SLES

SLES 15 — libcjson1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcjson1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:03520-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-57052 CVE-2023-26819 Upstream summary: cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers to bypass array bounds checking […]

Read more
SLES 15 — kernel-default-extra — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kernel-default-extra — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:12746 (see also SUSE bugzilla) Related CVEs: CVE-2025-22020 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove This fixes the following crash: ================================================================== […]

Read more
SLES 15 — liboqs7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — liboqs7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:0005-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-37305 CVE-2024-54137 CVE-2024-36405 Upstream summary: oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and […]

Read more
SLES 12 — tomcat — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tomcat — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:4075-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-52316 CVE-2018-8037 CVE-2026-29146 CVE-2026-32990 CVE-2026-34486 CVE-2023-45468 CVE-2025-48989 CVE-2025-66614  +12 more Upstream summary: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use […]

Read more
SLES 12 — libsndfile1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsndfile1 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:14769-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3246 CVE-2025-52194 CVE-2026-37555 CVE-2022-33065 CVE-2018-13139 CVE-2021-4156 CVE-2009-0186 CVE-2011-2696  +12 more Upstream summary: A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to […]

Read more
SLES 12 — atftp — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — atftp — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:1091-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-11365 CVE-2021-41054 CVE-2019-11366 CVE-2021-46671 Upstream summary: An issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a […]

Read more
SLES 12 — dnsmasq — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dnsmasq — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1826-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-2291 CVE-2020-25681 CVE-2020-25682 CVE-2020-25683 CVE-2020-25684 CVE-2020-25685 CVE-2020-25686 CVE-2020-25687  +12 more Upstream summary: dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing […]

Read more
SLES 12 — amazon-ssm-agent — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — amazon-ssm-agent — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:0436 (see also SUSE bugzilla) Related CVEs: CVE-2025-47913 CVE-2025-21613 CVE-2022-29527 CVE-2025-22870 Upstream summary: SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process. […]

Read more
SLES 12 — libicu-doc — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libicu-doc — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:11888 (see also SUSE bugzilla) Related CVEs: CVE-2025-5222 Upstream summary: A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed […]

Read more
SLES 12 — docker-distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — docker-distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory GHSA-hqxw-f8mx-cpmw (see also SUSE bugzilla) Related CVEs: CVE-2023-2253 CVE-2017-11468 Upstream summary: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records […]

Read more
CHAT