critical
Security update for openssl-3-x86_64-v3-livepatches
SUSE-SLES-16.0-675
This update for openssl-3-x86_64-v3-livepatches fixes the following issues: Changes in openssl-3-x86_64-v3-livepatches: - Add package for libopenssl3-x86-64-v3-3.5.0 (bsc#1259271). Fixed: - CVE-2025-11187: Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) (bsc#1250410).
-
Release DateMay 5 2026
-
ReferencesBugzilla: 1256880, 1250410, 1259271, 1256876, 1256878
CVEs: CVE-2025-15468, CVE-2025-9230, CVE-2025-15467, CVE-2025-11187 -
Typesecurity
-
Severitycritical
cloud_download Downloads
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server 16.0 x86_64
-
Packages