SUSE 5719 Published by

SUSE distributed eight moderate severity security updates across its openSUSE general availability repositories. The release addresses vulnerabilities in widely used software including chromedriver, python313-astropy, perl modules, proftpd, ffmpeg, and cloud management tools like amazon-ecs-init and google-osconfig-agent. Each package received a targeted version bump designed to patch known flaws without altering system stability.

openSUSE-SU-2026:11346-1: moderate: chromedriver-150.0.7871.181-1.1 on GA media
openSUSE-SU-2026:11353-1: moderate: python313-astropy-8.0.1-1.1 on GA media
openSUSE-SU-2026:11351-1: moderate: perl-XML-Bare-0.53-7.1 on GA media
openSUSE-SU-2026:11350-1: moderate: perl-HTTP-Date-6.80.0-1.1 on GA media
openSUSE-SU-2026:11352-1: moderate: proftpd-1.3.9c-1.1 on GA media
openSUSE-SU-2026:11347-1: moderate: ffmpeg-8-8.1.2-2.1 on GA media
openSUSE-SU-2026:11345-1: moderate: amazon-ecs-init-1.105.0-2.1 on GA media
openSUSE-SU-2026:11349-1: moderate: google-osconfig-agent-20260708.00-3.1 on GA media




openSUSE-SU-2026:11346-1: moderate: chromedriver-150.0.7871.181-1.1 on GA media


# chromedriver-150.0.7871.181-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11346-1
Rating: moderate

Cross-References:

* CVE-2026-16413
* CVE-2026-16414
* CVE-2026-16415
* CVE-2026-16416
* CVE-2026-16417
* CVE-2026-16418
* CVE-2026-16419
* CVE-2026-16420
* CVE-2026-16421
* CVE-2026-16422
* CVE-2026-16423
* CVE-2026-16424

Affected Products:

* openSUSE Tumbleweed

An update that solves 12 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-150.0.7871.181-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 150.0.7871.181-1.1
* chromium 150.0.7871.181-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-16413.html
* https://www.suse.com/security/cve/CVE-2026-16414.html
* https://www.suse.com/security/cve/CVE-2026-16415.html
* https://www.suse.com/security/cve/CVE-2026-16416.html
* https://www.suse.com/security/cve/CVE-2026-16417.html
* https://www.suse.com/security/cve/CVE-2026-16418.html
* https://www.suse.com/security/cve/CVE-2026-16419.html
* https://www.suse.com/security/cve/CVE-2026-16420.html
* https://www.suse.com/security/cve/CVE-2026-16421.html
* https://www.suse.com/security/cve/CVE-2026-16422.html
* https://www.suse.com/security/cve/CVE-2026-16423.html
* https://www.suse.com/security/cve/CVE-2026-16424.html



openSUSE-SU-2026:11353-1: moderate: python313-astropy-8.0.1-1.1 on GA media


# python313-astropy-8.0.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11353-1
Rating: moderate

Cross-References:

* CVE-2023-41334

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-astropy-8.0.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-astropy 8.0.1-1.1
* python314-astropy 8.0.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2023-41334.html



openSUSE-SU-2026:11351-1: moderate: perl-XML-Bare-0.53-7.1 on GA media


# perl-XML-Bare-0.53-7.1 on GA media

Announcement ID: openSUSE-SU-2026:11351-1
Rating: moderate

Cross-References:

* CVE-2026-13401
* CVE-2026-57074

CVSS scores:

* CVE-2026-13401 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-57074 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the perl-XML-Bare-0.53-7.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl-XML-Bare 0.53-7.1

## References:

* https://www.suse.com/security/cve/CVE-2026-13401.html
* https://www.suse.com/security/cve/CVE-2026-57074.html



openSUSE-SU-2026:11350-1: moderate: perl-HTTP-Date-6.80.0-1.1 on GA media


# perl-HTTP-Date-6.80.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11350-1
Rating: moderate

Cross-References:

* CVE-2026-14741

CVSS scores:

* CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the perl-HTTP-Date-6.80.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* perl-HTTP-Date 6.80.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-14741.html



openSUSE-SU-2026:11352-1: moderate: proftpd-1.3.9c-1.1 on GA media


# proftpd-1.3.9c-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11352-1
Rating: moderate

Cross-References:

* CVE-2026-42167

CVSS scores:

* CVE-2026-42167 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the proftpd-1.3.9c-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* proftpd 1.3.9c-1.1
* proftpd-devel 1.3.9c-1.1
* proftpd-doc 1.3.9c-1.1
* proftpd-lang 1.3.9c-1.1
* proftpd-ldap 1.3.9c-1.1
* proftpd-mysql 1.3.9c-1.1
* proftpd-pgsql 1.3.9c-1.1
* proftpd-radius 1.3.9c-1.1
* proftpd-sqlite 1.3.9c-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-42167.html



openSUSE-SU-2026:11347-1: moderate: ffmpeg-8-8.1.2-2.1 on GA media


# ffmpeg-8-8.1.2-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11347-1
Rating: moderate

Cross-References:

* CVE-2026-12706
* CVE-2026-8461

CVSS scores:

* CVE-2026-12706 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-8461 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ffmpeg-8-8.1.2-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ffmpeg-8 8.1.2-2.1
* ffmpeg-8-libavcodec-devel 8.1.2-2.1
* ffmpeg-8-libavdevice-devel 8.1.2-2.1
* ffmpeg-8-libavfilter-devel 8.1.2-2.1
* ffmpeg-8-libavformat-devel 8.1.2-2.1
* ffmpeg-8-libavutil-devel 8.1.2-2.1
* ffmpeg-8-libswresample-devel 8.1.2-2.1
* ffmpeg-8-libswscale-devel 8.1.2-2.1
* libavcodec62 8.1.2-2.1
* libavcodec62-32bit 8.1.2-2.1
* libavdevice62 8.1.2-2.1
* libavdevice62-32bit 8.1.2-2.1
* libavfilter11 8.1.2-2.1
* libavfilter11-32bit 8.1.2-2.1
* libavformat62 8.1.2-2.1
* libavformat62-32bit 8.1.2-2.1
* libavutil60 8.1.2-2.1
* libavutil60-32bit 8.1.2-2.1
* libswresample6 8.1.2-2.1
* libswresample6-32bit 8.1.2-2.1
* libswscale9 8.1.2-2.1
* libswscale9-32bit 8.1.2-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-12706.html
* https://www.suse.com/security/cve/CVE-2026-8461.html



openSUSE-SU-2026:11345-1: moderate: amazon-ecs-init-1.105.0-2.1 on GA media


# amazon-ecs-init-1.105.0-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11345-1
Rating: moderate

Cross-References:

* CVE-2026-56852

CVSS scores:

* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the amazon-ecs-init-1.105.0-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* amazon-ecs-init 1.105.0-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:11349-1: moderate: google-osconfig-agent-20260708.00-3.1 on GA media


# google-osconfig-agent-20260708.00-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11349-1
Rating: moderate

Cross-References:

* CVE-2026-56852

CVSS scores:

* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the google-osconfig-agent-20260708.00-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* google-osconfig-agent 20260708.00-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56852.html