drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in grub2
| Name: |
Mehrere Probleme in grub2 |
|
| ID: |
SUSE-SU-2025:20511-1 |
|
| Distribution: |
SUSE |
|
| Plattformen: |
SUSE Linux Micro 6.0 |
|
| Datum: |
Mo, 4. August 2025, 22:12 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-45780
https://www.cve.org/CVERecord?id=CVE-2025-0686
https://www.cve.org/CVERecord?id=CVE-2025-0689
https://www.cve.org/CVERecord?id=CVE-2025-0622
https://www.cve.org/CVERecord?id=CVE-2025-0624
https://www.cve.org/CVERecord?id=CVE-2025-0677
https://www.cve.org/CVERecord?id=CVE-2024-56737
https://www.cve.org/CVERecord?id=CVE-2024-45779
https://www.cve.org/CVERecord?id=CVE-2024-45781
https://www.cve.org/CVERecord?id=CVE-2024-49504
https://www.cve.org/CVERecord?id=CVE-2025-1118
https://www.cve.org/CVERecord?id=CVE-2024-45774
https://www.cve.org/CVERecord?id=CVE-2025-0685
https://www.cve.org/CVERecord?id=CVE-2025-0678
https://www.cve.org/CVERecord?id=CVE-2025-0690
https://www.cve.org/CVERecord?id=CVE-2024-45775
https://www.cve.org/CVERecord?id=CVE-2024-45778
https://www.cve.org/CVERecord?id=CVE-2024-45777
https://www.cve.org/CVERecord?id=CVE-2024-45776
https://www.cve.org/CVERecord?id=CVE-2025-1125
https://www.cve.org/CVERecord?id=CVE-2025-4382
https://www.cve.org/CVERecord?id=CVE-2024-45783
https://www.cve.org/CVERecord?id=CVE-2024-45782
https://www.cve.org/CVERecord?id=CVE-2025-0684 |
|
| Applikationen: |
GRUB |
|
Originalnachricht |
--===============6753930878272948610== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit
# Security update for grub2
Announcement ID: SUSE-SU-2025:20511-1 Release Date: 2025-07-29T08:22:13Z Rating: important References:
* bsc#1229163 * bsc#1229164 * bsc#1233606 * bsc#1233608 * bsc#1233609 * bsc#1233610 * bsc#1233612 * bsc#1233613 * bsc#1233614 * bsc#1233615 * bsc#1233616 * bsc#1233617 * bsc#1234958 * bsc#1236316 * bsc#1236317 * bsc#1237002 * bsc#1237006 * bsc#1237008 * bsc#1237009 * bsc#1237010 * bsc#1237011 * bsc#1237012 * bsc#1237013 * bsc#1237014 * bsc#1239674 * bsc#1242971
Cross-References:
* CVE-2024-45774 * CVE-2024-45775 * CVE-2024-45776 * CVE-2024-45777 * CVE-2024-45778 * CVE-2024-45779 * CVE-2024-45780 * CVE-2024-45781 * CVE-2024-45782 * CVE-2024-45783 * CVE-2024-49504 * CVE-2024-56737 * CVE-2025-0622 * CVE-2025-0624 * CVE-2025-0677 * CVE-2025-0678 * CVE-2025-0684 * CVE-2025-0685 * CVE-2025-0686 * CVE-2025-0689 * CVE-2025-0690 * CVE-2025-1118 * CVE-2025-1125 * CVE-2025-4382
CVSS scores:
* CVE-2024-45774 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45774 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45775 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45775 ( NVD ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2024-45776 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45776 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45777 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45777 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45778 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2024-45778 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45778 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45779 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45779 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2024-45779 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2024-45780 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45780 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45781 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45781 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45782 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45782 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45782 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45783 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45783 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-49504 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-49504 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-49504 ( NVD ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-56737 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56737 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-56737 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-0622 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0622 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0624 ( SUSE ): 7.6 CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2025-0624 ( NVD ): 7.6 CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2025-0677 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0677 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0677 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0678 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0684 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0684 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0684 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0685 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0685 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0685 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0685 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0686 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0686 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0686 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0686 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0689 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0689 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0689 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-0689 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-0690 ( SUSE ): 7.3 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-0690 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-0690 ( NVD ): 6.1 CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-1118 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-1118 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2025-1118 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2025-1125 ( SUSE ): 8.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-1125 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-1125 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-1125 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-4382 ( SUSE ): 8.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2025-4382 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-4382 ( NVD ): 5.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected Products:
* SUSE Linux Micro 6.0
An update that solves 24 vulnerabilities and has two fixes can now be installed.
## Description:
This update for grub2 fixes the following issues:
* CVE-2025-4382: Fixed TPM auto-decryption data exposure (bsc#1242971)
* Filter out the non-subvolume btrfs mount points when creating the relative path (bsc#1239674)
* CVE-2024-45781: Fixed ufs strcpy overflow (bsc#1233617)
* CVE-2024-56737: Fixed heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem (bsc#1234958) * CVE-2024-45782: Fixed hfs strcpy overflow (bsc#1233615) * CVE-2024-45780: Fixed overflow in tar/cpio(bsc#1233614) * CVE-2024-45783: Fixed hfsplus refcount overflow (bsc#1233616) * CVE-2025-0624: Fixed out-of-bounds write in grub_net_search_config_file() (bsc#1236316) * CVE-2024-45774: Fixed heap overflows in JPEG parser (bsc#1233609) * CVE-2024-45775: Fixed missing NULL check in extcmd parser (bsc#1233610) * CVE-2025-0622: Fixed command/gpg: Use-after-free due to hooks not being removed on module unload (bsc#1236317) * CVE-2024-45776: Fixed overflow in .MO file (gettext) handling (bsc#1233612) * CVE-2024-45777: Fixed integer overflow in gettext (bsc#1233613) * CVE-2025-0690: Fixed integer overflow in read that may lead to out-of-bounds write (bsc#1237012) * CVE-2025-1118: Fixed commands/dump: The dump command is not in lockdown when secure boot is enabled(bsc#1237013) * CVE-2024-45778: Fixed bfs filesystem not fuzzing stable (bsc#1233606) * CVE-2024-45779: Fixed bfs heap overflow (bsc#1233608) * CVE-2025-0677: Fixed integer overflow that may lead to heap based out-of- bounds write when handling symlinks in ufs (bsc#1237002) * CVE-2025-0684: Fixed reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237008) * CVE-2025-0685: Fixed jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237009) * CVE-2025-0686: Fixed romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237010) * CVE-2025-0689: Fixed udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution (bsc#1237011) * CVE-2025-1125: Fixed fs/hfs: Interger overflow may lead to heap based out- of-bounds write (bsc#1237014) * CVE-2025-0678: Fixed squash4: Integer overflow may lead to heap based out- of-bounds write when reading data (bsc#1237006)
* Bump upstream SBAT generation to 5 to block older grub2 versions.
* CVE-2024-49504: Fixed Bypassing TPM-bound disk encryption on SL(E)M encrypted Images (bsc#1229163) (bsc#1229164)
* Restrict CLI access if the encrypted root device is automatically unlocked by the TPM. LUKS password authentication is required for access to be granted
* Obsolete, as CLI access is now locked and granted access no longer requires the previous restrictions
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:
* SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-399=1
## Package List:
* SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * grub2-debuginfo-2.12~rc1-6.1 * grub2-debugsource-2.12~rc1-6.1 * grub2-2.12~rc1-6.1 * SUSE Linux Micro 6.0 (noarch) * grub2-snapper-plugin-2.12~rc1-6.1 * grub2-i386-pc-2.12~rc1-6.1 * grub2-x86_64-xen-2.12~rc1-6.1 * grub2-arm64-efi-2.12~rc1-6.1 * grub2-x86_64-efi-2.12~rc1-6.1 * SUSE Linux Micro 6.0 (s390x) * grub2-s390x-emu-2.12~rc1-6.1
## References:
* https://www.suse.com/security/cve/CVE-2024-45774.html * https://www.suse.com/security/cve/CVE-2024-45775.html * https://www.suse.com/security/cve/CVE-2024-45776.html * https://www.suse.com/security/cve/CVE-2024-45777.html * https://www.suse.com/security/cve/CVE-2024-45778.html * https://www.suse.com/security/cve/CVE-2024-45779.html * https://www.suse.com/security/cve/CVE-2024-45780.html * https://www.suse.com/security/cve/CVE-2024-45781.html * https://www.suse.com/security/cve/CVE-2024-45782.html * https://www.suse.com/security/cve/CVE-2024-45783.html * https://www.suse.com/security/cve/CVE-2024-49504.html * https://www.suse.com/security/cve/CVE-2024-56737.html * https://www.suse.com/security/cve/CVE-2025-0622.html * https://www.suse.com/security/cve/CVE-2025-0624.html * https://www.suse.com/security/cve/CVE-2025-0677.html * https://www.suse.com/security/cve/CVE-2025-0678.html * https://www.suse.com/security/cve/CVE-2025-0684.html * https://www.suse.com/security/cve/CVE-2025-0685.html * https://www.suse.com/security/cve/CVE-2025-0686.html * https://www.suse.com/security/cve/CVE-2025-0689.html * https://www.suse.com/security/cve/CVE-2025-0690.html * https://www.suse.com/security/cve/CVE-2025-1118.html * https://www.suse.com/security/cve/CVE-2025-1125.html * https://www.suse.com/security/cve/CVE-2025-4382.html * https://bugzilla.suse.com/show_bug.cgi?id=1229163 * https://bugzilla.suse.com/show_bug.cgi?id=1229164 * https://bugzilla.suse.com/show_bug.cgi?id=1233606 * https://bugzilla.suse.com/show_bug.cgi?id=1233608 * https://bugzilla.suse.com/show_bug.cgi?id=1233609 * https://bugzilla.suse.com/show_bug.cgi?id=1233610 * https://bugzilla.suse.com/show_bug.cgi?id=1233612 * https://bugzilla.suse.com/show_bug.cgi?id=1233613 * https://bugzilla.suse.com/show_bug.cgi?id=1233614 * https://bugzilla.suse.com/show_bug.cgi?id=1233615 * https://bugzilla.suse.com/show_bug.cgi?id=1233616 * https://bugzilla.suse.com/show_bug.cgi?id=1233617 * https://bugzilla.suse.com/show_bug.cgi?id=1234958 * https://bugzilla.suse.com/show_bug.cgi?id=1236316 * https://bugzilla.suse.com/show_bug.cgi?id=1236317 * https://bugzilla.suse.com/show_bug.cgi?id=1237002 * https://bugzilla.suse.com/show_bug.cgi?id=1237006 * https://bugzilla.suse.com/show_bug.cgi?id=1237008 * https://bugzilla.suse.com/show_bug.cgi?id=1237009 * https://bugzilla.suse.com/show_bug.cgi?id=1237010 * https://bugzilla.suse.com/show_bug.cgi?id=1237011 * https://bugzilla.suse.com/show_bug.cgi?id=1237012 * https://bugzilla.suse.com/show_bug.cgi?id=1237013 * https://bugzilla.suse.com/show_bug.cgi?id=1237014 * https://bugzilla.suse.com/show_bug.cgi?id=1239674 * https://bugzilla.suse.com/show_bug.cgi?id=1242971
--===============6753930878272948610== Content-Type: text/html; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit
<div class="container"> <h1>Security update for grub2</h1>
<table class="table table-striped table-bordered"> <tbody> <tr> <th>Announcement ID:</th> <td>SUSE-SU-2025:20511-1</td> </tr> <tr> <th>Release Date:</th> <td>2025-07-29T08:22:13Z</td> </tr> <tr> <th>Rating:</th> <td>important</td> </tr> <tr> <th>References:</th> <td> <ul> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1229163">bsc#1229163</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1229164">bsc#1229164</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233606">bsc#1233606</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233608">bsc#1233608</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233609">bsc#1233609</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233610">bsc#1233610</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233612">bsc#1233612</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233613">bsc#1233613</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233614">bsc#1233614</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233615">bsc#1233615</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233616">bsc#1233616</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233617">bsc#1233617</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1234958">bsc#1234958</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1236316">bsc#1236316</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1236317">bsc#1236317</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237002">bsc#1237002</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237006">bsc#1237006</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237008">bsc#1237008</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237009">bsc#1237009</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237010">bsc#1237010</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237011">bsc#1237011</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237012">bsc#1237012</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237013">bsc#1237013</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237014">bsc#1237014</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239674">bsc#1239674</a> </li> <li style="display: inline;"> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1242971">bsc#1242971</a> </li> </ul> </td> </tr> <tr> <th> Cross-References: </th> <td> <ul> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45774.html">CVE-2024-45774</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45775.html">CVE-2024-45775</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45776.html">CVE-2024-45776</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45777.html">CVE-2024-45777</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45778.html">CVE-2024-45778</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45779.html">CVE-2024-45779</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45780.html">CVE-2024-45780</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45781.html">CVE-2024-45781</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45782.html">CVE-2024-45782</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-45783.html">CVE-2024-45783</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-49504.html">CVE-2024-49504</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2024-56737.html">CVE-2024-56737</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0622.html">CVE-2025-0622</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0624.html">CVE-2025-0624</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0677.html">CVE-2025-0677</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0678.html">CVE-2025-0678</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0684.html">CVE-2025-0684</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0685.html">CVE-2025-0685</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0686.html">CVE-2025-0686</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0689.html">CVE-2025-0689</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-0690.html">CVE-2025-0690</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-1118.html">CVE-2025-1118</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-1125.html">CVE-2025-1125</a> </li> <li style="display: inline;"> <a href="https://www.suse.com/security/cve/CVE-2025-4382.html">CVE-2025-4382</a> </li> </ul> </td> </tr> <tr> <th>CVSS scores:</th> <td> <ul class="list-group"> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45774</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45774</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45775</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45775</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">5.2</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45776</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45776</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45777</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45777</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45778</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">3.9</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45778</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">4.1</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45778</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">5.5</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45779</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45779</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.0</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45779</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.0</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45780</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45780</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45781</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45781</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45782</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45782</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45782</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45783</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-45783</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">4.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-49504</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-49504</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.2</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-49504</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.0</span> <span class="cvss-vector">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-56737</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.4</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-56737</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2024-56737</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">8.8</span> <span class="cvss-vector">CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0622</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0622</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0624</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.6</span> <span class="cvss-vector">CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0624</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.6</span> <span class="cvss-vector">CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0677</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0677</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0677</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0678</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0678</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0678</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0678</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0684</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0684</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0684</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0685</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0685</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0685</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0685</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0686</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0686</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0686</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0686</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0689</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.9</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0689</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0689</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0689</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0690</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">7.3</span> <span class="cvss-vector">CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0690</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.1</span> <span class="cvss-vector">CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-0690</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.1</span> <span class="cvss-vector">CVSS:3.1/AV:P/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1118</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.7</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1118</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">4.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1118</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">4.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1125</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.7</span> <span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1125</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1125</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">6.4</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-1125</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">7.8</span> <span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-4382</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">8.4</span> <span class="cvss-vector">CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-4382</span> <span class="cvss-source"> ( SUSE ): </span> <span class="cvss-score">5.9</span> <span class="cvss-vector">CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span> </li> <li class="list-group-item"> <span class="cvss-reference">CVE-2025-4382</span> <span class="cvss-source"> ( NVD ): </span> <span class="cvss-score">5.9</span> <span class="cvss-vector">CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</span> </li> </ul> </td> </tr> <tr> <th>Affected Products:</th> <td> <ul class="list-group"> <li class="list-group-item">SUSE Linux Micro 6.0</li> </ul> </td> </tr> </tbody> </table>
<p>An update that solves 24 vulnerabilities and has two fixes can now be installed.</p>
<h2>Description:</h2> <p>This update for grub2 fixes the following issues:</p> <ul> <li> <p>CVE-2025-4382: Fixed TPM auto-decryption data exposure (bsc#1242971)</p> </li> <li> <p>Filter out the non-subvolume btrfs mount points when creating the relative path (bsc#1239674)</p> </li> <li> <p>CVE-2024-45781: Fixed ufs strcpy overflow (bsc#1233617)</p> </li> <li>CVE-2024-56737: Fixed heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem (bsc#1234958)</li> <li>CVE-2024-45782: Fixed hfs strcpy overflow (bsc#1233615)</li> <li>CVE-2024-45780: Fixed overflow in tar/cpio(bsc#1233614)</li> <li>CVE-2024-45783: Fixed hfsplus refcount overflow (bsc#1233616)</li> <li>CVE-2025-0624: Fixed out-of-bounds write in grub_net_search_config_file() (bsc#1236316)</li> <li>CVE-2024-45774: Fixed heap overflows in JPEG parser (bsc#1233609)</li> <li>CVE-2024-45775: Fixed missing NULL check in extcmd parser (bsc#1233610)</li> <li>CVE-2025-0622: Fixed command/gpg: Use-after-free due to hooks not being removed on module unload (bsc#1236317)</li> <li>CVE-2024-45776: Fixed overflow in .MO file (gettext) handling (bsc#1233612)</li> <li>CVE-2024-45777: Fixed integer overflow in gettext (bsc#1233613)</li> <li>CVE-2025-0690: Fixed integer overflow in read that may lead to out-of-bounds write (bsc#1237012)</li> <li>CVE-2025-1118: Fixed commands/dump: The dump command is not in lockdown when secure boot is enabled(bsc#1237013)</li> <li>CVE-2024-45778: Fixed bfs filesystem not fuzzing stable (bsc#1233606)</li> <li>CVE-2024-45779: Fixed bfs heap overflow (bsc#1233608)</li> <li>CVE-2025-0677: Fixed integer overflow that may lead to heap based out-of-bounds write when handling symlinks in ufs (bsc#1237002)</li> <li>CVE-2025-0684: Fixed reiserfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237008)</li> <li>CVE-2025-0685: Fixed jfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237009)</li> <li>CVE-2025-0686: Fixed romfs: Integer overflow when handling symlinks may lead to heap based out-of-bounds write when reading data (bsc#1237010)</li> <li>CVE-2025-0689: Fixed udf: Heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution (bsc#1237011)</li> <li>CVE-2025-1125: Fixed fs/hfs: Interger overflow may lead to heap based out-of-bounds write (bsc#1237014)</li> <li> <p>CVE-2025-0678: Fixed squash4: Integer overflow may lead to heap based out-of-bounds write when reading data (bsc#1237006)</p> </li> <li> <p>Bump upstream SBAT generation to 5 to block older grub2 versions.</p> </li> <li> <p>CVE-2024-49504: Fixed Bypassing TPM-bound disk encryption on SL(E)M encrypted Images (bsc#1229163) (bsc#1229164)</p> </li> <li> <p>Restrict CLI access if the encrypted root device is automatically unlocked by the TPM. LUKS password authentication is required for access to be granted</p> </li> <li>Obsolete, as CLI access is now locked and granted access no longer requires the previous restrictions</li> </ul>
<h2>Patch Instructions:</h2> <p> To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product: </p> <ul class="list-group"> <li class="list-group-item"> SUSE Linux Micro 6.0 <br/> <code>zypper in -t patch SUSE-SLE-Micro-6.0-399=1</code> </li> </ul>
<h2>Package List:</h2> <ul> <li> SUSE Linux Micro 6.0 (aarch64 s390x x86_64) <ul> <li>grub2-debuginfo-2.12~rc1-6.1</li> <li>grub2-debugsource-2.12~rc1-6.1</li> <li>grub2-2.12~rc1-6.1</li> </ul> </li> <li> SUSE Linux Micro 6.0 (noarch) <ul> <li>grub2-snapper-plugin-2.12~rc1-6.1</li> <li>grub2-i386-pc-2.12~rc1-6.1</li> <li>grub2-x86_64-xen-2.12~rc1-6.1</li> <li>grub2-arm64-efi-2.12~rc1-6.1</li> <li>grub2-x86_64-efi-2.12~rc1-6.1</li> </ul> </li> <li> SUSE Linux Micro 6.0 (s390x) <ul> <li>grub2-s390x-emu-2.12~rc1-6.1</li> </ul> </li> </ul>
<h2>References:</h2> <ul> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45774.html">https://www.suse.com/security/cve/CVE-2024-45774.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45775.html">https://www.suse.com/security/cve/CVE-2024-45775.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45776.html">https://www.suse.com/security/cve/CVE-2024-45776.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45777.html">https://www.suse.com/security/cve/CVE-2024-45777.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45778.html">https://www.suse.com/security/cve/CVE-2024-45778.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45779.html">https://www.suse.com/security/cve/CVE-2024-45779.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45780.html">https://www.suse.com/security/cve/CVE-2024-45780.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45781.html">https://www.suse.com/security/cve/CVE-2024-45781.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45782.html">https://www.suse.com/security/cve/CVE-2024-45782.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-45783.html">https://www.suse.com/security/cve/CVE-2024-45783.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-49504.html">https://www.suse.com/security/cve/CVE-2024-49504.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2024-56737.html">https://www.suse.com/security/cve/CVE-2024-56737.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0622.html">https://www.suse.com/security/cve/CVE-2025-0622.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0624.html">https://www.suse.com/security/cve/CVE-2025-0624.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0677.html">https://www.suse.com/security/cve/CVE-2025-0677.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0678.html">https://www.suse.com/security/cve/CVE-2025-0678.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0684.html">https://www.suse.com/security/cve/CVE-2025-0684.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0685.html">https://www.suse.com/security/cve/CVE-2025-0685.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0686.html">https://www.suse.com/security/cve/CVE-2025-0686.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0689.html">https://www.suse.com/security/cve/CVE-2025-0689.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-0690.html">https://www.suse.com/security/cve/CVE-2025-0690.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-1118.html">https://www.suse.com/security/cve/CVE-2025-1118.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-1125.html">https://www.suse.com/security/cve/CVE-2025-1125.html</a> </li> <li> <a href="https://www.suse.com/security/cve/CVE-2025-4382.html">https://www.suse.com/security/cve/CVE-2025-4382.html</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1229163">https://bugzilla.suse.com/show_bug.cgi?id=1229163</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1229164">https://bugzilla.suse.com/show_bug.cgi?id=1229164</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233606">https://bugzilla.suse.com/show_bug.cgi?id=1233606</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233608">https://bugzilla.suse.com/show_bug.cgi?id=1233608</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233609">https://bugzilla.suse.com/show_bug.cgi?id=1233609</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233610">https://bugzilla.suse.com/show_bug.cgi?id=1233610</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233612">https://bugzilla.suse.com/show_bug.cgi?id=1233612</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233613">https://bugzilla.suse.com/show_bug.cgi?id=1233613</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233614">https://bugzilla.suse.com/show_bug.cgi?id=1233614</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233615">https://bugzilla.suse.com/show_bug.cgi?id=1233615</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233616">https://bugzilla.suse.com/show_bug.cgi?id=1233616</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1233617">https://bugzilla.suse.com/show_bug.cgi?id=1233617</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1234958">https://bugzilla.suse.com/show_bug.cgi?id=1234958</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1236316">https://bugzilla.suse.com/show_bug.cgi?id=1236316</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1236317">https://bugzilla.suse.com/show_bug.cgi?id=1236317</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237002">https://bugzilla.suse.com/show_bug.cgi?id=1237002</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237006">https://bugzilla.suse.com/show_bug.cgi?id=1237006</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237008">https://bugzilla.suse.com/show_bug.cgi?id=1237008</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237009">https://bugzilla.suse.com/show_bug.cgi?id=1237009</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237010">https://bugzilla.suse.com/show_bug.cgi?id=1237010</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237011">https://bugzilla.suse.com/show_bug.cgi?id=1237011</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237012">https://bugzilla.suse.com/show_bug.cgi?id=1237012</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237013">https://bugzilla.suse.com/show_bug.cgi?id=1237013</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1237014">https://bugzilla.suse.com/show_bug.cgi?id=1237014</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1239674">https://bugzilla.suse.com/show_bug.cgi?id=1239674</a> </li> <li> <a href="https://bugzilla.suse.com/show_bug.cgi?id=1242971">https://bugzilla.suse.com/show_bug.cgi?id=1242971</a> </li> </ul> </div>
--===============6753930878272948610==--
|
|
|
|