SUSE 5611 Published by

Two security advisories have been released for openSUSE Tumbleweed addressing moderate vulnerabilities within specific system packages. The first notice details a fix for corosync that resolves CVE-2026-35091 and raises the package version to 3.1.10-4.1 on GA media. A second advisory covers libinput components by patching two distinct issues labeled as CVE-2026-35093 and CVE-2026-35094.

openSUSE-SU-2026:10488-1: moderate: corosync-3.1.10-4.1 on GA media
openSUSE-SU-2026:10489-1: moderate: libinput-devel-1.31.1-1.1 on GA media




openSUSE-SU-2026:10488-1: moderate: corosync-3.1.10-4.1 on GA media


# corosync-3.1.10-4.1 on GA media

Announcement ID: openSUSE-SU-2026:10488-1
Rating: moderate

Cross-References:

* CVE-2026-35091

CVSS scores:

* CVE-2026-35091 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-35091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the corosync-3.1.10-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* corosync 3.1.10-4.1
* corosync-devel 3.1.10-4.1
* corosync-libs 3.1.10-4.1

## References:

* https://www.suse.com/security/cve/CVE-2026-35091.html



openSUSE-SU-2026:10489-1: moderate: libinput-devel-1.31.1-1.1 on GA media


# libinput-devel-1.31.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:10489-1
Rating: moderate

Cross-References:

* CVE-2026-35093
* CVE-2026-35094

CVSS scores:

* CVE-2026-35093 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-35093 ( SUSE ): 6.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-35094 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-35094 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libinput-devel-1.31.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libinput-devel 1.31.1-1.1
* libinput-tools 1.31.1-1.1
* libinput-udev 1.31.1-1.1
* libinput10 1.31.1-1.1
* libinput10-32bit 1.31.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-35093.html
* https://www.suse.com/security/cve/CVE-2026-35094.html