SUSE-SU-2026:3549-1: moderate: Security update for python3-sqlparse
SUSE-SU-2026:3554-1: important: Security update for bind
SUSE-SU-2026:3558-1: important: Security update for perl
SUSE-SU-2026:3560-1: important: Security update for python311
SUSE-SU-2026:3561-1: moderate: Security update for PackageKit
SUSE-SU-2026:3569-1: important: Security update for python312
openSUSE-SU-2026:11487-1: moderate: java-1_8_0-openj9-1.8.0.502-1.1 on GA media
openSUSE-SU-2026:11490-1: moderate: libpcp-devel-6.3.8-3.1 on GA media
openSUSE-SU-2026:11482-1: moderate: wild-0.10.0-2.1 on GA media
openSUSE-SU-2026:11488-1: moderate: java-21-openj9-21.0.12.0-1.1 on GA media
openSUSE-SU-2026:11491-1: moderate: python313-Django5-5.2.17-1.1 on GA media
openSUSE-SU-2026:11489-1: moderate: java-25-openj9-25.0.4.0-1.1 on GA media
openSUSE-SU-2026:11486-1: moderate: java-17-openj9-17.0.20.0-1.1 on GA media
openSUSE-SU-2026:11485-1: moderate: java-11-openj9-11.0.32.0-1.1 on GA media
openSUSE-SU-2026:11484-1: moderate: chromedriver-151.0.7922.108-1.1 on GA media
openSUSE-SU-2026:11483-1: moderate: zpaqfranz-64.8-1.1 on GA media
SUSE-SU-2026:3571-1: moderate: Security update for ImageMagick
SUSE-SU-2026:3572-1: moderate: Security update for xmlrpc-c
SUSE-SU-2026:3573-1: moderate: Security update for gstreamer-plugins-bad
SUSE-SU-2026:3575-1: moderate: Security update for libarchive
SUSE-SU-2026:3576-1: important: Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update
SUSE-SU-2026:3577-1: important: Security update for snpguest
openSUSE-SU-2026:0280-1: important: Security update for go-sendxmpp
SUSE-SU-2026:3579-1: important: Security update for erlang26
SUSE-SU-2026:3588-1: moderate: Security update for python3-pip
SUSE-SU-2026:3589-1: moderate: Security update for python-pip
SUSE-SU-2026:3549-1: moderate: Security update for python3-sqlparse
# Security update for python3-sqlparse
Announcement ID: SUSE-SU-2026:3549-1
Release Date: 2026-08-10T16:35:52Z
Rating: moderate
References:
* bsc#1268597
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that has one security fix can now be installed.
## Description:
This update for python3-sqlparse fixes the following issue:
* Fixed an issue where formatting list of tuples leads to denial of service
(bsc#1268597).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3549=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3549=1
## Package List:
* Basesystem Module 15-SP7 (noarch)
* python3-sqlparse-0.4.2-150300.20.1
* openSUSE Leap 15.3 (noarch)
* python3-sqlparse-0.4.2-150300.20.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id68597
SUSE-SU-2026:3554-1: important: Security update for bind
# Security update for bind
Announcement ID: SUSE-SU-2026:3554-1
Release Date: 2026-08-10T16:49:22Z
Rating: important
References:
* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990
Cross-References:
* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321
CVSS scores:
* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities can now be installed.
## Description:
This update for bind fixes the following issues:
* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3554=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3554=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3554=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3554=1
## Package List:
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* bind-chrootenv-9.16.6-150300.22.62.1
* libns1604-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* bind-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccc1600-debuginfo-9.16.6-150300.22.62.1
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libbind9-1600-9.16.6-150300.22.62.1
* bind-utils-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-utils-debuginfo-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccc1600-9.16.6-150300.22.62.1
* libbind9-1600-debuginfo-9.16.6-150300.22.62.1
* bind-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libns1604-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* openSUSE Leap 15.3 (noarch)
* bind-doc-9.16.6-150300.22.62.1
* python3-bind-9.16.6-150300.22.62.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990
SUSE-SU-2026:3558-1: important: Security update for perl
# Security update for perl
Announcement ID: SUSE-SU-2026:3558-1
Release Date: 2026-08-10T18:02:15Z
Rating: important
References:
* bsc#1266304
* bsc#1268349
* bsc#1271372
Cross-References:
* CVE-2026-12087
* CVE-2026-57432
* CVE-2026-8376
CVSS scores:
* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-57432 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-8376 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-8376 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-8376 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products:
* Basesystem Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves three vulnerabilities can now be installed.
## Description:
This update for perl fixes the following issues:
* CVE-2026-8376: heap buffer overflow when compiling regular expressions with
a repeated fixed string on 32-bit builds (bsc#1266304).
* CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap
memory into the returned packed structure (bsc#1268349).
* CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-
of-bounds heap read in `pack` and `unpack` (bsc#1271372).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3558=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3558=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3558=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3558=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3558=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3558=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3558=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3558=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3558=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3558=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3558=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3558=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3558=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3558=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3558=1
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3558=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3558=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3558=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3558=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (aarch64_ilp32)
* perl-base-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-64bit-5.26.1-150300.17.23.1
* perl-64bit-5.26.1-150300.17.23.1
* perl-base-64bit-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (x86_64)
* perl-32bit-5.26.1-150300.17.23.1
* perl-core-DB_File-32bit-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-32bit-debuginfo-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* Basesystem Module 15-SP7 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* Development Tools Module 15-SP7 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Package Hub 15 15-SP7 (x86_64)
* perl-32bit-5.26.1-150300.17.23.1
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
## References:
* https://www.suse.com/security/cve/CVE-2026-12087.html
* https://www.suse.com/security/cve/CVE-2026-57432.html
* https://www.suse.com/security/cve/CVE-2026-8376.html
* https://bugzilla.suse.com/show_bug.cgi?id66304
* https://bugzilla.suse.com/show_bug.cgi?id68349
* https://bugzilla.suse.com/show_bug.cgi?id71372
SUSE-SU-2026:3560-1: important: Security update for python311
# Security update for python311
Announcement ID: SUSE-SU-2026:3560-1
Release Date: 2026-08-10T18:09:32Z
Rating: important
References:
* bsc#1264962
* bsc#1265268
* bsc#1267581
* bsc#1267821
* bsc#1268375
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269959
* bsc#1271192
Cross-References:
* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-15308
* CVE-2026-3276
* CVE-2026-4360
* CVE-2026-7210
* CVE-2026-7774
* CVE-2026-8328
CVSS scores:
* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves nine vulnerabilities and has one security fix can now be
installed.
## Description:
This update for python311 fixes the following issues:
Security issues fixed:
* CVE-2026-0864: improper handling of line-ending characters can lead to
configuration file injection when the `configparser` module is used
(bsc#1269066).
* CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
DoS when processing specially crafted Unicode input (bsc#1267581).
* CVE-2026-4360: in the `Tarfile.extract()` function, the filter parameter is
not passed properly when extracting hardlinks (bsc#1269959).
* CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
insufficient entropy for Expat hash-flooding protection (bsc#1264962).
* CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
outside the extraction directory (bsc#1267821).
* CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
supplied PASV host address (bsc#1265268).
* CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
allows escaping the destination directory and enables arbitrary file reads
and writes (bsc#1268977).
* CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
module streaming mode can lead to DoS (bsc#1269788).
* CVE-2026-15308: incremental `HTMLParser` allows CPU-exhaustion DoS via
repeated unterminated markup declarations (bsc#1271192).
Non security issue fixed:
* Improve testing for the support of `IPPROTO_UDPLITE`, which could be not
present although header files are (bsc#1268375).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3560=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3560=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3560=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3560=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3560=1
## Package List:
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-doc-3.11.15-150600.3.62.1
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-doc-devhelp-3.11.15-150600.3.62.1
* python311-devel-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-testsuite-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-testsuite-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (x86_64)
* python311-base-32bit-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-32bit-3.11.15-150600.3.62.2
* python311-32bit-3.11.15-150600.3.62.2
* python311-base-32bit-3.11.15-150600.3.62.2
* libpython3_11-1_0-32bit-debuginfo-3.11.15-150600.3.62.2
* python311-32bit-debuginfo-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* python311-base-64bit-3.11.15-150600.3.62.2
* python311-base-64bit-debuginfo-3.11.15-150600.3.62.2
* python311-64bit-3.11.15-150600.3.62.2
* libpython3_11-1_0-64bit-debuginfo-3.11.15-150600.3.62.2
* python311-64bit-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-64bit-3.11.15-150600.3.62.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
## References:
* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://bugzilla.suse.com/show_bug.cgi?id64962
* https://bugzilla.suse.com/show_bug.cgi?id65268
* https://bugzilla.suse.com/show_bug.cgi?id67581
* https://bugzilla.suse.com/show_bug.cgi?id67821
* https://bugzilla.suse.com/show_bug.cgi?id68375
* https://bugzilla.suse.com/show_bug.cgi?id68977
* https://bugzilla.suse.com/show_bug.cgi?id69066
* https://bugzilla.suse.com/show_bug.cgi?id69788
* https://bugzilla.suse.com/show_bug.cgi?id69959
* https://bugzilla.suse.com/show_bug.cgi?id71192
SUSE-SU-2026:3561-1: moderate: Security update for PackageKit
# Security update for PackageKit
Announcement ID: SUSE-SU-2026:3561-1
Release Date: 2026-08-10T18:12:19Z
Rating: moderate
References:
* bsc#1267250
Cross-References:
* CVE-2026-10294
CVSS scores:
* CVE-2026-10294 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-10294 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products:
* openSUSE Leap 15.4
An update that solves one vulnerability can now be installed.
## Description:
This update for PackageKit fixes the following issues:
* CVE-2026-10294: manipulation of the argument frontend-socket can lead to
improper authorization (bsc#1267250).
## Special Instructions and Notes:
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3561=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* PackageKit-debugsource-1.2.4-150400.3.34.1
* PackageKit-devel-debuginfo-1.2.4-150400.3.34.1
* typelib-1_0-PackageKitGlib-1_0-1.2.4-150400.3.34.1
* PackageKit-gstreamer-plugin-1.2.4-150400.3.34.1
* PackageKit-devel-1.2.4-150400.3.34.1
* PackageKit-debuginfo-1.2.4-150400.3.34.1
* PackageKit-gtk3-module-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-devel-1.2.4-150400.3.34.1
* PackageKit-gtk3-module-1.2.4-150400.3.34.1
* PackageKit-1.2.4-150400.3.34.1
* PackageKit-backend-zypp-debuginfo-1.2.4-150400.3.34.1
* PackageKit-gstreamer-plugin-debuginfo-1.2.4-150400.3.34.1
* PackageKit-backend-dnf-1.2.4-150400.3.34.1
* PackageKit-backend-zypp-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-1.2.4-150400.3.34.1
* PackageKit-backend-dnf-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-debuginfo-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (noarch)
* PackageKit-branding-upstream-1.2.4-150400.3.34.1
* PackageKit-lang-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libpackagekit-glib2-devel-64bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-64bit-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-64bit-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (x86_64)
* libpackagekit-glib2-18-32bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-devel-32bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-32bit-debuginfo-1.2.4-150400.3.34.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10294.html
* https://bugzilla.suse.com/show_bug.cgi?id67250
SUSE-SU-2026:3569-1: important: Security update for python312
# Security update for python312
Announcement ID: SUSE-SU-2026:3569-1
Release Date: 2026-08-11T08:02:52Z
Rating: important
References:
* bsc#1211301
* bsc#1264962
* bsc#1265268
* bsc#1267581
* bsc#1267821
* bsc#1268375
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269959
* bsc#1271192
Cross-References:
* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-15308
* CVE-2026-3276
* CVE-2026-4360
* CVE-2026-7210
* CVE-2026-7774
* CVE-2026-8328
CVSS scores:
* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves nine vulnerabilities and has two security fixes can now be
installed.
## Description:
This update for python312 fixes the following issues:
Security issues fixed:
* CVE-2026-0864: improper handling of line-ending characters can lead to
configuration file injection when the `configparser` module is used
(bsc#1269066).
* CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
DoS when processing specially crafted Unicode input (bsc#1267581).
* CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is
not passed properly when extracting hardlinks (bsc#1269959).
* CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
insufficient entropy for Expat hash-flooding protection (bsc#1264962).
* CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
outside the extraction directory (bsc#1267821).
* CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
supplied PASV host address (bsc#1265268).
* CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
allows escaping the destination directory and enables arbitrary file reads
and writes (bsc#1268977).
* CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
module streaming mode can lead to DoS (bsc#1269788).
* CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via
repeated unterminated markup declarations (bsc#1271192).
Non security issues fixed:
* [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
* crypto-policies: Extend the crypto-policies support for mozilla-nss,
openjdk, krb5, bind, stunnel, openssh, libssh and more packages
(bsc#1211301).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3569=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3569=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3569=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-tk-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-base-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-debugsource-3.12.13-150600.3.62.1
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-idle-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-base-3.12.13-150600.3.62.3
* python312-doc-devhelp-3.12.13-150600.3.62.1
* python312-idle-3.12.13-150600.3.62.1
* python312-testsuite-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-tk-3.12.13-150600.3.62.1
* python312-doc-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-testsuite-debuginfo-3.12.13-150600.3.62.3
* python312-debugsource-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* python312-base-64bit-3.12.13-150600.3.62.3
* libpython3_12-1_0-64bit-3.12.13-150600.3.62.3
* libpython3_12-1_0-64bit-debuginfo-3.12.13-150600.3.62.3
* python312-64bit-3.12.13-150600.3.62.1
* python312-base-64bit-debuginfo-3.12.13-150600.3.62.3
* python312-64bit-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (x86_64)
* libpython3_12-1_0-32bit-debuginfo-3.12.13-150600.3.62.3
* python312-base-32bit-debuginfo-3.12.13-150600.3.62.3
* libpython3_12-1_0-32bit-3.12.13-150600.3.62.3
* python312-base-32bit-3.12.13-150600.3.62.3
* python312-32bit-3.12.13-150600.3.62.1
* python312-32bit-debuginfo-3.12.13-150600.3.62.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-tk-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* python312-base-3.12.13-150600.3.62.3
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* python312-debugsource-3.12.13-150600.3.62.1
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-idle-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1
## References:
* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://bugzilla.suse.com/show_bug.cgi?id11301
* https://bugzilla.suse.com/show_bug.cgi?id64962
* https://bugzilla.suse.com/show_bug.cgi?id65268
* https://bugzilla.suse.com/show_bug.cgi?id67581
* https://bugzilla.suse.com/show_bug.cgi?id67821
* https://bugzilla.suse.com/show_bug.cgi?id68375
* https://bugzilla.suse.com/show_bug.cgi?id68977
* https://bugzilla.suse.com/show_bug.cgi?id69066
* https://bugzilla.suse.com/show_bug.cgi?id69788
* https://bugzilla.suse.com/show_bug.cgi?id69959
* https://bugzilla.suse.com/show_bug.cgi?id71192
openSUSE-SU-2026:11487-1: moderate: java-1_8_0-openj9-1.8.0.502-1.1 on GA media
# java-1_8_0-openj9-1.8.0.502-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11487-1
Rating: moderate
Cross-References:
* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-46968
* CVE-2026-47021
* CVE-2026-47058
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 7 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-1_8_0-openj9-1.8.0.502-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-1_8_0-openj9 1.8.0.502-1.1
* java-1_8_0-openj9-accessibility 1.8.0.502-1.1
* java-1_8_0-openj9-demo 1.8.0.502-1.1
* java-1_8_0-openj9-devel 1.8.0.502-1.1
* java-1_8_0-openj9-headless 1.8.0.502-1.1
* java-1_8_0-openj9-javadoc 1.8.0.502-1.1
* java-1_8_0-openj9-src 1.8.0.502-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47058.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
openSUSE-SU-2026:11490-1: moderate: libpcp-devel-6.3.8-3.1 on GA media
# libpcp-devel-6.3.8-3.1 on GA media
Announcement ID: openSUSE-SU-2026:11490-1
Rating: moderate
Cross-References:
* CVE-2026-16524
* CVE-2026-16526
* CVE-2026-16527
* CVE-2026-16529
* CVE-2026-16530
* CVE-2026-16531
CVSS scores:
* CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 6 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the libpcp-devel-6.3.8-3.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* libpcp-devel 6.3.8-3.1
* libpcp3 6.3.8-3.1
* libpcp_gui2 6.3.8-3.1
* libpcp_import1 6.3.8-3.1
* libpcp_mmv1 6.3.8-3.1
* libpcp_trace2 6.3.8-3.1
* libpcp_web1 6.3.8-3.1
* pcp 6.3.8-3.1
* pcp-conf 6.3.8-3.1
* pcp-devel 6.3.8-3.1
* pcp-doc 6.3.8-3.1
* pcp-export-pcp2elasticsearch 6.3.8-3.1
* pcp-export-pcp2graphite 6.3.8-3.1
* pcp-export-pcp2influxdb 6.3.8-3.1
* pcp-export-pcp2json 6.3.8-3.1
* pcp-export-pcp2spark 6.3.8-3.1
* pcp-export-pcp2xml 6.3.8-3.1
* pcp-export-pcp2zabbix 6.3.8-3.1
* pcp-gui 6.3.8-3.1
* pcp-import-collectl2pcp 6.3.8-3.1
* pcp-import-ganglia2pcp 6.3.8-3.1
* pcp-import-iostat2pcp 6.3.8-3.1
* pcp-import-mrtg2pcp 6.3.8-3.1
* pcp-import-sar2pcp 6.3.8-3.1
* pcp-import-sheet2pcp 6.3.8-3.1
* pcp-pmda-activemq 6.3.8-3.1
* pcp-pmda-amdgpu 6.3.8-3.1
* pcp-pmda-apache 6.3.8-3.1
* pcp-pmda-bash 6.3.8-3.1
* pcp-pmda-bonding 6.3.8-3.1
* pcp-pmda-cifs 6.3.8-3.1
* pcp-pmda-cisco 6.3.8-3.1
* pcp-pmda-dbping 6.3.8-3.1
* pcp-pmda-dm 6.3.8-3.1
* pcp-pmda-docker 6.3.8-3.1
* pcp-pmda-ds389 6.3.8-3.1
* pcp-pmda-ds389log 6.3.8-3.1
* pcp-pmda-elasticsearch 6.3.8-3.1
* pcp-pmda-gfs2 6.3.8-3.1
* pcp-pmda-gluster 6.3.8-3.1
* pcp-pmda-gpfs 6.3.8-3.1
* pcp-pmda-gpsd 6.3.8-3.1
* pcp-pmda-hacluster 6.3.8-3.1
* pcp-pmda-haproxy 6.3.8-3.1
* pcp-pmda-infiniband 6.3.8-3.1
* pcp-pmda-json 6.3.8-3.1
* pcp-pmda-lio 6.3.8-3.1
* pcp-pmda-lmsensors 6.3.8-3.1
* pcp-pmda-logger 6.3.8-3.1
* pcp-pmda-lustre 6.3.8-3.1
* pcp-pmda-lustrecomm 6.3.8-3.1
* pcp-pmda-mailq 6.3.8-3.1
* pcp-pmda-memcache 6.3.8-3.1
* pcp-pmda-mic 6.3.8-3.1
* pcp-pmda-mounts 6.3.8-3.1
* pcp-pmda-mysql 6.3.8-3.1
* pcp-pmda-named 6.3.8-3.1
* pcp-pmda-netcheck 6.3.8-3.1
* pcp-pmda-netfilter 6.3.8-3.1
* pcp-pmda-news 6.3.8-3.1
* pcp-pmda-nfsclient 6.3.8-3.1
* pcp-pmda-nginx 6.3.8-3.1
* pcp-pmda-nutcracker 6.3.8-3.1
* pcp-pmda-nvidia-gpu 6.3.8-3.1
* pcp-pmda-openmetrics 6.3.8-3.1
* pcp-pmda-openvswitch 6.3.8-3.1
* pcp-pmda-oracle 6.3.8-3.1
* pcp-pmda-pdns 6.3.8-3.1
* pcp-pmda-perfevent 6.3.8-3.1
* pcp-pmda-postfix 6.3.8-3.1
* pcp-pmda-rabbitmq 6.3.8-3.1
* pcp-pmda-redis 6.3.8-3.1
* pcp-pmda-resctrl 6.3.8-3.1
* pcp-pmda-roomtemp 6.3.8-3.1
* pcp-pmda-rsyslog 6.3.8-3.1
* pcp-pmda-samba 6.3.8-3.1
* pcp-pmda-sendmail 6.3.8-3.1
* pcp-pmda-shping 6.3.8-3.1
* pcp-pmda-slurm 6.3.8-3.1
* pcp-pmda-smart 6.3.8-3.1
* pcp-pmda-snmp 6.3.8-3.1
* pcp-pmda-sockets 6.3.8-3.1
* pcp-pmda-summary 6.3.8-3.1
* pcp-pmda-systemd 6.3.8-3.1
* pcp-pmda-trace 6.3.8-3.1
* pcp-pmda-unbound 6.3.8-3.1
* pcp-pmda-uwsgi 6.3.8-3.1
* pcp-pmda-weblog 6.3.8-3.1
* pcp-pmda-zimbra 6.3.8-3.1
* pcp-pmda-zswap 6.3.8-3.1
* pcp-selinux 6.3.8-3.1
* pcp-system-tools 6.3.8-3.1
* pcp-testsuite 6.3.8-3.1
* pcp-zeroconf 6.3.8-3.1
* perl-PCP-LogImport 6.3.8-3.1
* perl-PCP-LogSummary 6.3.8-3.1
* perl-PCP-MMV 6.3.8-3.1
* perl-PCP-PMDA 6.3.8-3.1
* python3-pcp 6.3.8-3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16524.html
* https://www.suse.com/security/cve/CVE-2026-16526.html
* https://www.suse.com/security/cve/CVE-2026-16527.html
* https://www.suse.com/security/cve/CVE-2026-16529.html
* https://www.suse.com/security/cve/CVE-2026-16530.html
* https://www.suse.com/security/cve/CVE-2026-16531.html
openSUSE-SU-2026:11482-1: moderate: wild-0.10.0-2.1 on GA media
# wild-0.10.0-2.1 on GA media
Announcement ID: openSUSE-SU-2026:11482-1
Rating: moderate
Cross-References:
* CVE-2026-25541
CVSS scores:
* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the wild-0.10.0-2.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* wild 0.10.0-2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-25541.html
openSUSE-SU-2026:11488-1: moderate: java-21-openj9-21.0.12.0-1.1 on GA media
# java-21-openj9-21.0.12.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11488-1
Rating: moderate
Cross-References:
* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059
CVSS scores:
* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 7 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-21-openj9-21.0.12.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-21-openj9 21.0.12.0-1.1
* java-21-openj9-demo 21.0.12.0-1.1
* java-21-openj9-devel 21.0.12.0-1.1
* java-21-openj9-headless 21.0.12.0-1.1
* java-21-openj9-javadoc 21.0.12.0-1.1
* java-21-openj9-jmods 21.0.12.0-1.1
* java-21-openj9-src 21.0.12.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
openSUSE-SU-2026:11491-1: moderate: python313-Django5-5.2.17-1.1 on GA media
# python313-Django5-5.2.17-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11491-1
Rating: moderate
Cross-References:
* CVE-2026-15307
* CVE-2026-15337
* CVE-2026-15830
* CVE-2026-15920
CVSS scores:
* CVE-2026-15307 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-15307 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N
* CVE-2026-15337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15337 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15830 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15830 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15920 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-15920 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 4 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the python313-Django5-5.2.17-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-Django5 5.2.17-1.1
* python314-Django5 5.2.17-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15307.html
* https://www.suse.com/security/cve/CVE-2026-15337.html
* https://www.suse.com/security/cve/CVE-2026-15830.html
* https://www.suse.com/security/cve/CVE-2026-15920.html
openSUSE-SU-2026:11489-1: moderate: java-25-openj9-25.0.4.0-1.1 on GA media
# java-25-openj9-25.0.4.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11489-1
Rating: moderate
Cross-References:
* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059
CVSS scores:
* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 7 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-25-openj9-25.0.4.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-25-openj9 25.0.4.0-1.1
* java-25-openj9-demo 25.0.4.0-1.1
* java-25-openj9-devel 25.0.4.0-1.1
* java-25-openj9-headless 25.0.4.0-1.1
* java-25-openj9-javadoc 25.0.4.0-1.1
* java-25-openj9-jmods 25.0.4.0-1.1
* java-25-openj9-src 25.0.4.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
openSUSE-SU-2026:11486-1: moderate: java-17-openj9-17.0.20.0-1.1 on GA media
# java-17-openj9-17.0.20.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11486-1
Rating: moderate
Cross-References:
* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059
CVSS scores:
* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 7 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-17-openj9-17.0.20.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-17-openj9 17.0.20.0-1.1
* java-17-openj9-demo 17.0.20.0-1.1
* java-17-openj9-devel 17.0.20.0-1.1
* java-17-openj9-headless 17.0.20.0-1.1
* java-17-openj9-javadoc 17.0.20.0-1.1
* java-17-openj9-jmods 17.0.20.0-1.1
* java-17-openj9-src 17.0.20.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
openSUSE-SU-2026:11485-1: moderate: java-11-openj9-11.0.32.0-1.1 on GA media
# java-11-openj9-11.0.32.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11485-1
Rating: moderate
Cross-References:
* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47057
* CVE-2026-47059
CVSS scores:
* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 8 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-11-openj9-11.0.32.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-11-openj9 11.0.32.0-1.1
* java-11-openj9-demo 11.0.32.0-1.1
* java-11-openj9-devel 11.0.32.0-1.1
* java-11-openj9-headless 11.0.32.0-1.1
* java-11-openj9-javadoc 11.0.32.0-1.1
* java-11-openj9-jmods 11.0.32.0-1.1
* java-11-openj9-src 11.0.32.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47057.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
openSUSE-SU-2026:11484-1: moderate: chromedriver-151.0.7922.108-1.1 on GA media
# chromedriver-151.0.7922.108-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11484-1
Rating: moderate
Cross-References:
* CVE-2026-19137
* CVE-2026-19138
* CVE-2026-19139
* CVE-2026-19140
* CVE-2026-19141
* CVE-2026-19142
* CVE-2026-19143
* CVE-2026-19144
* CVE-2026-19145
* CVE-2026-19146
* CVE-2026-19147
* CVE-2026-19148
* CVE-2026-19149
* CVE-2026-19150
* CVE-2026-19151
* CVE-2026-19152
* CVE-2026-19153
* CVE-2026-19154
* CVE-2026-19155
* CVE-2026-19156
* CVE-2026-19157
* CVE-2026-19158
* CVE-2026-19159
* CVE-2026-19160
* CVE-2026-19161
* CVE-2026-19162
* CVE-2026-19163
* CVE-2026-19164
* CVE-2026-19165
* CVE-2026-19166
* CVE-2026-19167
* CVE-2026-19168
* CVE-2026-19169
* CVE-2026-19170
* CVE-2026-19171
* CVE-2026-19172
* CVE-2026-19173
* CVE-2026-19174
* CVE-2026-19175
* CVE-2026-19176
* CVE-2026-19177
Affected Products:
* openSUSE Tumbleweed
An update that solves 41 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the chromedriver-151.0.7922.108-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* chromedriver 151.0.7922.108-1.1
* chromium 151.0.7922.108-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-19137.html
* https://www.suse.com/security/cve/CVE-2026-19138.html
* https://www.suse.com/security/cve/CVE-2026-19139.html
* https://www.suse.com/security/cve/CVE-2026-19140.html
* https://www.suse.com/security/cve/CVE-2026-19141.html
* https://www.suse.com/security/cve/CVE-2026-19142.html
* https://www.suse.com/security/cve/CVE-2026-19143.html
* https://www.suse.com/security/cve/CVE-2026-19144.html
* https://www.suse.com/security/cve/CVE-2026-19145.html
* https://www.suse.com/security/cve/CVE-2026-19146.html
* https://www.suse.com/security/cve/CVE-2026-19147.html
* https://www.suse.com/security/cve/CVE-2026-19148.html
* https://www.suse.com/security/cve/CVE-2026-19149.html
* https://www.suse.com/security/cve/CVE-2026-19150.html
* https://www.suse.com/security/cve/CVE-2026-19151.html
* https://www.suse.com/security/cve/CVE-2026-19152.html
* https://www.suse.com/security/cve/CVE-2026-19153.html
* https://www.suse.com/security/cve/CVE-2026-19154.html
* https://www.suse.com/security/cve/CVE-2026-19155.html
* https://www.suse.com/security/cve/CVE-2026-19156.html
* https://www.suse.com/security/cve/CVE-2026-19157.html
* https://www.suse.com/security/cve/CVE-2026-19158.html
* https://www.suse.com/security/cve/CVE-2026-19159.html
* https://www.suse.com/security/cve/CVE-2026-19160.html
* https://www.suse.com/security/cve/CVE-2026-19161.html
* https://www.suse.com/security/cve/CVE-2026-19162.html
* https://www.suse.com/security/cve/CVE-2026-19163.html
* https://www.suse.com/security/cve/CVE-2026-19164.html
* https://www.suse.com/security/cve/CVE-2026-19165.html
* https://www.suse.com/security/cve/CVE-2026-19166.html
* https://www.suse.com/security/cve/CVE-2026-19167.html
* https://www.suse.com/security/cve/CVE-2026-19168.html
* https://www.suse.com/security/cve/CVE-2026-19169.html
* https://www.suse.com/security/cve/CVE-2026-19170.html
* https://www.suse.com/security/cve/CVE-2026-19171.html
* https://www.suse.com/security/cve/CVE-2026-19172.html
* https://www.suse.com/security/cve/CVE-2026-19173.html
* https://www.suse.com/security/cve/CVE-2026-19174.html
* https://www.suse.com/security/cve/CVE-2026-19175.html
* https://www.suse.com/security/cve/CVE-2026-19176.html
* https://www.suse.com/security/cve/CVE-2026-19177.html
openSUSE-SU-2026:11483-1: moderate: zpaqfranz-64.8-1.1 on GA media
# zpaqfranz-64.8-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11483-1
Rating: moderate
Cross-References:
* CVE-2025-50327
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the zpaqfranz-64.8-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* zpaqfranz 64.8-1.1
## References:
* https://www.suse.com/security/cve/CVE-2025-50327.html
SUSE-SU-2026:3571-1: moderate: Security update for ImageMagick
# Security update for ImageMagick
Announcement ID: SUSE-SU-2026:3571-1
Release Date: 2026-08-11T08:36:12Z
Rating: moderate
References:
* bsc#1272953
Cross-References:
* CVE-2026-64685
CVSS scores:
* CVE-2026-64685 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-64685 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products:
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for ImageMagick fixes the following issue:
* CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of-
file check (bsc#1272953).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3571=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3571=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.110.1
* ImageMagick-devel-7.1.0.9-150400.6.110.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-7.1.0.9-150400.6.110.1
* libMagick++-devel-7.1.0.9-150400.6.110.1
* ImageMagick-extra-7.1.0.9-150400.6.110.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.110.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.110.1
* perl-PerlMagick-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.110.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.110.1
* ImageMagick-debugsource-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-devel-64bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-devel-64bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (x86_64)
* libMagick++-devel-32bit-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.110.1
* ImageMagick-devel-32bit-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (noarch)
* ImageMagick-doc-7.1.0.9-150400.6.110.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.110.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-debugsource-7.1.0.9-150400.6.110.1
## References:
* https://www.suse.com/security/cve/CVE-2026-64685.html
* https://bugzilla.suse.com/show_bug.cgi?id72953
SUSE-SU-2026:3572-1: moderate: Security update for xmlrpc-c
# Security update for xmlrpc-c
Announcement ID: SUSE-SU-2026:3572-1
Release Date: 2026-08-11T08:36:51Z
Rating: moderate
References:
* bsc#1272769
Cross-References:
* CVE-2026-15928
CVSS scores:
* CVE-2026-15928 ( SUSE ): 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-15928 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-15928 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for xmlrpc-c fixes the following issue:
* CVE-2026-15928: reflected cross-site scripting (XSS) via HTML injection in
the error page component (bsc#1272769).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3572=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3572=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3572=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-devel-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-1.51.07-150400.3.3.1
* libxmlrpc_util++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-1.51.07-150400.3.3.1
* libxmlrpc_util4-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc_server3-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc3-1.51.07-150400.3.3.1
* libxmlrpc_client++8-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-1.51.07-150400.3.3.1
* libxmlrpc_server++8-1.51.07-150400.3.3.1
* libxmlrpc_client3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc++8-1.51.07-150400.3.3.1
* libxmlrpc_util4-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-1.51.07-150400.3.3.1
* libxmlrpc3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util++8-1.51.07-150400.3.3.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-devel-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc_server3-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc_client++8-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-1.51.07-150400.3.3.1
* libxmlrpc_util++8-1.51.07-150400.3.3.1
* libxmlrpc_server++8-1.51.07-150400.3.3.1
* libxmlrpc++8-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-debuginfo-1.51.07-150400.3.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc3-1.51.07-150400.3.3.1
* libxmlrpc_util4-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util4-1.51.07-150400.3.3.1
* libxmlrpc3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client3-1.51.07-150400.3.3.1
* libxmlrpc_client3-debuginfo-1.51.07-150400.3.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15928.html
* https://bugzilla.suse.com/show_bug.cgi?id72769
SUSE-SU-2026:3573-1: moderate: Security update for gstreamer-plugins-bad
# Security update for gstreamer-plugins-bad
Announcement ID: SUSE-SU-2026:3573-1
Release Date: 2026-08-11T08:37:25Z
Rating: moderate
References:
* bsc#1268394
Cross-References:
* CVE-2026-52718
CVSS scores:
* CVE-2026-52718 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
An update that solves one vulnerability can now be installed.
## Description:
This update for gstreamer-plugins-bad fixes the following issue:
* CVE-2026-52718: byte count instead of a bit count in
gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and
an application crash (bsc#1268394).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3573=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libgstisoff-1_0-0-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsttranscoder-1_0-0-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.32.1
* gstreamer-transcoder-1.20.1-150400.3.32.1
* libgstva-1_0-0-1.20.1-150400.3.32.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.32.1
* gstreamer-transcoder-devel-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkanWayland-1_0-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-1.20.1-150400.3.32.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkan-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkanXCB-1_0-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.32.1
* gstreamer-transcoder-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstTranscoder-1_0-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-1.20.1-150400.3.32.1
* libgstplay-1_0-0-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* gstreamer-plugins-bad-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstplay-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-64bit-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-64bit-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-64bit-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-64bit-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstplay-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-64bit-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (x86_64)
* libgstisoff-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-32bit-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-32bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-32bit-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstplay-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstva-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstplay-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.32.1
## References:
* https://www.suse.com/security/cve/CVE-2026-52718.html
* https://bugzilla.suse.com/show_bug.cgi?id68394
SUSE-SU-2026:3575-1: moderate: Security update for libarchive
# Security update for libarchive
Announcement ID: SUSE-SU-2026:3575-1
Release Date: 2026-08-11T08:38:07Z
Rating: moderate
References:
* bsc#1254340
* bsc#1254341
* bsc#1260998
* bsc#1261002
* bsc#1261003
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
An update that has five security fixes can now be installed.
## Description:
This update for libarchive fixes the following issues:
* creating temporary files in the current working directory instead of the
target directory can lead to file creation failures when the working
directory is not writable (bsc#1254340).
* file descriptor leak in the mtree parser cleanup path could lead to file
descriptor exhaustion and denial of service (bsc#1261003).
* NULL pointer dereference in archive_acl_from_text_w() could lead to a
segmentation fault (bsc#1260998).
* reading from an invalid index when buffer size is smaller than
H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
* incorrect pointer handling for RAR5 files declaring over 8192 filters can
lead to excessive resource usage and denial of service (bsc#1261002).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3575=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3575=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3575=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3575=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3575=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3575=1
## Package List:
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libarchive-debugsource-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* bsdtar-debuginfo-3.5.1-150400.3.27.1
* bsdtar-3.5.1-150400.3.27.1
* libarchive13-3.5.1-150400.3.27.1
* libarchive-devel-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (x86_64)
* libarchive13-32bit-3.5.1-150400.3.27.1
* libarchive13-32bit-debuginfo-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libarchive13-64bit-debuginfo-3.5.1-150400.3.27.1
* libarchive13-64bit-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id54340
* https://bugzilla.suse.com/show_bug.cgi?id54341
* https://bugzilla.suse.com/show_bug.cgi?id60998
* https://bugzilla.suse.com/show_bug.cgi?id61002
* https://bugzilla.suse.com/show_bug.cgi?id61003
SUSE-SU-2026:3576-1: important: Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update
# Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update
Announcement ID: SUSE-SU-2026:3576-1
Release Date: 2026-08-11T11:51:08Z
Rating: important
References:
* bsc#1270182
* bsc#1270520
* bsc#1270613
* bsc#1270707
* bsc#1270794
* bsc#1270830
* bsc#1270939
* bsc#1270946
* bsc#1270985
* bsc#1273910
* bsc#1273911
* bsc#1273912
Cross-References:
* CVE-2026-41676
* CVE-2026-41677
* CVE-2026-41678
* CVE-2026-41681
* CVE-2026-41898
* CVE-2026-42327
* CVE-2026-44662
* CVE-2026-45784
CVSS scores:
* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41677 ( SUSE ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
* CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-41677 ( NVD ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-41678 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-41681 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-41681 ( NVD ): 8.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41898 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-41898 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-42327 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44662 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-44662 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45784 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-45784 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45784 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves eight vulnerabilities and has four security fixes can now
be installed.
## Description:
This update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update fixes the
following issues:
Security fixes:
* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270182).
* CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when
returning an oversized length (bsc#1270613).
* CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in
`aes::unwrap_key()` (bsc#1270707).
* CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()`
writing past caller buffer with no length check (bsc#1270794).
* CVE-2026-41898: openssl: information leak to network peers due to unchecked
callback-returned length in PSK and cookie generate trampolines
(bsc#1270830).
* CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders`
when processing certificates with non-UTF-8 OCSP URLs (bsc#1270520).
* CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-
wrap-with-padding (bsc#1270939).
* CVE-2026-45784: out-of-bounds write in `CipherCtxRef::cipher_update_inplace`
for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270985).
* GHSA-4f5j-9xgm-8pvr: arbitrary HTTP or HTTPS URL classified as an Office
document based on an attacker-controlled file query parameters and forwarded
to an Electron application (bsc#1273910).
* GHSA-6cq7-jcwm-cpmr: directory-provided RFC2307 user identifiers accepted
without exclusion of systemd's dynamic-user range allows for daemon
impersonation and command execution through the task helper (bsc#1273911).
* GHSA-6gp8-pp9v-gx45: daemon acts on Hello PIN enrollment requests whose
identity claims it never cryptographically verifies (bsc#1273912).
Other fixes:
* Version 2.3.14+git0.e23b4c54:
* fix(nss): avoid locked shadow entries
* Version 2.3.14:
* fix(deps): update libhimmelblau lockfile
* fix(pam): make account denials terminal
* debian: make the pam_allow_groups denial terminal in the account phase
* Version 2.3.13:
* Update cargo vet audits for backport
* Version 2.3.12+git0.9d56c6f1:
* Fix cargo-fuzz install in fuzz CI
* cargo vet
* Update ldap3_proto to 0.7.1
* Version 2.3.12:
* Update cargo vet audits for backport
* Remove invalid himmelblau.conf example info
* Fix SSHd configuration load order on Fedora/RHEL systems
* himmelblau-init-hsm-pin: don't bind the hsm-pin to PCR7
* qr-greeter: support GNOME Shell 50
* Update libhimmelblau to latest version
* deps(rust): bump tonic in the all-cargo-updates group across 1 directory
* cargo audit
* Version 2.3.11+git0.c802b25f:
* Update cargo vet audits for backport
* Reject auth when token spn local part differs from requested account_id
* Update libhimmelblau to latest version
* deps(rust): bump the all-cargo-updates group with 19 updates
* cargo vet
* Version 2.3.10:
* nss/pam: bail out early when SYSTEMD_ACTIVATION_UNIT points to himmelblau
* selinux: allow unconfined_service_t to search himmelblaud_t dirs
* idprovider: release providers lock before async alias lookup
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3576=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3576=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3576=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3576=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3576=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3576=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3576=1
## Package List:
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* openSUSE Leap 15.5 (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* openSUSE Leap 15.5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-qr-greeter-2.3.14+git0.e23b4c54-150500.11.12.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html
* https://bugzilla.suse.com/show_bug.cgi?id70182
* https://bugzilla.suse.com/show_bug.cgi?id70520
* https://bugzilla.suse.com/show_bug.cgi?id70613
* https://bugzilla.suse.com/show_bug.cgi?id70707
* https://bugzilla.suse.com/show_bug.cgi?id70794
* https://bugzilla.suse.com/show_bug.cgi?id70830
* https://bugzilla.suse.com/show_bug.cgi?id70939
* https://bugzilla.suse.com/show_bug.cgi?id70946
* https://bugzilla.suse.com/show_bug.cgi?id70985
* https://bugzilla.suse.com/show_bug.cgi?id73910
* https://bugzilla.suse.com/show_bug.cgi?id73911
* https://bugzilla.suse.com/show_bug.cgi?id73912
SUSE-SU-2026:3577-1: important: Security update for snpguest
# Security update for snpguest
Announcement ID: SUSE-SU-2026:3577-1
Release Date: 2026-08-11T11:53:28Z
Rating: important
References:
* bsc#1270527
* bsc#1270642
* bsc#1274139
Cross-References:
* CVE-2026-25541
* CVE-2026-41678
* CVE-2026-42327
CVSS scores:
* CVE-2026-25541 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( NVD ): 5.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41678 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42327 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves three vulnerabilities can now be installed.
## Description:
This update for snpguest fixes the following issues:
* CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to
undefined behavior and crashes (bsc#1274139).
* CVE-2026-41678: openssl: incorrect bounds assertion in AES keywrap can lead
to an out-of-bounds write (bsc#1270642).
* CVE-2026-42327: openssl: missing validation when processing certificates
with non-UTF-8 OCSP URLs can lead to undefined behavior (bsc#1270527).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3577=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3577=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3577=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1
* openSUSE Leap 15.6 (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debugsource-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1
## References:
* https://www.suse.com/security/cve/CVE-2026-25541.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://bugzilla.suse.com/show_bug.cgi?id70527
* https://bugzilla.suse.com/show_bug.cgi?id70642
* https://bugzilla.suse.com/show_bug.cgi?id74139
openSUSE-SU-2026:0280-1: important: Security update for go-sendxmpp
openSUSE Security Update: Security update for go-sendxmpp
_______________________________
Announcement ID: openSUSE-SU-2026:0280-1
Rating: important
References: #1266617
Cross-References: CVE-2026-39821
CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes one vulnerability is now available.
Description:
This update for go-sendxmpp fixes the following issues:
- Update to 0.17.0:
* Add --ox-transfer-private-key to transfer the encrypted private key to
PEP to transfer it to other devices (requires go-xmpp >= v0.3.7).
* Add --ox-receive-private-key to receive the encrypted private key from
PEP.
* Add config option no_root_warning.
* Add config option no_legacy_pgp_warning.
* Also disable legacy PGP when running as root (Ox was already disabled).
* Disable pinning for not using PLAIN when running as root.
* Add config option ox_trust_mode with settings blind and tofu.
* Due to new tofu trust mode for Ox, only one public key per contact is
accepted for easier ID handling.
* Ox: Check that fingerprint of received key equals the advertised one.
* CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels
allows for validation bypass and privilege escalation (boo#1266617):
Bump net to 0.57.0
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-280=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
go-sendxmpp-0.17.0-bp157.2.12.1
References:
https://www.suse.com/security/cve/CVE-2026-39821.html
https://bugzilla.suse.com/1266617
SUSE-SU-2026:3579-1: important: Security update for erlang26
# Security update for erlang26
Announcement ID: SUSE-SU-2026:3579-1
Release Date: 2026-08-11T14:05:55Z
Rating: important
References:
* bsc#1261726
* bsc#1266449
* bsc#1266466
* bsc#1268139
* bsc#1268141
* bsc#1268142
* bsc#1268146
* bsc#1268163
* bsc#1268164
* bsc#1270245
* bsc#1270246
* bsc#1270247
* bsc#1270250
* bsc#1270253
* bsc#1270258
* bsc#1272908
* bsc#1272909
* bsc#1272910
* bsc#1272911
* bsc#1272913
* bsc#1272914
* bsc#1272915
Cross-References:
* CVE-2026-28810
* CVE-2026-42789
* CVE-2026-42790
* CVE-2026-42792
* CVE-2026-47078
* CVE-2026-48855
* CVE-2026-48856
* CVE-2026-48858
* CVE-2026-48860
* CVE-2026-49759
* CVE-2026-49760
* CVE-2026-53422
* CVE-2026-54886
* CVE-2026-54887
* CVE-2026-54891
* CVE-2026-55737
* CVE-2026-55950
* CVE-2026-55952
* CVE-2026-55953
* CVE-2026-58227
* CVE-2026-59250
* CVE-2026-59251
CVSS scores:
* CVE-2026-28810 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-28810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-28810 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-28810 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-42789 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42789 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42789 ( NVD ): 7.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42789 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
* CVE-2026-42789 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-42790 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42790 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42790 ( NVD ): 7.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42790 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42790 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-42792 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-42792 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-42792 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42792 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47078 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L
* CVE-2026-47078 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
* CVE-2026-47078 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-48855 ( NVD ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48856 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48856 ( NVD ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48856 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48858 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-48858 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48858 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-48860 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-48860 ( NVD ): 7.5
CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48860 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-49759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49759 ( NVD ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-49759 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-49759 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-49760 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49760 ( NVD ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-49760 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53422 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53422 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-53422 ( NVD ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-53422 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-54886 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54886 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54886 ( NVD ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54886 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54887 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-54887 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54887 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54887 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-54891 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-54891 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-54891 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54891 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-55737 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-55737 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-55737 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55737 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55950 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55950 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55950 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55950 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55952 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55952 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55952 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55952 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55953 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-55953 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-55953 ( NVD ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55953 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-58227 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58227 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58227 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58227 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59250 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59250 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59250 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59251 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
* CVE-2026-59251 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59251 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59251 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.3
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves 22 vulnerabilities can now be installed.
## Description:
This update for erlang26 fixes the following issues:
* CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache
poisoning (bsc#1261726).
* CVE-2026-42789: `public_key` application accepts non-CA certificates as
intermediate issuers and this enables chain forgery (bsc#1266449).
* CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS
hostname verification allows for certificate forgery by MITM attacker
(bsc#1266466).
* CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to
improper handling of exceptional conditions (bsc#1272908).
* CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via
`check_dir_level` depth-counter bypass (bsc#1272909).
* CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem
path when root is configured (bsc#1268139).
* CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin
redirect targets (bsc#1268141).
* CVE-2026-48858: server-side request forgery allows FTP bounce attacks and
SSRF via an unvalidated `PASV` response IP address (bsc#1268142).
* CVE-2026-48860: `ssl` (`inet_tls_dist` module) allows unauthenticated bypass
of the distribution-over-TLS LAN allowlist (bsc#1268146).
* CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing
in `inet_drv` (bsc#1268163).
* CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large
integer (bsc#1268164).
* CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem
enumeration outside configured root (bsc#1270245).
* CVE-2026-54886: SSH SFTP server denial of service via extended channel data
infinite loop (bsc#1270246).
* CVE-2026-54887: use of default cryptographic key allows predictable DTLS
cookie computation during the startup window (bsc#1270247).
* CVE-2026-54891: plaintext injection towards (D)TLS client during handshake
(bsc#1270250).
* CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in
`LARGE_TUPLE_EXTP` decoding in `erts` external term format decoder
(bsc#1272910).
* CVE-2026-55950: time-of-check time-of-use race condition allows an
unauthenticated remote attacker to crash all active DTLS sessions on a
listener (bsc#1270253).
* CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when
clients send a malformed `ClientHello` with mismatched PSK identity and
binder list lengths (bsc#1270258).
* CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher
suites and allow for server authentication bypass (bsc#1272911).
* CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-
signed peer certificate chain (bsc#1272913).
* CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property
parm name (bsc#1272914).
* CVE-2026-59251: denial of service via exponential certificate policy tree
growth in path validation (bsc#1272915).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3579=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3579=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3579=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3579=1
## Package List:
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-jinterface-26.2.1-150300.7.28.1
* erlang26-wx-src-26.2.1-150300.7.28.1
* erlang26-dialyzer-src-26.2.1-150300.7.28.1
* erlang26-diameter-src-26.2.1-150300.7.28.1
* erlang26-wx-26.2.1-150300.7.28.1
* erlang26-et-26.2.1-150300.7.28.1
* erlang26-debugger-26.2.1-150300.7.28.1
* erlang26-reltool-src-26.2.1-150300.7.28.1
* erlang26-reltool-26.2.1-150300.7.28.1
* erlang26-debugger-src-26.2.1-150300.7.28.1
* erlang26-dialyzer-debuginfo-26.2.1-150300.7.28.1
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-doc-26.2.1-150300.7.28.1
* erlang26-diameter-26.2.1-150300.7.28.1
* erlang26-wx-debuginfo-26.2.1-150300.7.28.1
* erlang26-observer-src-26.2.1-150300.7.28.1
* erlang26-src-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-observer-26.2.1-150300.7.28.1
* erlang26-dialyzer-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* erlang26-jinterface-src-26.2.1-150300.7.28.1
* erlang26-et-src-26.2.1-150300.7.28.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
## References:
* https://www.suse.com/security/cve/CVE-2026-28810.html
* https://www.suse.com/security/cve/CVE-2026-42789.html
* https://www.suse.com/security/cve/CVE-2026-42790.html
* https://www.suse.com/security/cve/CVE-2026-42792.html
* https://www.suse.com/security/cve/CVE-2026-47078.html
* https://www.suse.com/security/cve/CVE-2026-48855.html
* https://www.suse.com/security/cve/CVE-2026-48856.html
* https://www.suse.com/security/cve/CVE-2026-48858.html
* https://www.suse.com/security/cve/CVE-2026-48860.html
* https://www.suse.com/security/cve/CVE-2026-49759.html
* https://www.suse.com/security/cve/CVE-2026-49760.html
* https://www.suse.com/security/cve/CVE-2026-53422.html
* https://www.suse.com/security/cve/CVE-2026-54886.html
* https://www.suse.com/security/cve/CVE-2026-54887.html
* https://www.suse.com/security/cve/CVE-2026-54891.html
* https://www.suse.com/security/cve/CVE-2026-55737.html
* https://www.suse.com/security/cve/CVE-2026-55950.html
* https://www.suse.com/security/cve/CVE-2026-55952.html
* https://www.suse.com/security/cve/CVE-2026-55953.html
* https://www.suse.com/security/cve/CVE-2026-58227.html
* https://www.suse.com/security/cve/CVE-2026-59250.html
* https://www.suse.com/security/cve/CVE-2026-59251.html
* https://bugzilla.suse.com/show_bug.cgi?id61726
* https://bugzilla.suse.com/show_bug.cgi?id66449
* https://bugzilla.suse.com/show_bug.cgi?id66466
* https://bugzilla.suse.com/show_bug.cgi?id68139
* https://bugzilla.suse.com/show_bug.cgi?id68141
* https://bugzilla.suse.com/show_bug.cgi?id68142
* https://bugzilla.suse.com/show_bug.cgi?id68146
* https://bugzilla.suse.com/show_bug.cgi?id68163
* https://bugzilla.suse.com/show_bug.cgi?id68164
* https://bugzilla.suse.com/show_bug.cgi?id70245
* https://bugzilla.suse.com/show_bug.cgi?id70246
* https://bugzilla.suse.com/show_bug.cgi?id70247
* https://bugzilla.suse.com/show_bug.cgi?id70250
* https://bugzilla.suse.com/show_bug.cgi?id70253
* https://bugzilla.suse.com/show_bug.cgi?id70258
* https://bugzilla.suse.com/show_bug.cgi?id72908
* https://bugzilla.suse.com/show_bug.cgi?id72909
* https://bugzilla.suse.com/show_bug.cgi?id72910
* https://bugzilla.suse.com/show_bug.cgi?id72911
* https://bugzilla.suse.com/show_bug.cgi?id72913
* https://bugzilla.suse.com/show_bug.cgi?id72914
* https://bugzilla.suse.com/show_bug.cgi?id72915
SUSE-SU-2026:3588-1: moderate: Security update for python3-pip
# Security update for python3-pip
Announcement ID: SUSE-SU-2026:3588-1
Release Date: 2026-08-11T14:56:50Z
Rating: moderate
References:
* bsc#1273090
Cross-References:
* CVE-2026-13346
CVSS scores:
* CVE-2026-13346 ( SUSE ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-13346 ( NVD ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for python3-pip fixes the following issue:
* CVE-2026-13346: incorrect handling of doubly-encoded package URLs from
malicious indexes allows files to be installed to arbitrary locations on
disk (bsc#1273090).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3588=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3588=1
## Package List:
* Basesystem Module 15-SP7 (noarch)
* python3-pip-wheel-20.0.2-150400.26.1
* python3-pip-20.0.2-150400.26.1
* openSUSE Leap 15.4 (noarch)
* python3-pip-wheel-20.0.2-150400.26.1
* python3-pip-test-20.0.2-150400.26.1
* python3-pip-20.0.2-150400.26.1
## References:
* https://www.suse.com/security/cve/CVE-2026-13346.html
* https://bugzilla.suse.com/show_bug.cgi?id73090
SUSE-SU-2026:3589-1: moderate: Security update for python-pip
# Security update for python-pip
Announcement ID: SUSE-SU-2026:3589-1
Release Date: 2026-08-11T14:57:17Z
Rating: moderate
References:
* bsc#1273090
Cross-References:
* CVE-2026-13346
CVSS scores:
* CVE-2026-13346 ( SUSE ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-13346 ( NVD ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves one vulnerability can now be installed.
## Description:
This update for python-pip fixes the following issue:
* CVE-2026-13346: incorrect handling of doubly-encoded package URLs from
malicious indexes allows files to be installed to arbitrary locations on
disk (bsc#1273090).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3589=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3589=1
* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3589=1
## Package List:
* Public Cloud Module 15-SP4 (noarch)
* python311-pip-22.3.1-150400.17.29.1
* Python 3 Module 15-SP7 (noarch)
* python311-pip-22.3.1-150400.17.29.1
* openSUSE Leap 15.4 (noarch)
* python311-pip-22.3.1-150400.17.29.1
## References:
* https://www.suse.com/security/cve/CVE-2026-13346.html
* https://bugzilla.suse.com/show_bug.cgi?id73090