Author: Marcus Meissner
SUSE Security Data considerations
SUSE provides security data for the CVE issues affecting the SUSE Linux products and the openSUSE distributions. We provide the data in OVAL, CVRF and CSAF formats under the Creative Commons license. The security data is generated from released updates, updates in QA, and our security tracking and scoring data. The same data sources are […]
Read More
SUSE responds to the copy.fail vulnerability
Copy Fail (tracked as CVE-2026-31431) is a critical vulnerability in the Linux kernel that allows a local non-root user to gain full root access to the system. It is considered extremely dangerous because it is a pure logic error – unlike other known holes like Dirty Pipe or Dirty COW, it does not require complex […]
Read More
Installing FIPS certified packages on SUSE Linux Enterprise Server 15 SP6 and SP7
SUSE has certified and is currently certifying various cryptographic modules for FIPS 140-3 on SUSE Linux Enterprise Server 15 SP6. Nearly all of those modules certified on SLES 15 SP6 can also be used on SLES 15 SP7, and for this purpose they are delivered to the SLES 15 SP7 Certifications Module. The modules consists […]
Read More
SUSE state of and strategy for Post Quantum Cryptography at the end of 2025
SUSE’s strategy on implementing post quantum cryptography (PQC) has been to adopt standards and upstream implementations when they become available, and deliver support to customers via maintenance or newer product revisions. Standardization status Cryptography and protocols on top of it needs to interoperate world wide between a wide range of third parties. This requires that […]
Read More
Statement on CVE-2024-22033 – Compromise of Open Build Service via source services
Maxime Rinaudo of Fenrisk (http://fenrisk.com) found a security vulnerability in one of the services that are available on the open build service (https://build.opensuse.org/). He disclosed this to us privately to allow us to fix it before he publicly discloses it. We appreciate this very much and would like to thank him for that again. On […]
Read More
SUSE has received first FIPS 140-3 cryptographic certificates
After several years of work the NIST CMVP agency has improved upon the existing FIPS 140-2 certification and established the FIPS 140-3 certification. The new standard brings many changes which are described in the Implementation Guidance. They established new requirements on lifecycle of cryptographic primitives and extended in the area of self-tests. They also took a […]
Read More
SUSE addresses supply chain attack against xz compression library
SUSE received notification of a supply chain attack against the “xz” compression tool and “liblzma5” library. Background Security Researcher Andres Freund reported to Debian that the xz / liblzma library had been backdoored. This backdoor was introduced in the upstream github xz project with release 5.6.0 in February 2024. For the statement from the openSUSE […]
Read More
SUSE addresses the SSH v2 protocol Terrapin Attack aka CVE-2023-48795
Today, on December 18th 2023, researchers from the Ruhr University Bochum published a protocol flaw in the SSH v2 protocol, codenamed Terrapin Attack. The flaw allows removing encrypted SSH messages at the begin of the communication, allowing downgrade of some security aspects of SSH connections. The flaw does not allow injecting new traffic or commands. […]
Read More
SUSE が SSH v2 プロトコルの Terrapin Attack(CVE-2023-48795)に対処
2023年12月18日、Ruhr University Bochumの研究者が、コードネーム「Terrapin […]
Read More
GO and FIPS 140-2 / 140-3 certified cryptography
The current FIPS 140-2 and ongoing FIPS 140-3 certification efforts by SUSE cover a wide range of system libraries and its users, and the Linux Kernel. One gap recently closed is the missing FIPS 140 support for applications written in the GO language. To allow building GO binaries with cryptography compliant to FIPS 140, SUSE […]
Read More
SUSE Linux Enterprise and SBOM support
After recent supply chain attacks and with ever increasing security automation especially the software inventory management becomes more and more important. Governments and other regulated industries now require publishing a so called Software Bill Of Materials (SBOM) to software products. Various SBOM formats have appeared in the market. SUSE has started to publish SBOM in […]
Read More
SUSE adds security automation support for Kernel Live Patches
SUSE has found that security automation is not handling SUSEs kernel livepatches very well. To understand the underlying problem and ways toward a solution, lets first look at the underlying concepts. Kernel Livepatching Kernel livepatching is a technology where functions within a running Linux kernel are patched to fix security issues, without rebooting or even […]
Read More
Applying DISA STIG hardening to SLES installations
Introduction The DISA and SUSE have authored a STIG (Secure Technical Implementation Guide) that describes how to harden a SUSE Linux Enterprise system. The STIG is a long list of rules, each containing description, detection of problems and how to remediate problems on a per rule basis. While originally STIGs are supposed to applied manually, […]
Read More
SUSE statement on “Dirty Pipe” attack
On Monday, March 7th, security researcher Max Kellermann published a new software vulnerability that affect users of the Linux Kernel. The vulnerability, called Dirty Pipe (CVE-2022-0847) , impacts Linux Kernels 5.8 and later, and allows local attackers to overwrite files even if they had only read permissions, allowing for easy privilege escalation. The issue is […]
Read More
SUSE Statement on log4j / log4shell / CVE-2021-44228 / Vulnerability
On Friday December 10 morning a new exploit in “log4j” Java logging framework was reported, that can be trivially exploited. This vulnerability is caused by a new feature introduced in log4j 2.x versions where a specific string embedded in messages logged by log4j would be interpreted by log4j to connect to remote sites and even […]
Read More
SUSE addresses BootHole security exposure
Security researchers from Eclypsium have published an attack called BootHole today. This attack requires root access to the bootloader used in Linux operating systems, GRUB2. It bypasses normal Secure Boot protections to persistently install malicious code which cannot be detected by the operating system. Given the need for root access to the bootloader, the described […]
Read More
Our CVE Pages – self help to security issues in SUSE Linux Enterprise
SUSE CVE Pages SUSE offers various self-service options for getting information on Security Issues. One of these self-service options that are intended for human consumption are our CVE Pages. For every CVE that might be related to our products we provide a webpage with our current status. These pages cover SUSE Enterprise products, and also contain […]
Read More