{"schema_version":"1.7.3","id":"SUSE-SU-2025:1332-1","published":"2025-04-17T01:37:13Z","modified":"2026-02-04T04:32:24.175510Z","related":["CVE-2023-45288","CVE-2024-6104","CVE-2025-22868","CVE-2025-22869","CVE-2025-27144","CVE-2025-30204"],"upstream":["CVE-2023-45288","CVE-2024-6104","CVE-2025-22868","CVE-2025-22869","CVE-2025-27144","CVE-2025-30204"],"summary":"Security update for rekor","details":"This update for rekor fixes the following issues:\n\n- CVE-2023-45288: rekor: golang.org/x/net/http2: Fixed close connections when receiving too many headers (bsc#1236519)\n- CVE-2024-6104: rekor: hashicorp/go-retryablehttp: Fixed sensitive information disclosure inside log file (bsc#1227053)\n- CVE-2025-22868: rekor: golang.org/x/oauth2/jws: Fixed unexpected memory consumption during token parsing (bsc#1239191)\n- CVE-2025-22869: rekor: golang.org/x/crypto/ssh: Fixed denial of service in the Key Exchange (bsc#1239327)\n- CVE-2025-27144: rekor: gopkg.in/go-jose/go-jose.v2,github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: Fixed denial of service in Go JOSE's parsing (bsc#1237638)\n- CVE-2025-30204: rekor: github.com/golang-jwt/jwt/v5: Fixed jwt-go allowing excessive memory allocation during header parsing (bsc#1240468)\n\nOther fixes:\n\n- Update to version 1.3.10:\n  * Features\n    - Added --client-signing-algorithms flag (#1974)\n  * Fixes / Misc\n    - emit unpopulated values when marshalling (#2438)\n    - pkg/api: better logs when algorithm registry rejects a key\n      (#2429)\n    - chore: improve mysql readiness checks (#2397)\n    - Added --client-signing-algorithms flag (#1974)\n\n- Update to version 1.3.9 (jsc#SLE-23476):\n  * Cache checkpoint for inactive shards (#2332)\n  * Support per-shard signing keys (#2330)\n\n- Update to version 1.3.8:\n  * Bug Fixes\n    - fix zizmor issues (#2298)\n    - remove unneeded value in log message (#2282)\n  * Quality Enhancements\n    - chore: relax go directive to permit 1.22.x\n    - fetch minisign from homebrew instead of custom ppa (#2329)\n    - fix(ci): simplify GOVERSION extraction\n    - chore(deps): bump actions pins to latest\n    - Updates go and golangci-lint (#2302)\n    - update builder to use go1.23.4 (#2301)\n    - clean up spaces\n    - log request body on 500 error to aid debugging (#2283)\n\n- Update to version 1.3.7:\n  * New Features\n    - log request body on 500 error to aid debugging (#2283)\n    - Add support for signing with Tink keyset (#2228)\n    - Add public key hash check in Signed Note verification (#2214)\n    - update Trillian TLS configuration (#2202)\n    - Add TLS support for Trillian server (#2164)\n    - Replace docker-compose with plugin if available (#2153)\n    - Add flags to backfill script (#2146)\n    - Unset DisableKeepalive for backfill HTTP client (#2137)\n    - Add script to delete indexes from Redis (#2120)\n    - Run CREATE statement in backfill script (#2109)\n    - Add MySQL support to backfill script (#2081)\n    - Run e2e tests on mysql and redis index backends (#2079)\n  * Bug Fixes\n    - remove unneeded value in log message (#2282)\n    - Add error message when computing consistency proof (#2278)\n    - fix validation error handling on API (#2217)\n    - fix error in pretty-printed inclusion proof from verify\n      subcommand (#2210)\n    - Fix index scripts (#2203)\n    - fix failing sharding test\n    - Better error handling in backfill script (#2148)\n    - Batch entries in cleanup script (#2158)\n    - Add missing workflow for index cleanup test (#2121)\n    - hashedrekord: fix schema $id (#2092)\n","affected":[{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP6","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Manager Proxy 4.3","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Manager%20Proxy%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"SUSE:Manager Server 4.3","purl":"pkg:rpm/suse/rekor&distro=SUSE%20Manager%20Server%204.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}},{"package":{"name":"rekor","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/rekor&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.10-150400.4.25.1"}]}],"ecosystem_specific":{"binaries":[{"rekor":"1.3.10-150400.4.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1332-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-20251332-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236519"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239191"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22868"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-27144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30204"}]}