🛡️ SUSE-SU-2025:3826-1 — rhnlib (CVE-2025-53883)
Description
Security update 4.3.16.1 for SUSE Manager Server 4.3 LTS
This update fixes the following issues:
susemanager-build-keys:
- Update SUSE GPG key and make it available for Salt (bsc#1250911)
susemanager-sls:
- Version 4.3.50-0
- Fix OS Family grain name (bsc#1250911)
- Version 4.3.49-0
- Fixed syntax error in Salt state
- Version 4.3.48-0
- Automatically deploy the SUSE GPG key (bsc#1250911)
spacewalk-java:
- Version 4.3.88-0 with security fix:
- CVE-2025-53883: Escape input strings in system search form (bsc#1246439)
rhnlib:
- Version 4.3.7-0:
- Use more secure defusedxml parser (bsc#1227577)
spacewalk-backend:
- Version 4.3.34-0:
- Use more secure defusedxml parser (bsc#1227577)
spacewalk-web:
- Version 4.3.46-0:
- Bumped the WebUI version to 4.3.16.1
How to apply this update:
1. Log in as root user to the Multi-Linux Manager Server.
2. Stop the Spacewalk service:
spacewalk-service stop
3. Apply the patch using either zypper patch or YaST Online Update.
4. Start the Spacewalk service:
spacewalk-service start
Affected software
SUSE-SU-2025:3826-1 is recorded against 7 packages.
- rhnlib (fixed in 4.3.7-150400.3.9.4)
- spacewalk-backend (fixed in 4.3.34-150400.3.58.6)
- spacewalk-java (fixed in 4.3.88-150400.3.113.5)
- spacewalk-web (fixed in 4.3.46-150400.3.63.5)
- susemanager-build-keys (fixed in 15.4.11-150400.3.38.1)
- susemanager-sls (fixed in 4.3.50-150400.3.68.1)
- susemanager-tftpsync-recv (fixed in 4.3.11-150400.3.15.3)
Timeline and source
Published on 28 October 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| rhnlib | — | 4.3.7-150400.3.9.4 |
| spacewalk-backend | — | 4.3.34-150400.3.58.6 |
| spacewalk-java | — | 4.3.88-150400.3.113.5 |
| spacewalk-web | — | 4.3.46-150400.3.63.5 |
| susemanager-build-keys | — | 15.4.11-150400.3.38.1 |
| susemanager-sls | — | 4.3.50-150400.3.68.1 |
| susemanager-tftpsync-recv | — | 4.3.11-150400.3.15.3 |
References
Similar Threats
- Unknown SUSE-SU-2025:3817-1
- Unknown SUSE-SU-2025:3819-1
- Unknown SUSE-SU-2024:3266-1
- Unknown SUSE-SU-2024:3267-1
- Unknown RHEA-2013:1392
Free Vulnerability Check
Is your site affected by SUSE-SU-2025:3826-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:3826-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.