An update that solves three vulnerabilities can now be installed.. # Security update for mozjs78 Announcement ID: SUSE-SU-2026:1956-1 Release Date: 2026-05-18T07:57:21Z Rating: important References: * bsc#1259713 * bsc#1259728 * bsc#1259731 Cross-References: * CVE-2026-32776 * CVE-2026-32777 * CVE-2026-32778 CVSS scores: * CVE-2026-32776 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32776 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32776 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32778 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32778 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for mozjs78 fixes the following issues * CVE-2026-32776: libexpat: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728). * CVE-2026-32777: libexpat: denial of service due to infinite loop in DTD content parsing (bsc#1259713). * CVE-2026-32778: libexpat: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259731). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1956=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1956=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1956=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1956=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1956=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1956=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1956=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1956=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1956=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1956=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 *libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * mozjs78-devel-78.15.0-150400.3.17.1 * libmozjs-78-0-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debuginfo-78.15.0-150400.3.17.1 * mozjs78-debugsource-78.15.0-150400.3.17.1 * libmozjs-78-0-78.15.0-150400.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32776.html * https://www.suse.com/security/cve/CVE-2026-32777.html * https://www.suse.com/security/cve/CVE-2026-32778.html * https://bugzilla.suse.com/show_bug.cgi?id=1259713 * https://bugzilla.suse.com/show_bug.cgi?id=1259728 * https://bugzilla.suse.com/show_bug.cgi?id=1259731 . # Security update for mozjs78 Announcement ID: SUSE-SU-2026:1956-1 Release Date: 2026-05-18T07:57:21. update, solves, three, vulnerabilities, installed, security, mozjs78. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for expat Announcement ID: SUSE-SU-2026:1137-1 Release Date: 2026-03-28T02:34:02Z Rating: important References: * bsc#1259711 * bsc#1259726 * bsc#1259729 Cross-References: * CVE-2026-32776 * CVE-2026-32777 * CVE-2026-32778 CVSS scores: * CVE-2026-32776 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32776 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32776 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32776 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32777 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32777 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-32778 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32778 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-32778 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for expat fixes the following issues: * CVE-2026-32776: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259726). * CVE-2026-32777: denial of service due to infinite loop in DTD content parsing (bsc#1259711). * CVE-2026-32778: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259729). ## Patch Instructions: To install this SUSE update usethe SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1137=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-1137=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * expat-debugsource-2.7.1-150000.3.45.1 * libexpat1-2.7.1-150000.3.45.1 * expat-debuginfo-2.7.1-150000.3.45.1 * libexpat1-debuginfo-2.7.1-150000.3.45.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * expat-debugsource-2.7.1-150000.3.45.1 * libexpat1-2.7.1-150000.3.45.1 * expat-debuginfo-2.7.1-150000.3.45.1 * libexpat1-debuginfo-2.7.1-150000.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32776.html * https://www.suse.com/security/cve/CVE-2026-32777.html * https://www.suse.com/security/cve/CVE-2026-32778.html * https://bugzilla.suse.com/show_bug.cgi?id=1259711 * https://bugzilla.suse.com/show_bug.cgi?id=1259726 * https://bugzilla.suse.com/show_bug.cgi?id=1259729 . An important security update for SUSE expat addresses multiple vulnerabilities, including DoS and pointer dereference risks.. SUSE update, expat patch, security advisory, CVE fix, Linux vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1228924 Cross-References: * CVE-2024-7006 . # Security update for tiff Announcement ID: SUSE-SU-2025:20068-1 Release Date: 2025-02-03T09:01:28Z Rating: moderate References: * bsc#1228924 Cross-References: * CVE-2024-7006 CVSS scores: * CVE-2024-7006 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7006 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for tiff fixes the following issues: * CVE-2024-7006: Fix pointer deref in tif_dirinfo.c [bsc#1228924] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-89=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libtiff6-4.6.0-4.1 * libtiff6-debuginfo-4.6.0-4.1 * tiff-debugsource-4.6.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7006.html * https://bugzilla.suse.com/show_bug.cgi?id=1228924 . SUSE Security Patch for libjpeg tackles CVE-2024-7007 to improve performance and resolve security flaws in the environment.. SUSE Linux Micro, tiff security, CVE-2024-7006, security update. . LinuxSecurity.com Team
* bsc#1228924 Cross-References: * CVE-2024-7006 . # Security update for tiff Announcement ID: SUSE-SU-2025:20068-1 Release Date: 2025-02-03T09:01:28Z Rating: moderate References: * bsc#1228924 Cross-References: * CVE-2024-7006 CVSS scores: * CVE-2024-7006 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7006 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for tiff fixes the following issues: * CVE-2024-7006: Fix pointer deref in tif_dirinfo.c [bsc#1228924] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-89=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libtiff6-debuginfo-4.6.0-4.1 * libtiff6-4.6.0-4.1 * tiff-debugsource-4.6.0-4.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7006.html * https://bugzilla.suse.com/show_bug.cgi?id=1228924 . SUSE issues an update for tiff targeting CVE-2024-7006 to resolve a pointer handling vulnerability.. SUSE Security Patch, tiff Update, pointer Security Issue. . LinuxSecurity.com Team
This update for ncurses fixes the following issues: CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061).. # Security update for ncurses Announcement ID: SUSE-SU-2024:1133-1 Rating: moderate References: * bsc#1220061 Cross-References: * CVE-2023-45918 CVSS scores: * CVE-2023-45918 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP5 * Development Tools Module 15-SP5 * Legacy Module 15-SP5 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ncurses fixes the following issues: * CVE-2023-45918: Fixed NULL pointer dereference via corrupted xterm-256color file (bsc#1220061). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-1133=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-1133=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1133=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-1133=1 * SUSE Linux Enterprise Micro 5.3 zypper in -tpatch SUSE-SLE-Micro-5.3-2024-1133=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1133=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-1133=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1133=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1133=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-1133=1 * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-1133=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-1133=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1133=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1133=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * openSUSE Leap 15.5 (x86_64) * ncurses-devel-32bit-debuginfo-6.1-150000.5.24.1 * libncurses5-32bit-debuginfo-6.1-150000.5.24.1 * ncurses5-devel-32bit-6.1-150000.5.24.1 * libncurses5-32bit-6.1-150000.5.24.1 * ncurses-devel-32bit-6.1-150000.5.24.1 * libncurses6-32bit-debuginfo-6.1-150000.5.24.1 * libncurses6-32bit-6.1-150000.5.24.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) *ncurses-devel-6.1-150000.5.24.1 * ncurses5-devel-6.1-150000.5.24.1 * tack-debuginfo-6.1-150000.5.24.1 * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * tack-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * libncurses5-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * libncurses5-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * ncurses-devel-debuginfo-6.1-150000.5.24.1 * terminfo-iterm-6.1-150000.5.24.1 * terminfo-screen-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE LinuxEnterprise Micro 5.5 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * ncurses-devel-6.1-150000.5.24.1 * terminfo-base-6.1-150000.5.24.1 * tack-debuginfo-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * tack-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * ncurses-devel-debuginfo-6.1-150000.5.24.1 * terminfo-iterm-6.1-150000.5.24.1 * terminfo-screen-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * Basesystem Module 15-SP5 (x86_64) * libncurses6-32bit-debuginfo-6.1-150000.5.24.1 * libncurses6-32bit-6.1-150000.5.24.1 * Development Tools Module 15-SP5 (x86_64) * ncurses-devel-32bit-debuginfo-6.1-150000.5.24.1 * ncurses-devel-32bit-6.1-150000.5.24.1 * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * ncurses-debugsource-6.1-150000.5.24.1 * libncurses5-debuginfo-6.1-150000.5.24.1 * ncurses5-devel-6.1-150000.5.24.1 * libncurses5-6.1-150000.5.24.1 * Legacy Module 15-SP5 (x86_64) * libncurses5-32bit-debuginfo-6.1-150000.5.24.1 * libncurses5-32bit-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * terminfo-base-6.1-150000.5.24.1 * ncurses-debugsource-6.1-150000.5.24.1 * libncurses6-6.1-150000.5.24.1 * ncurses-utils-6.1-150000.5.24.1 * terminfo-6.1-150000.5.24.1 * libncurses6-debuginfo-6.1-150000.5.24.1 * ncurses-utils-debuginfo-6.1-150000.5.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45918.html * https://bugzilla.suse.com/show_bug.cgi?id=1220061 . A recent patch resolves a vulnerability related to pointer dereference in ncurses, strengthening security measures for multiple openSUSE editions.. Ncurses Patch,System Update,OpenSUSE Security,Moderate Advisory,Pointer Dereference. . LinuxSecurity.com Team
x86 shadow paging arbitrary pointer dereference [XSA-430, CVE-2022-42335]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d28433ead1 2023-04-28 02:35:08.160946 --------------------------------------------------------------------------------Name : xen Product : Fedora 38 Version : 4.17.0 Release : 9.fc38 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor --------------------------------------------------------------------------------Update Information: x86 shadow paging arbitrary pointer dereference [XSA-430, CVE-2022-42335] --------------------------------------------------------------------------------ChangeLog: * Tue Apr 25 2023 Michael Young - 4.17.0-9 - x86 shadow paging arbitrary pointer dereference [XSA-430, CVE-2022-42335] --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d28433ead1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for krb5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4154-1 Rating: important References: #1189929 #1205126 Cross-References: CVE-2021-37750 CVE-2022-42898 CVSS scores: CVE-2021-37750 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-37750 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2022-42898 (SUSE): 6.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L Affected Products: SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server for SAP 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for krb5 fixes the following issues: - CVE-2021-37750: Fixed KDC null pointer dereference via a FAST inner body that lacks a server field (bsc#1189929). - CVE-2022-42898: Fixed integer overflow in PAC parsing (bsc#1205126). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-4154=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2022-4154=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-4154=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patchSUSE-SLE-Product-HPC-15-2022-4154=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): krb5-1.15.2-150000.6.17.1 krb5-client-1.15.2-150000.6.17.1 krb5-client-debuginfo-1.15.2-150000.6.17.1 krb5-debuginfo-1.15.2-150000.6.17.1 krb5-debugsource-1.15.2-150000.6.17.1 krb5-devel-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-debuginfo-1.15.2-150000.6.17.1 krb5-server-1.15.2-150000.6.17.1 krb5-server-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise Server for SAP 15 (x86_64): krb5-32bit-1.15.2-150000.6.17.1 krb5-32bit-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): krb5-1.15.2-150000.6.17.1 krb5-client-1.15.2-150000.6.17.1 krb5-client-debuginfo-1.15.2-150000.6.17.1 krb5-debuginfo-1.15.2-150000.6.17.1 krb5-debugsource-1.15.2-150000.6.17.1 krb5-devel-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-debuginfo-1.15.2-150000.6.17.1 krb5-server-1.15.2-150000.6.17.1 krb5-server-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): krb5-1.15.2-150000.6.17.1 krb5-client-1.15.2-150000.6.17.1 krb5-client-debuginfo-1.15.2-150000.6.17.1 krb5-debuginfo-1.15.2-150000.6.17.1 krb5-debugsource-1.15.2-150000.6.17.1 krb5-devel-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-debuginfo-1.15.2-150000.6.17.1 krb5-server-1.15.2-150000.6.17.1 krb5-server-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (x86_64): krb5-32bit-1.15.2-150000.6.17.1 krb5-32bit-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): krb5-1.15.2-150000.6.17.1 krb5-client-1.15.2-150000.6.17.1 krb5-client-debuginfo-1.15.2-150000.6.17.1 krb5-debuginfo-1.15.2-150000.6.17.1 krb5-debugsource-1.15.2-150000.6.17.1 krb5-devel-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-1.15.2-150000.6.17.1 krb5-plugin-kdb-ldap-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-1.15.2-150000.6.17.1 krb5-plugin-preauth-otp-debuginfo-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-1.15.2-150000.6.17.1 krb5-plugin-preauth-pkinit-debuginfo-1.15.2-150000.6.17.1 krb5-server-1.15.2-150000.6.17.1 krb5-server-debuginfo-1.15.2-150000.6.17.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (x86_64): krb5-32bit-1.15.2-150000.6.17.1 krb5-32bit-debuginfo-1.15.2-150000.6.17.1 References: https://www.suse.com/security/cve/CVE-2021-37750.html https://www.suse.com/security/cve/CVE-2022-42898.html https://bugzilla.suse.com/1189929 https://bugzilla.suse.com/1205126 . A KB5 update addresses critical vulnerabilities with two new fixes released for SUSE users.. Krb5 Patch,SUSE Linux,Security Fixes,Important Security Update. . Severity: Important. LinuxSecurity.com Team
An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openssl security and bug fix update Advisory ID: RHSA-2021:4424-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4424 Issue date: 2021-11-09 CVE Names: CVE-2021-23840 CVE-2021-23841 ==================================================================== 1. Summary: An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: integer overflow in CipherUpdate (CVE-2021-23840) * openssl: NULL pointer dereference in X509_issuer_and_serial_hash() (CVE-2021-23841) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 1908036 - openssl listens on IPv4 "any" socket only not on IPv6 1930310 - CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash() 1930324 - CVE-2021-23840 openssl: integer overflow in CipherUpdate 1934534 - Rebase OpenSSL to 1.1.1k 1934600 - DTLS1.0 connections are allowed in DEFAULT crypto-policy [rhel-8] 1939637 - Openssl -dtls option breaks in FIPS mode[rhel8] 1940085 - FIPS_selftest() fails in FIPS mode. 1965362 - In renegotiated handshake openssl sends extensions which client didn't advertise in second ClientHello [rhel-8] 6. Package List: Red Hat Enterprise Linux BaseOS (v.8): Source: openssl-1.1.1k-4.el8.src.rpm aarch64: openssl-1.1.1k-4.el8.aarch64.rpm openssl-debuginfo-1.1.1k-4.el8.aarch64.rpm openssl-debugsource-1.1.1k-4.el8.aarch64.rpm openssl-devel-1.1.1k-4.el8.aarch64.rpm openssl-libs-1.1.1k-4.el8.aarch64.rpm openssl-libs-debuginfo-1.1.1k-4.el8.aarch64.rpm openssl-perl-1.1.1k-4.el8.aarch64.rpm ppc64le: openssl-1.1.1k-4.el8.ppc64le.rpm openssl-debuginfo-1.1.1k-4.el8.ppc64le.rpm openssl-debugsource-1.1.1k-4.el8.ppc64le.rpm openssl-devel-1.1.1k-4.el8.ppc64le.rpm openssl-libs-1.1.1k-4.el8.ppc64le.rpm openssl-libs-debuginfo-1.1.1k-4.el8.ppc64le.rpm openssl-perl-1.1.1k-4.el8.ppc64le.rpm s390x: openssl-1.1.1k-4.el8.s390x.rpm openssl-debuginfo-1.1.1k-4.el8.s390x.rpm openssl-debugsource-1.1.1k-4.el8.s390x.rpm openssl-devel-1.1.1k-4.el8.s390x.rpm openssl-libs-1.1.1k-4.el8.s390x.rpm openssl-libs-debuginfo-1.1.1k-4.el8.s390x.rpm openssl-perl-1.1.1k-4.el8.s390x.rpm x86_64: openssl-1.1.1k-4.el8.x86_64.rpm openssl-debuginfo-1.1.1k-4.el8.i686.rpm openssl-debuginfo-1.1.1k-4.el8.x86_64.rpm openssl-debugsource-1.1.1k-4.el8.i686.rpm openssl-debugsource-1.1.1k-4.el8.x86_64.rpm openssl-devel-1.1.1k-4.el8.i686.rpm openssl-devel-1.1.1k-4.el8.x86_64.rpm openssl-libs-1.1.1k-4.el8.i686.rpm openssl-libs-1.1.1k-4.el8.x86_64.rpm openssl-libs-debuginfo-1.1.1k-4.el8.i686.rpm openssl-libs-debuginfo-1.1.1k-4.el8.x86_64.rpm openssl-perl-1.1.1k-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-23840 https://access.redhat.com/security/cve/CVE-2021-23841 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.5_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYYrdYdzjgjWX9erEAQj6ABAAqRDnIaOs2B3rKsf4N+Yn925VrF08Yb7q x7j3ncYOIRGlsw5m363I2nkE1Fvf9w/O1aLXly3CTlLN1KpifKiRwBZOBVnBJC18 jDemxS0CvtuCxGwtESGRUawdRe6IkTF4z7zDVKjSDaPsNE5UOvpOX5DQaAEKVAvl GAiTKHgguLOaLNzwqEKOKCcWpQQOGUrzzN3JcTiqZTzPWShSzdvIsPcDf15nkK27 XVmplmluVxcaDbve7hVAx5Zo6/smM9UBVtgF2iEb45nxsGkh+czu6pHdowBbp4uP r4n9nSTI8Fl5HrtFYQERuf3Ft9+OWfVy7GSXxe5pNg3KVFyKVfo2bAPpt5cq1V7G 7ke1wnlKSNus/kUme+mtPjDZqTb4lbSsNq1MF37pZ1gUVsUU5C0J9lNTRdpcB2EK ZJRoPka2hXUpO9wGQfQ8c0Vvf93v6uN7X/0sTj42157nqJd0ry7/fmpvo7re/oKd xPHDALDjUvS4ZgUkqOb0G+fUb2LCLPUsWNEMql/WLZAfKZIVjcIeelIJSuJ8dLKv oZNVJOxAQbndFWHOpNRCVMayERK4XegHKQguDAEfWzVUAS4IGCc6cwY15KUJ5vaZ W9cJ1fu5LKx7Q19Wz3jYJkMnoy+JHYtU1WJJ5yUMwvQw1QgIcu15BNGKbydm7imX 2E9d3hgUSpw=WTA4 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.