SLES

SLES 16 — python313-Pygments — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-Pygments — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:1500-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-20270 CVE-2021-27291 Upstream summary: An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting […]

Read more
SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgc1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-2673 CVE-2016-9427 Upstream summary: Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in […]

Read more
SLES 16 — python313-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-setuptools — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:6309 (see also SUSE bugzilla) Related CVEs: CVE-2024-6345 Upstream summary: A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These […]

Read more
SLES 12 — libplist1 — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libplist1 — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:1368-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-5209 CVE-2017-5834 CVE-2017-6440 CVE-2017-7982 CVE-2017-5545 CVE-2017-5835 CVE-2017-5836 Upstream summary: The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information […]

Read more
SLES 16 — shim — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — shim — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2023:219-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-28737 CVE-2023-40547 CVE-2024-2312 CVE-2014-3675 CVE-2014-3676 CVE-2014-3677 CVE-2023-40546 CVE-2023-40548  +3 more Upstream summary: There's a possible overflow in handle_image() when shim tries to load and execute […]

Read more
SLES 12 — libudf0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libudf0 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:0673-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-18201 CVE-2017-18199 Upstream summary: An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c. Table of contents […]

Read more
SLES 12 — libwpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libwpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:2931-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-14226 CVE-2018-19208 Upstream summary: WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer […]

Read more
SLES 12 — libFLAC8 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libFLAC8 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0814-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-0561 CVE-2020-0499 CVE-2014-8962 CVE-2014-9028 Upstream summary: In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This […]

Read more
SLES 16 — libheif1 — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — libheif1 — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-0996 CVE-2024-41311 CVE-2025-68431 CVE-2020-23109 CVE-2023-29659 CVE-2023-49460 CVE-2023-49462 CVE-2023-49463  +1 more Upstream summary: There is a vulnerability in the strided image data parsing code in the […]

Read more
SLES 16 — liblouis20 — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — liblouis20 — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2184-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-26981 CVE-2023-26767 CVE-2023-26768 CVE-2023-26769 CVE-2017-13738 CVE-2017-13739 CVE-2017-13740 CVE-2017-13741  +10 more Upstream summary: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, […]

Read more
CHAT