gpp_maybe
Security update for rust-keylime
SUSE-SLE-Micro-5.5-2025-2811
This update for rust-keylime fixes the following issues: - Update to version 0.2.7+141: * CVE-2025-58266: shlex: Fixed command injection (bsc#1247193) - Update to version 0.2.7+117: * CVE-2023-26964: rust-keylime: hyper,h2: stream stacking when H2 processing HTTP2 RST_STREAM frames (bsc#1210344). * CVE-2024-12224: rust-keylime: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243861). * CVE-2024-32650: rust-keylime: rust-rustls: Infinite loop in rustls::conn::ConnectionCommon:complete_io() with proper client input (bsc#1223234). * CVE-2024-43806: rust-keylime: rustix: rustix::fs::Dir iterator with the linux_raw backend can cause memory explosion (bsc#1229952). * CVE-2025-3416: rust-keylime: openssl: Use-After-Free in Md::fetch and Cipher::fetch in rust-openssl crate (bsc#1242623). * rust-shlex: Multiple issues involving quote API ( RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27, bsc#1230029)
-
Release DateAug 15 2025
-
ReferencesBugzilla: 1229952, 1242623, 1210344, 1223234, 1230029, 1243861, 1247193
CVEs: CVE-2024-32650, CVE-2024-12224, CVE-2024-43806, CVE-2023-26964, CVE-2025-3416, CVE-2025-58266 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.5 s390x
-
Packages
SUSE Linux Enterprise Micro 5.5 aarch64
-
Packages
SUSE Linux Enterprise Micro 5.5 ppc64le
-
Packages
SUSE Linux Enterprise Micro 5.5 x86_64
-
Packages