openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp
[email protected] Fri, 24 Jul 2026 17:53:48 +0200 (CEST)
| Newsgroups | gmane.linux.suse.security.announce |
|---|---|
| Message-ID | <[email protected]> |
openSUSE security update: security update for shibboleth-sp
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21418-1
Rating: important
References:
* bsc#1249394
Cross-References:
* CVE-2025-9943
CVSS scores:
* CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for shibboleth-sp fixes the following issue
- CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth
Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1329=1
Package List:
- openSUSE Leap 16.0:
libshibsp-lite12-3.5.0-160000.3.1
libshibsp12-3.5.0-160000.3.1
shibboleth-sp-3.5.0-160000.3.1
shibboleth-sp-devel-3.5.0-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2025-9943.html