Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in MySQL.. ========================================================================== Ubuntu Security Notice USN-7479-1 May 05, 2025 mysql-8.0, mysql-8.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-8.4: MySQL database - mysql-8.0: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.42 in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. Ubuntu 25.04 has been updated to MySQL 8.4.5. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-42.html https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-5.html https://www.oracle.com/security-alerts/cpuapr2025.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 mysql-server 8.4.5-0ubuntu0.1 Ubuntu 24.10 mysql-server-8.0 8.0.42-0ubuntu0.24.10.1 Ubuntu 24.04 LTS mysql-server-8.0 8.0.42-0ubuntu0.24.04.1 Ubuntu 22.04 LTS mysql-server-8.0 8.0.42-0ubuntu0.22.04.1 Ubuntu 20.04 LTS mysql-server-8.0 8.0.42-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7479-1 CVE-2025-21574, CVE-2025-21575, CVE-2025-21577,CVE-2025-21579, CVE-2025-21580, CVE-2025-21581, CVE-2025-21584, CVE-2025-21585, CVE-2025-21588, CVE-2025-30681, CVE-2025-30682, CVE-2025-30683, CVE-2025-30684, CVE-2025-30685, CVE-2025-30687, CVE-2025-30688, CVE-2025-30689, CVE-2025-30693, CVE-2025-30695, CVE-2025-30696, CVE-2025-30699, CVE-2025-30703, CVE-2025-30704, CVE-2025-30705, CVE-2025-30715, CVE-2025-30721, CVE-2025-30722 Package Information: https://launchpad.net/ubuntu/+source/mysql-8.4/8.4.5-0ubuntu0.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.42-0ubuntu0.24.10.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.42-0ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.42-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.42-0ubuntu0.20.04.1 . Explore a range of security enhancements for MySQL across different versions of Ubuntu, featuring added functionalities and resolved issues.. MySQL Security, Ubuntu Updates, MySQL Exploits, Database Security. . Severity: Critical. LinuxSecurity.com Team
* jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 . # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2025:1431-1 Release Date: 2025-05-02T08:11:11Z Rating: important References: * jsc#PED-11136 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: * Update to version 0.0.20250424T181457 (jsc#PED-11136) * GO-2025-3603 * GO-2025-3604 * GO-2025-3607 * GO-2025-3608 * GO-2025-3609 * GO-2025-3610 * GO-2025-3611 * GO-2025-3612 * GO-2025-3615 * GO-2025-3618 * GO-2025-3619 * GO-2025-3620 * GO-2025-3621 * GO-2025-3622 * GO-2025-3623 * GO-2025-3625 * GO-2025-3627 * GO-2025-3630 * GO-2025-3631 * GO-2025-3632 * GO-2025-3633 * GO-2025-3634 * GO-2025-3635 * GO-2025-3636 * GO-2025-3637 * GO-2025-3638 * GO-2025-3639 * GO-2025-3640 * GO-2025-3642 * GO-2025-3643 * GO-2025-3644 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1431=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1431=1 ## Package List: * openSUSE Leap 15.6 (noarch) * govulncheck-vulndb-0.0.20250424T181457-150000.1.68.1 * SUSE Package Hub 15 15-SP6 (noarch) * govulncheck-vulndb-0.0.20250424T181457-150000.1.68.1 ## References: * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11136&page_caps=&user_role= . Critical security patchreleased for govulncheck-vulndb affecting openSUSE Leap 15.6 and SUSE Linux Enterprise Desktop systems.. SUSE Linux, openSUSE, security updates, software management, govulncheck. . Severity: Important. LinuxSecurity.com Team
Potential code execution with tar.vim and special crafted tar files. References: - https://bugs.mageia.org/show_bug.cgi?id=34057 - https://www.openwall.com/lists/oss-security/2025/03/02/1 . MGASA-2025-0089 - Updated vim packages fix security vulnerability Publication date: 06 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0089.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-27423 Potential code execution with tar.vim and special crafted tar files. References: - https://bugs.mageia.org/show_bug.cgi?id=34057 - https://www.openwall.com/lists/oss-security/2025/03/02/1 - https://www.cve.org/CVERecord?id=CVE-2025-27423 SRPMS: - 9/core/vim-9.1.1166-1.mga9 . Mageia 2025-0090 addresses a security flaw in vim regarding crafted zip files. Please update immediately to enhance your system's security.. Mageia vim code execution tar files security fix. . Severity: Critical. LinuxSecurity.com Team
* bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2025:0638-1 Release Date: 2025-02-21T15:38:48Z Rating: important References: * bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543 * CVE-2024-54658 * CVE-2025-24143 * CVE-2025-24150 * CVE-2025-24158 * CVE-2025-24162 CVSS scores: * CVE-2024-27856 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-27856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-27856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-54543 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-54543 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2024-54543 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-54543 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-54658 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-54658 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-54658 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-24143 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-24143 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-24143 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-24143 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-24150 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-24150 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-24150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-24158 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N *CVE-2025-24158 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-24158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-24162 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-24162 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-24162 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: Update to version 2.46.6 (bsc#1236946): * CVE-2025-24143: A maliciously crafted webpage may be able to fingerprint the user. * CVE-2025-24150: Copying a URL from Web Inspector may lead to command injection. * CVE-2025-24158: Processing web content may lead to a denial-of-service. * CVE-2025-24162: Processing maliciously crafted web content may lead to an unexpected process crash. Already fixed in previous releases: * CVE-2024-54543: Processing maliciously crafted web content may lead to memory corruption. * CVE-2024-27856: Processing a file may lead to unexpected app termination or arbitrary code execution. * CVE-2024-54658:Processing web content may lead to a denial-of-service. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-638=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-638=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-638=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-638=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-638=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-638=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-638=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-638=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-638=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-638=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-638=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-638=1 ## Package List: * openSUSE Leap 15.4 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 *typelib-1_0-WebKitWebProcessExtension-6_0-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-6_0-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * webkit-jsc-4.1-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-minibrowser-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * webkit-jsc-4-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * webkit-jsc-6.0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * webkit-jsc-4.1-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit-jsc-4-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-minibrowser-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk4-minibrowser-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk4-minibrowser-debuginfo-2.46.6-150400.4.106.1 *webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit-jsc-6.0-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * typelib-1_0-WebKit-6_0-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-minibrowser-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk4-devel-2.46.6-150400.4.106.1 * openSUSE Leap 15.4 (x86_64) * libwebkit2gtk-4_1-0-32bit-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-32bit-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-32bit-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-32bit-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.46.6-150400.4.106.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-64bit-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-64bit-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-64bit-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-64bit-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 *webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 *libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 *libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 *typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 *webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 *libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 *typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * WebKitGTK-4.1-lang-2.46.6-150400.4.106.1 * WebKitGTK-6.0-lang-2.46.6-150400.4.106.1 * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-debuginfo-2.46.6-150400.4.106.1 * webkitgtk-6_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-6_0-1-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_1-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_1-2.46.6-150400.4.106.1 * webkit2gtk3-devel-2.46.6-150400.4.106.1 * libwebkit2gtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk4-debugsource-2.46.6-150400.4.106.1 *webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * libwebkitgtk-6_0-4-2.46.6-150400.4.106.1 * webkit2gtk-4_1-injected-bundles-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * SUSE Manager Proxy 4.3 (noarch) * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Manager Proxy 4.3 (x86_64) * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 *libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 * SUSE Manager Server 4.3 (noarch) * WebKitGTK-4.0-lang-2.46.6-150400.4.106.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libjavascriptcoregtk-4_0-18-debuginfo-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2-4_0-2.46.6-150400.4.106.1 * typelib-1_0-WebKit2WebExtension-4_0-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-devel-2.46.6-150400.4.106.1 * webkit2gtk-4_0-injected-bundles-2.46.6-150400.4.106.1 * libjavascriptcoregtk-4_0-18-2.46.6-150400.4.106.1 * webkit2gtk3-soup2-debugsource-2.46.6-150400.4.106.1 * typelib-1_0-JavaScriptCore-4_0-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-debuginfo-2.46.6-150400.4.106.1 * libwebkit2gtk-4_0-37-2.46.6-150400.4.106.1 ## References: * https://www.suse.com/security/cve/CVE-2024-27856.html * https://www.suse.com/security/cve/CVE-2024-54543.html * https://www.suse.com/security/cve/CVE-2024-54658.html * https://www.suse.com/security/cve/CVE-2025-24143.html * https://www.suse.com/security/cve/CVE-2025-24150.html * https://www.suse.com/security/cve/CVE-2025-24158.html * https://www.suse.com/security/cve/CVE-2025-24162.html * https://bugzilla.suse.com/show_bug.cgi?id=1236946 . Important patches improve webkit2gtk3 safety for various SUSE variants, defending against harmful intrusions and ensuring application reliability.. SUSE Security Advisory, webkit2gtk3 update, Linux patch management. . Severity: Important. LinuxSecurity.com Team
* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024 . # Security update for SUSE Manager Client Tools Announcement ID: SUSE-SU-2025:0524-1 Release Date: 2025-02-14T07:16:37Z Rating: moderate References: * bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024 * bsc#1231497 * bsc#1231568 * bsc#1231759 * bsc#1232575 * bsc#1232769 * bsc#1232817 * bsc#1232970 * bsc#1233202 * bsc#1233279 * bsc#1233630 * bsc#1233660 * bsc#1234123 * bsc#1234554 * bsc#1235145 * bsc#1236301 * jsc#MSQA-914 * jsc#PED-11591 * jsc#PED-11649 Cross-References: * CVE-2023-3128 * CVE-2023-6152 * CVE-2024-22037 * CVE-2024-45337 * CVE-2024-51744 * CVE-2024-6837 * CVE-2024-8118 CVSS scores: * CVE-2023-3128 ( SUSE ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2023-3128 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6152 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2023-6152 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2024-22037 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L * CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-22037 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-45337 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45337 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-51744 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-51744 ( SUSE ): 3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2024-51744 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2024-6837 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-6837 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-8118 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2024-8118 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 * SUSE Manager Client Tools for SLE 12 An update that solves seven vulnerabilities, contains three features and has 13 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): * Securityissues fixed: * CVE-2024-51744: Updated golang-jwt to version 5.0 to fix bad error handling (bsc#1232970) * Highlights of other changes: * Performance: * Significant enhancements to PromQL execution speed, TSDB operations (especially querying and compaction) and remote write operations. * Default GOGC value lowered to 75 for better memory management. * Option to limit memory usage from dropped targets added. * New Features: * Experimental OpenTelemetry ingestion. * Automatic memory limit handling. * Native histogram support, including new functions, UI enhancements, and improved scraping. * Improved alerting features, such as relabeling rules for AlertmanagerConfig and a new query_offset option. * Expanded service discovery options with added metadata and support for new services. * New promtool commands for PromQL formatting, label manipulation, metric pushing, and OpenMetrics dumping. * Bug Fixes: * Numerous fixes across scraping, API, TSDB, PromQL, and service discovery. * For a detailed list of changes consult the package changelog or https://github.com/prometheus/prometheus/compare/v2.45.6...v2.53.3 golang-github-prometheus-promu was updated to version 0.17.0: * Added codesign utility function grafana was updated from version 9.5.18 to 10.4.13 (jsc#PED-11591,jsc#PED-11649): * Security issues fixed: * CVE-2024-45337: Prevent possible misuse of ServerConfig.PublicKeyCallback by upgrading golang.org/x/crypto (bsc#1234554) * CVE-2023-3128: Fixed authentication bypass using Azure AD OAuth (bsc#1212641) * CVE-2023-6152: Add email verification when updating user email (bsc#1219912) * CVE-2024-6837: Fixed potential data source permission escalation (bsc#1236301) * CVE-2024-8118: Fixed permission on external alerting rule write endpoint (bsc#1231024) * Potential breaking changes in version 10: * In panels using the `extract fields` transformation, where one of the extracted names collides with one of thealready existing ields, the extracted field will be renamed. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. To resolve this either: update transformation or field override. * For the existing backend mode users who have Transformations with the `time` field, might see their transformations are not working. Those panels that have broken transformations will fail to render. This is because we changed the field key. To resolve this either: Remove the affected panel and re- create it; Select the `Time` field again; Edit the `time` field as `Time` for transformation in `panel.json` or `dashboard.json` * The following data source permission endpoints have been removed: `GET /datasources/:datasourceId/permissions` `POST /api/datasources/:datasourceId/permissions` `DELETE /datasources/:datasourceId/permissions` `POST /datasources/:datasourceId/enable-permissions` `POST /datasources/:datasourceId/disable-permissions` * Please use the following endpoints instead: `GET /api/access-control/datasources/:uid` for listing data source permissions `POST /api/access-control/datasources/:uid/users/:id`, `POST /api/access-control/datasources/:uid/teams/:id` and `POST /api/access-control/datasources/:uid/buildInRoles/:id` for adding or removing data source permissions * If you are using Terraform Grafana provider to manage data source permissions, you will need to upgrade your provider. * For the existing backend mode users who have table visualization might see some inconsistencies on their panels. We have updated the table column naming. This will potentially affect field transformations and/or field overrides. * The deprecated `/playlists/{uid}/dashboards` API endpoint has been removed. Dashboard information can be retrieved from the `/dashboard/...` APIs. * The `PUT /api/folders/:uid` endpoint no more supports modifying the folder's `UID` * Removed all components for the old panel header design. * Please review changes/breaking-changes-v10-3/ for more details * OAuth role mapping enforcement: This change impacts GitHub, Gitlab, Okta, and Generic OAuth. To avoid overriding manually set roles, enable the skip_org_role_sync option in the Grafana configuration for your OAuth provider before upgrading * Angular has been deprecated * Grafana legacy alerting has been deprecated * API keys are migrating to service accounts * The experimental “dashboard previews” feature is removed * Usernames are now case-insensitive by default * Grafana OAuth integrations do not work anymore with email lookups * The “Alias” field in the CloudWatch data source is removed * Athena data source plugin must be updated to version > =2.9.3 * Redshift data source plugin must be updated to version > =1.8.3 * DoiT International BigQuery plugin no longer supported * Please review changes/breaking-changes-v10-0 for more details * This update brings many new features, enhancements and fixes highlighted at: * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-4/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-3/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-2/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-1/ * https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v10-0/ spacecmd was updated to version 5.0.11-0: * Updated translation strings supportutils-plugin-salt was updated to version 1.2.3: * Adjusted requirements for plugin to allow compatibility with supportutils 3.2.9 release (bsc#1235145) * Provide backwards-compatible scripts version supportutils-plugin-susemanager-client was updated to version 5.0.4-0: * Adjusted requirements for plugin to allow compatibility with supportutils 3.2.9 release (bsc#1235145) uyuni-toolswas updated from version 0.1.23-0 to 0.1.27-0: * Security issues fixed: * CVE-2024-22037: Use podman secret to store the database credentials (bsc#1231497) * Other changes and bugs fixed: * Version 0.1.27-0 * Bump the default image tag to 5.0.3 * IsInstalled function fix * Run systemctl daemon-reload after changing the container image config (bsc#1233279) * Coco-replicas-upgrade * Persist search server indexes (bsc#1231759) * Sync deletes files during migration (bsc#1233660) * Ignore coco and hub images when applying PTF if they are not ailable (bsc#1229079) * Add --registry back to mgrpxy (bsc#1233202) * Only add java.hostname on migrated server if not present * Consider the configuration file to detect the coco or hub api images should be pulled (bsc#1229104) * Only raise an error if cloudguestregistryauth fails for PAYG (bsc#1233630) * Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123) * Version 0.1.26-0 * Ignore all zypper caches during migration (bsc#1232769) * Use the uyuni network for all podman containers (bsc#1232817) * Version 0.1.25-0 * Don't migrate enabled systemd services, recreate them (bsc#1232575) * Redact JSESSIONID and pxt-session-cookie values from logs and console output (bsc#1231568) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 12 zypper in -t patch SUSE-SLE-Manager-Tools-12-2025-524=1 ## Package List: * SUSE Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.28-1.16.1 * mgrctl-debuginfo-0.1.28-1.16.1 * golang-github-prometheus-prometheus-2.53.3-1.56.1 * golang-github-prometheus-promu-0.17.0-1.24.1 * grafana-10.4.13-1.66.2 * SUSE Manager Client Tools for SLE 12 (noarch) * supportutils-plugin-susemanager-client-5.0.4-6.33.1 *mgrctl-zsh-completion-0.1.28-1.16.1 * mgrctl-bash-completion-0.1.28-1.16.1 * supportutils-plugin-salt-1.2.3-6.25.1 * spacecmd-5.0.11-38.153.1 ## References: * https://www.suse.com/security/cve/CVE-2023-3128.html * https://www.suse.com/security/cve/CVE-2023-6152.html * https://www.suse.com/security/cve/CVE-2024-22037.html * https://www.suse.com/security/cve/CVE-2024-45337.html * https://www.suse.com/security/cve/CVE-2024-51744.html * https://www.suse.com/security/cve/CVE-2024-6837.html * https://www.suse.com/security/cve/CVE-2024-8118.html * https://bugzilla.suse.com/show_bug.cgi?id=1212641 * https://bugzilla.suse.com/show_bug.cgi?id=1219912 * https://bugzilla.suse.com/show_bug.cgi?id=1229079 * https://bugzilla.suse.com/show_bug.cgi?id=1229104 * https://bugzilla.suse.com/show_bug.cgi?id=1231024 * https://bugzilla.suse.com/show_bug.cgi?id=1231497 * https://bugzilla.suse.com/show_bug.cgi?id=1231568 * https://bugzilla.suse.com/show_bug.cgi?id=1231759 * https://bugzilla.suse.com/show_bug.cgi?id=1232575 * https://bugzilla.suse.com/show_bug.cgi?id=1232769 * https://bugzilla.suse.com/show_bug.cgi?id=1232817 * https://bugzilla.suse.com/show_bug.cgi?id=1232970 * https://bugzilla.suse.com/show_bug.cgi?id=1233202 * https://bugzilla.suse.com/show_bug.cgi?id=1233279 * https://bugzilla.suse.com/show_bug.cgi?id=1233630 * https://bugzilla.suse.com/show_bug.cgi?id=1233660 * https://bugzilla.suse.com/show_bug.cgi?id=1234123 * https://bugzilla.suse.com/show_bug.cgi?id=1234554 * https://bugzilla.suse.com/show_bug.cgi?id=1235145 * https://bugzilla.suse.com/show_bug.cgi?id=1236301 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11591&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role= . A new patch for SUSE ManagerClient Tools addresses several vulnerabilities, boosting user safety.. SUSE Manager Security,SUSE Updates,Threat Mitigation,Security Patches,SUSE Tools Fixes. . LinuxSecurity.com Team
* bsc#1229079 * bsc#1229104 * bsc#1230361 * bsc#1231497 * bsc#1231568 . # Security update for SUSE Manager Client Tools Announcement ID: SUSE-SU-2025:0532-1 Release Date: 2025-02-14T07:20:13Z Rating: moderate References: * bsc#1229079 * bsc#1229104 * bsc#1230361 * bsc#1231497 * bsc#1231568 * bsc#1231759 * bsc#1232575 * bsc#1232769 * bsc#1232817 * bsc#1233202 * bsc#1233279 * bsc#1233630 * bsc#1233660 * bsc#1234123 * jsc#ECO-3319 * jsc#MSQA-914 Cross-References: * CVE-2024-22037 CVSS scores: * CVE-2024-22037 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L * CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-22037 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Manager Client Tools for RHEL, Liberty and Clones 9 An update that solves one vulnerability, contains two features and has 13 security fixes can now be installed. ## Description: This update fixes the following issues: scap-security-guide was updated to version 0.1.75 (jsc#ECO-3319): * Added Ism profile for OL8, OL9 * Added new product kylinserver10 * Created OL10 product * Release SLMicro5 product * Replaced two date injections by SOURCE_DATE_EPOCH to make reproducible (bsc#1230361) * Updated PCI-DSS control file for version 4.0.1 spacecmd was updated to version 5.0.11-0: * Updated translation strings uyuni-tools was updated from version 0.1.23-0 to 0.1.27-0: * Security issues fixed: * CVE-2024-22037: Use podman secret to store the database credentials (bsc#1231497) * Other changes and bugs fixed: * Version 0.1.27-0 * Bump the default image tag to 5.0.3 * IsInstalled function fix * Run systemctl daemon-reload afterchanging the container image config (bsc#1233279) * Coco-replicas-upgrade * Persist search server indexes (bsc#1231759) * Sync deletes files during migration (bsc#1233660) * Ignore coco and hub images when applying PTF if they are not ailable (bsc#1229079) * Add --registry back to mgrpxy (bsc#1233202) * Only add java.hostname on migrated server if not present * Consider the configuration file to detect the coco or hub api images should be pulled (bsc#1229104) * Only raise an error if cloudguestregistryauth fails for PAYG (bsc#1233630) * Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123) * Version 0.1.26-0 * Ignore all zypper caches during migration (bsc#1232769) * Use the uyuni network for all podman containers (bsc#1232817) * Version 0.1.25-0 * Don't migrate enabled systemd services, recreate them (bsc#1232575) * Version 0.1.24-0 * Redact JSESSIONID and pxt-session-cookie values from logs and console output (bsc#1231568) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for RHEL, Liberty and Clones 9 zypper in -t patch SUSE-EL-9-CLIENT-TOOLS-2025-532=1 ## Package List: * SUSE Manager Client Tools for RHEL, Liberty and Clones 9 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.28-1.14.1 * mgrctl-debuginfo-0.1.28-1.14.1 * SUSE Manager Client Tools for RHEL, Liberty and Clones 9 (noarch) * mgrctl-zsh-completion-0.1.28-1.14.1 * scap-security-guide-redhat-0.1.75-1.32.1 * spacecmd-5.0.11-1.44.1 * mgrctl-bash-completion-0.1.28-1.14.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22037.html * https://bugzilla.suse.com/show_bug.cgi?id=1229079 * https://bugzilla.suse.com/show_bug.cgi?id=1229104 * https://bugzilla.suse.com/show_bug.cgi?id=1230361 *https://bugzilla.suse.com/show_bug.cgi?id=1231497 * https://bugzilla.suse.com/show_bug.cgi?id=1231568 * https://bugzilla.suse.com/show_bug.cgi?id=1231759 * https://bugzilla.suse.com/show_bug.cgi?id=1232575 * https://bugzilla.suse.com/show_bug.cgi?id=1232769 * https://bugzilla.suse.com/show_bug.cgi?id=1232817 * https://bugzilla.suse.com/show_bug.cgi?id=1233202 * https://bugzilla.suse.com/show_bug.cgi?id=1233279 * https://bugzilla.suse.com/show_bug.cgi?id=1233630 * https://bugzilla.suse.com/show_bug.cgi?id=1233660 * https://bugzilla.suse.com/show_bug.cgi?id=1234123 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FECO-3319&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= . Patch announcement for SUSE Manager Client Tools, detailing vulnerabilities resolved and guidance for implementation.. SUSE Manager Tools, security updates, software patching, SUSE advisory. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-9454 http://linux.oracle.com/errata/ELSA-2024-9454.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: podman-5.2.2-9.0.1.el9_5.x86_64.rpm podman-docker-5.2.2-9.0.1.el9_5.noarch.rpm podman-plugins-5.2.2-9.0.1.el9_5.x86_64.rpm podman-remote-5.2.2-9.0.1.el9_5.x86_64.rpm podman-tests-5.2.2-9.0.1.el9_5.x86_64.rpm aarch64: podman-5.2.2-9.0.1.el9_5.aarch64.rpm podman-docker-5.2.2-9.0.1.el9_5.noarch.rpm podman-plugins-5.2.2-9.0.1.el9_5.aarch64.rpm podman-remote-5.2.2-9.0.1.el9_5.aarch64.rpm podman-tests-5.2.2-9.0.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//podman-5.2.2-9.0.1.el9_5.src.rpm Related CVEs: CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 CVE-2024-9676 CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 Description of changes: [5.2.2-9.0.1] - Add devices on container startup, not on creation - overlay: Put should ignore ENINVAL for Unmount [Orabug: 36234694] - Drop nmap-ncat requirement and skip ignore-socket test case [Orabug: 34117404] [4:5.2.2-9] - update to the latest content of https://github.com/containers/podman/tree/v5.2-rhel (https://github.com/containers/podman/commit/6df7dfb) - Resolves: RHEL-61847 [4:5.2.2-8] - update to the latest content of https://github.com/containers/podman/tree/v5.2-rhel (https://github.com/containers/podman/commit/c03b5f3) - Resolves: RHEL-61667 [4:5.2.2-7] - attempt to fix the TMT testing pipeline - Resolves: RHEL-59714 [4:5.2.2-6] - podman gating: test CNI, thanks to Ed Santiago - Resolves: RHEL-61249 [4:5.2.2-5] - bump Epoch to 4 - Resolves: RHEL-60963 [2:5.2.2-4] - update to the latest content of https://github.com/containers/podman/tree/v5.2-rhel (https://github.com/containers/podman/commit/8e693ce) - Resolves: RHEL-60963 [2:5.2.2-3] - update to the latest content of https://github.com/containers/podman/tree/v5.2-rhel (https://github.com/containers/podman/commit/5f2c188) - Resolves: RHEL-59703 [2:5.2.2-2] - Add cni build tag to podman build - Resolves: RHEL-59714 _______________________________________________ El-errata mailing list
Several security issues were fixed in OpenJDK 17.. ========================================================================== Ubuntu Security Notice USN-7098-1 November 11, 2024 openjdk-17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenJDK 17. Software Description: - openjdk-17: Open Source Java implementation Details: Andy Boothe discovered that the Networking component of OpenJDK 17 did not properly handle access under certain circumstances. An unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2024-21208) It was discovered that the Hotspot component of OpenJDK 17 did not properly handle vectorization under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2024-21210, CVE-2024-21235) It was discovered that the Serialization component of OpenJDK 17 did not properly handle deserialization under certain circumstances. An unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2024-21217) It was discovered that the Hotspot component of OpenJDK 17 was not properly bounding certain UTF-8 strings, which could lead to a buffer overflow. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2024-21131) It was discovered that the Hotspot component of OpenJDK 17 could be made to run into an infinite loop. If an automated system were tricked into processing excessively large symbols, an attacker could possibly use this issue to cause a denial of service. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2024-21138) It wasdiscovered that the Hotspot component of OpenJDK 17 did not properly perform range check elimination. An attacker could possibly use this issue to cause a denial of service, execute arbitrary code or bypass Java sandbox restrictions. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2024-21140) Sergey Bylokhov discovered that OpenJDK 17 did not properly manage memory when handling 2D images. An attacker could possibly use this issue to obtain sensitive information. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2024-21145) It was discovered that the Hotspot component of OpenJDK 17 incorrectly handled memory when performing range check elimination under certain circumstances. An attacker could possibly use this issue to cause a denial of service, execute arbitrary code or bypass Java sandbox restrictions. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2024-21147) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 openjdk-17-jdk 17.0.13+11-2ubuntu1~24.10 openjdk-17-jdk-headless 17.0.13+11-2ubuntu1~24.10 openjdk-17-jre 17.0.13+11-2ubuntu1~24.10 openjdk-17-jre-headless 17.0.13+11-2ubuntu1~24.10 openjdk-17-jre-zero 17.0.13+11-2ubuntu1~24.10 Ubuntu 24.04 LTS openjdk-17-jdk 17.0.13+11-2ubuntu1~24.04 openjdk-17-jdk-headless 17.0.13+11-2ubuntu1~24.04 openjdk-17-jre 17.0.13+11-2ubuntu1~24.04 openjdk-17-jre-headless 17.0.13+11-2ubuntu1~24.04 openjdk-17-jre-zero 17.0.13+11-2ubuntu1~24.04 Ubuntu 22.04 LTS openjdk-17-jdk 17.0.13+11-2ubuntu1~22.04 openjdk-17-jdk-headless 17.0.13+11-2ubuntu1~22.04 openjdk-17-jre 17.0.13+11-2ubuntu1~22.04 openjdk-17-jre-headless 17.0.13+11-2ubuntu1~22.04 openjdk-17-jre-zero 17.0.13+11-2ubuntu1~22.04 Ubuntu 20.04 LTS openjdk-17-jdk 17.0.13+11-2ubuntu1~20.04 openjdk-17-jdk-headless 17.0.13+11-2ubuntu1~20.04 openjdk-17-jre 17.0.13+11-2ubuntu1~20.04 openjdk-17-jre-headless 17.0.13+11-2ubuntu1~20.04 openjdk-17-jre-zero 17.0.13+11-2ubuntu1~20.04 Ubuntu 18.04 LTS openjdk-17-jdk 17.0.13+11-2ubuntu1~18.04.2 Available with Ubuntu Pro openjdk-17-jdk-headless 17.0.13+11-2ubuntu1~18.04.2 Available with Ubuntu Pro openjdk-17-jre 17.0.13+11-2ubuntu1~18.04.2 Available with Ubuntu Pro openjdk-17-jre-headless 17.0.13+11-2ubuntu1~18.04.2 Available with Ubuntu Pro openjdk-17-jre-zero 17.0.13+11-2ubuntu1~18.04.2 Available with Ubuntu Pro This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart Java applications to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7098-1 CVE-2024-21131, CVE-2024-21138, CVE-2024-21140, CVE-2024-21145, CVE-2024-21147, CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235 Package Information: https://launchpad.net/ubuntu/+source/openjdk-17/17.0.13+11-2ubuntu1~22.04 https://launchpad.net/ubuntu/+source/openjdk-17/17.0.13+11-2ubuntu1~20.04 .The latest OpenJDK 17 security patches addressed severe vulnerabilities, such as remote code execution and denial of service threats.. Java Security Updates, Ubuntu Pro Security, Open Source Java Fixes, OpenJDK 17 Patches. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.