SUSE-SU-2026:0483-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20260483-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0483-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:0483-1
Upstream
Related
Published
2026-02-12T16:34:19Z
Modified
2026-02-13T16:42:49.231448Z
Summary
Security update for zabbix
Details

This update for zabbix fixes the following issues:

  • CVE-2024-36469: Introduced clamping for mitigation of timing attacks. (bsc#1240676)
  • CVE-2024-42325: Restricted access to user fields using user.get API method for users of User and Admin type, and restricted access to alert entities using alert.get API method for users of User and Admin types. (bsc#1240678)
References

Affected packages

SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 / zabbix

Package

Name
zabbix
Purl
pkg:rpm/suse/zabbix&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.12-4.45.1

Ecosystem specific

{
    "binaries": [
        {
            "zabbix-agent": "4.0.12-4.45.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0483-1.json"