SUSE 5736 Published by

SUSE rolled out a fresh batch of security patches for their 2026 releases, targeting known vulnerabilities across dozens of system packages. The update cycle prioritizes critical fixes for Chromium alongside important advisories for the Linux kernel, OpenVPN, dracut, and RPM.

openSUSE-SU-2026:11500-1: moderate: stunnel-5.80-1.1 on GA media
openSUSE-SU-2026:11495-1: moderate: git-cliff-2.13.1-1.1 on GA media
openSUSE-SU-2026:11498-1: moderate: python313-scikit-learn-1.9.0-1.1 on GA media
openSUSE-SU-2026:11494-1: moderate: clusterctl-1.14.0-1.1 on GA media
SUSE-SU-2026:3596-1: important: Security update for openvpn
SUSE-SU-2026:3599-1: important: Security update for dracut
SUSE-SU-2026:3600-1: important: Security update for rpm
openSUSE-SU-2026:21561-1: critical: Security update for chromium
openSUSE-SU-2026:21563-1: important: Security update for librest0_7
openSUSE-SU-2026:21567-1: moderate: Security update for zk
openSUSE-SU-2026:21557-1: moderate: Security update for gleam
openSUSE-SU-2026:21553-1: important: Security update for GraphicsMagick
openSUSE-SU-2026:21551-1: important: Security update for govulncheck-vulndb
openSUSE-SU-2026:21548-1: important: Security update for gd
openSUSE-SU-2026:21546-1: important: Security update for nodejs24
openSUSE-SU-2026:21545-1: important: Security update for nodejs22
SUSE-SU-2026:3593-1: important: Security update for the Linux Kernel
SUSE-SU-2026:3595-1: important: Security update for the Linux Kernel
openSUSE-SU-2026:0281-1: critical: Security update for chromium




openSUSE-SU-2026:11500-1: moderate: stunnel-5.80-1.1 on GA media


# stunnel-5.80-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11500-1
Rating: moderate

Cross-References:

* CVE-2026-70367
* CVE-2026-70368

CVSS scores:

* CVE-2026-70367 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-70367 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-70368 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-70368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the stunnel-5.80-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* stunnel 5.80-1.1
* stunnel-doc 5.80-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-70367.html
* https://www.suse.com/security/cve/CVE-2026-70368.html



openSUSE-SU-2026:11495-1: moderate: git-cliff-2.13.1-1.1 on GA media


# git-cliff-2.13.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11495-1
Rating: moderate

Cross-References:

* CVE-2026-25541

CVSS scores:

* CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the git-cliff-2.13.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* git-cliff 2.13.1-1.1
* git-cliff-bash-completion 2.13.1-1.1
* git-cliff-fish-completion 2.13.1-1.1
* git-cliff-zsh-completion 2.13.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-25541.html



openSUSE-SU-2026:11498-1: moderate: python313-scikit-learn-1.9.0-1.1 on GA media


# python313-scikit-learn-1.9.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11498-1
Rating: moderate

Cross-References:

* CVE-2024-5206

CVSS scores:

* CVE-2024-5206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-scikit-learn-1.9.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-scikit-learn 1.9.0-1.1
* python314-scikit-learn 1.9.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2024-5206.html



openSUSE-SU-2026:11494-1: moderate: clusterctl-1.14.0-1.1 on GA media


# clusterctl-1.14.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11494-1
Rating: moderate

Cross-References:

* CVE-2026-39883

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the clusterctl-1.14.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* clusterctl 1.14.0-1.1
* clusterctl-bash-completion 1.14.0-1.1
* clusterctl-fish-completion 1.14.0-1.1
* clusterctl-zsh-completion 1.14.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-39883.html



SUSE-SU-2026:3596-1: important: Security update for openvpn


# Security update for openvpn

Announcement ID: SUSE-SU-2026:3596-1
Release Date: 2026-08-12T11:37:59Z
Rating: important
References:

* bsc#1267944
* bsc#1267945
* bsc#1273126
* bsc#1273127
* bsc#1273128
* bsc#1273129
* bsc#1273130

Cross-References:

* CVE-2026-11771
* CVE-2026-12932
* CVE-2026-12996
* CVE-2026-13117
* CVE-2026-13379
* CVE-2026-35058
* CVE-2026-40215

CVSS scores:

* CVE-2026-11771 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-11771 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H
* CVE-2026-11771 ( NVD ): 7.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11771 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-12932 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-12932 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-12932 ( NVD ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-12932 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-12996 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-12996 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-12996 ( NVD ): 6.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-12996 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-13117 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13117 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-13117 ( NVD ): 6.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13117 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-13379 ( SUSE ): 5.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:N/SA:H
* CVE-2026-13379 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:H
* CVE-2026-13379 ( NVD ): 5.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13379 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-35058 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-35058 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-35058 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-35058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-40215 ( SUSE ): 6.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40215 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-40215 ( NVD ): 6.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:L/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-40215 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for openvpn fixes the following issues:

* CVE-2026-11771: NTLM proxy auth stack off-by-one write (bsc#1273126).
* CVE-2026-12932: memory leak using --tls-crypt-v2 (bsc#1273127).
* CVE-2026-12996: potential DoS and memory leak via TLS session use-after-free
(bsc#1273128).
* CVE-2026-13117: heap use-after-free via incomplete guard in
check_session_buf_not_used() (bsc#1273129).
* CVE-2026-13379: Windows interactive service DNS SearchList state pollution
(bsc#1273130).
* CVE-2026-35058: improper validation of packet length can lead to a denial of
service (bsc#1267945).
* CVE-2026-40215: race condition during TLS session promotion can lead to a
use-after-free (bsc#1267944).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3596=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3596=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3596=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3596=1

## Package List:

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* openvpn-debugsource-2.6.10-150600.3.26.1
* openvpn-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.26.1
* openvpn-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-devel-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-debugsource-2.6.10-150600.3.26.1
* openvpn-dco-debuginfo-2.6.10-150600.3.26.1
* openvpn-devel-2.6.10-150600.3.26.1
* openvpn-dco-2.6.10-150600.3.26.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* openvpn-debugsource-2.6.10-150600.3.26.1
* openvpn-down-root-plugin-2.6.10-150600.3.26.1
* openvpn-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.26.1
* openvpn-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-devel-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-debugsource-2.6.10-150600.3.26.1
* openvpn-dco-debuginfo-2.6.10-150600.3.26.1
* openvpn-devel-2.6.10-150600.3.26.1
* openvpn-dco-2.6.10-150600.3.26.1
* openvpn-down-root-plugin-debuginfo-2.6.10-150600.3.26.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* openvpn-debugsource-2.6.10-150600.3.26.1
* openvpn-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.26.1
* openvpn-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-devel-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-debugsource-2.6.10-150600.3.26.1
* openvpn-dco-debuginfo-2.6.10-150600.3.26.1
* openvpn-devel-2.6.10-150600.3.26.1
* openvpn-dco-2.6.10-150600.3.26.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* openvpn-debugsource-2.6.10-150600.3.26.1
* openvpn-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.26.1
* openvpn-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-devel-2.6.10-150600.3.26.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.26.1
* openvpn-dco-debugsource-2.6.10-150600.3.26.1
* openvpn-dco-debuginfo-2.6.10-150600.3.26.1
* openvpn-devel-2.6.10-150600.3.26.1
* openvpn-dco-2.6.10-150600.3.26.1

## References:

* https://www.suse.com/security/cve/CVE-2026-11771.html
* https://www.suse.com/security/cve/CVE-2026-12932.html
* https://www.suse.com/security/cve/CVE-2026-12996.html
* https://www.suse.com/security/cve/CVE-2026-13117.html
* https://www.suse.com/security/cve/CVE-2026-13379.html
* https://www.suse.com/security/cve/CVE-2026-35058.html
* https://www.suse.com/security/cve/CVE-2026-40215.html
* https://bugzilla.suse.com/show_bug.cgi?id67944
* https://bugzilla.suse.com/show_bug.cgi?id67945
* https://bugzilla.suse.com/show_bug.cgi?id73126
* https://bugzilla.suse.com/show_bug.cgi?id73127
* https://bugzilla.suse.com/show_bug.cgi?id73128
* https://bugzilla.suse.com/show_bug.cgi?id73129
* https://bugzilla.suse.com/show_bug.cgi?id73130



SUSE-SU-2026:3599-1: important: Security update for dracut


# Security update for dracut

Announcement ID: SUSE-SU-2026:3599-1
Release Date: 2026-08-12T11:53:40Z
Rating: important
References:

* bsc#1274432

Cross-References:

* CVE-2026-15816

CVSS scores:

* CVE-2026-15816 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-15816 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves one vulnerability can now be installed.

## Description:

This update for dracut fixes the following issue:

Update to version 055+suse.367.g85633e8.

Securitys issue fixed:

* CVE-2026-15816: root code execution via unescaped error message written to
sourced emergency-hook script in `die()` (bsc#1274432).

Other updates and bugfixes:

* Fix(base): sanitize message written by `die()` to the emergency hook.
* Feat(base): add escape function implementing `printf %q`.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3599=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3599=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3599=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3599=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3599=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3599=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3599=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3599=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3599=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* dracut-ima-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-extra-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-tools-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* dracut-ima-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* dracut-ima-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* dracut-ima-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* dracut-ima-055+suse.367.g85633e8-150400.3.52.1
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* dracut-debugsource-055+suse.367.g85633e8-150400.3.52.1
* dracut-fips-055+suse.367.g85633e8-150400.3.52.1
* dracut-debuginfo-055+suse.367.g85633e8-150400.3.52.1
* dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1
* dracut-055+suse.367.g85633e8-150400.3.52.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15816.html
* https://bugzilla.suse.com/show_bug.cgi?id74432



SUSE-SU-2026:3600-1: important: Security update for rpm


# Security update for rpm

Announcement ID: SUSE-SU-2026:3600-1
Release Date: 2026-08-12T12:00:44Z
Rating: important
References:

* bsc#1240054
* bsc#1269584

Cross-References:

* CVE-2026-44605

CVSS scores:

* CVE-2026-44605 ( SUSE ): 8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-44605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-44605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Public Cloud Module 15-SP5
* Public Cloud Module 15-SP6
* Public Cloud Module 15-SP7
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves one vulnerability and has one security fix can now be
installed.

## Description:

This update for rpm fixes the following issues:

Security issues fixed:

* CVE-2026-44605: heap buffer overflow in NDB database backend due to
unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584).

Other updates and bugfixes:

* Fix `libelf` handle not being closed, resulting in build errors when using a
NFS buildroot (bsc#1240054).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3600=1

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3600=1

* Public Cloud Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3600=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3600=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3600=1

* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3600=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3600=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3600=1

* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3600=1

* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3600=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3600=1

* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3600=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3600=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3600=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3600=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3600=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3600=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3600=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3600=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3600=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3600=1

## Package List:

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* rpm-imaevmsign-debuginfo-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-imaevmsign-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64)
* rpm-ndb-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* rpm-imaevmsign-debuginfo-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* rpm-imaevmsign-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* rpm-imaevmsign-debuginfo-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-imaevmsign-4.14.3-150400.59.19.1
* rpm-ndb-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* openSUSE Leap 15.4 (x86_64)
* rpm-ndb-32bit-4.14.3-150400.59.19.1
* rpm-ndb-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* rpm-64bit-4.14.3-150400.59.19.1
* rpm-ndb-64bit-4.14.3-150400.59.19.1
* rpm-64bit-debuginfo-4.14.3-150400.59.19.1
* rpm-ndb-64bit-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* rpm-imaevmsign-debuginfo-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-imaevmsign-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* Basesystem Module 15-SP7 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* rpm-ndb-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* python3-rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-devel-4.14.3-150400.59.19.1
* python311-rpm-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1
* rpm-debugsource-4.14.3-150400.59.19.1
* rpm-4.14.3-150400.59.19.1
* rpm-build-debuginfo-4.14.3-150400.59.19.1
* rpm-debuginfo-4.14.3-150400.59.19.1
* rpm-build-4.14.3-150400.59.19.1
* python3-rpm-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* rpm-32bit-debuginfo-4.14.3-150400.59.19.1
* rpm-32bit-4.14.3-150400.59.19.1
* Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64)
* rpm-ndb-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64)
* rpm-ndb-4.14.3-150400.59.19.1
* rpm-ndb-debugsource-4.14.3-150400.59.19.1
* rpm-ndb-debuginfo-4.14.3-150400.59.19.1
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-rpm-4.14.3-150400.59.19.1
* python311-rpm-debuginfo-4.14.3-150400.59.19.1
* python-rpm-debugsource-4.14.3-150400.59.19.1

## References:

* https://www.suse.com/security/cve/CVE-2026-44605.html
* https://bugzilla.suse.com/show_bug.cgi?id40054
* https://bugzilla.suse.com/show_bug.cgi?id69584



openSUSE-SU-2026:21561-1: critical: Security update for chromium


openSUSE security update: security update for chromium
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21561-1
Rating: critical
References:

* bsc#1274549

Cross-References:

* CVE-2026-19137
* CVE-2026-19138
* CVE-2026-19139
* CVE-2026-19140
* CVE-2026-19141
* CVE-2026-19142
* CVE-2026-19143
* CVE-2026-19144
* CVE-2026-19145
* CVE-2026-19146
* CVE-2026-19147
* CVE-2026-19148
* CVE-2026-19149
* CVE-2026-19150
* CVE-2026-19151
* CVE-2026-19152
* CVE-2026-19153
* CVE-2026-19154
* CVE-2026-19155
* CVE-2026-19156
* CVE-2026-19157
* CVE-2026-19158
* CVE-2026-19159
* CVE-2026-19160
* CVE-2026-19161
* CVE-2026-19162
* CVE-2026-19163
* CVE-2026-19164
* CVE-2026-19165
* CVE-2026-19166
* CVE-2026-19167
* CVE-2026-19168
* CVE-2026-19169
* CVE-2026-19170
* CVE-2026-19171
* CVE-2026-19172
* CVE-2026-19173
* CVE-2026-19174
* CVE-2026-19175
* CVE-2026-19176
* CVE-2026-19177

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 41 vulnerabilities and has one bug fix can now be installed.

Description:

This update for chromium fixes the following issues:

Changes in chromium:

- Chromium 151.0.7922.108 (boo#1274549):
* CVE-2026-19137: Use after free in WebGL
* CVE-2026-19149: Use after free in Aura
* CVE-2026-19154: Use after free in Skia
* CVE-2026-19157: Out of bounds write in ANGLE
* CVE-2026-19170: Use after free in WebGL
* CVE-2026-19172: Use after free in Views
* CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
* CVE-2026-19168: Inappropriate implementation in V8
* CVE-2026-19138: Heap buffer overflow in CrashReporting
* CVE-2026-19139: Race in CredentialProvider
* CVE-2026-19140: Use after free in GPU
* CVE-2026-19141: Use after free in Resources
* CVE-2026-19142: Use after free in Views
* CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
* CVE-2026-19144: Use after free in HTML
* CVE-2026-19145: Use after free in Translate
* CVE-2026-19146: Uninitialized Use in GPU
* CVE-2026-19147: Use after free in Aura
* CVE-2026-19148: Out of bounds write in GPU
* CVE-2026-19150: Inappropriate implementation in V8
* CVE-2026-19151: Use after free in V8
* CVE-2026-19152: Inappropriate implementation in Navigation
* CVE-2026-19153: Insufficient validation of untrusted input in Workers
* CVE-2026-19155: Use after free in Payments
* CVE-2026-19156: Heap buffer overflow in Base
* CVE-2026-19158: Use after free in Views
* CVE-2026-19159: Use after free in Views
* CVE-2026-19160: Uninitialized Use in Skia
* CVE-2026-19161: Uninitialized Use in Skia
* CVE-2026-19162: Out of bounds write in V8
* CVE-2026-19163: Use after free in Media
* CVE-2026-19164: Insufficient validation of untrusted input in Codecs
* CVE-2026-19165: Use after free in Extensions
* CVE-2026-19166: Use after free in Web Authentication
* CVE-2026-19167: Integer overflow in GPU
* CVE-2026-19171: Use after free in Media
* CVE-2026-19173: Out of bounds write in Skia
* CVE-2026-19174: Integer overflow in V8
* CVE-2026-19175: Use after free in Payments
* CVE-2026-19176: Use after free in Skia
* CVE-2026-19177: Insufficient validation of untrusted input in UI

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-475=1

Package List:

- openSUSE Leap 16.0:

chromedriver-151.0.7922.108-bp160.1.1
chromium-151.0.7922.108-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-19137.html
* https://www.suse.com/security/cve/CVE-2026-19138.html
* https://www.suse.com/security/cve/CVE-2026-19139.html
* https://www.suse.com/security/cve/CVE-2026-19140.html
* https://www.suse.com/security/cve/CVE-2026-19141.html
* https://www.suse.com/security/cve/CVE-2026-19142.html
* https://www.suse.com/security/cve/CVE-2026-19143.html
* https://www.suse.com/security/cve/CVE-2026-19144.html
* https://www.suse.com/security/cve/CVE-2026-19145.html
* https://www.suse.com/security/cve/CVE-2026-19146.html
* https://www.suse.com/security/cve/CVE-2026-19147.html
* https://www.suse.com/security/cve/CVE-2026-19148.html
* https://www.suse.com/security/cve/CVE-2026-19149.html
* https://www.suse.com/security/cve/CVE-2026-19150.html
* https://www.suse.com/security/cve/CVE-2026-19151.html
* https://www.suse.com/security/cve/CVE-2026-19152.html
* https://www.suse.com/security/cve/CVE-2026-19153.html
* https://www.suse.com/security/cve/CVE-2026-19154.html
* https://www.suse.com/security/cve/CVE-2026-19155.html
* https://www.suse.com/security/cve/CVE-2026-19156.html
* https://www.suse.com/security/cve/CVE-2026-19157.html
* https://www.suse.com/security/cve/CVE-2026-19158.html
* https://www.suse.com/security/cve/CVE-2026-19159.html
* https://www.suse.com/security/cve/CVE-2026-19160.html
* https://www.suse.com/security/cve/CVE-2026-19161.html
* https://www.suse.com/security/cve/CVE-2026-19162.html
* https://www.suse.com/security/cve/CVE-2026-19163.html
* https://www.suse.com/security/cve/CVE-2026-19164.html
* https://www.suse.com/security/cve/CVE-2026-19165.html
* https://www.suse.com/security/cve/CVE-2026-19166.html
* https://www.suse.com/security/cve/CVE-2026-19167.html
* https://www.suse.com/security/cve/CVE-2026-19168.html
* https://www.suse.com/security/cve/CVE-2026-19169.html
* https://www.suse.com/security/cve/CVE-2026-19170.html
* https://www.suse.com/security/cve/CVE-2026-19171.html
* https://www.suse.com/security/cve/CVE-2026-19172.html
* https://www.suse.com/security/cve/CVE-2026-19173.html
* https://www.suse.com/security/cve/CVE-2026-19174.html
* https://www.suse.com/security/cve/CVE-2026-19175.html
* https://www.suse.com/security/cve/CVE-2026-19176.html
* https://www.suse.com/security/cve/CVE-2026-19177.html



openSUSE-SU-2026:21563-1: important: Security update for librest0_7


openSUSE security update: security update for librest0_7
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21563-1
Rating: important
References:

* bsc#1272399

Cross-References:

* CVE-2026-16615

CVSS scores:

* CVE-2026-16615 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for librest0_7 fixes the following issues:

Changes in librest0_7:

- CVE-2026-16615: Fix weak random number generation (bsc#1272399, glgo#GNOME/librest!44).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-477=1

Package List:

- openSUSE Leap 16.0:

librest-0_7-0-0.8.1-bp160.2.1
librest0_7-devel-0.8.1-bp160.2.1
typelib-1_0-Rest-0_7-0.8.1-bp160.2.1

References:

* https://www.suse.com/security/cve/CVE-2026-16615.html



openSUSE-SU-2026:21567-1: moderate: Security update for zk


openSUSE security update: security update for zk
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21567-1
Rating: moderate
References:

* bsc#1253784

Cross-References:

* CVE-2025-58181

CVSS scores:

* CVE-2025-58181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-58181 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for zk fixes the following issues:

Changes in zk:

- Update to version 0.15.6:
* Parse links to notes in frontmatter
* Set filters for lsp completion items from the config
* Set a note's modification time in frontmatter and allow for custom key
naming for both creation and modification keys
* Indexing made significantly more performant
* Support filtering by date and time with " " instead of
T only
* Exclude globs now prune matching directories from indexing, improving
speed of indexing

- Update to version 0.15.5:
* List, edit and filter for broken links with --broken-links
* Update strftime package, supporting %g and %G formats in the
{{format-date}} helper
* Option to append links to selected text, instead of replacing
* Paths with ~ and env variables no longer error when passed to
--notebook-dir and --working-dir
* Guard LSP against unnecessary erroring on missing textDocument/definition
capabilities

- Update to version 0.15.4:
* fix "jump to definition" follows wrong link
* zk config --list (by @andrebauer, 484)
* Ignore commented links for LSP diagnostics. Use an AST to parse files, fixing
* other similar edge cases.
* Links in markdown footnotes now included in :ZkLinks
* Indexing notebook now 35% and 74% faster for full and incremental indexing
* respectively
* Stop crashing lsp server when server received textDocument/completion request with out of range parameters.
* lsp: Provide completion after [[ on lines with multi-byte characters
* Prevent crash in LookForward when the parameters is out of characters number.

- Update to version 0.15.2
* Find notes with missing backlinks using zk list --missing-backlink
* LSP diagnostic for missing backlinks when other notes link to current note
without reciprocal links
* Code action to add missing backlinks
* LSP diagnostic for self-referential links
* Release tarballs now output the program version
* Config path can be set with $ZK_CONFIG_DIR
* bump deps: golang.org/x/crypto v0.45.0 fixes CVE-2025-58181

- Update to version 0.15.0
* fixed LSP crashes when editing code fences and/or working in text files
with code fences
* new feature to set a group path "by name", in that any directory with the
same name can share the same group rules, no matter how deep in the
notebook. See references below.

- Update to version 0.14.2
* Path in .zk/config.toml for the default note template now accepts
UNIX "~/paths"
* Find notes without tags with zk list --tagless
* fix: LSP ignores magnet links as links to notes
* fix: Note titles with double quoted words no longer break json output
* fix: Grammar in error output
* fix: Group rules could not be nested

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-481=1

Package List:

- openSUSE Leap 16.0:

zk-0.15.6-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2025-58181.html



openSUSE-SU-2026:21557-1: moderate: Security update for gleam


openSUSE security update: security update for gleam
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21557-1
Rating: moderate
References:

* bsc#1272992

Cross-References:

* CVE-2026-59247

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for gleam fixes the following issues:

Changes in gleam:

- Update to 1.18.1:
* CVE-2026-59247: insufficient verification of data authenticity
allows a MITM adversary to substitute forged Hex package
contents during dependency resolution (bsc#1272992)
* Set minimum required Erlang version to 26
* All features and bug fixes are extensively highlighted with
examples in upstream's blog post at
https://gleam.run/news/a-field-day-for-gleams-language-server/
and changelog at
https://github.com/gleam-lang/gleam/blob/v1.18.1/CHANGELOG.md .
Some of the highlights include:
- A lot of new features for the LSP
- Faster JavaScript using singletons
- Deprecation of ambiguous pipe syntax
- Path support in Git dependencies
- Up to 13% faster compilation
- Fixed various bugs in Erlang and JavaScript code
generation.
- Fixed several bugs in the float handling for the JavaScript
target.
- Fixed a bug in the generation of Erlang .app files.
- Fixed a bug where the formatter would produce invalid code.
- Fixed a bug in the TypeScript type definition generation.
- Fixed a bug where the compiler would evaluate the numerator
and denominator of a division in the wrong order.
- Fixed a bug where gleam docs would not be generated.

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-471=1

Package List:

- openSUSE Leap 16.0:

gleam-1.18.1-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-59247.html



openSUSE-SU-2026:21553-1: important: Security update for GraphicsMagick


openSUSE security update: security update for graphicsmagick
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21553-1
Rating: important
References:

* bsc#1268878

Cross-References:

* CVE-2026-56379

CVSS scores:

* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for GraphicsMagick fixes the following issue:

- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG
files (bsc#1268878).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1450=1

Package List:

- openSUSE Leap 16.0:

GraphicsMagick-1.3.45-160000.12.1
GraphicsMagick-devel-1.3.45-160000.12.1
libGraphicsMagick++-Q16-12-1.3.45-160000.12.1
libGraphicsMagick++-devel-1.3.45-160000.12.1
libGraphicsMagick-Q16-3-1.3.45-160000.12.1
libGraphicsMagick3-config-1.3.45-160000.12.1
libGraphicsMagickWand-Q16-2-1.3.45-160000.12.1
perl-GraphicsMagick-1.3.45-160000.12.1

References:

* https://www.suse.com/security/cve/CVE-2026-56379.html



openSUSE-SU-2026:21551-1: important: Security update for govulncheck-vulndb


openSUSE security update: security update for govulncheck-vulndb
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21551-1
Rating: important

Cross-References:

* CVE-2026-2303
* CVE-2026-23603
* CVE-2026-24451
* CVE-2026-25038
* CVE-2026-29181
* CVE-2026-30246
* CVE-2026-32952
* CVE-2026-34783
* CVE-2026-35204
* CVE-2026-35205
* CVE-2026-35206
* CVE-2026-37462
* CVE-2026-39883
* CVE-2026-40611
* CVE-2026-40890
* CVE-2026-41178
* CVE-2026-41506
* CVE-2026-41642
* CVE-2026-41643
* CVE-2026-42285
* CVE-2026-42306
* CVE-2026-42328
* CVE-2026-42554
* CVE-2026-42931
* CVE-2026-44166
* CVE-2026-44283
* CVE-2026-44301
* CVE-2026-44332
* CVE-2026-44517
* CVE-2026-44740
* CVE-2026-44973
* CVE-2026-45022
* CVE-2026-45045
* CVE-2026-45135
* CVE-2026-45571
* CVE-2026-46384
* CVE-2026-46385
* CVE-2026-48978
* CVE-2026-49837
* CVE-2026-49838
* CVE-2026-50151
* CVE-2026-50162
* CVE-2026-50163
* CVE-2026-50274
* CVE-2026-52844
* CVE-2026-52845
* CVE-2026-52846
* CVE-2026-53624
* CVE-2026-54063
* CVE-2026-54448
* CVE-2026-55982
* CVE-2026-55984
* CVE-2026-55987
* CVE-2026-56750
* CVE-2026-58417
* CVE-2026-58418
* CVE-2026-58421
* CVE-2026-58425
* CVE-2026-58426
* CVE-2026-58427
* CVE-2026-58431
* CVE-2026-58432
* CVE-2026-58434
* CVE-2026-58435
* CVE-2026-58438
* CVE-2026-58439
* CVE-2026-58441
* CVE-2026-58442
* CVE-2026-58443
* CVE-2026-58445
* CVE-2026-58507
* CVE-2026-58510
* CVE-2026-59766
* CVE-2026-6993
* CVE-2026-7020
* CVE-2026-7482
* CVE-2026-8276

CVSS scores:

* CVE-2026-2303 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-35204 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-35204 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-35205 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-35205 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-35206 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-35206 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44283 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-44283 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-44973 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-45571 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-49837 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-50162 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-50162 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-50163 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
* CVE-2026-50274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54063 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-54063 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54448 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-54448 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7020 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-7020 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8276 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 77 vulnerabilities can now be installed.

Description:

This update for govulncheck-vulndb fixes the following issues:

- Update to version 0.0.20260727T201416 2026-07-27T20:14:16Z (jsc#PED-11136):

Go CVE Numbering Authority IDs added or updated with aliases:
* GO-2026-5046 CVE-2026-46385 GHSA-w8j3-pq8g-8m7w
* GO-2026-5047 CVE-2026-46384 GHSA-mc57-h6j3-3hmv
* GO-2026-5048 GHSA-mx64-mj3q-7prj
* GO-2026-5051
* GO-2026-5069 CVE-2026-30246 GHSA-35hp-hqmv-8qg8
* GO-2026-5074 CVE-2026-45022 GHSA-389r-gv7p-r3rp
* GO-2026-5105 CVE-2026-41506 GHSA-3xc5-wrhm-f963
* GO-2026-5116 CVE-2026-44517 GHSA-49p4-px3h-rq49
* GO-2026-5158 CVE-2026-41178 GHSA-5wrp-cwcj-q835
* GO-2026-5198 CVE-2026-41642 GHSA-7235-89m6-f4px
* GO-2026-5208 CVE-2026-40890 GHSA-77fj-vx54-gvh7
* GO-2026-5266 CVE-2026-41643 GHSA-8rxh-r2p6-7f2q
* GO-2026-5309 GHSA-c3wq-j5vh-68rc
* GO-2026-5327 CVE-2026-2303 GHSA-cp6g-7hqx-qxhp
* GO-2026-5336 CVE-2026-45571 GHSA-crhj-59gh-8x96
* GO-2026-5346 CVE-2026-52845 GHSA-f59h-q822-g45g
* GO-2026-5408 GHSA-gx7w-56w6-g48x
* GO-2026-5426 CVE-2026-39883 GHSA-hfvc-g4fc-pqhx
* GO-2026-5435 CVE-2026-35206 GHSA-hr2v-4r36-88hr
* GO-2026-5452 CVE-2026-34783 GHSA-j6v5-g24h-vg4j
* GO-2026-5463 CVE-2026-8276 GHSA-jcqv-2g3v-gm88
* GO-2026-5471 CVE-2026-6993 GHSA-jj45-xvq5-rhh9
* GO-2026-5490 CVE-2026-44740 GHSA-m3xc-h892-ggx6
* GO-2026-5492 CVE-2026-45135 GHSA-m675-2p33-xv9g
* GO-2026-5506 CVE-2026-29181 GHSA-mh2q-q3fh-2475
* GO-2026-5525 CVE-2026-42285 GHSA-p3w2-64xm-833j
* GO-2026-5543 CVE-2026-32952 GHSA-pjcq-xvwq-hhpj
* GO-2026-5548 CVE-2026-44166 GHSA-pq7p-mc74-g65w
* GO-2026-5566 CVE-2026-35205 GHSA-q5jf-9vfq-h4h7
* GO-2026-5569 GHSA-q76j-gcg9-vxc6
* GO-2026-5585 CVE-2026-42554 GHSA-qjv7-627w-8qjv
* GO-2026-5593 CVE-2026-40611 GHSA-qqx8-2xmm-jrv8
* GO-2026-5595 CVE-2026-52844 GHSA-qrp7-cvwr-j2c6
* GO-2026-5597 CVE-2026-44973 GHSA-qw64-3x98-g7q2
* GO-2026-5606 GHSA-r46f-3rpw-hxrv
* GO-2026-5617 CVE-2026-42306 GHSA-rg2x-37c3-w2rh
* GO-2026-5660 CVE-2026-52846 GHSA-vcc4-2c75-vc9v
* GO-2026-5666 CVE-2026-35204 GHSA-vmx8-mqv2-9gmg
* GO-2026-5684 CVE-2026-42328 GHSA-w239-58x2-q8p5
* GO-2026-5693 GHSA-w5pp-99ch-qj29
* GO-2026-5730 GHSA-wwhq-w58m-w29c
* GO-2026-5736 CVE-2026-44283 GHSA-x35m-3gp4-4fh5
* GO-2026-5740 CVE-2026-44301 GHSA-x597-9fr4-5857
* GO-2026-5748 CVE-2026-7482 GHSA-x8qc-fggm-mpqg
* GO-2026-5750 CVE-2026-7020 GHSA-x99g-8v8j-25j2
* GO-2026-5774 GHSA-3fxj-6jh8-hvhx
* GO-2026-5775 GHSA-9g5q-2w5x-hmxf
* GO-2026-5777 GHSA-rjr7-jggh-pgcp
* GO-2026-5781
* GO-2026-5841 GHSA-259r-337f-4rfw
* GO-2026-5879 CVE-2026-50162 GHSA-8xwf-rjm4-xvhv
* GO-2026-5880 CVE-2026-50163 GHSA-fxhp-mv3v-67qp
* GO-2026-5882 CVE-2026-50151 GHSA-jxpm-75mh-9fp7
* GO-2026-5884 GHSA-vh4v-2xq2-g5cg
* GO-2026-5885 CVE-2026-48978 GHSA-xf85-363p-868w
* GO-2026-5886 CVE-2026-44332 GHSA-g5vh-55hw-rxm8
* GO-2026-5887 CVE-2026-45045 GHSA-gcfq-8gqf-4876
* GO-2026-5912 CVE-2026-53624 GHSA-gv83-gqw6-9j2c
* GO-2026-5954 CVE-2026-49838 GHSA-frrj-87jh-2772
* GO-2026-5955 CVE-2026-49837 GHSA-gjrg-jjr3-56cm
* GO-2026-5960 CVE-2026-54063 GHSA-h69g-9hx6-f3v4
* GO-2026-5971 CVE-2026-37462 GHSA-pw7p-7fqv-hpj8
* GO-2026-5983 CVE-2026-54448 GHSA-q3fv-x8vg-qqm4
* GO-2026-6000 CVE-2026-50274 GHSA-74j5-xf3v-crq8
* GO-2026-6058 CVE-2026-58442 GHSA-h2x6-g7q6-344v
* GO-2026-6059 CVE-2026-58431 GHSA-h56g-4qw7-2mxg
* GO-2026-6060 CVE-2026-58426 GHSA-hg5r-vq93-9fv6
* GO-2026-6061 GHSA-hrxh-6v49-42gf
* GO-2026-6062 CVE-2026-58434 GHSA-j2w3-9c3r-g83q
* GO-2026-6063 CVE-2026-58417 GHSA-jr5x-6h83-wrxf
* GO-2026-6064 CVE-2026-55984 GHSA-m932-crvm-gcp5
* GO-2026-6065 CVE-2026-55982 GHSA-mg4f-x9v4-6h2p
* GO-2026-6066 CVE-2026-58507 GHSA-p4mj-98mv-xq26
* GO-2026-6067 CVE-2026-58445 GHSA-pgqf-926r-548m
* GO-2026-6068 CVE-2026-58427 GHSA-prr9-9mp4-5gp2
* GO-2026-6069 CVE-2026-58510 GHSA-q423-49rw-g9mh
* GO-2026-6070 CVE-2026-58432 GHSA-q9pg-jj6x-j9p6
* GO-2026-6071 CVE-2026-59766 GHSA-qf2f-qh6p-7v89
* GO-2026-6072 CVE-2026-56750 GHSA-rgv6-xp99-6mgj
* GO-2026-6073 CVE-2026-58435 GHSA-rh79-75qm-gwjr
* GO-2026-6074 GHSA-rjvx-x5h2-6px5
* GO-2026-6075 CVE-2026-58418 GHSA-rqhx-647v-wx32
* GO-2026-6076 CVE-2026-25038 GHSA-v73x-hx65-6pf4
* GO-2026-6077 CVE-2026-58421 GHSA-v96j-25gv-g2w9
* GO-2026-6078 CVE-2026-55987 GHSA-vrhc-jjfc-m3m3
* GO-2026-6079 CVE-2026-58425 GHSA-vxv2-8j6r-pcpg
* GO-2026-6080 CVE-2026-58439 GHSA-w5pg-649r-p6gg
* GO-2026-6081 CVE-2026-24451 GHSA-wrf9-r3h7-7x5v
* GO-2026-6082 CVE-2026-42931 GHSA-wwqq-x6w4-frm2
* GO-2026-6083 CVE-2026-23603 GHSA-x77v-q46j-393g
* GO-2026-6084 CVE-2026-58441 GHSA-xmj7-xj85-hfc3
* GO-2026-6085 CVE-2026-58438 GHSA-xv9x-fj9g-vj6h
* GO-2026-6086 CVE-2026-58443 GHSA-xxjv-752h-3vp2

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1447=1

Package List:

- openSUSE Leap 16.0:

References:

* https://www.suse.com/security/cve/CVE-2026-2303.html
* https://www.suse.com/security/cve/CVE-2026-23603.html
* https://www.suse.com/security/cve/CVE-2026-24451.html
* https://www.suse.com/security/cve/CVE-2026-25038.html
* https://www.suse.com/security/cve/CVE-2026-29181.html
* https://www.suse.com/security/cve/CVE-2026-30246.html
* https://www.suse.com/security/cve/CVE-2026-32952.html
* https://www.suse.com/security/cve/CVE-2026-34783.html
* https://www.suse.com/security/cve/CVE-2026-35204.html
* https://www.suse.com/security/cve/CVE-2026-35205.html
* https://www.suse.com/security/cve/CVE-2026-35206.html
* https://www.suse.com/security/cve/CVE-2026-37462.html
* https://www.suse.com/security/cve/CVE-2026-39883.html
* https://www.suse.com/security/cve/CVE-2026-40611.html
* https://www.suse.com/security/cve/CVE-2026-40890.html
* https://www.suse.com/security/cve/CVE-2026-41178.html
* https://www.suse.com/security/cve/CVE-2026-41506.html
* https://www.suse.com/security/cve/CVE-2026-41642.html
* https://www.suse.com/security/cve/CVE-2026-41643.html
* https://www.suse.com/security/cve/CVE-2026-42285.html
* https://www.suse.com/security/cve/CVE-2026-42306.html
* https://www.suse.com/security/cve/CVE-2026-42328.html
* https://www.suse.com/security/cve/CVE-2026-42554.html
* https://www.suse.com/security/cve/CVE-2026-42931.html
* https://www.suse.com/security/cve/CVE-2026-44166.html
* https://www.suse.com/security/cve/CVE-2026-44283.html
* https://www.suse.com/security/cve/CVE-2026-44301.html
* https://www.suse.com/security/cve/CVE-2026-44332.html
* https://www.suse.com/security/cve/CVE-2026-44517.html
* https://www.suse.com/security/cve/CVE-2026-44740.html
* https://www.suse.com/security/cve/CVE-2026-44973.html
* https://www.suse.com/security/cve/CVE-2026-45022.html
* https://www.suse.com/security/cve/CVE-2026-45045.html
* https://www.suse.com/security/cve/CVE-2026-45135.html
* https://www.suse.com/security/cve/CVE-2026-45571.html
* https://www.suse.com/security/cve/CVE-2026-46384.html
* https://www.suse.com/security/cve/CVE-2026-46385.html
* https://www.suse.com/security/cve/CVE-2026-48978.html
* https://www.suse.com/security/cve/CVE-2026-49837.html
* https://www.suse.com/security/cve/CVE-2026-49838.html
* https://www.suse.com/security/cve/CVE-2026-50151.html
* https://www.suse.com/security/cve/CVE-2026-50162.html
* https://www.suse.com/security/cve/CVE-2026-50163.html
* https://www.suse.com/security/cve/CVE-2026-50274.html
* https://www.suse.com/security/cve/CVE-2026-52844.html
* https://www.suse.com/security/cve/CVE-2026-52845.html
* https://www.suse.com/security/cve/CVE-2026-52846.html
* https://www.suse.com/security/cve/CVE-2026-53624.html
* https://www.suse.com/security/cve/CVE-2026-54063.html
* https://www.suse.com/security/cve/CVE-2026-54448.html
* https://www.suse.com/security/cve/CVE-2026-55982.html
* https://www.suse.com/security/cve/CVE-2026-55984.html
* https://www.suse.com/security/cve/CVE-2026-55987.html
* https://www.suse.com/security/cve/CVE-2026-56750.html
* https://www.suse.com/security/cve/CVE-2026-58417.html
* https://www.suse.com/security/cve/CVE-2026-58418.html
* https://www.suse.com/security/cve/CVE-2026-58421.html
* https://www.suse.com/security/cve/CVE-2026-58425.html
* https://www.suse.com/security/cve/CVE-2026-58426.html
* https://www.suse.com/security/cve/CVE-2026-58427.html
* https://www.suse.com/security/cve/CVE-2026-58431.html
* https://www.suse.com/security/cve/CVE-2026-58432.html
* https://www.suse.com/security/cve/CVE-2026-58434.html
* https://www.suse.com/security/cve/CVE-2026-58435.html
* https://www.suse.com/security/cve/CVE-2026-58438.html
* https://www.suse.com/security/cve/CVE-2026-58439.html
* https://www.suse.com/security/cve/CVE-2026-58441.html
* https://www.suse.com/security/cve/CVE-2026-58442.html
* https://www.suse.com/security/cve/CVE-2026-58443.html
* https://www.suse.com/security/cve/CVE-2026-58445.html
* https://www.suse.com/security/cve/CVE-2026-58507.html
* https://www.suse.com/security/cve/CVE-2026-58510.html
* https://www.suse.com/security/cve/CVE-2026-59766.html
* https://www.suse.com/security/cve/CVE-2026-6993.html
* https://www.suse.com/security/cve/CVE-2026-7020.html
* https://www.suse.com/security/cve/CVE-2026-7482.html
* https://www.suse.com/security/cve/CVE-2026-8276.html



openSUSE-SU-2026:21548-1: important: Security update for gd


openSUSE security update: security update for gd
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21548-1
Rating: important
References:

* bsc#1273101

Cross-References:

* CVE-2026-9672

CVSS scores:

* CVE-2026-9672 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for gd fixes the following issue:

- CVE-2026-9672: security issue in `libgd` (bsc#1273101).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1444=1

Package List:

- openSUSE Leap 16.0:

gd-2.3.3-160000.3.1
gd-devel-2.3.3-160000.3.1
libgd3-2.3.3-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-9672.html



openSUSE-SU-2026:21546-1: important: Security update for nodejs24


openSUSE security update: security update for nodejs24
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21546-1
Rating: important
References:

* bsc#1272882
* bsc#1272941
* bsc#1272942
* bsc#1272943
* bsc#1272944
* bsc#1272945
* bsc#1272946
* bsc#1272947
* bsc#1272948
* bsc#1272949
* bsc#1272950
* bsc#1272951

Cross-References:

* CVE-2026-54272
* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58041
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045

CVSS scores:

* CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 12 vulnerabilities and has 12 bug fixes can now be installed.

Description:

This update for nodejs24 fixes the following issues:

Update to 24.18.1.

- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-
boundary checks (bsc#1272882).
- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).
- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).
- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).
- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).
- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).
- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).
- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).
- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).
- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1442=1

Package List:

- openSUSE Leap 16.0:

corepack24-24.18.1-160000.1.1
nodejs24-24.18.1-160000.1.1
nodejs24-devel-24.18.1-160000.1.1
nodejs24-docs-24.18.1-160000.1.1
npm24-24.18.1-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-54272.html
* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58041.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html



openSUSE-SU-2026:21545-1: important: Security update for nodejs22


openSUSE security update: security update for nodejs22
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21545-1
Rating: important
References:

* bsc#1272882
* bsc#1272941
* bsc#1272942
* bsc#1272943
* bsc#1272944
* bsc#1272945
* bsc#1272947
* bsc#1272948
* bsc#1272949
* bsc#1272950
* bsc#1272951

Cross-References:

* CVE-2026-54272
* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045

CVSS scores:

* CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 11 vulnerabilities and has 11 bug fixes can now be installed.

Description:

This update for nodejs22 fixes the following issues:

Update to 22.23.2.

- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-
boundary checks (bsc#1272882).
- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).
- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).
- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).
- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).
- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).
- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).
- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).
- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).
- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1441=1

Package List:

- openSUSE Leap 16.0:

corepack22-22.23.2-160000.1.1
nodejs22-22.23.2-160000.1.1
nodejs22-devel-22.23.2-160000.1.1
nodejs22-docs-22.23.2-160000.1.1
npm22-22.23.2-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-54272.html
* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html



SUSE-SU-2026:3593-1: important: Security update for the Linux Kernel


# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2026:3593-1
Release Date: 2026-08-12T11:30:36Z
Rating: important
References:

* bsc#1185845
* bsc#1237888
* bsc#1243603
* bsc#1254767
* bsc#1255616
* bsc#1258718
* bsc#1262573
* bsc#1263718
* bsc#1263788
* bsc#1264013
* bsc#1264076
* bsc#1264089
* bsc#1265308
* bsc#1266238
* bsc#1266850
* bsc#1267384
* bsc#1267435
* bsc#1267494
* bsc#1267596
* bsc#1267656
* bsc#1267715
* bsc#1268029
* bsc#1269172
* bsc#1269174
* bsc#1269181
* bsc#1269188
* bsc#1269289
* bsc#1269577
* bsc#1269731
* bsc#1269773
* bsc#1269986
* bsc#1269988
* bsc#1269993
* bsc#1269997
* bsc#1270230
* bsc#1270257
* bsc#1271526
* bsc#1271825
* bsc#1271899
* bsc#1271904
* bsc#1271908
* bsc#1271912
* bsc#1271964
* bsc#1272176
* bsc#1272180
* bsc#1272207
* bsc#1272242
* bsc#1272263
* bsc#1272268
* bsc#1272607
* bsc#1272678
* bsc#1272694
* bsc#1272855
* bsc#1272865
* bsc#1272904
* bsc#1272907
* bsc#1272918
* bsc#1273004
* bsc#1273035
* bsc#1273097
* bsc#1273231
* bsc#1274072

Cross-References:

* CVE-2022-4994
* CVE-2023-2058
* CVE-2023-53995
* CVE-2025-21710
* CVE-2025-54518
* CVE-2026-31431
* CVE-2026-31598
* CVE-2026-31628
* CVE-2026-31759
* CVE-2026-43033
* CVE-2026-46052
* CVE-2026-46056
* CVE-2026-46080
* CVE-2026-46109
* CVE-2026-46145
* CVE-2026-46174
* CVE-2026-46193
* CVE-2026-46243
* CVE-2026-46323
* CVE-2026-46333
* CVE-2026-52956
* CVE-2026-52958
* CVE-2026-52967
* CVE-2026-52986
* CVE-2026-53050
* CVE-2026-53131
* CVE-2026-53196
* CVE-2026-53224
* CVE-2026-53246
* CVE-2026-53256
* CVE-2026-53260
* CVE-2026-53267
* CVE-2026-53354
* CVE-2026-53357
* CVE-2026-53375
* CVE-2026-53388
* CVE-2026-53391
* CVE-2026-53402
* CVE-2026-63794
* CVE-2026-63806
* CVE-2026-63807
* CVE-2026-63824
* CVE-2026-63829
* CVE-2026-63893
* CVE-2026-63917
* CVE-2026-63919
* CVE-2026-63921
* CVE-2026-63922
* CVE-2026-63924
* CVE-2026-63971
* CVE-2026-63975
* CVE-2026-63984
* CVE-2026-63994
* CVE-2026-64106
* CVE-2026-64189
* CVE-2026-64560
* CVE-2026-64561
* CVE-2026-64564
* CVE-2026-64600

CVSS scores:

* CVE-2023-2058 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2023-2058 ( NVD ): 2.4 CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
* CVE-2023-53995 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2023-53995 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-21710 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21710 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21710 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2025-54518 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-54518 ( NVD ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31598 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31598 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31628 ( SUSE ): 5.7
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-31628 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-31628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31759 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43033 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43033 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46080 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46109 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46145 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46145 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46174 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46174 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46174 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46193 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46193 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46243 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-52967 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52967 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-52986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52986 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53131 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53131 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53131 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-53196 ( SUSE ): 7.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53224 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53246 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53256 ( SUSE ): 7.7
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53267 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53354 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53354 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53354 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53357 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53375 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53375 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
* CVE-2026-53375 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53391 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53402 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53402 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53402 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63794 ( SUSE ): 7.5
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63794 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63794 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63806 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63806 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63806 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63807 ( SUSE ): 5.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63807 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
* CVE-2026-63807 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63824 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63824 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63829 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63829 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-63829 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63893 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-63893 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63917 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63917 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63919 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63919 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63919 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63921 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
* CVE-2026-63921 ( SUSE ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
* CVE-2026-63921 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63922 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63922 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63971 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( SUSE ): 8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63975 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63994 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64106 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64106 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-64106 ( NVD ): 9.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
* CVE-2026-64189 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64189 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64560 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64561 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64564 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64600 ( SUSE ): 8.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Availability Extension 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves 59 vulnerabilities and has three security fixes can now be
installed.

## Description:

The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security
issues:

The following security issues were fixed:

* CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097).
* CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa()
(bsc#1255616).
* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
(bsc#1267494).
* CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey
handlers (bsc#1267435).
* CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715).
* CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks
(bsc#1267656).
* CVE-2026-52956: libceph: Fix potential out-of-bounds access in
__ceph_x_decrypt() (bsc#1269172).
* CVE-2026-52958: libceph: Fix potential out-of-bounds access in
osdmap_decode() (bsc#1269174).
* CVE-2026-52967: smb/client: fix possible infinite loop and oob read in
symlink_data() (bsc#1269181).
* CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul
(bsc#1269289).
* CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota
deactivation (bsc#1269188).
* CVE-2026-53131: netfilter: require Ethernet MAC header before using
eth_hdr() (bsc#1269773).
* CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
(bsc#1269986).
* CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths
in cookie (bsc#1269997).
* CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO
processing (bsc#1269988).
* CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in
rfcomm_connect_ind() (bsc#1269993).
* CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested()
(bsc#1269731).
* CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval
(bsc#1269577).
* CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
(bsc#1270230).
* CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs
l2cap_conn_del() (bsc#1270257).
* CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches
(bsc#1271899).
* CVE-2026-53388: fuse: re-lock request before replacing page cache folio
(bsc#1271825).
* CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in
nfs4_decode_mp_ds_addr (bsc#1271904).
* CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of
(bsc#1271908).
* CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT
path (bsc#1271964).
* CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd
datamatch with get_unaligned() (bsc#1272268).
* CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking
max mapping level (bsc#1272263).
* CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2()
(bsc#1272180).
* CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for
changelink (bsc#1272176).
* CVE-2026-63893: thunderbolt: property: Reject u32 wrap in
tb_property_entry_valid() (bsc#1272607).
* CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink()
(bsc#1272904).
* CVE-2026-63919: xfrm: input: hold netns during deferred transport
reinjection (bsc#1272907).
* CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate()
(bsc#1272918).
* CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header
pointer once (bsc#1272855).
* CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff
(bsc#1272678).
* CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
(bsc#1272694).
* CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
(bsc#1272865).
* CVE-2026-63994: tunnels: load network headers after skb_cow() in
iptunnel_pmtud_build_icmp() (bsc#1273035).
* CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range
num_eventid_bits (bsc#1272242).
* CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list
resize (bsc#1272207).
* CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU
pages available (bsc#1273231).
* CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec()
race (bsc#1273004).
* CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP
processing (bsc#1274072).
* CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK
(bsc#1271526).

The following non security issues were fixed:

* hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
* mkspec-dtb: Skip missing DTBs.
* pkspec-dtb: Fix dtb-al rename.
* posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
* posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del()
(bsc#1271912).
* posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
* posix-cpu-timers: Handle interval timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set()
(bsc#1271912).
* posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
* posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
* posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
* posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
* posix-timers: Add proper state tracking (bsc#1271912).
* posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
* posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
* posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
* posix-timers: Consolidate signal queueing (bsc#1271912).
* posix-timers: Consolidate timer setup (bsc#1271912).
* posix-timers: Cure si_sys_private race (bsc#1271912).
* posix-timers: Document common_clock_get() correctly (bsc#1271912).
* posix-timers: Expand timer_arm() callbacks with a boolean return value
(bsc#1271912).
* posix-timers: Polish coding style in a few places (bsc#1271912).
* posix-timers: Retrieve interval in common timer_settime() code
(bsc#1271912).
* sctp: validate embedded address parameter length (git-fixes).
* time: Switch to hrtimer_setup() (bsc#1271912).

## Special Instructions and Notes:

* Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3593=1

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3593=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3593=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3593=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3593=1

* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3593=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3593=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3593=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3593=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3593=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3593=1

## Package List:

* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64)
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc s390x x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64)
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* SUSE Linux Enterprise Micro 5.4 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc s390x x86_64)
* kernel-default-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)
* kernel-default-optional-debuginfo-5.14.21-150400.24.235.1
* dlm-kmp-default-debuginfo-5.14.21-150400.24.235.1
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-livepatch-5.14.21-150400.24.235.1
* kernel-default-debugsource-5.14.21-150400.24.235.1
* gfs2-kmp-default-5.14.21-150400.24.235.1
* cluster-md-kmp-default-5.14.21-150400.24.235.1
* cluster-md-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-build-5.14.21-150400.24.235.1
* kselftests-kmp-default-5.14.21-150400.24.235.1
* kernel-obs-build-debugsource-5.14.21-150400.24.235.1
* kernel-default-optional-5.14.21-150400.24.235.1
* kernel-syms-5.14.21-150400.24.235.1
* ocfs2-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-qa-5.14.21-150400.24.235.1
* reiserfs-kmp-default-5.14.21-150400.24.235.1
* kernel-default-extra-debuginfo-5.14.21-150400.24.235.1
* gfs2-kmp-default-debuginfo-5.14.21-150400.24.235.1
* ocfs2-kmp-default-5.14.21-150400.24.235.1
* kernel-default-devel-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-extra-5.14.21-150400.24.235.1
* dlm-kmp-default-5.14.21-150400.24.235.1
* kselftests-kmp-default-debuginfo-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (aarch64)
* kernel-64kb-debugsource-5.14.21-150400.24.235.1
* kernel-64kb-optional-5.14.21-150400.24.235.1
* dtb-broadcom-5.14.21-150400.24.235.1
* dtb-marvell-5.14.21-150400.24.235.1
* dtb-xilinx-5.14.21-150400.24.235.1
* dtb-arm-5.14.21-150400.24.235.1
* kernel-64kb-debuginfo-5.14.21-150400.24.235.1
* cluster-md-kmp-64kb-5.14.21-150400.24.235.1
* ocfs2-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* dtb-amazon-5.14.21-150400.24.235.1
* dtb-mediatek-5.14.21-150400.24.235.1
* dtb-freescale-5.14.21-150400.24.235.1
* dtb-rockchip-5.14.21-150400.24.235.1
* kselftests-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-extra-5.14.21-150400.24.235.1
* dtb-nvidia-5.14.21-150400.24.235.1
* ocfs2-kmp-64kb-5.14.21-150400.24.235.1
* dtb-lg-5.14.21-150400.24.235.1
* dtb-apple-5.14.21-150400.24.235.1
* cluster-md-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* dlm-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* dtb-socionext-5.14.21-150400.24.235.1
* kernel-64kb-optional-debuginfo-5.14.21-150400.24.235.1
* dtb-cavium-5.14.21-150400.24.235.1
* dtb-sprd-5.14.21-150400.24.235.1
* gfs2-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* gfs2-kmp-64kb-5.14.21-150400.24.235.1
* reiserfs-kmp-64kb-5.14.21-150400.24.235.1
* reiserfs-kmp-64kb-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-debuginfo-5.14.21-150400.24.235.1
* dtb-qcom-5.14.21-150400.24.235.1
* dtb-altera-5.14.21-150400.24.235.1
* dtb-apm-5.14.21-150400.24.235.1
* dtb-amd-5.14.21-150400.24.235.1
* dtb-allwinner-5.14.21-150400.24.235.1
* kselftests-kmp-64kb-5.14.21-150400.24.235.1
* dtb-renesas-5.14.21-150400.24.235.1
* dlm-kmp-64kb-5.14.21-150400.24.235.1
* dtb-amlogic-5.14.21-150400.24.235.1
* dtb-hisilicon-5.14.21-150400.24.235.1
* kernel-64kb-extra-debuginfo-5.14.21-150400.24.235.1
* dtb-exynos-5.14.21-150400.24.235.1
* kernel-64kb-devel-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_235-default-debuginfo-1-150400.9.7.1
* kernel-default-livepatch-devel-5.14.21-150400.24.235.1
* kernel-livepatch-5_14_21-150400_24_235-default-1-150400.9.7.1
* kernel-livepatch-SLE15-SP4_Update_58-debugsource-1-150400.9.7.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-debugsource-5.14.21-150400.24.235.1
* kernel-default-base-rebuild-5.14.21-150400.24.235.1.150400.24.118.3
* kernel-kvmsmall-devel-5.14.21-150400.24.235.1
* kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-kvmsmall-debuginfo-5.14.21-150400.24.235.1
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* openSUSE Leap 15.4 (aarch64 nosrc ppc64le x86_64)
* kernel-kvmsmall-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (aarch64 nosrc ppc64le s390x x86_64)
* kernel-default-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (noarch)
* kernel-source-vanilla-5.14.21-150400.24.235.1
* kernel-docs-html-5.14.21-150400.24.235.1
* kernel-macros-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* kernel-devel-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (s390x)
* kernel-zfcpdump-debuginfo-5.14.21-150400.24.235.1
* kernel-zfcpdump-debugsource-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (nosrc s390x)
* kernel-zfcpdump-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (aarch64 nosrc)
* kernel-64kb-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.235.1
* openSUSE Leap 15.4 (nosrc)
* dtb-aarch64-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-syms-5.14.21-150400.24.235.1
* reiserfs-kmp-default-5.14.21-150400.24.235.1
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-build-5.14.21-150400.24.235.1
* kernel-default-devel-5.14.21-150400.24.235.1
* kernel-obs-build-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* kernel-devel-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* kernel-macros-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch nosrc)
* kernel-docs-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64)
* kernel-64kb-debugsource-5.14.21-150400.24.235.1
* kernel-64kb-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x
x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64)
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc)
* kernel-64kb-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (s390x)
* kernel-zfcpdump-debuginfo-5.14.21-150400.24.235.1
* kernel-zfcpdump-debugsource-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc s390x)
* kernel-zfcpdump-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-syms-5.14.21-150400.24.235.1
* reiserfs-kmp-default-5.14.21-150400.24.235.1
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-build-5.14.21-150400.24.235.1
* kernel-default-devel-5.14.21-150400.24.235.1
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* kernel-obs-build-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-devel-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc
x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64)
* kernel-64kb-debugsource-5.14.21-150400.24.235.1
* kernel-64kb-devel-5.14.21-150400.24.235.1
* kernel-64kb-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
nosrc)
* kernel-64kb-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64)
* kernel-64kb-debugsource-5.14.21-150400.24.235.1
* kernel-64kb-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-64kb-devel-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc)
* kernel-64kb-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-devel-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-syms-5.14.21-150400.24.235.1
* reiserfs-kmp-default-5.14.21-150400.24.235.1
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-build-5.14.21-150400.24.235.1
* kernel-default-devel-5.14.21-150400.24.235.1
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* kernel-obs-build-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc
x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le
s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* gfs2-kmp-default-5.14.21-150400.24.235.1
* ocfs2-kmp-default-debuginfo-5.14.21-150400.24.235.1
* dlm-kmp-default-5.14.21-150400.24.235.1
* cluster-md-kmp-default-5.14.21-150400.24.235.1
* dlm-kmp-default-debuginfo-5.14.21-150400.24.235.1
* cluster-md-kmp-default-debuginfo-5.14.21-150400.24.235.1
* gfs2-kmp-default-debuginfo-5.14.21-150400.24.235.1
* ocfs2-kmp-default-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise High Availability Extension 15 SP4 (nosrc)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-devel-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-syms-5.14.21-150400.24.235.1
* reiserfs-kmp-default-5.14.21-150400.24.235.1
* reiserfs-kmp-default-debuginfo-5.14.21-150400.24.235.1
* kernel-default-devel-debuginfo-5.14.21-150400.24.235.1
* kernel-obs-build-5.14.21-150400.24.235.1
* kernel-default-devel-5.14.21-150400.24.235.1
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* kernel-obs-build-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le
x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-livepatch-5_14_21-150400_24_235-default-debuginfo-1-150400.9.7.1
* kernel-livepatch-SLE15-SP4_Update_58-debugsource-1-150400.9.7.1
* kernel-default-livepatch-devel-5.14.21-150400.24.235.1
* kernel-livepatch-5_14_21-150400_24_235-default-1-150400.9.7.1
* kernel-default-livepatch-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Live Patching 15-SP4 (nosrc)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc s390x x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64)
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.235.1
* kernel-default-debuginfo-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.3 (noarch)
* kernel-macros-5.14.21-150400.24.235.1
* kernel-source-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc s390x x86_64)
* kernel-default-5.14.21-150400.24.235.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64)
* kernel-default-base-5.14.21-150400.24.235.1.150400.24.118.3

## References:

* https://www.suse.com/security/cve/CVE-2022-4994.html
* https://www.suse.com/security/cve/CVE-2023-2058.html
* https://www.suse.com/security/cve/CVE-2023-53995.html
* https://www.suse.com/security/cve/CVE-2025-21710.html
* https://www.suse.com/security/cve/CVE-2025-54518.html
* https://www.suse.com/security/cve/CVE-2026-31431.html
* https://www.suse.com/security/cve/CVE-2026-31598.html
* https://www.suse.com/security/cve/CVE-2026-31628.html
* https://www.suse.com/security/cve/CVE-2026-31759.html
* https://www.suse.com/security/cve/CVE-2026-43033.html
* https://www.suse.com/security/cve/CVE-2026-46052.html
* https://www.suse.com/security/cve/CVE-2026-46056.html
* https://www.suse.com/security/cve/CVE-2026-46080.html
* https://www.suse.com/security/cve/CVE-2026-46109.html
* https://www.suse.com/security/cve/CVE-2026-46145.html
* https://www.suse.com/security/cve/CVE-2026-46174.html
* https://www.suse.com/security/cve/CVE-2026-46193.html
* https://www.suse.com/security/cve/CVE-2026-46243.html
* https://www.suse.com/security/cve/CVE-2026-46323.html
* https://www.suse.com/security/cve/CVE-2026-46333.html
* https://www.suse.com/security/cve/CVE-2026-52956.html
* https://www.suse.com/security/cve/CVE-2026-52958.html
* https://www.suse.com/security/cve/CVE-2026-52967.html
* https://www.suse.com/security/cve/CVE-2026-52986.html
* https://www.suse.com/security/cve/CVE-2026-53050.html
* https://www.suse.com/security/cve/CVE-2026-53131.html
* https://www.suse.com/security/cve/CVE-2026-53196.html
* https://www.suse.com/security/cve/CVE-2026-53224.html
* https://www.suse.com/security/cve/CVE-2026-53246.html
* https://www.suse.com/security/cve/CVE-2026-53256.html
* https://www.suse.com/security/cve/CVE-2026-53260.html
* https://www.suse.com/security/cve/CVE-2026-53267.html
* https://www.suse.com/security/cve/CVE-2026-53354.html
* https://www.suse.com/security/cve/CVE-2026-53357.html
* https://www.suse.com/security/cve/CVE-2026-53375.html
* https://www.suse.com/security/cve/CVE-2026-53388.html
* https://www.suse.com/security/cve/CVE-2026-53391.html
* https://www.suse.com/security/cve/CVE-2026-53402.html
* https://www.suse.com/security/cve/CVE-2026-63794.html
* https://www.suse.com/security/cve/CVE-2026-63806.html
* https://www.suse.com/security/cve/CVE-2026-63807.html
* https://www.suse.com/security/cve/CVE-2026-63824.html
* https://www.suse.com/security/cve/CVE-2026-63829.html
* https://www.suse.com/security/cve/CVE-2026-63893.html
* https://www.suse.com/security/cve/CVE-2026-63917.html
* https://www.suse.com/security/cve/CVE-2026-63919.html
* https://www.suse.com/security/cve/CVE-2026-63921.html
* https://www.suse.com/security/cve/CVE-2026-63922.html
* https://www.suse.com/security/cve/CVE-2026-63924.html
* https://www.suse.com/security/cve/CVE-2026-63971.html
* https://www.suse.com/security/cve/CVE-2026-63975.html
* https://www.suse.com/security/cve/CVE-2026-63984.html
* https://www.suse.com/security/cve/CVE-2026-63994.html
* https://www.suse.com/security/cve/CVE-2026-64106.html
* https://www.suse.com/security/cve/CVE-2026-64189.html
* https://www.suse.com/security/cve/CVE-2026-64560.html
* https://www.suse.com/security/cve/CVE-2026-64561.html
* https://www.suse.com/security/cve/CVE-2026-64564.html
* https://www.suse.com/security/cve/CVE-2026-64600.html
* https://bugzilla.suse.com/show_bug.cgi?id85845
* https://bugzilla.suse.com/show_bug.cgi?id37888
* https://bugzilla.suse.com/show_bug.cgi?id43603
* https://bugzilla.suse.com/show_bug.cgi?id54767
* https://bugzilla.suse.com/show_bug.cgi?id55616
* https://bugzilla.suse.com/show_bug.cgi?id58718
* https://bugzilla.suse.com/show_bug.cgi?id62573
* https://bugzilla.suse.com/show_bug.cgi?id63718
* https://bugzilla.suse.com/show_bug.cgi?id63788
* https://bugzilla.suse.com/show_bug.cgi?id64013
* https://bugzilla.suse.com/show_bug.cgi?id64076
* https://bugzilla.suse.com/show_bug.cgi?id64089
* https://bugzilla.suse.com/show_bug.cgi?id65308
* https://bugzilla.suse.com/show_bug.cgi?id66238
* https://bugzilla.suse.com/show_bug.cgi?id66850
* https://bugzilla.suse.com/show_bug.cgi?id67384
* https://bugzilla.suse.com/show_bug.cgi?id67435
* https://bugzilla.suse.com/show_bug.cgi?id67494
* https://bugzilla.suse.com/show_bug.cgi?id67596
* https://bugzilla.suse.com/show_bug.cgi?id67656
* https://bugzilla.suse.com/show_bug.cgi?id67715
* https://bugzilla.suse.com/show_bug.cgi?id68029
* https://bugzilla.suse.com/show_bug.cgi?id69172
* https://bugzilla.suse.com/show_bug.cgi?id69174
* https://bugzilla.suse.com/show_bug.cgi?id69181
* https://bugzilla.suse.com/show_bug.cgi?id69188
* https://bugzilla.suse.com/show_bug.cgi?id69289
* https://bugzilla.suse.com/show_bug.cgi?id69577
* https://bugzilla.suse.com/show_bug.cgi?id69731
* https://bugzilla.suse.com/show_bug.cgi?id69773
* https://bugzilla.suse.com/show_bug.cgi?id69986
* https://bugzilla.suse.com/show_bug.cgi?id69988
* https://bugzilla.suse.com/show_bug.cgi?id69993
* https://bugzilla.suse.com/show_bug.cgi?id69997
* https://bugzilla.suse.com/show_bug.cgi?id70230
* https://bugzilla.suse.com/show_bug.cgi?id70257
* https://bugzilla.suse.com/show_bug.cgi?id71526
* https://bugzilla.suse.com/show_bug.cgi?id71825
* https://bugzilla.suse.com/show_bug.cgi?id71899
* https://bugzilla.suse.com/show_bug.cgi?id71904
* https://bugzilla.suse.com/show_bug.cgi?id71908
* https://bugzilla.suse.com/show_bug.cgi?id71912
* https://bugzilla.suse.com/show_bug.cgi?id71964
* https://bugzilla.suse.com/show_bug.cgi?id72176
* https://bugzilla.suse.com/show_bug.cgi?id72180
* https://bugzilla.suse.com/show_bug.cgi?id72207
* https://bugzilla.suse.com/show_bug.cgi?id72242
* https://bugzilla.suse.com/show_bug.cgi?id72263
* https://bugzilla.suse.com/show_bug.cgi?id72268
* https://bugzilla.suse.com/show_bug.cgi?id72607
* https://bugzilla.suse.com/show_bug.cgi?id72678
* https://bugzilla.suse.com/show_bug.cgi?id72694
* https://bugzilla.suse.com/show_bug.cgi?id72855
* https://bugzilla.suse.com/show_bug.cgi?id72865
* https://bugzilla.suse.com/show_bug.cgi?id72904
* https://bugzilla.suse.com/show_bug.cgi?id72907
* https://bugzilla.suse.com/show_bug.cgi?id72918
* https://bugzilla.suse.com/show_bug.cgi?id73004
* https://bugzilla.suse.com/show_bug.cgi?id73035
* https://bugzilla.suse.com/show_bug.cgi?id73097
* https://bugzilla.suse.com/show_bug.cgi?id73231
* https://bugzilla.suse.com/show_bug.cgi?id74072



SUSE-SU-2026:3595-1: important: Security update for the Linux Kernel


# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2026:3595-1
Release Date: 2026-08-12T11:33:42Z
Rating: important
References:

* bsc#1185845
* bsc#1226591
* bsc#1237888
* bsc#1239015
* bsc#1240552
* bsc#1240727
* bsc#1243603
* bsc#1244229
* bsc#1245457
* bsc#1245728
* bsc#1245729
* bsc#1245730
* bsc#1245731
* bsc#1246203
* bsc#1246212
* bsc#1251135
* bsc#1251971
* bsc#1252266
* bsc#1253049
* bsc#1254767
* bsc#1255616
* bsc#1256690
* bsc#1257466
* bsc#1257472
* bsc#1257541
* bsc#1258718
* bsc#1259580
* bsc#1260347
* bsc#1261648
* bsc#1262573
* bsc#1263010
* bsc#1263718
* bsc#1263788
* bsc#1264013
* bsc#1264053
* bsc#1264076
* bsc#1264089
* bsc#1264387
* bsc#1264558
* bsc#1264779
* bsc#1265308
* bsc#1265928
* bsc#1266238
* bsc#1266402
* bsc#1266414
* bsc#1266758
* bsc#1266765
* bsc#1266850
* bsc#1266913
* bsc#1267375
* bsc#1267384
* bsc#1267435
* bsc#1267494
* bsc#1267584
* bsc#1267596
* bsc#1267656
* bsc#1267715
* bsc#1268029
* bsc#1268237
* bsc#1268750
* bsc#1268989
* bsc#1269172
* bsc#1269174
* bsc#1269181
* bsc#1269188
* bsc#1269289
* bsc#1269512
* bsc#1269513
* bsc#1269577
* bsc#1269731
* bsc#1269773
* bsc#1269798
* bsc#1269986
* bsc#1269988
* bsc#1269993
* bsc#1269997
* bsc#1270257
* bsc#1271011
* bsc#1271526
* bsc#1271825
* bsc#1271866
* bsc#1271899
* bsc#1271904
* bsc#1271908
* bsc#1271912
* bsc#1271964
* bsc#1272176
* bsc#1272180
* bsc#1272207
* bsc#1272242
* bsc#1272263
* bsc#1272268
* bsc#1272573
* bsc#1272607
* bsc#1272665
* bsc#1272678
* bsc#1272693
* bsc#1272694
* bsc#1272855
* bsc#1272865
* bsc#1272904
* bsc#1272907
* bsc#1272918
* bsc#1273004
* bsc#1273035
* bsc#1273097
* bsc#1273231
* bsc#1274072
* jsc#PED-12576
* jsc#PED-16573

Cross-References:

* CVE-2022-4994
* CVE-2023-2058
* CVE-2023-53995
* CVE-2024-38542
* CVE-2025-21710
* CVE-2025-21953
* CVE-2025-54518
* CVE-2026-31431
* CVE-2026-31542
* CVE-2026-31598
* CVE-2026-31628
* CVE-2026-31759
* CVE-2026-43033
* CVE-2026-43056
* CVE-2026-43211
* CVE-2026-43276
* CVE-2026-43440
* CVE-2026-46052
* CVE-2026-46056
* CVE-2026-46080
* CVE-2026-46084
* CVE-2026-46109
* CVE-2026-46117
* CVE-2026-46126
* CVE-2026-46144
* CVE-2026-46145
* CVE-2026-46174
* CVE-2026-46193
* CVE-2026-46243
* CVE-2026-46323
* CVE-2026-46333
* CVE-2026-52933
* CVE-2026-52956
* CVE-2026-52958
* CVE-2026-52967
* CVE-2026-52986
* CVE-2026-53050
* CVE-2026-53131
* CVE-2026-53196
* CVE-2026-53224
* CVE-2026-53246
* CVE-2026-53256
* CVE-2026-53260
* CVE-2026-53267
* CVE-2026-53297
* CVE-2026-53324
* CVE-2026-53357
* CVE-2026-53375
* CVE-2026-53388
* CVE-2026-53391
* CVE-2026-53402
* CVE-2026-63794
* CVE-2026-63806
* CVE-2026-63807
* CVE-2026-63824
* CVE-2026-63829
* CVE-2026-63884
* CVE-2026-63893
* CVE-2026-63917
* CVE-2026-63919
* CVE-2026-63921
* CVE-2026-63922
* CVE-2026-63924
* CVE-2026-63946
* CVE-2026-63971
* CVE-2026-63975
* CVE-2026-63984
* CVE-2026-63994
* CVE-2026-64106
* CVE-2026-64189
* CVE-2026-64530
* CVE-2026-64560
* CVE-2026-64561
* CVE-2026-64564
* CVE-2026-64600

CVSS scores:

* CVE-2023-2058 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2023-2058 ( NVD ): 2.4 CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
* CVE-2023-53995 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2023-53995 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2024-38542 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2024-38542 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2024-38542 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-21710 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21710 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21710 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2025-21953 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-21953 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21953 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-21953 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-54518 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-54518 ( NVD ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31542 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31542 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31542 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31598 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31598 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31628 ( SUSE ): 5.7
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-31628 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-31628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31759 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43033 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43033 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43056 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43211 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43211 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43440 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43440 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46052 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46052 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46080 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46084 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46109 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46117 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46117 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46117 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46117 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46126 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46126 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46145 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46145 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46174 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46174 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46174 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46193 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46193 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46243 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52933 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52958 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-52967 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52967 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-52986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52986 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53131 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53131 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53131 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-53196 ( SUSE ): 7.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53196 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53196 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53224 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53246 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53256 ( SUSE ): 7.7
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53256 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53256 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53267 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53297 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53324 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53357 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53357 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53357 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53375 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53375 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
* CVE-2026-53375 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53391 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53402 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53402 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53402 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63794 ( SUSE ): 7.5
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63794 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63794 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63806 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63806 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63806 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63807 ( SUSE ): 5.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63807 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
* CVE-2026-63807 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63824 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63824 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63829 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63829 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-63829 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63884 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63884 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63884 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63893 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-63893 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63917 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63917 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63919 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63919 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63919 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63921 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
* CVE-2026-63921 ( SUSE ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
* CVE-2026-63921 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63922 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63922 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63946 ( SUSE ): 7.7
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63946 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63946 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63971 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( SUSE ): 8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63975 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63994 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64106 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64106 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-64106 ( NVD ): 9.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
* CVE-2026-64189 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64189 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64530 ( SUSE ): 8.8
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64560 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64561 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64564 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64600 ( SUSE ): 8.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves 75 vulnerabilities, contains two features and has 33
security fixes can now be installed.

## Description:

The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security
issues:

The following security issues were fixed:

* CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097).
* CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa()
(bsc#1255616).
* CVE-2024-38542: RDMA/mana_ib: boundary check before installing cq callbacks
(bsc#1226591).
* CVE-2025-21953: net: mana: cleanup mana struct after debugfs_remove()
(bsc#1240727).
* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
(bsc#1267494).
* CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey
handlers (bsc#1267435).
* CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715).
* CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks
(bsc#1267656).
* CVE-2026-52933: io_uring/poll: fix signed comparison in
io_poll_get_ownership() (bsc#1268989).
* CVE-2026-52956: libceph: Fix potential out-of-bounds access in
__ceph_x_decrypt() (bsc#1269172).
* CVE-2026-52958: libceph: Fix potential out-of-bounds access in
osdmap_decode() (bsc#1269174).
* CVE-2026-52967: smb/client: fix possible infinite loop and oob read in
symlink_data() (bsc#1269181).
* CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul
(bsc#1269289).
* CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota
deactivation (bsc#1269188).
* CVE-2026-53131: netfilter: require Ethernet MAC header before using
eth_hdr() (bsc#1269773).
* CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info()
(bsc#1269986).
* CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths
in cookie (bsc#1269997).
* CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO
processing (bsc#1269988).
* CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in
rfcomm_connect_ind() (bsc#1269993).
* CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested()
(bsc#1269731).
* CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval
(bsc#1269577).
* CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs
l2cap_conn_del() (bsc#1270257).
* CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches
(bsc#1271899).
* CVE-2026-53388: fuse: re-lock request before replacing page cache folio
(bsc#1271825).
* CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in
nfs4_decode_mp_ds_addr (bsc#1271904).
* CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of
(bsc#1271908).
* CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT
path (bsc#1271964).
* CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd
datamatch with get_unaligned() (bsc#1272268).
* CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking
max mapping level (bsc#1272263).
* CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2()
(bsc#1272180).
* CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for
changelink (bsc#1272176).
* CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge
(bsc#1272573).
* CVE-2026-63893: thunderbolt: property: Reject u32 wrap in
tb_property_entry_valid() (bsc#1272607).
* CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink()
(bsc#1272904).
* CVE-2026-63919: xfrm: input: hold netns during deferred transport
reinjection (bsc#1272907).
* CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate()
(bsc#1272918).
* CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header
pointer once (bsc#1272855).
* CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665).
* CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff
(bsc#1272678).
* CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
(bsc#1272694).
* CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
(bsc#1272865).
* CVE-2026-63994: tunnels: load network headers after skb_cow() in
iptunnel_pmtud_build_icmp() (bsc#1273035).
* CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range
num_eventid_bits (bsc#1272242).
* CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list
resize (bsc#1272207).
* CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec()
race (bsc#1273004).
* CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU
pages available (bsc#1273231).
* CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP
processing (bsc#1274072).
* CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK
(bsc#1271526).

The following non security issues were fixed:

* block: fix use-after-free of q->q_usage_counter (bsc#1268750).
* cpumask: add cpumask_weight_andnot() (bsc#1239015).
* Drivers: hv: fix missing kernel-doc description for 'size' in
request_arr_init() (git-fixes).
* Drivers: hv: remove stale comment (git-fixes).
* Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store()
(git-fixes).
* Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-
fixes).
* Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes).
* Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-
fixes).
* Drivers: hv: vmbus: Remove duplication and cleanup code in
create_gpadl_header() (git-fixes).
* Drivers: hv: vmbus: Update indentation in create_gpadl_header() (git-fixes).
* drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes).
* drm/hyperv: validate VMBus packet size in receive callback (git-fixes).
* ethtool: Implement ethtool_puts() (git-fixes).
* hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
* hv: utils: handle and propagate errors in kvp_register (git-fixes).
* hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).
* hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203).
* hv_sock: fix ARM64 support (git-fixes).
* hv_utils: Allow implicit ICTIMESYNCFLAG_SYNC (git-fixes).
* hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).
* IPv6/GRO: generic helper to remove temporary HBH/jumbo header in
(bsc#1246203).
* ipv6/gso: remove temporary HBH/jumbo header (bsc#1246203).
* ipv6: add struct hop_jumbo_hdr definition (bsc#1246203).
* jiffies: Cast to unsigned long in secs_to_jiffies() conversion
(bsc#1257466).
* jiffies: Define secs_to_jiffies() (bsc#1257466).
* lib/bitmap: add bitmap_weight_and() (bsc#1239015).
* mkspec-dtb: Skip missing DTBs.
* net/mana: fix warning in the writer of client oob (git-fixes).
* net/mana: Null service_wq on setup error to prevent double destroy (git-
fixes).
* net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
(bsc#1271866).
* net: mana: add a function to spread IRQs per CPUs (bsc#1239015).
* net: mana: Add debug logs in MANA network driver (bsc#1246212).
* net: mana: Add handler for hardware servicing events (bsc#1245730
bsc#1251971).
* net: mana: Add MAC address to vPort logs and clarify error messages (git-
fixes).
* net: mana: Add metadata support for xdp mode (git-fixes).
* net: mana: add msix index sharing between EQs (git-fixes).
* net: mana: Add NULL guards in teardown path to prevent panic on attach
failure (git-fixes).
* net: mana: Add standard counter rx_missed_errors (git-fixes).
* net: mana: Add support for auxiliary device servicing events (bsc#1251971).
* net: mana: Add support for Multi Vports on Bare metal (bsc#1244229).
* net: mana: Add support for PF device 0x00C1 (bsc#1268237).
* net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457).
* net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203).
* net: mana: Assigning IRQ affinity on HT cores (bsc#1239015).
* net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq()
(git-fixes).
* net: mana: Create separate EQs for each vPort (git-fixes).
* net: mana: Don't overwrite port probe error with add_adev result (git-
fixes).
* net: mana: Drop TX skb on post_work_request failure and unmap resources
(git-fixes).
* net: mana: explain irq_setup() algorithm (bsc#1245457).
* net: mana: Expose additional hardware counters for drop and TC via ethtool
(bsc#1245729).
* net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414).
* net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-
fixes).
* net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR
(git-fixes).
* net: mana: Fix double destroy_workqueue on service rescan PCI path (git-
fixes).
* net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes).
* net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs (bsc#1239015).
* net: mana: Fix memory leak in mana_gd_setup_irqs (bsc#1239015).
* net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes).
* net: mana: Fix spelling mistake "enforecement" -> "enforcement" (git-fixes).
* net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
(bsc#1265928).
* net: mana: fix use-after-free in add_adev() error path (git-fixes).
* net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering
teardown (git-fixes).
* net: mana: Fix use-after-free in reset service rescan path (git-fixes).
* net: mana: Fix warnings for missing export.h header inclusion (git-fixes).
* net: mana: Guard mana_remove against double invocation (git-fixes).
* net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check
(bsc#1269798).
* net: mana: Handle hardware recovery events when probing the device
(bsc#1257466).
* net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971).
* net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes).
* net: mana: Handle unsupported HWC commands (git-fixes).
* net: mana: hardening: Reject zero max_num_queues from
GDMA_QUERY_MAX_RESOURCES (git-fixes).
* net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-
fixes).
* net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE
response (git-fixes).
* net: mana: Implement ndo_tx_timeout and serialize queue resets per port
(bsc#1257472).
* net: mana: Init gf_stats_work before potential error paths in probe (git-
fixes).
* net: mana: Init link_change_work before potential error paths in probe (git-
fixes).
* net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1269798).
* net: mana: Move hardware counter stats from per-port to per-VF context (git-
fixes).
* net: mana: Probe rdma device in mana driver (git-fixes).
* net: mana: Record doorbell physical address in PF mode (bsc#1244229).
* net: mana: Reduce waiting time if HWC not responding (bsc#1252266).
* net: mana: remove double CQ cleanup in mana_create_rxq error path (git-
fixes).
* net: mana: Return error code from mana_create_rxq() (git-fixes).
* net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes).
* net: mana: Set default number of queues to 16 (bsc#1261648).
* net: mana: Set tx_packets to post gso processing packet count (bsc#1245731).
* net: mana: Skip redundant detach on already-detached port (git-fixes).
* net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes).
* net: mana: Support HW link state events (bsc#1253049).
* net: mana: Switch to page pool for jumbo frames (git-fixes).
* net: mana: Trigger VF reset/recovery on health check failure due to HWC
timeout (bsc#1259580).
* net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes).
* net: mana: use ethtool string helpers (git-fixes).
* net: mana: Use kvmalloc for large RX queue and buffer allocations
(bsc#1266765).
* net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes).
* net: mana: Use pci_name() for debugfs directory naming (git-fixes).
* net: mana: Use per-queue allocation for tx_qp to reduce allocation size
(bsc#1266765).
* net: mana: validate rx_req_idx to prevent out-of-bounds array access
(bsc#1266402).
* net: mana: Validate the packet length reported by the NIC (git-fixes).
* PCI: hv: Correct a comment (git-fixes).
* PCI: hv: Fix ring buffer size calculation (git-fixes).
* PCI: hv: remove unnecessary module_init/exit functions (git-fixes).
* PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes).
* PCI: hv: Set default NUMA node to 0 for devices without affinity info
(bsc#1261648).
* pkspec-dtb: Fix dtb-al rename.
* posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
* posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del()
(bsc#1271912).
* posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
* posix-cpu-timers: Handle interval timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set()
(bsc#1271912).
* posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
* posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
* posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
* posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
* posix-timers: Add proper state tracking (bsc#1271912).
* posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
* posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
* posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
* posix-timers: Consolidate signal queueing (bsc#1271912).
* posix-timers: Consolidate timer setup (bsc#1271912).
* posix-timers: Cure si_sys_private race (bsc#1271912).
* posix-timers: Document common_clock_get() correctly (bsc#1271912).
* posix-timers: Expand timer_arm() callbacks with a boolean return value
(bsc#1271912).
* posix-timers: Polish coding style in a few places (bsc#1271912).
* posix-timers: Retrieve interval in common timer_settime() code
(bsc#1271912).
* RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes).
* RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss()
(git-fixes).
* RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
(git-fixes).
* RDMA/mana: Validate rx_hash_key_len (git-fixes).
* RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135).
* RDMA/mana_ib: add additional port counters (bsc#1251135).
* RDMA/mana_ib: Add CQ interrupt support for RAW QP (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Add device statistics support (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Add device-memory support (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Add EQ creation for rnic adapter (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Add port statistics support (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: add support of multiple ports (bsc#1251135).
* RDMA/mana_ib: Adding and deleting GIDs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Allocate PAGE aligned doorbell index (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: check cqe length for kernel CQs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Configure mac address in RNIC (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Create and destroy RC QP (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Create and destroy rnic adapter (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: create and destroy RNIC cqs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Create and destroy UD/GSI QP (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: create EQs for RNIC CQs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: create kernel-level CQs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: create/destroy AH (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Disable RX steering on RSS QP destroy (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Enable RoCE on port 1 (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Ensure variable err is initialized (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: extend mana QP table (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Extend modify QP (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: extend query device (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Fix DSCP value in modify QP (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Fix error code in probe() (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135).
* RDMA/mana_ib: Fix missing ret value (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Handle net event for pointing to the current netdev
(bsc#1256690).
* RDMA/mana_ib: helpers to allocate kernel queues (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Implement DMABUF MR support (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: implement get_dma_mr (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Implement port parameters (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: implement req_notify_cq (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: implement uapi for creation of rnic cq (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Implement uapi to create and destroy RC QP (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: indicate CM support (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: initialize err for empty send WR lists (git-fixes).
* RDMA/mana_ib: introduce a helper to remove cq callbacks (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Introduce helpers to create and destroy mana queues
(bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Introduce mdev_to_gc helper function (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Modify QP state (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: polling of CQs for GSI/UD (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Process QP error events in mana_ib (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: query device capabilities (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Query feature_flags bitmask from FW (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: register RDMA device with GDMA (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: remove useless return values from dbg prints (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes).
* RDMA/mana_ib: request error CQEs when supported (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Set correct device into ib (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: set node_guid (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Support memory windows (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: support of the zero based MRs (bsc#1251135).
* RDMA/mana_ib: Take CQ type from the device type (bsc#1257541).
* RDMA/mana_ib: UD/GSI QP creation for kernel (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: UD/GSI work requests (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: unify mana_ib functions to support any gdma device
(bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (bsc#1271011
jsc#PED-16573).
* RDMA/mana_ib: Use num_comp_vectors of ib_device (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Use safer allocation function() (bsc#1251135).
* RDMA/mana_ib: Use struct mana_ib_queue for CQs (bsc#1240552 jsc#PED-12576).
* RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (bsc#1240552
jsc#PED-12576).
* RDMA/mana_ib: Use struct mana_ib_queue for WQs (bsc#1240552 jsc#PED-12576).
* sched/topology: Introduce for_each_numa_hop_mask() (bsc#1239015).
* sched/topology: Introduce sched_numa_hop_mask() (bsc#1239015).
* scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-
fixes).
* scsi: storvsc: Remove redundant ternary operators (git-fixes).
* scsi: storvsc: Replace symbolic permissions with octal (git-fixes).
* sctp: validate embedded address parameter length (git-fixes).
* tcp: gso: really support BIG TCP (bsc#1246203).
* time: Switch to hrtimer_setup() (bsc#1271912).

## Special Instructions and Notes:

* Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3595=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3595=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3595=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3595=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3595=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3595=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3595=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le
x86_64)
* kernel-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* ocfs2-kmp-default-5.14.21-150500.55.182.1
* dlm-kmp-default-5.14.21-150500.55.182.1
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-5.14.21-150500.55.182.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-5.14.21-150500.55.182.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-debugsource-5.14.21-150500.55.182.1
* reiserfs-kmp-default-5.14.21-150500.55.182.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-syms-5.14.21-150500.55.182.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2
* reiserfs-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch nosrc)
* kernel-docs-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* kernel-source-5.14.21-150500.55.182.1
* kernel-devel-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch nosrc)
* kernel-docs-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* dlm-kmp-default-5.14.21-150500.55.182.1
* kernel-default-devel-5.14.21-150500.55.182.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-5.14.21-150500.55.182.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-syms-5.14.21-150500.55.182.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2
* ocfs2-kmp-default-5.14.21-150500.55.182.1
* kernel-obs-build-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc
x86_64)
* kernel-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64)
* kernel-64kb-devel-5.14.21-150500.55.182.1
* kernel-64kb-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-debugsource-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* kernel-source-5.14.21-150500.55.182.1
* kernel-devel-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
nosrc)
* kernel-64kb-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc)
* kernel-64kb-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* dlm-kmp-default-5.14.21-150500.55.182.1
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-5.14.21-150500.55.182.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-5.14.21-150500.55.182.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-syms-5.14.21-150500.55.182.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2
* ocfs2-kmp-default-5.14.21-150500.55.182.1
* kernel-obs-build-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch nosrc)
* kernel-docs-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64)
* kernel-64kb-devel-5.14.21-150500.55.182.1
* kernel-64kb-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-debugsource-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* kernel-source-5.14.21-150500.55.182.1
* kernel-devel-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc
x86_64)
* kernel-default-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64 nosrc ppc64le s390x x86_64)
* kernel-default-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* kernel-obs-qa-5.14.21-150500.55.182.1
* dlm-kmp-default-5.14.21-150500.55.182.1
* kernel-default-devel-5.14.21-150500.55.182.1
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-5.14.21-150500.55.182.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kselftests-kmp-default-5.14.21-150500.55.182.1
* kernel-default-livepatch-5.14.21-150500.55.182.1
* kernel-default-extra-debuginfo-5.14.21-150500.55.182.1
* reiserfs-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* kernel-default-extra-5.14.21-150500.55.182.1
* kernel-obs-build-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.182.1
* kselftests-kmp-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-5.14.21-150500.55.182.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* reiserfs-kmp-default-5.14.21-150500.55.182.1
* kernel-syms-5.14.21-150500.55.182.1
* kernel-default-optional-debuginfo-5.14.21-150500.55.182.1
* ocfs2-kmp-default-5.14.21-150500.55.182.1
* kernel-default-optional-5.14.21-150500.55.182.1
* gfs2-kmp-default-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (nosrc)
* dtb-aarch64-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64)
* cluster-md-kmp-64kb-5.14.21-150500.55.182.1
* dtb-broadcom-5.14.21-150500.55.182.1
* dtb-socionext-5.14.21-150500.55.182.1
* dtb-nvidia-5.14.21-150500.55.182.1
* kernel-64kb-extra-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-optional-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-optional-5.14.21-150500.55.182.1
* dtb-amd-5.14.21-150500.55.182.1
* reiserfs-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* dtb-qcom-5.14.21-150500.55.182.1
* ocfs2-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* reiserfs-kmp-64kb-5.14.21-150500.55.182.1
* dtb-renesas-5.14.21-150500.55.182.1
* dtb-freescale-5.14.21-150500.55.182.1
* dtb-amazon-5.14.21-150500.55.182.1
* dlm-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* dtb-marvell-5.14.21-150500.55.182.1
* dtb-apple-5.14.21-150500.55.182.1
* kernel-64kb-devel-5.14.21-150500.55.182.1
* kernel-64kb-devel-debuginfo-5.14.21-150500.55.182.1
* dtb-allwinner-5.14.21-150500.55.182.1
* ocfs2-kmp-64kb-5.14.21-150500.55.182.1
* dtb-rockchip-5.14.21-150500.55.182.1
* kernel-64kb-debugsource-5.14.21-150500.55.182.1
* dtb-cavium-5.14.21-150500.55.182.1
* kernel-64kb-debuginfo-5.14.21-150500.55.182.1
* kselftests-kmp-64kb-5.14.21-150500.55.182.1
* gfs2-kmp-64kb-5.14.21-150500.55.182.1
* dtb-xilinx-5.14.21-150500.55.182.1
* dtb-amlogic-5.14.21-150500.55.182.1
* dtb-apm-5.14.21-150500.55.182.1
* dtb-mediatek-5.14.21-150500.55.182.1
* dtb-arm-5.14.21-150500.55.182.1
* dtb-lg-5.14.21-150500.55.182.1
* dtb-hisilicon-5.14.21-150500.55.182.1
* gfs2-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-extra-5.14.21-150500.55.182.1
* dtb-sprd-5.14.21-150500.55.182.1
* dtb-exynos-5.14.21-150500.55.182.1
* dtb-altera-5.14.21-150500.55.182.1
* cluster-md-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* kselftests-kmp-64kb-debuginfo-5.14.21-150500.55.182.1
* dlm-kmp-64kb-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_182-default-1-150500.11.5.1
* kernel-livepatch-SLE15-SP5_Update_44-debugsource-1-150500.11.5.1
* kernel-livepatch-5_14_21-150500_55_182-default-debuginfo-1-150500.11.5.1
* kernel-default-livepatch-devel-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64 nosrc ppc64le x86_64)
* kernel-kvmsmall-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (nosrc s390x)
* kernel-zfcpdump-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64 nosrc)
* kernel-64kb-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (x86_64)
* kernel-default-vdso-5.14.21-150500.55.182.1
* kernel-default-vdso-debuginfo-5.14.21-150500.55.182.1
* kernel-kvmsmall-vdso-debuginfo-5.14.21-150500.55.182.1
* kernel-kvmsmall-vdso-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-debugsource-5.14.21-150500.55.182.1
* kernel-default-base-rebuild-5.14.21-150500.55.182.1.150500.6.85.2
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2
* kernel-kvmsmall-debuginfo-5.14.21-150500.55.182.1
* kernel-kvmsmall-devel-5.14.21-150500.55.182.1
* kernel-kvmsmall-devel-debuginfo-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (noarch)
* kernel-docs-html-5.14.21-150500.55.182.1
* kernel-source-5.14.21-150500.55.182.1
* kernel-source-vanilla-5.14.21-150500.55.182.1
* kernel-devel-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (s390x)
* kernel-zfcpdump-debugsource-5.14.21-150500.55.182.1
* kernel-zfcpdump-debuginfo-5.14.21-150500.55.182.1
* openSUSE Leap 15.5 (noarch nosrc)
* kernel-docs-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* dlm-kmp-default-5.14.21-150500.55.182.1
* kernel-default-devel-5.14.21-150500.55.182.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.182.1
* cluster-md-kmp-default-5.14.21-150500.55.182.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-obs-build-debugsource-5.14.21-150500.55.182.1
* reiserfs-kmp-default-5.14.21-150500.55.182.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-syms-5.14.21-150500.55.182.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.182.1
* ocfs2-kmp-default-5.14.21-150500.55.182.1
* kernel-obs-build-5.14.21-150500.55.182.1
* reiserfs-kmp-default-debuginfo-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* gfs2-kmp-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64)
* kernel-64kb-devel-5.14.21-150500.55.182.1
* kernel-64kb-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-devel-debuginfo-5.14.21-150500.55.182.1
* kernel-64kb-debugsource-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc ppc64le s390x
x86_64)
* kernel-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le x86_64)
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* kernel-source-5.14.21-150500.55.182.1
* kernel-devel-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch nosrc)
* kernel-docs-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (s390x)
* kernel-zfcpdump-debugsource-5.14.21-150500.55.182.1
* kernel-zfcpdump-debuginfo-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc)
* kernel-64kb-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc s390x)
* kernel-zfcpdump-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_182-default-debuginfo-1-150500.11.5.1
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* kernel-livepatch-SLE15-SP5_Update_44-debugsource-1-150500.11.5.1
* kernel-default-livepatch-5.14.21-150500.55.182.1
* kernel-livepatch-5_14_21-150500_55_182-default-1-150500.11.5.1
* kernel-default-livepatch-devel-5.14.21-150500.55.182.1
* kernel-default-debugsource-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Live Patching 15-SP5 (nosrc)
* kernel-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* kernel-source-5.14.21-150500.55.182.1
* kernel-macros-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* kernel-default-debugsource-5.14.21-150500.55.182.1
* kernel-default-debuginfo-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 nosrc ppc64le s390x x86_64)
* kernel-default-5.14.21-150500.55.182.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64)
* kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2

## References:

* https://www.suse.com/security/cve/CVE-2022-4994.html
* https://www.suse.com/security/cve/CVE-2023-2058.html
* https://www.suse.com/security/cve/CVE-2023-53995.html
* https://www.suse.com/security/cve/CVE-2024-38542.html
* https://www.suse.com/security/cve/CVE-2025-21710.html
* https://www.suse.com/security/cve/CVE-2025-21953.html
* https://www.suse.com/security/cve/CVE-2025-54518.html
* https://www.suse.com/security/cve/CVE-2026-31431.html
* https://www.suse.com/security/cve/CVE-2026-31542.html
* https://www.suse.com/security/cve/CVE-2026-31598.html
* https://www.suse.com/security/cve/CVE-2026-31628.html
* https://www.suse.com/security/cve/CVE-2026-31759.html
* https://www.suse.com/security/cve/CVE-2026-43033.html
* https://www.suse.com/security/cve/CVE-2026-43056.html
* https://www.suse.com/security/cve/CVE-2026-43211.html
* https://www.suse.com/security/cve/CVE-2026-43276.html
* https://www.suse.com/security/cve/CVE-2026-43440.html
* https://www.suse.com/security/cve/CVE-2026-46052.html
* https://www.suse.com/security/cve/CVE-2026-46056.html
* https://www.suse.com/security/cve/CVE-2026-46080.html
* https://www.suse.com/security/cve/CVE-2026-46084.html
* https://www.suse.com/security/cve/CVE-2026-46109.html
* https://www.suse.com/security/cve/CVE-2026-46117.html
* https://www.suse.com/security/cve/CVE-2026-46126.html
* https://www.suse.com/security/cve/CVE-2026-46144.html
* https://www.suse.com/security/cve/CVE-2026-46145.html
* https://www.suse.com/security/cve/CVE-2026-46174.html
* https://www.suse.com/security/cve/CVE-2026-46193.html
* https://www.suse.com/security/cve/CVE-2026-46243.html
* https://www.suse.com/security/cve/CVE-2026-46323.html
* https://www.suse.com/security/cve/CVE-2026-46333.html
* https://www.suse.com/security/cve/CVE-2026-52933.html
* https://www.suse.com/security/cve/CVE-2026-52956.html
* https://www.suse.com/security/cve/CVE-2026-52958.html
* https://www.suse.com/security/cve/CVE-2026-52967.html
* https://www.suse.com/security/cve/CVE-2026-52986.html
* https://www.suse.com/security/cve/CVE-2026-53050.html
* https://www.suse.com/security/cve/CVE-2026-53131.html
* https://www.suse.com/security/cve/CVE-2026-53196.html
* https://www.suse.com/security/cve/CVE-2026-53224.html
* https://www.suse.com/security/cve/CVE-2026-53246.html
* https://www.suse.com/security/cve/CVE-2026-53256.html
* https://www.suse.com/security/cve/CVE-2026-53260.html
* https://www.suse.com/security/cve/CVE-2026-53267.html
* https://www.suse.com/security/cve/CVE-2026-53297.html
* https://www.suse.com/security/cve/CVE-2026-53324.html
* https://www.suse.com/security/cve/CVE-2026-53357.html
* https://www.suse.com/security/cve/CVE-2026-53375.html
* https://www.suse.com/security/cve/CVE-2026-53388.html
* https://www.suse.com/security/cve/CVE-2026-53391.html
* https://www.suse.com/security/cve/CVE-2026-53402.html
* https://www.suse.com/security/cve/CVE-2026-63794.html
* https://www.suse.com/security/cve/CVE-2026-63806.html
* https://www.suse.com/security/cve/CVE-2026-63807.html
* https://www.suse.com/security/cve/CVE-2026-63824.html
* https://www.suse.com/security/cve/CVE-2026-63829.html
* https://www.suse.com/security/cve/CVE-2026-63884.html
* https://www.suse.com/security/cve/CVE-2026-63893.html
* https://www.suse.com/security/cve/CVE-2026-63917.html
* https://www.suse.com/security/cve/CVE-2026-63919.html
* https://www.suse.com/security/cve/CVE-2026-63921.html
* https://www.suse.com/security/cve/CVE-2026-63922.html
* https://www.suse.com/security/cve/CVE-2026-63924.html
* https://www.suse.com/security/cve/CVE-2026-63946.html
* https://www.suse.com/security/cve/CVE-2026-63971.html
* https://www.suse.com/security/cve/CVE-2026-63975.html
* https://www.suse.com/security/cve/CVE-2026-63984.html
* https://www.suse.com/security/cve/CVE-2026-63994.html
* https://www.suse.com/security/cve/CVE-2026-64106.html
* https://www.suse.com/security/cve/CVE-2026-64189.html
* https://www.suse.com/security/cve/CVE-2026-64530.html
* https://www.suse.com/security/cve/CVE-2026-64560.html
* https://www.suse.com/security/cve/CVE-2026-64561.html
* https://www.suse.com/security/cve/CVE-2026-64564.html
* https://www.suse.com/security/cve/CVE-2026-64600.html
* https://bugzilla.suse.com/show_bug.cgi?id85845
* https://bugzilla.suse.com/show_bug.cgi?id26591
* https://bugzilla.suse.com/show_bug.cgi?id37888
* https://bugzilla.suse.com/show_bug.cgi?id39015
* https://bugzilla.suse.com/show_bug.cgi?id40552
* https://bugzilla.suse.com/show_bug.cgi?id40727
* https://bugzilla.suse.com/show_bug.cgi?id43603
* https://bugzilla.suse.com/show_bug.cgi?id44229
* https://bugzilla.suse.com/show_bug.cgi?id45457
* https://bugzilla.suse.com/show_bug.cgi?id45728
* https://bugzilla.suse.com/show_bug.cgi?id45729
* https://bugzilla.suse.com/show_bug.cgi?id45730
* https://bugzilla.suse.com/show_bug.cgi?id45731
* https://bugzilla.suse.com/show_bug.cgi?id46203
* https://bugzilla.suse.com/show_bug.cgi?id46212
* https://bugzilla.suse.com/show_bug.cgi?id51135
* https://bugzilla.suse.com/show_bug.cgi?id51971
* https://bugzilla.suse.com/show_bug.cgi?id52266
* https://bugzilla.suse.com/show_bug.cgi?id53049
* https://bugzilla.suse.com/show_bug.cgi?id54767
* https://bugzilla.suse.com/show_bug.cgi?id55616
* https://bugzilla.suse.com/show_bug.cgi?id56690
* https://bugzilla.suse.com/show_bug.cgi?id57466
* https://bugzilla.suse.com/show_bug.cgi?id57472
* https://bugzilla.suse.com/show_bug.cgi?id57541
* https://bugzilla.suse.com/show_bug.cgi?id58718
* https://bugzilla.suse.com/show_bug.cgi?id59580
* https://bugzilla.suse.com/show_bug.cgi?id60347
* https://bugzilla.suse.com/show_bug.cgi?id61648
* https://bugzilla.suse.com/show_bug.cgi?id62573
* https://bugzilla.suse.com/show_bug.cgi?id63010
* https://bugzilla.suse.com/show_bug.cgi?id63718
* https://bugzilla.suse.com/show_bug.cgi?id63788
* https://bugzilla.suse.com/show_bug.cgi?id64013
* https://bugzilla.suse.com/show_bug.cgi?id64053
* https://bugzilla.suse.com/show_bug.cgi?id64076
* https://bugzilla.suse.com/show_bug.cgi?id64089
* https://bugzilla.suse.com/show_bug.cgi?id64387
* https://bugzilla.suse.com/show_bug.cgi?id64558
* https://bugzilla.suse.com/show_bug.cgi?id64779
* https://bugzilla.suse.com/show_bug.cgi?id65308
* https://bugzilla.suse.com/show_bug.cgi?id65928
* https://bugzilla.suse.com/show_bug.cgi?id66238
* https://bugzilla.suse.com/show_bug.cgi?id66402
* https://bugzilla.suse.com/show_bug.cgi?id66414
* https://bugzilla.suse.com/show_bug.cgi?id66758
* https://bugzilla.suse.com/show_bug.cgi?id66765
* https://bugzilla.suse.com/show_bug.cgi?id66850
* https://bugzilla.suse.com/show_bug.cgi?id66913
* https://bugzilla.suse.com/show_bug.cgi?id67375
* https://bugzilla.suse.com/show_bug.cgi?id67384
* https://bugzilla.suse.com/show_bug.cgi?id67435
* https://bugzilla.suse.com/show_bug.cgi?id67494
* https://bugzilla.suse.com/show_bug.cgi?id67584
* https://bugzilla.suse.com/show_bug.cgi?id67596
* https://bugzilla.suse.com/show_bug.cgi?id67656
* https://bugzilla.suse.com/show_bug.cgi?id67715
* https://bugzilla.suse.com/show_bug.cgi?id68029
* https://bugzilla.suse.com/show_bug.cgi?id68237
* https://bugzilla.suse.com/show_bug.cgi?id68750
* https://bugzilla.suse.com/show_bug.cgi?id68989
* https://bugzilla.suse.com/show_bug.cgi?id69172
* https://bugzilla.suse.com/show_bug.cgi?id69174
* https://bugzilla.suse.com/show_bug.cgi?id69181
* https://bugzilla.suse.com/show_bug.cgi?id69188
* https://bugzilla.suse.com/show_bug.cgi?id69289
* https://bugzilla.suse.com/show_bug.cgi?id69512
* https://bugzilla.suse.com/show_bug.cgi?id69513
* https://bugzilla.suse.com/show_bug.cgi?id69577
* https://bugzilla.suse.com/show_bug.cgi?id69731
* https://bugzilla.suse.com/show_bug.cgi?id69773
* https://bugzilla.suse.com/show_bug.cgi?id69798
* https://bugzilla.suse.com/show_bug.cgi?id69986
* https://bugzilla.suse.com/show_bug.cgi?id69988
* https://bugzilla.suse.com/show_bug.cgi?id69993
* https://bugzilla.suse.com/show_bug.cgi?id69997
* https://bugzilla.suse.com/show_bug.cgi?id70257
* https://bugzilla.suse.com/show_bug.cgi?id71011
* https://bugzilla.suse.com/show_bug.cgi?id71526
* https://bugzilla.suse.com/show_bug.cgi?id71825
* https://bugzilla.suse.com/show_bug.cgi?id71866
* https://bugzilla.suse.com/show_bug.cgi?id71899
* https://bugzilla.suse.com/show_bug.cgi?id71904
* https://bugzilla.suse.com/show_bug.cgi?id71908
* https://bugzilla.suse.com/show_bug.cgi?id71912
* https://bugzilla.suse.com/show_bug.cgi?id71964
* https://bugzilla.suse.com/show_bug.cgi?id72176
* https://bugzilla.suse.com/show_bug.cgi?id72180
* https://bugzilla.suse.com/show_bug.cgi?id72207
* https://bugzilla.suse.com/show_bug.cgi?id72242
* https://bugzilla.suse.com/show_bug.cgi?id72263
* https://bugzilla.suse.com/show_bug.cgi?id72268
* https://bugzilla.suse.com/show_bug.cgi?id72573
* https://bugzilla.suse.com/show_bug.cgi?id72607
* https://bugzilla.suse.com/show_bug.cgi?id72665
* https://bugzilla.suse.com/show_bug.cgi?id72678
* https://bugzilla.suse.com/show_bug.cgi?id72693
* https://bugzilla.suse.com/show_bug.cgi?id72694
* https://bugzilla.suse.com/show_bug.cgi?id72855
* https://bugzilla.suse.com/show_bug.cgi?id72865
* https://bugzilla.suse.com/show_bug.cgi?id72904
* https://bugzilla.suse.com/show_bug.cgi?id72907
* https://bugzilla.suse.com/show_bug.cgi?id72918
* https://bugzilla.suse.com/show_bug.cgi?id73004
* https://bugzilla.suse.com/show_bug.cgi?id73035
* https://bugzilla.suse.com/show_bug.cgi?id73097
* https://bugzilla.suse.com/show_bug.cgi?id73231
* https://bugzilla.suse.com/show_bug.cgi?id74072
* https://jira.suse.com/browse/PED-12576
* https://jira.suse.com/browse/PED-16573



openSUSE-SU-2026:0281-1: critical: Security update for chromium


openSUSE Security Update: Security update for chromium
_______________________________

Announcement ID: openSUSE-SU-2026:0281-1
Rating: critical
References: #1274549
Cross-References: CVE-2026-19137 CVE-2026-19138 CVE-2026-19139
CVE-2026-19140 CVE-2026-19141 CVE-2026-19142
CVE-2026-19143 CVE-2026-19144 CVE-2026-19145
CVE-2026-19146 CVE-2026-19147 CVE-2026-19148
CVE-2026-19149 CVE-2026-19150 CVE-2026-19151
CVE-2026-19152 CVE-2026-19153 CVE-2026-19154
CVE-2026-19155 CVE-2026-19156 CVE-2026-19157
CVE-2026-19158 CVE-2026-19159 CVE-2026-19160
CVE-2026-19161 CVE-2026-19162 CVE-2026-19163
CVE-2026-19164 CVE-2026-19165 CVE-2026-19166
CVE-2026-19167 CVE-2026-19168 CVE-2026-19169
CVE-2026-19170 CVE-2026-19171 CVE-2026-19172
CVE-2026-19173 CVE-2026-19174 CVE-2026-19175
CVE-2026-19176 CVE-2026-19177
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes 41 vulnerabilities is now available.

Description:

This update for chromium fixes the following issues:

- Chromium 151.0.7922.108 (boo#1274549):
* CVE-2026-19137: Use after free in WebGL
* CVE-2026-19149: Use after free in Aura
* CVE-2026-19154: Use after free in Skia
* CVE-2026-19157: Out of bounds write in ANGLE
* CVE-2026-19170: Use after free in WebGL
* CVE-2026-19172: Use after free in Views
* CVE-2026-19169: Insufficient validation of untrusted input in
Contextual Tasks
* CVE-2026-19168: Inappropriate implementation in V8
* CVE-2026-19138: Heap buffer overflow in CrashReporting
* CVE-2026-19139: Race in CredentialProvider
* CVE-2026-19140: Use after free in GPU
* CVE-2026-19141: Use after free in Resources
* CVE-2026-19142: Use after free in Views
* CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
* CVE-2026-19144: Use after free in HTML
* CVE-2026-19145: Use after free in Translate
* CVE-2026-19146: Uninitialized Use in GPU
* CVE-2026-19147: Use after free in Aura
* CVE-2026-19148: Out of bounds write in GPU
* CVE-2026-19150: Inappropriate implementation in V8
* CVE-2026-19151: Use after free in V8
* CVE-2026-19152: Inappropriate implementation in Navigation
* CVE-2026-19153: Insufficient validation of untrusted input in Workers
* CVE-2026-19155: Use after free in Payments
* CVE-2026-19156: Heap buffer overflow in Base
* CVE-2026-19158: Use after free in Views
* CVE-2026-19159: Use after free in Views
* CVE-2026-19160: Uninitialized Use in Skia
* CVE-2026-19161: Uninitialized Use in Skia
* CVE-2026-19162: Out of bounds write in V8
* CVE-2026-19163: Use after free in Media
* CVE-2026-19164: Insufficient validation of untrusted input in Codecs
* CVE-2026-19165: Use after free in Extensions
* CVE-2026-19166: Use after free in Web Authentication
* CVE-2026-19167: Integer overflow in GPU
* CVE-2026-19171: Use after free in Media
* CVE-2026-19173: Out of bounds write in Skia
* CVE-2026-19174: Integer overflow in V8
* CVE-2026-19175: Use after free in Payments
* CVE-2026-19176: Use after free in Skia
* CVE-2026-19177: Insufficient validation of untrusted input in UI

- Chromium 151.0.7922.75:
* stability fix
* pull in SKIA updates

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-281=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):

chromedriver-151.0.7922.108-bp157.2.202.1
chromium-151.0.7922.108-bp157.2.202.1

References:

https://www.suse.com/security/cve/CVE-2026-19137.html
https://www.suse.com/security/cve/CVE-2026-19138.html
https://www.suse.com/security/cve/CVE-2026-19139.html
https://www.suse.com/security/cve/CVE-2026-19140.html
https://www.suse.com/security/cve/CVE-2026-19141.html
https://www.suse.com/security/cve/CVE-2026-19142.html
https://www.suse.com/security/cve/CVE-2026-19143.html
https://www.suse.com/security/cve/CVE-2026-19144.html
https://www.suse.com/security/cve/CVE-2026-19145.html
https://www.suse.com/security/cve/CVE-2026-19146.html
https://www.suse.com/security/cve/CVE-2026-19147.html
https://www.suse.com/security/cve/CVE-2026-19148.html
https://www.suse.com/security/cve/CVE-2026-19149.html
https://www.suse.com/security/cve/CVE-2026-19150.html
https://www.suse.com/security/cve/CVE-2026-19151.html
https://www.suse.com/security/cve/CVE-2026-19152.html
https://www.suse.com/security/cve/CVE-2026-19153.html
https://www.suse.com/security/cve/CVE-2026-19154.html
https://www.suse.com/security/cve/CVE-2026-19155.html
https://www.suse.com/security/cve/CVE-2026-19156.html
https://www.suse.com/security/cve/CVE-2026-19157.html
https://www.suse.com/security/cve/CVE-2026-19158.html
https://www.suse.com/security/cve/CVE-2026-19159.html
https://www.suse.com/security/cve/CVE-2026-19160.html
https://www.suse.com/security/cve/CVE-2026-19161.html
https://www.suse.com/security/cve/CVE-2026-19162.html
https://www.suse.com/security/cve/CVE-2026-19163.html
https://www.suse.com/security/cve/CVE-2026-19164.html
https://www.suse.com/security/cve/CVE-2026-19165.html
https://www.suse.com/security/cve/CVE-2026-19166.html
https://www.suse.com/security/cve/CVE-2026-19167.html
https://www.suse.com/security/cve/CVE-2026-19168.html
https://www.suse.com/security/cve/CVE-2026-19169.html
https://www.suse.com/security/cve/CVE-2026-19170.html
https://www.suse.com/security/cve/CVE-2026-19171.html
https://www.suse.com/security/cve/CVE-2026-19172.html
https://www.suse.com/security/cve/CVE-2026-19173.html
https://www.suse.com/security/cve/CVE-2026-19174.html
https://www.suse.com/security/cve/CVE-2026-19175.html
https://www.suse.com/security/cve/CVE-2026-19176.html
https://www.suse.com/security/cve/CVE-2026-19177.html
https://bugzilla.suse.com/1274549