Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6007-1
An update that solves three vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 54 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:02687-1 Release Date: 2025-08-04T17:04:20Z Rating: important References: * bsc#1245776 * bsc#1245793 * bsc#1245797 Cross-References: * CVE-2025-21702 * CVE-2025-37752 * CVE-2025-37797 CVSS scores: * CVE-2025-21702 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-37752 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-37797 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_195 fixes several issues. The following security issues were fixed: * CVE-2025-37797: net_sched: hfsc: Fix a UAF vulnerability in class handling (bsc#1245793). * CVE-2025-37752: net_sched: sch_sfq: move the limit validation (bsc#1245776). * CVE-2025-21702: pfifo_tail_enqueue: Drop new packet when sch-> limit == 0 (bsc#1245797). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-2687=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-2687=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_195-default-5-150300.2.1 * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP3_Update_54-debugsource-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-default-debuginfo-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-default-5-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_195-preempt-debuginfo-5-150300.2.1 * kernel-livepatch-5_3_18-150300_59_195-preempt-5-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-21702.html * https://www.suse.com/security/cve/CVE-2025-37752.html * https://www.suse.com/security/cve/CVE-2025-37797.html * https://bugzilla.suse.com/show_bug.cgi?id=1245776 * https://bugzilla.suse.com/show_bug.cgi?id=1245793 * https://bugzilla.suse.com/show_bug.cgi?id=1245797 . The recent release of Live Patch 54 for the Linux Kernel on openSUSE addresses several critical vulnerabilities, significantly bolstering system integrity and protection.. Linux Kernel, security advisory, openSUSE, system security, 2025 patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.