* bsc#1239889 Cross-References: * CVE-2025-31335 . # Security update for opensaml Announcement ID: SUSE-SU-2025:01500-1 Release Date: 2025-06-05T13:19:14Z Rating: moderate References: * bsc#1239889 Cross-References: * CVE-2025-31335 CVSS scores: * CVE-2025-31335 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2025-31335 ( NVD ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for opensaml fixes the following issues: * CVE-2025-31335: Fixed a bug where parameter manipulation allows the forging of signed SAML messages. (bsc#1239889) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2025-1500=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * opensaml-debuginfo-3.1.0-150300.3.3.1 * opensaml-schemas-3.1.0-150300.3.3.1 * libsaml11-debuginfo-3.1.0-150300.3.3.1 * libsaml-devel-3.1.0-150300.3.3.1 * opensaml-debugsource-3.1.0-150300.3.3.1 * libsaml11-3.1.0-150300.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31335.html * https://bugzilla.suse.com/show_bug.cgi?id=1239889 . A patch for SUSE addresses a significant issue in opensaml regarding parameter handling. Crucial for operational integrity in server environments.. SUSE Update, Opensaml Security, Server Applications Fix, Security Advisory, Moderate Rating. . LinuxSecurity.com Team
* bsc#1216423 Cross-References: * CVE-2023-45802 . # Security update for apache2 Announcement ID: SUSE-SU-2024:3961-1 Release Date: 2024-11-09T16:37:56Z Rating: important References: * bsc#1216423 Cross-References: * CVE-2023-45802 CVSS scores: * CVE-2023-45802 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45802 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2023-45802: HTTP/2 stream memory not reclaimed right away on RST (bsc#1216423). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patchSUSE-2024-3961=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3961=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-3961=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3961=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-3961=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-3961=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3961=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3961=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-3961=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3961=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3961=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-3961=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-3961=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-3961=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-example-pages-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-event-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 *apache2-event-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * openSUSE Leap 15.4 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-example-pages-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-event-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-event-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * openSUSE Leap 15.5 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-event-debuginfo-2.4.51-150400.6.40.1 * apache2-event-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * Server Applications Module 15-SP5 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * Server Applications Module 15-SP6 (noarch) *apache2-doc-2.4.51-150400.6.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 *apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Manager Proxy 4.3 (x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Manager Proxy 4.3 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Manager Retail BranchServer 4.3 (noarch) * apache2-doc-2.4.51-150400.6.40.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * apache2-devel-2.4.51-150400.6.40.1 * apache2-utils-debuginfo-2.4.51-150400.6.40.1 * apache2-worker-debuginfo-2.4.51-150400.6.40.1 * apache2-debugsource-2.4.51-150400.6.40.1 * apache2-2.4.51-150400.6.40.1 * apache2-utils-2.4.51-150400.6.40.1 * apache2-prefork-2.4.51-150400.6.40.1 * apache2-worker-2.4.51-150400.6.40.1 * apache2-debuginfo-2.4.51-150400.6.40.1 * apache2-prefork-debuginfo-2.4.51-150400.6.40.1 * SUSE Manager Server 4.3 (noarch) * apache2-doc-2.4.51-150400.6.40.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45802.html * https://bugzilla.suse.com/show_bug.cgi?id=1216423 . SUSE has launched an important security patch for nginx, addressing CVE-2023-45792 along with updates applicable to several versions and components.. apache2 security updates, SUSE important announcement, memory issue patching. . Severity: Important. LinuxSecurity.com Team
* bsc#1227270 * bsc#1227271 Cross-References: * CVE-2024-38477 . # Security update for apache2 Announcement ID: SUSE-SU-2024:2405-1 Rating: important References: * bsc#1227270 * bsc#1227271 Cross-References: * CVE-2024-38477 * CVE-2024-39573 CVSS scores: * CVE-2024-38477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-39573 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2024-38477: Fixed null pointer dereference in mod_proxy (bsc#1227270) * CVE-2024-39573: Fixed potential SSRF in mod_rewrite (bsc#1227271) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2405=1 SUSE-2024-2405=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2405=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2405=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-2405=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * apache2-prefork-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-event-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-utils-2.4.58-150600.5.11.1 * apache2-utils-debuginfo-2.4.58-150600.5.11.1 * apache2-event-debuginfo-2.4.58-150600.5.11.1 * apache2-utils-debugsource-2.4.58-150600.5.11.1 * apache2-event-debugsource-2.4.58-150600.5.11.1 * apache2-2.4.58-150600.5.11.1 * apache2-devel-2.4.58-150600.5.11.1 * apache2-prefork-debuginfo-2.4.58-150600.5.11.1 * apache2-worker-2.4.58-150600.5.11.1 * apache2-worker-debugsource-2.4.58-150600.5.11.1 * apache2-worker-debuginfo-2.4.58-150600.5.11.1 * apache2-prefork-debugsource-2.4.58-150600.5.11.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.58-150600.5.11.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-prefork-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-2.4.58-150600.5.11.1 * apache2-prefork-debuginfo-2.4.58-150600.5.11.1 * apache2-prefork-debugsource-2.4.58-150600.5.11.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-event-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-event-debuginfo-2.4.58-150600.5.11.1 * apache2-event-debugsource-2.4.58-150600.5.11.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-utils-2.4.58-150600.5.11.1 * apache2-utils-debuginfo-2.4.58-150600.5.11.1 * apache2-utils-debugsource-2.4.58-150600.5.11.1 * apache2-worker-2.4.58-150600.5.11.1 * apache2-devel-2.4.58-150600.5.11.1 * apache2-worker-debugsource-2.4.58-150600.5.11.1 * apache2-worker-debuginfo-2.4.58-150600.5.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38477.html * https://www.suse.com/security/cve/CVE-2024-39573.html * https://bugzilla.suse.com/show_bug.cgi?id=1227270 * https://bugzilla.suse.com/show_bug.cgi?id=1227271 . Important patches for apache2 focusing on vital security vulnerabilities such as null pointer dereference and SSRF attacks.. apache2 Security Updates,SUSE Advisory,Server Security,CriticalUpdate,Important Security Advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1222584 * bsc#1223849 Cross-References: * CVE-2024-4418 . # Security update for libvirt Announcement ID: SUSE-SU-2024:1962-1 Rating: moderate References: * bsc#1222584 * bsc#1223849 Cross-References: * CVE-2024-4418 CVSS scores: * CVE-2024-4418 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2024-4418: Fixed a stack use-after-free by ensuring temporary GSource is removed from client event loop. (bsc#1223849) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-1962=1 SUSE-2024-1962=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-1962=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-1962=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libvirt-daemon-proxy-10.0.0-150600.8.3.1 * libvirt-libs-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-lockd-10.0.0-150600.8.3.1 * libvirt-daemon-driver-lxc-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-logical-10.0.0-150600.8.3.1 * libvirt-daemon-lock-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-150600.8.3.1 * wireshark-plugin-libvirt-10.0.0-150600.8.3.1 * libvirt-daemon-driver-interface-10.0.0-150600.8.3.1 * libvirt-daemon-driver-network-10.0.0-150600.8.3.1 * libvirt-daemon-driver-lxc-10.0.0-150600.8.3.1 * libvirt-daemon-log-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-qemu-10.0.0-150600.8.3.1 * libvirt-daemon-driver-interface-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-150600.8.3.1 * libvirt-10.0.0-150600.8.3.1 * libvirt-client-qemu-10.0.0-150600.8.3.1 * libvirt-libs-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-core-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-common-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-log-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-disk-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nodedev-10.0.0-150600.8.3.1 * libvirt-devel-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-gluster-10.0.0-150600.8.3.1 * libvirt-daemon-common-10.0.0-150600.8.3.1 * libvirt-debugsource-10.0.0-150600.8.3.1 * libvirt-daemon-driver-qemu-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-sanlock-10.0.0-150600.8.3.1 * libvirt-daemon-lock-debuginfo-10.0.0-150600.8.3.1 * libvirt-nss-10.0.0-150600.8.3.1 * libvirt-client-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-gluster-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-sanlock-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-config-nwfilter-10.0.0-150600.8.3.1 * libvirt-daemon-config-network-10.0.0-150600.8.3.1 * libvirt-daemon-lxc-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-150600.8.3.1 *wireshark-plugin-libvirt-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-scsi-10.0.0-150600.8.3.1 * libvirt-daemon-proxy-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nwfilter-10.0.0-150600.8.3.1 * libvirt-client-10.0.0-150600.8.3.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-secret-10.0.0-150600.8.3.1 * libvirt-daemon-10.0.0-150600.8.3.1 * libvirt-daemon-hooks-10.0.0-150600.8.3.1 * libvirt-nss-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-mpath-10.0.0-150600.8.3.1 * openSUSE Leap 15.6 (x86_64) * libvirt-client-32bit-debuginfo-10.0.0-150600.8.3.1 * libvirt-devel-32bit-10.0.0-150600.8.3.1 * libvirt-daemon-xen-10.0.0-150600.8.3.1 * libvirt-daemon-driver-libxl-10.0.0-150600.8.3.1 * libvirt-daemon-driver-libxl-debuginfo-10.0.0-150600.8.3.1 * openSUSE Leap 15.6 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-150600.8.3.1 * openSUSE Leap 15.6 (noarch) * libvirt-doc-10.0.0-150600.8.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libvirt-devel-64bit-10.0.0-150600.8.3.1 * libvirt-client-64bit-debuginfo-10.0.0-150600.8.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libvirt-libs-10.0.0-150600.8.3.1 * libvirt-libs-debuginfo-10.0.0-150600.8.3.1 * libvirt-debugsource-10.0.0-150600.8.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-proxy-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-lockd-10.0.0-150600.8.3.1 *libvirt-daemon-driver-storage-logical-10.0.0-150600.8.3.1 * libvirt-daemon-lock-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-interface-10.0.0-150600.8.3.1 * libvirt-daemon-driver-network-10.0.0-150600.8.3.1 * libvirt-daemon-log-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-qemu-10.0.0-150600.8.3.1 * libvirt-daemon-driver-interface-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-150600.8.3.1 * libvirt-10.0.0-150600.8.3.1 * libvirt-client-qemu-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-core-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-common-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-log-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-disk-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nodedev-10.0.0-150600.8.3.1 * libvirt-devel-10.0.0-150600.8.3.1 * libvirt-daemon-common-10.0.0-150600.8.3.1 * libvirt-debugsource-10.0.0-150600.8.3.1 * libvirt-daemon-driver-qemu-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-sanlock-10.0.0-150600.8.3.1 * libvirt-daemon-lock-debuginfo-10.0.0-150600.8.3.1 * libvirt-nss-10.0.0-150600.8.3.1 * libvirt-client-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-150600.8.3.1 * libvirt-daemon-plugin-sanlock-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-config-nwfilter-10.0.0-150600.8.3.1 * libvirt-daemon-config-network-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-150600.8.3.1 *libvirt-daemon-driver-network-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-scsi-10.0.0-150600.8.3.1 * libvirt-daemon-proxy-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-nwfilter-10.0.0-150600.8.3.1 * libvirt-client-10.0.0-150600.8.3.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-secret-10.0.0-150600.8.3.1 * libvirt-daemon-10.0.0-150600.8.3.1 * libvirt-daemon-hooks-10.0.0-150600.8.3.1 * libvirt-nss-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-mpath-10.0.0-150600.8.3.1 * Server Applications Module 15-SP6 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-10.0.0-150600.8.3.1 * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-150600.8.3.1 * Server Applications Module 15-SP6 (noarch) * libvirt-doc-10.0.0-150600.8.3.1 * Server Applications Module 15-SP6 (x86_64) * libvirt-daemon-xen-10.0.0-150600.8.3.1 * libvirt-daemon-driver-libxl-10.0.0-150600.8.3.1 * libvirt-daemon-driver-libxl-debuginfo-10.0.0-150600.8.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4418.html * https://bugzilla.suse.com/show_bug.cgi?id=1222584 * https://bugzilla.suse.com/show_bug.cgi?id=1223849 . Patch released for libvirt addressing a moderate security vulnerability, remediating CVE-2024-4418. Detailed instructions for installation provided.. Libvirt Security Update, SUSE Patch Instructions, Stack Use-After-Free Fix. . LinuxSecurity.com Team
* bsc#1219836 Cross-References: * CVE-2024-1062 . # Security update for 389-ds Announcement ID: SUSE-SU-2024:1906-1 Rating: moderate References: * bsc#1219836 Cross-References: * CVE-2024-1062 CVSS scores: * CVE-2024-1062 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for 389-ds fixes the following issues: * Update to version 2.2.8~git65.347aae6: * CVE-2024-1062: Resolved possible denial of service when audit logging is enabled. (bsc#1219836) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-1906=1 openSUSE-SLE-15.6-2024-1906=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-1906=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * 389-ds-debuginfo-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-snmp-debuginfo-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-snmp-2.2.8~git65.347aae6-150600.8.3.1 * libsvrcore0-debuginfo-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-devel-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-debugsource-2.2.8~git65.347aae6-150600.8.3.1 * lib389-2.2.8~git65.347aae6-150600.8.3.1 * libsvrcore0-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-2.2.8~git65.347aae6-150600.8.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * 389-ds-debuginfo-2.2.8~git65.347aae6-150600.8.3.1 * libsvrcore0-debuginfo-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-devel-2.2.8~git65.347aae6-150600.8.3.1 *389-ds-debugsource-2.2.8~git65.347aae6-150600.8.3.1 * lib389-2.2.8~git65.347aae6-150600.8.3.1 * libsvrcore0-2.2.8~git65.347aae6-150600.8.3.1 * 389-ds-2.2.8~git65.347aae6-150600.8.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-1062.html * https://bugzilla.suse.com/show_bug.cgi?id=1219836 . SUSE has announced a significant security patch for 389-ds addressing a denial of service vulnerability within its audit logging functionalities.. 389-ds Security Update, SUSE Patching Instructions, Denial of Service. . LinuxSecurity.com Team
* bsc#1212119 * bsc#1216376 Cross-References: * CVE-2023-45145 . # Security update for redis7 Announcement ID: SUSE-SU-2024:0200-1 Rating: important References: * bsc#1212119 * bsc#1216376 Cross-References: * CVE-2023-45145 CVSS scores: * CVE-2023-45145 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-45145 ( NVD ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for redis7 fixes the following issues: * CVE-2023-45145: Fixed a potential permission bypass due to a race condition during UNIX socket creation (bsc#1216376). The following non-security issues were fixed: * Redis services are no longer disabled after an upgrade (bsc#1212119). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-200=1 openSUSE-SLE-15.5-2024-200=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-200=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * redis7-debugsource-7.0.8-150500.3.9.1 * redis7-7.0.8-150500.3.9.1 * redis7-debuginfo-7.0.8-150500.3.9.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * redis7-debugsource-7.0.8-150500.3.9.1 * redis7-7.0.8-150500.3.9.1 * redis7-debuginfo-7.0.8-150500.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45145.html *https://bugzilla.suse.com/show_bug.cgi?id=1212119 * https://bugzilla.suse.com/show_bug.cgi?id=1216376 . An essential security update for Redis 7 addresses a critical privilege escalation flaw. Follow the provided upgrade guidelines meticulously.. Permission Bypass, Redis7 Security Patch, openSUSE Redis Update. . Severity: Important. LinuxSecurity.com Team
This update for rabbitmq-server fixes the following issues: CVE-2023-46118: Introduce HTTP request body limit for definition uploads (bsc#1216582).. # Security update for rabbitmq-server Announcement ID: SUSE-SU-2023:4939-1 Rating: moderate References: * bsc#1216582 Cross-References: * CVE-2023-46118 CVSS scores: * CVE-2023-46118 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2023-46118 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP4 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for rabbitmq-server fixes the following issues: * CVE-2023-46118: Introduce HTTP request body limit for definition uploads (bsc#1216582). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-4939=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4939=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4939=1 * Server Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2023-4939=1 * Server Applications Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP5-2023-4939=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * rabbitmq-server-3.8.11-150300.3.14.1 * erlang-rabbitmq-client-3.8.11-150300.3.14.1 * rabbitmq-server-plugins-3.8.11-150300.3.14.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-3.8.11-150300.3.14.1 * erlang-rabbitmq-client-3.8.11-150300.3.14.1 * rabbitmq-server-plugins-3.8.11-150300.3.14.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-3.8.11-150300.3.14.1 * erlang-rabbitmq-client-3.8.11-150300.3.14.1 * rabbitmq-server-plugins-3.8.11-150300.3.14.1 * Server Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-3.8.11-150300.3.14.1 * erlang-rabbitmq-client-3.8.11-150300.3.14.1 * rabbitmq-server-plugins-3.8.11-150300.3.14.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-3.8.11-150300.3.14.1 * erlang-rabbitmq-client-3.8.11-150300.3.14.1 * rabbitmq-server-plugins-3.8.11-150300.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46118.html * https://bugzilla.suse.com/show_bug.cgi?id=1216582 . Important notice regarding rabbitmq-server concerning CVE-2023-46118, providing guidance on the limits of HTTP request bodies during setup.. RabbitMQ Update, openSUSE Security Patch, HTTP Request Limit. . LinuxSecurity.com Team
* bsc#1216588 Cross-References: * CVE-2023-46137 . # Security update for python3-Twisted Announcement ID: SUSE-SU-2023:4607-1 Rating: moderate References: * bsc#1216588 Cross-References: * CVE-2023-46137 CVSS scores: * CVE-2023-46137 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-46137 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP4 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python3-Twisted fixes the following issues: * CVE-2023-46137: Fixed issue inside serializing pipelined HTTP requests. (bsc#1216588) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4607=1 openSUSE-SLE-15.4-2023-4607=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4607=1 * Server Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2023-4607=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2023-4607=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python3-Twisted-22.2.0-150400.15.1 *python-Twisted-doc-22.2.0-150400.15.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.15.1 * Server Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.15.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.15.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46137.html * https://bugzilla.suse.com/show_bug.cgi?id=1216588 . An important patch for python3-Twisted has been deployed to address serious HTTP processing flaws in SUSE 15.4 and 15.5.. SUSE update, python3-Twisted security, HTTP requests fix, openSUSE vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.