An update that solves three vulnerabilities can now be installed.. # Security update for jasper Announcement ID: SUSE-SU-2026:20200-1 Release Date: 2026-01-30T09:59:14Z Rating: moderate References: * bsc#1247901 * bsc#1247902 * bsc#1247904 Cross-References: * CVE-2025-8835 * CVE-2025-8836 * CVE-2025-8837 CVSS scores: * CVE-2025-8835 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-8835 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8835 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8835 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8835 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-8836 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-8836 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-8836 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8836 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-8837 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-8837 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-8837 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8837 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-8837 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An updatethat solves three vulnerabilities can now be installed. ## Description: This update for jasper fixes the following issues: Update to 4.2.8: * CVE-2025-8837: Fixed a bug in the JPC decoder that could cause bad memory accesses if the debug level is set sufficiently high (bsc#1247901). * CVE-2025-8836: Added some missing range checking on several coding parameters in the JPC encoder (bsc#1247902). * CVE-2025-8835: Added a check for a missing color component in the jas_image_chclrspc function (bsc#1247904). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-223=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-223=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jasper-debugsource-4.2.8-160000.1.1 * libjasper7-debuginfo-4.2.8-160000.1.1 * libjasper7-4.2.8-160000.1.1 * jasper-debuginfo-4.2.8-160000.1.1 * jasper-4.2.8-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * jasper-debugsource-4.2.8-160000.1.1 * libjasper7-debuginfo-4.2.8-160000.1.1 * libjasper7-4.2.8-160000.1.1 * jasper-debuginfo-4.2.8-160000.1.1 * jasper-4.2.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8835.html * https://www.suse.com/security/cve/CVE-2025-8836.html * https://www.suse.com/security/cve/CVE-2025-8837.html * https://bugzilla.suse.com/show_bug.cgi?id=1247901 * https://bugzilla.suse.com/show_bug.cgi?id=1247902 * https://bugzilla.suse.com/show_bug.cgi?id=1247904 . Update for jasper fixes multiple security issues including memory access and coding errors. Install patches promptly.. jasper security patch moderate SUSE Linux update. . LinuxSecurity.com Team
Updated kernel packages that fix multiple security issues and two bugs are now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2015:0803-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:0803.html Issue date: 2015-04-14 CVE Names: CVE-2013-2596 CVE-2014-5471 CVE-2014-5472 CVE-2014-8159 ==================================================================== 1. Summary: Updated kernel packages that fix multiple security issues and two bugs are now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 6.4) - i386, noarch, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.4) - i386, ppc64, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. * It was found that the Linux kernel's Infiniband subsystem did not properly sanitize input parameters while registering memory regions from user space via the (u)verbs API. A local user with access to a /dev/infiniband/uverbsX device could use this flaw to crash the system or, potentially, escalate their privileges on the system. (CVE-2014-8159, Important) * An integer overflow flaw was found in the way the Linux kernel's Frame Bufferdevice implementation mapped kernel memory to user space via the mmap syscall. A local user able to access a frame buffer device file (/dev/fb*) could possibly use this flaw to escalate their privileges on the system. (CVE-2013-2596, Important) * It was found that the parse_rock_ridge_inode_internal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system. (CVE-2014-5471, CVE-2014-5472, Low) Red Hat would like to thank Mellanox for reporting the CVE-2014-8159 issue. This update also fixes the following bugs: * The kernel could sometimes panic due to a possible division by zero in the kernel scheduler. This bug has been fixed by defining a new div64_ul() division function and correcting the affected calculation in the proc_sched_show_task() function. (BZ#1199898) * When repeating a Coordinated Universal Time (UTC) value during a leap second (when the UTC time should be 23:59:60), the International Atomic Time (TAI) timescale previously stopped as the kernel NTP code incremented the TAI offset one second too late. A patch has been provided, which fixes the bug by incrementing the offset during the leap second itself. Now, the correct TAI is set during the leap second. (BZ#1201672) All kernel users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1034490 - CVE-2013-2596 kernel: integer overflow in fb_mmap 1134099 - CVE-2014-5471 CVE-2014-5472 kernel: isofs: unbound recursionwhen processing relocated directories 1181166 - CVE-2014-8159 kernel: infiniband: uverbs: unprotected physical memory access 6. Package List: Red Hat Enterprise Linux Server AUS (v.6.4): Source: kernel-2.6.32-358.59.1.el6.src.rpm i386: kernel-2.6.32-358.59.1.el6.i686.rpm kernel-debug-2.6.32-358.59.1.el6.i686.rpm kernel-debug-debuginfo-2.6.32-358.59.1.el6.i686.rpm kernel-debug-devel-2.6.32-358.59.1.el6.i686.rpm kernel-debuginfo-2.6.32-358.59.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-358.59.1.el6.i686.rpm kernel-devel-2.6.32-358.59.1.el6.i686.rpm kernel-headers-2.6.32-358.59.1.el6.i686.rpm perf-2.6.32-358.59.1.el6.i686.rpm perf-debuginfo-2.6.32-358.59.1.el6.i686.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.i686.rpm noarch: kernel-doc-2.6.32-358.59.1.el6.noarch.rpm kernel-firmware-2.6.32-358.59.1.el6.noarch.rpm ppc64: kernel-2.6.32-358.59.1.el6.ppc64.rpm kernel-bootwrapper-2.6.32-358.59.1.el6.ppc64.rpm kernel-debug-2.6.32-358.59.1.el6.ppc64.rpm kernel-debug-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm kernel-debug-devel-2.6.32-358.59.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-358.59.1.el6.ppc64.rpm kernel-devel-2.6.32-358.59.1.el6.ppc64.rpm kernel-headers-2.6.32-358.59.1.el6.ppc64.rpm perf-2.6.32-358.59.1.el6.ppc64.rpm perf-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm s390x: kernel-2.6.32-358.59.1.el6.s390x.rpm kernel-debug-2.6.32-358.59.1.el6.s390x.rpm kernel-debug-debuginfo-2.6.32-358.59.1.el6.s390x.rpm kernel-debug-devel-2.6.32-358.59.1.el6.s390x.rpm kernel-debuginfo-2.6.32-358.59.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-358.59.1.el6.s390x.rpm kernel-devel-2.6.32-358.59.1.el6.s390x.rpm kernel-headers-2.6.32-358.59.1.el6.s390x.rpm kernel-kdump-2.6.32-358.59.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-358.59.1.el6.s390x.rpm kernel-kdump-devel-2.6.32-358.59.1.el6.s390x.rpm perf-2.6.32-358.59.1.el6.s390x.rpm perf-debuginfo-2.6.32-358.59.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.s390x.rpm x86_64: kernel-2.6.32-358.59.1.el6.x86_64.rpm kernel-debug-2.6.32-358.59.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-358.59.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-358.59.1.el6.x86_64.rpm kernel-devel-2.6.32-358.59.1.el6.x86_64.rpm kernel-headers-2.6.32-358.59.1.el6.x86_64.rpm perf-2.6.32-358.59.1.el6.x86_64.rpm perf-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 6.4): Source: kernel-2.6.32-358.59.1.el6.src.rpm i386: kernel-debug-debuginfo-2.6.32-358.59.1.el6.i686.rpm kernel-debuginfo-2.6.32-358.59.1.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-358.59.1.el6.i686.rpm perf-debuginfo-2.6.32-358.59.1.el6.i686.rpm python-perf-2.6.32-358.59.1.el6.i686.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.i686.rpm ppc64: kernel-debug-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm kernel-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm kernel-debuginfo-common-ppc64-2.6.32-358.59.1.el6.ppc64.rpm perf-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm python-perf-2.6.32-358.59.1.el6.ppc64.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.ppc64.rpm s390x: kernel-debug-debuginfo-2.6.32-358.59.1.el6.s390x.rpm kernel-debuginfo-2.6.32-358.59.1.el6.s390x.rpm kernel-debuginfo-common-s390x-2.6.32-358.59.1.el6.s390x.rpm kernel-kdump-debuginfo-2.6.32-358.59.1.el6.s390x.rpm perf-debuginfo-2.6.32-358.59.1.el6.s390x.rpm python-perf-2.6.32-358.59.1.el6.s390x.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.s390x.rpm x86_64: kernel-debug-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-358.59.1.el6.x86_64.rpm perf-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm python-perf-2.6.32-358.59.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-358.59.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2013-2596 https://access.redhat.com/security/cve/CVE-2014-5471 https://access.redhat.com/security/cve/CVE-2014-5472 https://access.redhat.com/security/cve/CVE-2014-8159 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVLRBVXlSAg2UNWIIRAiVzAJ9oSk/OQV4sVYthXHoALRjlGAHnDACgt1ho cQvYpw1ezsPe8xXt/c/zQcc=4t9L -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
This update includes the latest release of Subversion 1.1, including the fix for a regression in the performance of repository browsing since version 1.1.0 and a variety of other bug fixes.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-423 2004-11-12 --------------------------------------------------------------------- Product : Fedora Core 3 Name : subversion Version : 1.1.1 Release : 1.1 Summary : Modern Version Control System designed to replace CVS Description : Subversion is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. Subversion only stores the differences between versions, instead of every complete file. Subversion is intended to be a compelling replacement for CVS. --------------------------------------------------------------------- Update Information: This update includes the latest release of Subversion 1.1, including the fix for a regression in the performance of repository browsing since version 1.1.0 and a variety of other bug fixes. --------------------------------------------------------------------- * Mon Nov 01 2004 Joe Orton 1.1.1-1.1 - rebuild * Tue Oct 26 2004 Joe Orton 1.1.1-1 - update to 1.1.1 - update -pie patch to address #134786 --------------------------------------------------------------------- This update can be downloaded from: 7950b1867019c2f1fb063823429dd566 SRPMS/subversion-1.1.1-1.1.src.rpm a71fc8ef99a2c428403e88e92ab4dda7 x86_64/subversion-1.1.1-1.1.x86_64.rpm 84a6f711a8ea90f4babf5e1f1dbbdcd5 x86_64/subversion-devel-1.1.1-1.1.x86_64.rpm 710204eb85ecac9ceab9762f21752151 x86_64/mod_dav_svn-1.1.1-1.1.x86_64.rpm 69a924e907c4a5a09f2cf079bd3aa9df x86_64/subversion-perl-1.1.1-1.1.x86_64.rpm e442ea2789d36b4b8cbe5e03aee09765 x86_64/debug/subversion-debuginfo-1.1.1-1.1.x86_64.rpm a69040704a67fdfdf44ce8de99ce4910 i386/subversion-1.1.1-1.1.i386.rpm 89b945d2427cdfbe5b470fbe68ded954 i386/subversion-devel-1.1.1-1.1.i386.rpm fb74b1ef6239d95a542c44b3b3089a56 i386/mod_dav_svn-1.1.1-1.1.i386.rpm 1bd351d7bff4b4dd0a3ab248e1cb469b i386/subversion-perl-1.1.1-1.1.i386.rpm 90cd40af88674ea5e09ab0ab63b8401e i386/debug/subversion-debuginfo-1.1.1-1.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Elevate your Git workflow with the new Arch Linux release focusing on improving stability and resolving errors.. Subversion Update, Fedora Improvement, Bug Fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.