Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 3 vulnerabilities can now be installed.. # jq-1.8.1-1.1 on GA media Announcement ID: openSUSE-SU-2025:15233-1 Rating: moderate Cross-References: * CVE-2024-23337 * CVE-2025-48060 * CVE-2025-49014 CVSS scores: * CVE-2024-23337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-23337 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49014 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-49014 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 3 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the jq-1.8.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * jq 1.8.1-1.1 * libjq-devel 1.8.1-1.1 * libjq1 1.8.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-23337.html * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2025-49014.html . Oversee the patch deployment process in openSUSE Tumbleweed to tackle moderate vulnerabilities related to jq and improve overall system security.. jq security, openSUSE Tumbleweed, moderate vulnerabilities, system updates. . LinuxSecurity.com Team
* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553 . # Security update for the Linux Kernel (Live Patch 46 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:0243-1 Release Date: 2025-01-27T11:33:48Z Rating: important References: * bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553 * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2021-47291 * CVE-2021-47598 * CVE-2022-48956 * CVE-2024-36971 * CVE-2024-41059 * CVE-2024-43861 * CVE-2024-50264 CVSS scores: * CVE-2021-47291 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47291 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2021-47598 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2021-47598 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-36971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41059 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-41059 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-41059 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-43861 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43861 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_167 fixes several issues. The following security issues were fixed: * CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). * CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). * CVE-2021-47598: sch_cake: do not call cake_destroy() from cake_init() (bsc#1227471). * CVE-2021-47291: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions (bsc#1227651). * CVE-2024-41059: hfsplus: fix uninit-value in copy_name (bsc#1228573). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-243=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-243=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_167-default-debuginfo-6-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_167-default-6-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_46-debugsource-6-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_167-preempt-6-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_167-preempt-debuginfo-6-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_167-default-6-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2021-47291.html * https://www.suse.com/security/cve/CVE-2021-47598.html *https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-36971.html * https://www.suse.com/security/cve/CVE-2024-41059.html * https://www.suse.com/security/cve/CVE-2024-43861.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1226324 * https://bugzilla.suse.com/show_bug.cgi?id=1227471 * https://bugzilla.suse.com/show_bug.cgi?id=1227651 * https://bugzilla.suse.com/show_bug.cgi?id=1228573 * https://bugzilla.suse.com/show_bug.cgi?id=1229553 * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . Safety enhancement for Linux Kernel Live Patch 46 in SLE 15 SP3 resolves various vulnerabilities, bolstering operational security.. Linux Kernel Updates,SUSE Linux Security,Live Patch 15 SP3,Kernel Fixes 2025. . Severity: Important. LinuxSecurity.com Team
* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059 . # Security update for the Linux Kernel (Live Patch 43 for SLE 15 SP3) Announcement ID: SUSE-SU-2024:2773-1 Rating: important References: * bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059 * bsc#1223363 * bsc#1223514 * bsc#1223683 * bsc#1225013 * bsc#1225211 * bsc#1225310 Cross-References: * CVE-2021-46955 * CVE-2021-47383 * CVE-2022-48651 * CVE-2023-1829 * CVE-2024-23307 * CVE-2024-26610 * CVE-2024-26828 * CVE-2024-26852 * CVE-2024-26923 * CVE-2024-27398 * CVE-2024-35950 CVSS scores: * CVE-2021-46955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2021-47383 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48651 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1829 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1829 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-23307 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26610 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-26828 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2024-26852 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-26923 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-27398 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-35950 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves 11 vulnerabilities cannow be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_158 fixes several issues. The following security issues were fixed: * CVE-2024-27398: Fixed use-after-free bug caused by sco_sock_timeout() (bsc#1225013). * CVE-2024-35950: drm/client: Fully protect modes with dev-> mode_config.mutex (bsc#1225310). * CVE-2021-47383: Fixed out-of-bound vmalloc access in imageblit (bsc#1225211). * CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223683). * CVE-2024-26828: Fixed underflow in parse_server_interfaces() (bsc#1223363). * CVE-2021-46955: Fixed an out-of-bounds read with openvswitch, when fragmenting IPv4 packets (bsc#1220537). * CVE-2024-23307: Fixed Integer Overflow or Wraparound vulnerability in x86 and ARM md, raid, raid5 modules (bsc#1220145). * CVE-2024-26852: Fixed use-after-free in ip6_route_mpath_notify() (bsc#1223059). * CVE-2024-26610: Fixed memory corruption in wifi/iwlwifi (bsc#1221302). * CVE-2022-48651: Fixed an out-of-bound bug in ipvlan caused by unset skb-> mac_header (bsc#1223514). * CVE-2023-1829: Fixed a use-after-free vulnerability in the control index filter (tcindex) (bsc#1210619). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2773=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2024-2773=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_158-default-5-150300.7.6.1 * kernel-livepatch-5_3_18-150300_59_158-default-debuginfo-5-150300.7.6.1 * kernel-livepatch-SLE15-SP3_Update_43-debugsource-5-150300.7.6.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_158-preempt-debuginfo-5-150300.7.6.1 *kernel-livepatch-5_3_18-150300_59_158-preempt-5-150300.7.6.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_158-default-5-150300.7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2021-46955.html * https://www.suse.com/security/cve/CVE-2021-47383.html * https://www.suse.com/security/cve/CVE-2022-48651.html * https://www.suse.com/security/cve/CVE-2023-1829.html * https://www.suse.com/security/cve/CVE-2024-23307.html * https://www.suse.com/security/cve/CVE-2024-26610.html * https://www.suse.com/security/cve/CVE-2024-26828.html * https://www.suse.com/security/cve/CVE-2024-26852.html * https://www.suse.com/security/cve/CVE-2024-26923.html * https://www.suse.com/security/cve/CVE-2024-27398.html * https://www.suse.com/security/cve/CVE-2024-35950.html * https://bugzilla.suse.com/show_bug.cgi?id=1210619 * https://bugzilla.suse.com/show_bug.cgi?id=1220145 * https://bugzilla.suse.com/show_bug.cgi?id=1220537 * https://bugzilla.suse.com/show_bug.cgi?id=1221302 * https://bugzilla.suse.com/show_bug.cgi?id=1223059 * https://bugzilla.suse.com/show_bug.cgi?id=1223363 * https://bugzilla.suse.com/show_bug.cgi?id=1223514 * https://bugzilla.suse.com/show_bug.cgi?id=1223683 * https://bugzilla.suse.com/show_bug.cgi?id=1225013 * https://bugzilla.suse.com/show_bug.cgi?id=1225211 * https://bugzilla.suse.com/show_bug.cgi?id=1225310 . Crucial Kernel Live Patch release for SUSE 15 SP3 tackles severe vulnerabilities, enhancing overall security of the platform.. SUSE Linux Update, Kernel Security Patch, SUSE Live Patching. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2023-48795. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a53b24023d 2024-01-29 06:23:44.937502 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 39 Version : 1.7.0 Release : 1.fc39 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-48795 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 21 2024 Navid Yaghoobi - 1.7.0-1 - release v1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255105 - CVE-2023-48795 prometheus-podman-exporter: ssh: Prefix truncation attack on Binary Packet Protocol (BPP) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a53b24023d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.7.0 ESR (MFSA2024-02) (bsc#1218955):. # Security update for MozillaFirefox Announcement ID: SUSE-SU-2024:0229-1 Rating: important References: * bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742 * CVE-2024-0746 * CVE-2024-0747 * CVE-2024-0749 * CVE-2024-0750 * CVE-2024-0751 * CVE-2024-0753 * CVE-2024-0755 CVSS scores: Affected Products: * Desktop Applications Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 115.7.0 ESR (MFSA2024-02) (bsc#1218955): *CVE-2024-0741: Out of bounds write in ANGLE * CVE-2024-0742: Failure to update user input timestamp * CVE-2024-0746: Crash when listing printers on Linux * CVE-2024-0747: Bypass of Content Security Policy when directive unsafe- inline was set * CVE-2024-0749: Phishing site popup could show local origin in address bar * CVE-2024-0750: Potential permissions request bypass via clickjacking * CVE-2024-0751: Privilege escalation through devtools * CVE-2024-0753: HSTS policy on subdomain could bypass policy of upper domain * CVE-2024-0755: Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-229=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-229=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-229=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-229=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-229=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-229=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patchSUSE-SLE-Product-SLES-15-SP4-LTSS-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-229=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-229=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-229=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * MozillaFirefox-branding-upstream-115.7.0-150200.152.123.1 * openSUSE Leap 15.5 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * Desktop Applications Module 15-SP5 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP3 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) *MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 *MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * MozillaFirefox-115.7.0-150200.152.123.1 * MozillaFirefox-debugsource-115.7.0-150200.152.123.1 * MozillaFirefox-debuginfo-115.7.0-150200.152.123.1 * MozillaFirefox-translations-other-115.7.0-150200.152.123.1 * MozillaFirefox-translations-common-115.7.0-150200.152.123.1 * SUSE Enterprise Storage 7.1 (noarch) * MozillaFirefox-devel-115.7.0-150200.152.123.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0741.html * https://www.suse.com/security/cve/CVE-2024-0742.html * https://www.suse.com/security/cve/CVE-2024-0746.html * https://www.suse.com/security/cve/CVE-2024-0747.html * https://www.suse.com/security/cve/CVE-2024-0749.html * https://www.suse.com/security/cve/CVE-2024-0750.html * https://www.suse.com/security/cve/CVE-2024-0751.html * https://www.suse.com/security/cve/CVE-2024-0753.html * https://www.suse.com/security/cve/CVE-2024-0755.html * https://bugzilla.suse.com/show_bug.cgi?id=1218955 . Apply the critical security patch for MozillaFirefox to resolve various vulnerabilities and improve overall system protection.. MozillaFirefox Update, openSUSE Security,Important Software Patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4570 https://linux.oracle.com/errata/ELSA-2023-4570.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: iperf3-3.5-7.el8_8.i686.rpm iperf3-3.5-7.el8_8.x86_64.rpm aarch64: iperf3-3.5-7.el8_8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//iperf3-3.5-7.el8_8.src.rpm Related CVEs: CVE-2023-38403 Description of changes: [3.5-7] - Fixes CVE-2023-38403 Resolves: rhbz#2223729 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3151 https://linux.oracle.com/errata/ELSA-2023-3151.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: thunderbird-102.11.0-1.0.1.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//thunderbird-102.11.0-1.0.1.el7_9.src.rpm Related CVEs: CVE-2023-32205 CVE-2023-32206 CVE-2023-32207 CVE-2023-32211 CVE-2023-32212 CVE-2023-32213 CVE-2023-32215 Description of changes: [102.11.0-1.0.1] - Replaced thunderbird-redhat-default-prefs.js with thunderbird-oracle-default-prefs.js - Enabled aarch64 build [102.11.0-1] - Update to 102.11.0 build1 _______________________________________________ El-errata mailing list
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for kubevirt ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3919-1 Rating: important References: Affected Products: SUSE Enterprise Storage 7.1 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Containers 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update rebuilds the kubevirt stack to include recent security updates in its basecontainers. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3919=1 - SUSE Linux Enterprise Module for Containers 15-SP3: zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2022-3919=1 Package List: - openSUSE Leap 15.3 (x86_64): kubevirt-container-disk-0.49.0-150300.8.15.1 kubevirt-container-disk-debuginfo-0.49.0-150300.8.15.1 kubevirt-manifests-0.49.0-150300.8.15.1 kubevirt-tests-0.49.0-150300.8.15.1 kubevirt-tests-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-api-0.49.0-150300.8.15.1 kubevirt-virt-api-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-controller-0.49.0-150300.8.15.1 kubevirt-virt-controller-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-handler-0.49.0-150300.8.15.1 kubevirt-virt-handler-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-launcher-0.49.0-150300.8.15.1 kubevirt-virt-launcher-debuginfo-0.49.0-150300.8.15.1 kubevirt-virt-operator-0.49.0-150300.8.15.1 kubevirt-virt-operator-debuginfo-0.49.0-150300.8.15.1 kubevirt-virtctl-0.49.0-150300.8.15.1 kubevirt-virtctl-debuginfo-0.49.0-150300.8.15.1 obs-service-kubevirt_containers_meta-0.49.0-150300.8.15.1 - SUSE Linux Enterprise Module for Containers 15-SP3 (x86_64): kubevirt-manifests-0.49.0-150300.8.15.1 kubevirt-virtctl-0.49.0-150300.8.15.1 kubevirt-virtctl-debuginfo-0.49.0-150300.8.15.1 References: . SUSE issues critical security patch for kubevirt impacting multiple SUSE solutions. Upgrade immediately to maintain system integrity.. Kubevirt Security Update,SUSE Container Fixes,SUSE Update Instructions,SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.