An update that solves one vulnerability can now be installed.. # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:1763-1 Release Date: 2026-05-08T08:59:32Z Rating: important References: * bsc#1239324 Cross-References: * CVE-2025-22869 CVSS scores: * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider- random, terraform-provider-tls fixes the following issues: * CVE-2025-22869: golang.org/x/crypto/ssh: denial of service when clients do not complete the key exchange in SSH servers which implement file transfer protocols (bsc#1239324). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patchSUSE-SLE-Module-Public-Cloud-15-SP4-2026-1763=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-1763=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-external-2.0.0-150200.6.6.1 * terraform-provider-azurerm-2.32.0-150200.6.6.1 * terraform-provider-google-3.43.0-150200.6.6.1 * terraform-provider-helm-2.9.0-150200.6.17.1 * terraform-provider-tls-3.0.0-150200.5.9.1 * terraform-provider-kubernetes-1.13.2-150200.6.6.1 * terraform-provider-random-3.0.0-150200.6.9.1 * terraform-provider-aws-3.11.0-150200.6.12.1 * terraform-provider-local-2.0.0-150200.6.11.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-external-2.0.0-150200.6.6.1 * terraform-provider-azurerm-2.32.0-150200.6.6.1 * terraform-provider-google-3.43.0-150200.6.6.1 * terraform-provider-helm-2.9.0-150200.6.17.1 * terraform-provider-tls-3.0.0-150200.5.9.1 * terraform-provider-kubernetes-1.13.2-150200.6.6.1 * terraform-provider-random-3.0.0-150200.6.9.1 * terraform-provider-aws-3.11.0-150200.6.12.1 * terraform-provider-local-2.0.0-150200.6.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22869.html * https://bugzilla.suse.com/show_bug.cgi?id=1239324 . SUSE update resolves important issue affecting multiple terraform providers, enhancing security and stability.. SUSE Update, Terraform Providers, Security Patch. . Severity: Important. LinuxSecurity.com Team
This update of terraform-provider-null fixes the following issues: rebuild the package with the go 1.21 security release (bsc#1212475).. # Security update for terraform-provider-null Announcement ID: SUSE-SU-2023:3588-1 Rating: important References: * #1212475 Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP5 An update that has one security fix can now be installed. ## Description: This update of terraform-provider-null fixes the following issues: * rebuild the package with the go 1.21 security release (bsc#1212475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patchopenSUSE-SLE-15.4-2023-3588=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3588=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3588=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2023-3588=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2023-3588=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2023-3588=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2023-3588=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1212475 . Critical security bulletin release for terraform-provider-void highlighting significant amendments across multiple Ubuntu distributions.. Terraform Provider Null, Security Advisory, SUSE Update, OpenSUSE Patch. . Severity: Important. LinuxSecurity.com Team
This update of terraform-provider-aws fixes the following issues: rebuild the package with the go 1.21 security release (bsc#1212475).. # Security update for terraform-provider-aws Announcement ID: SUSE-SU-2023:3589-1 Rating: important References: * #1212475 Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP5 An update that has one security fix can now be installed. ## Description: This update of terraform-provider-aws fixes the following issues: * rebuild the package with the go 1.21 security release (bsc#1212475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP2 zypper in -t patchSUSE-SLE-Module-Public-Cloud-15-SP2-2023-3589=1 * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2023-3589=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2023-3589=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2023-3589=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3589=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3589=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3589=1 ## Package List: * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1212475 . Important security patch for terraform-provider-aws rectifying major vulnerabilities in various SUSE Linux distributions.. terraform-provider-aws update, openSUSE security, critical fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability, contains two features and has two fixes is now available. . SUSE Security Update: Security update for terraform ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0263-1 Rating: moderate References: #1168921 #1170264 #1177421 ECO-2766 PM-2215 Cross-References: CVE-2020-14039 Affected Products: SUSE Linux Enterprise Module for Public Cloud 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability, contains two features and has two fixes is now available. Description: This update for terraform fixes the following issues: - Updated terraform to version 0.13.4 (bsc#1177421) * Many features, bug fixes, and enhancements were made during this update. Please refer to the terraform rpm changelog, for a full list of all changes. - The following terraform providers were updated: * terraform-provider-aws * terraform-provider-azurerm * terraform-provider-external * terraform-provider-google * terraform-provider-helm * terraform-provider-kubernetes * terraform-provider-local * terraform-provider-null * terraform-provider-random * terraform-provider-tls Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 15-SP2: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2021-263=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 15-SP2 (aarch64 ppc64le s390x x86_64): terraform-0.13.4-6.3.1 terraform-provider-aws-3.11.0-6.3.1 terraform-provider-azurerm-2.32.0-6.3.1 terraform-provider-external-2.0.0-6.3.1 terraform-provider-google-3.43.0-6.3.1 terraform-provider-helm-1.3.2-6.3.1 terraform-provider-kubernetes-1.13.2-6.3.1 terraform-provider-local-2.0.0-6.3.1 terraform-provider-null-3.0.0-6.3.1 terraform-provider-random-3.0.0-6.3.1 terraform-provider-tls-3.0.0-5.3.2 References: https://www.suse.com/security/cve/CVE-2020-14039.html https://bugzilla.suse.com/1168921 https://bugzilla.suse.com/1170264 https://bugzilla.suse.com/1177421 . SUSE has released a Security Update tackling vulnerabilities in terraform, providing critical fixes and improvements. Ensure your system remains secure and up-to-date by applying SUSE patches.. SUSE Security Update, Terraform Software Fix, Public Cloud Update. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for terraform ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0320-1 Rating: important References: #1158440 Cross-References: CVE-2019-19316 Affected Products: SUSE Linux Enterprise Module for Public Cloud 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for terraform to version 0.12.19 fixes the following issues: - CVE-2019-19316: Fixed an information leak where SAS token could be transfered in cleartext (bsc#1158440). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Public Cloud 15-SP1: zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP1-2020-320=1 Package List: - SUSE Linux Enterprise Module for Public Cloud 15-SP1 (aarch64 ppc64le s390x x86_64): terraform-0.12.19-3.6.1 References: https://www.suse.com/security/cve/CVE-2019-19316.html https://bugzilla.suse.com/1158440 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.