SUSE 5362 Published by

SUSE Linux has released several security updates, including mirrorsorcerer, SDL, python311-Django4, MozillaThunderbird, libetebase-devel, traefik, tomcat11, ggml-devel, sudo, velociraptor, libspdlog1, teleport, python313-3.13.5-2.1, libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1, and libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1:

openSUSE-SU-2025:15246-1: moderate: mirrorsorcerer-0.1.3~1-1.1 on GA media
openSUSE-SU-2025:15205-1: moderate: SDL-1.2.15-1.1 on GA media
openSUSE-SU-2025:15268-1: moderate: python311-Django4-4.2.22-1.1 on GA media
openSUSE-SU-2025:15204-1: moderate: MozillaThunderbird-128.11.1-2.1 on GA media
openSUSE-SU-2025:15238-1: moderate: libetebase-devel-0.5.8-1.1 on GA media
openSUSE-SU-2025:15206-1: moderate: SDL2-2.32.8-1.1 on GA media
openSUSE-SU-2025:15293-1: moderate: redis-8.0.2-1.1 on GA media
openSUSE-SU-2025:15272-1: moderate: python311-jupyter-core-5.8.1-1.1 on GA media
openSUSE-SU-2025:15304-1: moderate: traefik-3.4.3-1.1 on GA media
openSUSE-SU-2025:15303-1: moderate: tomcat11-11.0.8-1.1 on GA media
openSUSE-SU-2025:15245-1: moderate: ggml-devel-5699-1.1 on GA media
openSUSE-SU-2025:15298-1: moderate: sudo-1.9.17p1-1.1 on GA media
openSUSE-SU-2025:15307-1: moderate: velociraptor-0.7.0.4.git163.87ee3570-1.1 on GA media
openSUSE-SU-2025:15297-1: moderate: libspdlog1_15-1.15.3-2.1 on GA media
openSUSE-SU-2025:15295-1: moderate: python311-salt-3006.0-41.1 on GA media
openSUSE-SU-2025:15300-1: moderate: teleport-17.5.3-1.1 on GA media
openSUSE-SU-2025:15289-1: moderate: python314-3.14.0~b3-3.1 on GA media
openSUSE-SU-2025:15217-1: moderate: flake-pilot-3.1.19-1.1 on GA media
openSUSE-SU-2025:15283-1: moderate: python311-urllib3-2.5.0-1.1 on GA media
openSUSE-SU-2025:15287-1: moderate: python312-3.12.11-2.1 on GA media
openSUSE-SU-2025:15311-1: moderate: xwayland-24.1.8-1.1 on GA media
openSUSE-SU-2025:15310-1: moderate: xorg-x11-server-21.1.15-6.1 on GA media
openSUSE-SU-2025:15288-1: moderate: python313-3.13.5-2.1 on GA media
openSUSE-SU-2025:15309-1: moderate: libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1 on GA media
openSUSE-SU-2025:15279-1: moderate: python311-pydata-sphinx-theme-0.16.1-1.1 on GA media
openSUSE-SU-2025:15308-1: moderate: libwireshark18-4.4.7-1.1 on GA media
openSUSE-SU-2025:15281-1: moderate: python311-requests-2.32.4-1.1 on GA media
openSUSE-SU-2025:15306-1: moderate: valkey-8.1.2-1.1 on GA media
openSUSE-SU-2025:15305-1: moderate: traefik2-2.11.26-1.1 on GA media
openSUSE-SU-2025:15302-1: moderate: tomcat10-10.1.42-1.1 on GA media
openSUSE-SU-2025:15277-1: moderate: jupyter-panel-1.7.1-1.1 on GA media
openSUSE-SU-2025:15276-1: moderate: jupyter-nbdime-7.0.2-20.1 on GA media
openSUSE-SU-2025:15301-1: moderate: tomcat-9.0.106-1.1 on GA media
openSUSE-SU-2025:15275-1: moderate: jupyter-nbclassic-1.3.1-1.1 on GA media
openSUSE-SU-2025:15299-1: moderate: libsystemd0-257.7-1.1 on GA media
openSUSE-SU-2025:15274-1: moderate: jupyter-jupyterlab-templates-0.5.2-2.1 on GA media
openSUSE-SU-2025:15269-1: moderate: jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media
openSUSE-SU-2025:15296-1: moderate: ctdb-4.22.2+git.396.c752843dcf4-1.1 on GA media
openSUSE-SU-2025:15294-1: moderate: keylime-ima-policy-0.2.7+70-2.1 on GA media
openSUSE-SU-2025:15270-1: moderate: python-furo-doc-2024.8.6-3.1 on GA media
openSUSE-SU-2025:15261-1: moderate: perl-YAML-LibYAML-0.904.0-2.1 on GA media
openSUSE-SU-2025:15292-1: moderate: radare2-5.9.8-3.1 on GA media
openSUSE-SU-2025:15267-1: moderate: python311-Django-5.2.2-1.1 on GA media
openSUSE-SU-2025:15290-1: moderate: python39-3.9.23-3.1 on GA media
openSUSE-SU-2025:15285-1: moderate: python310-3.10.18-3.1 on GA media
openSUSE-SU-2025:15266-1: moderate: pure-ftpd-1.0.51-5.1 on GA media
openSUSE-SU-2025:15286-1: moderate: python311-3.11.13-2.1 on GA media
openSUSE-SU-2025:15264-1: moderate: postgresql-jdbc-42.7.7-1.1 on GA media
openSUSE-SU-2025:15265-1: moderate: libprotobuf-lite31_1_0-31.1-1.1 on GA media
openSUSE-SU-2025:15278-1: moderate: jupyter-plotly-6.1.2-1.1 on GA media
openSUSE-SU-2025:15271-1: moderate: jupyter-matplotlib-0.11.4-15.1 on GA media
openSUSE-SU-2025:15263-1: moderate: polaris-9.6.4-1.1 on GA media
openSUSE-SU-2025:15258-1: moderate: perl-32bit-5.40.2-3.1 on GA media
openSUSE-SU-2025:15260-1: moderate: perl-File-Find-Rule-0.350.0-1.1 on GA media
openSUSE-SU-2025:15247-1: moderate: moarvm-2025.05-1.1 on GA media
openSUSE-SU-2025:15259-1: moderate: perl-CryptX-0.87.0-1.1 on GA media
openSUSE-SU-2025:15254-1: moderate: openbao-2.3.1-1.1 on GA media
openSUSE-SU-2025:15262-1: moderate: podman-5.5.2-1.1 on GA media
openSUSE-SU-2025:15248-1: moderate: nix-2.29.1-1.1 on GA media
openSUSE-SU-2025:15257-1: moderate: pam_pkcs11-0.6.13-2.1 on GA media
openSUSE-SU-2025:15256-1: moderate: pam-1.7.1-1.1 on GA media
openSUSE-SU-2025:15242-1: moderate: libsoup-2_4-1-2.74.3-12.1 on GA media
openSUSE-SU-2025:15255-1: moderate: ovmf-202505-2.1 on GA media
openSUSE-SU-2025:15235-1: moderate: kubernetes1.31-apiserver-1.31.10-1.1 on GA media
openSUSE-SU-2025:15252-1: moderate: oci-cli-3.61.0-1.1 on GA media
openSUSE-SU-2025:15236-1: moderate: kubernetes1.32-apiserver-1.32.6-1.1 on GA media
openSUSE-SU-2025:15253-1: moderate: opa-1.6.0-1.1 on GA media
openSUSE-SU-2025:15251-1: moderate: nova-3.11.4-1.1 on GA media
openSUSE-SU-2025:15233-1: moderate: jq-1.8.1-1.1 on GA media
openSUSE-SU-2025:15250-1: moderate: corepack22-22.15.1-1.1 on GA media
openSUSE-SU-2025:15234-1: moderate: kubernetes1.30-apiserver-1.30.14-1.1 on GA media
openSUSE-SU-2025:15232-1: moderate: jgit-5.11.0-2.1 on GA media
openSUSE-SU-2025:15249-1: moderate: nodejs-electron-35.6.0-1.2 on GA media
openSUSE-SU-2025:15241-1: moderate: libsoup-3_0-0-3.6.5-6.1 on GA media
openSUSE-SU-2025:15240-1: moderate: libQt5Bootstrap-devel-static-32bit-5.15.17+kde122-2.1 on GA media
openSUSE-SU-2025:15237-1: moderate: libbd_btrfs-devel-3.1.1-2.1 on GA media
openSUSE-SU-2025:15227-1: moderate: grype-0.94.0-1.1 on GA media
openSUSE-SU-2025:15229-1: moderate: himmelblau-0.9.17+git.0.4a97692-1.1 on GA media
openSUSE-SU-2025:15228-1: moderate: helm-3.18.3-1.1 on GA media
openSUSE-SU-2025:15226-1: moderate: grafana-11.6.3-1.1 on GA media
openSUSE-SU-2025:15230-1: moderate: icu-77.1-3.1 on GA media
openSUSE-SU-2025:15220-1: moderate: git-lfs-3.7.0-1.1 on GA media
openSUSE-SU-2025:15224-1: moderate: go1.24-1.24.4-1.1 on GA media
openSUSE-SU-2025:15222-1: moderate: glibc-2.41-3.1 on GA media
openSUSE-SU-2025:15221-1: moderate: gio-branding-upstream-2.84.3-1.1 on GA media
openSUSE-SU-2025:15218-1: moderate: fractal-11.2-1.1 on GA media
openSUSE-SU-2025:15225-1: moderate: govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media
openSUSE-SU-2025:15223-1: moderate: go1.23-1.23.10-1.1 on GA media
openSUSE-SU-2025:15211-1: moderate: clamav-1.4.3-1.1 on GA media
openSUSE-SU-2025:15215-1: moderate: ffmpeg-4-4.4.6-4.1 on GA media
openSUSE-SU-2025:15210-1: moderate: chromedriver-138.0.7204.96-1.1 on GA media
openSUSE-SU-2025:15213-1: moderate: curl-8.14.1-4.1 on GA media
openSUSE-SU-2025:15219-1: moderate: gdm-48.0-10.1 on GA media
openSUSE-SU-2025:15216-1: moderate: firefox-esr-128.12.0-1.1 on GA media
openSUSE-SU-2025:15209-1: moderate: assimp-devel-6.0.2-1.1 on GA media
openSUSE-SU-2025:15212-1: moderate: clustershell-1.9.3-1.1 on GA media
openSUSE-SU-2025:15208-1: moderate: apache-commons-fileupload-1.6.0-1.1 on GA media
openSUSE-SU-2025:15203-1: moderate: MozillaFirefox-139.0.4-1.1 on GA media
openSUSE-SU-2025:15207-1: moderate: alloy-1.9.1-1.1 on GA media
openSUSE-SU-2025:15244-1: moderate: libtpms-devel-0.10.1-1.1 on GA media
openSUSE-SU-2025:15243-1: moderate: libssh-config-0.11.2-1.1 on GA media
openSUSE-SU-2025:15291-1: moderate: erlang-rabbitmq-client-3.13.7-4.1 on GA media




openSUSE-SU-2025:15246-1: moderate: mirrorsorcerer-0.1.3~1-1.1 on GA media


# mirrorsorcerer-0.1.3~1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15246-1
Rating: moderate

Cross-References:

* CVE-2025-5791

CVSS scores:

* CVE-2025-5791 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-5791 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the mirrorsorcerer-0.1.3~1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* mirrorsorcerer 0.1.3~1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5791.html



openSUSE-SU-2025:15205-1: moderate: SDL-1.2.15-1.1 on GA media


# SDL-1.2.15-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15205-1
Rating: moderate

Cross-References:

* CVE-2019-13616
* CVE-2019-7572
* CVE-2019-7573
* CVE-2019-7574
* CVE-2019-7575
* CVE-2019-7577
* CVE-2019-7578
* CVE-2019-7635
* CVE-2019-7636
* CVE-2019-7637
* CVE-2019-7638
* CVE-2021-33657

CVSS scores:

* CVE-2019-13616 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7572 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7573 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7574 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7575 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2019-7577 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7578 ( SUSE ): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2019-7635 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7636 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7637 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2019-7638 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2021-33657 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 12 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the SDL-1.2.15-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* SDL 1.2.15-1.1

## References:

* https://www.suse.com/security/cve/CVE-2019-13616.html
* https://www.suse.com/security/cve/CVE-2019-7572.html
* https://www.suse.com/security/cve/CVE-2019-7573.html
* https://www.suse.com/security/cve/CVE-2019-7574.html
* https://www.suse.com/security/cve/CVE-2019-7575.html
* https://www.suse.com/security/cve/CVE-2019-7577.html
* https://www.suse.com/security/cve/CVE-2019-7578.html
* https://www.suse.com/security/cve/CVE-2019-7635.html
* https://www.suse.com/security/cve/CVE-2019-7636.html
* https://www.suse.com/security/cve/CVE-2019-7637.html
* https://www.suse.com/security/cve/CVE-2019-7638.html
* https://www.suse.com/security/cve/CVE-2021-33657.html



openSUSE-SU-2025:15268-1: moderate: python311-Django4-4.2.22-1.1 on GA media


# python311-Django4-4.2.22-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15268-1
Rating: moderate

Cross-References:

* CVE-2025-48432

CVSS scores:

* CVE-2025-48432 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2025-48432 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-Django4-4.2.22-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-Django4 4.2.22-1.1
* python312-Django4 4.2.22-1.1
* python313-Django4 4.2.22-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-48432.html



openSUSE-SU-2025:15204-1: moderate: MozillaThunderbird-128.11.1-2.1 on GA media


# MozillaThunderbird-128.11.1-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15204-1
Rating: moderate

Cross-References:

* CVE-2025-5986

CVSS scores:

* CVE-2025-5986 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the MozillaThunderbird-128.11.1-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* MozillaThunderbird 128.11.1-2.1
* MozillaThunderbird-openpgp-librnp 128.11.1-2.1
* MozillaThunderbird-translations-common 128.11.1-2.1
* MozillaThunderbird-translations-other 128.11.1-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5986.html



openSUSE-SU-2025:15238-1: moderate: libetebase-devel-0.5.8-1.1 on GA media


# libetebase-devel-0.5.8-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15238-1
Rating: moderate

Cross-References:

* CVE-2025-3416

CVSS scores:

* CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libetebase-devel-0.5.8-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libetebase-devel 0.5.8-1.1
* libetebase0 0.5.8-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-3416.html



openSUSE-SU-2025:15206-1: moderate: SDL2-2.32.8-1.1 on GA media


# SDL2-2.32.8-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15206-1
Rating: moderate

Cross-References:

* CVE-2017-2888
* CVE-2019-13616
* CVE-2019-13626
* CVE-2019-7572
* CVE-2019-7573
* CVE-2019-7574
* CVE-2019-7575
* CVE-2019-7577
* CVE-2019-7578
* CVE-2019-7635
* CVE-2019-7636
* CVE-2019-7637
* CVE-2019-7638
* CVE-2020-14409
* CVE-2020-14410
* CVE-2021-33657
* CVE-2022-4743

CVSS scores:

* CVE-2017-2888 ( SUSE ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2019-13616 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-13626 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
* CVE-2019-7572 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7573 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7574 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7575 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2019-7577 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7578 ( SUSE ): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2019-7635 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7636 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2019-7637 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2019-7638 ( SUSE ): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2020-14409 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2020-14410 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2021-33657 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2022-4743 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 17 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the SDL2-2.32.8-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* SDL2 2.32.8-1.1

## References:

* https://www.suse.com/security/cve/CVE-2017-2888.html
* https://www.suse.com/security/cve/CVE-2019-13616.html
* https://www.suse.com/security/cve/CVE-2019-13626.html
* https://www.suse.com/security/cve/CVE-2019-7572.html
* https://www.suse.com/security/cve/CVE-2019-7573.html
* https://www.suse.com/security/cve/CVE-2019-7574.html
* https://www.suse.com/security/cve/CVE-2019-7575.html
* https://www.suse.com/security/cve/CVE-2019-7577.html
* https://www.suse.com/security/cve/CVE-2019-7578.html
* https://www.suse.com/security/cve/CVE-2019-7635.html
* https://www.suse.com/security/cve/CVE-2019-7636.html
* https://www.suse.com/security/cve/CVE-2019-7637.html
* https://www.suse.com/security/cve/CVE-2019-7638.html
* https://www.suse.com/security/cve/CVE-2020-14409.html
* https://www.suse.com/security/cve/CVE-2020-14410.html
* https://www.suse.com/security/cve/CVE-2021-33657.html
* https://www.suse.com/security/cve/CVE-2022-4743.html



openSUSE-SU-2025:15293-1: moderate: redis-8.0.2-1.1 on GA media


# redis-8.0.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15293-1
Rating: moderate

Cross-References:

* CVE-2024-31227
* CVE-2024-31228
* CVE-2024-31449
* CVE-2024-46981
* CVE-2024-51741
* CVE-2025-21605
* CVE-2025-27151

CVSS scores:

* CVE-2024-31227 ( SUSE ): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
* CVE-2024-31228 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-31449 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2024-46981 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2024-46981 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2024-51741 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-51741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-21605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-27151 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the redis-8.0.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* redis 8.0.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-31227.html
* https://www.suse.com/security/cve/CVE-2024-31228.html
* https://www.suse.com/security/cve/CVE-2024-31449.html
* https://www.suse.com/security/cve/CVE-2024-46981.html
* https://www.suse.com/security/cve/CVE-2024-51741.html
* https://www.suse.com/security/cve/CVE-2025-21605.html
* https://www.suse.com/security/cve/CVE-2025-27151.html



openSUSE-SU-2025:15272-1: moderate: python311-jupyter-core-5.8.1-1.1 on GA media


# python311-jupyter-core-5.8.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15272-1
Rating: moderate

Cross-References:

* CVE-2025-30167

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-jupyter-core-5.8.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-jupyter-core 5.8.1-1.1
* python312-jupyter-core 5.8.1-1.1
* python313-jupyter-core 5.8.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-30167.html



openSUSE-SU-2025:15304-1: moderate: traefik-3.4.3-1.1 on GA media


# traefik-3.4.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15304-1
Rating: moderate

Cross-References:

* CVE-2024-4533
* CVE-2024-45338
* CVE-2025-22868
* CVE-2025-22869
* CVE-2025-22872
* CVE-2025-27144
* CVE-2025-47952

CVSS scores:

* CVE-2024-45338 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-45338 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
* CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the traefik-3.4.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* traefik 3.4.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-4533.html
* https://www.suse.com/security/cve/CVE-2024-45338.html
* https://www.suse.com/security/cve/CVE-2025-22868.html
* https://www.suse.com/security/cve/CVE-2025-22869.html
* https://www.suse.com/security/cve/CVE-2025-22872.html
* https://www.suse.com/security/cve/CVE-2025-27144.html
* https://www.suse.com/security/cve/CVE-2025-47952.html



openSUSE-SU-2025:15303-1: moderate: tomcat11-11.0.8-1.1 on GA media


# tomcat11-11.0.8-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15303-1
Rating: moderate

Cross-References:

* CVE-2025-46701
* CVE-2025-48988
* CVE-2025-49125

CVSS scores:

* CVE-2025-46701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-46701 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-48988 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-48988 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49125 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-49125 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the tomcat11-11.0.8-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* tomcat11 11.0.8-1.1
* tomcat11-admin-webapps 11.0.8-1.1
* tomcat11-doc 11.0.8-1.1
* tomcat11-docs-webapp 11.0.8-1.1
* tomcat11-el-6_0-api 11.0.8-1.1
* tomcat11-embed 11.0.8-1.1
* tomcat11-jsp-4_0-api 11.0.8-1.1
* tomcat11-jsvc 11.0.8-1.1
* tomcat11-lib 11.0.8-1.1
* tomcat11-servlet-6_1-api 11.0.8-1.1
* tomcat11-webapps 11.0.8-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-46701.html
* https://www.suse.com/security/cve/CVE-2025-48988.html
* https://www.suse.com/security/cve/CVE-2025-49125.html



openSUSE-SU-2025:15245-1: moderate: ggml-devel-5699-1.1 on GA media


# ggml-devel-5699-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15245-1
Rating: moderate

Cross-References:

* CVE-2025-49847

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the ggml-devel-5699-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ggml-devel 5699-1.1
* libggml 5699-1.1
* libggml-base 5699-1.1
* libggml-cpu 5699-1.1
* libggml-opencl 5699-1.1
* libggml-vulkan 5699-1.1
* libllama 5699-1.1
* libmtmd 5699-1.1
* llamacpp 5699-1.1
* llamacpp-devel 5699-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49847.html



openSUSE-SU-2025:15298-1: moderate: sudo-1.9.17p1-1.1 on GA media


# sudo-1.9.17p1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15298-1
Rating: moderate

Cross-References:

* CVE-2025-32462
* CVE-2025-32463

CVSS scores:

* CVE-2025-32462 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-32462 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-32463 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-32463 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the sudo-1.9.17p1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* sudo 1.9.17p1-1.1
* sudo-devel 1.9.17p1-1.1
* sudo-plugin-python 1.9.17p1-1.1
* sudo-policy-sudo-auth-self 1.9.17p1-1.1
* sudo-policy-wheel-auth-self 1.9.17p1-1.1
* sudo-test 1.9.17p1-1.1
* system-group-sudo 1.9.17p1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-32462.html
* https://www.suse.com/security/cve/CVE-2025-32463.html



openSUSE-SU-2025:15307-1: moderate: velociraptor-0.7.0.4.git163.87ee3570-1.1 on GA media


# velociraptor-0.7.0.4.git163.87ee3570-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15307-1
Rating: moderate

Cross-References:

* CVE-2025-27144
* CVE-2025-27152
* CVE-2025-30204

CVSS scores:

* CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-27152 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-27152 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-30204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-30204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the velociraptor-0.7.0.4.git163.87ee3570-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* velociraptor 0.7.0.4.git163.87ee3570-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-27144.html
* https://www.suse.com/security/cve/CVE-2025-27152.html
* https://www.suse.com/security/cve/CVE-2025-30204.html



openSUSE-SU-2025:15297-1: moderate: libspdlog1_15-1.15.3-2.1 on GA media


# libspdlog1_15-1.15.3-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15297-1
Rating: moderate

Cross-References:

* CVE-2025-6140

CVSS scores:

* CVE-2025-6140 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-6140 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libspdlog1_15-1.15.3-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libspdlog1_15 1.15.3-2.1
* libspdlog1_15-32bit 1.15.3-2.1
* spdlog-devel 1.15.3-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6140.html



openSUSE-SU-2025:15295-1: moderate: python311-salt-3006.0-41.1 on GA media


# python311-salt-3006.0-41.1 on GA media

Announcement ID: openSUSE-SU-2025:15295-1
Rating: moderate

Cross-References:

* CVE-2024-38822
* CVE-2024-38823
* CVE-2024-38824
* CVE-2024-38825
* CVE-2025-22236
* CVE-2025-22237
* CVE-2025-22238
* CVE-2025-22239
* CVE-2025-22240
* CVE-2025-22241
* CVE-2025-22242
* CVE-2025-47287

CVSS scores:

* CVE-2024-38822 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
* CVE-2024-38822 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2024-38823 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2024-38823 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2024-38824 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2024-38824 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2024-38825 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
* CVE-2024-38825 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2025-22236 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
* CVE-2025-22236 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L
* CVE-2025-22237 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-22237 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22238 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-22238 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-22239 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
* CVE-2025-22239 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L
* CVE-2025-22240 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-22240 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22241 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
* CVE-2025-22241 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-22242 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22242 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-47287 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-47287 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 12 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python311-salt-3006.0-41.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-salt 3006.0-41.1
* python312-salt 3006.0-41.1
* python313-salt 3006.0-41.1
* salt 3006.0-41.1
* salt-api 3006.0-41.1
* salt-bash-completion 3006.0-41.1
* salt-cloud 3006.0-41.1
* salt-doc 3006.0-41.1
* salt-fish-completion 3006.0-41.1
* salt-master 3006.0-41.1
* salt-minion 3006.0-41.1
* salt-proxy 3006.0-41.1
* salt-ssh 3006.0-41.1
* salt-standalone-formulas-configuration 3006.0-41.1
* salt-syndic 3006.0-41.1
* salt-transactional-update 3006.0-41.1
* salt-zsh-completion 3006.0-41.1

## References:

* https://www.suse.com/security/cve/CVE-2024-38822.html
* https://www.suse.com/security/cve/CVE-2024-38823.html
* https://www.suse.com/security/cve/CVE-2024-38824.html
* https://www.suse.com/security/cve/CVE-2024-38825.html
* https://www.suse.com/security/cve/CVE-2025-22236.html
* https://www.suse.com/security/cve/CVE-2025-22237.html
* https://www.suse.com/security/cve/CVE-2025-22238.html
* https://www.suse.com/security/cve/CVE-2025-22239.html
* https://www.suse.com/security/cve/CVE-2025-22240.html
* https://www.suse.com/security/cve/CVE-2025-22241.html
* https://www.suse.com/security/cve/CVE-2025-22242.html
* https://www.suse.com/security/cve/CVE-2025-47287.html



openSUSE-SU-2025:15300-1: moderate: teleport-17.5.3-1.1 on GA media


# teleport-17.5.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15300-1
Rating: moderate

Cross-References:

* CVE-2025-49825

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the teleport-17.5.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* teleport 17.5.3-1.1
* teleport-bash-completion 17.5.3-1.1
* teleport-fdpass-teleport 17.5.3-1.1
* teleport-tbot 17.5.3-1.1
* teleport-tbot-bash-completion 17.5.3-1.1
* teleport-tbot-zsh-completion 17.5.3-1.1
* teleport-tctl 17.5.3-1.1
* teleport-tctl-bash-completion 17.5.3-1.1
* teleport-tctl-zsh-completion 17.5.3-1.1
* teleport-tsh 17.5.3-1.1
* teleport-tsh-bash-completion 17.5.3-1.1
* teleport-tsh-zsh-completion 17.5.3-1.1
* teleport-zsh-completion 17.5.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49825.html



openSUSE-SU-2025:15289-1: moderate: python314-3.14.0~b3-3.1 on GA media


# python314-3.14.0~b3-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15289-1
Rating: moderate

Cross-References:

* CVE-2025-4435
* CVE-2025-6069

CVSS scores:

* CVE-2025-4435 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python314-3.14.0~b3-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python314 3.14.0~b3-3.1
* python314-curses 3.14.0~b3-3.1
* python314-dbm 3.14.0~b3-3.1
* python314-idle 3.14.0~b3-3.1
* python314-tk 3.14.0~b3-3.1
* python314-x86-64-v3 3.14.0~b3-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4435.html
* https://www.suse.com/security/cve/CVE-2025-6069.html



openSUSE-SU-2025:15217-1: moderate: flake-pilot-3.1.19-1.1 on GA media


# flake-pilot-3.1.19-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15217-1
Rating: moderate

Cross-References:

* CVE-2025-3416
* CVE-2025-5791

CVSS scores:

* CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-5791 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-5791 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the flake-pilot-3.1.19-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* flake-pilot 3.1.19-1.1
* flake-pilot-firecracker 3.1.19-1.1
* flake-pilot-firecracker-dracut-netstart 3.1.19-1.1
* flake-pilot-firecracker-guestvm-tools 3.1.19-1.1
* flake-pilot-podman 3.1.19-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-3416.html
* https://www.suse.com/security/cve/CVE-2025-5791.html



openSUSE-SU-2025:15283-1: moderate: python311-urllib3-2.5.0-1.1 on GA media


# python311-urllib3-2.5.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15283-1
Rating: moderate

Cross-References:

* CVE-2025-50181
* CVE-2025-50182

CVSS scores:

* CVE-2025-50181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-50181 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-50182 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-50182 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python311-urllib3-2.5.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-urllib3 2.5.0-1.1
* python312-urllib3 2.5.0-1.1
* python313-urllib3 2.5.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-50181.html
* https://www.suse.com/security/cve/CVE-2025-50182.html



openSUSE-SU-2025:15287-1: moderate: python312-3.12.11-2.1 on GA media


# python312-3.12.11-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15287-1
Rating: moderate

Cross-References:

* CVE-2024-12718
* CVE-2025-4330
* CVE-2025-4517

CVSS scores:

* CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python312-3.12.11-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python312 3.12.11-2.1
* python312-32bit 3.12.11-2.1
* python312-curses 3.12.11-2.1
* python312-dbm 3.12.11-2.1
* python312-idle 3.12.11-2.1
* python312-tk 3.12.11-2.1
* python312-x86-64-v3 3.12.11-2.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12718.html
* https://www.suse.com/security/cve/CVE-2025-4330.html
* https://www.suse.com/security/cve/CVE-2025-4517.html



openSUSE-SU-2025:15311-1: moderate: xwayland-24.1.8-1.1 on GA media


# xwayland-24.1.8-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15311-1
Rating: moderate

Cross-References:

* CVE-2025-49175
* CVE-2025-49176
* CVE-2025-49177
* CVE-2025-49178
* CVE-2025-49179
* CVE-2025-49180

CVSS scores:

* CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the xwayland-24.1.8-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* xwayland 24.1.8-1.1
* xwayland-devel 24.1.8-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49175.html
* https://www.suse.com/security/cve/CVE-2025-49176.html
* https://www.suse.com/security/cve/CVE-2025-49177.html
* https://www.suse.com/security/cve/CVE-2025-49178.html
* https://www.suse.com/security/cve/CVE-2025-49179.html
* https://www.suse.com/security/cve/CVE-2025-49180.html



openSUSE-SU-2025:15310-1: moderate: xorg-x11-server-21.1.15-6.1 on GA media


# xorg-x11-server-21.1.15-6.1 on GA media

Announcement ID: openSUSE-SU-2025:15310-1
Rating: moderate

Cross-References:

* CVE-2025-49175
* CVE-2025-49176
* CVE-2025-49177
* CVE-2025-49178
* CVE-2025-49179
* CVE-2025-49180

CVSS scores:

* CVE-2025-49175 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2025-49175 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49176 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49177 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-49177 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-49178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-49178 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49179 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49179 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49180 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-49180 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the xorg-x11-server-21.1.15-6.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* xorg-x11-server 21.1.15-6.1
* xorg-x11-server-Xvfb 21.1.15-6.1
* xorg-x11-server-extra 21.1.15-6.1
* xorg-x11-server-sdk 21.1.15-6.1
* xorg-x11-server-source 21.1.15-6.1
* xorg-x11-server-wrapper 21.1.15-6.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49175.html
* https://www.suse.com/security/cve/CVE-2025-49176.html
* https://www.suse.com/security/cve/CVE-2025-49177.html
* https://www.suse.com/security/cve/CVE-2025-49178.html
* https://www.suse.com/security/cve/CVE-2025-49179.html
* https://www.suse.com/security/cve/CVE-2025-49180.html



openSUSE-SU-2025:15288-1: moderate: python313-3.13.5-2.1 on GA media


# python313-3.13.5-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15288-1
Rating: moderate

Cross-References:

* CVE-2024-12718
* CVE-2025-4330
* CVE-2025-4517

CVSS scores:

* CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-3.13.5-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313 3.13.5-2.1
* python313-32bit 3.13.5-2.1
* python313-curses 3.13.5-2.1
* python313-dbm 3.13.5-2.1
* python313-idle 3.13.5-2.1
* python313-tk 3.13.5-2.1
* python313-x86-64-v3 3.13.5-2.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12718.html
* https://www.suse.com/security/cve/CVE-2025-4330.html
* https://www.suse.com/security/cve/CVE-2025-4517.html



openSUSE-SU-2025:15309-1: moderate: libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1 on GA media


# libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1 on GA media

Announcement ID: openSUSE-SU-2025:15309-1
Rating: moderate

Cross-References:

* CVE-2024-58249

CVSS scores:

* CVE-2024-58249 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2024-58249 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libwx_gtk2u_adv-suse16_0_0-3.2.8-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libwx_gtk2u_adv-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_aui-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_core-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_gl-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_html-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_media-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_propgrid-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_qa-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_ribbon-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_richtext-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_stc-suse16_0_0 3.2.8-4.1
* libwx_gtk2u_xrc-suse16_0_0 3.2.8-4.1
* wxWidgets-3_2-devel 3.2.8-4.1

## References:

* https://www.suse.com/security/cve/CVE-2024-58249.html



openSUSE-SU-2025:15279-1: moderate: python311-pydata-sphinx-theme-0.16.1-1.1 on GA media


# python311-pydata-sphinx-theme-0.16.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15279-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-pydata-sphinx-theme-0.16.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-pydata-sphinx-theme 0.16.1-1.1
* python312-pydata-sphinx-theme 0.16.1-1.1
* python313-pydata-sphinx-theme 0.16.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15308-1: moderate: libwireshark18-4.4.7-1.1 on GA media


# libwireshark18-4.4.7-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15308-1
Rating: moderate

Cross-References:

* CVE-2025-5601

CVSS scores:

* CVE-2025-5601 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libwireshark18-4.4.7-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libwireshark18 4.4.7-1.1
* libwiretap15 4.4.7-1.1
* libwsutil16 4.4.7-1.1
* wireshark 4.4.7-1.1
* wireshark-devel 4.4.7-1.1
* wireshark-ui-qt 4.4.7-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5601.html



openSUSE-SU-2025:15281-1: moderate: python311-requests-2.32.4-1.1 on GA media


# python311-requests-2.32.4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15281-1
Rating: moderate

Cross-References:

* CVE-2024-47081

CVSS scores:

* CVE-2024-47081 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2024-47081 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-requests-2.32.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-requests 2.32.4-1.1
* python312-requests 2.32.4-1.1
* python313-requests 2.32.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-47081.html



openSUSE-SU-2025:15306-1: moderate: valkey-8.1.2-1.1 on GA media


# valkey-8.1.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15306-1
Rating: moderate

Cross-References:

* CVE-2025-27151
* CVE-2025-49112

CVSS scores:

* CVE-2025-27151 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2025-49112 ( SUSE ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-49112 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the valkey-8.1.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* valkey 8.1.2-1.1
* valkey-compat-redis 8.1.2-1.1
* valkey-devel 8.1.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-27151.html
* https://www.suse.com/security/cve/CVE-2025-49112.html



openSUSE-SU-2025:15305-1: moderate: traefik2-2.11.26-1.1 on GA media


# traefik2-2.11.26-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15305-1
Rating: moderate

Cross-References:

* CVE-2024-28180
* CVE-2024-45338
* CVE-2025-22868
* CVE-2025-22869
* CVE-2025-22871
* CVE-2025-22872
* CVE-2025-27144
* CVE-2025-32431
* CVE-2025-47952

CVSS scores:

* CVE-2024-28180 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2024-28180 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2024-45338 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-45338 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-22871 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-22871 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
* CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 9 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the traefik2-2.11.26-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* traefik2 2.11.26-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-28180.html
* https://www.suse.com/security/cve/CVE-2024-45338.html
* https://www.suse.com/security/cve/CVE-2025-22868.html
* https://www.suse.com/security/cve/CVE-2025-22869.html
* https://www.suse.com/security/cve/CVE-2025-22871.html
* https://www.suse.com/security/cve/CVE-2025-22872.html
* https://www.suse.com/security/cve/CVE-2025-27144.html
* https://www.suse.com/security/cve/CVE-2025-32431.html
* https://www.suse.com/security/cve/CVE-2025-47952.html



openSUSE-SU-2025:15302-1: moderate: tomcat10-10.1.42-1.1 on GA media


# tomcat10-10.1.42-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15302-1
Rating: moderate

Cross-References:

* CVE-2025-46701
* CVE-2025-48988
* CVE-2025-49125

CVSS scores:

* CVE-2025-46701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-46701 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-48988 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-48988 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49125 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-49125 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the tomcat10-10.1.42-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* tomcat10 10.1.42-1.1
* tomcat10-admin-webapps 10.1.42-1.1
* tomcat10-doc 10.1.42-1.1
* tomcat10-docs-webapp 10.1.42-1.1
* tomcat10-el-5_0-api 10.1.42-1.1
* tomcat10-embed 10.1.42-1.1
* tomcat10-jsp-3_1-api 10.1.42-1.1
* tomcat10-jsvc 10.1.42-1.1
* tomcat10-lib 10.1.42-1.1
* tomcat10-servlet-6_0-api 10.1.42-1.1
* tomcat10-webapps 10.1.42-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-46701.html
* https://www.suse.com/security/cve/CVE-2025-48988.html
* https://www.suse.com/security/cve/CVE-2025-49125.html



openSUSE-SU-2025:15277-1: moderate: jupyter-panel-1.7.1-1.1 on GA media


# jupyter-panel-1.7.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15277-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-panel-1.7.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-panel 1.7.1-1.1
* python311-panel 1.7.1-1.1
* python312-panel 1.7.1-1.1
* python313-panel 1.7.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15276-1: moderate: jupyter-nbdime-7.0.2-20.1 on GA media


# jupyter-nbdime-7.0.2-20.1 on GA media

Announcement ID: openSUSE-SU-2025:15276-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-nbdime-7.0.2-20.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-nbdime 7.0.2-20.1
* jupyter-nbdime-jupyterlab 3.0.2-20.1
* python311-nbdime 4.0.2-20.1
* python311-nbdime-git 4.0.2-20.1
* python311-nbdime-hg 4.0.2-20.1
* python312-nbdime 4.0.2-20.1
* python312-nbdime-git 4.0.2-20.1
* python312-nbdime-hg 4.0.2-20.1
* python313-nbdime 4.0.2-20.1
* python313-nbdime-git 4.0.2-20.1
* python313-nbdime-hg 4.0.2-20.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15301-1: moderate: tomcat-9.0.106-1.1 on GA media


# tomcat-9.0.106-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15301-1
Rating: moderate

Cross-References:

* CVE-2025-46701
* CVE-2025-48988
* CVE-2025-49125

CVSS scores:

* CVE-2025-46701 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-46701 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-48988 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-48988 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49125 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-49125 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the tomcat-9.0.106-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* tomcat 9.0.106-1.1
* tomcat-admin-webapps 9.0.106-1.1
* tomcat-docs-webapp 9.0.106-1.1
* tomcat-el-3_0-api 9.0.106-1.1
* tomcat-embed 9.0.106-1.1
* tomcat-javadoc 9.0.106-1.1
* tomcat-jsp-2_3-api 9.0.106-1.1
* tomcat-jsvc 9.0.106-1.1
* tomcat-lib 9.0.106-1.1
* tomcat-servlet-4_0-api 9.0.106-1.1
* tomcat-webapps 9.0.106-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-46701.html
* https://www.suse.com/security/cve/CVE-2025-48988.html
* https://www.suse.com/security/cve/CVE-2025-49125.html



openSUSE-SU-2025:15275-1: moderate: jupyter-nbclassic-1.3.1-1.1 on GA media


# jupyter-nbclassic-1.3.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15275-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-nbclassic-1.3.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-nbclassic 1.3.1-1.1
* python311-nbclassic 1.3.1-1.1
* python312-nbclassic 1.3.1-1.1
* python313-nbclassic 1.3.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15299-1: moderate: libsystemd0-257.7-1.1 on GA media


# libsystemd0-257.7-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15299-1
Rating: moderate

Cross-References:

* CVE-2025-4598

CVSS scores:

* CVE-2025-4598 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libsystemd0-257.7-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libsystemd0 257.7-1.1
* libsystemd0-32bit 257.7-1.1
* libudev1 257.7-1.1
* libudev1-32bit 257.7-1.1
* systemd 257.7-1.1
* systemd-32bit 257.7-1.1
* systemd-boot 257.7-1.1
* systemd-container 257.7-1.1
* systemd-devel 257.7-1.1
* systemd-devel-32bit 257.7-1.1
* systemd-doc 257.7-1.1
* systemd-experimental 257.7-1.1
* systemd-homed 257.7-1.1
* systemd-journal-remote 257.7-1.1
* systemd-lang 257.7-1.1
* systemd-networkd 257.7-1.1
* systemd-portable 257.7-1.1
* systemd-resolved 257.7-1.1
* systemd-sysvcompat 257.7-1.1
* systemd-testsuite 257.7-1.1
* udev 257.7-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4598.html



openSUSE-SU-2025:15274-1: moderate: jupyter-jupyterlab-templates-0.5.2-2.1 on GA media


# jupyter-jupyterlab-templates-0.5.2-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15274-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-jupyterlab-templates-0.5.2-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-jupyterlab-templates 0.5.2-2.1
* python311-jupyterlab-templates 0.5.2-2.1
* python312-jupyterlab-templates 0.5.2-2.1
* python313-jupyterlab-templates 0.5.2-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15269-1: moderate: jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media


# jupyter-bqplot-jupyterlab-0.5.44-10.1 on GA media

Announcement ID: openSUSE-SU-2025:15269-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-bqplot-jupyterlab-0.5.44-10.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-bqplot-jupyterlab 0.5.44-10.1
* jupyter-bqplot-notebook 0.5.44-10.1
* python311-bqplot 0.12.45-10.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15296-1: moderate: ctdb-4.22.2+git.396.c752843dcf4-1.1 on GA media


# ctdb-4.22.2+git.396.c752843dcf4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15296-1
Rating: moderate

Cross-References:

* CVE-2025-0620

CVSS scores:

* CVE-2025-0620 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-0620 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the ctdb-4.22.2+git.396.c752843dcf4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ctdb 4.22.2+git.396.c752843dcf4-1.1
* ctdb-pcp-pmda 4.22.2+git.396.c752843dcf4-1.1
* ldb-tools 4.22.2+git.396.c752843dcf4-1.1
* libldb-devel 4.22.2+git.396.c752843dcf4-1.1
* libldb2 4.22.2+git.396.c752843dcf4-1.1
* libldb2-32bit 4.22.2+git.396.c752843dcf4-1.1
* python3-ldb 4.22.2+git.396.c752843dcf4-1.1
* python3-ldb-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba 4.22.2+git.396.c752843dcf4-1.1
* samba-ad-dc 4.22.2+git.396.c752843dcf4-1.1
* samba-ad-dc-libs 4.22.2+git.396.c752843dcf4-1.1
* samba-ad-dc-libs-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-ceph 4.22.2+git.396.c752843dcf4-1.1
* samba-client 4.22.2+git.396.c752843dcf4-1.1
* samba-client-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-client-libs 4.22.2+git.396.c752843dcf4-1.1
* samba-client-libs-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-dcerpc 4.22.2+git.396.c752843dcf4-1.1
* samba-devel 4.22.2+git.396.c752843dcf4-1.1
* samba-devel-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-doc 4.22.2+git.396.c752843dcf4-1.1
* samba-dsdb-modules 4.22.2+git.396.c752843dcf4-1.1
* samba-gpupdate 4.22.2+git.396.c752843dcf4-1.1
* samba-ldb-ldap 4.22.2+git.396.c752843dcf4-1.1
* samba-libs 4.22.2+git.396.c752843dcf4-1.1
* samba-libs-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-libs-python3 4.22.2+git.396.c752843dcf4-1.1
* samba-libs-python3-32bit 4.22.2+git.396.c752843dcf4-1.1
* samba-python3 4.22.2+git.396.c752843dcf4-1.1
* samba-test 4.22.2+git.396.c752843dcf4-1.1
* samba-tool 4.22.2+git.396.c752843dcf4-1.1
* samba-winbind 4.22.2+git.396.c752843dcf4-1.1
* samba-winbind-libs 4.22.2+git.396.c752843dcf4-1.1
* samba-winbind-libs-32bit 4.22.2+git.396.c752843dcf4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-0620.html



openSUSE-SU-2025:15294-1: moderate: keylime-ima-policy-0.2.7+70-2.1 on GA media


# keylime-ima-policy-0.2.7+70-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15294-1
Rating: moderate

Cross-References:

* CVE-2024-12224
* CVE-2024-43806

CVSS scores:

* CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2024-43806 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the keylime-ima-policy-0.2.7+70-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* keylime-ima-policy 0.2.7+70-2.1
* rust-keylime 0.2.7+70-2.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12224.html
* https://www.suse.com/security/cve/CVE-2024-43806.html



openSUSE-SU-2025:15270-1: moderate: python-furo-doc-2024.8.6-3.1 on GA media


# python-furo-doc-2024.8.6-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15270-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python-furo-doc-2024.8.6-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python-furo-doc 2024.8.6-3.1
* python311-furo 2024.8.6-3.1
* python312-furo 2024.8.6-3.1
* python313-furo 2024.8.6-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15261-1: moderate: perl-YAML-LibYAML-0.904.0-2.1 on GA media


# perl-YAML-LibYAML-0.904.0-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15261-1
Rating: moderate

Cross-References:

* CVE-2025-40908

CVSS scores:

* CVE-2025-40908 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-40908 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the perl-YAML-LibYAML-0.904.0-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl-YAML-LibYAML 0.904.0-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-40908.html



openSUSE-SU-2025:15292-1: moderate: radare2-5.9.8-3.1 on GA media


# radare2-5.9.8-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15292-1
Rating: moderate

Cross-References:

* CVE-2025-1744
* CVE-2025-1864
* CVE-2025-5641

CVSS scores:

* CVE-2025-1744 ( SUSE ): 10 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2025-1744 ( SUSE ): 10 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-5641 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-5641 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the radare2-5.9.8-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* radare2 5.9.8-3.1
* radare2-devel 5.9.8-3.1
* radare2-zsh-completion 5.9.8-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-1744.html
* https://www.suse.com/security/cve/CVE-2025-1864.html
* https://www.suse.com/security/cve/CVE-2025-5641.html



openSUSE-SU-2025:15267-1: moderate: python311-Django-5.2.2-1.1 on GA media


# python311-Django-5.2.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15267-1
Rating: moderate

Cross-References:

* CVE-2025-48432

CVSS scores:

* CVE-2025-48432 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2025-48432 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-Django-5.2.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-Django 5.2.2-1.1
* python312-Django 5.2.2-1.1
* python313-Django 5.2.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-48432.html



openSUSE-SU-2025:15290-1: moderate: python39-3.9.23-3.1 on GA media


# python39-3.9.23-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15290-1
Rating: moderate

Cross-References:

* CVE-2024-12718
* CVE-2025-4330
* CVE-2025-4517
* CVE-2025-6069

CVSS scores:

* CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python39-3.9.23-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python39 3.9.23-3.1
* python39-curses 3.9.23-3.1
* python39-dbm 3.9.23-3.1
* python39-idle 3.9.23-3.1
* python39-tk 3.9.23-3.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12718.html
* https://www.suse.com/security/cve/CVE-2025-4330.html
* https://www.suse.com/security/cve/CVE-2025-4517.html
* https://www.suse.com/security/cve/CVE-2025-6069.html



openSUSE-SU-2025:15285-1: moderate: python310-3.10.18-3.1 on GA media


# python310-3.10.18-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15285-1
Rating: moderate

Cross-References:

* CVE-2024-12718
* CVE-2025-4330
* CVE-2025-4517
* CVE-2025-6069

CVSS scores:

* CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python310-3.10.18-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python310 3.10.18-3.1
* python310-32bit 3.10.18-3.1
* python310-curses 3.10.18-3.1
* python310-dbm 3.10.18-3.1
* python310-idle 3.10.18-3.1
* python310-tk 3.10.18-3.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12718.html
* https://www.suse.com/security/cve/CVE-2025-4330.html
* https://www.suse.com/security/cve/CVE-2025-4517.html
* https://www.suse.com/security/cve/CVE-2025-6069.html



openSUSE-SU-2025:15266-1: moderate: pure-ftpd-1.0.51-5.1 on GA media


# pure-ftpd-1.0.51-5.1 on GA media

Announcement ID: openSUSE-SU-2025:15266-1
Rating: moderate

Cross-References:

* CVE-2024-48208

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the pure-ftpd-1.0.51-5.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* pure-ftpd 1.0.51-5.1

## References:

* https://www.suse.com/security/cve/CVE-2024-48208.html



openSUSE-SU-2025:15286-1: moderate: python311-3.11.13-2.1 on GA media


# python311-3.11.13-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15286-1
Rating: moderate

Cross-References:

* CVE-2024-12718
* CVE-2025-4330
* CVE-2025-4517

CVSS scores:

* CVE-2024-12718 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-4517 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4517 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python311-3.11.13-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311 3.11.13-2.1
* python311-32bit 3.11.13-2.1
* python311-curses 3.11.13-2.1
* python311-dbm 3.11.13-2.1
* python311-idle 3.11.13-2.1
* python311-tk 3.11.13-2.1
* python311-x86-64-v3 3.11.13-2.1

## References:

* https://www.suse.com/security/cve/CVE-2024-12718.html
* https://www.suse.com/security/cve/CVE-2025-4330.html
* https://www.suse.com/security/cve/CVE-2025-4517.html



openSUSE-SU-2025:15264-1: moderate: postgresql-jdbc-42.7.7-1.1 on GA media


# postgresql-jdbc-42.7.7-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15264-1
Rating: moderate

Cross-References:

* CVE-2025-49146

CVSS scores:

* CVE-2025-49146 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2025-49146 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the postgresql-jdbc-42.7.7-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* postgresql-jdbc 42.7.7-1.1
* postgresql-jdbc-javadoc 42.7.7-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49146.html



openSUSE-SU-2025:15265-1: moderate: libprotobuf-lite31_1_0-31.1-1.1 on GA media


# libprotobuf-lite31_1_0-31.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15265-1
Rating: moderate

Cross-References:

* CVE-2025-4565

CVSS scores:

* CVE-2025-4565 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-4565 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libprotobuf-lite31_1_0-31.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libprotobuf-lite31_1_0 31.1-1.1
* libprotobuf-lite31_1_0-32bit 31.1-1.1
* libprotobuf31_1_0 31.1-1.1
* libprotobuf31_1_0-32bit 31.1-1.1
* libprotoc31_1_0 31.1-1.1
* libprotoc31_1_0-32bit 31.1-1.1
* libutf8_range-31_1_0 31.1-1.1
* libutf8_range-31_1_0-32bit 31.1-1.1
* protobuf-devel 31.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4565.html



openSUSE-SU-2025:15278-1: moderate: jupyter-plotly-6.1.2-1.1 on GA media


# jupyter-plotly-6.1.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15278-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-plotly-6.1.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-plotly 6.1.2-1.1
* python311-plotly 6.1.2-1.1
* python312-plotly 6.1.2-1.1
* python313-plotly 6.1.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15271-1: moderate: jupyter-matplotlib-0.11.4-15.1 on GA media


# jupyter-matplotlib-0.11.4-15.1 on GA media

Announcement ID: openSUSE-SU-2025:15271-1
Rating: moderate

Cross-References:

* CVE-2025-5889

CVSS scores:

* CVE-2025-5889 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2025-5889 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-matplotlib-0.11.4-15.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-matplotlib 0.11.4-15.1
* jupyter-matplotlib-jupyterlab 0.11.4-15.1
* python311-ipympl 0.9.4-15.1
* python312-ipympl 0.9.4-15.1
* python313-ipympl 0.9.4-15.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5889.html



openSUSE-SU-2025:15263-1: moderate: polaris-9.6.4-1.1 on GA media


# polaris-9.6.4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15263-1
Rating: moderate

Cross-References:

* CVE-2025-22874

CVSS scores:

* CVE-2025-22874 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-22874 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the polaris-9.6.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* polaris 9.6.4-1.1
* polaris-bash-completion 9.6.4-1.1
* polaris-fish-completion 9.6.4-1.1
* polaris-zsh-completion 9.6.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22874.html



openSUSE-SU-2025:15258-1: moderate: perl-32bit-5.40.2-3.1 on GA media


# perl-32bit-5.40.2-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15258-1
Rating: moderate

Cross-References:

* CVE-2025-40909

CVSS scores:

* CVE-2025-40909 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the perl-32bit-5.40.2-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl 5.40.2-3.1
* perl-32bit 5.40.2-3.1
* perl-base 5.40.2-3.1
* perl-base-32bit 5.40.2-3.1
* perl-doc 5.40.2-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-40909.html



openSUSE-SU-2025:15260-1: moderate: perl-File-Find-Rule-0.350.0-1.1 on GA media


# perl-File-Find-Rule-0.350.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15260-1
Rating: moderate

Cross-References:

* CVE-2011-10007

CVSS scores:

* CVE-2011-10007 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2011-10007 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the perl-File-Find-Rule-0.350.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl-File-Find-Rule 0.350.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2011-10007.html



openSUSE-SU-2025:15247-1: moderate: moarvm-2025.05-1.1 on GA media


# moarvm-2025.05-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15247-1
Rating: moderate

Cross-References:

* CVE-2014-5461

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the moarvm-2025.05-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* moarvm 2025.05-1.1
* moarvm-devel 2025.05-1.1

## References:

* https://www.suse.com/security/cve/CVE-2014-5461.html



openSUSE-SU-2025:15259-1: moderate: perl-CryptX-0.87.0-1.1 on GA media


# perl-CryptX-0.87.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15259-1
Rating: moderate

Cross-References:

* CVE-2025-40914

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the perl-CryptX-0.87.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl-CryptX 0.87.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-40914.html



openSUSE-SU-2025:15254-1: moderate: openbao-2.3.1-1.1 on GA media


# openbao-2.3.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15254-1
Rating: moderate

Cross-References:

* CVE-2025-4656
* CVE-2025-52893
* CVE-2025-52894

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the openbao-2.3.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* openbao 2.3.1-1.1
* openbao-agent 2.3.1-1.1
* openbao-cassandra-database-plugin 2.3.1-1.1
* openbao-influxdb-database-plugin 2.3.1-1.1
* openbao-mysql-database-plugin 2.3.1-1.1
* openbao-mysql-legacy-database-plugin 2.3.1-1.1
* openbao-postgresql-database-plugin 2.3.1-1.1
* openbao-server 2.3.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4656.html
* https://www.suse.com/security/cve/CVE-2025-52893.html
* https://www.suse.com/security/cve/CVE-2025-52894.html



openSUSE-SU-2025:15262-1: moderate: podman-5.5.2-1.1 on GA media


# podman-5.5.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15262-1
Rating: moderate

Cross-References:

* CVE-2025-6032

CVSS scores:

* CVE-2025-6032 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2025-6032 ( SUSE ): 9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the podman-5.5.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* podman 5.5.2-1.1
* podman-docker 5.5.2-1.1
* podman-remote 5.5.2-1.1
* podmansh 5.5.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6032.html



openSUSE-SU-2025:15248-1: moderate: nix-2.29.1-1.1 on GA media


# nix-2.29.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15248-1
Rating: moderate

Cross-References:

* CVE-2025-46415
* CVE-2025-52991
* CVE-2025-52992
* CVE-2025-52993

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the nix-2.29.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* nix 2.29.1-1.1
* nix-bash-completion 2.29.1-1.1
* nix-devel 2.29.1-1.1
* nix-doc 2.29.1-1.1
* nix-fish-completion 2.29.1-1.1
* nix-zsh-completion 2.29.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-46415.html
* https://www.suse.com/security/cve/CVE-2025-52991.html
* https://www.suse.com/security/cve/CVE-2025-52992.html
* https://www.suse.com/security/cve/CVE-2025-52993.html



openSUSE-SU-2025:15257-1: moderate: pam_pkcs11-0.6.13-2.1 on GA media


# pam_pkcs11-0.6.13-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15257-1
Rating: moderate

Cross-References:

* CVE-2025-6018

CVSS scores:

* CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the pam_pkcs11-0.6.13-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* pam_pkcs11 0.6.13-2.1
* pam_pkcs11-devel-doc 0.6.13-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6018.html



openSUSE-SU-2025:15256-1: moderate: pam-1.7.1-1.1 on GA media


# pam-1.7.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15256-1
Rating: moderate

Cross-References:

* CVE-2025-6020

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the pam-1.7.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* pam 1.7.1-1.1
* pam-32bit 1.7.1-1.1
* pam-devel 1.7.1-1.1
* pam-devel-32bit 1.7.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6020.html



openSUSE-SU-2025:15242-1: moderate: libsoup-2_4-1-2.74.3-12.1 on GA media


# libsoup-2_4-1-2.74.3-12.1 on GA media

Announcement ID: openSUSE-SU-2025:15242-1
Rating: moderate

Cross-References:

* CVE-2025-4945

CVSS scores:

* CVE-2025-4945 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4945 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libsoup-2_4-1-2.74.3-12.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libsoup-2_4-1 2.74.3-12.1
* libsoup-2_4-1-32bit 2.74.3-12.1
* libsoup2-devel 2.74.3-12.1
* libsoup2-devel-32bit 2.74.3-12.1
* libsoup2-lang 2.74.3-12.1
* typelib-1_0-Soup-2_4 2.74.3-12.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4945.html



openSUSE-SU-2025:15255-1: moderate: ovmf-202505-2.1 on GA media


# ovmf-202505-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15255-1
Rating: moderate

Cross-References:

* CVE-2024-38797
* CVE-2024-38805

CVSS scores:

* CVE-2024-38797 ( SUSE ): 4.6 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
* CVE-2024-38797 ( SUSE ): 5.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ovmf-202505-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ovmf 202505-2.1
* ovmf-tools 202505-2.1
* qemu-ovmf-ia32 202505-2.1
* qemu-ovmf-x86_64 202505-2.1
* qemu-ovmf-x86_64-debug 202505-2.1
* qemu-uefi-aarch32 202505-2.1
* qemu-uefi-aarch64 202505-2.1
* qemu-uefi-riscv64 202505-2.1

## References:

* https://www.suse.com/security/cve/CVE-2024-38797.html
* https://www.suse.com/security/cve/CVE-2024-38805.html



openSUSE-SU-2025:15235-1: moderate: kubernetes1.31-apiserver-1.31.10-1.1 on GA media


# kubernetes1.31-apiserver-1.31.10-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15235-1
Rating: moderate

Cross-References:

* CVE-2025-22872

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the kubernetes1.31-apiserver-1.31.10-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* kubernetes1.31-apiserver 1.31.10-1.1
* kubernetes1.31-client 1.31.10-1.1
* kubernetes1.31-client-bash-completion 1.31.10-1.1
* kubernetes1.31-client-common 1.31.10-1.1
* kubernetes1.31-client-fish-completion 1.31.10-1.1
* kubernetes1.31-controller-manager 1.31.10-1.1
* kubernetes1.31-kubeadm 1.31.10-1.1
* kubernetes1.31-kubelet 1.31.10-1.1
* kubernetes1.31-kubelet-common 1.31.10-1.1
* kubernetes1.31-proxy 1.31.10-1.1
* kubernetes1.31-scheduler 1.31.10-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22872.html



openSUSE-SU-2025:15252-1: moderate: oci-cli-3.61.0-1.1 on GA media


# oci-cli-3.61.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15252-1
Rating: moderate

Cross-References:

* CVE-2024-53899

CVSS scores:

* CVE-2024-53899 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-53899 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the oci-cli-3.61.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* oci-cli 3.61.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-53899.html



openSUSE-SU-2025:15236-1: moderate: kubernetes1.32-apiserver-1.32.6-1.1 on GA media


# kubernetes1.32-apiserver-1.32.6-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15236-1
Rating: moderate

Cross-References:

* CVE-2025-22872

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the kubernetes1.32-apiserver-1.32.6-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* kubernetes1.32-apiserver 1.32.6-1.1
* kubernetes1.32-client 1.32.6-1.1
* kubernetes1.32-client-bash-completion 1.32.6-1.1
* kubernetes1.32-client-common 1.32.6-1.1
* kubernetes1.32-client-fish-completion 1.32.6-1.1
* kubernetes1.32-controller-manager 1.32.6-1.1
* kubernetes1.32-kubeadm 1.32.6-1.1
* kubernetes1.32-kubelet 1.32.6-1.1
* kubernetes1.32-kubelet-common 1.32.6-1.1
* kubernetes1.32-proxy 1.32.6-1.1
* kubernetes1.32-scheduler 1.32.6-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22872.html



openSUSE-SU-2025:15253-1: moderate: opa-1.6.0-1.1 on GA media


# opa-1.6.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15253-1
Rating: moderate

Cross-References:

* CVE-2025-22870
* CVE-2025-46569

CVSS scores:

* CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
* CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the opa-1.6.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* opa 1.6.0-1.1
* opa-bash-completion 1.6.0-1.1
* opa-fish-completion 1.6.0-1.1
* opa-zsh-completion 1.6.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22870.html
* https://www.suse.com/security/cve/CVE-2025-46569.html



openSUSE-SU-2025:15251-1: moderate: nova-3.11.4-1.1 on GA media


# nova-3.11.4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15251-1
Rating: moderate

Cross-References:

* CVE-2025-22874

CVSS scores:

* CVE-2025-22874 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-22874 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the nova-3.11.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* nova 3.11.4-1.1
* nova-bash-completion 3.11.4-1.1
* nova-fish-completion 3.11.4-1.1
* nova-zsh-completion 3.11.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22874.html



openSUSE-SU-2025:15233-1: moderate: jq-1.8.1-1.1 on GA media


# jq-1.8.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15233-1
Rating: moderate

Cross-References:

* CVE-2024-23337
* CVE-2025-48060
* CVE-2025-49014

CVSS scores:

* CVE-2024-23337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2024-23337 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-49014 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-49014 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the jq-1.8.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jq 1.8.1-1.1
* libjq-devel 1.8.1-1.1
* libjq1 1.8.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-23337.html
* https://www.suse.com/security/cve/CVE-2025-48060.html
* https://www.suse.com/security/cve/CVE-2025-49014.html



openSUSE-SU-2025:15250-1: moderate: corepack22-22.15.1-1.1 on GA media


# corepack22-22.15.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15250-1
Rating: moderate

Cross-References:

* CVE-2025-23165
* CVE-2025-23166

CVSS scores:

* CVE-2025-23165 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-23165 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-23166 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-23166 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the corepack22-22.15.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* corepack22 22.15.1-1.1
* nodejs22 22.15.1-1.1
* nodejs22-devel 22.15.1-1.1
* nodejs22-docs 22.15.1-1.1
* npm22 22.15.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-23165.html
* https://www.suse.com/security/cve/CVE-2025-23166.html



openSUSE-SU-2025:15234-1: moderate: kubernetes1.30-apiserver-1.30.14-1.1 on GA media


# kubernetes1.30-apiserver-1.30.14-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15234-1
Rating: moderate

Cross-References:

* CVE-2025-22872

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the kubernetes1.30-apiserver-1.30.14-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* kubernetes1.30-apiserver 1.30.14-1.1
* kubernetes1.30-client 1.30.14-1.1
* kubernetes1.30-client-bash-completion 1.30.14-1.1
* kubernetes1.30-client-common 1.30.14-1.1
* kubernetes1.30-client-fish-completion 1.30.14-1.1
* kubernetes1.30-controller-manager 1.30.14-1.1
* kubernetes1.30-kubeadm 1.30.14-1.1
* kubernetes1.30-kubelet 1.30.14-1.1
* kubernetes1.30-kubelet-common 1.30.14-1.1
* kubernetes1.30-proxy 1.30.14-1.1
* kubernetes1.30-scheduler 1.30.14-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22872.html



openSUSE-SU-2025:15232-1: moderate: jgit-5.11.0-2.1 on GA media


# jgit-5.11.0-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15232-1
Rating: moderate

Cross-References:

* CVE-2023-4759
* CVE-2025-4949

CVSS scores:

* CVE-2023-4759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-4949 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the jgit-5.11.0-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jgit 5.11.0-2.1
* jgit-javadoc 5.11.0-2.1

## References:

* https://www.suse.com/security/cve/CVE-2023-4759.html
* https://www.suse.com/security/cve/CVE-2025-4949.html



openSUSE-SU-2025:15249-1: moderate: nodejs-electron-35.6.0-1.2 on GA media


# nodejs-electron-35.6.0-1.2 on GA media

Announcement ID: openSUSE-SU-2025:15249-1
Rating: moderate

Cross-References:

* CVE-2025-5419

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the nodejs-electron-35.6.0-1.2 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* nodejs-electron 35.6.0-1.2
* nodejs-electron-devel 35.6.0-1.2
* nodejs-electron-doc 35.6.0-1.2

## References:

* https://www.suse.com/security/cve/CVE-2025-5419.html



openSUSE-SU-2025:15241-1: moderate: libsoup-3_0-0-3.6.5-6.1 on GA media


# libsoup-3_0-0-3.6.5-6.1 on GA media

Announcement ID: openSUSE-SU-2025:15241-1
Rating: moderate

Cross-References:

* CVE-2025-4945

CVSS scores:

* CVE-2025-4945 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2025-4945 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libsoup-3_0-0-3.6.5-6.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libsoup-3_0-0 3.6.5-6.1
* libsoup-3_0-0-32bit 3.6.5-6.1
* libsoup-devel 3.6.5-6.1
* libsoup-devel-32bit 3.6.5-6.1
* libsoup-lang 3.6.5-6.1
* typelib-1_0-Soup-3_0 3.6.5-6.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4945.html



openSUSE-SU-2025:15240-1: moderate: libQt5Bootstrap-devel-static-32bit-5.15.17+kde122-2.1 on GA media


# libQt5Bootstrap-devel-static-32bit-5.15.17+kde122-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15240-1
Rating: moderate

Cross-References:

* CVE-2025-5455

CVSS scores:

* CVE-2025-5455 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libQt5Bootstrap-devel-static-32bit-5.15.17+kde122-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libQt5Bootstrap-devel-static 5.15.17+kde122-2.1
* libQt5Bootstrap-devel-static-32bit 5.15.17+kde122-2.1
* libQt5Concurrent-devel 5.15.17+kde122-2.1
* libQt5Concurrent-devel-32bit 5.15.17+kde122-2.1
* libQt5Concurrent5 5.15.17+kde122-2.1
* libQt5Concurrent5-32bit 5.15.17+kde122-2.1
* libQt5Core-devel 5.15.17+kde122-2.1
* libQt5Core-devel-32bit 5.15.17+kde122-2.1
* libQt5Core-private-headers-devel 5.15.17+kde122-2.1
* libQt5Core5 5.15.17+kde122-2.1
* libQt5Core5-32bit 5.15.17+kde122-2.1
* libQt5DBus-devel 5.15.17+kde122-2.1
* libQt5DBus-devel-32bit 5.15.17+kde122-2.1
* libQt5DBus-private-headers-devel 5.15.17+kde122-2.1
* libQt5DBus5 5.15.17+kde122-2.1
* libQt5DBus5-32bit 5.15.17+kde122-2.1
* libQt5Gui-devel 5.15.17+kde122-2.1
* libQt5Gui-devel-32bit 5.15.17+kde122-2.1
* libQt5Gui-private-headers-devel 5.15.17+kde122-2.1
* libQt5Gui5 5.15.17+kde122-2.1
* libQt5Gui5-32bit 5.15.17+kde122-2.1
* libQt5KmsSupport-devel-static 5.15.17+kde122-2.1
* libQt5KmsSupport-private-headers-devel 5.15.17+kde122-2.1
* libQt5Network-devel 5.15.17+kde122-2.1
* libQt5Network-devel-32bit 5.15.17+kde122-2.1
* libQt5Network-private-headers-devel 5.15.17+kde122-2.1
* libQt5Network5 5.15.17+kde122-2.1
* libQt5Network5-32bit 5.15.17+kde122-2.1
* libQt5OpenGL-devel 5.15.17+kde122-2.1
* libQt5OpenGL-devel-32bit 5.15.17+kde122-2.1
* libQt5OpenGL-private-headers-devel 5.15.17+kde122-2.1
* libQt5OpenGL5 5.15.17+kde122-2.1
* libQt5OpenGL5-32bit 5.15.17+kde122-2.1
* libQt5OpenGLExtensions-devel-static 5.15.17+kde122-2.1
* libQt5OpenGLExtensions-devel-static-32bit 5.15.17+kde122-2.1
* libQt5PlatformHeaders-devel 5.15.17+kde122-2.1
* libQt5PlatformSupport-devel-static 5.15.17+kde122-2.1
* libQt5PlatformSupport-devel-static-32bit 5.15.17+kde122-2.1
* libQt5PlatformSupport-private-headers-devel 5.15.17+kde122-2.1
* libQt5PrintSupport-devel 5.15.17+kde122-2.1
* libQt5PrintSupport-devel-32bit 5.15.17+kde122-2.1
* libQt5PrintSupport-private-headers-devel 5.15.17+kde122-2.1
* libQt5PrintSupport5 5.15.17+kde122-2.1
* libQt5PrintSupport5-32bit 5.15.17+kde122-2.1
* libQt5Sql-devel 5.15.17+kde122-2.1
* libQt5Sql-devel-32bit 5.15.17+kde122-2.1
* libQt5Sql-private-headers-devel 5.15.17+kde122-2.1
* libQt5Sql5 5.15.17+kde122-2.1
* libQt5Sql5-32bit 5.15.17+kde122-2.1
* libQt5Sql5-mysql 5.15.17+kde122-2.1
* libQt5Sql5-mysql-32bit 5.15.17+kde122-2.1
* libQt5Sql5-postgresql 5.15.17+kde122-2.1
* libQt5Sql5-postgresql-32bit 5.15.17+kde122-2.1
* libQt5Sql5-sqlite 5.15.17+kde122-2.1
* libQt5Sql5-sqlite-32bit 5.15.17+kde122-2.1
* libQt5Sql5-unixODBC 5.15.17+kde122-2.1
* libQt5Sql5-unixODBC-32bit 5.15.17+kde122-2.1
* libQt5Test-devel 5.15.17+kde122-2.1
* libQt5Test-devel-32bit 5.15.17+kde122-2.1
* libQt5Test-private-headers-devel 5.15.17+kde122-2.1
* libQt5Test5 5.15.17+kde122-2.1
* libQt5Test5-32bit 5.15.17+kde122-2.1
* libQt5Widgets-devel 5.15.17+kde122-2.1
* libQt5Widgets-devel-32bit 5.15.17+kde122-2.1
* libQt5Widgets-private-headers-devel 5.15.17+kde122-2.1
* libQt5Widgets5 5.15.17+kde122-2.1
* libQt5Widgets5-32bit 5.15.17+kde122-2.1
* libQt5Xml-devel 5.15.17+kde122-2.1
* libQt5Xml-devel-32bit 5.15.17+kde122-2.1
* libQt5Xml5 5.15.17+kde122-2.1
* libQt5Xml5-32bit 5.15.17+kde122-2.1
* libqt5-qtbase-common-devel 5.15.17+kde122-2.1
* libqt5-qtbase-devel 5.15.17+kde122-2.1
* libqt5-qtbase-examples 5.15.17+kde122-2.1
* libqt5-qtbase-examples-32bit 5.15.17+kde122-2.1
* libqt5-qtbase-platformtheme-gtk3 5.15.17+kde122-2.1
* libqt5-qtbase-platformtheme-xdgdesktopportal 5.15.17+kde122-2.1
* libqt5-qtbase-private-headers-devel 5.15.17+kde122-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5455.html



openSUSE-SU-2025:15237-1: moderate: libbd_btrfs-devel-3.1.1-2.1 on GA media


# libbd_btrfs-devel-3.1.1-2.1 on GA media

Announcement ID: openSUSE-SU-2025:15237-1
Rating: moderate

Cross-References:

* CVE-2025-6019

CVSS scores:

* CVE-2025-6019 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-6019 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libbd_btrfs-devel-3.1.1-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libbd_btrfs-devel 3.1.1-2.1
* libbd_btrfs3 3.1.1-2.1
* libbd_crypto-devel 3.1.1-2.1
* libbd_crypto3 3.1.1-2.1
* libbd_dm-devel 3.1.1-2.1
* libbd_dm3 3.1.1-2.1
* libbd_fs-devel 3.1.1-2.1
* libbd_fs3 3.1.1-2.1
* libbd_loop-devel 3.1.1-2.1
* libbd_loop3 3.1.1-2.1
* libbd_lvm-dbus-devel 3.1.1-2.1
* libbd_lvm-dbus3 3.1.1-2.1
* libbd_lvm-devel 3.1.1-2.1
* libbd_lvm3 3.1.1-2.1
* libbd_mdraid-devel 3.1.1-2.1
* libbd_mdraid3 3.1.1-2.1
* libbd_mpath-devel 3.1.1-2.1
* libbd_mpath3 3.1.1-2.1
* libbd_nvme-devel 3.1.1-2.1
* libbd_nvme3 3.1.1-2.1
* libbd_part-devel 3.1.1-2.1
* libbd_part3 3.1.1-2.1
* libbd_swap-devel 3.1.1-2.1
* libbd_swap3 3.1.1-2.1
* libbd_utils-devel 3.1.1-2.1
* libbd_utils3 3.1.1-2.1
* libblockdev 3.1.1-2.1
* libblockdev-devel 3.1.1-2.1
* libblockdev3 3.1.1-2.1
* python3-libblockdev 3.1.1-2.1
* typelib-1_0-BlockDev-3_0 3.1.1-2.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6019.html



openSUSE-SU-2025:15227-1: moderate: grype-0.94.0-1.1 on GA media


# grype-0.94.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15227-1
Rating: moderate

Cross-References:

* CVE-2025-5702

CVSS scores:

* CVE-2025-5702 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-5702 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the grype-0.94.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* grype 0.94.0-1.1
* grype-bash-completion 0.94.0-1.1
* grype-fish-completion 0.94.0-1.1
* grype-zsh-completion 0.94.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5702.html



openSUSE-SU-2025:15229-1: moderate: himmelblau-0.9.17+git.0.4a97692-1.1 on GA media


# himmelblau-0.9.17+git.0.4a97692-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15229-1
Rating: moderate

Cross-References:

* CVE-2025-53013

CVSS scores:

* CVE-2025-53013 ( SUSE ): 5.2 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2025-53013 ( SUSE ): 4.3 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the himmelblau-0.9.17+git.0.4a97692-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* himmelblau 0.9.17+git.0.4a97692-1.1
* himmelblau-qr-greeter 0.9.17+git.0.4a97692-1.1
* himmelblau-sshd-config 0.9.17+git.0.4a97692-1.1
* himmelblau-sso 0.9.17+git.0.4a97692-1.1
* libnss_himmelblau2 0.9.17+git.0.4a97692-1.1
* pam-himmelblau 0.9.17+git.0.4a97692-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-53013.html



openSUSE-SU-2025:15228-1: moderate: helm-3.18.3-1.1 on GA media


# helm-3.18.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15228-1
Rating: moderate

Cross-References:

* CVE-2025-22872

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the helm-3.18.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* helm 3.18.3-1.1
* helm-bash-completion 3.18.3-1.1
* helm-fish-completion 3.18.3-1.1
* helm-zsh-completion 3.18.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22872.html



openSUSE-SU-2025:15226-1: moderate: grafana-11.6.3-1.1 on GA media


# grafana-11.6.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15226-1
Rating: moderate

Cross-References:

* CVE-2025-1088
* CVE-2025-3415

CVSS scores:

* CVE-2025-1088 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-1088 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-3415 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2025-3415 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the grafana-11.6.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* grafana 11.6.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-1088.html
* https://www.suse.com/security/cve/CVE-2025-3415.html



openSUSE-SU-2025:15230-1: moderate: icu-77.1-3.1 on GA media


# icu-77.1-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15230-1
Rating: moderate

Cross-References:

* CVE-2025-5222

CVSS scores:

* CVE-2025-5222 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the icu-77.1-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* icu 77.1-3.1
* libicu-devel 77.1-3.1
* libicu-devel-32bit 77.1-3.1
* libicu-doc 77.1-3.1
* libicu77 77.1-3.1
* libicu77-32bit 77.1-3.1
* libicu77-bedata 77.1-3.1
* libicu77-ledata 77.1-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5222.html



openSUSE-SU-2025:15220-1: moderate: git-lfs-3.7.0-1.1 on GA media


# git-lfs-3.7.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15220-1
Rating: moderate

Cross-References:

* CVE-2025-22869

CVSS scores:

* CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the git-lfs-3.7.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* git-lfs 3.7.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22869.html



openSUSE-SU-2025:15224-1: moderate: go1.24-1.24.4-1.1 on GA media


# go1.24-1.24.4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15224-1
Rating: moderate

Cross-References:

* CVE-2025-0913
* CVE-2025-22874
* CVE-2025-4673

CVSS scores:

* CVE-2025-0913 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-0913 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-22874 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-22874 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the go1.24-1.24.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* go1.24 1.24.4-1.1
* go1.24-doc 1.24.4-1.1
* go1.24-libstd 1.24.4-1.1
* go1.24-race 1.24.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-0913.html
* https://www.suse.com/security/cve/CVE-2025-22874.html
* https://www.suse.com/security/cve/CVE-2025-4673.html



openSUSE-SU-2025:15222-1: moderate: glibc-2.41-3.1 on GA media


# glibc-2.41-3.1 on GA media

Announcement ID: openSUSE-SU-2025:15222-1
Rating: moderate

Cross-References:

* CVE-2025-4802
* CVE-2025-5745

CVSS scores:

* CVE-2025-4802 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-4802 ( SUSE ): 9.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2025-5745 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-5745 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the glibc-2.41-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* glibc 2.41-3.1
* glibc-devel 2.41-3.1
* glibc-devel-static 2.41-3.1
* glibc-extra 2.41-3.1
* glibc-gconv-modules-extra 2.41-3.1
* glibc-html 2.41-3.1
* glibc-i18ndata 2.41-3.1
* glibc-info 2.41-3.1
* glibc-lang 2.41-3.1
* glibc-locale 2.41-3.1
* glibc-locale-base 2.41-3.1
* glibc-profile 2.41-3.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4802.html
* https://www.suse.com/security/cve/CVE-2025-5745.html



openSUSE-SU-2025:15221-1: moderate: gio-branding-upstream-2.84.3-1.1 on GA media


# gio-branding-upstream-2.84.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15221-1
Rating: moderate

Cross-References:

* CVE-2025-6052

CVSS scores:

* CVE-2025-6052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-6052 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the gio-branding-upstream-2.84.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* gio-branding-upstream 2.84.3-1.1
* glib2-devel 2.84.3-1.1
* glib2-devel-32bit 2.84.3-1.1
* glib2-devel-static 2.84.3-1.1
* glib2-lang 2.84.3-1.1
* glib2-tests-devel 2.84.3-1.1
* glib2-tools 2.84.3-1.1
* glib2-tools-32bit 2.84.3-1.1
* libgio-2_0-0 2.84.3-1.1
* libgio-2_0-0-32bit 2.84.3-1.1
* libgirepository-2_0-0 2.84.3-1.1
* libglib-2_0-0 2.84.3-1.1
* libglib-2_0-0-32bit 2.84.3-1.1
* libgmodule-2_0-0 2.84.3-1.1
* libgmodule-2_0-0-32bit 2.84.3-1.1
* libgobject-2_0-0 2.84.3-1.1
* libgobject-2_0-0-32bit 2.84.3-1.1
* libgthread-2_0-0 2.84.3-1.1
* libgthread-2_0-0-32bit 2.84.3-1.1
* typelib-1_0-GIRepository-3_0 2.84.3-1.1
* typelib-1_0-GLib-2_0 2.84.3-1.1
* typelib-1_0-GLibUnix-2_0 2.84.3-1.1
* typelib-1_0-GModule-2_0 2.84.3-1.1
* typelib-1_0-GObject-2_0 2.84.3-1.1
* typelib-1_0-Gio-2_0 2.84.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6052.html



openSUSE-SU-2025:15218-1: moderate: fractal-11.2-1.1 on GA media


# fractal-11.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15218-1
Rating: moderate

Cross-References:

* CVE-2025-48937

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the fractal-11.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* fractal 11.2-1.1
* fractal-lang 11.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-48937.html



openSUSE-SU-2025:15225-1: moderate: govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media


# govulncheck-vulndb-0.0.20250612T141001-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15225-1
Rating: moderate

Cross-References:

* CVE-2020-36846
* CVE-2022-31022
* CVE-2023-42818
* CVE-2025-0913
* CVE-2025-1792
* CVE-2025-22874
* CVE-2025-25207
* CVE-2025-25208
* CVE-2025-2571
* CVE-2025-29785
* CVE-2025-3230
* CVE-2025-3260
* CVE-2025-3454
* CVE-2025-3611
* CVE-2025-3913
* CVE-2025-4128
* CVE-2025-4573
* CVE-2025-4673
* CVE-2025-47950
* CVE-2025-48494
* CVE-2025-48495
* CVE-2025-48710
* CVE-2025-48865
* CVE-2025-48938
* CVE-2025-48948
* CVE-2025-48949
* CVE-2025-49011
* CVE-2025-49136
* CVE-2025-49140

CVSS scores:

* CVE-2025-0913 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-0913 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-22874 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-22874 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-29785 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-29785 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-3260 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2025-3454 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2025-47950 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-47950 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 29 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the govulncheck-vulndb-0.0.20250612T141001-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* govulncheck-vulndb 0.0.20250612T141001-1.1

## References:

* https://www.suse.com/security/cve/CVE-2020-36846.html
* https://www.suse.com/security/cve/CVE-2022-31022.html
* https://www.suse.com/security/cve/CVE-2023-42818.html
* https://www.suse.com/security/cve/CVE-2025-0913.html
* https://www.suse.com/security/cve/CVE-2025-1792.html
* https://www.suse.com/security/cve/CVE-2025-22874.html
* https://www.suse.com/security/cve/CVE-2025-25207.html
* https://www.suse.com/security/cve/CVE-2025-25208.html
* https://www.suse.com/security/cve/CVE-2025-2571.html
* https://www.suse.com/security/cve/CVE-2025-29785.html
* https://www.suse.com/security/cve/CVE-2025-3230.html
* https://www.suse.com/security/cve/CVE-2025-3260.html
* https://www.suse.com/security/cve/CVE-2025-3454.html
* https://www.suse.com/security/cve/CVE-2025-3611.html
* https://www.suse.com/security/cve/CVE-2025-3913.html
* https://www.suse.com/security/cve/CVE-2025-4128.html
* https://www.suse.com/security/cve/CVE-2025-4573.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2025-47950.html
* https://www.suse.com/security/cve/CVE-2025-48494.html
* https://www.suse.com/security/cve/CVE-2025-48495.html
* https://www.suse.com/security/cve/CVE-2025-48710.html
* https://www.suse.com/security/cve/CVE-2025-48865.html
* https://www.suse.com/security/cve/CVE-2025-48938.html
* https://www.suse.com/security/cve/CVE-2025-48948.html
* https://www.suse.com/security/cve/CVE-2025-48949.html
* https://www.suse.com/security/cve/CVE-2025-49011.html
* https://www.suse.com/security/cve/CVE-2025-49136.html
* https://www.suse.com/security/cve/CVE-2025-49140.html



openSUSE-SU-2025:15223-1: moderate: go1.23-1.23.10-1.1 on GA media


# go1.23-1.23.10-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15223-1
Rating: moderate

Cross-References:

* CVE-2025-0913
* CVE-2025-4673

CVSS scores:

* CVE-2025-0913 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2025-0913 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the go1.23-1.23.10-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* go1.23 1.23.10-1.1
* go1.23-doc 1.23.10-1.1
* go1.23-libstd 1.23.10-1.1
* go1.23-race 1.23.10-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-0913.html
* https://www.suse.com/security/cve/CVE-2025-4673.html



openSUSE-SU-2025:15211-1: moderate: clamav-1.4.3-1.1 on GA media


# clamav-1.4.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15211-1
Rating: moderate

Cross-References:

* CVE-2025-20234
* CVE-2025-20260

CVSS scores:

* CVE-2025-20234 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-20234 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-20260 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the clamav-1.4.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* clamav 1.4.3-1.1
* clamav-devel 1.4.3-1.1
* clamav-docs-html 1.4.3-1.1
* clamav-milter 1.4.3-1.1
* libclamav12 1.4.3-1.1
* libclammspack0 1.4.3-1.1
* libfreshclam3 1.4.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-20234.html
* https://www.suse.com/security/cve/CVE-2025-20260.html



openSUSE-SU-2025:15215-1: moderate: ffmpeg-4-4.4.6-4.1 on GA media


# ffmpeg-4-4.4.6-4.1 on GA media

Announcement ID: openSUSE-SU-2025:15215-1
Rating: moderate

Cross-References:

* CVE-2022-1475
* CVE-2024-36616
* CVE-2024-36617
* CVE-2024-36618

CVSS scores:

* CVE-2022-1475 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2024-36616 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2024-36616 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2024-36617 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2024-36617 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2024-36618 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2024-36618 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ffmpeg-4-4.4.6-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ffmpeg-4 4.4.6-4.1
* ffmpeg-4-libavcodec-devel 4.4.6-4.1
* ffmpeg-4-libavdevice-devel 4.4.6-4.1
* ffmpeg-4-libavfilter-devel 4.4.6-4.1
* ffmpeg-4-libavformat-devel 4.4.6-4.1
* ffmpeg-4-libavresample-devel 4.4.6-4.1
* ffmpeg-4-libavutil-devel 4.4.6-4.1
* ffmpeg-4-libpostproc-devel 4.4.6-4.1
* ffmpeg-4-libswresample-devel 4.4.6-4.1
* ffmpeg-4-libswscale-devel 4.4.6-4.1
* ffmpeg-4-private-devel 4.4.6-4.1
* libavcodec58_134 4.4.6-4.1
* libavcodec58_134-32bit 4.4.6-4.1
* libavdevice58_13 4.4.6-4.1
* libavdevice58_13-32bit 4.4.6-4.1
* libavfilter7_110 4.4.6-4.1
* libavfilter7_110-32bit 4.4.6-4.1
* libavformat58_76 4.4.6-4.1
* libavformat58_76-32bit 4.4.6-4.1
* libavresample4_0 4.4.6-4.1
* libavresample4_0-32bit 4.4.6-4.1
* libavutil56_70 4.4.6-4.1
* libavutil56_70-32bit 4.4.6-4.1
* libpostproc55_9 4.4.6-4.1
* libpostproc55_9-32bit 4.4.6-4.1
* libswresample3_9 4.4.6-4.1
* libswresample3_9-32bit 4.4.6-4.1
* libswscale5_9 4.4.6-4.1
* libswscale5_9-32bit 4.4.6-4.1

## References:

* https://www.suse.com/security/cve/CVE-2022-1475.html
* https://www.suse.com/security/cve/CVE-2024-36616.html
* https://www.suse.com/security/cve/CVE-2024-36617.html
* https://www.suse.com/security/cve/CVE-2024-36618.html



openSUSE-SU-2025:15210-1: moderate: chromedriver-138.0.7204.96-1.1 on GA media


# chromedriver-138.0.7204.96-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15210-1
Rating: moderate

Cross-References:

* CVE-2025-5063
* CVE-2025-5064
* CVE-2025-5065
* CVE-2025-5066
* CVE-2025-5067
* CVE-2025-5068
* CVE-2025-5280
* CVE-2025-5281
* CVE-2025-5283
* CVE-2025-5419
* CVE-2025-5958
* CVE-2025-5959
* CVE-2025-6191
* CVE-2025-6192
* CVE-2025-6554
* CVE-2025-6555
* CVE-2025-6556
* CVE-2025-6557

CVSS scores:

* CVE-2025-5958 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-5959 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 18 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-138.0.7204.96-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 138.0.7204.96-1.1
* chromium 138.0.7204.96-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5063.html
* https://www.suse.com/security/cve/CVE-2025-5064.html
* https://www.suse.com/security/cve/CVE-2025-5065.html
* https://www.suse.com/security/cve/CVE-2025-5066.html
* https://www.suse.com/security/cve/CVE-2025-5067.html
* https://www.suse.com/security/cve/CVE-2025-5068.html
* https://www.suse.com/security/cve/CVE-2025-5280.html
* https://www.suse.com/security/cve/CVE-2025-5281.html
* https://www.suse.com/security/cve/CVE-2025-5283.html
* https://www.suse.com/security/cve/CVE-2025-5419.html
* https://www.suse.com/security/cve/CVE-2025-5958.html
* https://www.suse.com/security/cve/CVE-2025-5959.html
* https://www.suse.com/security/cve/CVE-2025-6191.html
* https://www.suse.com/security/cve/CVE-2025-6192.html
* https://www.suse.com/security/cve/CVE-2025-6554.html
* https://www.suse.com/security/cve/CVE-2025-6555.html
* https://www.suse.com/security/cve/CVE-2025-6556.html
* https://www.suse.com/security/cve/CVE-2025-6557.html



openSUSE-SU-2025:15213-1: moderate: curl-8.14.1-4.1 on GA media


# curl-8.14.1-4.1 on GA media

Announcement ID: openSUSE-SU-2025:15213-1
Rating: moderate

Cross-References:

* CVE-2025-5399

CVSS scores:

* CVE-2025-5399 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2025-5399 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the curl-8.14.1-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* curl 8.14.1-4.1
* curl-fish-completion 8.14.1-4.1
* curl-zsh-completion 8.14.1-4.1
* libcurl-devel 8.14.1-4.1
* libcurl-devel-32bit 8.14.1-4.1
* libcurl-devel-doc 8.14.1-4.1
* libcurl4 8.14.1-4.1
* libcurl4-32bit 8.14.1-4.1
* wcurl 8.14.1-4.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5399.html



openSUSE-SU-2025:15219-1: moderate: gdm-48.0-10.1 on GA media


# gdm-48.0-10.1 on GA media

Announcement ID: openSUSE-SU-2025:15219-1
Rating: moderate

Cross-References:

* CVE-2025-6018

CVSS scores:

* CVE-2025-6018 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-6018 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the gdm-48.0-10.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* gdm 48.0-10.1
* gdm-branding-upstream 48.0-10.1
* gdm-devel 48.0-10.1
* gdm-lang 48.0-10.1
* gdm-schema 48.0-10.1
* gdm-systemd 48.0-10.1
* gdm-xdm-integration 48.0-10.1
* gdmflexiserver 48.0-10.1
* libgdm1 48.0-10.1
* typelib-1_0-Gdm-1_0 48.0-10.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6018.html



openSUSE-SU-2025:15216-1: moderate: firefox-esr-128.12.0-1.1 on GA media


# firefox-esr-128.12.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15216-1
Rating: moderate

Cross-References:

* CVE-2025-6424
* CVE-2025-6425
* CVE-2025-6426
* CVE-2025-6429
* CVE-2025-6430

CVSS scores:

* CVE-2025-6424 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2025-6424 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-6425 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2025-6425 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-6426 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:L
* CVE-2025-6426 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L
* CVE-2025-6429 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2025-6429 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-6430 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2025-6430 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the firefox-esr-128.12.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* firefox-esr 128.12.0-1.1
* firefox-esr-branding-upstream 128.12.0-1.1
* firefox-esr-translations-common 128.12.0-1.1
* firefox-esr-translations-other 128.12.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-6424.html
* https://www.suse.com/security/cve/CVE-2025-6425.html
* https://www.suse.com/security/cve/CVE-2025-6426.html
* https://www.suse.com/security/cve/CVE-2025-6429.html
* https://www.suse.com/security/cve/CVE-2025-6430.html



openSUSE-SU-2025:15209-1: moderate: assimp-devel-6.0.2-1.1 on GA media


# assimp-devel-6.0.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15209-1
Rating: moderate

Cross-References:

* CVE-2025-2750
* CVE-2025-2751
* CVE-2025-2757
* CVE-2025-3158
* CVE-2025-3548

CVSS scores:

* CVE-2025-3158 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2025-3158 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-3548 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the assimp-devel-6.0.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* assimp-devel 6.0.2-1.1
* libassimp6 6.0.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-2750.html
* https://www.suse.com/security/cve/CVE-2025-2751.html
* https://www.suse.com/security/cve/CVE-2025-2757.html
* https://www.suse.com/security/cve/CVE-2025-3158.html
* https://www.suse.com/security/cve/CVE-2025-3548.html



openSUSE-SU-2025:15212-1: moderate: clustershell-1.9.3-1.1 on GA media


# clustershell-1.9.3-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15212-1
Rating: moderate

Cross-References:

* CVE-2023-52425

CVSS scores:

* CVE-2023-52425 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the clustershell-1.9.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* clustershell 1.9.3-1.1
* python3-clustershell 1.9.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2023-52425.html



openSUSE-SU-2025:15208-1: moderate: apache-commons-fileupload-1.6.0-1.1 on GA media


# apache-commons-fileupload-1.6.0-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15208-1
Rating: moderate

Cross-References:

* CVE-2025-48976

CVSS scores:

* CVE-2025-48976 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-48976 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the apache-commons-fileupload-1.6.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* apache-commons-fileupload 1.6.0-1.1
* apache-commons-fileupload-javadoc 1.6.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-48976.html



openSUSE-SU-2025:15203-1: moderate: MozillaFirefox-139.0.4-1.1 on GA media


# MozillaFirefox-139.0.4-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15203-1
Rating: moderate

Cross-References:

* CVE-2025-49709
* CVE-2025-49710

CVSS scores:

* CVE-2025-49709 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2025-49710 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the MozillaFirefox-139.0.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* MozillaFirefox 139.0.4-1.1
* MozillaFirefox-branding-upstream 139.0.4-1.1
* MozillaFirefox-devel 139.0.4-1.1
* MozillaFirefox-translations-common 139.0.4-1.1
* MozillaFirefox-translations-other 139.0.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49709.html
* https://www.suse.com/security/cve/CVE-2025-49710.html



openSUSE-SU-2025:15207-1: moderate: alloy-1.9.1-1.1 on GA media


# alloy-1.9.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15207-1
Rating: moderate

Cross-References:

* CVE-2025-22872
* CVE-2025-46327

CVSS scores:

* CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
* CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L
* CVE-2025-46327 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the alloy-1.9.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* alloy 1.9.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-22872.html
* https://www.suse.com/security/cve/CVE-2025-46327.html



openSUSE-SU-2025:15244-1: moderate: libtpms-devel-0.10.1-1.1 on GA media


# libtpms-devel-0.10.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15244-1
Rating: moderate

Cross-References:

* CVE-2025-49133

CVSS scores:

* CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libtpms-devel-0.10.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libtpms-devel 0.10.1-1.1
* libtpms0 0.10.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-49133.html



openSUSE-SU-2025:15243-1: moderate: libssh-config-0.11.2-1.1 on GA media


# libssh-config-0.11.2-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15243-1
Rating: moderate

Cross-References:

* CVE-2025-4877
* CVE-2025-4878
* CVE-2025-5318
* CVE-2025-5351
* CVE-2025-5372
* CVE-2025-5449
* CVE-2025-5987

CVSS scores:

* CVE-2025-4877 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2025-4877 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2025-4878 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-4878 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-5318 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2025-5318 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2025-5351 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2025-5351 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2025-5372 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
* CVE-2025-5372 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2025-5449 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-5449 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-5987 ( SUSE ): 5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2025-5987 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libssh-config-0.11.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libssh-config 0.11.2-1.1
* libssh-devel 0.11.2-1.1
* libssh4 0.11.2-1.1
* libssh4-32bit 0.11.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-4877.html
* https://www.suse.com/security/cve/CVE-2025-4878.html
* https://www.suse.com/security/cve/CVE-2025-5318.html
* https://www.suse.com/security/cve/CVE-2025-5351.html
* https://www.suse.com/security/cve/CVE-2025-5372.html
* https://www.suse.com/security/cve/CVE-2025-5449.html
* https://www.suse.com/security/cve/CVE-2025-5987.html



openSUSE-SU-2025:15291-1: moderate: erlang-rabbitmq-client-3.13.7-4.1 on GA media


# erlang-rabbitmq-client-3.13.7-4.1 on GA media

Announcement ID: openSUSE-SU-2025:15291-1
Rating: moderate

Cross-References:

* CVE-2025-30219

CVSS scores:

* CVE-2025-30219 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L
* CVE-2025-30219 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the erlang-rabbitmq-client-3.13.7-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* erlang-rabbitmq-client 3.13.7-4.1
* rabbitmq-server 3.13.7-4.1
* rabbitmq-server-bash-completion 3.13.7-4.1
* rabbitmq-server-plugins 3.13.7-4.1
* rabbitmq-server-zsh-completion 3.13.7-4.1

## References:

* https://www.suse.com/security/cve/CVE-2025-30219.html