Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kanidm ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0152-1 Rating: moderate References: #1242642 Cross-References: CVE-2025-3416 CVSS scores: CVE-2025-3416 (SUSE): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for kanidm fixes the following issues: - Update to version 1.6.2~git0.a20663ea8: * Release 1.6.2 * fix: clippy * maint: typo in log message * Set kid manually to prevent divergence * Order keys in application JWKS / Fix rotation bug * Fix toml issues with strings - Update to version 1.6.1~git0.2e4429eca: * Release 1.6.1 * Resolve reload of oauth2 on startup (#3604) - CVE-2025-3416: Fixed openssl use after free (boo#1242642) - Update to version 1.6.0~git0.d7ae0f336: * Release 1.6.0 * Avoid openssl for md4 * Fixes #3586, inverts the navbar button color (#3593) * Release 1.6.0-pre * chore: Release Notes (#3588) * Do not require instances to exist during optional config load (#3591) * Fix std::fmt::Display for some objects (#3587) * Drop fernet in favour of JWE (#3577) * docs: document how to configure oauth2 for opkssh (#3566) * Add kanidm_ssh_authorizedkeys_direct to client deb (#3585) * Bump the all group in /pykanidm with 2 updates (#3581) * Update dependencies, fix a bunch of clippy lints (#3576) * Support spaces in ssh key comments (#3575) * 20250402 3423 proxy protocol (#3542) * fix(web): Preserve SSH key content on form validation error (#3574) * Bump the all group in /pykanidm with 3updates (#3572) * Bump the all group in /pykanidm with 2 updates (#3564) * Bump crossbeam-channel from 0.5.14 to 0.5.15 in the cargo group (#3560) * Improve token handling (#3553) * Bump tokio from 1.44.1 to 1.44.2 in the cargo group (#3549) * Update fs4 and improve klock handling (#3551) * Less footguns (#3552) * Unify unix config parser (#3533) * Bump openssl from 0.10.71 to 0.10.72 in the cargo group (#3544) * Bump the all group in /pykanidm with 8 updates (#3547) * implement notify-reload protocol (#3540) * Allow versioning of server configs (#3515) * 20250314 remove protected plugin (#3504) * Bump the all group with 10 updates (#3539) * Bump mozilla-actions/sccache-action from 0.0.8 to 0.0.9 in the all group (#3538) * Bump the all group in /pykanidm with 4 updates (#3537) * Add max_ber_size to freeipa sync (#3530) * Bump the all group in /pykanidm with 5 updates (#3524) * Update Concread * Update developer_ethics.md (#3520) * Update examples.md (#3519) * Make schema indexing a boolean instead of index types (#3517) * Add missing lld dependency and fix syntax typo (#3490) * Update shell.nix to work with stable nixpkgs (#3514) * Improve unixd tasks channel comments (#3510) * Update kanidm_ppa_automation reference to latest (#3512) * Add set-description to group tooling (#3511) * packaging: Add kanidmd deb package, update documentation (#3506) * Bump the all group in /pykanidm with 5 updates (#3508) * 20250313 unixd system cache (#3501) * Support rfc2307 memberUid in sync operations. (#3466) * Bump mozilla-actions/sccache-action from 0.0.7 to 0.0.8 in the all group (#3496) * Update Traefik config example to remove invalid label (#3500) * Add uid/gid allocation table (#3498) * 20250225 ldap testing in testkit (#3460) * Bump the all group in /pykanidm with 5 updates (#3494) * Bump ring from 0.17.10 to 0.17.13 in the cargogroup (#3491) * Handle form-post as a response mode (#3467) * book: fix english (#3487) * Correct paths with Kanidm Tools Container (#3486) * 20250225 improve test performance (#3459) * Bump the all group in /pykanidm with 8 updates (#3484) * Use lld by default on linux (#3477) * 20250213 patch used wrong acp (#3432) * Android support (#3475) * Changed all CI/CD builds to locked (#3471) * Make it a bit clearer that providers are needed (#3468) * Fix incorrect credential generation in radius docs (#3465) * Add crypt formats for password import (#3458) * build: Create daemon image from scratch (#3452) * address webfinger doc feedbacks (#3446) * Bump the all group across 1 directory with 5 updates (#3453) * [htmx] Admin ui for groups and users management (#3019) * Fixes #3406: add configurable maximum queryable attributes for LDAP (#3431) * Accept invalid certs and fix token_cache_path (#3439) * Accept lowercase ldap pwd hashes (#3444) * TOTP label verification (#3419) * Rewrite WebFinger docs (#3443) * doc: fix formatting of URL table, remove Caddyfile instructions (#3442) * book: add OAuth2 Proxy example (#3434) * Exempt idm_admin and admin from denied names. (#3429) * Book fixes (#3433) * ci: uniform Docker builds (#3430) * 20240213 3413 domain displayname (#3425) * Correct path to kanidm config example in documentation. (#3424) * Support redirect uris with query parameters (#3422) * Update to 1.6.0-dev (#3418) * Remove white background from square logo. (#3417) * feat: Added webfinger implementation (#3410) * Bump the all group in /pykanidm with 7 updates (#3412) - Update to version 1.5.0~git2.21c2a1bd0: * fix: documentation fail (#3555) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run thecommand listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-152=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): kanidm-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-debugsource-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-docs-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-server-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-1.6.2~git0.a20663ea8-bp156.29.1 kanidm-unixd-clients-debuginfo-1.6.2~git0.a20663ea8-bp156.29.1 References: https://www.suse.com/security/cve/CVE-2025-3416.html https://bugzilla.suse.com/1242642 . Security update for openSUSE kanidm addresses moderate threat from CVE-2025-3416, improving system stability.. openSUSE kanidm security patch moderate CVE-2025-3416 update. . Severity: moderate. LinuxSecurity.com Team
* bsc#1225551 Cross-References: * CVE-2024-4741 . # Security update for openssl-1_1 Announcement ID: SUSE-SU-2024:2035-1 Rating: important References: * bsc#1225551 Cross-References: * CVE-2024-4741 CVSS scores: * CVE-2024-4741 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: * CVE-2024-4741: Fixed a use-after-free with SSL_free_buffers. (bsc#1225551) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-2035=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-2035=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-2035=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-2035=1 * SUSE Linux Enterprise Server forSAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-2035=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-2035=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-2035=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-2035=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2035=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-2035=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * openssl-1_1-doc-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl-1_1-devel-32bit-1.1.1d-150200.11.91.1 *libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * openssl-1_1-doc-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl-1_1-devel-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (x86_64) *libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * openssl-1_1-doc-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl-1_1-devel-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Enterprise Storage 7.1 (noarch) * openssl-1_1-doc-1.1.1d-150200.11.91.1 * SUSE Enterprise Storage 7.1 (x86_64) * libopenssl1_1-32bit-1.1.1d-150200.11.91.1 * libopenssl-1_1-devel-32bit-1.1.1d-150200.11.91.1 * libopenssl1_1-32bit-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-32bit-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 *openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libopenssl-1_1-devel-1.1.1d-150200.11.91.1 * openssl-1_1-debuginfo-1.1.1d-150200.11.91.1 * libopenssl1_1-1.1.1d-150200.11.91.1 * libopenssl1_1-hmac-1.1.1d-150200.11.91.1 * openssl-1_1-debugsource-1.1.1d-150200.11.91.1 * libopenssl1_1-debuginfo-1.1.1d-150200.11.91.1 * openssl-1_1-1.1.1d-150200.11.91.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4741.html * https://bugzilla.suse.com/show_bug.cgi?id=1225551 . Important patch issued for openssl-1_1 enhancing security for specific SUSE systems. Addresses CVE-2024-4741 with significant severity ratings.. SUSE Security Advisory,Openssl Patch,SSL Security Fix,Security Update. . Severity: Important. LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2769-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.90 , suse/sle15:15.4 , suse/sle15:15.4.27.14.90 Container Release : 27.14.90 Severity : moderate Type : security References : 1201519 1204844 1213517 1213853 CVE-2023-3817 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3397-1 Released: Wed Aug 23 18:35:56 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213517,1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) - Don't pass zero length input to EVP_Cipher because s390x assembler optimized AES cannot handle zero size. (bsc#1213517) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3410-1 Released: Thu Aug 24 06:56:32 2023 Summary: Recommended update for audit Type: recommended Severity: moderate References: 1201519,1204844 This update for audit fixes the following issues: - Create symbolic link from /sbin/audisp-syslog to /usr/sbin/audisp-syslog (bsc#1201519) - Fix rules not loaded when restarting auditd.service (bsc#1204844) The following package changes have been done: - libaudit1-3.0.6-150400.4.13.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.53.1 updated - libopenssl1_1-1.1.1l-150400.7.53.1 updated - openssl-1_1-1.1.1l-150400.7.53.1 updated . Keep updated on SUSE Container Update Notification for suse/sle15, covering security updatesand corrections released in August 2023.. SUSE Container Update, OpenSSL Fix, Audit Update. . LinuxSecurity.com Team
The container bci/dotnet-sdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2548-1 Container Tags : bci/dotnet-sdk:6.0 , bci/dotnet-sdk:6.0-9.21 , bci/dotnet-sdk:6.0.20 , bci/dotnet-sdk:6.0.20-9.21 Container Release : 9.21 Severity : moderate Type : security References : 1213853 CVE-2023-3817 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3242-1 Released: Tue Aug 8 18:19:40 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213853,CVE-2023-3817 This update for openssl-1_1 fixes the following issues: - CVE-2023-3817: Fixed a potential DoS due to excessive time spent checking DH q parameter value. (bsc#1213853) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.15.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.15.1 updated - container:sles15-image-15.0.0-36.5.22 updated . Explore the latest SUSE Container Update Notice for bci/dotnet-sdk, highlighting recent patches and a significant OpenSSL fix categorized as moderate severity.. bci/dotnet-sdk, container update, OpenSSL security, SUSE advisory. . LinuxSecurity.com Team
The container bci/openjdk-devel was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2467-1 Container Tags : bci/openjdk-devel:11 , bci/openjdk-devel:11-8.36 Container Release : 8.36 Severity : moderate Type : security References : 1213487 CVE-2023-3446 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2965-1 Released: Tue Jul 25 12:30:22 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213487,CVE-2023-3446 This update for openssl-1_1 fixes the following issues: - CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2966-1 Released: Tue Jul 25 14:26:14 2023 Summary: Recommended update for libxml2 Type: recommended Severity: moderate References: This update for libxml2 fixes the following issues: - Build also for modern python version (jsc#PED-68) The following package changes have been done: - libxml2-2-2.10.3-150500.5.5.1 updated - libopenssl1_1-1.1.1l-150500.17.9.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.9.1 updated - openssl-1_1-1.1.1l-150500.17.9.1 updated - container:bci-openjdk-11-15.5.11-9.17 updated . Essential Patches for bci/openjdk-devel and libxml2 within SUSE Container: Addressing Vulnerabilities.. SUSE Container, bci/openjdk-devel, security patch, openssl fix, libxml2 update. . LinuxSecurity.com Team
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2457-1 Container Tags : suse/sle-micro/5.4/toolbox:12.1 , suse/sle-micro/5.4/toolbox:12.1-4.2.74 , suse/sle-micro/5.4/toolbox:latest Container Release : 4.2.74 Severity : moderate Type : security References : 1213487 CVE-2023-3446 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2962-1 Released: Tue Jul 25 09:34:53 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213487,CVE-2023-3446 This update for openssl-1_1 fixes the following issues: - CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150400.7.48.1 updated - libopenssl1_1-1.1.1l-150400.7.48.1 updated - openssl-1_1-1.1.1l-150400.7.48.1 updated - container:sles15-image-15.0.0-27.14.85 updated . Important SUSE Container Security Update Notification for toolbox responding to CVE-2023-3446 threat. Ensure safety with this patch.. SUSE Container Update, Toolbox Update, OpenSSL Fix. . LinuxSecurity.com Team
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2429-1 Container Tags : bci/dotnet-aspnet:6.0 , bci/dotnet-aspnet:6.0-10.16 , bci/dotnet-aspnet:6.0.20 , bci/dotnet-aspnet:6.0.20-10.16 Container Release : 10.16 Severity : moderate Type : security References : 1213487 CVE-2023-3446 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2965-1 Released: Tue Jul 25 12:30:22 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1213487,CVE-2023-3446 This update for openssl-1_1 fixes the following issues: - CVE-2023-3446: Fixed DH_check() excessive time with over sized modulus (bsc#1213487). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2966-1 Released: Tue Jul 25 14:26:14 2023 Summary: Recommended update for libxml2 Type: recommended Severity: moderate References: This update for libxml2 fixes the following issues: - Build also for modern python version (jsc#PED-68) The following package changes have been done: - libxml2-2-2.10.3-150500.5.5.1 updated - libopenssl1_1-1.1.1l-150500.17.9.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.9.1 updated - container:sles15-image-15.0.0-36.5.20 updated . SUSE Container Security Notice tackles vulnerabilities in bci/python and libcurl. Discover additional details about the patching process.. Container Updates, Dotnet Security, OpenSSL Fix, Libxml2 Patch. . LinuxSecurity.com Team
The container bci/openjdk-devel was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:2129-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-8.13 , bci/openjdk-devel:latest Container Release : 8.13 Severity : important Type : security References : 1201627 1207534 1211430 CVE-2022-4304 CVE-2023-2650 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 29171 Released: Tue Jun 20 12:29:00 2023 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1201627,1207534,1211430,CVE-2022-4304,CVE-2023-2650 This update for openssl-1_1 fixes the following issues: - CVE-2023-2650: Fixed possible denial of service translating ASN.1 object identifiers (bsc#1211430). - CVE-2022-4304: Reworked the fix for the Timing-Oracle in RSA decryption. The previous fix for this timing side channel turned out to cause a severe 2-3x performance regression in the typical use case (bsc#1207534). - Update further expiring certificates that affect tests (bsc#1201627) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2625-1 Released: Fri Jun 23 17:16:11 2023 Summary: Recommended update for gcc12 Type: recommended Severity: moderate References: This update for gcc12 fixes the following issues: - Update to GCC 12.3 release, 0c61aa720e62f1baf0bfd178e283, git1204 * includes regression and other bug fixes - Speed up builds with --enable-link-serialization. - Update embedded newlib to version 4.2.0 The following package changes have been done: - libgcc_s1-12.3.0+git1204-150000.1.10.1 updated -libstdc++6-12.3.0+git1204-150000.1.10.1 updated - libopenssl1_1-1.1.1l-150500.17.6.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.6.1 updated - openssl-1_1-1.1.1l-150500.17.6.1 updated - container:bci-openjdk-17-15.5.17-8.6 updated . SUSE Container Update Bulletin regarding bci/openjdk-devel incorporates critical security enhancements and fixes for known vulnerabilities.. bci/openjdk-devel update,SUSE Container Advisory,security update,OpenSSL fix,GCC performance. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.