SLES

SLES 15 — libcfg6 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcfg6 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 3 March 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:7201 (see also SUSE bugzilla) Related CVEs: CVE-2025-30472 CVE-2026-35091 CVE-2026-35092 Upstream summary: Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in […]

Read more
SLES 16 — libexiv2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — libexiv2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:20923-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-26623 CVE-2021-29457 CVE-2023-44398 CVE-2025-54080 CVE-2025-55304 CVE-2026-25884 CVE-2026-27596 CVE-2026-27631  +12 more Upstream summary: Exiv2 is a C++ library and a command-line utility to read, write, delete […]

Read more
SLES 16 — rust — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — rust — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2439-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-12083 CVE-2020-1967 CVE-2018-1000622 Upstream summary: The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety […]

Read more
SLES 16 — stalld — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — stalld — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:20468-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-54159 Upstream summary: stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack. Table of contents […]

Read more
SLES 15 — libcap2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcap2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 March 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:12423 (see also SUSE bugzilla) Related CVEs: CVE-2026-4878 CVE-2023-2603 CVE-2023-2602 Upstream summary: A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` […]

Read more
SLES 16 — python313-waitress — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-waitress — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:496-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24761 CVE-2024-49768 CVE-2024-49769 CVE-2022-31015 Upstream summary: Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and […]

Read more
SLES 16 — permctl — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — permctl — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2020:110-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-3687 CVE-2019-3690 CVE-2020-8013 CVE-2022-31252 CVE-2019-3688 Upstream summary: The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" […]

Read more
SLES 15 — go1.23 — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.23 — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 March 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:13935 (see also SUSE bugzilla) Related CVEs: CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-0913 CVE-2025-4673 CVE-2025-22871 Upstream summary: The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly […]

Read more
SLES 16 — kea — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — kea — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:21038 (see also SUSE bugzilla) Related CVEs: CVE-2025-11232 CVE-2026-3608 CVE-2025-40779 CVE-2025-32801 CVE-2025-32802 CVE-2025-32803 Upstream summary: To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the […]

Read more
SLES 16 — npm24 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — npm24 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 1 March 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory RHSA-2026:7080 (see also SUSE bugzilla) Related CVEs: CVE-2026-21710 CVE-2026-21713 CVE-2026-21714 CVE-2026-21716 CVE-2026-21717 CVE-2026-21712 CVE-2025-59464 CVE-2026-21715 Upstream summary: A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is […]

Read more
CHAT