SLES 15

SLES 15 — libsaml11 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libsaml11 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01500-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-31335 Upstream summary: The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on […]

Read more
SLES 15 — libupb37 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libupb37 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0573-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-4785 CVE-2024-11407 CVE-2024-7246 CVE-2023-32732 Upstream summary: Lack of error handling in the TCP server in Google's gRPC starting version 1.23 on posix-compatible platforms (ex. Linux) […]

Read more
SLES 15 — python3-Twisted — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-Twisted — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2732-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-41671 CVE-2022-21716 CVE-2020-10109 CVE-2022-21712 CVE-2024-41810 CVE-2023-46137 CVE-2022-24801 CVE-2019-12387  +2 more Upstream summary: Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP […]

Read more
SLES 15 — ucode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ucode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03052-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-20053 CVE-2025-20109 CVE-2025-22839 CVE-2025-22840 CVE-2025-22889 CVE-2025-26403 CVE-2025-32086 CVE-2024-21820  +12 more Upstream summary: Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may […]

Read more
SLES 15 — python311-pydantic — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-pydantic — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2021-29510 CVE-2024-3772 Upstream summary: Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` […]

Read more
SLES 15 — libnvidia-container1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libnvidia-container1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3950-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-0132 CVE-2024-0133 Upstream summary: NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted […]

Read more
SLES 15 — keepalived — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — keepalived — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2086-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-44225 CVE-2018-19044 CVE-2018-19045 CVE-2018-19046 CVE-2024-41184 Upstream summary: In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to […]

Read more
SLES 15 — tuned — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tuned — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10384 (see also SUSE bugzilla) Related CVEs: CVE-2024-52336 CVE-2024-52337 Upstream summary: A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users […]

Read more
SLES 15 — python311-aiohttp — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-aiohttp — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3110-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42367 CVE-2023-47627 CVE-2024-23334 CVE-2024-23829 CVE-2023-49082 Upstream summary: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior […]

Read more
SLES 15 — sbt — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — sbt — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0726-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-25710 CVE-2024-26308 CVE-2023-46122 Upstream summary: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through […]

Read more
CHAT