SUSE 5721 Published by

SUSE released a batch of security advisories addressing critical vulnerabilities across multiple core system libraries and applications. Patches target glib2, python-Pillow, Chromium, systemd, and the Linux kernel for SUSE Enterprise versions 15 SP5 through SP7 to resolve out-of-bounds memory access issues, denial-of-service flaws, and use-after-free conditions linked to over a dozen CVE identifiers. Most advisories carry an important rating, with kernel live patches addressing high-severity memory corruption and network stack flaws that demand immediate deployment on production infrastructure. Administrators should apply these updates through YaST or zypper patch to restore system integrity across openSUSE Leap releases and SUSE Linux Enterprise deployments without disrupting running workloads for live-patched components.

SUSE-SU-2026:3235-1: important: Security update for glib2
SUSE-SU-2026:3238-1: important: Security update for python-pyasn1
SUSE-SU-2026:3240-1: important: Security update for python-soupsieve
SUSE-SU-2026:3243-1: low: Security update for gpg2
SUSE-SU-2026:3244-1: moderate: Security update for systemd
SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)
openSUSE-SU-2026:0263-1: important: Security update for trivy
openSUSE-SU-2026:0264-1: important: Security update for chromium
openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media
openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media
openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media
SUSE-SU-2026:3268-1: important: Security update for python-Pillow
SUSE-SU-2026:3270-1: moderate: Security update for alsa
SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)




SUSE-SU-2026:3235-1: important: Security update for glib2


# Security update for glib2

Announcement ID: SUSE-SU-2026:3235-1
Release Date: 2026-07-24T12:42:20Z
Rating: important
References:

* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021

Cross-References:

* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016

CVSS scores:

* CVE-2026-58010 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58012 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves six vulnerabilities can now be installed.

## Description:

This update for glib2 fixes the following issues:

* CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could
cause a 1-byte out-of-bounds read (bsc#1270009).
* CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a
2-byte out-of-bounds read (bsc#1270010).
* CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-
change replacements could cause an out-of- bounds read (bsc#1270016).
* CVE-2026-58013: multi-byte custom line terminator in
g_io_channel_read_line_backend could trigger an out-of-bounds read
(bsc#1270018).
* CVE-2026-58014: processing empty key file values in
g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access
(bsc#1270021).
* CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned
integer overflow (bsc#1270008).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3235=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3235=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3235=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3235=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3235=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3235=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3235=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3235=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3235=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3235=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3235=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3235=1

## Package List:

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* glib2-tests-devel-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* glib2-tests-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-doc-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* glib2-devel-static-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libgmodule-2_0-0-64bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-64bit-2.70.5-150400.3.37.1
* glib2-devel-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-64bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-64bit-2.70.5-150400.3.37.1
* libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-64bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-64bit-2.70.5-150400.3.37.1
* libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-64bit-2.70.5-150400.3.37.1
* libgio-2_0-0-64bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (x86_64)
* libgthread-2_0-0-32bit-2.70.5-150400.3.37.1
* libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* glib2-devel-32bit-2.70.5-150400.3.37.1
* glib2-tools-32bit-2.70.5-150400.3.37.1
* glib2-tools-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* glib2-devel-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* openSUSE Leap 15.4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* gio-branding-upstream-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* glib2-tools-debuginfo-2.70.5-150400.3.37.1
* glib2-debugsource-2.70.5-150400.3.37.1
* libglib-2_0-0-2.70.5-150400.3.37.1
* libgmodule-2_0-0-2.70.5-150400.3.37.1
* libgio-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-2.70.5-150400.3.37.1
* libgthread-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgmodule-2_0-0-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-debuginfo-2.70.5-150400.3.37.1
* glib2-tools-2.70.5-150400.3.37.1
* glib2-devel-debuginfo-2.70.5-150400.3.37.1
* glib2-devel-2.70.5-150400.3.37.1
* libgio-2_0-0-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* libgmodule-2_0-0-32bit-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-2.70.5-150400.3.37.1
* libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-2.70.5-150400.3.37.1
* libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.37.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* glib2-lang-2.70.5-150400.3.37.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html
* https://bugzilla.suse.com/show_bug.cgi?id70008
* https://bugzilla.suse.com/show_bug.cgi?id70009
* https://bugzilla.suse.com/show_bug.cgi?id70010
* https://bugzilla.suse.com/show_bug.cgi?id70016
* https://bugzilla.suse.com/show_bug.cgi?id70018
* https://bugzilla.suse.com/show_bug.cgi?id70021



SUSE-SU-2026:3238-1: important: Security update for python-pyasn1


# Security update for python-pyasn1

Announcement ID: SUSE-SU-2026:3238-1
Release Date: 2026-07-24T12:56:31Z
Rating: important
References:

* bsc#1271464
* bsc#1271465
* bsc#1271466

Cross-References:

* CVE-2026-59884
* CVE-2026-59885
* CVE-2026-59886

CVSS scores:

* CVE-2026-59884 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59884 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59884 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59885 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59885 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59885 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59886 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59886 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59886 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves three vulnerabilities can now be installed.

## Description:

This update for python-pyasn1 fixes the following issues:

* CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long-
form tag IDs (bsc#1271464).
* CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID
processing allows denial of service (bsc#1271465).
* CVE-2026-59886: uncontrolled resource consumption when converting decoded
REAL values (bsc#1271466).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3238=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3238=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3238=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3238=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3238=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3238=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3238=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3238=1

* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3238=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3238=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3238=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3238=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3238=1

## Package List:

* Python 3 Module 15-SP7 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* openSUSE Leap 15.4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* Public Cloud Module 15-SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* python311-pyasn1-0.5.0-150400.12.16.1

## References:

* https://www.suse.com/security/cve/CVE-2026-59884.html
* https://www.suse.com/security/cve/CVE-2026-59885.html
* https://www.suse.com/security/cve/CVE-2026-59886.html
* https://bugzilla.suse.com/show_bug.cgi?id71464
* https://bugzilla.suse.com/show_bug.cgi?id71465
* https://bugzilla.suse.com/show_bug.cgi?id71466



SUSE-SU-2026:3240-1: important: Security update for python-soupsieve


# Security update for python-soupsieve

Announcement ID: SUSE-SU-2026:3240-1
Release Date: 2026-07-24T13:05:20Z
Rating: important
References:

* bsc#1256316
* bsc#1271187
* bsc#1271188

Cross-References:

* CVE-2026-49476
* CVE-2026-49477

CVSS scores:

* CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.6
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves two vulnerabilities and has one security fix can now be
installed.

## Description:

This update for python-soupsieve fixes the following issues

* CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists
(bsc#1271187).
* CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector
Parser (bsc#1271188).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3240=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3240=1

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3240=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3240=1

## Package List:

* openSUSE Leap 15.6 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* Python 3 Module 15-SP7 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* python311-soupsieve-2.5-150600.3.3.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* python311-soupsieve-2.5-150600.3.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-49476.html
* https://www.suse.com/security/cve/CVE-2026-49477.html
* https://bugzilla.suse.com/show_bug.cgi?id56316
* https://bugzilla.suse.com/show_bug.cgi?id71187
* https://bugzilla.suse.com/show_bug.cgi?id71188



SUSE-SU-2026:3243-1: low: Security update for gpg2


# Security update for gpg2

Announcement ID: SUSE-SU-2026:3243-1
Release Date: 2026-07-24T13:09:39Z
Rating: low
References:

* bsc#1269279

Cross-References:

* CVE-2026-57062

CVSS scores:

* CVE-2026-57062 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57062 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-57062 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for gpg2 fixes the following issue:

* CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM
(bsc#1269279).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3243=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3243=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* gpg2-debugsource-2.4.4-150600.3.18.1
* gpg2-tpm-debuginfo-2.4.4-150600.3.18.1
* gpg2-2.4.4-150600.3.18.1
* dirmngr-debuginfo-2.4.4-150600.3.18.1
* dirmngr-2.4.4-150600.3.18.1
* gpg2-debuginfo-2.4.4-150600.3.18.1
* gpg2-tpm-2.4.4-150600.3.18.1
* openSUSE Leap 15.6 (noarch)
* gpg2-lang-2.4.4-150600.3.18.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* gpg2-debugsource-2.4.4-150600.3.18.1
* gpg2-2.4.4-150600.3.18.1
* dirmngr-debuginfo-2.4.4-150600.3.18.1
* dirmngr-2.4.4-150600.3.18.1
* gpg2-debuginfo-2.4.4-150600.3.18.1
* Basesystem Module 15-SP7 (noarch)
* gpg2-lang-2.4.4-150600.3.18.1

## References:

* https://www.suse.com/security/cve/CVE-2026-57062.html
* https://bugzilla.suse.com/show_bug.cgi?id69279



SUSE-SU-2026:3244-1: moderate: Security update for systemd


# Security update for systemd

Announcement ID: SUSE-SU-2026:3244-1
Release Date: 2026-07-24T13:11:41Z
Rating: moderate
References:

* bsc#1261400
* bsc#1261982
* bsc#1261983
* bsc#1262305
* bsc#1267644
* bsc#1267647

Cross-References:

* CVE-2026-40226

CVSS scores:

* CVE-2026-40226 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability and has five security fixes can now be
installed.

## Description:

This update for systemd fixes the following issues:

Security issues fixed:

* CVE-2026-40226: nspawn: escape-to-host via malformed optional config file
(bsc#1261400).

Other updates and bugfixes:

* Fix soft reboot not restarting user services with default.target
(bsc#1262305).
* Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
* Import commit 429043ca9a (bsc#1261982 bsc#1261983).
* Import commit 58e5d2e21e (bsc#1261982).
* Import commit 4bd91117cc (bsc#1261983).

## Special Instructions and Notes:

* Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3244=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3244=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3244=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libudev-mini1-debuginfo-254.27-150600.4.71.1
* systemd-sysvcompat-debuginfo-254.27-150600.4.71.2
* systemd-mini-254.27-150600.4.71.1
* systemd-network-254.27-150600.4.71.2
* systemd-testsuite-254.27-150600.4.71.2
* systemd-254.27-150600.4.71.2
* systemd-resolved-debuginfo-254.27-150600.4.71.2
* libsystemd0-debuginfo-254.27-150600.4.71.2
* systemd-doc-254.27-150600.4.71.2
* udev-254.27-150600.4.71.2
* systemd-journal-remote-debuginfo-254.27-150600.4.71.2
* systemd-networkd-254.27-150600.4.71.2
* udev-mini-debuginfo-254.27-150600.4.71.1
* libudev1-debuginfo-254.27-150600.4.71.2
* systemd-debugsource-254.27-150600.4.71.2
* systemd-homed-debuginfo-254.27-150600.4.71.2
* systemd-networkd-debuginfo-254.27-150600.4.71.2
* systemd-mini-debuginfo-254.27-150600.4.71.1
* systemd-mini-container-debuginfo-254.27-150600.4.71.1
* libsystemd0-254.27-150600.4.71.2
* udev-mini-254.27-150600.4.71.1
* libudev1-254.27-150600.4.71.2
* systemd-experimental-debuginfo-254.27-150600.4.71.2
* systemd-mini-devel-254.27-150600.4.71.1
* libudev-mini1-254.27-150600.4.71.1
* systemd-debuginfo-254.27-150600.4.71.2
* libsystemd0-mini-debuginfo-254.27-150600.4.71.1
* systemd-coredump-debuginfo-254.27-150600.4.71.2
* systemd-testsuite-debuginfo-254.27-150600.4.71.2
* systemd-container-254.27-150600.4.71.2
* systemd-experimental-254.27-150600.4.71.2
* systemd-portable-debuginfo-254.27-150600.4.71.2
* libsystemd0-mini-254.27-150600.4.71.1
* systemd-portable-254.27-150600.4.71.2
* systemd-mini-debugsource-254.27-150600.4.71.1
* systemd-journal-remote-254.27-150600.4.71.2
* systemd-coredump-254.27-150600.4.71.2
* systemd-mini-container-254.27-150600.4.71.1
* systemd-resolved-254.27-150600.4.71.2
* systemd-container-debuginfo-254.27-150600.4.71.2
* systemd-homed-254.27-150600.4.71.2
* udev-debuginfo-254.27-150600.4.71.2
* systemd-devel-254.27-150600.4.71.2
* systemd-sysvcompat-254.27-150600.4.71.2
* openSUSE Leap 15.6 (x86_64)
* libudev1-32bit-254.27-150600.4.71.2
* libsystemd0-32bit-debuginfo-254.27-150600.4.71.2
* libudev1-32bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-32bit-254.27-150600.4.71.2
* systemd-32bit-254.27-150600.4.71.2
* systemd-devel-32bit-254.27-150600.4.71.2
* systemd-32bit-debuginfo-254.27-150600.4.71.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libudev1-64bit-254.27-150600.4.71.2
* systemd-64bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-64bit-debuginfo-254.27-150600.4.71.2
* systemd-devel-64bit-254.27-150600.4.71.2
* libsystemd0-64bit-254.27-150600.4.71.2
* libudev1-64bit-debuginfo-254.27-150600.4.71.2
* systemd-64bit-254.27-150600.4.71.2
* openSUSE Leap 15.6 (aarch64 i586 x86_64)
* systemd-boot-254.27-150600.4.71.2
* systemd-boot-debuginfo-254.27-150600.4.71.2
* openSUSE Leap 15.6 (noarch)
* systemd-lang-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* systemd-sysvcompat-debuginfo-254.27-150600.4.71.2
* systemd-doc-254.27-150600.4.71.2
* libsystemd0-debuginfo-254.27-150600.4.71.2
* systemd-resolved-debuginfo-254.27-150600.4.71.2
* systemd-254.27-150600.4.71.2
* udev-254.27-150600.4.71.2
* systemd-journal-remote-debuginfo-254.27-150600.4.71.2
* libudev1-debuginfo-254.27-150600.4.71.2
* systemd-debugsource-254.27-150600.4.71.2
* libsystemd0-254.27-150600.4.71.2
* libudev1-254.27-150600.4.71.2
* systemd-debuginfo-254.27-150600.4.71.2
* systemd-coredump-debuginfo-254.27-150600.4.71.2
* systemd-container-254.27-150600.4.71.2
* systemd-journal-remote-254.27-150600.4.71.2
* systemd-coredump-254.27-150600.4.71.2
* systemd-resolved-254.27-150600.4.71.2
* systemd-container-debuginfo-254.27-150600.4.71.2
* udev-debuginfo-254.27-150600.4.71.2
* systemd-devel-254.27-150600.4.71.2
* systemd-sysvcompat-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (noarch)
* systemd-lang-254.27-150600.4.71.2
* Basesystem Module 15-SP7 (x86_64)
* libudev1-32bit-254.27-150600.4.71.2
* libsystemd0-32bit-debuginfo-254.27-150600.4.71.2
* libudev1-32bit-debuginfo-254.27-150600.4.71.2
* libsystemd0-32bit-254.27-150600.4.71.2
* systemd-32bit-254.27-150600.4.71.2
* systemd-32bit-debuginfo-254.27-150600.4.71.2
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* systemd-debugsource-254.27-150600.4.71.2
* systemd-debuginfo-254.27-150600.4.71.2
* systemd-network-254.27-150600.4.71.2
* systemd-networkd-debuginfo-254.27-150600.4.71.2
* systemd-networkd-254.27-150600.4.71.2

## References:

* https://www.suse.com/security/cve/CVE-2026-40226.html
* https://bugzilla.suse.com/show_bug.cgi?id61400
* https://bugzilla.suse.com/show_bug.cgi?id61982
* https://bugzilla.suse.com/show_bug.cgi?id61983
* https://bugzilla.suse.com/show_bug.cgi?id62305
* https://bugzilla.suse.com/show_bug.cgi?id67644
* https://bugzilla.suse.com/show_bug.cgi?id67647



SUSE-SU-2026:3254-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP6)


# Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise
15 SP6)

Announcement ID: SUSE-SU-2026:3254-1
Release Date: 2026-07-26T18:33:35Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves six vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.109 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3254=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3254=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3256-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7)


# Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise
15 SP7)

Announcement ID: SUSE-SU-2026:3256-1
Release Date: 2026-07-27T07:33:42Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves six vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.52 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3260=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3256=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3255=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3258=1
SUSE-SLE-Module-Live-Patching-15-SP6-2026-3257=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3259=1

* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3263=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3256=1 SUSE-2026-3255=1 SUSE-2026-3258=1
SUSE-2026-3257=1 SUSE-2026-3259=1 SUSE-2026-3260=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_95-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-7-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_20-debugsource-9-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_21-debugsource-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-9-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_23-debugsource-6-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-5-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_24-debugsource-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_100-default-6-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_19-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_92-default-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-7-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_103-default-5-150600.2.1
* kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_22-debugsource-7-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP7_Update_14-debugsource-4-150700.2.1
* kernel-livepatch-6_4_0-150700_53_52-default-debuginfo-4-150700.2.1
* kernel-livepatch-6_4_0-150700_53_52-default-4-150700.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648



openSUSE-SU-2026:0263-1: important: Security update for trivy


openSUSE Security Update: Security update for trivy
_______________________________

Announcement ID: openSUSE-SU-2026:0263-1
Rating: important
References: #1266495 #1268356 #1269269 #1269271 #1271658
#1271670
Cross-References: CVE-2026-39821 CVE-2026-46680 CVE-2026-50151
CVE-2026-54448 CVE-2026-55092 CVE-2026-56852

CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-46680 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2026-50151 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2026-54448 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-55092 (SUSE): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-56852 (SUSE): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes 6 vulnerabilities is now available.

Description:

This update for trivy fixes the following issues:

- Update embedded dependencies:
* update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)
* update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)
* update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)

- Update trivy to version 0.72.0:
* release: v0.72.0 [main] (#10782)
* test: close plugin manager in tests cleanup (#10904)
* Merge commit from fork
* feat(bottlerocket): add vulnerability matching for Bottlerocket OS
(#10893)
* fix(misconf): support github_repository_vulnerability_alerts resource
(#10680)
* feat(java): detect JAR licenses from packaged LICENSE files (#10856)
* fix(nodejs): parse project dependencies from multi-document
pnpm-lock.yaml (#10861)
* fix(server): propagate package repository class in client/server mode
(#10874)
* chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to
2.3.2 (#10888)
* fix(vuln): fall back to UNKNOWN severity when vulnerability details
are missing (#10795)
* feat(java): detect JAR licenses from the embedded pom.xml (#10851)
* chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
* ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2
(#10873)
* chore(deps): bump alpine to 3.24.1 (#10868)
* docs: fix article typo in plugin developer guide (#10860)
* feat(misconf): Adds CloudFront standard logging v2 support to
AVD-AWS-0010 (#10848)
* docs: fix typos (#10857)
* fix(terraform): avoid data race on global getter.Getters in remote
module resolver (#10843)
* feat(secret): support new stateless format for GitHub App installation
tokens (#10826)
* fix: correct format verbs in diagnostic messages (#10805)
* ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1
(#10845)
* refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist
(#10830)
* docs: fix repository scan heading typo (#10828)
* Merge commit from fork
* fix: forward ospkg detector options through ospkg.NewScanner (#10811)
* chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
* fix(vex): load VEX documents from within the repository directory
(#10820)
* ci!: migrate docker config to dockers_v2 (#10783)
* feat(dotnet): detect bundled runtime in self-contained deployments
(#10786)
* feat(secret): add OpenAI secret detection rules (#10798)
* ci: expect GitHub App bot as backport PR author (#10813)
* fix: surface the original analysis error instead of context
cancellation (#10793)
* chore(deps): bump the github-actions group across 1 directory with 11
updates (#10803)
* chore(deps): bump the common group with 4 updates (#10797)
* chore(deps): bump the aws group with 4 updates (#10796)
* fix: use random suffix for process temp directory instead of PID
(#10431)
* docs: update signature verification for deb and rpm packages (#10784)
* fix(image): lookup origin layer for custom resources in merged layers
(#10788)
* test: fix flaky containerd integration test (#10760)
* ci: bump GoReleaser to v2.16.0 (#10774)
* docs: fix broken nixpkgs reference link in installation guide (#10776)
* test(java): force offline-scan for client/server integration tests
(#10721)
* fix(image): deterministic OS package deduplication for images with
embedded SBOMs (#10777)
* fix(spdx): guard against nil root component in SPDX marshaler (#10771)
* ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0
(#10768)

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-263=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

trivy-0.72.0-bp157.2.15.1

References:

https://www.suse.com/security/cve/CVE-2026-39821.html
https://www.suse.com/security/cve/CVE-2026-46680.html
https://www.suse.com/security/cve/CVE-2026-50151.html
https://www.suse.com/security/cve/CVE-2026-54448.html
https://www.suse.com/security/cve/CVE-2026-55092.html
https://www.suse.com/security/cve/CVE-2026-56852.html
https://bugzilla.suse.com/1266495
https://bugzilla.suse.com/1268356
https://bugzilla.suse.com/1269269
https://bugzilla.suse.com/1269271
https://bugzilla.suse.com/1271658
https://bugzilla.suse.com/1271670



openSUSE-SU-2026:0264-1: important: Security update for chromium


openSUSE Security Update: Security update for chromium
_______________________________

Announcement ID: openSUSE-SU-2026:0264-1
Rating: important
References: #1272460
Cross-References: CVE-2026-16804 CVE-2026-16805 CVE-2026-16806
CVE-2026-16807
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes four vulnerabilities is now available.

Description:

This update for chromium fixes the following issues:

- Chromium 150.0.7871.186 (boo#1272460):
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-264=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 ppc64le x86_64):

chromedriver-150.0.7871.186-bp157.2.196.1
chromium-150.0.7871.186-bp157.2.196.1

References:

https://www.suse.com/security/cve/CVE-2026-16804.html
https://www.suse.com/security/cve/CVE-2026-16805.html
https://www.suse.com/security/cve/CVE-2026-16806.html
https://www.suse.com/security/cve/CVE-2026-16807.html
https://bugzilla.suse.com/1272460



openSUSE-SU-2026:11366-1: moderate: mcphost-0.34.0-9.1 on GA media


# mcphost-0.34.0-9.1 on GA media

Announcement ID: openSUSE-SU-2026:11366-1
Rating: moderate

Cross-References:

* CVE-2026-5160
* CVE-2026-56852

CVSS scores:

* CVE-2026-5160 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the mcphost-0.34.0-9.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* mcphost 0.34.0-9.1
* mcphost-bash-completion 0.34.0-9.1
* mcphost-fish-completion 0.34.0-9.1
* mcphost-zsh-completion 0.34.0-9.1

## References:

* https://www.suse.com/security/cve/CVE-2026-5160.html
* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:11369-1: moderate: opennlp-1.9.5-2.1 on GA media


# opennlp-1.9.5-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11369-1
Rating: moderate

Cross-References:

* CVE-2026-63317

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the opennlp-1.9.5-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* opennlp 1.9.5-2.1
* opennlp-morfologik-addon 1.9.5-2.1
* opennlp-tools 1.9.5-2.1
* opennlp-uima 1.9.5-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-63317.html



openSUSE-SU-2026:11364-1: moderate: libknet-devel-1.33-2.1 on GA media


# libknet-devel-1.33-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11364-1
Rating: moderate

Cross-References:

* CVE-2026-15811
* CVE-2026-15812
* CVE-2026-15813

CVSS scores:

* CVE-2026-15811 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
* CVE-2026-15812 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-15813 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libknet-devel-1.33-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libknet-devel 1.33-2.1
* libknet1 1.33-2.1
* libknet1-compress-bzip2-plugin 1.33-2.1
* libknet1-compress-lz4-plugin 1.33-2.1
* libknet1-compress-lzma-plugin 1.33-2.1
* libknet1-compress-lzo2-plugin 1.33-2.1
* libknet1-compress-plugins-all 1.33-2.1
* libknet1-compress-zlib-plugin 1.33-2.1
* libknet1-compress-zstd-plugin 1.33-2.1
* libknet1-crypto-nss-plugin 1.33-2.1
* libknet1-crypto-openssl-plugin 1.33-2.1
* libknet1-crypto-plugins-all 1.33-2.1
* libknet1-plugins-all 1.33-2.1
* libnozzle-devel 1.33-2.1
* libnozzle1 1.33-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15811.html
* https://www.suse.com/security/cve/CVE-2026-15812.html
* https://www.suse.com/security/cve/CVE-2026-15813.html



SUSE-SU-2026:3268-1: important: Security update for python-Pillow


# Security update for python-Pillow

Announcement ID: SUSE-SU-2026:3268-1
Release Date: 2026-07-27T10:59:26Z
Rating: important
References:

* bsc#1270409
* bsc#1270410
* bsc#1270411
* bsc#1270412
* bsc#1271418
* bsc#1271419
* bsc#1271420
* bsc#1271421
* bsc#1271422
* bsc#1271424
* bsc#1271425

Cross-References:

* CVE-2026-54058
* CVE-2026-54059
* CVE-2026-54060
* CVE-2026-55379
* CVE-2026-55380
* CVE-2026-59197
* CVE-2026-59198
* CVE-2026-59199
* CVE-2026-59200
* CVE-2026-59204
* CVE-2026-59205

CVSS scores:

* CVE-2026-54058 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-54058 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59197 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-59198 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-59199 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59200 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59204 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59204 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59205 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves 11 vulnerabilities can now be installed.

## Description:

This update for python-Pillow fixes the following issues:

* CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on
`mmap` path (bsc#1271419).
* CVE-2026-54059: bomb protection bypass via PCF font loading due to
`Image.frombytes()` being called without `_decompression_bomb_check()`
(bsc#1270409).
* CVE-2026-54060: excessive allocation due to `FontFile.compile()`:
`Image.new()` being called without `_decompression_bomb_check()`
(bsc#1270410).
* CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()`
being called without `_decompression_bomb_check()` (bsc#1270411).
* CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions
being accepted without `_decompression_bomb_check()` in
`GdImageFile._open()` (bsc#1270412).
* CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via
integer overflow in `ImagingExpand` (bsc#1271418).
* CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA
RLE encoder (bsc#1271420).
* CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and
`Image.crop()` via signed coordinate overflow (bsc#1271421).
* CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()`
(bsc#1271422).
* CVE-2026-59204: denial of service through memory exhaustion via JPEG2000
tiled decoder (bsc#1271424).
* CVE-2026-59205: controlled heap out-of-bounds write in
`ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3268=1

* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3268=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3268=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3268=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3268=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3268=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3268=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3268=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3268=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3268=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3268=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3268=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1

## References:

* https://www.suse.com/security/cve/CVE-2026-54058.html
* https://www.suse.com/security/cve/CVE-2026-54059.html
* https://www.suse.com/security/cve/CVE-2026-54060.html
* https://www.suse.com/security/cve/CVE-2026-55379.html
* https://www.suse.com/security/cve/CVE-2026-55380.html
* https://www.suse.com/security/cve/CVE-2026-59197.html
* https://www.suse.com/security/cve/CVE-2026-59198.html
* https://www.suse.com/security/cve/CVE-2026-59199.html
* https://www.suse.com/security/cve/CVE-2026-59200.html
* https://www.suse.com/security/cve/CVE-2026-59204.html
* https://www.suse.com/security/cve/CVE-2026-59205.html
* https://bugzilla.suse.com/show_bug.cgi?id70409
* https://bugzilla.suse.com/show_bug.cgi?id70410
* https://bugzilla.suse.com/show_bug.cgi?id70411
* https://bugzilla.suse.com/show_bug.cgi?id70412
* https://bugzilla.suse.com/show_bug.cgi?id71418
* https://bugzilla.suse.com/show_bug.cgi?id71419
* https://bugzilla.suse.com/show_bug.cgi?id71420
* https://bugzilla.suse.com/show_bug.cgi?id71421
* https://bugzilla.suse.com/show_bug.cgi?id71422
* https://bugzilla.suse.com/show_bug.cgi?id71424
* https://bugzilla.suse.com/show_bug.cgi?id71425



SUSE-SU-2026:3270-1: moderate: Security update for alsa


# Security update for alsa

Announcement ID: SUSE-SU-2026:3270-1
Release Date: 2026-07-27T11:01:30Z
Rating: moderate
References:

* bsc#1268853

Cross-References:

* CVE-2026-56109

CVSS scores:

* CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-56109 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for alsa fixes the following issue

* CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that
can allow attackers to corrupt memory (bsc#1268853).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3270=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3270=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le x86_64)
* libatopology2-debuginfo-1.2.10-150600.4.3.1
* alsa-topology-devel-1.2.10-150600.4.3.1
* libatopology2-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* alsa-debugsource-1.2.10-150600.4.3.1
* libasound2-debuginfo-1.2.10-150600.4.3.1
* alsa-1.2.10-150600.4.3.1
* libasound2-1.2.10-150600.4.3.1
* alsa-devel-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libatopology2-64bit-1.2.10-150600.4.3.1
* alsa-topology-devel-64bit-1.2.10-150600.4.3.1
* libasound2-64bit-1.2.10-150600.4.3.1
* libatopology2-64bit-debuginfo-1.2.10-150600.4.3.1
* alsa-devel-64bit-1.2.10-150600.4.3.1
* libasound2-64bit-debuginfo-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (noarch)
* alsa-docs-1.2.10-150600.4.3.1
* openSUSE Leap 15.6 (x86_64)
* libatopology2-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-debuginfo-1.2.10-150600.4.3.1
* libatopology2-32bit-debuginfo-1.2.10-150600.4.3.1
* alsa-topology-devel-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-1.2.10-150600.4.3.1
* alsa-devel-32bit-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* alsa-debugsource-1.2.10-150600.4.3.1
* libasound2-debuginfo-1.2.10-150600.4.3.1
* alsa-1.2.10-150600.4.3.1
* libasound2-1.2.10-150600.4.3.1
* alsa-devel-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le x86_64)
* libatopology2-debuginfo-1.2.10-150600.4.3.1
* libatopology2-1.2.10-150600.4.3.1
* Basesystem Module 15-SP7 (x86_64)
* libasound2-32bit-1.2.10-150600.4.3.1
* libasound2-32bit-debuginfo-1.2.10-150600.4.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56109.html
* https://bugzilla.suse.com/show_bug.cgi?id68853



SUSE-SU-2026:3289-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP5)


# Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise
15 SP5)

Announcement ID: SUSE-SU-2026:3289-1
Release Date: 2026-07-27T15:36:28Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves five vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.116 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3289=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3295=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3293=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3287=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3292=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3296=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3294=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3280=1 SUSE-SLE-Module-Live-
Patching-15-SP5-2026-3279=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-3288=1
SUSE-SLE-Module-Live-Patching-15-SP5-2026-3290=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3289=1 SUSE-2026-3295=1 SUSE-2026-3293=1
SUSE-2026-3287=1 SUSE-2026-3292=1 SUSE-2026-3296=1 SUSE-2026-3294=1
SUSE-2026-3280=1 SUSE-2026-3279=1 SUSE-2026-3288=1 SUSE-2026-3290=1

## Package List:

* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_33-debugsource-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_28-debugsource-21-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_34-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_121-default-16-150500.2.1
* kernel-livepatch-5_14_21-150500_55_163-default-5-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_37-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-22-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_30-debugsource-16-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_31-debugsource-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_36-debugsource-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_127-default-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-11-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_27-debugsource-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-14-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_141-default-7-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_32-debugsource-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-11-150500.2.1
* kernel-livepatch-5_14_21-150500_55_144-default-7-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_39-debugsource-5-150500.2.1
* kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-22-150500.2.1
* kernel-livepatch-5_14_21-150500_55_116-default-19-150500.2.1
* kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-21-150500.2.1
* kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-11-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x)
* kernel-livepatch-SLE15-SP5_Update_29-debugsource-19-150500.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648