openSUSE Leap 15.5

openSUSE Leap 15.5 — cosign — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — cosign — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1486-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-29902 CVE-2024-29903 CVE-2023-46737 Upstream summary: Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a […]

Read more
openSUSE Leap 15.5 — helm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — helm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:4213-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-25620 CVE-2024-26147 CVE-2023-25173 Upstream summary: Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client […]

Read more
openSUSE Leap 15.5 — shadow — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — shadow — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2603-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4235 CVE-2023-4641 Upstream summary: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees Table of contents Symptom & Impact Environment & […]

Read more
openSUSE Leap 15.5 — rekor — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — rekor — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2515-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33199 Upstream summary: Rekor's goals are to provide an immutable tamper resistant ledger of metadata generated within a software projects supply chain. A malformed […]

Read more
openSUSE Leap 15.5 — keylime-agent — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — keylime-agent — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3525-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-38201 CVE-2023-38200 Upstream summary: A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. […]

Read more
openSUSE Leap 15.5 — minidlna — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — minidlna — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:0093-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33476 Upstream summary: ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic […]

Read more
openSUSE Leap 15.5 — libQt5Gui5 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — libQt5Gui5 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:4647 (see also SUSE bugzilla) Related CVEs: CVE-2024-39936 CVE-2023-24607 CVE-2023-32763 CVE-2023-45935 CVE-2023-51714 CVE-2023-37369 CVE-2023-32762 CVE-2023-33285  +2 more Upstream summary: An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before […]

Read more
openSUSE Leap 15.5 — lxc — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — lxc — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:0342-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-47952 Upstream summary: lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even […]

Read more
openSUSE Leap 15.5 — nghttp2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — nghttp2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1156-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28182 CVE-2023-35945 Upstream summary: nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 […]

Read more
openSUSE Leap 15.5 — rpm — vulnerability — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — rpm — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1557-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3521 Upstream summary: There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM […]

Read more
CHAT