SLES 15

SLES 15 — libheif1 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libheif1 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3960-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-41311 CVE-2023-0996 CVE-2025-68431 CVE-2023-49460 CVE-2023-49462 CVE-2023-49463 CVE-2023-49464 CVE-2020-23109  +2 more Upstream summary: In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an […]

Read more
SLES 15 — libxslt1 — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libxslt1 — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:20892-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-11731 CVE-2024-55549 CVE-2025-24855 CVE-2021-30560 CVE-2019-18197 CVE-2023-40403 CVE-2016-4738 CVE-2017-5029  +5 more Upstream summary: A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT […]

Read more
SLES 15 — valkey — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — valkey — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1949-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-23631 CVE-2026-25243 CVE-2026-23479 CVE-2025-67733 CVE-2026-21863 CVE-2025-49112 Upstream summary: Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated […]

Read more
SLES 15 — pipewire — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pipewire — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02339-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-6427 CVE-2025-6428 CVE-2025-6431 CVE-2025-6432 CVE-2025-6433 CVE-2025-6434 CVE-2025-6435 CVE-2025-6436  +12 more Upstream summary: An attacker was able to bypass the `connect-src` directive of a Content Security […]

Read more
SLES 15 — wicked2nm — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — wicked2nm — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02957-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-55159 Upstream summary: slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within […]

Read more
SLES 15 — postgresql-jdbc — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — postgresql-jdbc — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 17 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0769-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-1597 CVE-2026-42198 CVE-2022-31197 CVE-2022-41946 Upstream summary: pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. […]

Read more
SLES 15 — python3-ecdsa — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-ecdsa — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1436-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-33936 Upstream summary: The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature […]

Read more
SLES 15 — haveged — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — haveged — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:2008-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-41054 Upstream summary: In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting […]

Read more
SLES 15 — rsync — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rsync — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 15 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0118-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-12084 CVE-2026-29518 CVE-2026-41035 CVE-2026-43618 CVE-2024-12087 CVE-2022-29154 CVE-2020-14387 CVE-2026-43617  +12 more Upstream summary: A heap-based buffer overflow flaw was found in the rsync daemon. This issue […]

Read more
SLES 15 — pam_u2f — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — pam_u2f — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0167-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-23013 CVE-2021-31924 CVE-2019-12209 CVE-2019-12210 CVE-2019-9578 Upstream summary: In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module […]

Read more
CHAT