SUSE-SU-2025:01987-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202501987-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:01987-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2025:01987-1
Related
Published
2025-06-18T02:09:10Z
Modified
2025-06-18T12:59:26.345378Z
Upstream
  • CVE-2024-9476
  • CVE-2025-3454
  • CVE-2025-2703
Summary
Security update for Multi-Linux Manager Client Tools
Details

This update fixes the following issues:

golang-github-prometheus-prometheus was updated to version 2.53.4:

  • Security issues fixed:

    • CVE-2023-45288: Require Go >= 1.23 for building (bsc#1236516)
    • CVE-2025-22870: Bumped golang.org/x/net to version 0.39.0 (bsc#1238686)
  • Other bugs fixes from version 2.53.4:

    • Runtime: fixed GOGC being set to 0 when installed with empty prometheus.yml file resulting high cpu usage
    • Scrape: fixed dropping valid metrics after previous scrape failed

prometheus-blackbox_exporter was updated from version 0.24.0 to 0.26.0 (jsc#PED-12872):

  • Security issues fixed:

    • CVE-2025-22870: Fixed proxy bypassing using IPv6 zone IDs (bsc#1238680)
    • CVE-2023-45288: Fixed closing connections when receiving too many headers (bsc#1236515)
  • Other changes from version 0.26.0:

    • Changes:
      • Replace go-kit/log with log/slog module.
    • Features:
      • Add metric to record tls ciphersuite negotiated during handshake.
      • Add a way to export labels with content matched by the probe. Reports Certificate Serial number.
    • Enhancement:
      • Add stale workflow to start sync with stale.yaml in Prometheus.
    • Bug fixes:
      • Only register grpc TLS metrics on successful handshake.
  • Other changes from version 0.25.0:

    • Features:
      • Allow to get Probe logs by target.
      • Log errors from probe.
    • Bug fixes:
      • Prevent logging confusing error message.
      • Explicit registration of internal exporter metrics.

grafana was updated from version 10.4.15 to 11.5.5 (jsc#PED-12918):

  • Security issues fixed:

    • CVE-2025-4123: Fix cross-site scripting vulnerability (bsc#1243714).
    • CVE-2025-22872: Bump golang.org/x/net/html (bsc#1241809)
    • CVE-2025-3580: Prevent unauthorized server admin deletion (bsc#1243672).
    • CVE-2025-29923: Bump github.com/redis/go-redis/v9 to 9.6.3.
    • CVE-2025-3454: Sanitize paths before evaluating access to route (bsc#1241683).
    • CVE-2025-2703: Fix built-in XY Chart plugin (bsc#1241687).
    • CVE-2025-22870: Bump golang.org/x/net (bsc#1238703).
    • CVE-2024-9476: Fix Migration Assistant issue (bsc#1233343)
    • CVE-2024-9264: SQL Expressions (bsc#1231844)
    • CVE-2023-45288: Bump golang.org/x/net (bsc#1236510)
    • CVE-2025-22870: Bump golang.org/x/net to version 0.37.0 (bsc#1238686)
  • Potential breaking changes in version 11.5.0:

    • Loki: Default to /labels API with query param instead of /series API.
  • Potential breaking changes in version 11.0.1:

    • If you had selected your language as 'Portugu�s Brasileiro' previously, this will be reset. You have to select it again in your Preferences for the fix to be applied and the translations will then be shown.
  • Potential breaking changes in version 11.0.0:

    • AngularJS support is turned off by default.
    • Legacy alerting is entirely removed.
    • Subfolders cause very rare issues with folders which have slashes in their names.
    • The input data source is removed.
    • Data sources: Responses which are associated with hidden queries will be removed (filtered) by Grafana.
    • The URL which is generated when viewing an individual repeated panel has changed.
    • React Router is deprecated.
    • The grafana/e2e testing tool is deprecated.
  • This update brings many new features, enhancements and fixes highlighted at:

    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-5/
    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-4/
    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-3/
    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-2/
    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-1/
    • https://grafana.com/docs/grafana/next/whatsnew/whats-new-in-v11-0/

golang-github-prometheus-node_exporter was updated to version 1.9.1:

  • Security issues fixed:

    • CVE-2025-22870: Bumped golang.org/x/net to version 0.37.0 (bsc#1238686)
  • Other changes from version 1.9.1:

    • pressure: Fix missing IRQ on older kernels
    • Fix Darwin memory leak

golang-github-prometheus-alertmanager:

  • Security issues fixed:
    • CVE-2025-22870: Fix proxy bypassing using IPv6 zone IDs (bsc#1238686)
    • CVE-2023-45288: Fix HTTP/2 CONTINUATION flood in net/http (bsc#1236516)
References

Affected packages

SUSE:Manager Client Tools 12 / golang-github-prometheus-alertmanager

Package

Name
golang-github-prometheus-alertmanager
Purl
pkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.0-1.31.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.26.0-1.31.2",
            "prometheus-blackbox_exporter": "0.26.0-1.27.1",
            "golang-github-prometheus-prometheus": "2.53.4-1.60.2",
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2",
            "grafana": "11.5.5-1.79.2"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-1.36.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.26.0-1.31.2",
            "prometheus-blackbox_exporter": "0.26.0-1.27.1",
            "golang-github-prometheus-prometheus": "2.53.4-1.60.2",
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2",
            "grafana": "11.5.5-1.79.2"
        }
    ]
}

SUSE:Manager Client Tools 12 / golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.53.4-1.60.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.26.0-1.31.2",
            "prometheus-blackbox_exporter": "0.26.0-1.27.1",
            "golang-github-prometheus-prometheus": "2.53.4-1.60.2",
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2",
            "grafana": "11.5.5-1.79.2"
        }
    ]
}

SUSE:Manager Client Tools 12 / grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.5.5-1.79.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.26.0-1.31.2",
            "prometheus-blackbox_exporter": "0.26.0-1.27.1",
            "golang-github-prometheus-prometheus": "2.53.4-1.60.2",
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2",
            "grafana": "11.5.5-1.79.2"
        }
    ]
}

SUSE:Manager Client Tools 12 / prometheus-blackbox_exporter

Package

Name
prometheus-blackbox_exporter
Purl
pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%2012

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.0-1.27.1

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-alertmanager": "0.26.0-1.31.2",
            "prometheus-blackbox_exporter": "0.26.0-1.27.1",
            "golang-github-prometheus-prometheus": "2.53.4-1.60.2",
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2",
            "grafana": "11.5.5-1.79.2"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5-LTSS / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-1.36.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2"
        }
    ]
}

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / golang-github-prometheus-node_exporter

Package

Name
golang-github-prometheus-node_exporter
Purl
pkg:rpm/suse/golang-github-prometheus-node_exporter&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.1-1.36.2

Ecosystem specific

{
    "binaries": [
        {
            "golang-github-prometheus-node_exporter": "1.9.1-1.36.2"
        }
    ]
}