SUSE 5735 Published by

SUSE issued a batch of security advisories to address dozens of vulnerabilities across essential system packages. The updates focus on high-risk components including bind, erlang26, Python 3.11, Python 3.12, Perl, and the Chromium browser driver, carrying importance ratings from moderate to important. System administrators running SUSE Linux Enterprise Server 15 or any openSUSE Leap and Tumbleweed variant should deploy the fixes through YaST or zypper patch to neutralize attack vectors like buffer overflows and authentication bypasses. Additional advisories cover support libraries and utilities such as ImageMagick, xmlrpc-c, and the himmelblau authentication daemon to seal specific exploitation pathways.

SUSE-SU-2026:3549-1: moderate: Security update for python3-sqlparse
SUSE-SU-2026:3554-1: important: Security update for bind
SUSE-SU-2026:3558-1: important: Security update for perl
SUSE-SU-2026:3560-1: important: Security update for python311
SUSE-SU-2026:3561-1: moderate: Security update for PackageKit
SUSE-SU-2026:3569-1: important: Security update for python312
openSUSE-SU-2026:11487-1: moderate: java-1_8_0-openj9-1.8.0.502-1.1 on GA media
openSUSE-SU-2026:11490-1: moderate: libpcp-devel-6.3.8-3.1 on GA media
openSUSE-SU-2026:11482-1: moderate: wild-0.10.0-2.1 on GA media
openSUSE-SU-2026:11488-1: moderate: java-21-openj9-21.0.12.0-1.1 on GA media
openSUSE-SU-2026:11491-1: moderate: python313-Django5-5.2.17-1.1 on GA media
openSUSE-SU-2026:11489-1: moderate: java-25-openj9-25.0.4.0-1.1 on GA media
openSUSE-SU-2026:11486-1: moderate: java-17-openj9-17.0.20.0-1.1 on GA media
openSUSE-SU-2026:11485-1: moderate: java-11-openj9-11.0.32.0-1.1 on GA media
openSUSE-SU-2026:11484-1: moderate: chromedriver-151.0.7922.108-1.1 on GA media
openSUSE-SU-2026:11483-1: moderate: zpaqfranz-64.8-1.1 on GA media
SUSE-SU-2026:3571-1: moderate: Security update for ImageMagick
SUSE-SU-2026:3572-1: moderate: Security update for xmlrpc-c
SUSE-SU-2026:3573-1: moderate: Security update for gstreamer-plugins-bad
SUSE-SU-2026:3575-1: moderate: Security update for libarchive
SUSE-SU-2026:3576-1: important: Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update
SUSE-SU-2026:3577-1: important: Security update for snpguest
openSUSE-SU-2026:0280-1: important: Security update for go-sendxmpp
SUSE-SU-2026:3579-1: important: Security update for erlang26
SUSE-SU-2026:3588-1: moderate: Security update for python3-pip
SUSE-SU-2026:3589-1: moderate: Security update for python-pip




SUSE-SU-2026:3549-1: moderate: Security update for python3-sqlparse


# Security update for python3-sqlparse

Announcement ID: SUSE-SU-2026:3549-1
Release Date: 2026-08-10T16:35:52Z
Rating: moderate
References:

* bsc#1268597

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that has one security fix can now be installed.

## Description:

This update for python3-sqlparse fixes the following issue:

* Fixed an issue where formatting list of tuples leads to denial of service
(bsc#1268597).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3549=1

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3549=1

## Package List:

* Basesystem Module 15-SP7 (noarch)
* python3-sqlparse-0.4.2-150300.20.1
* openSUSE Leap 15.3 (noarch)
* python3-sqlparse-0.4.2-150300.20.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id68597



SUSE-SU-2026:3554-1: important: Security update for bind


# Security update for bind

Announcement ID: SUSE-SU-2026:3554-1
Release Date: 2026-08-10T16:49:22Z
Rating: important
References:

* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990

Cross-References:

* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321

CVSS scores:

* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves six vulnerabilities can now be installed.

## Description:

This update for bind fixes the following issues:

* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3554=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3554=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3554=1

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3554=1

## Package List:

* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* bind-chrootenv-9.16.6-150300.22.62.1
* libns1604-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* bind-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccc1600-debuginfo-9.16.6-150300.22.62.1
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libbind9-1600-9.16.6-150300.22.62.1
* bind-utils-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-utils-debuginfo-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccc1600-9.16.6-150300.22.62.1
* libbind9-1600-debuginfo-9.16.6-150300.22.62.1
* bind-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libns1604-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* openSUSE Leap 15.3 (noarch)
* bind-doc-9.16.6-150300.22.62.1
* python3-bind-9.16.6-150300.22.62.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libirs1601-debuginfo-9.16.6-150300.22.62.1
* libisc1606-debuginfo-9.16.6-150300.22.62.1
* libisccfg1600-9.16.6-150300.22.62.1
* libdns1605-debuginfo-9.16.6-150300.22.62.1
* bind-debugsource-9.16.6-150300.22.62.1
* libirs-devel-9.16.6-150300.22.62.1
* libirs1601-9.16.6-150300.22.62.1
* libisccfg1600-debuginfo-9.16.6-150300.22.62.1
* libdns1605-9.16.6-150300.22.62.1
* bind-debuginfo-9.16.6-150300.22.62.1
* libisc1606-9.16.6-150300.22.62.1

## References:

* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990



SUSE-SU-2026:3558-1: important: Security update for perl


# Security update for perl

Announcement ID: SUSE-SU-2026:3558-1
Release Date: 2026-08-10T18:02:15Z
Rating: important
References:

* bsc#1266304
* bsc#1268349
* bsc#1271372

Cross-References:

* CVE-2026-12087
* CVE-2026-57432
* CVE-2026-8376

CVSS scores:

* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-12087 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-57432 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-57432 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-8376 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-8376 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-8376 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products:

* Basesystem Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.3
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves three vulnerabilities can now be installed.

## Description:

This update for perl fixes the following issues:

* CVE-2026-8376: heap buffer overflow when compiling regular expressions with
a repeated fixed string on 32-bit builds (bsc#1266304).
* CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap
memory into the returned packed structure (bsc#1268349).
* CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-
of-bounds heap read in `pack` and `unpack` (bsc#1271372).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3558=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3558=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3558=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3558=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3558=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3558=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3558=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3558=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3558=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3558=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3558=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3558=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3558=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3558=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3558=1

* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3558=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3558=1

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3558=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3558=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (aarch64_ilp32)
* perl-base-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-64bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-64bit-5.26.1-150300.17.23.1
* perl-64bit-5.26.1-150300.17.23.1
* perl-base-64bit-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (x86_64)
* perl-32bit-5.26.1-150300.17.23.1
* perl-core-DB_File-32bit-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-core-DB_File-32bit-debuginfo-5.26.1-150300.17.23.1
* openSUSE Leap 15.3 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* perl-doc-5.26.1-150300.17.23.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* Basesystem Module 15-SP7 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* perl-5.26.1-150300.17.23.1
* perl-base-5.26.1-150300.17.23.1
* perl-core-DB_File-debuginfo-5.26.1-150300.17.23.1
* perl-debugsource-5.26.1-150300.17.23.1
* perl-core-DB_File-5.26.1-150300.17.23.1
* perl-debuginfo-5.26.1-150300.17.23.1
* perl-base-debuginfo-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* perl-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-debuginfo-5.26.1-150300.17.23.1
* perl-base-32bit-5.26.1-150300.17.23.1
* Development Tools Module 15-SP7 (noarch)
* perl-doc-5.26.1-150300.17.23.1
* SUSE Package Hub 15 15-SP7 (x86_64)
* perl-32bit-5.26.1-150300.17.23.1
* perl-32bit-debuginfo-5.26.1-150300.17.23.1

## References:

* https://www.suse.com/security/cve/CVE-2026-12087.html
* https://www.suse.com/security/cve/CVE-2026-57432.html
* https://www.suse.com/security/cve/CVE-2026-8376.html
* https://bugzilla.suse.com/show_bug.cgi?id66304
* https://bugzilla.suse.com/show_bug.cgi?id68349
* https://bugzilla.suse.com/show_bug.cgi?id71372



SUSE-SU-2026:3560-1: important: Security update for python311


# Security update for python311

Announcement ID: SUSE-SU-2026:3560-1
Release Date: 2026-08-10T18:09:32Z
Rating: important
References:

* bsc#1264962
* bsc#1265268
* bsc#1267581
* bsc#1267821
* bsc#1268375
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269959
* bsc#1271192

Cross-References:

* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-15308
* CVE-2026-3276
* CVE-2026-4360
* CVE-2026-7210
* CVE-2026-7774
* CVE-2026-8328

CVSS scores:

* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves nine vulnerabilities and has one security fix can now be
installed.

## Description:

This update for python311 fixes the following issues:

Security issues fixed:

* CVE-2026-0864: improper handling of line-ending characters can lead to
configuration file injection when the `configparser` module is used
(bsc#1269066).
* CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
DoS when processing specially crafted Unicode input (bsc#1267581).
* CVE-2026-4360: in the `Tarfile.extract()` function, the filter parameter is
not passed properly when extracting hardlinks (bsc#1269959).
* CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
insufficient entropy for Expat hash-flooding protection (bsc#1264962).
* CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
outside the extraction directory (bsc#1267821).
* CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
supplied PASV host address (bsc#1265268).
* CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
allows escaping the destination directory and enables arbitrary file reads
and writes (bsc#1268977).
* CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
module streaming mode can lead to DoS (bsc#1269788).
* CVE-2026-15308: incremental `HTMLParser` allows CPU-exhaustion DoS via
repeated unterminated markup declarations (bsc#1271192).

Non security issue fixed:

* Improve testing for the support of `IPPROTO_UDPLITE`, which could be not
present although header files are (bsc#1268375).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3560=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3560=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3560=1

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3560=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3560=1

## Package List:

* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-doc-3.11.15-150600.3.62.1
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-doc-devhelp-3.11.15-150600.3.62.1
* python311-devel-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2
* python311-testsuite-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-testsuite-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (x86_64)
* python311-base-32bit-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-32bit-3.11.15-150600.3.62.2
* python311-32bit-3.11.15-150600.3.62.2
* python311-base-32bit-3.11.15-150600.3.62.2
* libpython3_11-1_0-32bit-debuginfo-3.11.15-150600.3.62.2
* python311-32bit-debuginfo-3.11.15-150600.3.62.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* python311-base-64bit-3.11.15-150600.3.62.2
* python311-base-64bit-debuginfo-3.11.15-150600.3.62.2
* python311-64bit-3.11.15-150600.3.62.2
* libpython3_11-1_0-64bit-debuginfo-3.11.15-150600.3.62.2
* python311-64bit-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-64bit-3.11.15-150600.3.62.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.62.2
* python311-base-debuginfo-3.11.15-150600.3.62.2
* libpython3_11-1_0-3.11.15-150600.3.62.2
* python311-3.11.15-150600.3.62.2
* python311-devel-3.11.15-150600.3.62.2
* python311-dbm-3.11.15-150600.3.62.2
* python311-curses-3.11.15-150600.3.62.2
* python311-debugsource-3.11.15-150600.3.62.2
* python311-tools-3.11.15-150600.3.62.2
* python311-curses-debuginfo-3.11.15-150600.3.62.2
* python311-dbm-debuginfo-3.11.15-150600.3.62.2
* python311-idle-3.11.15-150600.3.62.2
* python311-tk-3.11.15-150600.3.62.2
* python311-debuginfo-3.11.15-150600.3.62.2
* python311-core-debugsource-3.11.15-150600.3.62.2
* python311-base-3.11.15-150600.3.62.2
* python311-tk-debuginfo-3.11.15-150600.3.62.2

## References:

* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://bugzilla.suse.com/show_bug.cgi?id64962
* https://bugzilla.suse.com/show_bug.cgi?id65268
* https://bugzilla.suse.com/show_bug.cgi?id67581
* https://bugzilla.suse.com/show_bug.cgi?id67821
* https://bugzilla.suse.com/show_bug.cgi?id68375
* https://bugzilla.suse.com/show_bug.cgi?id68977
* https://bugzilla.suse.com/show_bug.cgi?id69066
* https://bugzilla.suse.com/show_bug.cgi?id69788
* https://bugzilla.suse.com/show_bug.cgi?id69959
* https://bugzilla.suse.com/show_bug.cgi?id71192



SUSE-SU-2026:3561-1: moderate: Security update for PackageKit


# Security update for PackageKit

Announcement ID: SUSE-SU-2026:3561-1
Release Date: 2026-08-10T18:12:19Z
Rating: moderate
References:

* bsc#1267250

Cross-References:

* CVE-2026-10294

CVSS scores:

* CVE-2026-10294 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-10294 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products:

* openSUSE Leap 15.4

An update that solves one vulnerability can now be installed.

## Description:

This update for PackageKit fixes the following issues:

* CVE-2026-10294: manipulation of the argument frontend-socket can lead to
improper authorization (bsc#1267250).

## Special Instructions and Notes:

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3561=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* PackageKit-debugsource-1.2.4-150400.3.34.1
* PackageKit-devel-debuginfo-1.2.4-150400.3.34.1
* typelib-1_0-PackageKitGlib-1_0-1.2.4-150400.3.34.1
* PackageKit-gstreamer-plugin-1.2.4-150400.3.34.1
* PackageKit-devel-1.2.4-150400.3.34.1
* PackageKit-debuginfo-1.2.4-150400.3.34.1
* PackageKit-gtk3-module-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-devel-1.2.4-150400.3.34.1
* PackageKit-gtk3-module-1.2.4-150400.3.34.1
* PackageKit-1.2.4-150400.3.34.1
* PackageKit-backend-zypp-debuginfo-1.2.4-150400.3.34.1
* PackageKit-gstreamer-plugin-debuginfo-1.2.4-150400.3.34.1
* PackageKit-backend-dnf-1.2.4-150400.3.34.1
* PackageKit-backend-zypp-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-1.2.4-150400.3.34.1
* PackageKit-backend-dnf-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-debuginfo-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (noarch)
* PackageKit-branding-upstream-1.2.4-150400.3.34.1
* PackageKit-lang-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libpackagekit-glib2-devel-64bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-64bit-debuginfo-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-64bit-1.2.4-150400.3.34.1
* openSUSE Leap 15.4 (x86_64)
* libpackagekit-glib2-18-32bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-devel-32bit-1.2.4-150400.3.34.1
* libpackagekit-glib2-18-32bit-debuginfo-1.2.4-150400.3.34.1

## References:

* https://www.suse.com/security/cve/CVE-2026-10294.html
* https://bugzilla.suse.com/show_bug.cgi?id67250



SUSE-SU-2026:3569-1: important: Security update for python312


# Security update for python312

Announcement ID: SUSE-SU-2026:3569-1
Release Date: 2026-08-11T08:02:52Z
Rating: important
References:

* bsc#1211301
* bsc#1264962
* bsc#1265268
* bsc#1267581
* bsc#1267821
* bsc#1268375
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269959
* bsc#1271192

Cross-References:

* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-15308
* CVE-2026-3276
* CVE-2026-4360
* CVE-2026-7210
* CVE-2026-7774
* CVE-2026-8328

CVSS scores:

* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves nine vulnerabilities and has two security fixes can now be
installed.

## Description:

This update for python312 fixes the following issues:

Security issues fixed:

* CVE-2026-0864: improper handling of line-ending characters can lead to
configuration file injection when the `configparser` module is used
(bsc#1269066).
* CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
DoS when processing specially crafted Unicode input (bsc#1267581).
* CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is
not passed properly when extracting hardlinks (bsc#1269959).
* CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
insufficient entropy for Expat hash-flooding protection (bsc#1264962).
* CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
outside the extraction directory (bsc#1267821).
* CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
supplied PASV host address (bsc#1265268).
* CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
allows escaping the destination directory and enables arbitrary file reads
and writes (bsc#1268977).
* CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
module streaming mode can lead to DoS (bsc#1269788).
* CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via
repeated unterminated markup declarations (bsc#1271192).

Non security issues fixed:

* [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
* crypto-policies: Extend the crypto-policies support for mozilla-nss,
openjdk, krb5, bind, stunnel, openssh, libssh and more packages
(bsc#1211301).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3569=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3569=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3569=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-tk-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-base-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-debugsource-3.12.13-150600.3.62.1
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-idle-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-base-3.12.13-150600.3.62.3
* python312-doc-devhelp-3.12.13-150600.3.62.1
* python312-idle-3.12.13-150600.3.62.1
* python312-testsuite-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-tk-3.12.13-150600.3.62.1
* python312-doc-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-testsuite-debuginfo-3.12.13-150600.3.62.3
* python312-debugsource-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* python312-base-64bit-3.12.13-150600.3.62.3
* libpython3_12-1_0-64bit-3.12.13-150600.3.62.3
* libpython3_12-1_0-64bit-debuginfo-3.12.13-150600.3.62.3
* python312-64bit-3.12.13-150600.3.62.1
* python312-base-64bit-debuginfo-3.12.13-150600.3.62.3
* python312-64bit-debuginfo-3.12.13-150600.3.62.1
* openSUSE Leap 15.6 (x86_64)
* libpython3_12-1_0-32bit-debuginfo-3.12.13-150600.3.62.3
* python312-base-32bit-debuginfo-3.12.13-150600.3.62.3
* libpython3_12-1_0-32bit-3.12.13-150600.3.62.3
* python312-base-32bit-3.12.13-150600.3.62.3
* python312-32bit-3.12.13-150600.3.62.1
* python312-32bit-debuginfo-3.12.13-150600.3.62.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python312-dbm-3.12.13-150600.3.62.1
* python312-curses-debuginfo-3.12.13-150600.3.62.1
* python312-dbm-debuginfo-3.12.13-150600.3.62.1
* python312-devel-3.12.13-150600.3.62.3
* libpython3_12-1_0-debuginfo-3.12.13-150600.3.62.3
* python312-3.12.13-150600.3.62.1
* python312-core-debugsource-3.12.13-150600.3.62.3
* python312-tk-3.12.13-150600.3.62.1
* python312-base-debuginfo-3.12.13-150600.3.62.3
* python312-curses-3.12.13-150600.3.62.1
* python312-tools-3.12.13-150600.3.62.3
* python312-base-3.12.13-150600.3.62.3
* python312-tk-debuginfo-3.12.13-150600.3.62.1
* python312-debugsource-3.12.13-150600.3.62.1
* libpython3_12-1_0-3.12.13-150600.3.62.3
* python312-idle-3.12.13-150600.3.62.1
* python312-debuginfo-3.12.13-150600.3.62.1

## References:

* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://bugzilla.suse.com/show_bug.cgi?id11301
* https://bugzilla.suse.com/show_bug.cgi?id64962
* https://bugzilla.suse.com/show_bug.cgi?id65268
* https://bugzilla.suse.com/show_bug.cgi?id67581
* https://bugzilla.suse.com/show_bug.cgi?id67821
* https://bugzilla.suse.com/show_bug.cgi?id68375
* https://bugzilla.suse.com/show_bug.cgi?id68977
* https://bugzilla.suse.com/show_bug.cgi?id69066
* https://bugzilla.suse.com/show_bug.cgi?id69788
* https://bugzilla.suse.com/show_bug.cgi?id69959
* https://bugzilla.suse.com/show_bug.cgi?id71192



openSUSE-SU-2026:11487-1: moderate: java-1_8_0-openj9-1.8.0.502-1.1 on GA media


# java-1_8_0-openj9-1.8.0.502-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11487-1
Rating: moderate

Cross-References:

* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-46968
* CVE-2026-47021
* CVE-2026-47058
* CVE-2026-47063
* CVE-2026-60147

CVSS scores:

* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-1_8_0-openj9-1.8.0.502-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-1_8_0-openj9 1.8.0.502-1.1
* java-1_8_0-openj9-accessibility 1.8.0.502-1.1
* java-1_8_0-openj9-demo 1.8.0.502-1.1
* java-1_8_0-openj9-devel 1.8.0.502-1.1
* java-1_8_0-openj9-headless 1.8.0.502-1.1
* java-1_8_0-openj9-javadoc 1.8.0.502-1.1
* java-1_8_0-openj9-src 1.8.0.502-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47058.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html



openSUSE-SU-2026:11490-1: moderate: libpcp-devel-6.3.8-3.1 on GA media


# libpcp-devel-6.3.8-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11490-1
Rating: moderate

Cross-References:

* CVE-2026-16524
* CVE-2026-16526
* CVE-2026-16527
* CVE-2026-16529
* CVE-2026-16530
* CVE-2026-16531

CVSS scores:

* CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libpcp-devel-6.3.8-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libpcp-devel 6.3.8-3.1
* libpcp3 6.3.8-3.1
* libpcp_gui2 6.3.8-3.1
* libpcp_import1 6.3.8-3.1
* libpcp_mmv1 6.3.8-3.1
* libpcp_trace2 6.3.8-3.1
* libpcp_web1 6.3.8-3.1
* pcp 6.3.8-3.1
* pcp-conf 6.3.8-3.1
* pcp-devel 6.3.8-3.1
* pcp-doc 6.3.8-3.1
* pcp-export-pcp2elasticsearch 6.3.8-3.1
* pcp-export-pcp2graphite 6.3.8-3.1
* pcp-export-pcp2influxdb 6.3.8-3.1
* pcp-export-pcp2json 6.3.8-3.1
* pcp-export-pcp2spark 6.3.8-3.1
* pcp-export-pcp2xml 6.3.8-3.1
* pcp-export-pcp2zabbix 6.3.8-3.1
* pcp-gui 6.3.8-3.1
* pcp-import-collectl2pcp 6.3.8-3.1
* pcp-import-ganglia2pcp 6.3.8-3.1
* pcp-import-iostat2pcp 6.3.8-3.1
* pcp-import-mrtg2pcp 6.3.8-3.1
* pcp-import-sar2pcp 6.3.8-3.1
* pcp-import-sheet2pcp 6.3.8-3.1
* pcp-pmda-activemq 6.3.8-3.1
* pcp-pmda-amdgpu 6.3.8-3.1
* pcp-pmda-apache 6.3.8-3.1
* pcp-pmda-bash 6.3.8-3.1
* pcp-pmda-bonding 6.3.8-3.1
* pcp-pmda-cifs 6.3.8-3.1
* pcp-pmda-cisco 6.3.8-3.1
* pcp-pmda-dbping 6.3.8-3.1
* pcp-pmda-dm 6.3.8-3.1
* pcp-pmda-docker 6.3.8-3.1
* pcp-pmda-ds389 6.3.8-3.1
* pcp-pmda-ds389log 6.3.8-3.1
* pcp-pmda-elasticsearch 6.3.8-3.1
* pcp-pmda-gfs2 6.3.8-3.1
* pcp-pmda-gluster 6.3.8-3.1
* pcp-pmda-gpfs 6.3.8-3.1
* pcp-pmda-gpsd 6.3.8-3.1
* pcp-pmda-hacluster 6.3.8-3.1
* pcp-pmda-haproxy 6.3.8-3.1
* pcp-pmda-infiniband 6.3.8-3.1
* pcp-pmda-json 6.3.8-3.1
* pcp-pmda-lio 6.3.8-3.1
* pcp-pmda-lmsensors 6.3.8-3.1
* pcp-pmda-logger 6.3.8-3.1
* pcp-pmda-lustre 6.3.8-3.1
* pcp-pmda-lustrecomm 6.3.8-3.1
* pcp-pmda-mailq 6.3.8-3.1
* pcp-pmda-memcache 6.3.8-3.1
* pcp-pmda-mic 6.3.8-3.1
* pcp-pmda-mounts 6.3.8-3.1
* pcp-pmda-mysql 6.3.8-3.1
* pcp-pmda-named 6.3.8-3.1
* pcp-pmda-netcheck 6.3.8-3.1
* pcp-pmda-netfilter 6.3.8-3.1
* pcp-pmda-news 6.3.8-3.1
* pcp-pmda-nfsclient 6.3.8-3.1
* pcp-pmda-nginx 6.3.8-3.1
* pcp-pmda-nutcracker 6.3.8-3.1
* pcp-pmda-nvidia-gpu 6.3.8-3.1
* pcp-pmda-openmetrics 6.3.8-3.1
* pcp-pmda-openvswitch 6.3.8-3.1
* pcp-pmda-oracle 6.3.8-3.1
* pcp-pmda-pdns 6.3.8-3.1
* pcp-pmda-perfevent 6.3.8-3.1
* pcp-pmda-postfix 6.3.8-3.1
* pcp-pmda-rabbitmq 6.3.8-3.1
* pcp-pmda-redis 6.3.8-3.1
* pcp-pmda-resctrl 6.3.8-3.1
* pcp-pmda-roomtemp 6.3.8-3.1
* pcp-pmda-rsyslog 6.3.8-3.1
* pcp-pmda-samba 6.3.8-3.1
* pcp-pmda-sendmail 6.3.8-3.1
* pcp-pmda-shping 6.3.8-3.1
* pcp-pmda-slurm 6.3.8-3.1
* pcp-pmda-smart 6.3.8-3.1
* pcp-pmda-snmp 6.3.8-3.1
* pcp-pmda-sockets 6.3.8-3.1
* pcp-pmda-summary 6.3.8-3.1
* pcp-pmda-systemd 6.3.8-3.1
* pcp-pmda-trace 6.3.8-3.1
* pcp-pmda-unbound 6.3.8-3.1
* pcp-pmda-uwsgi 6.3.8-3.1
* pcp-pmda-weblog 6.3.8-3.1
* pcp-pmda-zimbra 6.3.8-3.1
* pcp-pmda-zswap 6.3.8-3.1
* pcp-selinux 6.3.8-3.1
* pcp-system-tools 6.3.8-3.1
* pcp-testsuite 6.3.8-3.1
* pcp-zeroconf 6.3.8-3.1
* perl-PCP-LogImport 6.3.8-3.1
* perl-PCP-LogSummary 6.3.8-3.1
* perl-PCP-MMV 6.3.8-3.1
* perl-PCP-PMDA 6.3.8-3.1
* python3-pcp 6.3.8-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16524.html
* https://www.suse.com/security/cve/CVE-2026-16526.html
* https://www.suse.com/security/cve/CVE-2026-16527.html
* https://www.suse.com/security/cve/CVE-2026-16529.html
* https://www.suse.com/security/cve/CVE-2026-16530.html
* https://www.suse.com/security/cve/CVE-2026-16531.html



openSUSE-SU-2026:11482-1: moderate: wild-0.10.0-2.1 on GA media


# wild-0.10.0-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11482-1
Rating: moderate

Cross-References:

* CVE-2026-25541

CVSS scores:

* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the wild-0.10.0-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* wild 0.10.0-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-25541.html



openSUSE-SU-2026:11488-1: moderate: java-21-openj9-21.0.12.0-1.1 on GA media


# java-21-openj9-21.0.12.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11488-1
Rating: moderate

Cross-References:

* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059

CVSS scores:

* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-21-openj9-21.0.12.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-21-openj9 21.0.12.0-1.1
* java-21-openj9-demo 21.0.12.0-1.1
* java-21-openj9-devel 21.0.12.0-1.1
* java-21-openj9-headless 21.0.12.0-1.1
* java-21-openj9-javadoc 21.0.12.0-1.1
* java-21-openj9-jmods 21.0.12.0-1.1
* java-21-openj9-src 21.0.12.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html



openSUSE-SU-2026:11491-1: moderate: python313-Django5-5.2.17-1.1 on GA media


# python313-Django5-5.2.17-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11491-1
Rating: moderate

Cross-References:

* CVE-2026-15307
* CVE-2026-15337
* CVE-2026-15830
* CVE-2026-15920

CVSS scores:

* CVE-2026-15307 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-15307 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N
* CVE-2026-15337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15337 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15830 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15830 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15920 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-15920 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-Django5-5.2.17-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-Django5 5.2.17-1.1
* python314-Django5 5.2.17-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15307.html
* https://www.suse.com/security/cve/CVE-2026-15337.html
* https://www.suse.com/security/cve/CVE-2026-15830.html
* https://www.suse.com/security/cve/CVE-2026-15920.html



openSUSE-SU-2026:11489-1: moderate: java-25-openj9-25.0.4.0-1.1 on GA media


# java-25-openj9-25.0.4.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11489-1
Rating: moderate

Cross-References:

* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059

CVSS scores:

* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-25-openj9-25.0.4.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-25-openj9 25.0.4.0-1.1
* java-25-openj9-demo 25.0.4.0-1.1
* java-25-openj9-devel 25.0.4.0-1.1
* java-25-openj9-headless 25.0.4.0-1.1
* java-25-openj9-javadoc 25.0.4.0-1.1
* java-25-openj9-jmods 25.0.4.0-1.1
* java-25-openj9-src 25.0.4.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html



openSUSE-SU-2026:11486-1: moderate: java-17-openj9-17.0.20.0-1.1 on GA media


# java-17-openj9-17.0.20.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11486-1
Rating: moderate

Cross-References:

* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47059

CVSS scores:

* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-17-openj9-17.0.20.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-17-openj9 17.0.20.0-1.1
* java-17-openj9-demo 17.0.20.0-1.1
* java-17-openj9-devel 17.0.20.0-1.1
* java-17-openj9-headless 17.0.20.0-1.1
* java-17-openj9-javadoc 17.0.20.0-1.1
* java-17-openj9-jmods 17.0.20.0-1.1
* java-17-openj9-src 17.0.20.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html



openSUSE-SU-2026:11485-1: moderate: java-11-openj9-11.0.32.0-1.1 on GA media


# java-11-openj9-11.0.32.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11485-1
Rating: moderate

Cross-References:

* CVE-2026-16439
* CVE-2026-16441
* CVE-2026-41254
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47027
* CVE-2026-47057
* CVE-2026-47059

CVSS scores:

* CVE-2026-16439 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:H/A:H
* CVE-2026-16439 ( SUSE ): 5.8 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L
* CVE-2026-16441 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
* CVE-2026-16441 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 8 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-11-openj9-11.0.32.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-11-openj9 11.0.32.0-1.1
* java-11-openj9-demo 11.0.32.0-1.1
* java-11-openj9-devel 11.0.32.0-1.1
* java-11-openj9-headless 11.0.32.0-1.1
* java-11-openj9-javadoc 11.0.32.0-1.1
* java-11-openj9-jmods 11.0.32.0-1.1
* java-11-openj9-src 11.0.32.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16439.html
* https://www.suse.com/security/cve/CVE-2026-16441.html
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47057.html
* https://www.suse.com/security/cve/CVE-2026-47059.html



openSUSE-SU-2026:11484-1: moderate: chromedriver-151.0.7922.108-1.1 on GA media


# chromedriver-151.0.7922.108-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11484-1
Rating: moderate

Cross-References:

* CVE-2026-19137
* CVE-2026-19138
* CVE-2026-19139
* CVE-2026-19140
* CVE-2026-19141
* CVE-2026-19142
* CVE-2026-19143
* CVE-2026-19144
* CVE-2026-19145
* CVE-2026-19146
* CVE-2026-19147
* CVE-2026-19148
* CVE-2026-19149
* CVE-2026-19150
* CVE-2026-19151
* CVE-2026-19152
* CVE-2026-19153
* CVE-2026-19154
* CVE-2026-19155
* CVE-2026-19156
* CVE-2026-19157
* CVE-2026-19158
* CVE-2026-19159
* CVE-2026-19160
* CVE-2026-19161
* CVE-2026-19162
* CVE-2026-19163
* CVE-2026-19164
* CVE-2026-19165
* CVE-2026-19166
* CVE-2026-19167
* CVE-2026-19168
* CVE-2026-19169
* CVE-2026-19170
* CVE-2026-19171
* CVE-2026-19172
* CVE-2026-19173
* CVE-2026-19174
* CVE-2026-19175
* CVE-2026-19176
* CVE-2026-19177

Affected Products:

* openSUSE Tumbleweed

An update that solves 41 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-151.0.7922.108-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 151.0.7922.108-1.1
* chromium 151.0.7922.108-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-19137.html
* https://www.suse.com/security/cve/CVE-2026-19138.html
* https://www.suse.com/security/cve/CVE-2026-19139.html
* https://www.suse.com/security/cve/CVE-2026-19140.html
* https://www.suse.com/security/cve/CVE-2026-19141.html
* https://www.suse.com/security/cve/CVE-2026-19142.html
* https://www.suse.com/security/cve/CVE-2026-19143.html
* https://www.suse.com/security/cve/CVE-2026-19144.html
* https://www.suse.com/security/cve/CVE-2026-19145.html
* https://www.suse.com/security/cve/CVE-2026-19146.html
* https://www.suse.com/security/cve/CVE-2026-19147.html
* https://www.suse.com/security/cve/CVE-2026-19148.html
* https://www.suse.com/security/cve/CVE-2026-19149.html
* https://www.suse.com/security/cve/CVE-2026-19150.html
* https://www.suse.com/security/cve/CVE-2026-19151.html
* https://www.suse.com/security/cve/CVE-2026-19152.html
* https://www.suse.com/security/cve/CVE-2026-19153.html
* https://www.suse.com/security/cve/CVE-2026-19154.html
* https://www.suse.com/security/cve/CVE-2026-19155.html
* https://www.suse.com/security/cve/CVE-2026-19156.html
* https://www.suse.com/security/cve/CVE-2026-19157.html
* https://www.suse.com/security/cve/CVE-2026-19158.html
* https://www.suse.com/security/cve/CVE-2026-19159.html
* https://www.suse.com/security/cve/CVE-2026-19160.html
* https://www.suse.com/security/cve/CVE-2026-19161.html
* https://www.suse.com/security/cve/CVE-2026-19162.html
* https://www.suse.com/security/cve/CVE-2026-19163.html
* https://www.suse.com/security/cve/CVE-2026-19164.html
* https://www.suse.com/security/cve/CVE-2026-19165.html
* https://www.suse.com/security/cve/CVE-2026-19166.html
* https://www.suse.com/security/cve/CVE-2026-19167.html
* https://www.suse.com/security/cve/CVE-2026-19168.html
* https://www.suse.com/security/cve/CVE-2026-19169.html
* https://www.suse.com/security/cve/CVE-2026-19170.html
* https://www.suse.com/security/cve/CVE-2026-19171.html
* https://www.suse.com/security/cve/CVE-2026-19172.html
* https://www.suse.com/security/cve/CVE-2026-19173.html
* https://www.suse.com/security/cve/CVE-2026-19174.html
* https://www.suse.com/security/cve/CVE-2026-19175.html
* https://www.suse.com/security/cve/CVE-2026-19176.html
* https://www.suse.com/security/cve/CVE-2026-19177.html



openSUSE-SU-2026:11483-1: moderate: zpaqfranz-64.8-1.1 on GA media


# zpaqfranz-64.8-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11483-1
Rating: moderate

Cross-References:

* CVE-2025-50327

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the zpaqfranz-64.8-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* zpaqfranz 64.8-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-50327.html



SUSE-SU-2026:3571-1: moderate: Security update for ImageMagick


# Security update for ImageMagick

Announcement ID: SUSE-SU-2026:3571-1
Release Date: 2026-08-11T08:36:12Z
Rating: moderate
References:

* bsc#1272953

Cross-References:

* CVE-2026-64685

CVSS scores:

* CVE-2026-64685 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-64685 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products:

* Desktop Applications Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for ImageMagick fixes the following issue:

* CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of-
file check (bsc#1272953).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3571=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3571=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.110.1
* ImageMagick-devel-7.1.0.9-150400.6.110.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-7.1.0.9-150400.6.110.1
* libMagick++-devel-7.1.0.9-150400.6.110.1
* ImageMagick-extra-7.1.0.9-150400.6.110.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.110.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.110.1
* perl-PerlMagick-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.110.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.110.1
* ImageMagick-debugsource-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-devel-64bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-devel-64bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (x86_64)
* libMagick++-devel-32bit-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.110.1
* ImageMagick-devel-32bit-7.1.0.9-150400.6.110.1
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.110.1
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.110.1
* openSUSE Leap 15.4 (noarch)
* ImageMagick-doc-7.1.0.9-150400.6.110.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.110.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.110.1
* ImageMagick-debugsource-7.1.0.9-150400.6.110.1

## References:

* https://www.suse.com/security/cve/CVE-2026-64685.html
* https://bugzilla.suse.com/show_bug.cgi?id72953



SUSE-SU-2026:3572-1: moderate: Security update for xmlrpc-c


# Security update for xmlrpc-c

Announcement ID: SUSE-SU-2026:3572-1
Release Date: 2026-08-11T08:36:51Z
Rating: moderate
References:

* bsc#1272769

Cross-References:

* CVE-2026-15928

CVSS scores:

* CVE-2026-15928 ( SUSE ): 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-15928 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-15928 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for xmlrpc-c fixes the following issue:

* CVE-2026-15928: reflected cross-site scripting (XSS) via HTML injection in
the error page component (bsc#1272769).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3572=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3572=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3572=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-devel-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-1.51.07-150400.3.3.1
* libxmlrpc_util++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-1.51.07-150400.3.3.1
* libxmlrpc_util4-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc_server3-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc3-1.51.07-150400.3.3.1
* libxmlrpc_client++8-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-1.51.07-150400.3.3.1
* libxmlrpc_server++8-1.51.07-150400.3.3.1
* libxmlrpc_client3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc++8-1.51.07-150400.3.3.1
* libxmlrpc_util4-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-1.51.07-150400.3.3.1
* libxmlrpc3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util++8-1.51.07-150400.3.3.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-devel-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_pstream++8-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc_server3-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-1.51.07-150400.3.3.1
* libxmlrpc_client++8-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-1.51.07-150400.3.3.1
* libxmlrpc_util++8-1.51.07-150400.3.3.1
* libxmlrpc_server++8-1.51.07-150400.3.3.1
* libxmlrpc++8-1.51.07-150400.3.3.1
* libxmlrpc_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_abyss++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_packetsocket8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server++8-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_server_cgi++8-1.51.07-150400.3.3.1
* libxmlrpc_server_abyss3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_cpp8-debuginfo-1.51.07-150400.3.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* xmlrpc-c-debuginfo-1.51.07-150400.3.3.1
* xmlrpc-c-debugsource-1.51.07-150400.3.3.1
* libxmlrpc3-1.51.07-150400.3.3.1
* libxmlrpc_util4-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_util4-1.51.07-150400.3.3.1
* libxmlrpc3-debuginfo-1.51.07-150400.3.3.1
* libxmlrpc_client3-1.51.07-150400.3.3.1
* libxmlrpc_client3-debuginfo-1.51.07-150400.3.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15928.html
* https://bugzilla.suse.com/show_bug.cgi?id72769



SUSE-SU-2026:3573-1: moderate: Security update for gstreamer-plugins-bad


# Security update for gstreamer-plugins-bad

Announcement ID: SUSE-SU-2026:3573-1
Release Date: 2026-08-11T08:37:25Z
Rating: moderate
References:

* bsc#1268394

Cross-References:

* CVE-2026-52718

CVSS scores:

* CVE-2026-52718 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4

An update that solves one vulnerability can now be installed.

## Description:

This update for gstreamer-plugins-bad fixes the following issue:

* CVE-2026-52718: byte count instead of a bit count in
gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and
an application crash (bsc#1268394).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3573=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libgstisoff-1_0-0-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsttranscoder-1_0-0-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.32.1
* gstreamer-transcoder-1.20.1-150400.3.32.1
* libgstva-1_0-0-1.20.1-150400.3.32.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.32.1
* gstreamer-transcoder-devel-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkanWayland-1_0-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-1.20.1-150400.3.32.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkan-1_0-1.20.1-150400.3.32.1
* typelib-1_0-GstVulkanXCB-1_0-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.32.1
* gstreamer-transcoder-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstTranscoder-1_0-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-1.20.1-150400.3.32.1
* libgstplay-1_0-0-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.32.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* gstreamer-plugins-bad-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstplay-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-64bit-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-64bit-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-64bit-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-64bit-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstplay-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-64bit-debuginfo-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-64bit-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-64bit-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (x86_64)
* libgstisoff-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstva-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-32bit-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-32bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstmpegts-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstadaptivedemux-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstsctp-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstcodecparsers-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstisoff-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstphotography-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-32bit-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgsturidownloader-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstcodecs-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwayland-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstvulkan-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstplay-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* gstreamer-plugins-bad-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstva-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstbasecamerabinsrc-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstplay-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstbadaudio-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstplayer-1_0-0-32bit-1.20.1-150400.3.32.1
* libgstwebrtc-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* libgstinsertbin-1_0-0-32bit-debuginfo-1.20.1-150400.3.32.1
* openSUSE Leap 15.4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.32.1

## References:

* https://www.suse.com/security/cve/CVE-2026-52718.html
* https://bugzilla.suse.com/show_bug.cgi?id68394



SUSE-SU-2026:3575-1: moderate: Security update for libarchive


# Security update for libarchive

Announcement ID: SUSE-SU-2026:3575-1
Release Date: 2026-08-11T08:38:07Z
Rating: moderate
References:

* bsc#1254340
* bsc#1254341
* bsc#1260998
* bsc#1261002
* bsc#1261003

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4

An update that has five security fixes can now be installed.

## Description:

This update for libarchive fixes the following issues:

* creating temporary files in the current working directory instead of the
target directory can lead to file creation failures when the working
directory is not writable (bsc#1254340).
* file descriptor leak in the mtree parser cleanup path could lead to file
descriptor exhaustion and denial of service (bsc#1261003).
* NULL pointer dereference in archive_acl_from_text_w() could lead to a
segmentation fault (bsc#1260998).
* reading from an invalid index when buffer size is smaller than
H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
* incorrect pointer handling for RAR5 files declaring over 8192 filters can
lead to excessive resource usage and denial of service (bsc#1261002).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3575=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3575=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3575=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3575=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3575=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3575=1

## Package List:

* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libarchive-debugsource-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* bsdtar-debuginfo-3.5.1-150400.3.27.1
* bsdtar-3.5.1-150400.3.27.1
* libarchive13-3.5.1-150400.3.27.1
* libarchive-devel-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (x86_64)
* libarchive13-32bit-3.5.1-150400.3.27.1
* libarchive13-32bit-debuginfo-3.5.1-150400.3.27.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libarchive13-64bit-debuginfo-3.5.1-150400.3.27.1
* libarchive13-64bit-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libarchive13-3.5.1-150400.3.27.1
* libarchive13-debuginfo-3.5.1-150400.3.27.1
* libarchive-debugsource-3.5.1-150400.3.27.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id54340
* https://bugzilla.suse.com/show_bug.cgi?id54341
* https://bugzilla.suse.com/show_bug.cgi?id60998
* https://bugzilla.suse.com/show_bug.cgi?id61002
* https://bugzilla.suse.com/show_bug.cgi?id61003



SUSE-SU-2026:3576-1: important: Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update


# Security update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update

Announcement ID: SUSE-SU-2026:3576-1
Release Date: 2026-08-11T11:51:08Z
Rating: important
References:

* bsc#1270182
* bsc#1270520
* bsc#1270613
* bsc#1270707
* bsc#1270794
* bsc#1270830
* bsc#1270939
* bsc#1270946
* bsc#1270985
* bsc#1273910
* bsc#1273911
* bsc#1273912

Cross-References:

* CVE-2026-41676
* CVE-2026-41677
* CVE-2026-41678
* CVE-2026-41681
* CVE-2026-41898
* CVE-2026-42327
* CVE-2026-44662
* CVE-2026-45784

CVSS scores:

* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41677 ( SUSE ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
* CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-41677 ( NVD ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-41678 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-41681 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-41681 ( NVD ): 8.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41898 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-41898 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-42327 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44662 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-44662 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45784 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-45784 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45784 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves eight vulnerabilities and has four security fixes can now
be installed.

## Description:

This update for himmelblau, himmelblau.SUSE_SLE-15-SP5_Update fixes the
following issues:

Security fixes:

* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270182).
* CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when
returning an oversized length (bsc#1270613).
* CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in
`aes::unwrap_key()` (bsc#1270707).
* CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()`
writing past caller buffer with no length check (bsc#1270794).
* CVE-2026-41898: openssl: information leak to network peers due to unchecked
callback-returned length in PSK and cookie generate trampolines
(bsc#1270830).
* CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders`
when processing certificates with non-UTF-8 OCSP URLs (bsc#1270520).
* CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-
wrap-with-padding (bsc#1270939).
* CVE-2026-45784: out-of-bounds write in `CipherCtxRef::cipher_update_inplace`
for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270985).
* GHSA-4f5j-9xgm-8pvr: arbitrary HTTP or HTTPS URL classified as an Office
document based on an attacker-controlled file query parameters and forwarded
to an Electron application (bsc#1273910).
* GHSA-6cq7-jcwm-cpmr: directory-provided RFC2307 user identifiers accepted
without exclusion of systemd's dynamic-user range allows for daemon
impersonation and command execution through the task helper (bsc#1273911).
* GHSA-6gp8-pp9v-gx45: daemon acts on Hello PIN enrollment requests whose
identity claims it never cryptographically verifies (bsc#1273912).

Other fixes:

* Version 2.3.14+git0.e23b4c54:

* fix(nss): avoid locked shadow entries

* Version 2.3.14:

* fix(deps): update libhimmelblau lockfile

* fix(pam): make account denials terminal
* debian: make the pam_allow_groups denial terminal in the account phase

* Version 2.3.13:

* Update cargo vet audits for backport

* Version 2.3.12+git0.9d56c6f1:

* Fix cargo-fuzz install in fuzz CI

* cargo vet
* Update ldap3_proto to 0.7.1

* Version 2.3.12:

* Update cargo vet audits for backport

* Remove invalid himmelblau.conf example info
* Fix SSHd configuration load order on Fedora/RHEL systems
* himmelblau-init-hsm-pin: don't bind the hsm-pin to PCR7
* qr-greeter: support GNOME Shell 50
* Update libhimmelblau to latest version
* deps(rust): bump tonic in the all-cargo-updates group across 1 directory
* cargo audit

* Version 2.3.11+git0.c802b25f:

* Update cargo vet audits for backport

* Reject auth when token spn local part differs from requested account_id
* Update libhimmelblau to latest version
* deps(rust): bump the all-cargo-updates group with 19 updates
* cargo vet

* Version 2.3.10:

* nss/pam: bail out early when SYSTEMD_ACTIVATION_UNIT points to himmelblau

* selinux: allow unconfined_service_t to search himmelblaud_t dirs
* idprovider: release providers lock before async alias lookup

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3576=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3576=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3576=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3576=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3576=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3576=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3576=1

## Package List:

* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* openSUSE Leap 15.5 (aarch64 x86_64)
* himmelblau-sso-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-sso-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* pam-himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-debuginfo-2.3.14+git0.e23b4c54-150500.11.12.1
* libnss_himmelblau2-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-2.3.14+git0.e23b4c54-150500.11.12.1
* openSUSE Leap 15.5 (noarch)
* himmelblau-sshd-config-2.3.14+git0.e23b4c54-150500.11.12.1
* himmelblau-qr-greeter-2.3.14+git0.e23b4c54-150500.11.12.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html
* https://bugzilla.suse.com/show_bug.cgi?id70182
* https://bugzilla.suse.com/show_bug.cgi?id70520
* https://bugzilla.suse.com/show_bug.cgi?id70613
* https://bugzilla.suse.com/show_bug.cgi?id70707
* https://bugzilla.suse.com/show_bug.cgi?id70794
* https://bugzilla.suse.com/show_bug.cgi?id70830
* https://bugzilla.suse.com/show_bug.cgi?id70939
* https://bugzilla.suse.com/show_bug.cgi?id70946
* https://bugzilla.suse.com/show_bug.cgi?id70985
* https://bugzilla.suse.com/show_bug.cgi?id73910
* https://bugzilla.suse.com/show_bug.cgi?id73911
* https://bugzilla.suse.com/show_bug.cgi?id73912



SUSE-SU-2026:3577-1: important: Security update for snpguest


# Security update for snpguest

Announcement ID: SUSE-SU-2026:3577-1
Release Date: 2026-08-11T11:53:28Z
Rating: important
References:

* bsc#1270527
* bsc#1270642
* bsc#1274139

Cross-References:

* CVE-2026-25541
* CVE-2026-41678
* CVE-2026-42327

CVSS scores:

* CVE-2026-25541 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( NVD ): 5.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41678 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42327 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves three vulnerabilities can now be installed.

## Description:

This update for snpguest fixes the following issues:

* CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to
undefined behavior and crashes (bsc#1274139).
* CVE-2026-41678: openssl: incorrect bounds assertion in AES keywrap can lead
to an out-of-bounds write (bsc#1270642).
* CVE-2026-42327: openssl: missing validation when processing certificates
with non-UTF-8 OCSP URLs can lead to undefined behavior (bsc#1270527).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3577=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3577=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3577=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1
* openSUSE Leap 15.6 (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debugsource-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* snpguest-0.3.2-150600.3.14.1
* snpguest-debuginfo-0.3.2-150600.3.14.1

## References:

* https://www.suse.com/security/cve/CVE-2026-25541.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://bugzilla.suse.com/show_bug.cgi?id70527
* https://bugzilla.suse.com/show_bug.cgi?id70642
* https://bugzilla.suse.com/show_bug.cgi?id74139



openSUSE-SU-2026:0280-1: important: Security update for go-sendxmpp


openSUSE Security Update: Security update for go-sendxmpp
_______________________________

Announcement ID: openSUSE-SU-2026:0280-1
Rating: important
References: #1266617
Cross-References: CVE-2026-39821
CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for go-sendxmpp fixes the following issues:

- Update to 0.17.0:
* Add --ox-transfer-private-key to transfer the encrypted private key to
PEP to transfer it to other devices (requires go-xmpp >= v0.3.7).
* Add --ox-receive-private-key to receive the encrypted private key from
PEP.
* Add config option no_root_warning.
* Add config option no_legacy_pgp_warning.
* Also disable legacy PGP when running as root (Ox was already disabled).
* Disable pinning for not using PLAIN when running as root.
* Add config option ox_trust_mode with settings blind and tofu.
* Due to new tofu trust mode for Ox, only one public key per contact is
accepted for easier ID handling.
* Ox: Check that fingerprint of received key equals the advertised one.
* CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels
allows for validation bypass and privilege escalation (boo#1266617):
Bump net to 0.57.0

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-280=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

go-sendxmpp-0.17.0-bp157.2.12.1

References:

https://www.suse.com/security/cve/CVE-2026-39821.html
https://bugzilla.suse.com/1266617



SUSE-SU-2026:3579-1: important: Security update for erlang26


# Security update for erlang26

Announcement ID: SUSE-SU-2026:3579-1
Release Date: 2026-08-11T14:05:55Z
Rating: important
References:

* bsc#1261726
* bsc#1266449
* bsc#1266466
* bsc#1268139
* bsc#1268141
* bsc#1268142
* bsc#1268146
* bsc#1268163
* bsc#1268164
* bsc#1270245
* bsc#1270246
* bsc#1270247
* bsc#1270250
* bsc#1270253
* bsc#1270258
* bsc#1272908
* bsc#1272909
* bsc#1272910
* bsc#1272911
* bsc#1272913
* bsc#1272914
* bsc#1272915

Cross-References:

* CVE-2026-28810
* CVE-2026-42789
* CVE-2026-42790
* CVE-2026-42792
* CVE-2026-47078
* CVE-2026-48855
* CVE-2026-48856
* CVE-2026-48858
* CVE-2026-48860
* CVE-2026-49759
* CVE-2026-49760
* CVE-2026-53422
* CVE-2026-54886
* CVE-2026-54887
* CVE-2026-54891
* CVE-2026-55737
* CVE-2026-55950
* CVE-2026-55952
* CVE-2026-55953
* CVE-2026-58227
* CVE-2026-59250
* CVE-2026-59251

CVSS scores:

* CVE-2026-28810 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-28810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-28810 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-28810 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-42789 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42789 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42789 ( NVD ): 7.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42789 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
* CVE-2026-42789 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-42790 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42790 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42790 ( NVD ): 7.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42790 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42790 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
* CVE-2026-42792 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-42792 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-42792 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42792 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47078 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L
* CVE-2026-47078 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
* CVE-2026-47078 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-48855 ( NVD ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48855 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48856 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48856 ( NVD ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48856 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48858 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-48858 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48858 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-48860 ( SUSE ): 8.0 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-48860 ( NVD ): 7.5
CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48860 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-49759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49759 ( NVD ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-49759 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-49759 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-49760 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49760 ( NVD ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-49760 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53422 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53422 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-53422 ( NVD ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-53422 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-54886 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54886 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54886 ( NVD ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54886 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54887 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-54887 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54887 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54887 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-54891 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-54891 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-54891 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54891 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-55737 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-55737 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-55737 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55737 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55950 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55950 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55950 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55950 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55952 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55952 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55952 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55952 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55953 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-55953 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-55953 ( NVD ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-55953 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-58227 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58227 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58227 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58227 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59250 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59250 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59250 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59251 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
* CVE-2026-59251 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59251 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59251 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.3
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves 22 vulnerabilities can now be installed.

## Description:

This update for erlang26 fixes the following issues:

* CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache
poisoning (bsc#1261726).
* CVE-2026-42789: `public_key` application accepts non-CA certificates as
intermediate issuers and this enables chain forgery (bsc#1266449).
* CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS
hostname verification allows for certificate forgery by MITM attacker
(bsc#1266466).
* CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to
improper handling of exceptional conditions (bsc#1272908).
* CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via
`check_dir_level` depth-counter bypass (bsc#1272909).
* CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem
path when root is configured (bsc#1268139).
* CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin
redirect targets (bsc#1268141).
* CVE-2026-48858: server-side request forgery allows FTP bounce attacks and
SSRF via an unvalidated `PASV` response IP address (bsc#1268142).
* CVE-2026-48860: `ssl` (`inet_tls_dist` module) allows unauthenticated bypass
of the distribution-over-TLS LAN allowlist (bsc#1268146).
* CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing
in `inet_drv` (bsc#1268163).
* CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large
integer (bsc#1268164).
* CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem
enumeration outside configured root (bsc#1270245).
* CVE-2026-54886: SSH SFTP server denial of service via extended channel data
infinite loop (bsc#1270246).
* CVE-2026-54887: use of default cryptographic key allows predictable DTLS
cookie computation during the startup window (bsc#1270247).
* CVE-2026-54891: plaintext injection towards (D)TLS client during handshake
(bsc#1270250).
* CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in
`LARGE_TUPLE_EXTP` decoding in `erts` external term format decoder
(bsc#1272910).
* CVE-2026-55950: time-of-check time-of-use race condition allows an
unauthenticated remote attacker to crash all active DTLS sessions on a
listener (bsc#1270253).
* CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when
clients send a malformed `ClientHello` with mismatched PSK identity and
binder list lengths (bsc#1270258).
* CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher
suites and allow for server authentication bypass (bsc#1272911).
* CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-
signed peer certificate chain (bsc#1272913).
* CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property
parm name (bsc#1272914).
* CVE-2026-59251: denial of service via exponential certificate policy tree
growth in path validation (bsc#1272915).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3579=1

* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3579=1

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3579=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3579=1

## Package List:

* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-jinterface-26.2.1-150300.7.28.1
* erlang26-wx-src-26.2.1-150300.7.28.1
* erlang26-dialyzer-src-26.2.1-150300.7.28.1
* erlang26-diameter-src-26.2.1-150300.7.28.1
* erlang26-wx-26.2.1-150300.7.28.1
* erlang26-et-26.2.1-150300.7.28.1
* erlang26-debugger-26.2.1-150300.7.28.1
* erlang26-reltool-src-26.2.1-150300.7.28.1
* erlang26-reltool-26.2.1-150300.7.28.1
* erlang26-debugger-src-26.2.1-150300.7.28.1
* erlang26-dialyzer-debuginfo-26.2.1-150300.7.28.1
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-doc-26.2.1-150300.7.28.1
* erlang26-diameter-26.2.1-150300.7.28.1
* erlang26-wx-debuginfo-26.2.1-150300.7.28.1
* erlang26-observer-src-26.2.1-150300.7.28.1
* erlang26-src-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-observer-26.2.1-150300.7.28.1
* erlang26-dialyzer-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* erlang26-jinterface-src-26.2.1-150300.7.28.1
* erlang26-et-src-26.2.1-150300.7.28.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* erlang26-debugsource-26.2.1-150300.7.28.1
* erlang26-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-debuginfo-26.2.1-150300.7.28.1
* erlang26-epmd-26.2.1-150300.7.28.1
* erlang26-26.2.1-150300.7.28.1

## References:

* https://www.suse.com/security/cve/CVE-2026-28810.html
* https://www.suse.com/security/cve/CVE-2026-42789.html
* https://www.suse.com/security/cve/CVE-2026-42790.html
* https://www.suse.com/security/cve/CVE-2026-42792.html
* https://www.suse.com/security/cve/CVE-2026-47078.html
* https://www.suse.com/security/cve/CVE-2026-48855.html
* https://www.suse.com/security/cve/CVE-2026-48856.html
* https://www.suse.com/security/cve/CVE-2026-48858.html
* https://www.suse.com/security/cve/CVE-2026-48860.html
* https://www.suse.com/security/cve/CVE-2026-49759.html
* https://www.suse.com/security/cve/CVE-2026-49760.html
* https://www.suse.com/security/cve/CVE-2026-53422.html
* https://www.suse.com/security/cve/CVE-2026-54886.html
* https://www.suse.com/security/cve/CVE-2026-54887.html
* https://www.suse.com/security/cve/CVE-2026-54891.html
* https://www.suse.com/security/cve/CVE-2026-55737.html
* https://www.suse.com/security/cve/CVE-2026-55950.html
* https://www.suse.com/security/cve/CVE-2026-55952.html
* https://www.suse.com/security/cve/CVE-2026-55953.html
* https://www.suse.com/security/cve/CVE-2026-58227.html
* https://www.suse.com/security/cve/CVE-2026-59250.html
* https://www.suse.com/security/cve/CVE-2026-59251.html
* https://bugzilla.suse.com/show_bug.cgi?id61726
* https://bugzilla.suse.com/show_bug.cgi?id66449
* https://bugzilla.suse.com/show_bug.cgi?id66466
* https://bugzilla.suse.com/show_bug.cgi?id68139
* https://bugzilla.suse.com/show_bug.cgi?id68141
* https://bugzilla.suse.com/show_bug.cgi?id68142
* https://bugzilla.suse.com/show_bug.cgi?id68146
* https://bugzilla.suse.com/show_bug.cgi?id68163
* https://bugzilla.suse.com/show_bug.cgi?id68164
* https://bugzilla.suse.com/show_bug.cgi?id70245
* https://bugzilla.suse.com/show_bug.cgi?id70246
* https://bugzilla.suse.com/show_bug.cgi?id70247
* https://bugzilla.suse.com/show_bug.cgi?id70250
* https://bugzilla.suse.com/show_bug.cgi?id70253
* https://bugzilla.suse.com/show_bug.cgi?id70258
* https://bugzilla.suse.com/show_bug.cgi?id72908
* https://bugzilla.suse.com/show_bug.cgi?id72909
* https://bugzilla.suse.com/show_bug.cgi?id72910
* https://bugzilla.suse.com/show_bug.cgi?id72911
* https://bugzilla.suse.com/show_bug.cgi?id72913
* https://bugzilla.suse.com/show_bug.cgi?id72914
* https://bugzilla.suse.com/show_bug.cgi?id72915



SUSE-SU-2026:3588-1: moderate: Security update for python3-pip


# Security update for python3-pip

Announcement ID: SUSE-SU-2026:3588-1
Release Date: 2026-08-11T14:56:50Z
Rating: moderate
References:

* bsc#1273090

Cross-References:

* CVE-2026-13346

CVSS scores:

* CVE-2026-13346 ( SUSE ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-13346 ( NVD ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for python3-pip fixes the following issue:

* CVE-2026-13346: incorrect handling of doubly-encoded package URLs from
malicious indexes allows files to be installed to arbitrary locations on
disk (bsc#1273090).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3588=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3588=1

## Package List:

* Basesystem Module 15-SP7 (noarch)
* python3-pip-wheel-20.0.2-150400.26.1
* python3-pip-20.0.2-150400.26.1
* openSUSE Leap 15.4 (noarch)
* python3-pip-wheel-20.0.2-150400.26.1
* python3-pip-test-20.0.2-150400.26.1
* python3-pip-20.0.2-150400.26.1

## References:

* https://www.suse.com/security/cve/CVE-2026-13346.html
* https://bugzilla.suse.com/show_bug.cgi?id73090



SUSE-SU-2026:3589-1: moderate: Security update for python-pip


# Security update for python-pip

Announcement ID: SUSE-SU-2026:3589-1
Release Date: 2026-08-11T14:57:17Z
Rating: moderate
References:

* bsc#1273090

Cross-References:

* CVE-2026-13346

CVSS scores:

* CVE-2026-13346 ( SUSE ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-13346 ( NVD ): 5.6
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves one vulnerability can now be installed.

## Description:

This update for python-pip fixes the following issue:

* CVE-2026-13346: incorrect handling of doubly-encoded package URLs from
malicious indexes allows files to be installed to arbitrary locations on
disk (bsc#1273090).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3589=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3589=1

* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3589=1

## Package List:

* Public Cloud Module 15-SP4 (noarch)
* python311-pip-22.3.1-150400.17.29.1
* Python 3 Module 15-SP7 (noarch)
* python311-pip-22.3.1-150400.17.29.1
* openSUSE Leap 15.4 (noarch)
* python311-pip-22.3.1-150400.17.29.1

## References:

* https://www.suse.com/security/cve/CVE-2026-13346.html
* https://bugzilla.suse.com/show_bug.cgi?id73090