* bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 . # Security update for sevctl Announcement ID: SUSE-SU-2025:20783-1 Release Date: 2025-09-17T11:34:38Z Rating: moderate References: * bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 * CVE-2025-3416 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2025-3416: openssl: Fixed Use-After-Free in Md::fetch and Cipher::fetch (bsc#1242618) * CVE-2024-12224: idna: Fixed Punycode improper validation (bsc#1243860) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-267=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * sevctl-debuginfo-0.4.3-slfo.1.1_3.1 * sevctl-debugsource-0.4.3-slfo.1.1_3.1 * sevctl-0.4.3-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://bugzilla.suse.com/show_bug.cgi?id=1242618 * https://bugzilla.suse.com/show_bug.cgi?id=1243860 . Security update forsevctl resolves two issues: improper validation and Use-After-Free vulnerability for SUSE.. SUSE security update sevctl vulnerabilities. . LinuxSecurity.com Team
* bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 . # Security update for sevctl Announcement ID: SUSE-SU-2025:03306-1 Release Date: 2025-09-23T13:13:44Z Rating: moderate References: * bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 * CVE-2025-3416 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2024-12224: idna: Fixed improper validation of unsafe equivalence in punycode. (bsc#1243860) * CVE-2025-3416: openssl: Fixed use-after-free in Md::fetch and Cipher::fetch (bsc#1242618) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2025-3306=1 ## Package List: * Server Applications Module 15-SP7 (x86_64) * sevctl-debuginfo-0.6.0-150700.3.3.1 * sevctl-0.6.0-150700.3.3.1 * sevctl-debugsource-0.6.0-150700.3.3.1 ## References: *https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://bugzilla.suse.com/show_bug.cgi?id=1242618 * https://bugzilla.suse.com/show_bug.cgi?id=1243860 . SUSE has released updates for sevctl that resolve notable security concerns, specifically those involving inadequate validation and use-after-free flaws.. SUSE sevctl security issues, patch notification, moderate severity updates. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for sevctl Announcement ID: SUSE-SU-2025:03307-1 Release Date: 2025-09-23T13:13:50Z Rating: moderate References: * bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 * CVE-2025-3416 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2024-12224: idna: Fixed improper validation of unsafe equivalence in punycode. (bsc#1243860) * CVE-2025-3416: openssl: Fixed use-after-free in Md::fetch and Cipher::fetch (bsc#1242618) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3307=1 openSUSE-SLE-15.6-2025-3307=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-3307=1 ## Package List: * openSUSE Leap 15.6 (x86_64) *sevctl-debuginfo-0.4.3-150600.4.3.1 * sevctl-0.4.3-150600.4.3.1 * Server Applications Module 15-SP6 (x86_64) * sevctl-debuginfo-0.4.3-150600.4.3.1 * sevctl-0.4.3-150600.4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://bugzilla.suse.com/show_bug.cgi?id=1242618 * https://bugzilla.suse.com/show_bug.cgi?id=1243860 . This advisory covers two security flaws identified in sevctl impacting Fedora with moderate impact scores. Prompt action for installation is recommended.. openSUSE updates, sevctl vulnerabilities, moderate severity fixes, Linux security advisory. . LinuxSecurity.com Team
* bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 . # Security update for sevctl Announcement ID: SUSE-SU-2025:20716-1 Release Date: 2025-09-12T08:47:46Z Rating: moderate References: * bsc#1242618 * bsc#1243860 Cross-References: * CVE-2024-12224 * CVE-2025-3416 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2025-3416: openssl: Fixed Use-After-Free in Md::fetch and Cipher::fetch (bsc#1242618) * CVE-2024-12224: idna: Fixed Punycode labels not producing any non-ASCII when decode (bsc#1243860) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-459=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * sevctl-debuginfo-0.4.3-3.1 * sevctl-0.4.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://bugzilla.suse.com/show_bug.cgi?id=1242618 * https://bugzilla.suse.com/show_bug.cgi?id=1243860 . Obtain essential information regarding the SUSEupdate for sevctl addressing moderate security vulnerabilities, as reported in advisory ID: SUSE-SU-2025:20716-1.. SUSE Linux, sevctl, security update. . LinuxSecurity.com Team
* bsc#1218499 * bsc#1218502 * bsc#1229953 Cross-References: . # Security update for sevctl Announcement ID: SUSE-SU-2025:20071-1 Release Date: 2025-02-03T09:03:35Z Rating: moderate References: * bsc#1218499 * bsc#1218502 * bsc#1229953 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for sevctl fixes the following issues: Security issue fixed: * CVE-2023-50711: Fixed out of bounds memory accesses in a vendored dependency (bsc#1218502) Non-security issue fixed: * Update vendored dependencies and re-enable cargo update obs service (bsc#1229953) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-136=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * sevctl-0.4.3-2.1 * sevctl-debugsource-0.4.3-2.1 * sevctl-debuginfo-0.4.3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218499 * https://bugzilla.suse.com/show_bug.cgi?id=1218502 * https://bugzilla.suse.com/show_bug.cgi?id=1229953 . SUSE's security advisory on sevctl highlights moderate vulnerabilities and urges users to apply updates. Check your sevctl version and update accordingly.. SUSE Linux Micro, sevctl update, security advisory, memory access fix. . LinuxSecurity.com Team
* bsc#1218499 * bsc#1218502 * bsc#1229953 Cross-References: . # Security update for sevctl Announcement ID: SUSE-SU-2025:20071-1 Release Date: 2025-02-03T09:03:35Z Rating: moderate References: * bsc#1218499 * bsc#1218502 * bsc#1229953 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for sevctl fixes the following issues: Security issue fixed: * CVE-2023-50711: Fixed out of bounds memory accesses in a vendored dependency (bsc#1218502) Non-security issue fixed: * Update vendored dependencies and re-enable cargo update obs service (bsc#1229953) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-136=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * sevctl-debuginfo-0.4.3-2.1 * sevctl-debugsource-0.4.3-2.1 * sevctl-0.4.3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218499 * https://bugzilla.suse.com/show_bug.cgi?id=1218502 * https://bugzilla.suse.com/show_bug.cgi?id=1229953 . The recent patch for SUSE Linux Micro 6.0 rectifies issues related to out of bounds access within sevctl. Users are encouraged to follow the recommended methods for installation.. SUSE Linux Micro, sevctl, memory access fix, software patch. . LinuxSecurity.com Team
This update for sevctl fixes the following issues: CVE-2023-50711: Fixed out of bounds memory accesses in vmm-sys-util (bsc#1218502, bsc#1218499). # Security update for sevctl Announcement ID: SUSE-SU-2024:0250-1 Rating: important References: * bsc#1218499 * bsc#1218502 * jsc#PED-4981 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability, contains one feature and has one security fix can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2023-50711: Fixed out of bounds memory accesses in vmm-sys-util (bsc#1218502, bsc#1218499) Non-security fixes: * Updated to version 0.4.3 (jsc#PED-4981) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-250=1 openSUSE-SLE-15.5-2024-250=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-250=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 * Server Applications Module 15-SP5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218499 * https://bugzilla.suse.com/show_bug.cgi?id=1218502 * . Importantannouncement regarding sevctl on openSUSE related to a vulnerability in memory management. Update promptly!. openSUSE Update, Memory Access Issue, sevctl Security Patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1218499 * bsc#1218502 * jsc#PED-4981 Cross-References: . # Security update for sevctl Announcement ID: SUSE-SU-2024:0250-1 Rating: important References: * bsc#1218499 * bsc#1218502 * jsc#PED-4981 Cross-References: * CVE-2023-50711 CVSS scores: * CVE-2023-50711 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L * CVE-2023-50711 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability, contains one feature and has one security fix can now be installed. ## Description: This update for sevctl fixes the following issues: * CVE-2023-50711: Fixed out of bounds memory accesses in vmm-sys-util (bsc#1218502, bsc#1218499) Non-security fixes: * Updated to version 0.4.3 (jsc#PED-4981) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-250=1 openSUSE-SLE-15.5-2024-250=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-250=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 * Server Applications Module 15-SP5 (x86_64) * sevctl-debuginfo-0.4.3-150500.3.3.1 * sevctl-debugsource-0.4.3-150500.3.3.1 * sevctl-0.4.3-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-50711.html * https://bugzilla.suse.com/show_bug.cgi?id=1218499 * https://bugzilla.suse.com/show_bug.cgi?id=1218502 * . Important update rollout for sevctl addressing CVE-2023-50712 affecting multiple SUSE LinuxEnterprise products.. SUSE Security Update, Sevctl Patch, Memory Access Fix, SUSE Linux Products. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.