Security update 4.3.15.2 SUSE Manager Server 4.3
Announcement ID: | SUSE-SU-2025:01994-1 |
---|---|
Release Date: | 2025-06-18T02:13:39Z |
Rating: | moderate |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves one vulnerability, contains two features and has one security fix can now be installed.
Description:
This update fixes the following issues:
netty:
-
Security issues fixed:
-
CVE-2024-47535: Decorate InputStream to throw an exception once the data read limit is reached (bsc#1233297)
-
Other changes:
-
Replace AlgorithmId.sha256WithRSAEncryption_oid usage with specify the OID directly
susemanager-sync-data:
-
Version 4.3.22-0:
-
Added support for OES 24.4 (bsc#1230585)
- Set Ubuntu 24.04 as released
How to apply this update:
- Log in as root user to the Multi-Linux Manager Server.
- Stop the Spacewalk service:
spacewalk-service stop
- Apply the patch using either zypper patch or YaST Online Update.
- Start the Spacewalk service:
spacewalk-service start
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Manager Server 4.3 Module
zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2025-1994=1
Package List:
-
SUSE Manager Server 4.3 Module (noarch)
- netty-4.1.44.Final-150400.3.6.3
- susemanager-sync-data-4.3.23-150400.3.41.3