An update that solves one vulnerability can now be installed.. # Security update for iperf Announcement ID: SUSE-SU-2026:20403-1 Release Date: 2025-04-22T13:46:21Z Rating: moderate References: * bsc#1234705 Cross-References: * CVE-2024-53580 CVSS scores: * CVE-2024-53580 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-53580 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53580 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for iperf fixes the following issues: * CVE-2024-53580: Fixed segmentation violation via the iperf_exchange_parameters() function (bsc#1234705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-78=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * iperf-3.17.1-slfo.1.1_2.1 * libiperf0-debuginfo-3.17.1-slfo.1.1_2.1 * iperf-debuginfo-3.17.1-slfo.1.1_2.1 * libiperf0-3.17.1-slfo.1.1_2.1 * iperf-debugsource-3.17.1-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-53580.html * https://bugzilla.suse.com/show_bug.cgi?id=1234705 . SUSE security update for iperf addresses CVE-2024-53580 with moderate severity. Install patch for optimal protection.. iperf security update, SUSE Linux Micro, CVE-2024-53580, iperf patch. . LinuxSecurity.com Team
An issues has been found in taglib, an audio meta-data library. The issue is related to a segmentation violation and a resulting application crash due to processing a crafted WAV file in which an id3 chunk is the only valid chunk. For Debian 11 bullseye, this problem has been fixed in version. Debian LTS Advisory DLA-4450-1
* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References: . # Security update for Mesa Announcement ID: SUSE-SU-2025:20082-1 Release Date: 2025-02-03T09:06:43Z Rating: moderate References: * bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References: * CVE-2023-45913 * CVE-2023-45919 * CVE-2023-45922 CVSS scores: * CVE-2023-45913 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H * CVE-2023-45913 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45919 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:H * CVE-2023-45919 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2023-45922 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H * CVE-2023-45922 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for Mesa fixes the following issues: * CVE-2023-45913: Fixed NULL pointer dereference via dri2GetGlxDrawableFromXDrawableId() (bsc#1222040). * CVE-2023-45919: Fixed buffer over-read in glXQueryServerString() (bsc#1222041). * CVE-2023-45922: Fixed segmentation violation in __glXGetDrawableAttribute() (bsc#1222042). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-144=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * Mesa-dri-23.3.4-8.1 * Mesa-libGL1-debuginfo-23.3.4-8.1 * libgbm1-23.3.4-8.1 * Mesa-libglapi0-debuginfo-23.3.4-8.1 * Mesa-libGL1-23.3.4-8.1 * Mesa-debugsource-23.3.4-8.1 * libgbm1-debuginfo-23.3.4-8.1 * Mesa-libglapi0-23.3.4-8.1 * Mesa-drivers-debugsource-23.3.4-8.1 * Mesa-23.3.4-8.1 * Mesa-dri-debuginfo-23.3.4-8.1 *Mesa-libEGL1-debuginfo-23.3.4-8.1 * Mesa-libEGL1-23.3.4-8.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * Mesa-gallium-23.3.4-8.1 * Mesa-gallium-debuginfo-23.3.4-8.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45913.html * https://www.suse.com/security/cve/CVE-2023-45919.html * https://www.suse.com/security/cve/CVE-2023-45922.html * https://bugzilla.suse.com/show_bug.cgi?id=1222040 * https://bugzilla.suse.com/show_bug.cgi?id=1222041 * https://bugzilla.suse.com/show_bug.cgi?id=1222042 . SUSE Linux Micro 6.0 addresses three security flaws in Mesa through an urgent update, featuring essential guidance for patching.. SUSE Linux Micro, Mesa update, security patch, buffer over-read, NULL pointer fix. . LinuxSecurity.com Team
* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References: . # Security update for Mesa Announcement ID: SUSE-SU-2025:20082-1 Release Date: 2025-02-03T09:06:43Z Rating: moderate References: * bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References: * CVE-2023-45913 * CVE-2023-45919 * CVE-2023-45922 CVSS scores: * CVE-2023-45913 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H * CVE-2023-45913 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45919 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:H * CVE-2023-45919 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2023-45922 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H * CVE-2023-45922 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for Mesa fixes the following issues: * CVE-2023-45913: Fixed NULL pointer dereference via dri2GetGlxDrawableFromXDrawableId() (bsc#1222040). * CVE-2023-45919: Fixed buffer over-read in glXQueryServerString() (bsc#1222041). * CVE-2023-45922: Fixed segmentation violation in __glXGetDrawableAttribute() (bsc#1222042). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-144=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * Mesa-libglapi0-23.3.4-8.1 * Mesa-dri-23.3.4-8.1 * libgbm1-23.3.4-8.1 * Mesa-libEGL1-23.3.4-8.1 * Mesa-debugsource-23.3.4-8.1 * Mesa-libglapi0-debuginfo-23.3.4-8.1 * Mesa-drivers-debugsource-23.3.4-8.1 * Mesa-23.3.4-8.1 * Mesa-libEGL1-debuginfo-23.3.4-8.1 * libgbm1-debuginfo-23.3.4-8.1 * Mesa-dri-debuginfo-23.3.4-8.1 *Mesa-libGL1-23.3.4-8.1 * Mesa-libGL1-debuginfo-23.3.4-8.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * Mesa-gallium-debuginfo-23.3.4-8.1 * Mesa-gallium-23.3.4-8.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45913.html * https://www.suse.com/security/cve/CVE-2023-45919.html * https://www.suse.com/security/cve/CVE-2023-45922.html * https://bugzilla.suse.com/show_bug.cgi?id=1222040 * https://bugzilla.suse.com/show_bug.cgi?id=1222041 * https://bugzilla.suse.com/show_bug.cgi?id=1222042 . Protective upgrade for Mesa tackling various vulnerabilities and boosting defense against risks.. SUSE Linux Micro, Mesa Update, Security Fixes. . LinuxSecurity.com Team
* bsc#1234705 Cross-References: * CVE-2024-53580 . # Security update for iperf Announcement ID: SUSE-SU-2025:20290-1 Release Date: 2025-04-22T13:46:21Z Rating: moderate References: * bsc#1234705 Cross-References: * CVE-2024-53580 CVSS scores: * CVE-2024-53580 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-53580 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53580 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro Extras 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for iperf fixes the following issues: * CVE-2024-53580: Fixed segmentation violation via the iperf_exchange_parameters() function (bsc#1234705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-78=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * iperf-debuginfo-3.17.1-slfo.1.1_2.1 * iperf-debugsource-3.17.1-slfo.1.1_2.1 * iperf-3.17.1-slfo.1.1_2.1 * libiperf0-debuginfo-3.17.1-slfo.1.1_2.1 * libiperf0-3.17.1-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-53580.html * https://bugzilla.suse.com/show_bug.cgi?id=1234705 . New iPerf update released for SUSE to address a moderate risk vulnerability, avoiding segmentation faults. Ensure installation is completed without delay.. SUSE Security Advisory, iperf Update, Segmentation Fix, Linux Security Patch. . LinuxSecurity.com Team
Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1aff9a0e04 2025-03-16 00:15:25.688701+00:00 -------------------------------------------------------------------------------- Name : ffmpeg Product : Fedora 42 Version : 7.1.1 Release : 1.fc42 URL : https://ffmpeg.org/ Summary : A complete solution to record, convert and stream audio and video Description : FFmpeg is a leading multimedia framework, able to decode, encode, transcode, mux, demux, stream, filter and play pretty much anything that humans and machines have created. It supports the most obscure ancient formats up to the cutting edge. No matter if they were designed by some standards committee, the community or a corporation. This build of ffmpeg is limited in the number of codecs supported. -------------------------------------------------------------------------------- Update Information: Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921. -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 6 2025 Dominik Mierzejewski - 7.1.1-1 - Update to 7.1.1 (resolves rhbz#2349351) - Enable LC3 codec via liblc3 - Backport fix for CVE-2025-22921 (resolves rhbz#2346558) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2346558 - CVE-2025-22921 ffmpeg: Segmentation Violation in FFmpeg [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2346558 [ 2 ] Bug #2346566 - CVE-2025-25468 ffmpeg: Memory Leak in FFmpeg libavutil/mem.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2346566 [ 3 ] Bug #2349351 - ffmpeg-7.1.1 isavailable https://bugzilla.redhat.com/show_bug.cgi?id=2349351 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1aff9a0e04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ab5fe60520 2025-03-13 01:09:59.782815+00:00 -------------------------------------------------------------------------------- Name : ffmpeg Product : Fedora 41 Version : 7.1.1 Release : 1.fc41 URL : https://ffmpeg.org/ Summary : A complete solution to record, convert and stream audio and video Description : FFmpeg is a leading multimedia framework, able to decode, encode, transcode, mux, demux, stream, filter and play pretty much anything that humans and machines have created. It supports the most obscure ancient formats up to the cutting edge. No matter if they were designed by some standards committee, the community or a corporation. This build of ffmpeg is limited in the number of codecs supported. -------------------------------------------------------------------------------- Update Information: Latest maintenance release from 7.1 branch. Changelog: https://github.com/FFmpeg/FFmpeg/blob/n7.1.1/Changelog . Contains backported fix for CVE-2025-22921. -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 6 2025 Dominik Mierzejewski - 7.1.1-1 - Update to 7.1.1 (resolves rhbz#2349351) - Enable LC3 codec via liblc3 - Backport fix for CVE-2025-22921 (resolves rhbz#2346558) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2346558 - CVE-2025-22921 ffmpeg: Segmentation Violation in FFmpeg [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2346558 [ 2 ] Bug #2346566 - CVE-2025-25468 ffmpeg: Memory Leak in FFmpeg libavutil/mem.c [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2346566 [ 3 ] Bug #2349351 - ffmpeg-7.1.1 isavailable https://bugzilla.redhat.com/show_bug.cgi?id=2349351 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ab5fe60520' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1234705 Cross-References: * CVE-2024-53580 . # Security update for iperf Announcement ID: SUSE-SU-2025:0291-1 Release Date: 2025-01-29T16:12:00Z Rating: moderate References: * bsc#1234705 Cross-References: * CVE-2024-53580 CVSS scores: * CVE-2024-53580 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-53580 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53580 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for iperf fixes the following issues: * Update to version 3.18 * CVE-2024-53580: Fixed a segmentation violation via the iperf_exchange_parameters() function. (bsc#1234705) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-291=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-291=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-291=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * iperf-3.18-150000.3.12.1 * iperf-devel-3.18-150000.3.12.1 * iperf-debugsource-3.18-150000.3.12.1 * libiperf0-3.18-150000.3.12.1 * libiperf0-debuginfo-3.18-150000.3.12.1 * iperf-debuginfo-3.18-150000.3.12.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * iperf-3.18-150000.3.12.1 *iperf-devel-3.18-150000.3.12.1 * iperf-debugsource-3.18-150000.3.12.1 * libiperf0-3.18-150000.3.12.1 * libiperf0-debuginfo-3.18-150000.3.12.1 * iperf-debuginfo-3.18-150000.3.12.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * iperf-3.18-150000.3.12.1 * iperf-debugsource-3.18-150000.3.12.1 * libiperf0-3.18-150000.3.12.1 * libiperf0-debuginfo-3.18-150000.3.12.1 * iperf-debuginfo-3.18-150000.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-53580.html * https://bugzilla.suse.com/show_bug.cgi?id=1234705 . A crucial patch for iperf addresses a segmentation fault, improving reliability across SUSE offerings.. iperf update, SUSE security advisory, software patch, iperf segmentation, SUSE product update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.