SUSE-SU-2026:3123-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263123-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3123-1
Upstream
Related
Published
2026-07-20T07:01:11Z
Modified
2026-07-21T09:45:06Z
Summary
Security update for shibboleth-sp
Details

This update for shibboleth-sp fixes the following issue:

  • CVE-2025-9943: SQL injection in the 'ID' attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Module for Server Applications 15 SP7
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:rpm/suse/shibboleth-sp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.0-150300.3.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "libshibsp-lite8":  "3.1.0-150300.3.6.1",
            "libshibsp9":  "3.1.0-150300.3.6.1",
            "shibboleth-sp":  "3.1.0-150300.3.6.1",
            "shibboleth-sp-devel":  "3.1.0-150300.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3123-1.json"