* bsc#1243419 * bsc#1246995 Affected Products: * Public Cloud Module 12 . # Security update for regionServiceClientConfigAzure Announcement ID: SUSE-SU-2025:03169-1 Release Date: 2025-09-11T12:38:15Z Rating: critical References: * bsc#1243419 * bsc#1246995 Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two security fixes can now be installed. ## Description: This update for regionServiceClientConfigAzure contains the following fixes: * Update to version 3.0.0. (bsc#1246995) * SLE 16 python-requests requires SSL v3 certificates. Update 2 region server certs to support SLE 16 when it gets released. * Update dependency name for metadata package, name change in SLE 16. (bsc#1243419) * Replacing certificate for rgnsrv-azure-southeastasia to get rid of weird chain cert ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2025-3169=1 ## Package List: * Public Cloud Module 12 (noarch) *regionServiceClientConfigAzure-3.0.0-3.32.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1243419 * https://bugzilla.suse.com/show_bug.cgi?id=1246995 . A critical security patch is now available for the regionServiceClientConfigAzure in SUSE Linux Enterprise. Immediate updates are advised.. SUSE Public Cloud Module, Azure Security, Software Patching. . Severity: Critical. LinuxSecurity.com Team
* bsc#1243419 * bsc#1246995 Affected Products: * Public Cloud Module 12 . # Security update for regionServiceClientConfigEC2 Announcement ID: SUSE-SU-2025:03170-1 Release Date: 2025-09-11T12:38:40Z Rating: critical References: * bsc#1243419 * bsc#1246995 Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two security fixes can now be installed. ## Description: This update for regionServiceClientConfigEC2 contains the following fixes: * Update to version 5.0.0. (bsc#1246995) * SLE 16 python-requests requires SSL v3 certificates. Update 2 region server certs to support SLE 16 when it gets released. * Update dependency to accomodate metadata binary package name change in SLE 16. (bsc#1243419) * New 4096 certificate for rgnsrv-ec2-us-east1 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2025-3170=1 ## Package List: * Public Cloud Module 12 (noarch) *regionServiceClientConfigEC2-5.0.0-4.37.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1243419 * https://bugzilla.suse.com/show_bug.cgi?id=1246995 . Security update crucial for regionServiceClientConfigEC2 on SUSE Linux, addressing SSL certificates issues.. SUSE Linux, regionServiceClientConfigEC2, Public Cloud Module, security update, SSL certificates. . Severity: Critical. LinuxSecurity.com Team
* bsc#1242063 * bsc#1246995 Affected Products: * Public Cloud Module 12 . # Security update for regionServiceClientConfigGCE Announcement ID: SUSE-SU-2025:03171-1 Release Date: 2025-09-11T12:38:50Z Rating: critical References: * bsc#1242063 * bsc#1246995 Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has two security fixes can now be installed. ## Description: This update for regionServiceClientConfigGCE contains the following fixes: * Update to version 5.0.0. (bsc#1246995) * SLE 16 python-requests requires SSL v3 certificates. Update 2 region server certs to support SLE 16 when it gets released. * Update conditional to handle name change of metadata package in SLE 16. (bsc#1242063) * Add noipv6 patch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2025-3171=1 ## Package List: * Public Cloud Module 12 (noarch) * regionServiceClientConfigGCE-5.0.0-5.21.1 ## References: *https://bugzilla.suse.com/show_bug.cgi?id=1242063 * https://bugzilla.suse.com/show_bug.cgi?id=1246995 . Important patch for serviceConnectionSettingsGCE addresses numerous vulnerabilities. Swift response advised.. Public Cloud Module, SUSE Linux, system update, server integrity, configuration fix. . Severity: Critical. LinuxSecurity.com Team
* bsc#1242063 * bsc#1246995 Affected Products: * openSUSE Leap 15.6 . # Security update for regionServiceClientConfigGCE Announcement ID: SUSE-SU-2025:03119-1 Release Date: 2025-09-09T12:59:59Z Rating: critical References: * bsc#1242063 * bsc#1246995 Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that has two security fixes can now be installed. ## Description: This update for regionServiceClientConfigGCE contains the following fixes: * Update to version 5.0.0 (bsc#1246995) * SLE 16 python-requests requires SSL v3 certificates. Update 2 region server certs to support SLE 16 when it gets released. * Update conditional to handle name change of metadata package in SLE 16. (bsc#1242063) * Add noipv6 patch ## Patch Instructions: To install thisSUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-3119=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3119=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3119=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3119=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3119=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-3119=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2025-3119=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2025-3119=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2025-3119=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2025-3119=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2025-3119=1 ## Package List: * openSUSE Leap 15.6 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * Public Cloud Module 15-SP3 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * Public Cloud Module 15-SP4 (noarch) *regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * Public Cloud Module 15-SP5 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * Public Cloud Module 15-SP6 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 * Public Cloud Module 15-SP7 (noarch) * regionServiceClientConfigGCE-5.0.0-150000.4.18.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1242063 * https://bugzilla.suse.com/show_bug.cgi?id=1246995 . Essential security patch for regionServiceClientConfigGCE on openSUSE Leap addresses major setup vulnerabilities.. openSUSE security, critical updates, regionServiceClientConfigGCE, public cloud module. . Severity: Critical. LinuxSecurity.com Team
* bsc#1234563 * bsc#1239763 * bsc#1239866 Cross-References: . # Security update for google-guest-agent Announcement ID: SUSE-SU-2025:1142-1 Release Date: 2025-04-04T13:30:47Z Rating: important References: * bsc#1234563 * bsc#1239763 * bsc#1239866 Cross-References: * CVE-2024-45337 CVSS scores: * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2024-45337: golang.org/x/crypto/ssh: Fixed misuse of ServerConfig.PublicKeyCallback leading to authorization bypass (bsc#1234563). Other fixes: \- Updated to version 20250327.01 (bsc#1239763, bsc#1239866) * Remove error messages from gce_workload_cert_refresh and metadata script runner (#527) \- from version 20250327.00 * Update guest-logging-go dependency (#526) * Add 'created-by' metadata, and pass it as option to logging library (#508) * Revert "oslogin: Correctly handlenewlines at the end of modified files (#520)" (#523) * Re-enable disabled services if the core plugin was enabled (#522) * Enable guest services on package upgrade (#519) * oslogin: Correctly handle newlines at the end of modified files (#520) * Fix core plugin path (#518) * Fix package build issues (#517) * Fix dependencies ran go mod tidy -v (#515) * Fix debian build path (#514) * Bundle compat metadata script runner binary in package (#513) * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512) * Update startup/shutdown services to launch compat manager (#503) * Bundle new gce metadata script runner binary in agent package (#502) * Revert "Revert bundling new binaries in the package (#509)" (#511) \- from version 20250326.00 * Re- enable disabled services if the core plugin was enabled (#521) \- from version 20250324.00 * Enable guest services on package upgrade (#519) * oslogin: Correctly handle newlines at the end of modified files (#520) * Fix core plugin path (#518) * Fix package build issues (#517) * Fix dependencies ran go mod tidy -v (#515) * Fix debian build path (#514) * Bundle compat metadata script runner binary in package (#513) * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512) * Update startup/shutdown services to launch compat manager (#503) * Bundle new gce metadata script runner binary in agent package (#502) * Revert "Revert bundling new binaries in the package (#509)" (#511) * Revert bundling new binaries in the package (#509) * Fix typo in windows build script (#501) * Include core plugin binary for all packages (#500) * Start packaging compat manager (#498) * Start bundling ggactl_plugin_cleanup binary in all agent packages (#492) * scripts: introduce a wrapper to locally build deb package (#490) * Introduce compat-manager systemd unit (#497) \- from version 20250317.00 * Revert "Revert bundling new binaries in the package (#509)" (#511) * Revert bundling new binaries in the package (#509) * Fix typo in windows build script (#501) * Include core plugin binary for all packages (#500) *Start packaging compat manager (#498) * Start bundling ggactl_plugin_cleanup binary in all agent packages (#492) * scripts: introduce a wrapper to locally build deb package (#490) * Introduce compat-manager systemd unit (#497) \- from version 20250312.00 * Revert bundling new binaries in the package (#509) * Fix typo in windows build script (#501) * Include core plugin binary for all packages (#500) * Start packaging compat manager (#498) * Start bundling ggactl_plugin_cleanup binary in all agent packages (#492) * scripts: introduce a wrapper to locally build deb package (#490) * Introduce compat-manager systemd unit (#497) \- from version 20250305.00 * Revert bundling new binaries in the package (#509) * Fix typo in windows build script (#501) * Include core plugin binary for all packages (#500) * Start packaging compat manager (#498) * Start bundling ggactl_plugin_cleanup binary in all agent packages (#492) * scripts: introduce a wrapper to locally build deb package (#490) * Introduce compat-manager systemd unit (#497) \- from version 20250304.01 * Fix typo in windows build script (#501) \- from version 20250214.01 * Include core plugin binary for all packages (#500) \- from version 20250212.00 * Start packaging compat manager (#498) * Start bundling ggactl_plugin_cleanup binary in all agent packages (#492) \- from version 20250211.00 * scripts: introduce a wrapper to locally build deb package (#490) * Introduce compat-manager systemd unit (#497) \- from version 20250207.00 * vlan: toggle vlan configuration in debian packaging (#495) * vlan: move config out of unstable section (#494) * Add clarification to comments regarding invalid NICs and the `invalid` tag. (#493) * Include interfaces in lists even if it has an invalid MAC. (#489) * Fix windows package build failures (#491) * vlan: don't index based on the vlan ID (#486) * Revert PR #482 (#488) * Remove Amy and Zach from OWNERS (#487) * Skip interfaces in interfaceNames() instead of erroring if there is an (#482) * Fix Debian packaging if guestagent manager is not checked out (#485) \- from version 20250204.02 * force concourse to move version forward. \- from version 20250204.01 * vlan: toggle vlan configuration in debian packaging (#495) \- from version 20250204.00 * vlan: move config out of unstable section (#494) * Add clarification to comments regarding invalid NICs and the `invalid` tag. (#493) \- from version 20250203.01 * Include interfaces in lists even if it has an invalid MAC. (#489) \- from version 20250203.00 * Fix windows package build failures (#491) * vlan: don't index based on the vlan ID (#486) * Revert PR #482 (#488) * Remove Amy and Zach from OWNERS (#487) * Skip interfaces in interfaceNames() instead of erroring if there is an (#482) * Fix Debian packaging if guest agent manager is not checked out (#485) \- from version 20250122.00 * networkd(vlan): remove the interface in addition to config (#468) * Implement support for vlan dynamic removal, update dhclient to remove only if configured (#465) * Update logging library (#479) * Remove Pat from owners file. (#478) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2025-1142=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20250327.01-1.50.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45337.html * https://bugzilla.suse.com/show_bug.cgi?id=1234563 * https://bugzilla.suse.com/show_bug.cgi?id=1239763 * https://bugzilla.suse.com/show_bug.cgi?id=1239866 . Patch release for google-guest-agent addressing critical vulnerabilities impacting Public Cloud Module among other components.. google-guest-agent, SUSE, authorization bypass, public cloud module, security update. . Severity: Important. LinuxSecurity.com Team
* bsc#1230100 Cross-References: * CVE-2024-35255 . # Security update for python-azure-identity Announcement ID: SUSE-SU-2025:0750-1 Release Date: 2025-02-28T16:25:48Z Rating: moderate References: * bsc#1230100 Cross-References: * CVE-2024-35255 CVSS scores: * CVE-2024-35255 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-35255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-azure-identity fixes the following issues: * CVE-2024-35255: race condition leading to privilege escalation and unauthorized access to sensitive information in Azure Identity libraries (bsc#1230100). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-750=1 * Public Cloud Module15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2025-750=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2025-750=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2025-750=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2025-750=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python3-azure-identity-1.10.0.0-150200.6.7.1 * Public Cloud Module 15-SP3 (noarch) * python3-azure-identity-1.10.0.0-150200.6.7.1 * Public Cloud Module 15-SP4 (noarch) * python3-azure-identity-1.10.0.0-150200.6.7.1 * Public Cloud Module 15-SP5 (noarch) * python3-azure-identity-1.10.0.0-150200.6.7.1 * Public Cloud Module 15-SP6 (noarch) * python3-azure-identity-1.10.0.0-150200.6.7.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35255.html * https://bugzilla.suse.com/show_bug.cgi?id=1230100 . An important patch addresses a timing flaw in python-azure-identity for multiple SUSE versions. Secure your environments immediately.. python Azure identity patch, SUSE Linux update, privilege escalation fix. . LinuxSecurity.com Team
* bsc#1223726 Cross-References: * CVE-2024-30251 . # Security update for python-aiohttp Announcement ID: SUSE-SU-2024:4328-1 Release Date: 2024-12-16T13:16:13Z Rating: important References: * bsc#1223726 Cross-References: * CVE-2024-30251 CVSS scores: * CVE-2024-30251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2024-30251: Fixed infinite loop on specially crafted POST request (bsc#1223726). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: *openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4328=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2024-4328=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2024-4328=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-4328=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-4328=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2024-4328=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python-aiohttp-doc-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python-aiohttp-doc-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.21.1 * python3-aiohttp-3.6.0-150100.3.21.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30251.html *https://bugzilla.suse.com/show_bug.cgi?id=1223726 . An essential announcement for python-aiohttp concerning CVE-2024-30251. Apply the necessary updates on openSUSE and Cloud Modules.. python aiohttp updates, SUSE security announcement, CVE-2024-30251 patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1200528 Cross-References: * CVE-2022-1996 . # Security update for aws-iam-authenticator Announcement ID: SUSE-SU-2024:4329-1 Release Date: 2024-12-16T13:16:54Z Rating: critical References: * bsc#1200528 Cross-References: * CVE-2022-1996 CVSS scores: * CVE-2022-1996 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-1996 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-1996 ( NVD ): 9.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for aws-iam-authenticator fixes the following issues: * CVE-2022-1996: Fixed CORS bypass (bsc#1200528). ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4329=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-4329=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2024-4329=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2024-4329=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-4329=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-4329=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2024-4329=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * Public Cloud Module 15-SP2 (x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.5.3-150000.1.12.1 ## References: * https://www.suse.com/security/cve/CVE-2022-1996.html * https://bugzilla.suse.com/show_bug.cgi?id=1200528 . Important patch released for aws-iam-authenticator resolving a CORS circumvention vulnerability. Ensure you apply the required updates on your SUSE environment.. aws-iam-authenticator security update, openSUSE critical patch, CORS bypass fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.