NodeJS, GHC-Pandoc, Libblockdev, Python, Gstreamer updates for SUSE

Published by

SUSE Linux has recently released significant updates addressing security vulnerabilities across various software packages, including Node.js, GHC-Pandoc, Libblockdev, Python (versions 3.9 to 3.12), and GStreamer plugins. These updates are aimed at enhancing system security and fixing critical bugs.

Key Updates Include:

1. Node.js (nodejs20):
- Security updates addressing three vulnerabilities (CVE-2025-23165, CVE-2025-23166, CVE-2025-23167).
- Improvements in error handling and HTTP header processing.
- Installation can be performed using `zypper patch` commands specific to the SUSE version.

2. GHC-Pandoc:
- Update to fix a critical vulnerability (CVE-2024-38526) related to supply chain attacks.
- Affected versions include openSUSE Leap 15.5 and 15.6, among others.

3. Libblockdev:
- Addressed a privilege escalation vulnerability (CVE-2025-6019) that could occur during file system resizing.
- The update covers multiple SUSE distributions, including the Basesystem Module and SUSE Linux Enterprise Server.

4. Python (Versions 3.9, 3.10, 3.11, 3.12):
- Multiple security fixes that resolve vulnerabilities, including denial of service (DoS) risks and issues with symlink handling (CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4516, CVE-2025-4517).
- Each Python version update includes various bug fixes and improvements.

5. GStreamer Plugins (gstreamer-plugins-good):
- Updates to address three vulnerabilities (CVE-2024-47540, CVE-2025-47183, CVE-2025-47219) related to memory management and out-of-bounds reads in demuxers.
- Available for multiple architectures and distributions.

Installation Instructions:
To apply the updates, users are encouraged to use the recommended installation methods provided by SUSE, such as YaST online_update or the `zypper patch` commands associated with their specific product versions.

Conclusion:
These updates reflect SUSE's commitment to maintaining the security and stability of its operating systems and applications. Users are advised to keep their environments up to date with these patches to mitigate potential security risks.

For detailed installation instructions, users can refer to the specific patch announcements on the SUSE website, which include references and further documentation regarding the vulnerabilities addressed

NodeJS, GHC-Pandoc, Libblockdev, Python, Gstreamer updates for SUSE

SUSE Linux has been updated with multiple security enhancements, including updates for nodejs20, ghc-pandoc, libblockdev, python39, python310, python311, python312, and gstreamer-plugins-good:

SUSE-SU-2025:02039-1: important: Security update for nodejs20
SUSE-SU-2025:02037-1: important: Security update for ghc-pandoc
SUSE-SU-2025:02044-1: important: Security update for libblockdev
SUSE-SU-2025:02045-1: important: Security update for nodejs20
SUSE-SU-2025:02050-1: important: Security update for python39
SUSE-SU-2025:02047-1: important: Security update for python310
SUSE-SU-2025:02049-1: important: Security update for python311
SUSE-SU-2025:02048-1: important: Security update for python312
SUSE-SU-2025:02053-1: important: Security update for gstreamer-plugins-good

NodeJS, GHC-Pandoc, Libblockdev, Python, Gstreamer updates for SUSE @ Linux Compatible