openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp

[email protected] Fri, 24 Jul 2026 17:53:48 +0200 (CEST)
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
openSUSE security update: security update for shibboleth-sp
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21418-1
Rating: important
References:

  * bsc#1249394



Cross-References:

  * CVE-2025-9943



CVSS scores:

  * CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products:

         openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for shibboleth-sp fixes the following issue

- CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth
  Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).


Patch instructions:

   To install this openSUSE security update use the suse recommended installation methods
   like YaST online_update or "zypper patch".
   Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

   zypper in -t patch openSUSE-Leap-16.0-1329=1

Package List:

- openSUSE Leap 16.0:

  libshibsp-lite12-3.5.0-160000.3.1
  libshibsp12-3.5.0-160000.3.1
  shibboleth-sp-3.5.0-160000.3.1
  shibboleth-sp-devel-3.5.0-160000.3.1

References:

  * https://www.suse.com/security/cve/CVE-2025-9943.html