1. Python Packages:
- python311-Pillow: Updated to version 11.3.0-1.1, addressing vulnerabilities associated with CVE-2025-48379.
- python39: A security update has been released to mitigate CVE-2025-6069, enhancing HTMLParser's efficiency against crafted inputs.
2. Dpkg:
- dpkg: Version 1.22.21-1.1 has been released, fixing a vulnerability tied to CVE-2025-6297.
3. Apache Modules:
- apache2-mod_security2: The update to version 2.9.11-1.1 addresses CVE-2025-52891.
4. Mozilla Thunderbird:
- The update to version 128.12.0-1.1 resolves multiple vulnerabilities (CVE-2025-6424, CVE-2025-6425, CVE-2025-6426, CVE-2025-6429, CVE-2025-6430) which could lead to severe security issues.
5. JavaScript Libraries:
- libmozjs: Updated to version 128.12.0-1.1, this package addresses numerous vulnerabilities, including those listed in CVEs 2025-5263 through 2025-6430.
6. Valkey:
- This package has been updated to resolve vulnerabilities CVE-2025-27151 and CVE-2025-49112.
7. Incus:
- The latest version 6.14-1.1 has been released, fixing vulnerabilities CVE-2025-52889 and CVE-2025-52890.
Each of these updates is categorized as moderate in severity, indicating that while they are important to address, they do not represent the highest level of risk. Users are encouraged to apply these patches using recommended installation methods such as YaST or zypper to ensure that their systems remain secure.
Additional Context
These updates not only address specific vulnerabilities but also improve the overall stability and functionality of the software packages included in the SUSE ecosystem. Regular updates like these highlight the importance of maintaining software security in an increasingly digital world, where vulnerabilities can be exploited if left unaddressed. Users should remain vigilant and keep their systems updated to mitigate potential security risks.In future updates, it may be beneficial for SUSE to enhance communication regarding the nature of vulnerabilities and the impact of the updates, providing users with a clearer understanding of the importance of each patch. Additionally, encouraging best practices in software management could further enhance user security
Python, Dpkg, Thunderbird, and more updates for SUSE
SUSE Linux has been updated with multiple security enhancements, including python311-Pillow, dpkg, apache2-mod_security2, Mozilla Thunderbird, libmozjs, python39, valkey, and incus:
openSUSE-SU-2025:15316-1: moderate: python311-Pillow-11.3.0-1.1 on GA media
openSUSE-SU-2025:15314-1: moderate: dpkg-1.22.21-1.1 on GA media
openSUSE-SU-2025:15313-1: moderate: apache2-mod_security2-2.9.11-1.1 on GA media
openSUSE-SU-2025:15312-1: moderate: MozillaThunderbird-128.12.0-1.1 on GA media
openSUSE-SU-2025:15315-1: moderate: libmozjs-128-0-128.12.0-1.1 on GA media
SUSE-SU-2025:02232-1: moderate: Security update for python39
SUSE-SU-2025:02231-1: moderate: Security update for valkey
openSUSE-SU-2025:15317-1: moderate: incus-6.14-1.1 on GA mediaPython, Dpkg, Thunderbird, and more updates for SUSE @ Linux Compatible