SLES

SLES 16 — libutf8_range — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — libutf8_range — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 June 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02309-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-4565 CVE-2026-0994 Upstream summary: Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive […]

Read more
SLES 12 — tiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 June 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:12265 (see also SUSE bugzilla) Related CVEs: CVE-2026-4775 CVE-2025-9900 CVE-2025-8176 CVE-2023-26965 CVE-2022-48281 CVE-2022-3970 CVE-2022-2519 CVE-2022-2521  +12 more Upstream summary: A flaw was found in the libtiff library. A remote attacker could exploit […]

Read more
SLES 15 — netty — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — netty — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 June 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1353-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-33870 CVE-2025-55163 CVE-2025-58056 CVE-2025-24970 CVE-2024-29025 CVE-2023-44487 CVE-2022-41881 CVE-2022-41915  +12 more Upstream summary: Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final […]

Read more
SLES 16 — apache2-mod_auth_openidc — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — apache2-mod_auth_openidc — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 June 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9180 (see also SUSE bugzilla) Related CVEs: CVE-2024-24814 CVE-2025-31492 CVE-2019-14857 CVE-2021-32785 CVE-2021-32786 CVE-2022-23527 Upstream summary: mod_auth_openidc is an OpenID Certified(tm) authentication and authorization module for the Apache 2.x HTTP server that implements […]

Read more
SLES 16 — pkexec — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — pkexec — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 June 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:1842-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3560 CVE-2021-4034 CVE-2010-0750 CVE-2011-1485 CVE-2015-3255 CVE-2015-3256 CVE-2018-19788 CVE-2019-6133  +5 more Upstream summary: It was found that polkit could be tricked into bypassing the credential checks […]

Read more
SLES 16 — python313-pywbem — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-pywbem — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 June 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2014:0580-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-6418 Upstream summary: PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an […]

Read more
SLES 16 — libzip5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — libzip5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 June 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1162 CVE-2012-1163 CVE-2017-12858 CVE-2017-14107 Upstream summary: Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial […]

Read more
SLES 12 — mariadb — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — mariadb — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 June 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:0111 (see also SUSE bugzilla) Related CVEs: CVE-2025-13699 CVE-2014-0224 CVE-2019-2529 CVE-2020-2574 CVE-2021-2180 CVE-2010-5298 CVE-2014-0195 CVE-2014-0198  +12 more Upstream summary: MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote […]

Read more
SLES 15 — tar — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tar — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 June 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:0002 (see also SUSE bugzilla) Related CVEs: CVE-2025-45582 CVE-2022-48303 CVE-2010-0624 CVE-2016-6321 CVE-2021-20193 CVE-2023-39804 CVE-2018-20482 CVE-2019-9923 Upstream summary: GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with […]

Read more
CHAT