SUSE-SU-2025:20336-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-202520336-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20336-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2025:20336-1
Published
2025-05-21T15:40:23Z
Modified
2026-03-23T04:48:55Z
Summary
Security update for ca-certificates-mozilla
Details

This update for ca-certificates-mozilla fixes the following issues:

  • test for a concretely missing certificate rather than just the directory, as the latter is now also provided by openssl-3

  • Re-create java-cacerts with SOURCE_DATE_EPOCH set for reproducible builds (bsc#1229003)

  • explicit remove distrusted certs, as the distrust does not get exported correctly and the SSL certs are still trusted. (bsc#1240343)

    • Entrust.net Premium 2048 Secure Server CA
    • Entrust Root Certification Authority
    • AffirmTrust Commercial
    • AffirmTrust Networking
    • AffirmTrust Premium
    • AffirmTrust Premium ECC
    • Entrust Root Certification Authority - G2
    • Entrust Root Certification Authority - EC1
    • GlobalSign Root E46
    • GLOBALTRUST 2020
  • pass file argument to awk (bsc#1240009)

  • update to 2.74 state of Mozilla SSL root CAs: Removed:

    • SwissSign Silver CA - G2 Added:
    • D-TRUST BR Root CA 2 2023
    • D-TRUST EV Root CA 2 2023
  • remove extensive signature printing in comments of the cert bundle

  • Define two macros to break a build cycle with p11-kit.

  • Updated to 2.72 state of Mozilla SSL root CAs (bsc#1234798) Removed:

    • SecureSign RootCA11
    • Security Communication RootCA3 Added:
    • TWCA CYBER Root CA
    • TWCA Global Root CA G2
    • SecureSign Root CA12
    • SecureSign Root CA14
    • SecureSign Root CA15
References

Affected packages

SUSE:Linux Micro 6.0 / ca-certificates-mozilla

Package

Name
ca-certificates-mozilla
Purl
pkg:rpm/suse/ca-certificates-mozilla&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.74-1.1

Ecosystem specific

{
    "binaries":  [
        {
            "ca-certificates-mozilla":  "2.74-1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20336-1.json"