Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
# Security update for kernel-livepatch-MICRO-6-0_Update_26 Announcement ID: SUSE-SU-2026:22518-1 Release Date: 2026-07-06T09:28:38Z Rating: important References:. # Security update for kernel-livepatch-MICRO-6-0_Update_26 Announcement ID: SUSE-SU-2026:22518-1 Release Date: 2026-07-06T09:28:38Z Rating: important References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-500=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-1-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-default-debuginfo-1-1.1 . An important security update for SUSE Linux Micro 6.0 kernel-livepatch to address critical issues.. SUSE Linux Micro, kernel update, security fix, system patch. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for containerd Announcement ID: SUSE-SU-2026:22424-1 Release Date: 2026-06-25T09:00:00Z Rating: important References: * bsc#1262948 * bsc#1265794 * bsc#1266640 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ## Patch Instructions: To install this SUSEupdate use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-769=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * containerd-1.7.29-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262948 * https://bugzilla.suse.com/show_bug.cgi?id=1265794 * https://bugzilla.suse.com/show_bug.cgi?id=1266640 . An important security update for containerd fixes three vulnerabilities affecting SUSE. Immediate action required.. SUSE containerd update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for htmldoc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0046-1 Rating: important References: #1232380 Cross-References: CVE-2024-46478 Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for htmldoc fixes the following issues: - CVE-2024-46478: Fixed buffer overflow when handling tabs through the parse_pre function (boo#1232380). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-46=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): htmldoc-1.9.16-bp157.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-46478.html https://bugzilla.suse.com/1232380 . Update fixes important buffer overflow in htmldoc for openSUSE, potentially impacting system security and stability.. openSUSE security update, htmldoc patch, buffer overflow fix, important security advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1229007 Cross-References: * CVE-2024-7409 . # Security update for qemu Announcement ID: SUSE-SU-2025:02530-1 Release Date: 2025-07-25T22:20:37Z Rating: important References: * bsc#1229007 Cross-References: * CVE-2024-7409 CVSS scores: * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for qemu fixes the following issues: * CVE-2024-7409: Fixed denial of service via improper synchronization in QEMU NBD Server during socket closure (bsc#1229007) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-2530=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2530=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * qemu-audio-alsa-3.1.1.1-78.1 * qemu-ui-curses-debuginfo-3.1.1.1-78.1 * qemu-tools-3.1.1.1-78.1 * qemu-ui-gtk-debuginfo-3.1.1.1-78.1 * qemu-audio-sdl-3.1.1.1-78.1 * qemu-audio-pa-debuginfo-3.1.1.1-78.1 * qemu-ui-sdl-debuginfo-3.1.1.1-78.1 * qemu-audio-oss-debuginfo-3.1.1.1-78.1 * qemu-lang-3.1.1.1-78.1 * qemu-audio-pa-3.1.1.1-78.1 *qemu-debugsource-3.1.1.1-78.1 * qemu-block-iscsi-debuginfo-3.1.1.1-78.1 * qemu-block-curl-debuginfo-3.1.1.1-78.1 * qemu-audio-sdl-debuginfo-3.1.1.1-78.1 * qemu-block-curl-3.1.1.1-78.1 * qemu-guest-agent-3.1.1.1-78.1 * qemu-3.1.1.1-78.1 * qemu-guest-agent-debuginfo-3.1.1.1-78.1 * qemu-block-ssh-debuginfo-3.1.1.1-78.1 * qemu-ui-gtk-3.1.1.1-78.1 * qemu-audio-alsa-debuginfo-3.1.1.1-78.1 * qemu-audio-oss-3.1.1.1-78.1 * qemu-ui-curses-3.1.1.1-78.1 * qemu-ui-sdl-3.1.1.1-78.1 * qemu-block-ssh-3.1.1.1-78.1 * qemu-block-iscsi-3.1.1.1-78.1 * qemu-tools-debuginfo-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64) * qemu-arm-debuginfo-3.1.1.1-78.1 * qemu-arm-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 x86_64) * qemu-block-rbd-debuginfo-3.1.1.1-78.1 * qemu-block-rbd-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * qemu-vgabios-1.12.0_0_ga698c89-78.1 * qemu-ipxe-1.0.0+-78.1 * qemu-sgabios-8-78.1 * qemu-seabios-1.12.0_0_ga698c89-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le) * qemu-ppc-3.1.1.1-78.1 * qemu-ppc-debuginfo-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * qemu-kvm-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * qemu-s390-debuginfo-3.1.1.1-78.1 * qemu-s390-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * qemu-x86-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * qemu-audio-alsa-3.1.1.1-78.1 * qemu-ui-curses-debuginfo-3.1.1.1-78.1 * qemu-tools-3.1.1.1-78.1 * qemu-ui-gtk-debuginfo-3.1.1.1-78.1 * qemu-audio-sdl-3.1.1.1-78.1 * qemu-audio-pa-debuginfo-3.1.1.1-78.1 * qemu-ui-sdl-debuginfo-3.1.1.1-78.1 * qemu-audio-oss-debuginfo-3.1.1.1-78.1 * qemu-lang-3.1.1.1-78.1 * qemu-audio-pa-3.1.1.1-78.1 * qemu-debugsource-3.1.1.1-78.1 * qemu-block-iscsi-debuginfo-3.1.1.1-78.1 *qemu-block-curl-debuginfo-3.1.1.1-78.1 * qemu-audio-sdl-debuginfo-3.1.1.1-78.1 * qemu-block-curl-3.1.1.1-78.1 * qemu-guest-agent-3.1.1.1-78.1 * qemu-3.1.1.1-78.1 * qemu-guest-agent-debuginfo-3.1.1.1-78.1 * qemu-block-ssh-debuginfo-3.1.1.1-78.1 * qemu-ui-gtk-3.1.1.1-78.1 * qemu-kvm-3.1.1.1-78.1 * qemu-x86-3.1.1.1-78.1 * qemu-audio-alsa-debuginfo-3.1.1.1-78.1 * qemu-block-rbd-debuginfo-3.1.1.1-78.1 * qemu-audio-oss-3.1.1.1-78.1 * qemu-ui-curses-3.1.1.1-78.1 * qemu-ui-sdl-3.1.1.1-78.1 * qemu-block-ssh-3.1.1.1-78.1 * qemu-block-iscsi-3.1.1.1-78.1 * qemu-tools-debuginfo-3.1.1.1-78.1 * qemu-block-rbd-3.1.1.1-78.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * qemu-seabios-1.12.0_0_ga698c89-78.1 * qemu-ipxe-1.0.0+-78.1 * qemu-vgabios-1.12.0_0_ga698c89-78.1 * qemu-sgabios-8-78.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7409.html * https://bugzilla.suse.com/show_bug.cgi?id=1229007 . Ensure your SUSE systems are secured by applying the latest QEMU patch addressing CVE-2024-7409, which mitigates a critical security vulnerability.. SUSE Security Update, QEMU Denial of Service, CVE-2024-7409 Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1243721 Cross-References: * CVE-2025-5222 . # Security update for icu Announcement ID: SUSE-SU-2025:02059-1 Release Date: 2025-06-23T01:38:23Z Rating: important References: * bsc#1243721 Cross-References: * CVE-2025-5222 CVSS scores: * CVE-2025-5222 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-5222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for icu fixes the following issues: * CVE-2025-5222: Stack buffer overflow in the SRBRoot:addTag function (bsc#1243721). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively youcan run the command listed for your product: * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2059=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2059=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-2059=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-2059=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-2059=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-2059=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-2059=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2059=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2059=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2059=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2059=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-2059=1 ## Package List: * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * Basesystem Module 15-SP6 (noarch) * libicu60_2-bedata-60.2-150000.3.18.1 * libicu60_2-ledata-60.2-150000.3.18.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 *libicu60_2-debuginfo-60.2-150000.3.18.1 * Basesystem Module 15-SP7 (noarch) * libicu60_2-bedata-60.2-150000.3.18.1 * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * libicu60_2-bedata-60.2-150000.3.18.1 * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libicu60_2-bedata-60.2-150000.3.18.1 * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux EnterpriseServer 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libicu60_2-bedata-60.2-150000.3.18.1 * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * icu-debuginfo-60.2-150000.3.18.1 * icu-debugsource-60.2-150000.3.18.1 * libicu60_2-60.2-150000.3.18.1 * libicu60_2-debuginfo-60.2-150000.3.18.1 * SUSE Enterprise Storage 7.1 (noarch) * libicu60_2-ledata-60.2-150000.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-5222.html * https://bugzilla.suse.com/show_bug.cgi?id=1243721 . Essential SUSE Linux patch for icu tackles significant stack buffer overflow vulnerability with advised update procedures.. SUSE Linux, security update, icu, buffer overflow fix, server patching. . Severity:Important. LinuxSecurity.com Team
* bsc#1224282 Cross-References: * CVE-2024-34459 . # Security update for libxml2 Announcement ID: SUSE-SU-2025:20043-1 Release Date: 2025-02-03T08:54:24Z Rating: moderate References: * bsc#1224282 Cross-References: * CVE-2024-34459 CVSS scores: * CVE-2024-34459 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issues: * CVE-2024-34459: Fixed buffer over-read in (bsc#1224282) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-45=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libxml2-2-debuginfo-2.11.6-3.1 * libxml2-tools-2.11.6-3.1 * libxml2-2-2.11.6-3.1 * libxml2-tools-debuginfo-2.11.6-3.1 * libxml2-debugsource-2.11.6-3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34459.html * https://bugzilla.suse.com/show_bug.cgi?id=1224282 . The libxml2 library on SUSE Linux Micro has been updated to address a moderate buffer over-read vulnerability affecting earlier versions, mitigating potential data leaks and corruption. libxml2 update, SUSE security patch, buffer over-read fix, Linux security update. . LinuxSecurity.com Team
* bsc#1236314 Cross-References: * CVE-2025-24531 . # Security update for pam_pkcs11 Announcement ID: SUSE-SU-2025:20130-1 Release Date: 2025-02-26T13:23:33Z Rating: critical References: * bsc#1236314 Cross-References: * CVE-2025-24531 CVSS scores: * CVE-2025-24531 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-24531 ( SUSE ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for pam_pkcs11 fixes the following issues: * CVE-2025-24531: Fixed regression in version 0.6.12 returning PAM_IGNORE in many situations with possible authentication bypass (bsc#1236314). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-219=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * pam_pkcs11-debugsource-0.6.12-2.1 * pam_pkcs11-0.6.12-2.1 * pam_pkcs11-debuginfo-0.6.12-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24531.html * https://bugzilla.suse.com/show_bug.cgi?id=1236314 . Keep informed about the recent security patch for SUSE Linux Micro concerning pam_pkcs11, which resolves specific authentication problems.. SUSE Linux Security Update, pam_pkcs11 Critical Issue, Authentication Bypass Fix. . Severity: Critical. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for corosync Announcement ID: SUSE-SU-2025:1084-1 Release Date: 2025-04-01T10:19:10Z Rating: critical References: * bsc#1239987 Cross-References: * CVE-2025-30472 CVSS scores: * CVE-2025-30472 ( SUSE ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-30472 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP3 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 Business Critical Linux * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for corosync fixes the following issues: * CVE-2025-30472: Fixed stack buffer overflow from 'orf_token_endian_convert' (bsc#1239987) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: *openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1084=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1084=1 * SUSE Linux Enterprise High Availability Extension 15 SP3 zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2025-1084=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2025-1084=1 * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2025-1084=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2025-1084=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 * openSUSE Leap 15.3 (x86_64) * libcmap4-32bit-2.4.6-150300.12.13.1 * libcmap4-32bit-debuginfo-2.4.6-150300.12.13.1 *libsam4-32bit-2.4.6-150300.12.13.1 * libcpg4-32bit-2.4.6-150300.12.13.1 * libvotequorum8-32bit-2.4.6-150300.12.13.1 * libquorum5-32bit-debuginfo-2.4.6-150300.12.13.1 * libcfg6-32bit-debuginfo-2.4.6-150300.12.13.1 * libcpg4-32bit-debuginfo-2.4.6-150300.12.13.1 * libsam4-32bit-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-32bit-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-32bit-debuginfo-2.4.6-150300.12.13.1 * libquorum5-32bit-2.4.6-150300.12.13.1 * libcfg6-32bit-2.4.6-150300.12.13.1 * libtotem_pg5-32bit-2.4.6-150300.12.13.1 * libcorosync_common4-32bit-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-32bit-2.4.6-150300.12.13.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libvotequorum8-64bit-debuginfo-2.4.6-150300.12.13.1 * libcmap4-64bit-2.4.6-150300.12.13.1 * libcorosync_common4-64bit-debuginfo-2.4.6-150300.12.13.1 * libcmap4-64bit-debuginfo-2.4.6-150300.12.13.1 * libsam4-64bit-2.4.6-150300.12.13.1 * libcfg6-64bit-2.4.6-150300.12.13.1 * libcpg4-64bit-2.4.6-150300.12.13.1 * libvotequorum8-64bit-2.4.6-150300.12.13.1 * libquorum5-64bit-2.4.6-150300.12.13.1 * libsam4-64bit-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-64bit-2.4.6-150300.12.13.1 * libcfg6-64bit-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-64bit-debuginfo-2.4.6-150300.12.13.1 * libcpg4-64bit-debuginfo-2.4.6-150300.12.13.1 * libquorum5-64bit-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-64bit-2.4.6-150300.12.13.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 *corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 * openSUSE Leap 15.6 (x86_64) * libcmap4-32bit-2.4.6-150300.12.13.1 * libcmap4-32bit-debuginfo-2.4.6-150300.12.13.1 * libsam4-32bit-2.4.6-150300.12.13.1 * libcpg4-32bit-2.4.6-150300.12.13.1 * libvotequorum8-32bit-2.4.6-150300.12.13.1 * libquorum5-32bit-debuginfo-2.4.6-150300.12.13.1 * libcfg6-32bit-debuginfo-2.4.6-150300.12.13.1 * libcpg4-32bit-debuginfo-2.4.6-150300.12.13.1 * libsam4-32bit-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-32bit-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-32bit-debuginfo-2.4.6-150300.12.13.1 * libquorum5-32bit-2.4.6-150300.12.13.1 * libcfg6-32bit-2.4.6-150300.12.13.1 * libtotem_pg5-32bit-2.4.6-150300.12.13.1 * libcorosync_common4-32bit-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-32bit-2.4.6-150300.12.13.1 * SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le s390x x86_64) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 *corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 * SUSE LinuxEnterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * libcfg6-2.4.6-150300.12.13.1 * libcmap4-debuginfo-2.4.6-150300.12.13.1 * corosync-testagents-debuginfo-2.4.6-150300.12.13.1 * corosync-debugsource-2.4.6-150300.12.13.1 * libcorosync-devel-2.4.6-150300.12.13.1 * libsam4-2.4.6-150300.12.13.1 * libvotequorum8-debuginfo-2.4.6-150300.12.13.1 * corosync-2.4.6-150300.12.13.1 * corosync-debuginfo-2.4.6-150300.12.13.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.13.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.13.1 * libquorum5-2.4.6-150300.12.13.1 * libquorum5-debuginfo-2.4.6-150300.12.13.1 * libtotem_pg5-2.4.6-150300.12.13.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.13.1 *libcorosync_common4-2.4.6-150300.12.13.1 * corosync-qdevice-2.4.6-150300.12.13.1 * libsam4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-debuginfo-2.4.6-150300.12.13.1 * libvotequorum8-2.4.6-150300.12.13.1 * corosync-testagents-2.4.6-150300.12.13.1 * libcfg6-debuginfo-2.4.6-150300.12.13.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.13.1 * libcpg4-2.4.6-150300.12.13.1 * corosync-qnetd-2.4.6-150300.12.13.1 * libcmap4-2.4.6-150300.12.13.1 ## References: * https://www.suse.com/security/cve/CVE-2025-30472.html * https://bugzilla.suse.com/show_bug.cgi?id=1239987 . Address the urgent Corosync buffer overflow vulnerability by applying the latest openSUSE update. Obtain patch instructions immediately!. corosync security patch, SUSE update instructions, openSUSE critical advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.