SLES

SLES 15 — libndp0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libndp0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2283-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-5564 CVE-2016-3698 Upstream summary: A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered […]

Read more
SLES 15 — uwsgi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — uwsgi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9306 (see also SUSE bugzilla) Related CVEs: CVE-2024-24795 Upstream summary: HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications […]

Read more
SLES 12 — krb5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — krb5 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 29 April 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2010:006 (see also SUSE bugzilla) Related CVEs: CVE-2009-4212 CVE-2024-37370 CVE-2024-26458 CVE-2023-36054 CVE-2020-28196 CVE-2002-2443 CVE-2009-0846 CVE-2009-0847  +12 more Upstream summary: Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in […]

Read more
SLES 12 — libvte — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvte — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 April 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2151-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-37535 Upstream summary: GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape sequence, a […]

Read more
SLES 12 — pdsh — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pdsh — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 26 April 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0960-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-6438 CVE-2016-10030 CVE-2020-27745 CVE-2022-29500 CVE-2022-29501 CVE-2022-29502 CVE-2024-48936 CVE-2017-15566  +10 more Upstream summary: SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. Table of […]

Read more
SLES 12 — libjasper1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libjasper1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 April 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1396-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-31744 CVE-2020-27828 CVE-2015-5203 CVE-2015-5221 CVE-2016-1577 CVE-2016-8654 CVE-2016-9262 CVE-2016-9560  +12 more Upstream summary: In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnerability, […]

Read more
SLES 15 — wget — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — wget — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2871-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-13089 CVE-2017-13090 CVE-2019-5953 CVE-2021-31879 CVE-2024-10524 CVE-2024-38428 CVE-2010-2252 CVE-2014-4877  +5 more Upstream summary: The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. […]

Read more
SLES 15 — python3-eventlet — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-eventlet — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03051-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-58068 Upstream summary: Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling […]

Read more
SLES 12 — google-osconfig-agent — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — google-osconfig-agent — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 April 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01985-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-45339 Upstream summary: When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and […]

Read more
SLES 15 — podman — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — podman — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:15900 (see also SUSE bugzilla) Related CVEs: CVE-2025-9566 CVE-2025-6032 CVE-2024-11218 CVE-2022-1227 CVE-2022-21698 CVE-2025-47914 CVE-2024-9676 CVE-2024-9675  +7 more Upstream summary: There's a vulnerability in podman where an attacker may use the kube play […]

Read more
CHAT