Explore top 10 tips to secure your open-source projects now. Read More
×RabbitMQ Server's management UI could be made to run code via cross-site scripting (XSS).. ========================================================================== Ubuntu Security Notice USN-7399-1 March 31, 2025 rabbitmq-server vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: RabbitMQ Server's management UI could be made to run code via cross-site scripting (XSS). Software Description: - rabbitmq-server: AMQP server written in Erlang Details: It was discovered that RabbitMQ Server's management UI did not sanitize certain input. An attacker could possibly use this issue to inject code by performing a cross-site scripting (XSS) attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 rabbitmq-server 3.12.1-1ubuntu2.1 Ubuntu 24.04 LTS rabbitmq-server 3.12.1-1ubuntu1.2 Ubuntu 22.04 LTS rabbitmq-server 3.9.27-0ubuntu0.2 Ubuntu 20.04 LTS rabbitmq-server 3.8.3-0ubuntu0.3 After a standard system update you need to restart RabbitMQ Server to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7399-1 CVE-2025-30219 Package Information: https://launchpad.net/ubuntu/+source/rabbitmq-server/3.12.1-1ubuntu2.1 https://launchpad.net/ubuntu/+source/rabbitmq-server/3.12.1-1ubuntu1.2 https://launchpad.net/ubuntu/+source/rabbitmq-server/3.9.27-0ubuntu0.2 https://launchpad.net/ubuntu/+source/rabbitmq-server/3.8.3-0ubuntu0.3 . RabbitMQ Server's management UI has a critical XSS flaw requiring updates for Ubuntu 20.04 to 24.10 to mitigate risks.. rabbitmq, server's, management, cross-site, scripting, (xss),==========. . Severity: Important. LinuxSecurity.com Team
* bsc#1212641 * bsc#1219912 * bsc#1231024 * bsc#1234554 * bsc#1236301 . # Security update for grafana Announcement ID: SUSE-SU-2025:0545-1 Release Date: 2025-02-14T07:24:23Z Rating: moderate References: * bsc#1212641 * bsc#1219912 * bsc#1231024 * bsc#1234554 * bsc#1236301 * jsc#MSQA-914 * jsc#PED-11591 * jsc#PED-11649 Cross-References: * CVE-2023-3128 * CVE-2023-6152 * CVE-2024-45337 * CVE-2024-6837 * CVE-2024-8118 CVSS scores: * CVE-2023-3128 ( SUSE ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6152 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-6837 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-6837 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-8118 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2024-8118 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves five vulnerabilities and contains three features can now be installed. ## Description: This update for grafana fixes the following issues: grafana was updated from version 9.5.18 to10.4.13 (jsc#PED-11591,jsc#PED-11649): * Security issues fixed: * CVE-2024-45337: Prevent possible misuse of ServerConfig.PublicKeyCallback by upgrading golang.org/x/crypto (bsc#1234554) * CVE-2023-3128: Fixed authentication bypass using Azure AD OAuth (bsc#1212641) * CVE-2023-6152: Add email verification when updating user email (bsc#1219912) * CVE-2024-6837: Fixed potential data source permission escalation (bsc#1236301) * CVE-2024-8118: Fixed permission on external alerting rule write endpoint (bsc#1231024) * Potential breaking changes in version 10: * In panels using the `extract fields` transformation, where one of the extracted names collides with one of the already existing ields, the extracted field will be renamed. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. To resolve this either: update transformation or field override. * For the existing backend mode users who have Transformations with the `time` field, might see their transformations are not working. Those panels that have broken transformations will fail to render. This is because we changed the field key. To resolve this either: Remove the affected panel and re- create it; Select the `Time` field again; Edit the `time` field as `Time` for transformation in `panel.json` or `dashboard.json` * The following data source permission endpoints have been removed: `GET /datasources/:datasourceId/permissions` `POST /api/datasources/:datasourceId/permissions` `DELETE /datasources/:datasourceId/permissions` `POST /datasources/:datasourceId/enable-permissions` `POST /datasources/:datasourceId/disable-permissions` * Please use the following endpoints instead: `GET /api/access-control/datasources/:uid` for listing data source permissions `POST/api/access-control/datasources/:uid/users/:id`, `POST /api/access-control/datasources/:uid/teams/:id` and `POST /api/access-control/datasources/:uid/buildInRoles/:id` for adding or removing data source permissions * If you are using Terraform Grafana provider to manage data source permissions, you will need to upgrade your provider. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. * The deprecated `/playlists/{uid}/dashboards` API endpoint has been removed. Dashboard information can be retrieved from the `/dashboard/...` APIs. * The `PUT /api/folders/:uid` endpoint no more supports modifying the folder's `UID` * Removed all components for the old panel header design. * Please review changes/breaking-changes-v10-3/ for more details * OAuth role mapping enforcement: This change impacts GitHub, Gitlab, Okta, and Generic OAuth. To avoid overriding manually set roles, enable the skip_org_role_sync option in the Grafana configuration for your OAuth provider before upgrading * Angular has been deprecated * Grafana legacy alerting has been deprecated * API keys are migrating to service accounts * The experimental “dashboard previews” feature is removed * Usernames are now case-insensitive by default * Grafana OAuth integrations do not work anymore with email lookups * The “Alias” field in the CloudWatch data source is removed * Athena data source plugin must be updated to version > =2.9.3 * Redshift data source plugin must be updated to version > =1.8.3 * DoiT International BigQuery plugin no longer supported * Please review changes/breaking-changes-v10-0 for more details * This update brings many new features, enhancements and fixes highlighted at: * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-4/ *https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-3/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-2/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-1/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-0/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-545=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-545=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * grafana-10.4.13-150200.3.59.1 * grafana-debuginfo-10.4.13-150200.3.59.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * grafana-10.4.13-150200.3.59.1 * grafana-debuginfo-10.4.13-150200.3.59.1 ## References: * https://www.suse.com/security/cve/CVE-2023-3128.html * https://www.suse.com/security/cve/CVE-2023-6152.html * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2024-6837.html * https://www.suse.com/security/cve/CVE-2024-8118.html * https://bugzilla.suse.com/show_bug.cgi?id=1212641 * https://bugzilla.suse.com/show_bug.cgi?id=1219912 * https://bugzilla.suse.com/show_bug.cgi?id=1231024 * https://bugzilla.suse.com/show_bug.cgi?id=1234554 * https://bugzilla.suse.com/show_bug.cgi?id=1236301 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11591&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role= . Cautious Grafana security announcement including assorted flaw resolutions and enhancements for SUSE clientele.. grafana SecurityUpdate, SUSE Advisory, Security Patching, Grafana Auth Fix. . LinuxSecurity.com Team
* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016 . # Security update for the Linux Kernel (Live Patch 61 for SLE 12 SP5) Announcement ID: SUSE-SU-2025:0440-1 Release Date: 2025-02-12T07:04:06Z Rating: important References: * bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016 * CVE-2024-47684 CVSS scores: * CVE-2024-45016 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45016 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47684 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-47684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47684 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 4.12.14-122_231 fixes several issues. The following security issues were fixed: * CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230998). * CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231993). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2025-440=1 SUSE-SLE-Live- Patching-12-SP5-2025-439=1 SUSE-SLE-Live-Patching-12-SP5-2025-442=1 SUSE-SLE- Live-Patching-12-SP5-2025-441=1 SUSE-SLE-Live-Patching-12-SP5-2025-443=1 SUSE- SLE-Live-Patching-12-SP5-2025-444=1 SUSE-SLE-Live-Patching-12-SP5-2025-445=1 SUSE-SLE-Live-Patching-12-SP5-2025-446=1 ## Package List: * SUSE Linux EnterpriseLive Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_201-default-12-2.1 * kgraft-patch-4_12_14-122_228-default-3-2.1 * kgraft-patch-4_12_14-122_225-default-4-2.1 * kgraft-patch-4_12_14-122_219-default-7-2.1 * kgraft-patch-4_12_14-122_216-default-10-2.1 * kgraft-patch-4_12_14-122_231-default-3-2.1 * kgraft-patch-4_12_14-122_189-default-15-2.1 * kgraft-patch-4_12_14-122_194-default-13-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-45016.html * https://www.suse.com/security/cve/CVE-2024-47684.html * https://bugzilla.suse.com/show_bug.cgi?id=1230998 * https://bugzilla.suse.com/show_bug.cgi?id=1231993 . SUSE unveils crucial update for Linux Kernel resolving two security vulnerabilities along with guidance for applying the fixes.. SUSE Linux Kernel Patch, Linux Security Update, Kernel Fix, TCP Security Issue. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 41 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0098-1 Release Date: 2025-01-14T15:33:35Z Rating: important References: * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956 * CVE-2024-50264 CVSS scores: * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_150 fixes several issues. The following security issues were fixed: * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-98=1 SUSE-2025-99=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-98=1 SUSE-SLE- Module-Live-Patching-15-SP3-2025-99=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) *kernel-livepatch-5_3_18-150300_59_150-default-14-150300.2.1 * kernel-livepatch-5_3_18-150300_59_150-default-debuginfo-14-150300.2.1 * kernel-livepatch-5_3_18-150300_59_147-default-15-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_41-debugsource-14-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_40-debugsource-15-150300.2.1 * kernel-livepatch-5_3_18-150300_59_147-default-debuginfo-15-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_147-preempt-debuginfo-15-150300.2.1 * kernel-livepatch-5_3_18-150300_59_150-preempt-debuginfo-14-150300.2.1 * kernel-livepatch-5_3_18-150300_59_147-preempt-15-150300.2.1 * kernel-livepatch-5_3_18-150300_59_150-preempt-14-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_150-default-14-150300.2.1 * kernel-livepatch-5_3_18-150300_59_147-default-15-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Essential live update for the Linux Kernel resolves significant vulnerabilities in Fedora and Red Hat Enterprise Linux.. Linux Kernel Update,SUSE Linux Advisory,Key Security Patches,openSUSE Security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has 10 fixes is now available. . openSUSE Security Update: Security update for cobbler ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0382-1 Rating: important References: #1203478 #1204900 #1205489 #1205749 #1206060 #1206160 #1206520 #1207595 #1209149 #1219933 #1231332 Cross-References: CVE-2024-47533 CVSS scores: CVE-2024-47533 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that solves one vulnerability and has 10 fixes is now available. Description: This update for cobbler fixes the following issues: Update to 3.3.7: * Security: Fix issue that allowed anyone to connect to the API as admin (CVE-2024-47533, boo#1231332) * bind - Fix bug that prevents cname entries from being generated successfully * Fix build on RHEL9 based distributions (fence-agents-all split) * Fix for Windows systems * Docs: Add missing dependencies for source installation * Fix issue that prevented systems from being synced when the profile was edited Update to 3.3.6: * Upstream all openSUSE specific patches that were maintained in Git * Fix rename of items that had uppercase letters * Skip inconsistent collections instead of crashing the daemon - Update to 3.3.5: * Added collection indicies for UUID's, MAC's, IP addresses and hostnames boo#1219933 * Re-added to_dict() caching * Added lazy loading for the daemon (off by default) - Update to 3.3.4: * Added cobbler-tests-containers subpackage * Updated the distro_signatures.json database * The default name for grub2-efi changed to grubx64.efi to match the DHCP template - Do generateboot menus even if no profiles or systems - only local boot - Avoid crashing running buildiso in certain conditions. - Fix settings migration schema to work while upgrading on existing running Uyuni and SUSE Manager servers running with old Cobbler settings (boo#1203478) - Consider case of "next_server" being a hostname during migration of Cobbler collections. - Fix problem with "proxy_url_ext" setting being None type. - Update v2 to v3 migration script to allow migration of collections that contains settings from Cobbler 2. (boo#1203478) - Fix problem for the migration of "autoinstall" collection attribute. - Fix failing Cobbler tests after upgrading to 3.3.3. - Fix regression: allow empty string as interface_type value (boo#1203478) - Avoid possible override of existing values during migration of collections to 3.0.0 (boo#1206160) - Add missing code for previous patch file around boot_loaders migration. - Improve Cobbler performance with item cache and threadpool (boo#1205489) - Skip collections that are inconsistent instead of crashing (boo#1205749) - Items: Fix creation of "default" NetworkInterface (boo#1206520) - S390X systems require their kernel options to have a linebreak at 79 characters (boo#1207595) - settings-migration-v1-to-v2.sh will now handle paths with whitespace correct - Fix renaming Cobbler items (boo#1204900, boo#1209149) - Fix cobbler buildiso so that the artifact can be booted by EFI firmware. (boo#1206060) - Add input_string_*, input_boolean, input_int functiont to public API Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-382=1 Package List: - openSUSE Backports SLE-15-SP5 (noarch): cobbler-3.3.7-bp155.2.3.2 cobbler-tests-3.3.7-bp155.2.3.2 cobbler-tests-containers-3.3.7-bp155.2.3.2 References: https://www.suse.com/security/cve/CVE-2024-47533.html https://bugzilla.suse.com/1203478 https://bugzilla.suse.com/1204900 https://bugzilla.suse.com/1205489 https://bugzilla.suse.com/1205749 https://bugzilla.suse.com/1206060 https://bugzilla.suse.com/1206160 https://bugzilla.suse.com/1206520 https://bugzilla.suse.com/1207595 https://bugzilla.suse.com/1209149 https://bugzilla.suse.com/1219933 https://bugzilla.suse.com/1231332 . A noteworthy release for Fedora addresses a critical bug while introducing several improvements for the Ansible automation framework.. openSUSE security update,cobbler API fix,openSUSE Backports,important update. . Severity: Important. LinuxSecurity.com Team
* bsc#1228097 Cross-References: * CVE-2024-40725 . # Security update for apache2 Announcement ID: SUSE-SU-2024:3742-1 Release Date: 2024-10-21T13:58:41Z Rating: important References: * bsc#1228097 Cross-References: * CVE-2024-40725 CVSS scores: * CVE-2024-40725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-40725 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2024-40725: Fixed source code disclosure of local content (bsc#1228097) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-3742=1 openSUSE-SLE-15.6-2024-3742=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-3742=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-3742=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-3742=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * apache2-worker-2.4.58-150600.5.26.1 * apache2-devel-2.4.58-150600.5.26.1 * apache2-debuginfo-2.4.58-150600.5.26.1 * apache2-2.4.58-150600.5.26.1 * apache2-prefork-2.4.58-150600.5.26.1 * apache2-prefork-debugsource-2.4.58-150600.5.26.1 * apache2-utils-2.4.58-150600.5.26.1 * apache2-utils-debuginfo-2.4.58-150600.5.26.1 * apache2-utils-debugsource-2.4.58-150600.5.26.1 * apache2-worker-debuginfo-2.4.58-150600.5.26.1 * apache2-event-debugsource-2.4.58-150600.5.26.1 * apache2-debugsource-2.4.58-150600.5.26.1 * apache2-event-2.4.58-150600.5.26.1 * apache2-worker-debugsource-2.4.58-150600.5.26.1 * apache2-prefork-debuginfo-2.4.58-150600.5.26.1 * apache2-event-debuginfo-2.4.58-150600.5.26.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.58-150600.5.26.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-debuginfo-2.4.58-150600.5.26.1 * apache2-2.4.58-150600.5.26.1 * apache2-prefork-2.4.58-150600.5.26.1 * apache2-prefork-debugsource-2.4.58-150600.5.26.1 * apache2-debugsource-2.4.58-150600.5.26.1 * apache2-prefork-debuginfo-2.4.58-150600.5.26.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-debuginfo-2.4.58-150600.5.26.1 * apache2-event-debugsource-2.4.58-150600.5.26.1 * apache2-debugsource-2.4.58-150600.5.26.1 * apache2-event-2.4.58-150600.5.26.1 * apache2-event-debuginfo-2.4.58-150600.5.26.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-worker-2.4.58-150600.5.26.1 * apache2-devel-2.4.58-150600.5.26.1 * apache2-utils-2.4.58-150600.5.26.1 * apache2-utils-debugsource-2.4.58-150600.5.26.1 * apache2-utils-debuginfo-2.4.58-150600.5.26.1 * apache2-worker-debuginfo-2.4.58-150600.5.26.1 * apache2-worker-debugsource-2.4.58-150600.5.26.1 ## References: * https://www.suse.com/security/cve/CVE-2024-40725.html * https://bugzilla.suse.com/show_bug.cgi?id=1228097 . Essential patches for apache2 resolve significant vulnerabilities in SUSE offerings launched on 2024-10-21.. SUSE Security Advisory, apache2 Patch, local content disclosure, software update. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12547 http://linux.oracle.com/errata/ELSA-2024-12547.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.333.5.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.333.5.1.el7uek.x86_64.rpm aarch64: kernel-uek-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-debug-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-debug-devel-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-devel-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-doc-5.4.17-2136.333.5.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-tools-libs-5.4.17-2136.333.5.1.el7uek.aarch64.rpm perf-5.4.17-2136.333.5.1.el7uek.aarch64.rpm python-perf-5.4.17-2136.333.5.1.el7uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//kernel-uek-5.4.17-2136.333.5.1.el7uek.src.rpm Related CVEs: CVE-2024-41090 CVE-2024-41091 Description of changes: [5.4.17-2136.333.5.1.el7uek] - net/mlx5e: drop shorter ethernet frames (Manjunath Patil) [Orabug: 36660755] - pci: add hotplug patch support for SOLIDIGM Aura10 AIC 0x025e:0x0b60 (Alan Adamson) [Orabug: 36836653] _______________________________________________ El-errata mailing list
* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882 . # Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP4) Announcement ID: SUSE-SU-2024:2447-1 Rating: important References: * bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882 * bsc#1223059 * bsc#1223363 * bsc#1223514 * bsc#1223681 * bsc#1223683 Cross-References: * CVE-2022-48651 * CVE-2023-52502 * CVE-2023-6546 * CVE-2024-23307 * CVE-2024-26610 * CVE-2024-26766 * CVE-2024-26828 * CVE-2024-26852 * CVE-2024-26923 * CVE-2024-26930 CVSS scores: * CVE-2022-48651 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52502 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6546 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6546 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26610 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-26766 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26828 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2024-26852 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26923 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26930 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26930 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 10vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_111 fixes several issues. The following security issues were fixed: * CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223683). * CVE-2024-26930: Fixed double free of the ha-> vp_map pointer (bsc#1223681). * CVE-2024-26828: Fixed underflow in parse_server_interfaces() (bsc#1223363). * CVE-2024-23307: Fixed Integer Overflow or Wraparound vulnerability in x86 and ARM md, raid, raid5 modules (bsc#1220145). * CVE-2024-26852: Fixed use-after-free in ip6_route_mpath_notify() (bsc#1223059). * CVE-2024-26610: Fixed memory corruption in wifi/iwlwifi (bsc#1221302). * CVE-2022-48651: Fixed an out-of-bound bug in ipvlan caused by unset skb-> mac_header (bsc#1223514). * CVE-2024-26766: Fixed SDMA off-by-one error in _pad_sdma_tx_descs() (bsc#1222882). * CVE-2023-52502: Fixed a race condition in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn() (bsc#1220832). * CVE-2023-6546: Fixed a race condition in the GSM 0710 tty multiplexor via the GSMIOC_SETCONF ioctl that could lead to local privilege escalation (bsc#1222685). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2447=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2024-2447=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_111-default-4-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_111-default-debuginfo-4-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_24-debugsource-4-150400.9.6.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_111-default-4-150400.9.6.1 *kernel-livepatch-5_14_21-150400_24_111-default-debuginfo-4-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_24-debugsource-4-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48651.html * https://www.suse.com/security/cve/CVE-2023-52502.html * https://www.suse.com/security/cve/CVE-2023-6546.html * https://www.suse.com/security/cve/CVE-2024-23307.html * https://www.suse.com/security/cve/CVE-2024-26610.html * https://www.suse.com/security/cve/CVE-2024-26766.html * https://www.suse.com/security/cve/CVE-2024-26828.html * https://www.suse.com/security/cve/CVE-2024-26852.html * https://www.suse.com/security/cve/CVE-2024-26923.html * https://www.suse.com/security/cve/CVE-2024-26930.html * https://bugzilla.suse.com/show_bug.cgi?id=1220145 * https://bugzilla.suse.com/show_bug.cgi?id=1220832 * https://bugzilla.suse.com/show_bug.cgi?id=1221302 * https://bugzilla.suse.com/show_bug.cgi?id=1222685 * https://bugzilla.suse.com/show_bug.cgi?id=1222882 * https://bugzilla.suse.com/show_bug.cgi?id=1223059 * https://bugzilla.suse.com/show_bug.cgi?id=1223363 * https://bugzilla.suse.com/show_bug.cgi?id=1223514 * https://bugzilla.suse.com/show_bug.cgi?id=1223681 * https://bugzilla.suse.com/show_bug.cgi?id=1223683 . SUSE Linux Kernel implements essential enhancements, tackling numerous challenges and significant security flaws and risks.. SUSE Linux Kernel, Live Patch Updates, Server Security Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.