Описание
Security update for himmelblau
This update for himmelblau fixes the following issues:
- CVE-2025-5791: Fixed using deprecated
userscrate (bsc#1244202) - CVE-2025-3416: Fixed use-After-Free in Md::fetch and Cipher::fetch in rust-openssl crate (bsc#1242648)
Update to version 0.7.17+git.0.1ebdab0
- Update sccache-action version to use new cache service
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
himmelblau-sshd-config-0.7.17+git.0.1ebdab0-150700.3.3.2
libnss_himmelblau2-0.7.17+git.0.1ebdab0-150700.3.3.2
pam-himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
Ссылки
- Link for SUSE-SU-2025:02166-1
- E-Mail link for SUSE-SU-2025:02166-1
- SUSE Security Ratings
- SUSE Bug 1242648
- SUSE Bug 1244202
- SUSE CVE CVE-2025-3416 page
- SUSE CVE CVE-2025-5791 page
Описание
A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:himmelblau-sshd-config-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:libnss_himmelblau2-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:pam-himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
Ссылки
- CVE-2025-3416
- SUSE Bug 1242599
Описание
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:himmelblau-sshd-config-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:libnss_himmelblau2-0.7.17+git.0.1ebdab0-150700.3.3.2
SUSE Linux Enterprise Module for Basesystem 15 SP7:pam-himmelblau-0.7.17+git.0.1ebdab0-150700.3.3.2
Ссылки
- CVE-2025-5791
- SUSE Bug 1244187