SUSE-SU-2026:3235-1: important: Security update for glib2
SUSE-SU-2026:3238-1: important: Security update for python-pyasn1
SUSE-SU-2026:3240-1: important: Security update for python-soupsieve
SUSE-SU-2026:3243-1: low: Security update for gpg2
SUSE-SU-2026:3244-1: moderate: Security update for systemd
SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
openSUSE-SU-2026:0263-1: important: Security update for trivy
openSUSE-SU-2026:0264-1: important: Security update for chromium
openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media
openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media
openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media
SUSE-SU-2026:3268-1: important: Security update for python-Pillow
SUSE-SU-2026:3270-1: moderate: Security update for alsa
SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3235-1: important: Security update for glib2
# Security update for glib2
Announcement ID: SUSE-SU-2026:3235-1
Release Date: 2026-07-24T12:42:20Z
Rating: important
References:
* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021
Cross-References:
* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016
CVSS scores:
* CVE-2026-58010 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58012 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves six vulnerabilities can now be installed.
## Description:
This update for glib2 fixes the following issues:
* CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could
cause a 1-byte out-of-bounds read (bsc#1270009).
* CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a
2-byte out-of-bounds read (bsc#1270010).
* CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-
change replacements could cause an out-of- bounds read (bsc#1270016).
* CVE-2026-58013: multi-byte custom line terminator in
g_io_channel_read_line_backend could trigger an out-of-bounds read
(bsc#1270018).
* CVE-2026-58014: processing empty key file values in
g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access
(bsc#1270021).
* CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned
integer overflow (bsc#1270008).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3235=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3235=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3235=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3235=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3235=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3235=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3235=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3235=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3235=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3235=1
## Package List:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* glib2-tests-devel-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* glib2-tests-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-doc-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* glib2-devel-static-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libgmodule-2_0-0-64bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-64bit-2.70.5-150400.3.37.1
* glib2-devel-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-64bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-64bit-2.70.5-150400.3.37.1
* libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-64bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-64bit-2.70.5-150400.3.37.1
* libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-64bit-2.70.5-150400.3.37.1
* libgio-2_0-0-64bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (x86_64)
* libgthread-2_0-0-32bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* glib2-devel-32bit-2.70.5-150400.3.37.1
* glib2-tools-32bit-2.70.5-150400.3.37.1
* glib2-tools-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* glib2-devel-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* gio-branding-upstream-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
## References:
* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html
* https://bugzilla.suse.com/show_bug.cgi?id70008
* https://bugzilla.suse.com/show_bug.cgi?id70009
* https://bugzilla.suse.com/show_bug.cgi?id70010
* https://bugzilla.suse.com/show_bug.cgi?id70016
* https://bugzilla.suse.com/show_bug.cgi?id70018
* https://bugzilla.suse.com/show_bug.cgi?id70021
SUSE-SU-2026:3238-1: important: Security update for python-pyasn1
# Security update for python-pyasn1
Announcement ID: SUSE-SU-2026:3238-1
Release Date: 2026-07-24T12:56:31Z
Rating: important
References:
* bsc#1271464
* bsc#1271465
* bsc#1271466
Cross-References:
* CVE-2026-59884
* CVE-2026-59885
* CVE-2026-59886
CVSS scores:
* CVE-2026-59884 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59884 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59884 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59885 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59885 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59885 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59886 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59886 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59886 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves three vulnerabilities can now be installed.
## Description:
This update for python-pyasn1 fixes the following issues:
* CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long-
form tag IDs (bsc#1271464).
* CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID
processing allows denial of service (bsc#1271465).
* CVE-2026-59886: uncontrolled resource consumption when converting decoded
REAL values (bsc#1271466).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3238=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3238=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3238=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3238=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3238=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3238=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3238=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3238=1
* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3238=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3238=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3238=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3238=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3238=1
## Package List:
* Python 3 Module 15-SP7 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* openSUSE Leap 15.4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* Public Cloud Module 15-SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
## References:
* https://www.suse.com/security/cve/CVE-2026-59884.html
* https://www.suse.com/security/cve/CVE-2026-59885.html
* https://www.suse.com/security/cve/CVE-2026-59886.html
* https://bugzilla.suse.com/show_bug.cgi?id71464
* https://bugzilla.suse.com/show_bug.cgi?id71465
* https://bugzilla.suse.com/show_bug.cgi?id71466
SUSE-SU-2026:3240-1: important: Security update for python-soupsieve
# Security update for python-soupsieve
Announcement ID: SUSE-SU-2026:3240-1
Release Date: 2026-07-24T13:05:20Z
Rating: important
References:
* bsc#1256316
* bsc#1271187
* bsc#1271188
Cross-References:
* CVE-2026-49476
* CVE-2026-49477
CVSS scores:
* CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.6
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves two vulnerabilities and has one security fix can now be
installed.
## Description:
This update for python-soupsieve fixes the following issues
* CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists
(bsc#1271187).
* CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector
Parser (bsc#1271188).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3240=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3240=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3240=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3240=1
## Package List:
* openSUSE Leap 15.6 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* Python 3 Module 15-SP7 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* python311-soupsieve-2.5-150600.3.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-49476.html
* https://www.suse.com/security/cve/CVE-2026-49477.html
* https://bugzilla.suse.com/show_bug.cgi?id56316
* https://bugzilla.suse.com/show_bug.cgi?id71187
* https://bugzilla.suse.com/show_bug.cgi?id71188
SUSE-SU-2026:3243-1: low: Security update for gpg2
# Security update for gpg2
Announcement ID: SUSE-SU-2026:3243-1
Release Date: 2026-07-24T13:09:39Z
Rating: low
References:
* bsc#1269279
Cross-References:
* CVE-2026-57062
CVSS scores:
* CVE-2026-57062 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for gpg2 fixes the following issue:
* CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM
(bsc#1269279).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3243=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3243=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* gpg2-debugsource-2.4.4-150600.3.18.1
* gpg2-tpm-debuginfo-2.4.4-150600.3.18.1
* gpg2-2.4.4-150600.3.18.1
* dirmngr-debuginfo-2.4.4-150600.3.18.1
* dirmngr-2.4.4-150600.3.18.1
* gpg2-debuginfo-2.4.4-150600.3.18.1
* gpg2-tpm-2.4.4-150600.3.18.1
* openSUSE Leap 15.6 (noarch)
* gpg2-lang-2.4.4-150600.3.18.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* gpg2-debugsource-2.4.4-150600.3.18.1
* gpg2-2.4.4-150600.3.18.1
* dirmngr-debuginfo-2.4.4-150600.3.18.1
* dirmngr-2.4.4-150600.3.18.1
* gpg2-debuginfo-2.4.4-150600.3.18.1
* Basesystem Module 15-SP7 (noarch)
* gpg2-lang-2.4.4-150600.3.18.1
## References:
* https://www.suse.com/security/cve/CVE-2026-57062.html
* https://bugzilla.suse.com/show_bug.cgi?id69279
SUSE-SU-2026:3244-1: moderate: Security update for systemd
# Security update for systemd
Announcement ID: SUSE-SU-2026:3244-1
Release Date: 2026-07-24T13:11:41Z
Rating: moderate
References:
* bsc#1261400
* bsc#1261982
* bsc#1261983
* bsc#1262305
* bsc#1267644
* bsc#1267647
Cross-References:
* CVE-2026-40226
CVSS scores:
* CVE-2026-40226 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves one vulnerability and has five security fixes can now be
installed.
## Description:
This update for systemd fixes the following issues:
Security issues fixed:
* CVE-2026-40226: nspawn: escape-to-host via malformed optional config file
(bsc#1261400).
Other updates and bugfixes:
* Fix soft reboot not restarting user services with default.target
(bsc#1262305).
* Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
* Import commit 429043ca9a (bsc#1261982 bsc#1261983).
* Import commit 58e5d2e21e (bsc#1261982).
* Import commit 4bd91117cc (bsc#1261983).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3244=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3244=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3244=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libudev-mini1-debuginfo-254.27-150600.4.71.1
* systemd-sysvcompat-debuginfo-254.27-150600.4.71.2
* systemd-mini-254.27-150600.4.71.1
* systemd-network-254.27-150600.4.71.2
* systemd-testsuite-254.27-150600.4.71.2
* systemd-254.27-150600.4.71.2
* systemd-resolved-debuginfo-254.27-150600.4.71.2
* libsystemd0-debuginfo-254.27-150600.4.71.2
* systemd-doc-254.27-150600.4.71.2
* udev-254.27-150600.4.71.2
* systemd-journal-remote-debuginfo-254.27-150600.4.71.2
* systemd-networkd-254.27-150600.4.71.2
* udev-mini-debuginfo-254.27-150600.4.71.1
* libudev1-debuginfo-254.27-150600.4.71.2
* systemd-debugsource-254.27-150600.4.71.2
* systemd-homed-debuginfo-254.27-150600.4.71.2
* systemd-networkd-debuginfo-254.27-150600.4.71.2
* systemd-mini-debuginfo-254.27-150600.4.71.1
* systemd-mini-container-debuginfo-254.27-150600.4.71.1
* libsystemd0-254.27-150600.4.71.2
* udev-mini-254.27-150600.4.71.1
* libudev1-254.27-150600.4.71.2
* systemd-experimental-debuginfo-254.27-150600.4.71.2
* systemd-mini-devel-254.27-150600.4.71.1
* libudev-mini1-254.27-150600.4.71.1
* systemd-debuginfo-254.27-150600.4.71.2
* libsystemd0-mini-debuginfo-254.27-150600.4.71.1
* systemd-coredump-debuginfo-254.27-150600.4.71.2
* systemd-testsuite-debuginfo-254.27-150600.4.71.2
* systemd-container-254.27-150600.4.71.2
* systemd-experimental-254.27-150600.4.71.2
* systemd-portable-debuginfo-254.27-150600.4.71.2
* libsystemd0-mini-254.27-150600.4.71.1
* systemd-portable-254.27-150600.4.71.2
* systemd-mini-debugsource-254.27-150600.4.71.1
* systemd-journal-remote-254.27-150600.4.71.2
* systemd-coredump-254.27-150600.4.71.2
* systemd-mini-container-254.27-150600.4.71.1
* systemd-resolved-254.27-150600.4.71.2
* systemd-container-debuginfo-254.27-150600.4.71.2
* systemd-homed-254.27-150600.4.71.2
* udev-debuginfo-254.27-150600.4.71.2
* systemd-devel-254.27-150600.4.71.2
* systemd-sysvcompat-254.27-150600.4.71.2
* openSUSE Leap 15.6 (x86_64)
* libudev1-32bit-254.27-150600.4.71.2
* libsystemd0-32bit-debuginfo-254.27-150600.4.71.2
* libudev1-32bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-32bit-254.27-150600.4.71.2
* systemd-32bit-254.27-150600.4.71.2
* systemd-devel-32bit-254.27-150600.4.71.2
* systemd-32bit-debuginfo-254.27-150600.4.71.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libudev1-64bit-254.27-150600.4.71.2
* systemd-64bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-64bit-debuginfo-254.27-150600.4.71.2
* systemd-devel-64bit-254.27-150600.4.71.2
* libsystemd0-64bit-254.27-150600.4.71.2
* libudev1-64bit-debuginfo-254.27-150600.4.71.2
* systemd-64bit-254.27-150600.4.71.2
* openSUSE Leap 15.6 (aarch64 i586 x86_64)
* systemd-boot-254.27-150600.4.71.2
* systemd-boot-debuginfo-254.27-150600.4.71.2
* openSUSE Leap 15.6 (noarch)
* systemd-lang-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* systemd-sysvcompat-debuginfo-254.27-150600.4.71.2
* systemd-doc-254.27-150600.4.71.2
* libsystemd0-debuginfo-254.27-150600.4.71.2
* systemd-resolved-debuginfo-254.27-150600.4.71.2
* systemd-254.27-150600.4.71.2
* udev-254.27-150600.4.71.2
* systemd-journal-remote-debuginfo-254.27-150600.4.71.2
* libudev1-debuginfo-254.27-150600.4.71.2
* systemd-debugsource-254.27-150600.4.71.2
* libsystemd0-254.27-150600.4.71.2
* libudev1-254.27-150600.4.71.2
* systemd-debuginfo-254.27-150600.4.71.2
* systemd-coredump-debuginfo-254.27-150600.4.71.2
* systemd-container-254.27-150600.4.71.2
* systemd-journal-remote-254.27-150600.4.71.2
* systemd-coredump-254.27-150600.4.71.2
* systemd-resolved-254.27-150600.4.71.2
* systemd-container-debuginfo-254.27-150600.4.71.2
* udev-debuginfo-254.27-150600.4.71.2
* systemd-devel-254.27-150600.4.71.2
* systemd-sysvcompat-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (noarch)
* systemd-lang-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (x86_64)
* libudev1-32bit-254.27-150600.4.71.2
* libsystemd0-32bit-debuginfo-254.27-150600.4.71.2
* libudev1-32bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-32bit-254.27-150600.4.71.2
* systemd-32bit-254.27-150600.4.71.2
* systemd-32bit-debuginfo-254.27-150600.4.71.2
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* systemd-debugsource-254.27-150600.4.71.2
* systemd-debuginfo-254.27-150600.4.71.2
* systemd-network-254.27-150600.4.71.2
* systemd-networkd-debuginfo-254.27-150600.4.71.2
* systemd-networkd-254.27-150600.4.71.2
## References:
* https://www.suse.com/security/cve/CVE-2026-40226.html
* https://bugzilla.suse.com/show_bug.cgi?id61400
* https://bugzilla.suse.com/show_bug.cgi?id61982
* https://bugzilla.suse.com/show_bug.cgi?id61983
* https://bugzilla.suse.com/show_bug.cgi?id62305
* https://bugzilla.suse.com/show_bug.cgi?id67644
* https://bugzilla.suse.com/show_bug.cgi?id67647
SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
# Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise
15 SP6)
Announcement ID: SUSE-SU-2026:3254-1
Release Date: 2026-07-26T18:33:35Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves six vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.109 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3254=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3254=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
# Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise
15 SP7)
Announcement ID: SUSE-SU-2026:3256-1
Release Date: 2026-07-27T07:33:42Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.52 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3260=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3256=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3255=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3258=1
SUSE-SLE-Module-Live-Patching-15-SP6-2026-3257=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3259=1
* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3263=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3256=1 SUSE-2026-3255=1 SUSE-2026-3258=1
SUSE-2026-3257=1 SUSE-2026-3259=1 SUSE-2026-3260=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP7_Update_14-debugsource-4-150700.2.1
* kernel-livepatch-6_4_0-150700_53_52-default-debuginfo-4-150700.2.1
* kernel-livepatch-6_4_0-150700_53_52-default-4-150700.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648
openSUSE-SU-2026:0263-1: important: Security update for trivy
openSUSE Security Update: Security update for trivy
_______________________________
Announcement ID: openSUSE-SU-2026:0263-1
Rating: important
References: #1266495 #1268356 #1269269 #1269271 #1271658
#1271670
Cross-References: CVE-2026-39821 CVE-2026-46680 CVE-2026-50151
CVE-2026-54448 CVE-2026-55092 CVE-2026-56852
CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-46680 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-50151 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2026-54448 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-55092 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-56852 (SUSE): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes 6 vulnerabilities is now available.
Description:
This update for trivy fixes the following issues:
- Update embedded dependencies:
* update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)
* update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)
* update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)
- Update trivy to version 0.72.0:
* release: v0.72.0 [main] (#10782)
* test: close plugin manager in tests cleanup (#10904)
* Merge commit from fork
* feat(bottlerocket): add vulnerability matching for Bottlerocket OS
(#10893)
* fix(misconf): support github_repository_vulnerability_alerts resource
(#10680)
* feat(java): detect JAR licenses from packaged LICENSE files (#10856)
* fix(nodejs): parse project dependencies from multi-document
pnpm-lock.yaml (#10861)
* fix(server): propagate package repository class in client/server mode
(#10874)
* chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to
2.3.2 (#10888)
* fix(vuln): fall back to UNKNOWN severity when vulnerability details
are missing (#10795)
* feat(java): detect JAR licenses from the embedded pom.xml (#10851)
* chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
* ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2
(#10873)
* chore(deps): bump alpine to 3.24.1 (#10868)
* docs: fix article typo in plugin developer guide (#10860)
* feat(misconf): Adds CloudFront standard logging v2 support to
AVD-AWS-0010 (#10848)
* docs: fix typos (#10857)
* fix(terraform): avoid data race on global getter.Getters in remote
module resolver (#10843)
* feat(secret): support new stateless format for GitHub App installation
tokens (#10826)
* fix: correct format verbs in diagnostic messages (#10805)
* ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1
(#10845)
* refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist
(#10830)
* docs: fix repository scan heading typo (#10828)
* Merge commit from fork
* fix: forward ospkg detector options through ospkg.NewScanner (#10811)
* chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
* fix(vex): load VEX documents from within the repository directory
(#10820)
* ci!: migrate docker config to dockers_v2 (#10783)
* feat(dotnet): detect bundled runtime in self-contained deployments
(#10786)
* feat(secret): add OpenAI secret detection rules (#10798)
* ci: expect GitHub App bot as backport PR author (#10813)
* fix: surface the original analysis error instead of context
cancellation (#10793)
* chore(deps): bump the github-actions group across 1 directory with 11
updates (#10803)
* chore(deps): bump the common group with 4 updates (#10797)
* chore(deps): bump the aws group with 4 updates (#10796)
* fix: use random suffix for process temp directory instead of PID
(#10431)
* docs: update signature verification for deb and rpm packages (#10784)
* fix(image): lookup origin layer for custom resources in merged layers
(#10788)
* test: fix flaky containerd integration test (#10760)
* ci: bump GoReleaser to v2.16.0 (#10774)
* docs: fix broken nixpkgs reference link in installation guide (#10776)
* test(java): force offline-scan for client/server integration tests
(#10721)
* fix(image): deterministic OS package deduplication for images with
embedded SBOMs (#10777)
* fix(spdx): guard against nil root component in SPDX marshaler (#10771)
* ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0
(#10768)
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-263=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
trivy-0.72.0-bp157.2.15.1
References:
https://www.suse.com/security/cve/CVE-2026-39821.html
https://www.suse.com/security/cve/CVE-2026-46680.html
https://www.suse.com/security/cve/CVE-2026-50151.html
https://www.suse.com/security/cve/CVE-2026-54448.html
https://www.suse.com/security/cve/CVE-2026-55092.html
https://www.suse.com/security/cve/CVE-2026-56852.html
https://bugzilla.suse.com/1266495
https://bugzilla.suse.com/1268356
https://bugzilla.suse.com/1269269
https://bugzilla.suse.com/1269271
https://bugzilla.suse.com/1271658
https://bugzilla.suse.com/1271670
openSUSE-SU-2026:0264-1: important: Security update for chromium
openSUSE Security Update: Security update for chromium
_______________________________
Announcement ID: openSUSE-SU-2026:0264-1
Rating: important
References: #1272460
Cross-References: CVE-2026-16804 CVE-2026-16805 CVE-2026-16806
CVE-2026-16807
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes four vulnerabilities is now available.
Description:
This update for chromium fixes the following issues:
- Chromium 150.0.7871.186 (boo#1272460):
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-264=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):
chromedriver-150.0.7871.186-bp157.2.196.1
chromium-150.0.7871.186-bp157.2.196.1
References:
https://www.suse.com/security/cve/CVE-2026-16804.html
https://www.suse.com/security/cve/CVE-2026-16805.html
https://www.suse.com/security/cve/CVE-2026-16806.html
https://www.suse.com/security/cve/CVE-2026-16807.html
https://bugzilla.suse.com/1272460
openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media
# mcphost-0.34.0-9.1 on GA media
Announcement ID: openSUSE-SU-2026:11366-1
Rating: moderate
Cross-References:
* CVE-2026-5160
* CVE-2026-56852
CVSS scores:
* CVE-2026-5160 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 2 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the mcphost-0.34.0-9.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* mcphost 0.34.0-9.1
* mcphost-bash-completion 0.34.0-9.1
* mcphost-fish-completion 0.34.0-9.1
* mcphost-zsh-completion 0.34.0-9.1
## References:
* https://www.suse.com/security/cve/CVE-2026-5160.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media
# opennlp-1.9.5-2.1 on GA media
Announcement ID: openSUSE-SU-2026:11369-1
Rating: moderate
Cross-References:
* CVE-2026-63317
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the opennlp-1.9.5-2.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* opennlp 1.9.5-2.1
* opennlp-morfologik-addon 1.9.5-2.1
* opennlp-tools 1.9.5-2.1
* opennlp-uima 1.9.5-2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-63317.html
openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media
# libknet-devel-1.33-2.1 on GA media
Announcement ID: openSUSE-SU-2026:11364-1
Rating: moderate
Cross-References:
* CVE-2026-15811
* CVE-2026-15812
* CVE-2026-15813
CVSS scores:
* CVE-2026-15811 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
* CVE-2026-15812 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-15813 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Products:
* openSUSE Tumbleweed
An update that solves 3 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the libknet-devel-1.33-2.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* libknet-devel 1.33-2.1
* libknet1 1.33-2.1
* libknet1-compress-bzip2-plugin 1.33-2.1
* libknet1-compress-lz4-plugin 1.33-2.1
* libknet1-compress-lzma-plugin 1.33-2.1
* libknet1-compress-lzo2-plugin 1.33-2.1
* libknet1-compress-plugins-all 1.33-2.1
* libknet1-compress-zlib-plugin 1.33-2.1
* libknet1-compress-zstd-plugin 1.33-2.1
* libknet1-crypto-nss-plugin 1.33-2.1
* libknet1-crypto-openssl-plugin 1.33-2.1
* libknet1-crypto-plugins-all 1.33-2.1
* libknet1-plugins-all 1.33-2.1
* libnozzle-devel 1.33-2.1
* libnozzle1 1.33-2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15811.html
* https://www.suse.com/security/cve/CVE-2026-15812.html
* https://www.suse.com/security/cve/CVE-2026-15813.html
SUSE-SU-2026:3268-1: important: Security update for python-Pillow
# Security update for python-Pillow
Announcement ID: SUSE-SU-2026:3268-1
Release Date: 2026-07-27T10:59:26Z
Rating: important
References:
* bsc#1270409
* bsc#1270410
* bsc#1270411
* bsc#1270412
* bsc#1271418
* bsc#1271419
* bsc#1271420
* bsc#1271421
* bsc#1271422
* bsc#1271424
* bsc#1271425
Cross-References:
* CVE-2026-54058
* CVE-2026-54059
* CVE-2026-54060
* CVE-2026-55379
* CVE-2026-55380
* CVE-2026-59197
* CVE-2026-59198
* CVE-2026-59199
* CVE-2026-59200
* CVE-2026-59204
* CVE-2026-59205
CVSS scores:
* CVE-2026-54058 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-54058 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59197 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59198 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-59199 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59200 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59204 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59204 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59205 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves 11 vulnerabilities can now be installed.
## Description:
This update for python-Pillow fixes the following issues:
* CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on
`mmap` path (bsc#1271419).
* CVE-2026-54059: bomb protection bypass via PCF font loading due to
`Image.frombytes()` being called without `_decompression_bomb_check()`
(bsc#1270409).
* CVE-2026-54060: excessive allocation due to `FontFile.compile()`:
`Image.new()` being called without `_decompression_bomb_check()`
(bsc#1270410).
* CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()`
being called without `_decompression_bomb_check()` (bsc#1270411).
* CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions
being accepted without `_decompression_bomb_check()` in
`GdImageFile._open()` (bsc#1270412).
* CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via
integer overflow in `ImagingExpand` (bsc#1271418).
* CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA
RLE encoder (bsc#1271420).
* CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and
`Image.crop()` via signed coordinate overflow (bsc#1271421).
* CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()`
(bsc#1271422).
* CVE-2026-59204: denial of service through memory exhaustion via JPEG2000
tiled decoder (bsc#1271424).
* CVE-2026-59205: controlled heap out-of-bounds write in
`ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3268=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3268=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3268=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3268=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3268=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3268=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3268=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3268=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3268=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3268=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3268=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3268=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
## References:
* https://www.suse.com/security/cve/CVE-2026-54058.html
* https://www.suse.com/security/cve/CVE-2026-54059.html
* https://www.suse.com/security/cve/CVE-2026-54060.html
* https://www.suse.com/security/cve/CVE-2026-55379.html
* https://www.suse.com/security/cve/CVE-2026-55380.html
* https://www.suse.com/security/cve/CVE-2026-59197.html
* https://www.suse.com/security/cve/CVE-2026-59198.html
* https://www.suse.com/security/cve/CVE-2026-59199.html
* https://www.suse.com/security/cve/CVE-2026-59200.html
* https://www.suse.com/security/cve/CVE-2026-59204.html
* https://www.suse.com/security/cve/CVE-2026-59205.html
* https://bugzilla.suse.com/show_bug.cgi?id70409
* https://bugzilla.suse.com/show_bug.cgi?id70410
* https://bugzilla.suse.com/show_bug.cgi?id70411
* https://bugzilla.suse.com/show_bug.cgi?id70412
* https://bugzilla.suse.com/show_bug.cgi?id71418
* https://bugzilla.suse.com/show_bug.cgi?id71419
* https://bugzilla.suse.com/show_bug.cgi?id71420
* https://bugzilla.suse.com/show_bug.cgi?id71421
* https://bugzilla.suse.com/show_bug.cgi?id71422
* https://bugzilla.suse.com/show_bug.cgi?id71424
* https://bugzilla.suse.com/show_bug.cgi?id71425
SUSE-SU-2026:3270-1: moderate: Security update for alsa
# Security update for alsa
Announcement ID: SUSE-SU-2026:3270-1
Release Date: 2026-07-27T11:01:30Z
Rating: moderate
References:
* bsc#1268853
Cross-References:
* CVE-2026-56109
CVSS scores:
* CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-56109 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for alsa fixes the following issue
* CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that
can allow attackers to corrupt memory (bsc#1268853).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3270=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3270=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le x86_64)
* libatopology2-debuginfo-1.2.10-150600.4.3.1
* alsa-topology-devel-1.2.10-150600.4.3.1
* libatopology2-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* alsa-debugsource-1.2.10-150600.4.3.1
* libasound2-debuginfo-1.2.10-150600.4.3.1
* alsa-1.2.10-150600.4.3.1
* libasound2-1.2.10-150600.4.3.1
* alsa-devel-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libatopology2-64bit-1.2.10-150600.4.3.1
* alsa-topology-devel-64bit-1.2.10-150600.4.3.1
* libasound2-64bit-1.2.10-150600.4.3.1
* libatopology2-64bit-debuginfo-1.2.10-150600.4.3.1
* alsa-devel-64bit-1.2.10-150600.4.3.1
* libasound2-64bit-debuginfo-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (noarch)
* alsa-docs-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (x86_64)
* libatopology2-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-debuginfo-1.2.10-150600.4.3.1
* libatopology2-32bit-debuginfo-1.2.10-150600.4.3.1
* alsa-topology-devel-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-1.2.10-150600.4.3.1
* alsa-devel-32bit-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* alsa-debugsource-1.2.10-150600.4.3.1
* libasound2-debuginfo-1.2.10-150600.4.3.1
* alsa-1.2.10-150600.4.3.1
* libasound2-1.2.10-150600.4.3.1
* alsa-devel-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le x86_64)
* libatopology2-debuginfo-1.2.10-150600.4.3.1
* libatopology2-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (x86_64)
* libasound2-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-debuginfo-1.2.10-150600.4.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56109.html
* https://bugzilla.suse.com/show_bug.cgi?id68853
SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)
# Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise
15 SP5)
Announcement ID: SUSE-SU-2026:3289-1
Release Date: 2026-07-27T15:36:28Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves five vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.116 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3289=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3295=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3293=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3287=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3292=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3296=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3294=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3280=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3279=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3288=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3290=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3289=1 SUSE-2026-3295=1 SUSE-2026-3293=1
SUSE-2026-3287=1 SUSE-2026-3292=1 SUSE-2026-3296=1 SUSE-2026-3294=1
SUSE-2026-3280=1 SUSE-2026-3279=1 SUSE-2026-3288=1 SUSE-2026-3290=1
## Package List:
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x)
* kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648