Linuxsecurity SUSE Linux Micro 6.2 gnutls Vulnerabilities Addressed in Latest Update
Article Content
- •SUSE Linux Micro 6.2 has released a critical update addressing two vulnerabilities.
- •CVE-2025-14831 allows for DoS attacks through resource exhaustion during certificate verification.
- •Users are urged to apply the update immediately to mitigate risks associated with these vulnerabilities.
On April 8, 2026, SUSE released an update for gnutls in SUSE Linux Micro 6.2 to address two vulnerabilities: CVE-2025-14831 and CVE-2025-9820. CVE-2025-14831 involves a denial-of-service (DoS) attack that can occur due to excessive resource consumption during certificate verification. CVE-2025-9820 is a buffer overflow vulnerability in the gnutls_pkcs11_token_init function. Both vulnerabilities were reported and have been patched, with the update also adding functionality to specify the hash algorithm for the PSK. The affected systems include various architectures of SUSE Linux Micro 6.2. Users are advised to apply the update using recommended installation methods such as YaST or zypper patch. The vulnerabilities were published on January 26, 2026, and February 9, 2026, respectively. The update is crucial for maintaining system security and preventing potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2025-14831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…