FlawAtlas
Search the atlas
SUSE-SU-2025:01990-1 Not scored

Security update for golang-github-prometheus-prometheus

This update for golang-github-prometheus-prometheus fixes the following issues: - Security issues fixed: * CVE-2023-45288: Require Go >= 1.23 for building (bsc#1236516) * CVE-2025-22870: Bump golang.org/x/net to version 0.39.0 (bsc#1238686) - Version was updated to 2.53.4 with the following bug fixes: * Runtime: fix GOGC is being set to 0 when installed with empty prometheus.yml file resulting high cpu usage * Scrape: fix dropping valid metrics after previous scrape failed

Exploit probability Not scored
Published June 18, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP6 golang-github-prometheus-prometheus
SUSE:Linux Enterprise Module for Package Hub 15 SP7 golang-github-prometheus-prometheus
SUSE:Manager Proxy Module 4.3 golang-github-prometheus-prometheus
openSUSE:Leap 15.6 golang-github-prometheus-prometheus

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01990-1

This update for golang-github-prometheus-prometheus fixes the following issues: - Security issues fixed: * CVE-2023-45288: Require Go >= 1.23 for building (bsc#1236516) * CVE-2025-22870: Bump golang.org/x/net to version 0.39.0 (bsc#1238686) - Version was updated to 2.53.4 with the following bug fixes: * Runtime: fix GOGC is being set to 0 when installed with empty prometheus.yml file resulting high cpu usage * Scrape: fix dropping valid metrics after previous scrape failed

View original source

05 / REFERENCES

Further evidence