SUSE-RU-2025:03425-1: important: Recommended update for libnvme, nvme-cli

SLE-UPDATES null at suse.de
Mon Sep 29 12:30:12 UTC 2025



# Recommended update for libnvme, nvme-cli

Announcement ID: SUSE-RU-2025:03425-1  
Release Date: 2025-09-29T09:44:08Z  
Rating: important  
References:

  * bsc#1246914

  
Affected Products:

  * Basesystem Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that has one fix can now be installed.

## Description:

This update for libnvme, nvme-cli fixes the following issues:

  * Fix libnvme/nvme-cli TLS PSK generation logic not compliant to RFC 8446
    (bsc#1246914):
    * linux: use EVP_PKEY_CTX_add1_hkdf_info only once in compat function
    * nvme/linux: check for empty digest in gen_tls_identity()
    * nvme/linux: add fallback implementation for nvme_insert_tls_key_compat()
    * linux: fix HKDF TLS key derivation back to OpenSSL 3.0.8
    * libnvme: TLS PSK derivation fixes
    * linux: rename __nvme_insert_tls_key_versioned() to __nvme_insert_tls_key()
    * linux: rename __nvme_insert_tls_key() to __nvme_import_tls_key()
    * test/psk: add testcase for TLS identity derivation
    * linux: set errno when nvme_generate_tls_key_identity() fails
    * nvme: add --compat flag for 'gen-tls-key' and 'check-tls-key'

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3425=1

## Package List:

  * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * libnvme-debuginfo-1.11+17.g61f36cae-150700.4.14.1
    * libnvme1-1.11+17.g61f36cae-150700.4.14.1
    * python3-libnvme-1.11+17.g61f36cae-150700.4.14.1
    * libnvme-debugsource-1.11+17.g61f36cae-150700.4.14.1
    * nvme-cli-debugsource-2.11+29.g61f8d34b-150700.3.12.1
    * libnvme-devel-1.11+17.g61f36cae-150700.4.14.1
    * libnvme-mi1-1.11+17.g61f36cae-150700.4.14.1
    * nvme-cli-debuginfo-2.11+29.g61f8d34b-150700.3.12.1
    * libnvme-mi1-debuginfo-1.11+17.g61f36cae-150700.4.14.1
    * nvme-cli-2.11+29.g61f8d34b-150700.3.12.1
    * python3-libnvme-debuginfo-1.11+17.g61f36cae-150700.4.14.1
    * libnvme1-debuginfo-1.11+17.g61f36cae-150700.4.14.1
  * Basesystem Module 15-SP7 (noarch)
    * nvme-cli-bash-completion-2.11+29.g61f8d34b-150700.3.12.1
    * nvme-cli-zsh-completion-2.11+29.g61f8d34b-150700.3.12.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1246914

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20250929/8e1e3f2e/attachment.htm>


More information about the sle-updates mailing list