An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for uriparser ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20910-1 Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for uriparser fixes the following issue: - CVE-2025-67899: unbounded recursion and stack consumption (bsc#1255000). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-895=1 Package List: - openSUSE Leap 16.0: liburiparser1-0.9.8-160000.4.1 uriparser-0.9.8-160000.4.1 uriparser-devel-0.9.8-160000.4.1 uriparser-doc-0.9.8-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2025-67899.html . Update available for openSUSE addressing moderate security issue in uriparser related to stack consumption.. openSUSE, uriparser, unbounded recursion, security update. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for uriparser Announcement ID: SUSE-SU-2026:0444-1 Release Date: 2026-02-11T09:59:48Z Rating: moderate References: * bsc#1255000 Cross-References: * CVE-2025-67899 CVSS scores: * CVE-2025-67899 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67899 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-67899 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for uriparser fixes the following issues: * CVE-2025-67899: large input containing many commas can cause unbounded recursion and stack consumption (bsc#1255000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-444=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-444=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * uriparser-0.8.5-150000.3.11.1 * uriparser-debuginfo-0.8.5-150000.3.11.1 * uriparser-devel-0.8.5-150000.3.11.1 * liburiparser1-debuginfo-0.8.5-150000.3.11.1 * uriparser-debugsource-0.8.5-150000.3.11.1 * liburiparser1-0.8.5-150000.3.11.1 * openSUSE Leap 15.6 (x86_64) * liburiparser1-32bit-debuginfo-0.8.5-150000.3.11.1 * liburiparser1-32bit-0.8.5-150000.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-67899.html * https://bugzilla.suse.com/show_bug.cgi?id=1255000 . Discover the moderate security update for uriparser addressing CVE-2025-67899 affecting SUSE systems.. uriparser update,SUSE security,unbounded recursion,CVE-2025-67899. . LinuxSecurity.com Team
Update to uriparser-1.0.0, fixes CVE-2025-67899.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-bf69e91bda 2025-12-21 00:50:40.670508+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 42 Version : 1.0.0 Release : 1.fc42 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.0, fixes CVE-2025-67899. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 15 2025 Sandro Mani - 1.0.0-1 - Update to 1.0.0 * Thu Sep 4 2025 Sandro Mani - 0.9.9-1 - Update to 0.9.9 * Fri Jul 25 2025 Fedora Release Engineering - 0.9.8-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423026 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423026 [ 2 ] Bug #2423027 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-bf69e91bda' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packagesare signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to uriparser-1.0.0, fixes CVE-2025-67899.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5c12420f33 2025-12-20 00:52:30.902724+00:00 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 43 Version : 1.0.0 Release : 1.fc43 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-1.0.0, fixes CVE-2025-67899. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 15 2025 Sandro Mani - 1.0.0-1 - Update to 1.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2423026 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2423026 [ 2 ] Bug #2423027 - CVE-2025-67899 uriparser: uriparser: Unbounded recursion and stack consumption via large input [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2423027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5c12420f33' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1231264 * bsc#1231265 Cross-References: * CVE-2024-31228 . # Security update for redis Announcement ID: SUSE-SU-2024:3575-1 Release Date: 2024-10-09T16:55:37Z Rating: important References: * bsc#1231264 * bsc#1231265 Cross-References: * CVE-2024-31228 * CVE-2024-31449 CVSS scores: * CVE-2024-31228 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-31228 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-31449 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-31449 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for redis fixes the following issues: * CVE-2024-31228: Fixed unbounded recursive pattern matching (bsc#1231265) * CVE-2024-31449: Fixed integer overflow bug in Lua bit_tohex (bsc#1231264) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-3575=1 * openSUSE Leap 15.4 zypper in -t patchSUSE-2024-3575=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3575=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-3575=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-3575=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-3575=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-3575=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-3575=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-3575=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-3575=1 ## Package List: * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Manager Proxy 4.3 (x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * redis-debugsource-6.2.6-150400.3.28.1 * redis-debuginfo-6.2.6-150400.3.28.1 * redis-6.2.6-150400.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2024-31228.html * https://www.suse.com/security/cve/CVE-2024-31449.html * https://bugzilla.suse.com/show_bug.cgi?id=1231264 * https://bugzilla.suse.com/show_bug.cgi?id=1231265 . Canonical reveals critical updates addressing vulnerabilities in MongoDB, providing patch guidelines and listing impacted software.. SUSE redis update, Redis security advisory, Redis vulnerabilities fix. . Severity: Important. LinuxSecurity.com Team
. SUSE Container Update Advisory: suse/sles12sp5 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2020:687-1 Container Tags : suse/sles12sp5:6.5.95 , suse/sles12sp5:latest Container Release : 6.5.95 Severity : moderate Type : security References : 1178512 CVE-2020-28196 ----------------------------------------------------------------- The container suse/sles12sp5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:3379-1 Released: Thu Nov 19 09:30:16 2020 Summary: Security update for krb5 Type: security Severity: moderate References: 1178512,CVE-2020-28196 This update for krb5 fixes the following security issue: - CVE-2020-28196: Fixed an unbounded recursion via an ASN.1-encoded Kerberos message (bsc#1178512). . SUSE Container Update Notice for suse/sles12sp5 tackles a medium security vulnerability in krb5 involving unrestrained recursion.. SUSE Container Update, suse/sles12sp5 Advisory, security update, krb5 update, moderate severity. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for krb5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3377-1 Rating: moderate References: #1178512 Cross-References: CVE-2020-28196 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP2 SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for krb5 fixes the following security issue: - CVE-2020-28196: Fixed an unbounded recursion via an ASN.1-encoded Kerberos message (bsc#1178512). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP2-2020-3377=1 - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-3377=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-3377=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-3377=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP2 (aarch64 ppc64le s390x x86_64): krb5-debuginfo-1.16.3-3.15.1 krb5-debugsource-1.16.3-3.15.1 krb5-plugin-kdb-ldap-1.16.3-3.15.1 krb5-plugin-kdb-ldap-debuginfo-1.16.3-3.15.1 krb5-server-1.16.3-3.15.1 krb5-server-debuginfo-1.16.3-3.15.1 - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64): krb5-debuginfo-1.16.3-3.15.1 krb5-debugsource-1.16.3-3.15.1 krb5-plugin-kdb-ldap-1.16.3-3.15.1 krb5-plugin-kdb-ldap-debuginfo-1.16.3-3.15.1 krb5-server-1.16.3-3.15.1 krb5-server-debuginfo-1.16.3-3.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): krb5-1.16.3-3.15.1 krb5-client-1.16.3-3.15.1 krb5-client-debuginfo-1.16.3-3.15.1 krb5-debuginfo-1.16.3-3.15.1 krb5-debugsource-1.16.3-3.15.1 krb5-devel-1.16.3-3.15.1 krb5-plugin-preauth-otp-1.16.3-3.15.1 krb5-plugin-preauth-otp-debuginfo-1.16.3-3.15.1 krb5-plugin-preauth-pkinit-1.16.3-3.15.1 krb5-plugin-preauth-pkinit-debuginfo-1.16.3-3.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (x86_64): krb5-32bit-1.16.3-3.15.1 krb5-32bit-debuginfo-1.16.3-3.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): krb5-1.16.3-3.15.1 krb5-client-1.16.3-3.15.1 krb5-client-debuginfo-1.16.3-3.15.1 krb5-debuginfo-1.16.3-3.15.1 krb5-debugsource-1.16.3-3.15.1 krb5-devel-1.16.3-3.15.1 krb5-plugin-preauth-otp-1.16.3-3.15.1 krb5-plugin-preauth-otp-debuginfo-1.16.3-3.15.1 krb5-plugin-preauth-pkinit-1.16.3-3.15.1 krb5-plugin-preauth-pkinit-debuginfo-1.16.3-3.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64): krb5-32bit-1.16.3-3.15.1 krb5-32bit-debuginfo-1.16.3-3.15.1 References: https://www.suse.com/security/cve/CVE-2020-28196.html https://bugzilla.suse.com/1178512 . SUSE Security Patch for krb5 resolves a medium risk vulnerability related to unchecked recursion in Kerberos communications.. SUSE Linux, krb5 security, server applications, software update, security vulnerability. . LinuxSecurity.com Team
Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-3098-2 October 11, 2016 linux-lts-trusty vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux-lts-trusty: Linux hardware enablement kernel from Trusty for Precise Details: USN-3098-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu 12.04 LTS. Vladimír Beneš discovered an unbounded recursion in the VLAN and TEB Generic Receive Offload (GRO) processing implementations in the Linux kernel, A remote attacker could use this to cause a stack corruption, leading to a denial of service (system crash). (CVE-2016-7039) Marco Grassi discovered a use-after-free condition could occur in the TCP retransmit queue handling code in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2016-6828) Pengfei Wang discovered a race condition in the audit subsystem in the Linux kernel. A local attacker could use this to corrupt audit logs or disrupt system-call auditing. (CVE-2016-6136) Pengfei Wang discovered a race condition in the Adaptec AAC RAID controller driver in the Linux kernel when handling ioctl()s. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-6480) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: linux-image-3.13.0-98-generic 3.13.0-98.145~precise1 linux-image-3.13.0-98-generic-lpae 3.13.0-98.145~precise1 After a standard system update you need toreboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: CVE-2016-6136, CVE-2016-6480, CVE-2016-6828, CVE-2016-7039 Package Information: https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-98.145~precise1 . Ubuntu Security Alert USN-3098-2 provides updates for the Trusty HWE kernel, rectifying a range of significant vulnerabilities.. Kernel Security, Trusty HWE Update, Ubuntu Security Notices. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.