SUSE-SU-2025:3826-1

Source
https://www.suse.com/support/update/announcement/2025/suse-su-20253826-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:3826-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2025:3826-1
Upstream
  • CVE-2025-53883
Related
  • CVE-2025-53883
Published
2025-10-28T07:26:47Z
Modified
2025-10-28T20:32:36.700628Z
Summary
Security update 4.3.16.1 for SUSE Manager Server 4.3 LTS
Details

This update fixes the following issues:

susemanager-build-keys:

  • Update SUSE GPG key and make it available for Salt (bsc#1250911)

susemanager-sls:

  • Version 4.3.50-0
    • Fix OS Family grain name (bsc#1250911)
  • Version 4.3.49-0
    • Fixed syntax error in Salt state
  • Version 4.3.48-0
    • Automatically deploy the SUSE GPG key (bsc#1250911)

spacewalk-java:

  • Version 4.3.88-0 with security fix:
    • CVE-2025-53883: Escape input strings in system search form (bsc#1246439)

rhnlib:

  • Version 4.3.7-0:
    • Use more secure defusedxml parser (bsc#1227577)

spacewalk-backend:

  • Version 4.3.34-0:
    • Use more secure defusedxml parser (bsc#1227577)

spacewalk-web:

  • Version 4.3.46-0:
    • Bumped the WebUI version to 4.3.16.1

How to apply this update:

  1. Log in as root user to the Multi-Linux Manager Server.
  2. Stop the Spacewalk service: spacewalk-service stop
  3. Apply the patch using either zypper patch or YaST Online Update.
  4. Start the Spacewalk service: spacewalk-service start
References

Affected packages

SUSE:Manager Proxy LTS 4.3

rhnlib

Package

Name
rhnlib
Purl
pkg:rpm/suse/rhnlib&distro=SUSE%20Manager%20Proxy%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.7-150400.3.9.4

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "susemanager-tftpsync-recv": "4.3.11-150400.3.15.3",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4"
        }
    ]
}

spacewalk-backend

Package

Name
spacewalk-backend
Purl
pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.34-150400.3.58.6

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "susemanager-tftpsync-recv": "4.3.11-150400.3.15.3",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4"
        }
    ]
}

spacewalk-web

Package

Name
spacewalk-web
Purl
pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.46-150400.3.63.5

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "susemanager-tftpsync-recv": "4.3.11-150400.3.15.3",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4"
        }
    ]
}

susemanager-build-keys

Package

Name
susemanager-build-keys
Purl
pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Proxy%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.4.11-150400.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "susemanager-tftpsync-recv": "4.3.11-150400.3.15.3",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4"
        }
    ]
}

susemanager-tftpsync-recv

Package

Name
susemanager-tftpsync-recv
Purl
pkg:rpm/suse/susemanager-tftpsync-recv&distro=SUSE%20Manager%20Proxy%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.11-150400.3.15.3

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "susemanager-tftpsync-recv": "4.3.11-150400.3.15.3",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4"
        }
    ]
}

SUSE:Manager Server LTS 4.3

rhnlib

Package

Name
rhnlib
Purl
pkg:rpm/suse/rhnlib&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.7-150400.3.9.4

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}

spacewalk-backend

Package

Name
spacewalk-backend
Purl
pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.34-150400.3.58.6

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}

spacewalk-java

Package

Name
spacewalk-java
Purl
pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.88-150400.3.113.5

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}

spacewalk-web

Package

Name
spacewalk-web
Purl
pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.46-150400.3.63.5

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}

susemanager-build-keys

Package

Name
susemanager-build-keys
Purl
pkg:rpm/suse/susemanager-build-keys&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.4.11-150400.3.38.1

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}

susemanager-sls

Package

Name
susemanager-sls
Purl
pkg:rpm/suse/susemanager-sls&distro=SUSE%20Manager%20Server%20LTS%204.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.50-150400.3.68.1

Ecosystem specific

{
    "binaries": [
        {
            "spacewalk-base-minimal": "4.3.46-150400.3.63.5",
            "spacewalk-backend": "4.3.34-150400.3.58.6",
            "spacewalk-base": "4.3.46-150400.3.63.5",
            "spacewalk-backend-applet": "4.3.34-150400.3.58.6",
            "spacewalk-java-config": "4.3.88-150400.3.113.5",
            "spacewalk-backend-config-files-tool": "4.3.34-150400.3.58.6",
            "spacewalk-backend-config-files": "4.3.34-150400.3.58.6",
            "susemanager-build-keys": "15.4.11-150400.3.38.1",
            "spacewalk-backend-sql-postgresql": "4.3.34-150400.3.58.6",
            "spacewalk-taskomatic": "4.3.88-150400.3.113.5",
            "spacewalk-backend-iss": "4.3.34-150400.3.58.6",
            "spacewalk-backend-iss-export": "4.3.34-150400.3.58.6",
            "spacewalk-html": "4.3.46-150400.3.63.5",
            "spacewalk-backend-config-files-common": "4.3.34-150400.3.58.6",
            "spacewalk-backend-xml-export-libs": "4.3.34-150400.3.58.6",
            "spacewalk-backend-package-push-server": "4.3.34-150400.3.58.6",
            "uyuni-config-modules": "4.3.50-150400.3.68.1",
            "python3-rhnlib": "4.3.7-150400.3.9.4",
            "spacewalk-java-lib": "4.3.88-150400.3.113.5",
            "susemanager-sls": "4.3.50-150400.3.68.1",
            "spacewalk-base-minimal-config": "4.3.46-150400.3.63.5",
            "spacewalk-java-postgresql": "4.3.88-150400.3.113.5",
            "spacewalk-backend-tools": "4.3.34-150400.3.58.6",
            "spacewalk-backend-app": "4.3.34-150400.3.58.6",
            "spacewalk-backend-sql": "4.3.34-150400.3.58.6",
            "spacewalk-java": "4.3.88-150400.3.113.5",
            "spacewalk-backend-xmlrpc": "4.3.34-150400.3.58.6",
            "susemanager-build-keys-web": "15.4.11-150400.3.38.1",
            "spacewalk-backend-server": "4.3.34-150400.3.58.6"
        }
    ]
}