SUSE 5495 Published by

Several security updates are available for openSUSE Tumbleweed, which solve vulnerabilities in various packages. The affected packages include chromedriver, libsixel-bash-completion, trivy, 7zip, and go1.25, with a total of eight vulnerabilities addressed across these packages. Each update is rated as moderate and can be installed to fix the corresponding vulnerabilities. The updates provide patches for CVE-2025-9864, CVE-2025-9865, CVE-2025-9866, CVE-2025-9867, CVE-2025-9300, CVE-2025-46569, CVE-2025-53816, and CVE-2025-47910.

openSUSE-SU-2025:15524-1: moderate: chromedriver-140.0.7339.80-1.1 on GA media
openSUSE-SU-2025:15526-1: moderate: libsixel-bash-completion-1.10.5-2.1 on GA media
openSUSE-SU-2025:15530-1: moderate: trivy-0.65.0-2.1 on GA media
openSUSE-SU-2025:15523-1: moderate: 7zip-25.01-1.1 on GA media
openSUSE-SU-2025:15525-1: moderate: go1.25-1.25.1-1.1 on GA media




openSUSE-SU-2025:15524-1: moderate: chromedriver-140.0.7339.80-1.1 on GA media


# chromedriver-140.0.7339.80-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15524-1
Rating: moderate

Cross-References:

* CVE-2025-9864
* CVE-2025-9865
* CVE-2025-9866
* CVE-2025-9867

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-140.0.7339.80-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 140.0.7339.80-1.1
* chromium 140.0.7339.80-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-9864.html
* https://www.suse.com/security/cve/CVE-2025-9865.html
* https://www.suse.com/security/cve/CVE-2025-9866.html
* https://www.suse.com/security/cve/CVE-2025-9867.html



openSUSE-SU-2025:15526-1: moderate: libsixel-bash-completion-1.10.5-2.1 on GA media


# libsixel-bash-completion-1.10.5-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15526-1
Rating: moderate

Cross-References:

* CVE-2025-9300

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libsixel-bash-completion-1.10.5-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libsixel-bash-completion 1.10.5-2.1
* libsixel-devel 1.10.5-2.1
* libsixel-utils 1.10.5-2.1
* libsixel-zsh-completion 1.10.5-2.1
* libsixel1 1.10.5-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-9300.html



openSUSE-SU-2025:15530-1: moderate: trivy-0.65.0-2.1 on GA media


# trivy-0.65.0-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15530-1
Rating: moderate

Cross-References:

* CVE-2025-46569

CVSS scores:

* CVE-2025-46569 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
* CVE-2025-46569 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the trivy-0.65.0-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* trivy 0.65.0-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-46569.html



openSUSE-SU-2025:15523-1: moderate: 7zip-25.01-1.1 on GA media


# 7zip-25.01-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15523-1
Rating: moderate

Cross-References:

* CVE-2025-53816
* CVE-2025-53817

CVSS scores:

* CVE-2025-53816 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2025-53816 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2025-53817 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-53817 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the 7zip-25.01-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* 7zip 25.01-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-53816.html
* https://www.suse.com/security/cve/CVE-2025-53817.html



openSUSE-SU-2025:15525-1: moderate: go1.25-1.25.1-1.1 on GA media


# go1.25-1.25.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15525-1
Rating: moderate

Cross-References:

* CVE-2025-47910

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the go1.25-1.25.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* go1.25 1.25.1-1.1
* go1.25-doc 1.25.1-1.1
* go1.25-libstd 1.25.1-1.1
* go1.25-race 1.25.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-47910.html