SLES

SLES 15 — openvpn — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — openvpn — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 2 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-46850 CVE-2025-13086 CVE-2022-0547 CVE-2017-7521 CVE-2017-7522 CVE-2025-2704 CVE-2024-5594 CVE-2024-28882  +7 more Upstream summary: Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined […]

Read more
SLES 15 — python311-pytest — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-pytest — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1744-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-71176 Upstream summary: pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of […]

Read more
SLES 15 — libsodium23 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libsodium23 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0368-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-69277 CVE-2025-15444 Upstream summary: libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an […]

Read more
SLES 15 — apache2-mod_security2 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache2-mod_security2 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:8837 (see also SUSE bugzilla) Related CVEs: CVE-2025-47947 CVE-2025-48866 CVE-2023-24021 CVE-2022-48279 CVE-2025-54571 CVE-2009-5031 CVE-2012-4528 CVE-2013-1915  +2 more Upstream summary: ModSecurity is an open source, cross platform web application firewall (WAF) engine for […]

Read more
SLES 15 — ftdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ftdump — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory ESSA-2025:2834 (see also SUSE bugzilla) Related CVEs: CVE-2025-27363 CVE-2020-15999 CVE-2023-2004 CVE-2022-27404 CVE-2022-27405 CVE-2022-27406 CVE-2014-2240 CVE-2014-9656  +12 more Upstream summary: An out of bounds write exists in FreeType versions 2.13.0 and below (newer […]

Read more
SLES 15 — libcryptopp5_6_5 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcryptopp5_6_5 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:01816-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28285 CVE-2016-9939 CVE-2015-2141 Upstream summary: A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in […]

Read more
SLES 12 — gnome-shell — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gnome-shell — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9114 (see also SUSE bugzilla) Related CVEs: CVE-2024-36472 CVE-2010-4000 CVE-2017-8288 CVE-2019-3820 Upstream summary: In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses […]

Read more
SLES 12 — grub2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — grub2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 March 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory ESSA-2025:2835 (see also SUSE bugzilla) Related CVEs: CVE-2024-56737 CVE-2025-0624 CVE-2023-4692 CVE-2021-3695 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28736  +12 more Upstream summary: GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c […]

Read more
SLES 15 — containerd — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — containerd — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:21042-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-25621 CVE-2025-64329 CVE-2024-40635 CVE-2023-25153 CVE-2022-23471 Upstream summary: containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 […]

Read more
SLES 15 — python3-docker — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-docker — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 March 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:0012 (see also SUSE bugzilla) Related CVEs: CVE-2024-35195 Upstream summary: Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with […]

Read more
CHAT