SLES

SLES 15 — sqlite3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — sqlite3 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:11802 (see also SUSE bugzilla) Related CVEs: CVE-2025-6965 CVE-2023-2137 CVE-2022-46908 CVE-2019-19603 CVE-2019-20218 CVE-2020-13435 CVE-2018-20346 CVE-2019-19880  +12 more Upstream summary: There exists a vulnerability in SQLite versions before 3.50.2 where the number of […]

Read more
SLES 16 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — freeradius-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1039-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-11235 CVE-2019-17185 CVE-2022-41860 CVE-2022-41861 CVE-2008-4474 CVE-2012-3547 CVE-2014-2015 CVE-2015-4680  +12 more Upstream summary: FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is […]

Read more
SLES 12 — npm14 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm14 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3447-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-44487 CVE-2023-30581 CVE-2022-25881 CVE-2023-23920 CVE-2023-38552 CVE-2023-32006 CVE-2023-32559 CVE-2023-32002  +3 more Upstream summary: The HTTP/2 protocol allows a denial of service (server resource consumption) because request […]

Read more
SLES 12 — uuidd — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — uuidd — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1106-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-28085 CVE-2014-9114 CVE-2016-2779 CVE-2017-2616 CVE-2018-7738 CVE-2026-3184 CVE-2025-14104 CVE-2021-37600  +3 more Upstream summary: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape […]

Read more
SLES 15 — libxslt1 — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libxslt1 — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:20892-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-11731 CVE-2024-55549 CVE-2025-24855 CVE-2021-30560 CVE-2019-18197 CVE-2023-40403 CVE-2016-4738 CVE-2017-5029  +5 more Upstream summary: A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT […]

Read more
SLES 16 — dom4j — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — dom4j — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1382-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-10683 CVE-2018-1000632 Upstream summary: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, […]

Read more
SLES 16 — chrony — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — chrony — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2014-0021 CVE-2012-4502 CVE-2012-4503 CVE-2020-14367 CVE-2016-1567 Upstream summary: Chrony before 1.29.1 has traffic amplification in cmdmon protocol Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — unrar — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:1975-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-33899 CVE-2022-30333 CVE-2017-12938 CVE-2017-12940 CVE-2017-12941 CVE-2017-12942 CVE-2017-20006 CVE-2012-6706 Upstream summary: RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen […]

Read more
SLES 15 — gpg2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — gpg2 — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:2719 (see also SUSE bugzilla) Related CVEs: CVE-2026-24882 CVE-2025-68973 CVE-2010-2547 CVE-2013-4402 CVE-2018-12020 CVE-2020-25125 CVE-2022-34903 CVE-2019-14855  +6 more Upstream summary: In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling […]

Read more
SLES 15 — busybox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — busybox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:0758-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-26157 CVE-2026-26158 CVE-2025-60876 CVE-2022-48174 CVE-2016-2147 CVE-2018-1000500 CVE-2018-1000517 CVE-2021-28831  +12 more Upstream summary: A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction […]

Read more
CHAT