SUSE 5677 Published by

SUSE has released a series of moderate security updates for Tumbleweed that address multiple vulnerabilities across several widely used packages. The chromedriver update stands out by fixing 74 separate issues, while other patches target critical components like strongswan, Django, FFmpeg, and Ansible. Each advisory includes detailed CVSS ratings that highlight the potential impact on system confidentiality and availability if left unpatched. System administrators should prioritize installing these GA media updates to close security gaps before attackers can exploit the known flaws.

openSUSE-SU-2026:11005-1: moderate: strongswan-6.0.7-1.1 on GA media
openSUSE-SU-2026:11008-1: moderate: chromedriver-149.0.7827.102-1.1 on GA media
openSUSE-SU-2026:11003-1: moderate: python313-Django6-6.0.6-1.1 on GA media
openSUSE-SU-2026:11009-1: moderate: ffmpeg-7-7.1.4-3.1 on GA media
openSUSE-SU-2026:11007-1: moderate: ansible-core-2.21.0-3.1 on GA media
openSUSE-SU-2026:11001-1: moderate: postgresql-jdbc-42.7.11-1.1 on GA media
openSUSE-SU-2026:11006-1: moderate: tmux-3.6b-2.1 on GA media




openSUSE-SU-2026:11005-1: moderate: strongswan-6.0.7-1.1 on GA media


# strongswan-6.0.7-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11005-1
Rating: moderate

Cross-References:

* CVE-2026-47895

CVSS scores:

* CVE-2026-47895 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-47895 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the strongswan-6.0.7-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* strongswan 6.0.7-1.1
* strongswan-doc 6.0.7-1.1
* strongswan-fips 6.0.7-1.1
* strongswan-ipsec 6.0.7-1.1
* strongswan-mysql 6.0.7-1.1
* strongswan-nm 6.0.7-1.1
* strongswan-sqlite 6.0.7-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-47895.html



openSUSE-SU-2026:11008-1: moderate: chromedriver-149.0.7827.102-1.1 on GA media


# chromedriver-149.0.7827.102-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11008-1
Rating: moderate

Cross-References:

* CVE-2026-11628
* CVE-2026-11629
* CVE-2026-11630
* CVE-2026-11631
* CVE-2026-11632
* CVE-2026-11633
* CVE-2026-11634
* CVE-2026-11635
* CVE-2026-11636
* CVE-2026-11637
* CVE-2026-11638
* CVE-2026-11639
* CVE-2026-11640
* CVE-2026-11641
* CVE-2026-11642
* CVE-2026-11643
* CVE-2026-11644
* CVE-2026-11645
* CVE-2026-11646
* CVE-2026-11647
* CVE-2026-11648
* CVE-2026-11649
* CVE-2026-11650
* CVE-2026-11651
* CVE-2026-11652
* CVE-2026-11653
* CVE-2026-11654
* CVE-2026-11655
* CVE-2026-11656
* CVE-2026-11657
* CVE-2026-11658
* CVE-2026-11659
* CVE-2026-11660
* CVE-2026-11661
* CVE-2026-11662
* CVE-2026-11663
* CVE-2026-11664
* CVE-2026-11665
* CVE-2026-11666
* CVE-2026-11667
* CVE-2026-11668
* CVE-2026-11669
* CVE-2026-11670
* CVE-2026-11671
* CVE-2026-11672
* CVE-2026-11673
* CVE-2026-11674
* CVE-2026-11675
* CVE-2026-11676
* CVE-2026-11677
* CVE-2026-11678
* CVE-2026-11679
* CVE-2026-11680
* CVE-2026-11681
* CVE-2026-11682
* CVE-2026-11683
* CVE-2026-11684
* CVE-2026-11685
* CVE-2026-11686
* CVE-2026-11687
* CVE-2026-11688
* CVE-2026-11689
* CVE-2026-11690
* CVE-2026-11691
* CVE-2026-11692
* CVE-2026-11693
* CVE-2026-11694
* CVE-2026-11695
* CVE-2026-11696
* CVE-2026-11697
* CVE-2026-11698
* CVE-2026-11699
* CVE-2026-11700
* CVE-2026-11701

Affected Products:

* openSUSE Tumbleweed

An update that solves 74 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-149.0.7827.102-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 149.0.7827.102-1.1
* chromium 149.0.7827.102-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-11628.html
* https://www.suse.com/security/cve/CVE-2026-11629.html
* https://www.suse.com/security/cve/CVE-2026-11630.html
* https://www.suse.com/security/cve/CVE-2026-11631.html
* https://www.suse.com/security/cve/CVE-2026-11632.html
* https://www.suse.com/security/cve/CVE-2026-11633.html
* https://www.suse.com/security/cve/CVE-2026-11634.html
* https://www.suse.com/security/cve/CVE-2026-11635.html
* https://www.suse.com/security/cve/CVE-2026-11636.html
* https://www.suse.com/security/cve/CVE-2026-11637.html
* https://www.suse.com/security/cve/CVE-2026-11638.html
* https://www.suse.com/security/cve/CVE-2026-11639.html
* https://www.suse.com/security/cve/CVE-2026-11640.html
* https://www.suse.com/security/cve/CVE-2026-11641.html
* https://www.suse.com/security/cve/CVE-2026-11642.html
* https://www.suse.com/security/cve/CVE-2026-11643.html
* https://www.suse.com/security/cve/CVE-2026-11644.html
* https://www.suse.com/security/cve/CVE-2026-11645.html
* https://www.suse.com/security/cve/CVE-2026-11646.html
* https://www.suse.com/security/cve/CVE-2026-11647.html
* https://www.suse.com/security/cve/CVE-2026-11648.html
* https://www.suse.com/security/cve/CVE-2026-11649.html
* https://www.suse.com/security/cve/CVE-2026-11650.html
* https://www.suse.com/security/cve/CVE-2026-11651.html
* https://www.suse.com/security/cve/CVE-2026-11652.html
* https://www.suse.com/security/cve/CVE-2026-11653.html
* https://www.suse.com/security/cve/CVE-2026-11654.html
* https://www.suse.com/security/cve/CVE-2026-11655.html
* https://www.suse.com/security/cve/CVE-2026-11656.html
* https://www.suse.com/security/cve/CVE-2026-11657.html
* https://www.suse.com/security/cve/CVE-2026-11658.html
* https://www.suse.com/security/cve/CVE-2026-11659.html
* https://www.suse.com/security/cve/CVE-2026-11660.html
* https://www.suse.com/security/cve/CVE-2026-11661.html
* https://www.suse.com/security/cve/CVE-2026-11662.html
* https://www.suse.com/security/cve/CVE-2026-11663.html
* https://www.suse.com/security/cve/CVE-2026-11664.html
* https://www.suse.com/security/cve/CVE-2026-11665.html
* https://www.suse.com/security/cve/CVE-2026-11666.html
* https://www.suse.com/security/cve/CVE-2026-11667.html
* https://www.suse.com/security/cve/CVE-2026-11668.html
* https://www.suse.com/security/cve/CVE-2026-11669.html
* https://www.suse.com/security/cve/CVE-2026-11670.html
* https://www.suse.com/security/cve/CVE-2026-11671.html
* https://www.suse.com/security/cve/CVE-2026-11672.html
* https://www.suse.com/security/cve/CVE-2026-11673.html
* https://www.suse.com/security/cve/CVE-2026-11674.html
* https://www.suse.com/security/cve/CVE-2026-11675.html
* https://www.suse.com/security/cve/CVE-2026-11676.html
* https://www.suse.com/security/cve/CVE-2026-11677.html
* https://www.suse.com/security/cve/CVE-2026-11678.html
* https://www.suse.com/security/cve/CVE-2026-11679.html
* https://www.suse.com/security/cve/CVE-2026-11680.html
* https://www.suse.com/security/cve/CVE-2026-11681.html
* https://www.suse.com/security/cve/CVE-2026-11682.html
* https://www.suse.com/security/cve/CVE-2026-11683.html
* https://www.suse.com/security/cve/CVE-2026-11684.html
* https://www.suse.com/security/cve/CVE-2026-11685.html
* https://www.suse.com/security/cve/CVE-2026-11686.html
* https://www.suse.com/security/cve/CVE-2026-11687.html
* https://www.suse.com/security/cve/CVE-2026-11688.html
* https://www.suse.com/security/cve/CVE-2026-11689.html
* https://www.suse.com/security/cve/CVE-2026-11690.html
* https://www.suse.com/security/cve/CVE-2026-11691.html
* https://www.suse.com/security/cve/CVE-2026-11692.html
* https://www.suse.com/security/cve/CVE-2026-11693.html
* https://www.suse.com/security/cve/CVE-2026-11694.html
* https://www.suse.com/security/cve/CVE-2026-11695.html
* https://www.suse.com/security/cve/CVE-2026-11696.html
* https://www.suse.com/security/cve/CVE-2026-11697.html
* https://www.suse.com/security/cve/CVE-2026-11698.html
* https://www.suse.com/security/cve/CVE-2026-11699.html
* https://www.suse.com/security/cve/CVE-2026-11700.html
* https://www.suse.com/security/cve/CVE-2026-11701.html



openSUSE-SU-2026:11003-1: moderate: python313-Django6-6.0.6-1.1 on GA media


# python313-Django6-6.0.6-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11003-1
Rating: moderate

Cross-References:

* CVE-2026-35193
* CVE-2026-48587
* CVE-2026-6873
* CVE-2026-7666
* CVE-2026-8404

CVSS scores:

* CVE-2026-35193 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-35193 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-48587 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-48587 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6873 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-6873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7666 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-7666 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8404 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-8404 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-Django6-6.0.6-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-Django6 6.0.6-1.1
* python314-Django6 6.0.6-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-35193.html
* https://www.suse.com/security/cve/CVE-2026-48587.html
* https://www.suse.com/security/cve/CVE-2026-6873.html
* https://www.suse.com/security/cve/CVE-2026-7666.html
* https://www.suse.com/security/cve/CVE-2026-8404.html



openSUSE-SU-2026:11009-1: moderate: ffmpeg-7-7.1.4-3.1 on GA media


# ffmpeg-7-7.1.4-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11009-1
Rating: moderate

Cross-References:

* CVE-2026-30997

CVSS scores:

* CVE-2026-30997 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-30997 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the ffmpeg-7-7.1.4-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ffmpeg-7 7.1.4-3.1
* ffmpeg-7-libavcodec-devel 7.1.4-3.1
* ffmpeg-7-libavdevice-devel 7.1.4-3.1
* ffmpeg-7-libavfilter-devel 7.1.4-3.1
* ffmpeg-7-libavformat-devel 7.1.4-3.1
* ffmpeg-7-libavutil-devel 7.1.4-3.1
* ffmpeg-7-libpostproc-devel 7.1.4-3.1
* ffmpeg-7-libswresample-devel 7.1.4-3.1
* ffmpeg-7-libswscale-devel 7.1.4-3.1
* libavcodec61 7.1.4-3.1
* libavdevice61 7.1.4-3.1
* libavfilter10 7.1.4-3.1
* libavformat61 7.1.4-3.1
* libavutil59 7.1.4-3.1
* libpostproc58 7.1.4-3.1
* libswresample5 7.1.4-3.1
* libswscale8 7.1.4-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-30997.html



openSUSE-SU-2026:11007-1: moderate: ansible-core-2.21.0-3.1 on GA media


# ansible-core-2.21.0-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11007-1
Rating: moderate

Cross-References:

* CVE-2026-11332

CVSS scores:

* CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the ansible-core-2.21.0-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ansible-core 2.21.0-3.1
* ansible-test 2.21.0-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-11332.html



openSUSE-SU-2026:11001-1: moderate: postgresql-jdbc-42.7.11-1.1 on GA media


# postgresql-jdbc-42.7.11-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11001-1
Rating: moderate

Cross-References:

* CVE-2026-42198

CVSS scores:

* CVE-2026-42198 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the postgresql-jdbc-42.7.11-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* postgresql-jdbc 42.7.11-1.1
* postgresql-jdbc-javadoc 42.7.11-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-42198.html



openSUSE-SU-2026:11006-1: moderate: tmux-3.6b-2.1 on GA media


# tmux-3.6b-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11006-1
Rating: moderate

Cross-References:

* CVE-2026-11623

CVSS scores:

* CVE-2026-11623 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11623 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the tmux-3.6b-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* tmux 3.6b-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-11623.html