SLES 15

SLES 15 — jetty-io — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jetty-io — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1751-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-2332 CVE-2026-5795 CVE-2025-5115 CVE-2024-13009 CVE-2024-22201 CVE-2023-36478 CVE-2022-2048 CVE-2021-28165  +12 more Upstream summary: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk […]

Read more
SLES 15 — log4j — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — log4j — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 24 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory BLOG-LOG4SHELL (see also SUSE bugzilla) Related CVEs: CVE-2021-44228 CVE-2019-17571 CVE-2022-23305 CVE-2022-23307 CVE-2021-45105 CVE-2021-45046 CVE-2026-34477 CVE-2026-34479  +7 more Upstream summary: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI […]

Read more
SLES 15 — Mesa — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — Mesa — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1343-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-40393 CVE-2023-45913 CVE-2023-45919 CVE-2023-45922 CVE-2019-5068 Upstream summary: In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount […]

Read more
SLES 15 — libgif7 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libgif7 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8117 (see also SUSE bugzilla) Related CVEs: CVE-2023-48161 CVE-2018-11490 CVE-2026-23868 CVE-2025-31344 CVE-2019-15133 CVE-2022-28506 CVE-2015-7555 CVE-2016-3977  +1 more Upstream summary: Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to […]

Read more
SLES 15 — python3-pyasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-pyasn1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:12176 (see also SUSE bugzilla) Related CVEs: CVE-2026-30922 CVE-2026-23490 Upstream summary: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service […]

Read more
SLES 15 — perl-Crypt-URandom — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-Crypt-URandom — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1170-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-2474 Upstream summary: Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function […]

Read more
SLES 15 — python2-Jinja2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-Jinja2 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0308 (see also SUSE bugzilla) Related CVEs: CVE-2024-56326 CVE-2016-10745 CVE-2019-10906 CVE-2019-8341 CVE-2020-28493 CVE-2025-27516 CVE-2014-0012 Upstream summary: Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed […]

Read more
SLES 15 — yelp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — yelp — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:7430 (see also SUSE bugzilla) Related CVEs: CVE-2025-3155 Upstream summary: A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows […]

Read more
SLES 15 — npm24 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — npm24 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:7350 (see also SUSE bugzilla) Related CVEs: CVE-2026-21712 CVE-2025-59464 Upstream summary: A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized […]

Read more
SLES 15 — php-composer2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — php-composer2 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1784-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-40176 CVE-2026-40261 CVE-2024-35241 CVE-2024-35242 CVE-2024-24821 CVE-2022-24828 CVE-2023-43655 CVE-2025-67746 Upstream summary: Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 […]

Read more
CHAT