FlawAtlas
Search the atlas
SUSE-SU-2025:01994-1 Not scored

Security update 4.3.15.2 SUSE Manager Server 4.3

This update fixes the following issues: netty: - Security issues fixed: * CVE-2024-47535: Decorate InputStream to throw an exception once the data read limit is reached (bsc#1233297) - Other changes: * Replace AlgorithmId.sha256WithRSAEncryption_oid usage with specify the OID directly susemanager-sync-data: - Version 4.3.22-0: * Added support for OES 24.4 (bsc#1230585) * Set Ubuntu 24.04 as released How to apply this update: 1. Log in as root user to the Multi-Linux Manager Server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start`

Exploit probability Not scored
Published June 18, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Manager Server Module 4.3 netty
SUSE:Manager Server Module 4.3 susemanager-sync-data

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01994-1

This update fixes the following issues: netty: - Security issues fixed: * CVE-2024-47535: Decorate InputStream to throw an exception once the data read limit is reached (bsc#1233297) - Other changes: * Replace AlgorithmId.sha256WithRSAEncryption_oid usage with specify the OID directly susemanager-sync-data: - Version 4.3.22-0: * Added support for OES 24.4 (bsc#1230585) * Set Ubuntu 24.04 as released How to apply this update: 1. Log in as root user to the Multi-Linux Manager Server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start`

View original source

05 / REFERENCES

Further evidence