An update that solves two vulnerabilities can now be installed.. # Security update for libvirt Announcement ID: SUSE-SU-2026:0279-1 Release Date: 2026-01-23T15:09:06Z Rating: moderate References: * bsc#1253278 * bsc#1253703 Cross-References: * CVE-2025-12748 * CVE-2025-13193 CVSS scores: * CVE-2025-12748 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-12748 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-12748 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-13193 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-13193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-13193 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2025-13193: Fixed umask for 'qemu-img' when creating external inactive snapshots (bsc#1253703) * CVE-2025-12748: Fixed check ACLs before parsing the whole domain XML (bsc#1253278) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-279=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-279=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libvirt-libs-debuginfo-11.0.0-150700.4.13.1 *libvirt-debugsource-11.0.0-150700.4.13.1 * libvirt-libs-11.0.0-150700.4.13.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-log-11.0.0-150700.4.13.1 * libvirt-daemon-driver-nwfilter-11.0.0-150700.4.13.1 * libvirt-daemon-common-11.0.0-150700.4.13.1 * libvirt-daemon-driver-interface-11.0.0-150700.4.13.1 * libvirt-daemon-driver-nodedev-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-core-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-qemu-11.0.0-150700.4.13.1 * libvirt-client-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-logical-11.0.0-150700.4.13.1 * libvirt-daemon-config-nwfilter-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-scsi-debuginfo-11.0.0-150700.4.13.1 * libvirt-debugsource-11.0.0-150700.4.13.1 * libvirt-daemon-plugin-lockd-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-lock-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-mpath-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-log-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-scsi-11.0.0-150700.4.13.1 * libvirt-daemon-plugin-sanlock-debuginfo-11.0.0-150700.4.13.1 * libvirt-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-11.0.0-150700.4.13.1 * libvirt-daemon-driver-secret-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-qemu-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-logical-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-plugin-sanlock-11.0.0-150700.4.13.1 * libvirt-nss-11.0.0-150700.4.13.1 * libvirt-nss-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-qemu-11.0.0-150700.4.13.1 * libvirt-daemon-driver-secret-11.0.0-150700.4.13.1 * libvirt-daemon-plugin-lockd-11.0.0-150700.4.13.1 * libvirt-daemon-driver-network-11.0.0-150700.4.13.1 * libvirt-daemon-lock-11.0.0-150700.4.13.1 * libvirt-daemon-proxy-11.0.0-150700.4.13.1 *libvirt-client-qemu-11.0.0-150700.4.13.1 * libvirt-daemon-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-disk-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-interface-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-mpath-11.0.0-150700.4.13.1 * libvirt-daemon-config-network-11.0.0-150700.4.13.1 * libvirt-daemon-hooks-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-proxy-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-iscsi-11.0.0-150700.4.13.1 * libvirt-client-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-network-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-core-11.0.0-150700.4.13.1 * libvirt-daemon-common-debuginfo-11.0.0-150700.4.13.1 * libvirt-devel-11.0.0-150700.4.13.1 * libvirt-daemon-driver-nwfilter-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-disk-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-iscsi-direct-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-driver-nodedev-11.0.0-150700.4.13.1 * Server Applications Module 15-SP7 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-11.0.0-150700.4.13.1 * libvirt-daemon-driver-storage-rbd-debuginfo-11.0.0-150700.4.13.1 * Server Applications Module 15-SP7 (noarch) * libvirt-doc-11.0.0-150700.4.13.1 * Server Applications Module 15-SP7 (x86_64) * libvirt-daemon-driver-libxl-11.0.0-150700.4.13.1 * libvirt-daemon-driver-libxl-debuginfo-11.0.0-150700.4.13.1 * libvirt-daemon-xen-11.0.0-150700.4.13.1 ## References: * https://www.suse.com/security/cve/CVE-2025-12748.html * https://www.suse.com/security/cve/CVE-2025-13193.html * https://bugzilla.suse.com/show_bug.cgi?id=1253278 * https://bugzilla.suse.com/show_bug.cgi?id=1253703 . An update for libvirt addresses two moderate security issues on SUSE systems; installation recommended..Libvirt Update, SUSE Security Patch, Moderate Security Advisory, Linux Access Control. . LinuxSecurity.com Team
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e4ed1863bf 2025-09-12 02:30:53.358180+00:00 -------------------------------------------------------------------------------- Name : snapshot Product : Fedora 41 Version : 47.1 Release : 2.fc41 URL : Summary : Take pictures and videos Description : Take pictures and videos on your computer, tablet, or phone. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 3 2025 Fabio Valentini - 47.1-2 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2392051 - CVE-2025-58160 snapshot: Tracing log pollution [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2392051 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e4ed1863bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : snapshot Product : Fedora 39 Version : 45.2 Release : 2.fc39 URL : Summary : Take pictures and videos Description : Take pictures and videos on your computer, tablet, or phone. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Fri May 24 2024 Fabio Valentini - 45.2-2 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update for grafana is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: grafana security update Advisory ID: RHSA-2021:3770-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:3770 Issue date: 2021-10-12 CVE Names: CVE-2021-39226 ==================================================================== 1. Summary: An update for grafana is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.2) - aarch64, ppc64le, s390x, x86_64 3. Description: Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * grafana: Snapshot authentication bypass (CVE-2021-39226) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2011063 - CVE-2021-39226 grafana: Snapshot authentication bypass 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.2): Source: grafana-6.3.6-3.el8_2.src.rpm aarch64: grafana-6.3.6-3.el8_2.aarch64.rpm grafana-azure-monitor-6.3.6-3.el8_2.aarch64.rpm grafana-cloudwatch-6.3.6-3.el8_2.aarch64.rpm grafana-debuginfo-6.3.6-3.el8_2.aarch64.rpm grafana-elasticsearch-6.3.6-3.el8_2.aarch64.rpm grafana-graphite-6.3.6-3.el8_2.aarch64.rpm grafana-influxdb-6.3.6-3.el8_2.aarch64.rpm grafana-loki-6.3.6-3.el8_2.aarch64.rpm grafana-mssql-6.3.6-3.el8_2.aarch64.rpm grafana-mysql-6.3.6-3.el8_2.aarch64.rpm grafana-opentsdb-6.3.6-3.el8_2.aarch64.rpm grafana-postgres-6.3.6-3.el8_2.aarch64.rpm grafana-prometheus-6.3.6-3.el8_2.aarch64.rpm grafana-stackdriver-6.3.6-3.el8_2.aarch64.rpm ppc64le: grafana-6.3.6-3.el8_2.ppc64le.rpm grafana-azure-monitor-6.3.6-3.el8_2.ppc64le.rpm grafana-cloudwatch-6.3.6-3.el8_2.ppc64le.rpm grafana-debuginfo-6.3.6-3.el8_2.ppc64le.rpm grafana-elasticsearch-6.3.6-3.el8_2.ppc64le.rpm grafana-graphite-6.3.6-3.el8_2.ppc64le.rpm grafana-influxdb-6.3.6-3.el8_2.ppc64le.rpm grafana-loki-6.3.6-3.el8_2.ppc64le.rpm grafana-mssql-6.3.6-3.el8_2.ppc64le.rpm grafana-mysql-6.3.6-3.el8_2.ppc64le.rpm grafana-opentsdb-6.3.6-3.el8_2.ppc64le.rpm grafana-postgres-6.3.6-3.el8_2.ppc64le.rpm grafana-prometheus-6.3.6-3.el8_2.ppc64le.rpm grafana-stackdriver-6.3.6-3.el8_2.ppc64le.rpm s390x: grafana-6.3.6-3.el8_2.s390x.rpm grafana-azure-monitor-6.3.6-3.el8_2.s390x.rpm grafana-cloudwatch-6.3.6-3.el8_2.s390x.rpm grafana-debuginfo-6.3.6-3.el8_2.s390x.rpm grafana-elasticsearch-6.3.6-3.el8_2.s390x.rpm grafana-graphite-6.3.6-3.el8_2.s390x.rpm grafana-influxdb-6.3.6-3.el8_2.s390x.rpm grafana-loki-6.3.6-3.el8_2.s390x.rpm grafana-mssql-6.3.6-3.el8_2.s390x.rpm grafana-mysql-6.3.6-3.el8_2.s390x.rpm grafana-opentsdb-6.3.6-3.el8_2.s390x.rpm grafana-postgres-6.3.6-3.el8_2.s390x.rpm grafana-prometheus-6.3.6-3.el8_2.s390x.rpm grafana-stackdriver-6.3.6-3.el8_2.s390x.rpm x86_64: grafana-6.3.6-3.el8_2.x86_64.rpm grafana-azure-monitor-6.3.6-3.el8_2.x86_64.rpm grafana-cloudwatch-6.3.6-3.el8_2.x86_64.rpm grafana-debuginfo-6.3.6-3.el8_2.x86_64.rpm grafana-elasticsearch-6.3.6-3.el8_2.x86_64.rpm grafana-graphite-6.3.6-3.el8_2.x86_64.rpm grafana-influxdb-6.3.6-3.el8_2.x86_64.rpm grafana-loki-6.3.6-3.el8_2.x86_64.rpm grafana-mssql-6.3.6-3.el8_2.x86_64.rpm grafana-mysql-6.3.6-3.el8_2.x86_64.rpm grafana-opentsdb-6.3.6-3.el8_2.x86_64.rpm grafana-postgres-6.3.6-3.el8_2.x86_64.rpm grafana-prometheus-6.3.6-3.el8_2.x86_64.rpm grafana-stackdriver-6.3.6-3.el8_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-39226 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYWVn4tzjgjWX9erEAQhfFg/+K6whZOQwhfGwLf0Nk42dHhVfcdkKRSZa z3KHM4mFL4zSdIeJMOm8ThyzTh528eJqDC5v+/ucVA04EFP6joEAPHdsgkAdXBPD PZX1MJfWlxETy7ySvvC9QCF+AGH/GxaAutUvaeyNB10eMPVdjbwUFYSvsh8a0GFx jV6ffp4oBASubPW3S4GHPJczE8fyoI0vMDLbo/gLFrxQRaeigfYQMWAlh45r6rir GwvnyyEbE4xh1v76kXuaXomWHSskBMhb1z8kveh64scUonK/+0F0m0Gfx2NlTL8f WHiY0MopEv19CZ8xXZjcJhsyqSdvV3eAqNRpv2a5mndLcKiLkqxQvX+zrLbvG1mo l864RiKQezOGzcAcc8rbNeT0EsS0P/c1+MkE9HH/OarSY5BROs1jnZCb9Q9czLes IsCbBosrbKyt5HK+SJfy4OsxqRa5ArlS1O1u01Jec87Ys2pOjJGFb3bmg71o+WxQ ozzqqSbqUrxd6iI5o4sQHJwuwNAvOMBJgS9amQyp44NLrExILPiX7U8sd+S+vZNO OJ0RSVPUuu4q7PqUuPbfPyWXeuErxc6K5AMWE6oFnDt+TcITfl3s+oy9LVDV3qvd d5b47d+ZqIaLK4P0khqO85Wx25mjnhcDSB40QqWOv9HnJnK0bNYWdnF5mqow+JPo EzD6WeQTiiE=AdtJ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.