SLES

SLES 15 — rhino — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rhino — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:4390-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-66453 Upstream summary: Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an […]

Read more
SLES 15 — php8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — php8 — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 8 February 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1957-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-14179 CVE-2026-6722 CVE-2026-7258 CVE-2026-7261 CVE-2026-7568 CVE-2026-7259 CVE-2024-11236 CVE-2024-8932  +4 more Upstream summary: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and […]

Read more
SLES 16 — libfastjson4 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — libfastjson4 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:108-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-12762 Upstream summary: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. Table of contents […]

Read more
SLES 12 — libgif6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgif6 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 February 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1357-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-11490 CVE-2026-23868 CVE-2025-31344 CVE-2023-39742 CVE-2022-28506 CVE-2015-7555 CVE-2016-3977 CVE-2021-40633 Upstream summary: The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c […]

Read more
SLES 15 — librsvg — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — librsvg — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 February 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-FU-2026:20990-1 (see also SUSE bugzilla) Related CVEs: CVE-2026-25727 CVE-2023-38633 CVE-2021-25900 CVE-2024-43806 CVE-2011-3146 CVE-2013-1881 CVE-2019-20446 CVE-2017-11464 Upstream summary: time provides date and time handling in Rust. From 0.3.6 to before 0.3.47, when user-provided […]

Read more
SLES 16 — go — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — go — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 7 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-15041 CVE-2018-16873 CVE-2018-6574 CVE-2014-7189 CVE-2016-3959 CVE-2016-5386 CVE-2018-16874 CVE-2018-16875  +5 more Upstream summary: Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. […]

Read more
SLES 16 — erlang — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — erlang — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 7 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:4215-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-37026 CVE-2026-21620 CVE-2026-28808 CVE-2026-32144 CVE-2020-25623 CVE-2020-35733 CVE-2026-23941 CVE-2026-23942  +5 more Upstream summary: In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is […]

Read more
SLES 16 — zypper — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — zypper — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-7436 CVE-2017-9269 Upstream summary: In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to […]

Read more
SLES 16 — ppp — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — ppp — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:0489-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-8597 CVE-2014-3158 CVE-2015-3310 CVE-2022-4603 Upstream summary: eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. […]

Read more
SLES 16 — python313-pytest — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-pytest — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 February 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2026:1744-1 (see also SUSE bugzilla) Related CVEs: CVE-2025-71176 Upstream summary: pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of […]

Read more
CHAT