This update addresses a null pointer dereferencing issue that could cause the session for a client that sent specially-crafted commands to the server to crash (not the sessions of other clients).
Bing Shi discovered that GnuTLS, a portable library which implements the Transport Layer Security and Datagram Transport Layer Security protocols, had inefficient handling of certificate data with a large number of names or name constraints, potentially leading to Denial of
* bsc#1236946 Cross-References: * CVE-2024-27856 * CVE-2024-54543
* bsc#1237084 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6
* bsc#1237084 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5
* bsc#1236560 Cross-References: * CVE-2024-45339
https://security-tracker.debian.org/tracker/DSA-5869-1
The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker.
The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree.
Includes CVE fixes.
Fix regression of Match directive processing
Update gnutls to the latest upstream release, including a fix for CVE-2024-12243.
Security fix for CVE-2025-0938
* bsc#1237091 Cross-References: * CVE-2025-1244
* bsc#1237037 * bsc#1237038 Cross-References: * CVE-2025-24970
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
Several security issues were fixed in libsndfile.
https://security-tracker.debian.org/tracker/DSA-5867-1
* bsc#1237091 Cross-References: * CVE-2025-1244
A vulnerability was discovered in pam-pkcs11, a PAM module which allows to use PKCS#11 based smart cards in the PAM authentication stack, which may allow to bypass the authentication in some scenarios.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
Several security issues were fixed in Docker.
The Qualys Threat Research Unit (TRU) discovered that the OpenSSH client is vulnerable to a machine-in-the-middle attack if the VerifyHostKeyDNS option is enabled (disabled by default).
* bsc#1237096 Cross-References: * CVE-2024-31068 * CVE-2024-36293
https://security-tracker.debian.org/tracker/DSA-5868-1
The following vulnerability has been discovered in the glog package for Go: When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process’s log file path
Multiple vulnerabilties have been found in freelrdp2, a free implementation of the Remote Desktop Protocol (RDP). The vulnerabilties potentially allows authentication bypasses on configuration errors, buffer overreads, DoS vectors, buffer overflows or accessing files
Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8
Update to upstream 2.1-48. 20250211 Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-02) at revision 0x38; Addition of 06-bf-06/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38; Addition of 06-bf-07/0x07 microcode (in intel-ucode/06-97-05) at revision 0x38;
Update to 133.0.6943.98 CVE-2025-0995: Use after free in V8 CVE-2025-0996: Inappropriate implementation in Browser UI CVE-2025-0997: Use after free in Navigation CVE-2025-0998: Out of bounds memory access in V8
Multiple vulnerabilities were fixed in trafficserver, a caching proxy server. CVE-2024-38479
C’©dric Krier has found that trytond, the Tryton application server, accepts compressed content from unauthenticated requests which makes it vulnerable to zip bomb attacks (see DLA 4022-1).
Update to WebKitGTK 2.46.6: Fix a crash when enabling Skia CPU rendering. Fix several crashes and rendering issues. Fix CVE-2024-54543, CVE-2025-24143, CVE-2025-24150, CVE-2025-24158, CVE-2025-24162
Latest upstream release. It adds support for tiles and fixes reading images generated by iOS 18+. See https://github.com/strukturag/libheif/releases for more details about the changes since 1.17.6. NOTE: heif-convert tool was renamed to heif-dec. How to test:
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.
* bsc#1236878 Cross-References: * CVE-2024-12133
Several security issues were fixed in Apache ActiveMQ.
* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024
* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024
https://security-tracker.debian.org/tracker/DSA-5866-1
* bsc#1012628 * bsc#1194869 * bsc#1215199 * bsc#1216813 * bsc#1218470
* bsc#1236705 Cross-References: * CVE-2025-0938
* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883
* bsc#1228044 * bsc#1236282 Cross-References: * CVE-2025-0395
* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References:
* bsc#1229644 * bsc#1229663 * bsc#1230998 * bsc#1231993
* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016
https://security-tracker.debian.org/tracker/DSA-5865-1
https://security-tracker.debian.org/tracker/DSA-5864-1
https://security-tracker.debian.org/tracker/DSA-5863-1
* bsc#1228165 * bsc#1236705 Cross-References: * CVE-2025-0938
* bsc#1227056 * bsc#1236483 Cross-References: * CVE-2023-45288
* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883
* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528
* bsc#1233760 Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6
USN-7206-3 caused some regression in rsync.
* bsc#1236596 Cross-References: * CVE-2024-11187
https://security-tracker.debian.org/tracker/DSA-5862-1
https://security-tracker.debian.org/tracker/DSA-5861-1
Vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.
update to 1.33.0
Security fix for CVE-2023-52892, CVE-2024-27354
Add code to deal with sched_setattr() not being exported in glibc 2.41 Address CVE-2024-54159 denial of services via symlink attack
Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4
New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more
Updated to latest upstream (135.0)
Update to 0.8.4
xrdp allows an infinite number of login attempts. (CVE-2024-39917) References: – https://bugs.mageia.org/show_bug.cgi?id=33985 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FMYGECEBC7XEBNQ2ZHXYRQBLCMHHXKP5/
When an input DER data contains a large number of SEQUENCE OF or SET OF elements, decoding the data and searching a specific element in it take quadratic time to complete. This could be utilized for a remote DoS attack by presenting a crafted certificate to the network peer.
Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.
