An update that solves one vulnerability can now be installed.. # Security update for python-Django Announcement ID: SUSE-SU-2025:01952-1 Release Date: 2025-06-13T13:55:13Z Rating: moderate References: * bsc#1244095 Cross-References: * CVE-2025-48432 CVSS scores: * CVE-2025-48432 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N * CVE-2025-48432 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2025-48432 ( NVD ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-Django fixes the following issues: * CVE-2025-48432: log injection or forgery due to unescaped control characters being added into logs (bsc#1244095). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-1952=1 openSUSE-SLE-15.6-2025-1952=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1952=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-1952=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-Django-4.2.11-150600.3.24.1 * SUSE Package Hub 15 15-SP6 (noarch) * python311-Django-4.2.11-150600.3.24.1 * SUSE Package Hub 15 15-SP7 (noarch) * python311-Django-4.2.11-150600.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48432.html * https://bugzilla.suse.com/show_bug.cgi?id=1244095 . Important security patch for python-Django mitigates log injection vulnerabilities in openSUSE systems. Make sure to apply the suggested updates.. openSUSE, security advisory, python-Django update, log injection fix. . LinuxSecurity.com Team
* bsc#1225462 Cross-References: * CVE-2024-54661 . # Security update for socat Announcement ID: SUSE-SU-2024:4294-1 Release Date: 2024-12-11T13:06:43Z Rating: moderate References: * bsc#1225462 Cross-References: * CVE-2024-54661 CVSS scores: * CVE-2024-54661 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2024-54661 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for socat fixes the following issues: * CVE-2024-54661: Fixed arbitrary file overwrite via predictable /tmp directory (bsc#1225462) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2024-4294=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * socat-debugsource-1.7.2.4-4.3.1 * socat-1.7.2.4-4.3.1 * socat-debuginfo-1.7.2.4-4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-54661.html * https://bugzilla.suse.com/show_bug.cgi?id=1225462 . Important enhancement for socat addresses significant challenges. Adhere to setup guidelines for openSUSE platforms now.. socat security update, suse linux server, socat patch release. . LinuxSecurity.com Team
* bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610 . # Security update for the Linux Kernel RT (Live Patch 0 for SLE 15 SP5) Announcement ID: SUSE-SU-2024:1097-1 Rating: important References: * bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610 Cross-References: * CVE-2023-0461 * CVE-2023-39191 * CVE-2023-46813 * CVE-2023-51779 * CVE-2023-6531 CVSS scores: * CVE-2023-0461 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-0461 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-39191 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-39191 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2023-46813 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-46813 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-51779 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6531 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6531 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150500_11 fixes several issues. The following security issues were fixed: * CVE-2023-6531: Fixed a use-after-free flaw due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic()on the socket that the SKB is queued on (bsc#1218487). * CVE-2023-46813: Fixed a local privilege escalation with user-space programs that have access to MMIO regions (bsc#1216898). * CVE-2023-39191:Fixed a lack of validation of dynamic pointers within user- supplied eBPF programs that may have allowed an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code. (bsc#1215863) * CVE-2023-51779: Fixed a use-after-free because of a bt_sock_ioctl race condition in bt_sock_recvmsg (bsc#1218610). * CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208911). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1097=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2024-1097=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * kernel-livepatch-5_14_21-150500_11-rt-9-150500.6.2 * kernel-livepatch-5_14_21-150500_11-rt-debuginfo-9-150500.6.2 * kernel-livepatch-SLE15-SP5-RT_Update_0-debugsource-9-150500.6.2 * SUSE Linux Enterprise Live Patching 15-SP5 (x86_64) * kernel-livepatch-5_14_21-150500_11-rt-9-150500.6.2 * kernel-livepatch-5_14_21-150500_11-rt-debuginfo-9-150500.6.2 * kernel-livepatch-SLE15-SP5-RT_Update_0-debugsource-9-150500.6.2 ## References: * https://www.suse.com/security/cve/CVE-2023-0461.html * https://www.suse.com/security/cve/CVE-2023-39191.html * https://www.suse.com/security/cve/CVE-2023-46813.html * https://www.suse.com/security/cve/CVE-2023-51779.html * https://www.suse.com/security/cve/CVE-2023-6531.html * https://bugzilla.suse.com/show_bug.cgi?id=1208911 * https://bugzilla.suse.com/show_bug.cgi?id=1215887 * https://bugzilla.suse.com/show_bug.cgi?id=1216898 * https://bugzilla.suse.com/show_bug.cgi?id=1218487 * https://bugzilla.suse.com/show_bug.cgi?id=1218610 . Important notice for Linux Kernel: A recent update has been issued to address multiple security vulnerabilities in SUSE systems. Prompt application of the patch iscrucial for safety. Linux Kernel, Security Advisory, SUSE Patch, Privilege Escalation, Use-After-Free. . Severity: Important. LinuxSecurity.com Team
* bsc#1215469 Cross-References: * CVE-2023-41419 . # Security update for python-gevent Announcement ID: SUSE-SU-2023:4091-1 Rating: important References: * bsc#1215469 Cross-References: * CVE-2023-41419 CVSS scores: * CVE-2023-41419 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2023-41419 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSEManager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-gevent fixes the following issues: * CVE-2023-41419: Fixed a http request smuggling (bsc#1215469). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4091=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4091=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4091=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4091=1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4091=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4091=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4091=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4091=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4091=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4091=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patchSUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4091=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4091=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4091=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4091=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4091=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4091=1 ## Package List: * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE CaaS Platform 4.0 (x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 *python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 *python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python2-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * python2-gevent-1.2.2-150000.5.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Manager Proxy 4.2 (x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * python-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-debuginfo-1.2.2-150000.5.3.1 * python3-gevent-1.2.2-150000.5.3.1 * python-gevent-debugsource-1.2.2-150000.5.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-41419.html * https://bugzilla.suse.com/show_bug.cgi?id=1215469 . This important patch for python-gevent addresses vulnerabilities related to HTTP request smuggling, assigned a CVSS score of 9.8.. python GeventSecurity,SUSE Important Updates,HTTP Request Smuggling. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.