SLES

SLES 15 — perl-Cpanel-JSON-XS — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — perl-Cpanel-JSON-XS — vulnerability — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 18 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03193-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-40929 Upstream summary: Cpanel::JSON::XS before version 4.40 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or […]

Read more
SLES 15 — libvpx4 — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libvpx4 — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2408-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-6349 CVE-2024-5197 CVE-2023-5217 CVE-2019-2126 CVE-2016-1621 CVE-2016-2464 CVE-2017-0641 CVE-2017-13194  +5 more Upstream summary: A heap overflow vulnerability exists in libvpx – Encoding a frame that has […]

Read more
SLES 15 — apptainer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apptainer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 10 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0439-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-65105 CVE-2025-8556 Upstream summary: Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of the forms […]

Read more
SLES 15 — build — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — build — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4212-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-22038 CVE-2010-4226 CVE-2017-14804 Upstream summary: Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service. […]

Read more
SLES 15 — apache2-mod_jk — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache2-mod_jk — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:3963-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11759 CVE-2023-41081 CVE-2024-46544 CVE-2008-5519 CVE-2014-8111 CVE-2018-1323 Upstream summary: The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the […]

Read more
SLES 15 — supportutils-plugin-salt — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — supportutils-plugin-salt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:4008-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-22037 Upstream summary: The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment […]

Read more
SLES 15 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liblasso3 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 8 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:21452 (see also SUSE bugzilla) Related CVEs: CVE-2025-47151 CVE-2025-46784 CVE-2025-46404 CVE-2025-46705 CVE-2021-28091 Upstream summary: A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted […]

Read more
SLES 12 — net-snmp — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — net-snmp — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 February 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:0668 (see also SUSE bugzilla) Related CVEs: CVE-2025-68615 CVE-2020-15862 CVE-2015-5621 CVE-2018-18065 CVE-2022-44792 CVE-2022-44793 CVE-2022-24805 CVE-2022-24806  +8 more Upstream summary: net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 […]

Read more
SLES 12 — libxml2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libxml2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 February 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:12447 (see also SUSE bugzilla) Related CVEs: CVE-2025-7425 CVE-2025-49794 CVE-2025-49796 CVE-2025-6021 CVE-2024-56171 CVE-2022-49043 CVE-2024-25062 CVE-2022-40303  +12 more Upstream summary: A flaw was found in libxslt where the attribute type, atype, flags are […]

Read more
SLES 15 — python311-pycares — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-pycares — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 February 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03354-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-48945 Upstream summary: pycares is a Python module which provides an interface to c-ares. c-ares is a C library that performs DNS requests and name […]

Read more
CHAT