SLES

SLES 15 — tuned — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tuned — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10384 (see also SUSE bugzilla) Related CVEs: CVE-2024-52336 CVE-2024-52337 Upstream summary: A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users […]

Read more
SLES 12 — kernel-docs — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kernel-docs — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 6 January 2025 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SA:2011:019 (see also SUSE bugzilla) Related CVEs: CVE-2011-1180 CVE-2024-26923 CVE-2022-2991 CVE-2018-25020 CVE-2016-3135 CVE-2016-6187 CVE-2016-7039 CVE-2016-8636  +12 more Upstream summary: Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux […]

Read more
SLES 15 — python311-aiohttp — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-aiohttp — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3110-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42367 CVE-2023-47627 CVE-2024-23334 CVE-2024-23829 CVE-2023-49082 Upstream summary: aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior […]

Read more
SLES 15 — sbt — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — sbt — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0726-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-25710 CVE-2024-26308 CVE-2023-46122 Upstream summary: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through […]

Read more
SLES 15 — docker-stable — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — docker-stable — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 5–30 min  Last verified: 2 January 2025 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0226-1 Related CVEs: CVE-2024-2365 Upstream summary: A vulnerability classified as problematic was found in Musicshelf 1.0/1.1 on Android. Affected by this vulnerability is an unknown functionality of the file io\fabric\sdk\android\services\network\PinningTrustManager.java of the […]

Read more
SLES 12 — go1.22 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — go1.22 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 December 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:6908 (see also SUSE bugzilla) Related CVEs: CVE-2024-34155 CVE-2024-34156 CVE-2024-34158 CVE-2024-24788 Upstream summary: Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic […]

Read more
SLES 12 — netatalk — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — netatalk — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 30 December 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0316-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-43634 CVE-2021-31439 CVE-2022-23121 CVE-2022-23125 CVE-2024-38439 CVE-2024-38440 CVE-2024-38441 CVE-2022-22995  +3 more Upstream summary: This vulnerability allows remote attackers to execute arbitrary code on affected installations of […]

Read more
SLES 15 — npm12 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — npm12 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1301-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-27983 CVE-2024-22019 CVE-2023-30581 CVE-2021-37701 CVE-2021-37712 CVE-2021-37713 CVE-2021-39134 CVE-2021-39135  +12 more Upstream summary: An attacker can make the Node.js HTTP/2 server completely unavailable by sending a […]

Read more
SLES 15 — gnome-shell — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gnome-shell — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9114 (see also SUSE bugzilla) Related CVEs: CVE-2024-36472 CVE-2023-43090 CVE-2010-4000 CVE-2017-8288 CVE-2019-3820 CVE-2020-17489 Upstream summary: In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on […]

Read more
SLES 15 — apache-commons-configuration — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — apache-commons-configuration — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 December 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1365-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-29131 CVE-2024-29133 Upstream summary: Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade […]

Read more
CHAT