based .pyc files under FIPS mode Resolves: RHEL-40776 [3.12.3-1] - Update to 3.12.3 Related: RHEL-33685 [3.12.2-3] - Move all test modules to the python3-test package, namely: - __phello__ - _xxsubinterpreters - xxlimited - xxlimited_35 - xxsubtype [3.12.2-2] - Fix tests for XMLPullParser with Expat with fixed CVE [3.12.2-1] - Update to 3.12.2 Resolves: RHEL-33685 _______________________________________________ El-errata mailing list
An issue has been found in cups, the Common UNIX Printing System(tm). When starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3826-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1818 http://linux.oracle.com/errata/ELSA-2024-1818.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-1.8.0-openjdk-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.412.b08-2.0.1.el9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.412.b08-2.0.1.el9.noarch.rpm java-1.8.0-openjdk-src-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.412.b08-2.0.1.el9.x86_64.rpm aarch64: java-1.8.0-openjdk-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-demo-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-devel-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-headless-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-javadoc-1.8.0.412.b08-2.0.1.el9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.412.b08-2.0.1.el9.noarch.rpm java-1.8.0-openjdk-src-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-demo-fastdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-demo-slowdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-devel-fastdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-devel-slowdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-fastdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-headless-fastdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-headless-slowdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-slowdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-src-fastdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm java-1.8.0-openjdk-src-slowdebug-1.8.0.412.b08-2.0.1.el9.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//java-1.8.0-openjdk-1.8.0.412.b08-2.0.1.el9.src.rpm Related CVEs: CVE-2024-21011 CVE-2024-21068 CVE-2024-21085 CVE-2024-21094 Description of changes: [1:1.8.0.412.b08-2.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.