🛡️ SUSE-SU-2025:3819-1 — dracut-saltboot (CVE-2025-47908 +3 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update 5.1.1 for Multi-Linux Manager Client Tools

This update fixes the following issues:

dracut-saltboot was updated from version 0.1 to version 1.0.0:

  • Version 1.0.0 bugs fixed:
  • Reboot on salt key timeout (bsc#1237495)
  • Fixed parsing files with space in the name (bsc#1252100)

golang-github-prometheus-alertmanager was updated from version 0.26.0 to 0.28.1 to :

  • Security issues fixed:
  • CVE-2025-47908: Fixed a Denial of Service vulnerability (bsc#1247748)
  • Version 0.28.1 changes and bugs fixed (jsc#PED-13285):
  • Improved performance of inhibition rules when using Equal

labels.

  • Improve the documentation on escaping in UTF-8 matchers.
  • Update alertmanager_config_hash metric help to document the

hash is not cryptographically strong.

  • Fixed panic in amtool when using --verbose.
  • Fixed templating of channel field for Rocket.Chat.
  • Fixed rocketchat_configs written as rocket_configs in docs.
  • Fixed usage for --enable-feature flag.
  • Trim whitespace from OpsGenie API Key.
  • Fixed Jira project template not rendered when searching for

existing issues.

  • Fixed subtle bug in JSON/YAML encoding of inhibition rules that

would cause Equal labels to be omitted.

  • Fixed header for slack_configs in docs.
  • Fixed weight and wrap of Microsoft Teams notifications.
  • Version 0.28.0 changes and bugs fixed:
  • Templating errors in the SNS integration now return an error.
  • Adopt log/slog, drop go-kit/log.
  • Added a new Microsoft Teams integration based on Flows.
  • Added a new Rocket.Chat integration.
  • Added a new Jira integration.
  • Added support for GOMEMLIMIT, enable it via the feature flag

--enable-feature=auto-gomemlimit.

  • Added support for GOMAXPROCS, enable it via the feature flag

--enable-feature=auto-gomaxprocs.

  • Added support for limits of silences including the maximum number

of active and pending silences, and the maximum size per

silence (in bytes). You can use the flags

--silences.max-silences and --silences.max-silence-size-bytes

to set them accordingly.

  • Muted alerts now show whether they are suppressed or not in

both the /api/v2/alerts endpoint and the Alertmanager UI.

  • Version 0.27.0 changes and bugs fixed:
  • API: Removal of all api/v1/ endpoints. These endpoints

now log and return a deprecation message and respond with a

status code of 410.

  • UTF-8 Support: Introduction of support for any UTF-8

character as part of label names and matchers.

  • Discord Integration: Enforce max length in message.
  • Metrics: Introduced the experimental feature flag

--enable-feature=receiver-name-in-metrics to include the

receiver name.

  • Metrics: Introduced a new gauge named

alertmanager_inhibition_rules that counts the number of

configured inhibition rules.

  • Metrics: Introduced a new counter named

alertmanager_alerts_supressed_total that tracks muted alerts,

it contains a reason label to indicate the source of the mute.

  • Discord Integration: Introduced support for webhook_url_file.
  • Microsoft Teams Integration: Introduced support for

webhook_url_file.

  • Microsoft Teams Integration: Added support for summary.
  • Metrics: Notification metrics now support two new values for

the label reason, contextCanceled and contextDeadlineExceeded.

  • Email Integration: Contents of auth_password_file are now

trimmed of prefixed and suffixed whitespace.

  • amtool: Fixes the error scheme required for webhook url when

using amtool with --alertmanager.url.

  • Mixin: Fixed AlertmanagerFailedToSendAlerts,

AlertmanagerClusterFailedToSendAlerts, and

AlertmanagerClusterFailedToSendAlerts to make sure they ignore

the reason label.

grafana was updated to from version 11.5.5 to 11.5.7:

  • Security issues fixed:
  • CVE-2025-6023: Fixed cross-site-scripting via scripted dashboards (bsc#1246735)
  • CVE-2025-6197: Fixed open redirect in organization switching (bsc#1246736)
  • CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)
  • Other bugs fixed:
  • Azure: Fixed legend formatting.
  • Azure: Fixed resource name determination in template variable queries.

mgr-push was updated from version 5.1.3 to 5.1.4:

  • Use absolute paths when invoking external commands

python-defusedxml:

  • New package implemented at version 0.7.1

rhnlib was updated from version 5.1.2 to 5.1.3:

  • Use more secure defusedxml parser (bsc#1227577)

spacecmd was updated from version 5.1.8 to 5.1.11:

  • Version 5.1.11 changes and bugs fixed:
  • Make spacecmd work with Python 3.12 and higher
  • Call print statements properly in Python 3
  • Version 5.1.10 changes and bugs fixed:
  • Fixed use of renamed config parser class where the backward

compatible alias was dropped in latest python version

(bsc#1246586)

  • Version 5.1.9 changes and bugs fixed:
  • Fixed installation of python lib files on Ubuntu

Affected software

SUSE-SU-2025:3819-1 is recorded against 10 packages.

  • dracut-saltboot (fixed in 1.0.0-150002.3.3.1)
  • golang-github-prometheus-alertmanager (fixed in 0.28.1-150002.4.3.3)
  • grafana (fixed in 11.5.7-150002.4.3.3)
  • mgr-push (fixed in 5.1.4-150002.3.3.3)
  • python-defusedxml (fixed in 0.7.1-150002.1.3.2)
  • rhnlib (fixed in 5.1.3-150002.3.3.2)
  • spacecmd (fixed in 5.1.11-150002.3.3.2)
  • spacewalk-client-tools (fixed in 5.1.7-150002.3.3.3)
  • supportutils-plugin-susemanager-client (fixed in 5.1.4-150002.3.3.2)
  • uyuni-tools (fixed in 5.1.20-150002.3.3.3)

Timeline and source

Published on 28 October 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-10-28
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
dracut-saltboot 1.0.0-150002.3.3.1
golang-github-prometheus-alertmanager 0.28.1-150002.4.3.3
grafana 11.5.7-150002.4.3.3
mgr-push 5.1.4-150002.3.3.3
python-defusedxml 0.7.1-150002.1.3.2
rhnlib 5.1.3-150002.3.3.2
spacecmd 5.1.11-150002.3.3.2
spacewalk-client-tools 5.1.7-150002.3.3.3
supportutils-plugin-susemanager-client 5.1.4-150002.3.3.2
uyuni-tools 5.1.20-150002.3.3.3

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:3819-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:3819-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025