SLES 12

SLES 12 — MozillaFirefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — MozillaFirefox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 14 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:19588 (see also SUSE bugzilla) Related CVEs: CVE-2026-7320 CVE-2026-7321 CVE-2026-7322 CVE-2026-7323 CVE-2026-6746 CVE-2026-6747 CVE-2026-6748 CVE-2026-6749  +12 more Upstream summary: Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability […]

Read more
SLES 12 — runc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — runc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:19927 (see also SUSE bugzilla) Related CVEs: CVE-2025-31133 CVE-2025-52565 CVE-2025-52881 CVE-2024-21626 CVE-2023-27561 CVE-2021-30465 CVE-2016-8867 CVE-2016-9962  +12 more Upstream summary: runc is a CLI tool for spawning and running containers according to the […]

Read more
SLES 12 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:11371 (see also SUSE bugzilla) Related CVEs: CVE-2026-1519 CVE-2025-40778 CVE-2024-11187 CVE-2024-1737 CVE-2024-1975 CVE-2023-4408 CVE-2023-50387 CVE-2023-50868  +12 more Upstream summary: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted […]

Read more
SLES 12 — libpoppler60 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpoppler60 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02788-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-50420 CVE-2025-52886 CVE-2025-32364 CVE-2025-32365 CVE-2024-56378 CVE-2025-11896 CVE-2025-3154 Upstream summary: An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite […]

Read more
SLES 12 — dovecot22 — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dovecot22 — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1641-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-27856 CVE-2025-59032 CVE-2026-27858 CVE-2020-12673 CVE-2020-12674 CVE-2020-24386 CVE-2017-14461 CVE-2019-11500  +11 more Upstream summary: Doveadm credentials are verified using direct comparison which is susceptible to timing oracle […]

Read more
SLES 12 — libgif6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgif6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1357-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11490 CVE-2026-23868 CVE-2025-31344 CVE-2023-39742 CVE-2022-28506 CVE-2015-7555 CVE-2016-3977 CVE-2021-40633 Upstream summary: The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c […]

Read more
SLES 12 — munge — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — munge — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:2918 (see also SUSE bugzilla) Related CVEs: CVE-2026-25506 CVE-2019-3691 Upstream summary: MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer […]

Read more
SLES 12 — freeipmi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — freeipmi — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:13515 (see also SUSE bugzilla) Related CVEs: CVE-2026-33554 Upstream summary: ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set […]

Read more
SLES 12 — libcairo2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libcairo2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2016:1100-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-3190 CVE-2016-9082 CVE-2017-7475 CVE-2017-9814 CVE-2019-6461 CVE-2025-50422 CVE-2019-6462 Upstream summary: The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial […]

Read more
SLES 12 — libfreebl3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libfreebl3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 3 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:385-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 CVE-2020-6829 CVE-2026-2781 CVE-2025-9187 CVE-2023-0767 CVE-2022-31741  +12 more Upstream summary: When converting coordinates from projective to affine, the modular inversion was not performed […]

Read more
CHAT