MGASA-2025-0294 - Updated spdlog packages fix security vulnerability. MGASA-2025-0294 - Updated spdlog packages fix security vulnerability Publication date: 15 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0294.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-6140 Description: Spdlog pattern_formatter-inl.h scoped_padder resource consumption. (CVE-2025-6140) References: - https://bugs.mageia.org/show_bug.cgi?id=34446 - https://lists.opensuse.org/archives/list/
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for spdlog ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0241-1 Rating: moderate References: #1244696 Cross-References: CVE-2025-6140 CVSS scores: CVE-2025-6140 (SUSE): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for spdlog fixes the following issues: - CVE-2025-6140: Fixed input manipulation that may lead to resource consumption (boo#1244696) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-241=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): libspdlog1_11-1.11.0-bp157.2.3.1 spdlog-devel-1.11.0-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libspdlog1_11-64bit-1.11.0-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-6140.html https://bugzilla.suse.com/1244696 . A resource consumption vulnerability has been found in the spdlog library affecting openSUSE systems. This may lead to performance degradation in applications using spdlog. openSUSE Security, spdlog Update, resource issue, security Patch, CVE-2025-6140. . LinuxSecurity.com Team
Backported the upstream CVE-2025-6140 fix.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7d5c7fe0c7 2025-06-21 02:10:24.663259+00:00 -------------------------------------------------------------------------------- Name : spdlog Product : Fedora 41 Version : 1.14.1 Release : 4.fc41 URL : https://github.com/gabime/spdlog Summary : Super fast C++ logging library Description : This is a packaged version of the gabime/spdlog C++ logging library available at Github. -------------------------------------------------------------------------------- Update Information: Backported the upstream CVE-2025-6140 fix. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 17 2025 Vitaly - 1.14.1-4 - Backported the upstream CVE-2025-6140 fix. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2373092 - CVE-2025-6140 spdlog: spdlog pattern_formatter-inl.h scoped_padder resource consumption [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2373092 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7d5c7fe0c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.