🛡️ SUSE-RU-2025:4131-1 — python-cerberus (CVE-2025-55159)
Description
Recommended update for suse-migration-sle16-activation, SLES16-Migration, SLES16-SAP_Migration, suse-migration-services, suse-migration-rpm, wicked2nm, image-janitor
This update for suse-migration-sle16-activation, SLES16-Migration, SLES16-SAP_Migration, suse-migration-services, suse-migration-rpm, wicked2nm, image-janitor fixes the following issues:
Changes for suse-migration-sle16-activation:
- Simplify interface naming by disabling predictable names at boot
- shellcheck heavily complained
- check migration target before testing for architecture version
- Create systemd.link files for virtual VMware/Hyper-V NICs
- Add changes for newest wicked2nm
- Activation packages can no longer be noarch
- Architecture check before allowing migration to be activated
- Add missing pre snapshot setup to run_migration
- Add wicked2nm network migration
- Setup ExclusiveArch for activation packages
- Make activation package require by provides tag
- Fix product related requirement settings
Changes for SLES16-Migration:
- Added .ssh directory for migration user
- Add etc/motd overlay file
Print message how to show migration progress information
- Fix build on more architectures
- Initial changelog
Changes for SLES16-SAP_Migration:
- Support wicked2nm migration
- Migration live image for SLES4SAP 15 to 16
Changes for suse-migration-services:
- Set systemd offline for Zypper in chroot mode
- Fix apparmor install procedure
- Fixed azuremetadata device lookup
- Use of f-strings not allowed in the DMS
- Simplify interface naming by disabling predictable names at boot
- Fixed test_check_lsm_migration unit test
- Fix setup_host_network_test by mocking os.makedirs
- wicked2nm: log network state on nm-online failure
- Fixed LSM pre checks to be more robust
- shellcheck heavily complained
- Do not evaluate wicked2nm output in precheck
- Fix unit test for lsm check
- prechecks/lsm.py: remove _apparmor_analyze_profiles()
- LSM migration check for AppArmor -> SELinux
- Improve pre-check message
- Fix MinSLEVersion value depending on target
- reduce package set on migration image
- Fixed behavior of wicked2m pre check
- implementation of sshd root login pre-check
- Fixed selinux to apparmor migration
- Fixed reading of migration config for target class
- Add recursion guard to MigrationConfig::_merge_config_dicts
- shrink migration image
- container/sle16/config.sh
- sle16/config.sh - use dropin for s390 migration-config
- doc: fix indentation
- check for migration target by matching ISO file name
- config: introduce dropin dir migration-config.d/
- Apply SLE16 live image setup to container setup
- bind mount only required subdirectories under /run into chroot
- Add missing package requirement
- check migration target before testing for architecture version
- setup_host_network: simplify code - use os.makedirs()
- Create systemd.link files for virtual VMware/Hyper-V NIC
- Preserve systemd.link files from /etc/systemd/network/
- Add changes for the newest wicked2nm
- Ensure wicked2nm is a dependency of pre-checks for SLE 16 migration
- Activation packages can no longer be noarch
- Fix update of image .changes files
- Architecture check before allowing migration to be activated
- Improve error logs when wicked2nm fails
- Include image changelog to version bump
- Ensure wicked2nm migration is always running, despite warnings
- Fix: add --no-recommends on patterns-base-selinux installation
- Update suse-migration-services for container use
- Update SLE16 migration container
- Update SAP live migration image
- Add missing pre snapshot setup to run_migration
- Follow up fix for the wicked to nm migration
- Add wicked2nm network migration
- Add glob support to preserve_files
- Setup ExclusiveArch for activation packages
- Build sles4sap migration for cloud on x86_64 only
- Do not build sles4sap migration on s390x
- Use systemctl kexec
- Fix: return the correct kernel path based on machine type
- Fixed glob pattern match for package name
- Remove menitoning of SLES 12-SP4
- Make activation package require by provides tag
- Added SLES16-SAP_Migration live image
- Do not use list[str] type hint
- Fix error evaluation from offline_migrations API
- Fix logging from non unit files
- Fix product related requirement settings
- Repos for migration image must be in kiwi
- Added .ssh to migration user for SAP 15 live image
- Added SLES15-SAP_Migration Makefile target
- Add proper release package for SLE16 migration
- Fix typo in service name
- Drop obsolete check for resolv.conf
- Fix migration user home dir setup for SLE16
- Update README_QA.rst
- test: split unit test for setup_name_resolver
- Install patterns-base-selinux for Apparmor migration
- Ensure the rebuild counter is not stripped from the rpm
- Exit silently if no migration iso is found
- Ensure rpmlintrc file is part of suse-migration-services SRPM
- Ignore fixup! entries when generating changelog
- Increase python test matrix
- Remove redundanct requires on itself
- Fix
Affected software
SUSE-RU-2025:4131-1 is recorded against 6 packages.
- python-cerberus (fixed in 1.3.2-150700.20.2.10)
- sles16-migration (fixed in 2.1.26-15.22.4)
- sles16-sap-migration (fixed in 2.1.26-15.14.4)
- suse-migration-services (fixed in 2.1.26-150700.16.12.1)
- suse-migration-sle16-activation (fixed in 2.1.26-150700.15.9.1)
- wicked2nm (fixed in 1.4.0-150700.15.7.2)
Timeline and source
Published on 18 November 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| python-cerberus | — | 1.3.2-150700.20.2.10 |
| sles16-migration | — | 2.1.26-15.22.4 |
| sles16-sap-migration | — | 2.1.26-15.14.4 |
| suse-migration-services | — | 2.1.26-150700.16.12.1 |
| suse-migration-sle16-activation | — | 2.1.26-150700.15.9.1 |
| wicked2nm | — | 1.4.0-150700.15.7.2 |
References
Free Vulnerability Check
Is your site affected by SUSE-RU-2025:4131-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-RU-2025:4131-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.