SUSE 5715 Published by

SUSE published a batch of security updates for openSUSE and SUSE Linux Enterprise distributions, identifying flaws in packages ranging from the Linux Kernel and Chromium to LibreOffice and ImageMagick. Administrators should prioritize the important advisories affecting sssd, libreoffice, libkrun, go1.25-openssl, aws-nitro-enclaves-cli, python-aiohttp, vim, opam, chromium, and the Linux Kernel. Moderate-severity fixes are also available for beets, nghttp2, python-tornado6, php7, avahi, kubevirt container disk, acl, iscsiuio, libsoup, libgit2, and MozillaFirefox.

openSUSE-SU-2026:21383-1: moderate: Security update for beets
openSUSE-SU-2026:21382-1: important: Security update for chromium
openSUSE-SU-2026:21380-1: important: Security update for opam
openSUSE-SU-2026:21372-1: important: Security update for python-aiohttp
openSUSE-SU-2026:21374-1: important: Security update for vim
openSUSE-SU-2026:11317-1: moderate: iscsiuio-0.7.8.8-112.1 on GA media
openSUSE-SU-2026:11316-1: moderate: libsoup-3_0-0-3.6.6-7.1 on GA media
openSUSE-SU-2026:11315-1: moderate: libgit2-1_9-1.9.6-1.1 on GA media
openSUSE-SU-2026:11311-1: moderate: MozillaFirefox-152.0.6-1.1 on GA media
openSUSE-SU-2026:11313-1: moderate: avahi-0.8-45.1 on GA media
openSUSE-SU-2026:11314-1: moderate: kubevirt1.8-container-disk-1.8.4-2.1 on GA media
openSUSE-SU-2026:11312-1: moderate: acl-2.4.0-1.1 on GA media
openSUSE-SU-2026:11310-1: moderate: ImageMagick-7.1.2.27-3.1 on GA media
SUSE-SU-2026:3139-1: important: Security update for sssd
SUSE-SU-2026:3140-1: important: Security update for libreoffice
openSUSE-SU-2026:0255-1: important: Security update for libkrun
SUSE-SU-2026:3151-1: important: Security update for go1.25-openssl
SUSE-SU-2026:3152-1: important: Security update for aws-nitro-enclaves-cli
SUSE-SU-2026:3153-1: moderate: Security update for nghttp2
SUSE-SU-2026:3155-1: moderate: Security update for python-tornado6
SUSE-SU-2026:3156-1: important: Security update for the Linux Kernel
SUSE-SU-2026:3165-1: moderate: Security update for php7




openSUSE-SU-2026:21383-1: moderate: Security update for beets


openSUSE security update: security update for beets
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21383-1
Rating: moderate
References:

* bsc#1263988

Cross-References:

* CVE-2026-42052

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for beets fixes the following issues:

Changes in beets:

- CVE-2026-42052: Prior to version 2.10.0, the bundled web UI uses Underscore
template interpolation mode for untrusted metadata fields. (boo#1263988)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-434=1

Package List:

- openSUSE Leap 16.0:

beets-2.2.0-bp160.2.1

References:

* https://www.suse.com/security/cve/CVE-2026-42052.html



openSUSE-SU-2026:21382-1: important: Security update for chromium


openSUSE security update: security update for chromium
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21382-1
Rating: important
References:

* bsc#1271656

Cross-References:

* CVE-2026-15899
* CVE-2026-15900
* CVE-2026-15901
* CVE-2026-15902
* CVE-2026-15903
* CVE-2026-15904
* CVE-2026-15905

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 7 vulnerabilities and has one bug fix can now be installed.

Description:

This update for chromium fixes the following issues:

Changes in chromium:

- Chromium 150.0.7871.128 (boo#1271656):
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-433=1

Package List:

- openSUSE Leap 16.0:

chromedriver-150.0.7871.128-bp160.1.1
chromium-150.0.7871.128-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-15899.html
* https://www.suse.com/security/cve/CVE-2026-15900.html
* https://www.suse.com/security/cve/CVE-2026-15901.html
* https://www.suse.com/security/cve/CVE-2026-15902.html
* https://www.suse.com/security/cve/CVE-2026-15903.html
* https://www.suse.com/security/cve/CVE-2026-15904.html
* https://www.suse.com/security/cve/CVE-2026-15905.html



openSUSE-SU-2026:21380-1: important: Security update for opam


openSUSE security update: security update for opam
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21380-1
Rating: important
References:

* bsc#1262281

Cross-References:

* CVE-2026-41082
* CVE-2026-57825

CVSS scores:

* CVE-2026-41082 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-41082 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 2 vulnerabilities and has one bug fix can now be installed.

Description:

This update for opam fixes the following issues:

Changes in opam:

- Update to version 2.5.2 (CVE-2026-57825)
see included CHANGES file for details

- Update to version 2.5.1 (CVE-2026-41082 bsc#1262281)
see included CHANGES file for details

- Update to version 2.5.0
see included CHANGES file for details

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-431=1

Package List:

- openSUSE Leap 16.0:

opam-2.5.2-bp160.1.1
opam-devel-2.5.2-bp160.1.1
opam-installer-2.5.2-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-41082.html
* https://www.suse.com/security/cve/CVE-2026-57825.html



openSUSE-SU-2026:21372-1: important: Security update for python-aiohttp


openSUSE security update: security update for python-aiohttp
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21372-1
Rating: important
References:

* bsc#1268398
* bsc#1268543
* bsc#1268544
* bsc#1268549
* bsc#1268556
* bsc#1268559
* bsc#1268560
* bsc#1268561

Cross-References:

* CVE-2026-50269
* CVE-2026-54273
* CVE-2026-54274
* CVE-2026-54275
* CVE-2026-54277
* CVE-2026-54278
* CVE-2026-54279
* CVE-2026-54280

CVSS scores:

* CVE-2026-50269 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-54273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54274 ( SUSE ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
* CVE-2026-54275 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-54277 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54278 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54278 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54279 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-54280 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 8 vulnerabilities and has 8 bug fixes can now be installed.

Description:

This update for python-aiohttp fixes the following issues

- CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers
(bsc#1268398).
- CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption
(bsc#1268543).
- CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive
resource consumption (bsc#1268544).
- CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549).
- CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource
consumption (bsc#1268556).
- CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS
(bsc#1268559).
- CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560).
- CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and
can cause resource starvation (bsc#1268561).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1281=1

Package List:

- openSUSE Leap 16.0:

python313-aiohttp-3.11.16-160000.6.1

References:

* https://www.suse.com/security/cve/CVE-2026-50269.html
* https://www.suse.com/security/cve/CVE-2026-54273.html
* https://www.suse.com/security/cve/CVE-2026-54274.html
* https://www.suse.com/security/cve/CVE-2026-54275.html
* https://www.suse.com/security/cve/CVE-2026-54277.html
* https://www.suse.com/security/cve/CVE-2026-54278.html
* https://www.suse.com/security/cve/CVE-2026-54279.html
* https://www.suse.com/security/cve/CVE-2026-54280.html



openSUSE-SU-2026:21374-1: important: Security update for vim


openSUSE security update: security update for vim
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21374-1
Rating: important
References:

* bsc#1271193
* bsc#1271194
* bsc#1271195

Cross-References:

* CVE-2026-59856
* CVE-2026-59857
* CVE-2026-59858

CVSS scores:

* CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.

Description:

This update for vim fixes the following issues:

Update to version 9.2.0780.

Security issues fixed:

- CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194).
- CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195).
- CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193).

Other updates and bugfixes:

- Version 9.2.0780 changelog:
* filetype detect missing from completion (9.2.0726).
* popup images not rendered correctly when unfocused (9.2.0727).
* filetype: supertux info pattern is relative to current dir
(9.2.0728).
* % skips parens on continued quoted lines (9.2.0729).
* GTK4 GUI tabline is not updated (9.2.0730).
* GTK4 GUI scrollbar size not updated when restoring a session
(9.2.0731).
* session: terminal restored using absolute columns/rows (9.2.0732).
* GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).
* function pointer passed to STRNCMP() instead of a length
(9.2.0734).
* tests: comment test can be improved (9.2.0737).
* completion: 'autocompletedelay' blocks the main loop and drops
autocommands (9.2.0739).
* GTK4: scrollbar wrongly displayed (9.2.0740).
* complete_check() does not return TRUE for mapped input (9.2.0741).
* filetype: SSH keys and related filetypes not recognized (9.2.0742).
* string macros silently accept a size of the wrong type (9.2.0743).
* popup_atcursor() closes immediately on white space (9.2.0744).
* cscope: connection leak when growing the array fails (9.2.0747).
* 'autocompletedelay' interferes with CTRL-G U (9.2.0748).
* 'autocompletedelay' interferes with i_CTRL-K (9.2.0749).
* completion: 'autocompletedelay' deferral leaks state (9.2.0750).
* GTK3 GUI is slow under Wayland (9.2.0751).
* GTK4: drag-and-drop does not support HTML (9.2.0752).
* GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).
* repeated completion length lookup in search_for_exact_line
(9.2.0754).
* 'autocomplete' behaves inconsistently when recording (9.2.0755).
* session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).
* tests: test_popupwin fails with zsh because of the prompt
(9.2.0757).
* pum: no opacity when background not set for Popup menu group
(9.2.0758).
* some code for 'autocompletedelay' is no longer needed (9.2.0759).
* compiler warning for using potentially uninitialized var
(9.2.0760).
* runtime(netrw): Unix: unable to open '\' file (9.2.0761).
* duplicated sub-option name check in :set completion (9.2.0762).
* tests: style issue in test_plugin_netrw (9.2.0763).
* compiler warning about unused function (9.2.0764).
* popup: opacity popup over a terminal is not cleared when moved
(9.2.0765).
* quick_tab entries for empty letters point to the wrong index
(9.2.0766).
* legacy/vim9cmd modifiers do not set script version for options
values (9.2.0767).
* legacy/vim9cmd modifiers are not exclusive (9.2.0768).
* conversion to utf-16be using iconv is inconsistent (9.2.0769).
* dict_add_dict() has inconsistent ownership on failure (9.2.0770).
* dict_add_list() has inconsistent ownership on failure (9.2.0771).
* Vim9: null dereference inside alloc_type() (9.2.0772).
* memory leak in evalfunc.c on alloc failure (9.2.0773).
* memory leak in f_getscriptinfo() on alloc failure (9.2.0774).
* memory leak in highlight_get_info() on alloc failure (9.2.0775).
* memory leak in sign_getlist() on alloc failure (9.2.0776).
* memory leak in add_defer() on alloc failure (9.2.0777).
* memory leak in compile_dict() on alloc failure (9.2.0778).
* memory leak in type_name_func() on alloc failure (9.2.0779).
* memory leak in evalvars.c on alloc failure (9.2.0780).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1283=1

Package List:

- openSUSE Leap 16.0:

gvim-9.2.0780-160000.1.1
vim-9.2.0780-160000.1.1
vim-data-9.2.0780-160000.1.1
vim-data-common-9.2.0780-160000.1.1
vim-small-9.2.0780-160000.1.1
xxd-9.2.0780-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-59856.html
* https://www.suse.com/security/cve/CVE-2026-59857.html
* https://www.suse.com/security/cve/CVE-2026-59858.html



openSUSE-SU-2026:11317-1: moderate: iscsiuio-0.7.8.8-112.1 on GA media


# iscsiuio-0.7.8.8-112.1 on GA media

Announcement ID: openSUSE-SU-2026:11317-1
Rating: moderate

Cross-References:

* CVE-2026-44943

CVSS scores:

* CVE-2026-44943 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-44943 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the iscsiuio-0.7.8.8-112.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* iscsiuio 0.7.8.8-112.1
* libopeniscsiusr0 0.2.0-112.1
* open-iscsi 2.1.12-112.1
* open-iscsi-devel 2.1.12-112.1

## References:

* https://www.suse.com/security/cve/CVE-2026-44943.html



openSUSE-SU-2026:11316-1: moderate: libsoup-3_0-0-3.6.6-7.1 on GA media


# libsoup-3_0-0-3.6.6-7.1 on GA media

Announcement ID: openSUSE-SU-2026:11316-1
Rating: moderate

Cross-References:

* CVE-2026-12478

CVSS scores:

* CVE-2026-12478 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-12478 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libsoup-3_0-0-3.6.6-7.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libsoup-3_0-0 3.6.6-7.1
* libsoup-3_0-0-32bit 3.6.6-7.1
* libsoup-devel 3.6.6-7.1
* libsoup-devel-32bit 3.6.6-7.1
* libsoup-lang 3.6.6-7.1
* typelib-1_0-Soup-3_0 3.6.6-7.1

## References:

* https://www.suse.com/security/cve/CVE-2026-12478.html



openSUSE-SU-2026:11315-1: moderate: libgit2-1_9-1.9.6-1.1 on GA media


# libgit2-1_9-1.9.6-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11315-1
Rating: moderate

Cross-References:

* CVE-2026-53583
* CVE-2026-53584
* CVE-2026-53585
* CVE-2026-53586
* CVE-2026-53587

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libgit2-1_9-1.9.6-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libgit2-1_9 1.9.6-1.1
* libgit2-devel 1.9.6-1.1
* libgit2-tools 1.9.6-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-53583.html
* https://www.suse.com/security/cve/CVE-2026-53584.html
* https://www.suse.com/security/cve/CVE-2026-53585.html
* https://www.suse.com/security/cve/CVE-2026-53586.html
* https://www.suse.com/security/cve/CVE-2026-53587.html



openSUSE-SU-2026:11311-1: moderate: MozillaFirefox-152.0.6-1.1 on GA media


# MozillaFirefox-152.0.6-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11311-1
Rating: moderate

Cross-References:

* CVE-2026-15718
* CVE-2026-15719

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the MozillaFirefox-152.0.6-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* MozillaFirefox 152.0.6-1.1
* MozillaFirefox-branding-upstream 152.0.6-1.1
* MozillaFirefox-devel 152.0.6-1.1
* MozillaFirefox-translations-common 152.0.6-1.1
* MozillaFirefox-translations-other 152.0.6-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15718.html
* https://www.suse.com/security/cve/CVE-2026-15719.html



openSUSE-SU-2026:11313-1: moderate: avahi-0.8-45.1 on GA media


# avahi-0.8-45.1 on GA media

Announcement ID: openSUSE-SU-2026:11313-1
Rating: moderate

Cross-References:

* CVE-2025-59529

CVSS scores:

* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the avahi-0.8-45.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* avahi 0.8-45.1
* avahi-autoipd 0.8-45.1
* avahi-compat-howl-devel 0.8-45.1
* avahi-compat-mDNSResponder-devel 0.8-45.1
* avahi-lang 0.8-45.1
* avahi-utils 0.8-45.1
* libavahi-client3 0.8-45.1
* libavahi-client3-32bit 0.8-45.1
* libavahi-common3 0.8-45.1
* libavahi-common3-32bit 0.8-45.1
* libavahi-core7 0.8-45.1
* libavahi-devel 0.8-45.1
* libavahi-libevent1 0.8-45.1
* libdns_sd 0.8-45.1
* libdns_sd-32bit 0.8-45.1
* libhowl0 0.8-45.1
* python313-avahi 0.8-45.1
* python314-avahi 0.8-45.1

## References:

* https://www.suse.com/security/cve/CVE-2025-59529.html



openSUSE-SU-2026:11314-1: moderate: kubevirt1.8-container-disk-1.8.4-2.1 on GA media


# kubevirt1.8-container-disk-1.8.4-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11314-1
Rating: moderate

Cross-References:

* CVE-2026-27136
* CVE-2026-33814
* CVE-2026-39821
* CVE-2026-39827
* CVE-2026-39828
* CVE-2026-39832
* CVE-2026-42508

CVSS scores:

* CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
* CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 7 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the kubevirt1.8-container-disk-1.8.4-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* kubevirt1.8-container-disk 1.8.4-2.1
* kubevirt1.8-manifests 1.8.4-2.1
* kubevirt1.8-pr-helper-conf 1.8.4-2.1
* kubevirt1.8-sidecar-shim 1.8.4-2.1
* kubevirt1.8-tests 1.8.4-2.1
* kubevirt1.8-virt-api 1.8.4-2.1
* kubevirt1.8-virt-controller 1.8.4-2.1
* kubevirt1.8-virt-exportproxy 1.8.4-2.1
* kubevirt1.8-virt-exportserver 1.8.4-2.1
* kubevirt1.8-virt-handler 1.8.4-2.1
* kubevirt1.8-virt-launcher 1.8.4-2.1
* kubevirt1.8-virt-operator 1.8.4-2.1
* kubevirt1.8-virt-synchronization-controller 1.8.4-2.1
* kubevirt1.8-virtctl 1.8.4-2.1
* obs-service-kubevirt1.8_containers_meta 1.8.4-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-27136.html
* https://www.suse.com/security/cve/CVE-2026-33814.html
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-39827.html
* https://www.suse.com/security/cve/CVE-2026-39828.html
* https://www.suse.com/security/cve/CVE-2026-39832.html
* https://www.suse.com/security/cve/CVE-2026-42508.html



openSUSE-SU-2026:11312-1: moderate: acl-2.4.0-1.1 on GA media


# acl-2.4.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11312-1
Rating: moderate

Cross-References:

* CVE-2026-54369
* CVE-2026-54370
* CVE-2026-54371

CVSS scores:

* CVE-2026-54369 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-54369 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-54370 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-54370 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-54371 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-54371 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the acl-2.4.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* acl 2.4.0-1.1
* libacl-devel 2.4.0-1.1
* libacl-devel-32bit 2.4.0-1.1
* libacl1 2.4.0-1.1
* libacl1-32bit 2.4.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-54369.html
* https://www.suse.com/security/cve/CVE-2026-54370.html
* https://www.suse.com/security/cve/CVE-2026-54371.html



openSUSE-SU-2026:11310-1: moderate: ImageMagick-7.1.2.27-3.1 on GA media


# ImageMagick-7.1.2.27-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11310-1
Rating: moderate

Cross-References:

* CVE-2026-56375
* CVE-2026-61464
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61871
* CVE-2026-61872

CVSS scores:

* CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( SUSE ): 1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61871 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61871 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 14 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ImageMagick-7.1.2.27-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ImageMagick 7.1.2.27-3.1
* ImageMagick-config-7-SUSE 7.1.2.27-3.1
* ImageMagick-devel 7.1.2.27-3.1
* ImageMagick-devel-32bit 7.1.2.27-3.1
* ImageMagick-doc 7.1.2.27-3.1
* ImageMagick-extra 7.1.2.27-3.1
* libMagick++-7_Q16HDRI5 7.1.2.27-3.1
* libMagick++-7_Q16HDRI5-32bit 7.1.2.27-3.1
* libMagick++-devel 7.1.2.27-3.1
* libMagick++-devel-32bit 7.1.2.27-3.1
* libMagickCore-7_Q16HDRI10 7.1.2.27-3.1
* libMagickCore-7_Q16HDRI10-32bit 7.1.2.27-3.1
* libMagickWand-7_Q16HDRI10 7.1.2.27-3.1
* libMagickWand-7_Q16HDRI10-32bit 7.1.2.27-3.1
* perl-PerlMagick 7.1.2.27-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
* https://www.suse.com/security/cve/CVE-2026-61860.html
* https://www.suse.com/security/cve/CVE-2026-61862.html
* https://www.suse.com/security/cve/CVE-2026-61863.html
* https://www.suse.com/security/cve/CVE-2026-61864.html
* https://www.suse.com/security/cve/CVE-2026-61865.html
* https://www.suse.com/security/cve/CVE-2026-61866.html
* https://www.suse.com/security/cve/CVE-2026-61867.html
* https://www.suse.com/security/cve/CVE-2026-61868.html
* https://www.suse.com/security/cve/CVE-2026-61869.html
* https://www.suse.com/security/cve/CVE-2026-61871.html
* https://www.suse.com/security/cve/CVE-2026-61872.html



SUSE-SU-2026:3139-1: important: Security update for sssd


# Security update for sssd

Announcement ID: SUSE-SU-2026:3139-1
Release Date: 2026-07-20T17:56:06Z
Rating: important
References:

* bsc#1246196
* bsc#1270708
* bsc#1270709

Cross-References:

* CVE-2026-14474
* CVE-2026-14476

CVSS scores:

* CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves two vulnerabilities and has one security fix can now be
installed.

## Description:

This update for sssd fixes the following issues

* CVE-2026-14474: sudo LDAP provider searches entire directory tree for
sudoRole objects by default, enabling privilege escalation (bsc#1270709).
* CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath
allows Kerberos authentication bypass (bsc#1270708).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3139=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3139=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3139=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3139=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3139=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3139=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3139=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3139=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3139=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* sssd-debugsource-2.5.2-150400.4.45.1
* libnfsidmap-sss-debuginfo-2.5.2-150400.4.45.1
* sssd-ad-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-kcm-debuginfo-2.5.2-150400.4.45.1
* python3-sss_nss_idmap-2.5.2-150400.4.45.1
* sssd-proxy-2.5.2-150400.4.45.1
* sssd-krb5-debuginfo-2.5.2-150400.4.45.1
* python3-ipa_hbac-debuginfo-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-2.5.2-150400.4.45.1
* libsss_idmap-devel-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-kcm-2.5.2-150400.4.45.1
* libsss_nss_idmap-devel-2.5.2-150400.4.45.1
* python3-sss-murmur-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* python3-ipa_hbac-2.5.2-150400.4.45.1
* sssd-dbus-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* libipa_hbac-devel-2.5.2-150400.4.45.1
* python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.45.1
* libnfsidmap-sss-2.5.2-150400.4.45.1
* sssd-ipa-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-2.5.2-150400.4.45.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp-devel-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* python3-sss-murmur-2.5.2-150400.4.45.1
* sssd-tools-debuginfo-2.5.2-150400.4.45.1
* python3-sssd-config-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-2.5.2-150400.4.45.1
* sssd-dbus-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-tools-2.5.2-150400.4.45.1
* python3-sssd-config-2.5.2-150400.4.45.1
* sssd-winbind-idmap-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-ad-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* openSUSE Leap 15.4 (x86_64)
* sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1
* sssd-common-32bit-2.5.2-150400.4.45.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* sssd-common-64bit-2.5.2-150400.4.45.1
* sssd-common-64bit-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* sssd-debugsource-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-kcm-debuginfo-2.5.2-150400.4.45.1
* sssd-ad-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-2.5.2-150400.4.45.1
* sssd-krb5-debuginfo-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-2.5.2-150400.4.45.1
* libsss_idmap-devel-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-kcm-2.5.2-150400.4.45.1
* libsss_simpleifp0-2.5.2-150400.4.45.1
* libsss_nss_idmap-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-dbus-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* libipa_hbac-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-2.5.2-150400.4.45.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp-devel-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* sssd-tools-debuginfo-2.5.2-150400.4.45.1
* python3-sssd-config-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-2.5.2-150400.4.45.1
* sssd-dbus-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* python3-sssd-config-2.5.2-150400.4.45.1
* sssd-winbind-idmap-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-ad-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap-devel-2.5.2-150400.4.45.1
* sssd-tools-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1
* sssd-common-32bit-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* sssd-debugsource-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-ad-debuginfo-2.5.2-150400.4.45.1
* sssd-kcm-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-2.5.2-150400.4.45.1
* sssd-krb5-debuginfo-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-2.5.2-150400.4.45.1
* libsss_idmap-devel-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-kcm-2.5.2-150400.4.45.1
* libsss_simpleifp0-2.5.2-150400.4.45.1
* libsss_nss_idmap-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* sssd-dbus-2.5.2-150400.4.45.1
* libipa_hbac-devel-2.5.2-150400.4.45.1
* sssd-ipa-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-2.5.2-150400.4.45.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp-devel-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* sssd-tools-debuginfo-2.5.2-150400.4.45.1
* python3-sssd-config-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-2.5.2-150400.4.45.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.45.1
* sssd-dbus-debuginfo-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-tools-2.5.2-150400.4.45.1
* python3-sssd-config-2.5.2-150400.4.45.1
* sssd-winbind-idmap-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-ad-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1
* sssd-common-32bit-2.5.2-150400.4.45.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-kcm-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-ad-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-2.5.2-150400.4.45.1
* sssd-krb5-debuginfo-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-2.5.2-150400.4.45.1
* libsss_idmap-devel-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-kcm-2.5.2-150400.4.45.1
* libsss_nss_idmap-devel-2.5.2-150400.4.45.1
* libsss_simpleifp0-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-dbus-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* libipa_hbac-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-2.5.2-150400.4.45.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp-devel-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* sssd-tools-debuginfo-2.5.2-150400.4.45.1
* python3-sssd-config-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-2.5.2-150400.4.45.1
* sssd-dbus-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* python3-sssd-config-2.5.2-150400.4.45.1
* sssd-winbind-idmap-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-ad-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap-devel-2.5.2-150400.4.45.1
* sssd-tools-2.5.2-150400.4.45.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1
* sssd-common-32bit-2.5.2-150400.4.45.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-kcm-debuginfo-2.5.2-150400.4.45.1
* sssd-ad-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-proxy-2.5.2-150400.4.45.1
* sssd-krb5-debuginfo-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-2.5.2-150400.4.45.1
* libsss_idmap-devel-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-kcm-2.5.2-150400.4.45.1
* libsss_nss_idmap-devel-2.5.2-150400.4.45.1
* libsss_simpleifp0-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-dbus-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* libipa_hbac-devel-2.5.2-150400.4.45.1
* sssd-ipa-debuginfo-2.5.2-150400.4.45.1
* sssd-proxy-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.45.1
* sssd-ipa-2.5.2-150400.4.45.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.45.1
* libsss_simpleifp-devel-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* sssd-tools-debuginfo-2.5.2-150400.4.45.1
* python3-sssd-config-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-2.5.2-150400.4.45.1
* sssd-dbus-debuginfo-2.5.2-150400.4.45.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.45.1
* sssd-tools-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* python3-sssd-config-2.5.2-150400.4.45.1
* sssd-winbind-idmap-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-ad-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap-devel-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* sssd-common-32bit-debuginfo-2.5.2-150400.4.45.1
* sssd-common-32bit-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.45.1
* sssd-debugsource-2.5.2-150400.4.45.1
* sssd-ldap-2.5.2-150400.4.45.1
* libsss_idmap0-2.5.2-150400.4.45.1
* sssd-krb5-common-2.5.2-150400.4.45.1
* sssd-common-2.5.2-150400.4.45.1
* sssd-ldap-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-2.5.2-150400.4.45.1
* sssd-2.5.2-150400.4.45.1
* sssd-common-debuginfo-2.5.2-150400.4.45.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.45.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.45.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.45.1

## References:

* https://www.suse.com/security/cve/CVE-2026-14474.html
* https://www.suse.com/security/cve/CVE-2026-14476.html
* https://bugzilla.suse.com/show_bug.cgi?id46196
* https://bugzilla.suse.com/show_bug.cgi?id70708
* https://bugzilla.suse.com/show_bug.cgi?id70709



SUSE-SU-2026:3140-1: important: Security update for libreoffice


# Security update for libreoffice

Announcement ID: SUSE-SU-2026:3140-1
Release Date: 2026-07-20T18:01:17Z
Rating: important
References:

* bsc#1264357
* bsc#1267735
* bsc#1268494
* bsc#1268497
* bsc#1268504
* bsc#1268522
* bsc#1268527
* bsc#1268528
* bsc#1268529
* jsc#PED-16098

Cross-References:

* CVE-2026-4430
* CVE-2026-50593
* CVE-2026-6039
* CVE-2026-6040
* CVE-2026-6045
* CVE-2026-6047
* CVE-2026-8356
* CVE-2026-8357
* CVE-2026-8358

CVSS scores:

* CVE-2026-4430 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-4430 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-4430 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4430 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-50593 ( SUSE ): 4.6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-50593 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-50593 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H
* CVE-2026-6039 ( SUSE ): 6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-6039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-6039 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6040 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-6040 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-6040 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6040 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-6045 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-6045 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-6045 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6047 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-6047 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-6047 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8356 ( SUSE ): 6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8356 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-8356 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8357 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8357 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-8357 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8357 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-8358 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8358 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-8358 ( NVD ): 5.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Linux Enterprise Workstation Extension 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves nine vulnerabilities and contains one feature can now be
installed.

## Description:

This update for libreoffice fixes the following issues:

Update to LibreOffice 26.2.5.1.

Security issues fixed:

* CVE-2026-4430: out-of-bounds write via crafted OOXML documents with
mismatched encryption salt parameters (bsc#1264357).
* CVE-2026-6039: denial of service via specially crafted DXF polyline import
(bsc#1268494).
* CVE-2026-6040: heap use-after-free when importing the blank-width characters
of an ODF number format (bsc#1268527).
* CVE-2026-6045: heap buffer overflow via crafted EMF+ graphics import
(bsc#1268497).
* CVE-2026-6047: denial of service via heap buffer overflow in OOXML document
processing (bsc#1268504).
* CVE-2026-8356: denial of service via a specially crafted PPT file
(bsc#1268522).
* CVE-2026-8357: heap buffer overflow in Calc formula compilation
(bsc#1268528).
* CVE-2026-8358: heap buffer overflow in spreadsheet tracked-changes import
(bsc#1268529).
* CVE-2026-50593: graphite2: out-of-bounds write via Graphite actions
(bsc#1267735).

Other updates and bugfixes:

* Update to LibreOffice 26.2.5.1.
* Update bundled dependencies:
* `fontconfig` 2.17.1 -> 2.18.0
* `graphite2-minimal` 1.3.14 -> 1.3.15
* `libcmis` 0.6.2 -> 0.6.3
* `libgpg-error` 1.59 -> 1.61
* `lxml` 6.1.0 -> 6.1.1
* `md4c` 0.5.2 -> 0.5.3
* `poppler` 26.04.0 -> 26.06.0
* `sqlite-amalgamation` 3530000 -> 3530100
* `xmlsec1` 1.3.9 -> 1.3.11
* Update to LibreOffice 26.2.3.2 (jsc#PED-16098).
* Upgraded dependencies:
* `boost`: 1_88_0 -> 1_89_0
* `freetype`: 2.14.1 -> 2.14.3
* `harfbuzz`: 12.3.0 -> 12.3.2
* `icu4c`: 77_1 -> 78.3
* `libgpg-error`: 1.56 -> 1.59
* `liborcus`: 0.20.1 -> 0.21.0
* `pdfium`: 7012 -> 7471
* `poppler`: 25.12.0 -> 26.04.0
* `skia`: m136 -> m142
* New bundled sources:
* `afdko` 4.0.3
* `antlr4-cpp-runtime` 4.13.2
* `fast_float` 8.2.2
* `libffi` 3.5.2
* `lxml` 6.1.0
* `md4c` 0.5.2
* `meson` 1.8.3
* `Python` 3.12.13
* `sqlite` 3530000
* `xmlsec1` 1.3.9
* `xz` 5.8.3
* Add `patch`, required to build the bundled Python on all architectures.
* Bundling a specific Python is now required as the one we ship (3.6) is too
old to build `harfbuzz`.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3140=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3140=1

* SUSE Linux Enterprise Workstation Extension 15 SP7
zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3140=1

## Package List:

* SUSE Package Hub 15 15-SP7 (noarch)
* libreoffice-l10n-sa_IN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ne-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-et-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sq-26.2.5.1-150500.20.37.1
* libreoffice-l10n-as-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ug-26.2.5.1-150500.20.37.1
* libreoffice-l10n-om-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kab-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sd-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kok-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en_ZA-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-brx-26.2.5.1-150500.20.37.1
* libreoffice-l10n-be-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tt-26.2.5.1-150500.20.37.1
* libreoffice-branding-upstream-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ar-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-af-26.2.5.1-150500.20.37.1
* libreoffice-l10n-szl-26.2.5.1-150500.20.37.1
* libreoffice-icon-themes-26.2.5.1-150500.20.37.1
* libreoffice-l10n-oc-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sid-26.2.5.1-150500.20.37.1
* libreoffice-l10n-he-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-vec-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ga-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ks-26.2.5.1-150500.20.37.1
* libreoffice-l10n-km-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ka-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dgo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-el-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ve-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mr-26.2.5.1-150500.20.37.1
* libreoffice-gdb-pretty-printers-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-st-26.2.5.1-150500.20.37.1
* libreoffice-l10n-th-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-xh-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ro-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hsb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-am-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ml-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-my-26.2.5.1-150500.20.37.1
* libreoffice-l10n-da-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gu-26.2.5.1-150500.20.37.1
* libreoffice-glade-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dsb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ss-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lt-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mai-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fur-26.2.5.1-150500.20.37.1
* libreoffice-l10n-de-26.2.5.1-150500.20.37.1
* libreoffice-l10n-or-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ta-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ru-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bg-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dz-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mni-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en_GB-26.2.5.1-150500.20.37.1
* libreoffice-l10n-vi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bn_IN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gug-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-es-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-is-26.2.5.1-150500.20.37.1
* libreoffice-l10n-it-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ca_valencia-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sw_TZ-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ts-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ja-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-si-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ast-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kmr_Latn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ca-26.2.5.1-150500.20.37.1
* libreoffice-l10n-te-26.2.5.1-150500.20.37.1
* libreoffice-l10n-uz-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nso-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gd-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-id-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-rw-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ko-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tg-26.2.5.1-150500.20.37.1
* libreoffice-l10n-br-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cs-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sat-26.2.5.1-150500.20.37.1
* libreoffice-l10n-uk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bs-26.2.5.1-150500.20.37.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le)
* libreoffice-base-26.2.5.1-150500.20.37.1
* libreoffice-writer-extensions-26.2.5.1-150500.20.37.1
* libreoffice-sdk-26.2.5.1-150500.20.37.1
* libreoffice-mailmerge-26.2.5.1-150500.20.37.1
* libreoffice-calc-26.2.5.1-150500.20.37.1
* libreoffice-math-26.2.5.1-150500.20.37.1
* libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-officebean-26.2.5.1-150500.20.37.1
* libreofficekit-devel-26.2.5.1-150500.20.37.1
* libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-draw-26.2.5.1-150500.20.37.1
* libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-sdk-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-26.2.5.1-150500.20.37.1
* libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-librelogo-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1
* libreofficekit-26.2.5.1-150500.20.37.1
* libreoffice-filters-optional-26.2.5.1-150500.20.37.1
* libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-extensions-26.2.5.1-150500.20.37.1
* libreoffice-impress-26.2.5.1-150500.20.37.1
* libreoffice-qt5-26.2.5.1-150500.20.37.1
* libreoffice-sdk-doc-26.2.5.1-150500.20.37.1
* libreoffice-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-debugsource-26.2.5.1-150500.20.37.1
* libreoffice-gnome-26.2.5.1-150500.20.37.1
* libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-26.2.5.1-150500.20.37.1
* libreoffice-qt5-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-writer-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1
* libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le x86_64)
* libreoffice-base-drivers-firebird-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-firebird-26.2.5.1-150500.20.37.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch)
* libreoffice-l10n-ja-26.2.5.1-150500.20.37.1
* libreoffice-l10n-da-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-si-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-et-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ca-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ga-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-as-26.2.5.1-150500.20.37.1
* libreoffice-l10n-te-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ts-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ss-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nso-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lt-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mai-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fur-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-or-26.2.5.1-150500.20.37.1
* libreoffice-l10n-de-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ta-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bg-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ru-26.2.5.1-150500.20.37.1
* libreoffice-l10n-el-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ve-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dz-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ko-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-br-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cs-26.2.5.1-150500.20.37.1
* libreoffice-l10n-st-26.2.5.1-150500.20.37.1
* libreoffice-l10n-th-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-xh-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en-26.2.5.1-150500.20.37.1
* libreoffice-branding-upstream-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ar-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ro-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-af-26.2.5.1-150500.20.37.1
* libreoffice-icon-themes-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1
* libreoffice-l10n-es-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-it-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-he-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ml-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-uk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hy-26.2.5.1-150500.20.37.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64)
* libreoffice-base-26.2.5.1-150500.20.37.1
* libreoffice-writer-extensions-26.2.5.1-150500.20.37.1
* libreoffice-mailmerge-26.2.5.1-150500.20.37.1
* libreoffice-calc-26.2.5.1-150500.20.37.1
* libreoffice-math-26.2.5.1-150500.20.37.1
* libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-officebean-26.2.5.1-150500.20.37.1
* libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-draw-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-26.2.5.1-150500.20.37.1
* libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1
* libreofficekit-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-filters-optional-26.2.5.1-150500.20.37.1
* libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-extensions-26.2.5.1-150500.20.37.1
* libreoffice-impress-26.2.5.1-150500.20.37.1
* libreoffice-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-debugsource-26.2.5.1-150500.20.37.1
* libreoffice-gnome-26.2.5.1-150500.20.37.1
* libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-26.2.5.1-150500.20.37.1
* libreoffice-writer-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* libreoffice-base-26.2.5.1-150500.20.37.1
* libreoffice-mailmerge-26.2.5.1-150500.20.37.1
* libreoffice-sdk-26.2.5.1-150500.20.37.1
* libreoffice-writer-extensions-26.2.5.1-150500.20.37.1
* libreoffice-calc-26.2.5.1-150500.20.37.1
* libreoffice-math-26.2.5.1-150500.20.37.1
* libreoffice-writer-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-officebean-26.2.5.1-150500.20.37.1
* libreofficekit-devel-26.2.5.1-150500.20.37.1
* libreoffice-officebean-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-draw-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-sdk-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-gnome-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-26.2.5.1-150500.20.37.1
* libreoffice-impress-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-pyuno-26.2.5.1-150500.20.37.1
* libreoffice-librelogo-26.2.5.1-150500.20.37.1
* libreofficekit-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-filters-optional-26.2.5.1-150500.20.37.1
* libreoffice-math-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-calc-extensions-26.2.5.1-150500.20.37.1
* libreoffice-impress-26.2.5.1-150500.20.37.1
* libreoffice-qt5-26.2.5.1-150500.20.37.1
* libreoffice-sdk-doc-26.2.5.1-150500.20.37.1
* libreoffice-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-debugsource-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-firebird-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-base-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-gnome-26.2.5.1-150500.20.37.1
* libreoffice-gtk3-26.2.5.1-150500.20.37.1
* libreoffice-qt5-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-writer-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-postgresql-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-draw-debuginfo-26.2.5.1-150500.20.37.1
* libreoffice-base-drivers-firebird-26.2.5.1-150500.20.37.1
* openSUSE Leap 15.5 (noarch)
* libreoffice-l10n-sa_IN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ne-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-et-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sq-26.2.5.1-150500.20.37.1
* libreoffice-l10n-as-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ug-26.2.5.1-150500.20.37.1
* libreoffice-l10n-om-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kab-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sd-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kok-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en_ZA-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-brx-26.2.5.1-150500.20.37.1
* libreoffice-l10n-be-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tt-26.2.5.1-150500.20.37.1
* libreoffice-branding-upstream-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ar-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-af-26.2.5.1-150500.20.37.1
* libreoffice-icon-themes-26.2.5.1-150500.20.37.1
* libreoffice-l10n-szl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-oc-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sid-26.2.5.1-150500.20.37.1
* libreoffice-l10n-he-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-vec-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ga-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ks-26.2.5.1-150500.20.37.1
* libreoffice-l10n-km-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ka-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dgo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-el-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ve-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mr-26.2.5.1-150500.20.37.1
* libreoffice-gdb-pretty-printers-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-st-26.2.5.1-150500.20.37.1
* libreoffice-l10n-th-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_CN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-xh-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ro-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hsb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-am-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ml-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zu-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-da-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-my-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gu-26.2.5.1-150500.20.37.1
* libreoffice-glade-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gl-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dsb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ss-26.2.5.1-150500.20.37.1
* libreoffice-l10n-or-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mai-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fur-26.2.5.1-150500.20.37.1
* libreoffice-l10n-de-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lt-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ta-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ru-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bg-26.2.5.1-150500.20.37.1
* libreoffice-l10n-eo-26.2.5.1-150500.20.37.1
* libreoffice-l10n-dz-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mni-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ckb-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en_GB-26.2.5.1-150500.20.37.1
* libreoffice-l10n-vi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bn_IN-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gug-26.2.5.1-150500.20.37.1
* libreoffice-l10n-en-26.2.5.1-150500.20.37.1
* libreoffice-l10n-mn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-es-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-is-26.2.5.1-150500.20.37.1
* libreoffice-l10n-it-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ca_valencia-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sw_TZ-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ts-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fy-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ja-26.2.5.1-150500.20.37.1
* libreoffice-l10n-fi-26.2.5.1-150500.20.37.1
* libreoffice-l10n-si-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ast-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kmr_Latn-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ca-26.2.5.1-150500.20.37.1
* libreoffice-l10n-te-26.2.5.1-150500.20.37.1
* libreoffice-l10n-uz-26.2.5.1-150500.20.37.1
* libreoffice-l10n-hr-26.2.5.1-150500.20.37.1
* libreoffice-l10n-nso-26.2.5.1-150500.20.37.1
* libreoffice-l10n-gd-26.2.5.1-150500.20.37.1
* libreoffice-kdeintegration-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-lv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-id-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sv-26.2.5.1-150500.20.37.1
* libreoffice-l10n-rw-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ab-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_BR-26.2.5.1-150500.20.37.1
* libreoffice-l10n-ko-26.2.5.1-150500.20.37.1
* libreoffice-l10n-tg-26.2.5.1-150500.20.37.1
* libreoffice-l10n-br-26.2.5.1-150500.20.37.1
* libreoffice-l10n-cs-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sat_Olck-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pt_PT-26.2.5.1-150500.20.37.1
* libreoffice-l10n-kk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-pa-26.2.5.1-150500.20.37.1
* libreoffice-l10n-sat-26.2.5.1-150500.20.37.1
* libreoffice-l10n-uk-26.2.5.1-150500.20.37.1
* libreoffice-l10n-zh_TW-26.2.5.1-150500.20.37.1
* libreoffice-l10n-bs-26.2.5.1-150500.20.37.1

## References:

* https://www.suse.com/security/cve/CVE-2026-4430.html
* https://www.suse.com/security/cve/CVE-2026-50593.html
* https://www.suse.com/security/cve/CVE-2026-6039.html
* https://www.suse.com/security/cve/CVE-2026-6040.html
* https://www.suse.com/security/cve/CVE-2026-6045.html
* https://www.suse.com/security/cve/CVE-2026-6047.html
* https://www.suse.com/security/cve/CVE-2026-8356.html
* https://www.suse.com/security/cve/CVE-2026-8357.html
* https://www.suse.com/security/cve/CVE-2026-8358.html
* https://bugzilla.suse.com/show_bug.cgi?id64357
* https://bugzilla.suse.com/show_bug.cgi?id67735
* https://bugzilla.suse.com/show_bug.cgi?id68494
* https://bugzilla.suse.com/show_bug.cgi?id68497
* https://bugzilla.suse.com/show_bug.cgi?id68504
* https://bugzilla.suse.com/show_bug.cgi?id68522
* https://bugzilla.suse.com/show_bug.cgi?id68527
* https://bugzilla.suse.com/show_bug.cgi?id68528
* https://bugzilla.suse.com/show_bug.cgi?id68529
* https://jira.suse.com/browse/PED-16098



openSUSE-SU-2026:0255-1: important: Security update for libkrun


openSUSE Security Update: Security update for libkrun
_______________________________

Announcement ID: openSUSE-SU-2026:0255-1
Rating: important
References: #1270198 #1270429 #1270470 #1270582 #1270683
#1270721 #1270831 #1270877
Cross-References: CVE-2025-24898 CVE-2026-41676 CVE-2026-41677
CVE-2026-41678 CVE-2026-41681 CVE-2026-41898
CVE-2026-42327 CVE-2026-44662
CVSS scores:
CVE-2025-24898 (SUSE): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVE-2026-41676 (SUSE): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
CVE-2026-41677 (SUSE): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
CVE-2026-41678 (SUSE): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-41681 (SUSE): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-41898 (SUSE): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-42327 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE-2026-44662 (SUSE): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes 8 vulnerabilities is now available.

Description:

This update for libkrun fixes the following issues:

Update vendored openssl crate to version 0.10.81 to deal with:

CVE-2026-41676 (boo#1270198), CVE-2025-24898 (boo#1270429),
CVE-2026-41677 (boo#1270582), CVE-2026-42327 (boo#1270470), CVE-2026-41678
(boo#1270683), CVE-2026-41898 (boo#1270831), CVE-2026-41681 (boo#1270721),
CVE-2026-44662 (boo#1270877).

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-255=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 x86_64):

libkrun-devel-1.4.10-bp157.2.3.1
libkrun1-1.4.10-bp157.2.3.1

- openSUSE Backports SLE-15-SP7 (x86_64):

libkrun-sev-devel-1.4.10-bp157.2.3.1
libkrun-sev1-1.4.10-bp157.2.3.1

References:

https://www.suse.com/security/cve/CVE-2025-24898.html
https://www.suse.com/security/cve/CVE-2026-41676.html
https://www.suse.com/security/cve/CVE-2026-41677.html
https://www.suse.com/security/cve/CVE-2026-41678.html
https://www.suse.com/security/cve/CVE-2026-41681.html
https://www.suse.com/security/cve/CVE-2026-41898.html
https://www.suse.com/security/cve/CVE-2026-42327.html
https://www.suse.com/security/cve/CVE-2026-44662.html
https://bugzilla.suse.com/1270198
https://bugzilla.suse.com/1270429
https://bugzilla.suse.com/1270470
https://bugzilla.suse.com/1270582
https://bugzilla.suse.com/1270683
https://bugzilla.suse.com/1270721
https://bugzilla.suse.com/1270831
https://bugzilla.suse.com/1270877



SUSE-SU-2026:3151-1: important: Security update for go1.25-openssl


# Security update for go1.25-openssl

Announcement ID: SUSE-SU-2026:3151-1
Release Date: 2026-07-21T12:48:54Z
Rating: important
References:

* bsc#1244485
* bsc#1245878
* bsc#1259264
* bsc#1259265
* bsc#1259268
* bsc#1264394
* bsc#1267442
* bsc#1267444
* bsc#1267450
* bsc#1271014
* bsc#1271015
* jsc#PED-1962
* jsc#SLE-18320

Cross-References:

* CVE-2026-25679
* CVE-2026-27139
* CVE-2026-27142
* CVE-2026-27145
* CVE-2026-39822
* CVE-2026-42504
* CVE-2026-42505
* CVE-2026-42507

CVSS scores:

* CVE-2026-25679 ( SUSE ): 4.6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-27139 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-27142 ( SUSE ): 5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-27145 ( SUSE ): 4.6
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42504 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-42507 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products:

* Development Tools Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves eight vulnerabilities, contains two features and has three
security fixes can now be installed.

## Description:

This update for go1.25-openssl fixes the following issues

* Update to version go1.25.12 (bsc#1244485).
* CVE-2026-25679: net/url: reject IPv6 literal not at start of host
(bsc#1259264).
* CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268).
* CVE-2026-27142: html/template: URLs in meta content attribute actions are
not escaped (bsc#1259265).
* CVE-2026-27145: crypto/x509: split candidate hostname only once
(bsc#1267450).
* CVE-2026-39822: os: Root escape via symlink plus trailing slash
(bsc#1271014).
* CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader
(bsc#1267442).
* CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello
(bsc#1271015).
* CVE-2026-42507: net/textproto: arbitrary input are included in errors
without any escaping (bsc#1267444).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3151=1

* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3151=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3151=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3151=1

## Package List:

* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* go1.25-openssl-1.25.12-150600.13.21.1
* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1
* go1.25-openssl-doc-1.25.12-150600.13.21.1
* go1.25-openssl-race-1.25.12-150600.13.21.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* go1.25-openssl-1.25.12-150600.13.21.1
* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1
* go1.25-openssl-doc-1.25.12-150600.13.21.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* go1.25-openssl-race-1.25.12-150600.13.21.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* go1.25-openssl-1.25.12-150600.13.21.1
* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1
* go1.25-openssl-doc-1.25.12-150600.13.21.1
* go1.25-openssl-race-1.25.12-150600.13.21.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* go1.25-openssl-1.25.12-150600.13.21.1
* go1.25-openssl-debuginfo-1.25.12-150600.13.21.1
* go1.25-openssl-doc-1.25.12-150600.13.21.1
* go1.25-openssl-race-1.25.12-150600.13.21.1

## References:

* https://www.suse.com/security/cve/CVE-2026-25679.html
* https://www.suse.com/security/cve/CVE-2026-27139.html
* https://www.suse.com/security/cve/CVE-2026-27142.html
* https://www.suse.com/security/cve/CVE-2026-27145.html
* https://www.suse.com/security/cve/CVE-2026-39822.html
* https://www.suse.com/security/cve/CVE-2026-42504.html
* https://www.suse.com/security/cve/CVE-2026-42505.html
* https://www.suse.com/security/cve/CVE-2026-42507.html
* https://bugzilla.suse.com/show_bug.cgi?id44485
* https://bugzilla.suse.com/show_bug.cgi?id45878
* https://bugzilla.suse.com/show_bug.cgi?id59264
* https://bugzilla.suse.com/show_bug.cgi?id59265
* https://bugzilla.suse.com/show_bug.cgi?id59268
* https://bugzilla.suse.com/show_bug.cgi?id64394
* https://bugzilla.suse.com/show_bug.cgi?id67442
* https://bugzilla.suse.com/show_bug.cgi?id67444
* https://bugzilla.suse.com/show_bug.cgi?id67450
* https://bugzilla.suse.com/show_bug.cgi?id71014
* https://bugzilla.suse.com/show_bug.cgi?id71015
* https://jira.suse.com/browse/PED-1962
* https://jira.suse.com/browse/SLE-18320



SUSE-SU-2026:3152-1: important: Security update for aws-nitro-enclaves-cli


# Security update for aws-nitro-enclaves-cli

Announcement ID: SUSE-SU-2026:3152-1
Release Date: 2026-07-21T12:51:48Z
Rating: important
References:

* bsc#1270492
* bsc#1270542
* bsc#1270705
* bsc#1270747
* bsc#1270839
* bsc#1270932
* bsc#1270952

Cross-References:

* CVE-2026-41677
* CVE-2026-41678
* CVE-2026-41681
* CVE-2026-41898
* CVE-2026-42327
* CVE-2026-44662
* CVE-2026-45784

CVSS scores:

* CVE-2026-41677 ( SUSE ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
* CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-41677 ( NVD ): 1.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-41678 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41678 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-41681 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-41681 ( NVD ): 8.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41898 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-41898 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-42327 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44662 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-44662 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-45784 ( SUSE ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-45784 ( NVD ): 5.1
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.6
* Public Cloud Module 15-SP6
* Public Cloud Module 15-SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for aws-nitro-enclaves-cli fixes the following issues

* CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when
returning an oversized length (bsc#1270542).
* CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in
`aes::unwrap_key()` (bsc#1270705).
* CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()`
writing past caller buffer with no length check (bsc#1270747).
* CVE-2026-41898: openssl: information leak to network peers due to unchecked
callback-returned length in PSK and cookie generate trampolines
(bsc#1270839).
* CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders`
when processing certificates with non-UTF-8 OCSP URLs (bsc#1270492).
* CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-
wrap-with-padding (bsc#1270932).
* CVE-2026-45784: openssl: out-of-bounds write in
`CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to
incorrectly sized output buffers (bsc#1270952).

Changes for aws-nitro-enclaves-cli:

* Update to version 1.4.5.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3152=1

* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3152=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3152=1

## Package List:

* Public Cloud Module 15-SP7 (aarch64 x86_64)
* aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1
* system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* openSUSE Leap 15.6 (aarch64 x86_64)
* aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1
* system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* Public Cloud Module 15-SP6 (aarch64 x86_64)
* aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-150600.10.12.1
* system-group-ne-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debugsource-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-150600.10.12.1
* aws-nitro-enclaves-cli-debuginfo-1.4.5~git0.18a5f6f-150600.10.12.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html
* https://bugzilla.suse.com/show_bug.cgi?id70492
* https://bugzilla.suse.com/show_bug.cgi?id70542
* https://bugzilla.suse.com/show_bug.cgi?id70705
* https://bugzilla.suse.com/show_bug.cgi?id70747
* https://bugzilla.suse.com/show_bug.cgi?id70839
* https://bugzilla.suse.com/show_bug.cgi?id70932
* https://bugzilla.suse.com/show_bug.cgi?id70952



SUSE-SU-2026:3153-1: moderate: Security update for nghttp2


# Security update for nghttp2

Announcement ID: SUSE-SU-2026:3153-1
Release Date: 2026-07-21T12:54:31Z
Rating: moderate
References:

* bsc#1269489

Cross-References:

* CVE-2026-58055

CVSS scores:

* CVE-2026-58055 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-58055 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for nghttp2 fixes the following issue

* CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling
and cross-client response-queue poisoning (bsc#1269489).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3153=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3153=1

## Package List:

* openSUSE Leap 15.6 (x86_64)
* libnghttp2-14-32bit-1.40.0-150600.25.8.1
* libnghttp2_asio1-32bit-1.40.0-150600.25.8.1
* libnghttp2_asio1-32bit-debuginfo-1.40.0-150600.25.8.1
* libnghttp2-14-32bit-debuginfo-1.40.0-150600.25.8.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nghttp2-1.40.0-150600.25.8.1
* python3-nghttp2-1.40.0-150600.25.8.1
* libnghttp2-14-debuginfo-1.40.0-150600.25.8.1
* nghttp2-debuginfo-1.40.0-150600.25.8.1
* libnghttp2-devel-1.40.0-150600.25.8.1
* libnghttp2_asio1-1.40.0-150600.25.8.1
* libnghttp2-14-1.40.0-150600.25.8.1
* libnghttp2_asio1-debuginfo-1.40.0-150600.25.8.1
* python3-nghttp2-debuginfo-1.40.0-150600.25.8.1
* nghttp2-python-debugsource-1.40.0-150600.25.8.1
* nghttp2-debugsource-1.40.0-150600.25.8.1
* libnghttp2_asio-devel-1.40.0-150600.25.8.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libnghttp2_asio1-64bit-debuginfo-1.40.0-150600.25.8.1
* libnghttp2-14-64bit-debuginfo-1.40.0-150600.25.8.1
* libnghttp2_asio1-64bit-1.40.0-150600.25.8.1
* libnghttp2-14-64bit-1.40.0-150600.25.8.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nghttp2-debuginfo-1.40.0-150600.25.8.1
* libnghttp2_asio1-1.40.0-150600.25.8.1
* libnghttp2_asio1-debuginfo-1.40.0-150600.25.8.1
* nghttp2-debugsource-1.40.0-150600.25.8.1
* libnghttp2_asio-devel-1.40.0-150600.25.8.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58055.html
* https://bugzilla.suse.com/show_bug.cgi?id69489



SUSE-SU-2026:3155-1: moderate: Security update for python-tornado6


# Security update for python-tornado6

Announcement ID: SUSE-SU-2026:3155-1
Release Date: 2026-07-21T12:58:53Z
Rating: moderate
References:

* bsc#1269012

Affected Products:

* openSUSE Leap 15.4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that has one security fix can now be installed.

## Description:

This update for python-tornado6 fixes the following issue

* GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on
handle reuse (bsc#1269012).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3155=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3155=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python311-tornado6-debuginfo-6.3.2-150400.9.21.1
* python-tornado6-debugsource-6.3.2-150400.9.21.1
* python311-tornado6-6.3.2-150400.9.21.1
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-tornado6-6.3.2-150400.9.21.1
* python311-tornado6-debuginfo-6.3.2-150400.9.21.1
* python-tornado6-debugsource-6.3.2-150400.9.21.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id69012



SUSE-SU-2026:3156-1: important: Security update for the Linux Kernel


# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2026:3156-1
Release Date: 2026-07-21T13:34:56Z
Rating: important
References:

* bsc#1264484
* bsc#1265421
* bsc#1267365
* bsc#1267369
* bsc#1267494
* bsc#1267567
* bsc#1267591
* bsc#1267618
* bsc#1267635
* bsc#1267684
* bsc#1267722
* bsc#1267918
* bsc#1267966
* bsc#1267993
* bsc#1268022
* bsc#1268049
* bsc#1268237
* bsc#1268335
* bsc#1268660
* bsc#1268989
* bsc#1269022
* bsc#1269033
* bsc#1269036
* bsc#1269090
* bsc#1269100
* bsc#1269159
* bsc#1269172
* bsc#1269174
* bsc#1269184
* bsc#1269193
* bsc#1269195
* bsc#1269310
* bsc#1269314
* bsc#1269398
* bsc#1269493
* bsc#1269574
* bsc#1269678
* bsc#1269681
* bsc#1269795
* bsc#1269798
* bsc#1269821
* bsc#1269884
* bsc#1269986
* bsc#1269993
* bsc#1270022
* bsc#1270059
* bsc#1270257
* bsc#1271050
* bsc#1271366
* jsc#PED-16303
* jsc#PED-16305

Cross-References:

* CVE-2026-43109
* CVE-2026-46052
* CVE-2026-46071
* CVE-2026-46076
* CVE-2026-46116
* CVE-2026-46173
* CVE-2026-46229
* CVE-2026-46242
* CVE-2026-46253
* CVE-2026-46266
* CVE-2026-46274
* CVE-2026-46289
* CVE-2026-46319
* CVE-2026-46320
* CVE-2026-46330
* CVE-2026-46331
* CVE-2026-52909
* CVE-2026-52918
* CVE-2026-52923
* CVE-2026-52924
* CVE-2026-52933
* CVE-2026-52943
* CVE-2026-52955
* CVE-2026-52956
* CVE-2026-52958
* CVE-2026-52969
* CVE-2026-52972
* CVE-2026-52993
* CVE-2026-53016
* CVE-2026-53041
* CVE-2026-53052
* CVE-2026-53053
* CVE-2026-53071
* CVE-2026-53072
* CVE-2026-53133
* CVE-2026-53178
* CVE-2026-53182
* CVE-2026-53196
* CVE-2026-53253
* CVE-2026-53256
* CVE-2026-53357
* CVE-2026-53359
* CVE-2026-53362
* CVE-2026-53366

CVSS scores:

* CVE-2026-43109 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46071 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46076 ( SUSE ): 8.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-46116 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46173 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46229 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46242 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46289 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46320 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-46330 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52909 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52918 ( SUSE ): 8.6
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52923 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-52924 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52943 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52972 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52993 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53052 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53053 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53133 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53178 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53178 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53182 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( SUSE ): 7.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53256 ( SUSE ): 7.7
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53357 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53362 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise High Availability Extension 15 SP6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves 44 vulnerabilities, contains two features and has five
security fixes can now be installed.

## Description:

The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security
issues

The following security issues were fixed:

* CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock
(bsc#1264484).
* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
(bsc#1267494).
* CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).
* CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted
by L1 (bsc#1267365).
* CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete (bsc#1267369).
* CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task
(bsc#1267722).
* CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data
exposure (bsc#1267567).
* CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc()
(bsc#1267618).
* CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old()
(bsc#1267635).
* CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
(bsc#1267684).
* CVE-2026-46289: lib/scatterlist: fix length calculations in
extract_kvec_to_sg (bsc#1267966).
* CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft
(bsc#1268022).
* CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp()
(bsc#1267993).
* CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049).
* CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device
(bsc#1268660).
* CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
* CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
(bsc#1269033).
* CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling
(bsc#1269036).
* CVE-2026-52933: io_uring/poll: fix signed comparison in
io_poll_get_ownership() (bsc#1268989).
* CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve
helpers (bsc#1269022).
* CVE-2026-52955: libceph: Fix potential out-of-bounds access in
crush_decode() (bsc#1269159).
* CVE-2026-52956: libceph: Fix potential out-of-bounds access in
__ceph_x_decrypt() (bsc#1269172).
* CVE-2026-52958: libceph: Fix potential out-of-bounds access in
osdmap_decode() (bsc#1269174).
* CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn()
(bsc#1269184).
* CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000
(bsc#1269195).
* CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
* CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
* CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full
(bsc#1269398).
* CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before
accessing data (bsc#1269314).
* CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's
devid (bsc#1269310).
* CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in
l2cap_ecred_reconf_rsp (bsc#1269678).
* CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with
HCI_PROTO_DEFER (bsc#1269681).
* CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G
(bsc#1269821).
* CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before
ie_length subtraction (bsc#1269795).
* CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884).
* CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
(bsc#1269986).
* CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in
bnep_rx_frame() extension handling (bsc#1269574).
* CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in
rfcomm_connect_ind() (bsc#1269993).
* CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs
l2cap_conn_del() (bsc#1270257).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270059).
* CVE-2026-53362: ipv6: account for fraggap on the paged allocation path
(bsc#1269493).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271366).

The following non security issues were fixed:

* hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).
* ipv4: account for fraggap on the paged allocation path (git-fixes).
* ipv6: account for fraggap on the paged allocation path (git-fixes).
* KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock
(bsc#1271050).
* KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose
(bsc#1271050).
* KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU
(bsc#1271050).
* KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-
fixes).
* loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression
(jsc#PED-16303).
* loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported
(jsc#PED-16303).
* module: fix init_module_from_file() error handling (jsc#PED-16303).
* module: make waiting for a concurrent module loader interruptible
(jsc#PED-16303).
* module: Split modules_install compression and in-kernel decompression
(jsc#PED-16303).
* module: split up 'finit_module()' into init_module_from_file() helper
(jsc#PED-16303).
* module: warn about excessively long module waits (jsc#PED-16303).
* modules: catch concurrent module loads, treat them as idempotent
(jsc#PED-16303).
* net: mana: Add support for PF device 0x00C1 (bsc#1268237).
* net: mana: Allocate interrupt context for each EQ when creating vPort (git-
fixes).
* net: mana: Create separate EQs for each vPort (git-fixes).
* net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-
fixes).
* net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-
fixes).
* net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes).
* net: mana: Introduce GIC context with refcounting for interrupt management
(git-fixes).
* net: mana: Optimize irq affinity for low vcpu configs (git-fixes).
* net: mana: Query device capabilities and configure MSI-X sharing for EQs
(git-fixes).
* net: mana: Use GIC functions to allocate global EQs (git-fixes).
* RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes).
* RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes).
* scsi: storvsc: Replace symbolic permissions with octal (git-fixes).
* scsi: target: Fix hexadecimal CHAP_I handling (git-fixes).
* x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305).
* x86/tsc: Disable clocksource watchdog checking on recent and future UV
platforms (jsc#PED-16305).

## Special Instructions and Notes:

* Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3156=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1

## Package List:

* openSUSE Leap 15.6 (aarch64)
* dtb-apm-6.4.0-150600.23.125.1
* dtb-lg-6.4.0-150600.23.125.1
* kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1
* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-64kb-6.4.0-150600.23.125.1
* dtb-amazon-6.4.0-150600.23.125.1
* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-amlogic-6.4.0-150600.23.125.1
* dtb-amd-6.4.0-150600.23.125.1
* kernel-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-sprd-6.4.0-150600.23.125.1
* kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1
* dtb-nvidia-6.4.0-150600.23.125.1
* dtb-xilinx-6.4.0-150600.23.125.1
* dtb-mediatek-6.4.0-150600.23.125.1
* kernel-64kb-extra-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-6.4.0-150600.23.125.1
* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* kernel-64kb-debugsource-6.4.0-150600.23.125.1
* dtb-renesas-6.4.0-150600.23.125.1
* dtb-arm-6.4.0-150600.23.125.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1
* dtb-broadcom-6.4.0-150600.23.125.1
* dtb-altera-6.4.0-150600.23.125.1
* kselftests-kmp-64kb-6.4.0-150600.23.125.1
* kernel-64kb-optional-6.4.0-150600.23.125.1
* dtb-qcom-6.4.0-150600.23.125.1
* cluster-md-kmp-64kb-6.4.0-150600.23.125.1
* dtb-hisilicon-6.4.0-150600.23.125.1
* gfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-allwinner-6.4.0-150600.23.125.1
* dtb-exynos-6.4.0-150600.23.125.1
* dtb-apple-6.4.0-150600.23.125.1
* dtb-marvell-6.4.0-150600.23.125.1
* kernel-64kb-devel-6.4.0-150600.23.125.1
* dtb-cavium-6.4.0-150600.23.125.1
* reiserfs-kmp-64kb-6.4.0-150600.23.125.1
* dtb-freescale-6.4.0-150600.23.125.1
* dtb-rockchip-6.4.0-150600.23.125.1
* dlm-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-64kb-6.4.0-150600.23.125.1
* dtb-socionext-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* kernel-default-livepatch-6.4.0-150600.23.125.1
* kernel-default-extra-debuginfo-6.4.0-150600.23.125.1
* kernel-default-optional-debuginfo-6.4.0-150600.23.125.1
* kselftests-kmp-default-6.4.0-150600.23.125.1
* kernel-default-devel-6.4.0-150600.23.125.1
* kernel-default-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-default-6.4.0-150600.23.125.1
* reiserfs-kmp-default-6.4.0-150600.23.125.1
* kernel-obs-build-debugsource-6.4.0-150600.23.125.1
* kernel-default-debugsource-6.4.0-150600.23.125.1
* kernel-obs-build-6.4.0-150600.23.125.1
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kselftests-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-syms-6.4.0-150600.23.125.1
* kernel-default-optional-6.4.0-150600.23.125.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1
* cluster-md-kmp-default-6.4.0-150600.23.125.1
* ocfs2-kmp-default-6.4.0-150600.23.125.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-default-devel-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-obs-qa-6.4.0-150600.23.125.1
* kernel-default-extra-6.4.0-150600.23.125.1
* gfs2-kmp-default-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-devel-debuginfo-6.4.0-150600.23.125.1
* kernel-kvmsmall-devel-6.4.0-150600.23.125.1
* kernel-kvmsmall-debuginfo-6.4.0-150600.23.125.1
* kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3
* kernel-default-base-rebuild-6.4.0-150600.23.125.1.150600.12.58.3
* kernel-kvmsmall-debugsource-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (noarch)
* kernel-source-vanilla-6.4.0-150600.23.125.1
* kernel-macros-6.4.0-150600.23.125.1
* kernel-devel-6.4.0-150600.23.125.1
* kernel-docs-html-6.4.0-150600.23.125.1
* kernel-source-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (nosrc s390x)
* kernel-zfcpdump-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_29-debugsource-1-150600.13.7.1
* kernel-livepatch-6_4_0-150600_23_125-default-1-150600.13.7.1
* kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-1-150600.13.7.1
* kernel-default-livepatch-devel-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (aarch64 nosrc ppc64le x86_64)
* kernel-kvmsmall-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (aarch64 nosrc ppc64le s390x x86_64)
* kernel-default-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (ppc64le x86_64)
* kernel-debug-debugsource-6.4.0-150600.23.125.1
* kernel-debug-devel-debuginfo-6.4.0-150600.23.125.1
* kernel-debug-devel-6.4.0-150600.23.125.1
* kernel-debug-debuginfo-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (nosrc)
* dtb-aarch64-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (aarch64 nosrc)
* kernel-64kb-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (nosrc ppc64le x86_64)
* kernel-debug-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (s390x)
* kernel-zfcpdump-debuginfo-6.4.0-150600.23.125.1
* kernel-zfcpdump-debugsource-6.4.0-150600.23.125.1
* openSUSE Leap 15.6 (x86_64)
* kernel-debug-vdso-debuginfo-6.4.0-150600.23.125.1
* kernel-kvmsmall-vdso-6.4.0-150600.23.125.1
* kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.125.1
* kernel-default-vdso-6.4.0-150600.23.125.1
* kernel-debug-vdso-6.4.0-150600.23.125.1
* kernel-default-vdso-debuginfo-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch nosrc)
* kernel-docs-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* kernel-syms-6.4.0-150600.23.125.1
* kernel-default-devel-6.4.0-150600.23.125.1
* kernel-default-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-default-6.4.0-150600.23.125.1
* reiserfs-kmp-default-6.4.0-150600.23.125.1
* kernel-obs-build-debugsource-6.4.0-150600.23.125.1
* cluster-md-kmp-default-6.4.0-150600.23.125.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-default-debugsource-6.4.0-150600.23.125.1
* kernel-obs-build-6.4.0-150600.23.125.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-default-6.4.0-150600.23.125.1
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-default-6.4.0-150600.23.125.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-default-devel-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* kernel-macros-6.4.0-150600.23.125.1
* kernel-devel-6.4.0-150600.23.125.1
* kernel-source-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc ppc64le s390x
x86_64)
* kernel-default-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc)
* kernel-64kb-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64)
* kernel-64kb-debugsource-6.4.0-150600.23.125.1
* kernel-64kb-debuginfo-6.4.0-150600.23.125.1
* kernel-64kb-devel-6.4.0-150600.23.125.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le x86_64)
* kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3
* SUSE Linux Enterprise Server 15 SP6 LTSS (s390x)
* kernel-zfcpdump-debuginfo-6.4.0-150600.23.125.1
* kernel-zfcpdump-debugsource-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (nosrc s390x)
* kernel-zfcpdump-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le
x86_64)
* kernel-default-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* kernel-syms-6.4.0-150600.23.125.1
* kernel-default-devel-6.4.0-150600.23.125.1
* kernel-default-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-default-6.4.0-150600.23.125.1
* reiserfs-kmp-default-6.4.0-150600.23.125.1
* kernel-obs-build-debugsource-6.4.0-150600.23.125.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.125.1
* cluster-md-kmp-default-6.4.0-150600.23.125.1
* kernel-default-debugsource-6.4.0-150600.23.125.1
* kernel-obs-build-6.4.0-150600.23.125.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-default-6.4.0-150600.23.125.1
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-default-6.4.0-150600.23.125.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* kernel-default-base-6.4.0-150600.23.125.1.150600.12.58.3
* kernel-default-devel-debuginfo-6.4.0-150600.23.125.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* kernel-macros-6.4.0-150600.23.125.1
* kernel-devel-6.4.0-150600.23.125.1
* kernel-source-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.125.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-default-debuginfo-6.4.0-150600.23.125.1
* kernel-default-livepatch-6.4.0-150600.23.125.1
* kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-1-150600.13.7.1
* kernel-default-debugsource-6.4.0-150600.23.125.1
* kernel-default-livepatch-devel-6.4.0-150600.23.125.1
* kernel-livepatch-SLE15-SP6_Update_29-debugsource-1-150600.13.7.1
* kernel-livepatch-6_4_0-150600_23_125-default-1-150600.13.7.1
* SUSE Linux Enterprise Live Patching 15-SP6 (nosrc)
* kernel-default-6.4.0-150600.23.125.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le
s390x x86_64)
* kernel-default-debugsource-6.4.0-150600.23.125.1
* kernel-default-debuginfo-6.4.0-150600.23.125.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (nosrc)
* kernel-default-6.4.0-150600.23.125.1

## References:

* https://www.suse.com/security/cve/CVE-2026-43109.html
* https://www.suse.com/security/cve/CVE-2026-46052.html
* https://www.suse.com/security/cve/CVE-2026-46071.html
* https://www.suse.com/security/cve/CVE-2026-46076.html
* https://www.suse.com/security/cve/CVE-2026-46116.html
* https://www.suse.com/security/cve/CVE-2026-46173.html
* https://www.suse.com/security/cve/CVE-2026-46229.html
* https://www.suse.com/security/cve/CVE-2026-46242.html
* https://www.suse.com/security/cve/CVE-2026-46253.html
* https://www.suse.com/security/cve/CVE-2026-46266.html
* https://www.suse.com/security/cve/CVE-2026-46274.html
* https://www.suse.com/security/cve/CVE-2026-46289.html
* https://www.suse.com/security/cve/CVE-2026-46319.html
* https://www.suse.com/security/cve/CVE-2026-46320.html
* https://www.suse.com/security/cve/CVE-2026-46330.html
* https://www.suse.com/security/cve/CVE-2026-46331.html
* https://www.suse.com/security/cve/CVE-2026-52909.html
* https://www.suse.com/security/cve/CVE-2026-52918.html
* https://www.suse.com/security/cve/CVE-2026-52923.html
* https://www.suse.com/security/cve/CVE-2026-52924.html
* https://www.suse.com/security/cve/CVE-2026-52933.html
* https://www.suse.com/security/cve/CVE-2026-52943.html
* https://www.suse.com/security/cve/CVE-2026-52955.html
* https://www.suse.com/security/cve/CVE-2026-52956.html
* https://www.suse.com/security/cve/CVE-2026-52958.html
* https://www.suse.com/security/cve/CVE-2026-52969.html
* https://www.suse.com/security/cve/CVE-2026-52972.html
* https://www.suse.com/security/cve/CVE-2026-52993.html
* https://www.suse.com/security/cve/CVE-2026-53016.html
* https://www.suse.com/security/cve/CVE-2026-53041.html
* https://www.suse.com/security/cve/CVE-2026-53052.html
* https://www.suse.com/security/cve/CVE-2026-53053.html
* https://www.suse.com/security/cve/CVE-2026-53071.html
* https://www.suse.com/security/cve/CVE-2026-53072.html
* https://www.suse.com/security/cve/CVE-2026-53133.html
* https://www.suse.com/security/cve/CVE-2026-53178.html
* https://www.suse.com/security/cve/CVE-2026-53182.html
* https://www.suse.com/security/cve/CVE-2026-53196.html
* https://www.suse.com/security/cve/CVE-2026-53253.html
* https://www.suse.com/security/cve/CVE-2026-53256.html
* https://www.suse.com/security/cve/CVE-2026-53357.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53362.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id64484
* https://bugzilla.suse.com/show_bug.cgi?id65421
* https://bugzilla.suse.com/show_bug.cgi?id67365
* https://bugzilla.suse.com/show_bug.cgi?id67369
* https://bugzilla.suse.com/show_bug.cgi?id67494
* https://bugzilla.suse.com/show_bug.cgi?id67567
* https://bugzilla.suse.com/show_bug.cgi?id67591
* https://bugzilla.suse.com/show_bug.cgi?id67618
* https://bugzilla.suse.com/show_bug.cgi?id67635
* https://bugzilla.suse.com/show_bug.cgi?id67684
* https://bugzilla.suse.com/show_bug.cgi?id67722
* https://bugzilla.suse.com/show_bug.cgi?id67918
* https://bugzilla.suse.com/show_bug.cgi?id67966
* https://bugzilla.suse.com/show_bug.cgi?id67993
* https://bugzilla.suse.com/show_bug.cgi?id68022
* https://bugzilla.suse.com/show_bug.cgi?id68049
* https://bugzilla.suse.com/show_bug.cgi?id68237
* https://bugzilla.suse.com/show_bug.cgi?id68335
* https://bugzilla.suse.com/show_bug.cgi?id68660
* https://bugzilla.suse.com/show_bug.cgi?id68989
* https://bugzilla.suse.com/show_bug.cgi?id69022
* https://bugzilla.suse.com/show_bug.cgi?id69033
* https://bugzilla.suse.com/show_bug.cgi?id69036
* https://bugzilla.suse.com/show_bug.cgi?id69090
* https://bugzilla.suse.com/show_bug.cgi?id69100
* https://bugzilla.suse.com/show_bug.cgi?id69159
* https://bugzilla.suse.com/show_bug.cgi?id69172
* https://bugzilla.suse.com/show_bug.cgi?id69174
* https://bugzilla.suse.com/show_bug.cgi?id69184
* https://bugzilla.suse.com/show_bug.cgi?id69193
* https://bugzilla.suse.com/show_bug.cgi?id69195
* https://bugzilla.suse.com/show_bug.cgi?id69310
* https://bugzilla.suse.com/show_bug.cgi?id69314
* https://bugzilla.suse.com/show_bug.cgi?id69398
* https://bugzilla.suse.com/show_bug.cgi?id69493
* https://bugzilla.suse.com/show_bug.cgi?id69574
* https://bugzilla.suse.com/show_bug.cgi?id69678
* https://bugzilla.suse.com/show_bug.cgi?id69681
* https://bugzilla.suse.com/show_bug.cgi?id69795
* https://bugzilla.suse.com/show_bug.cgi?id69798
* https://bugzilla.suse.com/show_bug.cgi?id69821
* https://bugzilla.suse.com/show_bug.cgi?id69884
* https://bugzilla.suse.com/show_bug.cgi?id69986
* https://bugzilla.suse.com/show_bug.cgi?id69993
* https://bugzilla.suse.com/show_bug.cgi?id70022
* https://bugzilla.suse.com/show_bug.cgi?id70059
* https://bugzilla.suse.com/show_bug.cgi?id70257
* https://bugzilla.suse.com/show_bug.cgi?id71050
* https://bugzilla.suse.com/show_bug.cgi?id71366
* https://jira.suse.com/browse/PED-16303
* https://jira.suse.com/browse/PED-16305



SUSE-SU-2026:3165-1: moderate: Security update for php7


# Security update for php7

Announcement ID: SUSE-SU-2026:3165-1
Release Date: 2026-07-21T14:55:01Z
Rating: moderate
References:

* bsc#1270351

Cross-References:

* CVE-2026-14355

CVSS scores:

* CVE-2026-14355 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* Legacy Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for php7 fixes the following issue

* CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL
extension contains a buffer allocation flaw (bsc#1270351).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3165=1

* Legacy Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3165=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3165=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* php7-sockets-debuginfo-7.4.33-150400.4.63.1
* php7-pdo-7.4.33-150400.4.63.1
* php7-tokenizer-7.4.33-150400.4.63.1
* php7-exif-7.4.33-150400.4.63.1
* php7-pgsql-7.4.33-150400.4.63.1
* php7-embed-debugsource-7.4.33-150400.4.63.1
* php7-posix-debuginfo-7.4.33-150400.4.63.1
* php7-sysvsem-debuginfo-7.4.33-150400.4.63.1
* php7-xmlreader-debuginfo-7.4.33-150400.4.63.1
* php7-mysql-7.4.33-150400.4.63.1
* php7-openssl-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-7.4.33-150400.4.63.1
* php7-embed-7.4.33-150400.4.63.1
* php7-fastcgi-debuginfo-7.4.33-150400.4.63.1
* php7-xsl-7.4.33-150400.4.63.1
* php7-fpm-debugsource-7.4.33-150400.4.63.1
* php7-curl-debuginfo-7.4.33-150400.4.63.1
* php7-zip-debuginfo-7.4.33-150400.4.63.1
* php7-devel-7.4.33-150400.4.63.1
* php7-readline-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-debuginfo-7.4.33-150400.4.63.1
* php7-ftp-debuginfo-7.4.33-150400.4.63.1
* php7-snmp-debuginfo-7.4.33-150400.4.63.1
* php7-tidy-7.4.33-150400.4.63.1
* php7-snmp-7.4.33-150400.4.63.1
* php7-phar-7.4.33-150400.4.63.1
* php7-pcntl-debuginfo-7.4.33-150400.4.63.1
* php7-fastcgi-7.4.33-150400.4.63.1
* php7-cli-debuginfo-7.4.33-150400.4.63.1
* php7-debugsource-7.4.33-150400.4.63.1
* php7-pdo-debuginfo-7.4.33-150400.4.63.1
* php7-zip-7.4.33-150400.4.63.1
* php7-debuginfo-7.4.33-150400.4.63.1
* php7-ftp-7.4.33-150400.4.63.1
* php7-xmlwriter-7.4.33-150400.4.63.1
* php7-gd-7.4.33-150400.4.63.1
* php7-soap-7.4.33-150400.4.63.1
* php7-curl-7.4.33-150400.4.63.1
* php7-dom-debuginfo-7.4.33-150400.4.63.1
* php7-odbc-7.4.33-150400.4.63.1
* php7-dba-debuginfo-7.4.33-150400.4.63.1
* php7-gettext-debuginfo-7.4.33-150400.4.63.1
* php7-dom-7.4.33-150400.4.63.1
* php7-mysql-debuginfo-7.4.33-150400.4.63.1
* php7-opcache-debuginfo-7.4.33-150400.4.63.1
* php7-iconv-debuginfo-7.4.33-150400.4.63.1
* php7-tidy-debuginfo-7.4.33-150400.4.63.1
* php7-phar-debuginfo-7.4.33-150400.4.63.1
* php7-sysvshm-7.4.33-150400.4.63.1
* php7-calendar-7.4.33-150400.4.63.1
* php7-xmlrpc-debuginfo-7.4.33-150400.4.63.1
* php7-ldap-debuginfo-7.4.33-150400.4.63.1
* php7-fastcgi-debugsource-7.4.33-150400.4.63.1
* php7-xmlwriter-debuginfo-7.4.33-150400.4.63.1
* php7-calendar-debuginfo-7.4.33-150400.4.63.1
* php7-sysvsem-7.4.33-150400.4.63.1
* php7-gettext-7.4.33-150400.4.63.1
* php7-tokenizer-debuginfo-7.4.33-150400.4.63.1
* php7-test-7.4.33-150400.4.63.1
* php7-mbstring-7.4.33-150400.4.63.1
* apache2-mod_php7-debugsource-7.4.33-150400.4.63.1
* php7-shmop-7.4.33-150400.4.63.1
* php7-bcmath-7.4.33-150400.4.63.1
* php7-pcntl-7.4.33-150400.4.63.1
* php7-sockets-7.4.33-150400.4.63.1
* php7-sysvmsg-7.4.33-150400.4.63.1
* php7-zlib-debuginfo-7.4.33-150400.4.63.1
* php7-cli-7.4.33-150400.4.63.1
* php7-bz2-7.4.33-150400.4.63.1
* php7-ldap-7.4.33-150400.4.63.1
* php7-readline-7.4.33-150400.4.63.1
* php7-posix-7.4.33-150400.4.63.1
* php7-bz2-debuginfo-7.4.33-150400.4.63.1
* php7-gmp-debuginfo-7.4.33-150400.4.63.1
* php7-json-7.4.33-150400.4.63.1
* php7-7.4.33-150400.4.63.1
* php7-zlib-7.4.33-150400.4.63.1
* php7-sysvmsg-debuginfo-7.4.33-150400.4.63.1
* php7-odbc-debuginfo-7.4.33-150400.4.63.1
* php7-mbstring-debuginfo-7.4.33-150400.4.63.1
* php7-fpm-7.4.33-150400.4.63.1
* php7-intl-debuginfo-7.4.33-150400.4.63.1
* php7-gd-debuginfo-7.4.33-150400.4.63.1
* php7-opcache-7.4.33-150400.4.63.1
* php7-fileinfo-debuginfo-7.4.33-150400.4.63.1
* php7-pgsql-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1
* php7-openssl-7.4.33-150400.4.63.1
* php7-ctype-7.4.33-150400.4.63.1
* php7-fileinfo-7.4.33-150400.4.63.1
* php7-xmlreader-7.4.33-150400.4.63.1
* php7-enchant-debuginfo-7.4.33-150400.4.63.1
* php7-gmp-7.4.33-150400.4.63.1
* php7-ctype-debuginfo-7.4.33-150400.4.63.1
* php7-xsl-debuginfo-7.4.33-150400.4.63.1
* php7-dba-7.4.33-150400.4.63.1
* php7-enchant-7.4.33-150400.4.63.1
* php7-sqlite-debuginfo-7.4.33-150400.4.63.1
* php7-json-debuginfo-7.4.33-150400.4.63.1
* php7-shmop-debuginfo-7.4.33-150400.4.63.1
* php7-fpm-debuginfo-7.4.33-150400.4.63.1
* php7-xmlrpc-7.4.33-150400.4.63.1
* php7-soap-debuginfo-7.4.33-150400.4.63.1
* php7-intl-7.4.33-150400.4.63.1
* php7-bcmath-debuginfo-7.4.33-150400.4.63.1
* php7-embed-debuginfo-7.4.33-150400.4.63.1
* php7-sysvshm-debuginfo-7.4.33-150400.4.63.1
* php7-exif-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-7.4.33-150400.4.63.1
* php7-iconv-7.4.33-150400.4.63.1
* php7-sqlite-7.4.33-150400.4.63.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* php7-pdo-7.4.33-150400.4.63.1
* php7-sockets-debuginfo-7.4.33-150400.4.63.1
* php7-tokenizer-7.4.33-150400.4.63.1
* php7-exif-7.4.33-150400.4.63.1
* php7-pgsql-7.4.33-150400.4.63.1
* php7-embed-debugsource-7.4.33-150400.4.63.1
* php7-posix-debuginfo-7.4.33-150400.4.63.1
* php7-sysvsem-debuginfo-7.4.33-150400.4.63.1
* php7-xmlreader-debuginfo-7.4.33-150400.4.63.1
* php7-mysql-7.4.33-150400.4.63.1
* php7-openssl-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-7.4.33-150400.4.63.1
* php7-embed-7.4.33-150400.4.63.1
* php7-fastcgi-debuginfo-7.4.33-150400.4.63.1
* php7-xsl-7.4.33-150400.4.63.1
* php7-fpm-debugsource-7.4.33-150400.4.63.1
* php7-curl-debuginfo-7.4.33-150400.4.63.1
* php7-zip-debuginfo-7.4.33-150400.4.63.1
* php7-readline-debuginfo-7.4.33-150400.4.63.1
* php7-sodium-debuginfo-7.4.33-150400.4.63.1
* php7-ftp-debuginfo-7.4.33-150400.4.63.1
* php7-snmp-debuginfo-7.4.33-150400.4.63.1
* php7-tidy-7.4.33-150400.4.63.1
* php7-snmp-7.4.33-150400.4.63.1
* php7-fastcgi-7.4.33-150400.4.63.1
* php7-phar-7.4.33-150400.4.63.1
* php7-pcntl-debuginfo-7.4.33-150400.4.63.1
* php7-cli-debuginfo-7.4.33-150400.4.63.1
* php7-debugsource-7.4.33-150400.4.63.1
* php7-pdo-debuginfo-7.4.33-150400.4.63.1
* php7-zip-7.4.33-150400.4.63.1
* php7-debuginfo-7.4.33-150400.4.63.1
* php7-ftp-7.4.33-150400.4.63.1
* php7-xmlwriter-7.4.33-150400.4.63.1
* php7-gd-7.4.33-150400.4.63.1
* php7-soap-7.4.33-150400.4.63.1
* php7-curl-7.4.33-150400.4.63.1
* php7-dom-debuginfo-7.4.33-150400.4.63.1
* php7-odbc-7.4.33-150400.4.63.1
* php7-dba-debuginfo-7.4.33-150400.4.63.1
* php7-gettext-debuginfo-7.4.33-150400.4.63.1
* php7-dom-7.4.33-150400.4.63.1
* php7-mysql-debuginfo-7.4.33-150400.4.63.1
* php7-opcache-debuginfo-7.4.33-150400.4.63.1
* php7-iconv-debuginfo-7.4.33-150400.4.63.1
* php7-tidy-debuginfo-7.4.33-150400.4.63.1
* php7-phar-debuginfo-7.4.33-150400.4.63.1
* php7-sysvshm-7.4.33-150400.4.63.1
* php7-calendar-7.4.33-150400.4.63.1
* php7-xmlrpc-debuginfo-7.4.33-150400.4.63.1
* php7-ldap-debuginfo-7.4.33-150400.4.63.1
* php7-fastcgi-debugsource-7.4.33-150400.4.63.1
* php7-xmlwriter-debuginfo-7.4.33-150400.4.63.1
* php7-calendar-debuginfo-7.4.33-150400.4.63.1
* php7-sysvsem-7.4.33-150400.4.63.1
* php7-gettext-7.4.33-150400.4.63.1
* php7-tokenizer-debuginfo-7.4.33-150400.4.63.1
* php7-test-7.4.33-150400.4.63.1
* php7-mbstring-7.4.33-150400.4.63.1
* apache2-mod_php7-debugsource-7.4.33-150400.4.63.1
* php7-shmop-7.4.33-150400.4.63.1
* php7-bcmath-7.4.33-150400.4.63.1
* php7-pcntl-7.4.33-150400.4.63.1
* php7-sockets-7.4.33-150400.4.63.1
* php7-sysvmsg-7.4.33-150400.4.63.1
* php7-zlib-debuginfo-7.4.33-150400.4.63.1
* php7-cli-7.4.33-150400.4.63.1
* php7-bz2-7.4.33-150400.4.63.1
* php7-ldap-7.4.33-150400.4.63.1
* php7-readline-7.4.33-150400.4.63.1
* php7-posix-7.4.33-150400.4.63.1
* php7-bz2-debuginfo-7.4.33-150400.4.63.1
* php7-gmp-debuginfo-7.4.33-150400.4.63.1
* php7-json-7.4.33-150400.4.63.1
* php7-7.4.33-150400.4.63.1
* php7-sysvmsg-debuginfo-7.4.33-150400.4.63.1
* php7-zlib-7.4.33-150400.4.63.1
* php7-odbc-debuginfo-7.4.33-150400.4.63.1
* php7-mbstring-debuginfo-7.4.33-150400.4.63.1
* php7-intl-debuginfo-7.4.33-150400.4.63.1
* php7-fpm-7.4.33-150400.4.63.1
* php7-gd-debuginfo-7.4.33-150400.4.63.1
* php7-fileinfo-debuginfo-7.4.33-150400.4.63.1
* php7-opcache-7.4.33-150400.4.63.1
* php7-pgsql-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1
* php7-openssl-7.4.33-150400.4.63.1
* php7-ctype-7.4.33-150400.4.63.1
* php7-fileinfo-7.4.33-150400.4.63.1
* php7-xmlreader-7.4.33-150400.4.63.1
* php7-enchant-debuginfo-7.4.33-150400.4.63.1
* php7-gmp-7.4.33-150400.4.63.1
* php7-ctype-debuginfo-7.4.33-150400.4.63.1
* php7-xsl-debuginfo-7.4.33-150400.4.63.1
* php7-dba-7.4.33-150400.4.63.1
* php7-enchant-7.4.33-150400.4.63.1
* php7-sqlite-debuginfo-7.4.33-150400.4.63.1
* php7-json-debuginfo-7.4.33-150400.4.63.1
* php7-shmop-debuginfo-7.4.33-150400.4.63.1
* php7-fpm-debuginfo-7.4.33-150400.4.63.1
* php7-xmlrpc-7.4.33-150400.4.63.1
* php7-soap-debuginfo-7.4.33-150400.4.63.1
* php7-intl-7.4.33-150400.4.63.1
* php7-bcmath-debuginfo-7.4.33-150400.4.63.1
* php7-embed-debuginfo-7.4.33-150400.4.63.1
* php7-sysvshm-debuginfo-7.4.33-150400.4.63.1
* php7-exif-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-7.4.33-150400.4.63.1
* php7-iconv-7.4.33-150400.4.63.1
* php7-sqlite-7.4.33-150400.4.63.1
* Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* php7-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-debuginfo-7.4.33-150400.4.63.1
* apache2-mod_php7-debugsource-7.4.33-150400.4.63.1
* php7-debugsource-7.4.33-150400.4.63.1
* apache2-mod_php7-7.4.33-150400.4.63.1
* php7-7.4.33-150400.4.63.1

## References:

* https://www.suse.com/security/cve/CVE-2026-14355.html
* https://bugzilla.suse.com/show_bug.cgi?id70351