SUSE 5692 Published by

openSUSE published a batch of moderate security updates for openSUSE Tumbleweed and the SLE-15-SP7 Backports repository to close multiple recently identified flaws. The patch cycle addresses twelve distinct Common Vulnerabilities and Exposures entries across packages like ImageMagick, Glances, Python PDM, tar, hydra, calibre, jupyter-nbclassic, agama-web-ui, assimp-devel, and xtrabackup

openSUSE-SU-2026:11129-1: moderate: assimp-devel-6.0.5-4.1 on GA media
openSUSE-SU-2026:11131-1: moderate: hydra-9.7+git20.gbccaea1-1.1 on GA media
openSUSE-SU-2026:11130-1: moderate: calibre-9.10.0-1.1 on GA media
openSUSE-SU-2026:11123-1: moderate: jupyter-nbclassic-1.3.3-2.1 on GA media
openSUSE-SU-2026:11128-1: moderate: agama-web-ui-22+143.ee15dea20-46.1 on GA media
openSUSE-SU-2026:11125-1: moderate: tar-1.35-8.1 on GA media
openSUSE-SU-2026:11124-1: moderate: python311-pdm-2.28.0-1.1 on GA media
openSUSE-SU-2026:11127-1: moderate: ImageMagick-7.1.2.25-3.1 on GA media
openSUSE-SU-2026:11122-1: moderate: glances-common-4.5.5-1.1 on GA media
openSUSE-SU-2026:0221-1: moderate: Security update for xtrabackup




openSUSE-SU-2026:11129-1: moderate: assimp-devel-6.0.5-4.1 on GA media


# assimp-devel-6.0.5-4.1 on GA media

Announcement ID: openSUSE-SU-2026:11129-1
Rating: moderate

Cross-References:

* CVE-2026-10200
* CVE-2026-10232

CVSS scores:

* CVE-2026-10200 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-10200 ( SUSE ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10232 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-10232 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the assimp-devel-6.0.5-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* assimp-devel 6.0.5-4.1
* libassimp6 6.0.5-4.1

## References:

* https://www.suse.com/security/cve/CVE-2026-10200.html
* https://www.suse.com/security/cve/CVE-2026-10232.html



openSUSE-SU-2026:11131-1: moderate: hydra-9.7+git20.gbccaea1-1.1 on GA media


# hydra-9.7+git20.gbccaea1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11131-1
Rating: moderate

Cross-References:

* CVE-2026-56766

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the hydra-9.7+git20.gbccaea1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* hydra 9.7+git20.gbccaea1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56766.html



openSUSE-SU-2026:11130-1: moderate: calibre-9.10.0-1.1 on GA media


# calibre-9.10.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11130-1
Rating: moderate

Cross-References:

* CVE-2026-53511

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the calibre-9.10.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* calibre 9.10.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-53511.html



openSUSE-SU-2026:11123-1: moderate: jupyter-nbclassic-1.3.3-2.1 on GA media


# jupyter-nbclassic-1.3.3-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11123-1
Rating: moderate

Cross-References:

* CVE-2026-48779

CVSS scores:

* CVE-2026-48779 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-48779 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-nbclassic-1.3.3-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-nbclassic 1.3.3-2.1
* python311-nbclassic 1.3.3-2.1
* python313-nbclassic 1.3.3-2.1
* python314-nbclassic 1.3.3-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-48779.html



openSUSE-SU-2026:11128-1: moderate: agama-web-ui-22+143.ee15dea20-46.1 on GA media


# agama-web-ui-22+143.ee15dea20-46.1 on GA media

Announcement ID: openSUSE-SU-2026:11128-1
Rating: moderate

Cross-References:

* CVE-2026-34077

CVSS scores:

* CVE-2026-34077 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the agama-web-ui-22+143.ee15dea20-46.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* agama-web-ui 22+143.ee15dea20-46.1

## References:

* https://www.suse.com/security/cve/CVE-2026-34077.html



openSUSE-SU-2026:11125-1: moderate: tar-1.35-8.1 on GA media


# tar-1.35-8.1 on GA media

Announcement ID: openSUSE-SU-2026:11125-1
Rating: moderate

Cross-References:

* CVE-2026-5704

CVSS scores:

* CVE-2026-5704 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-5704 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the tar-1.35-8.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* tar 1.35-8.1
* tar-backup-scripts 1.35-8.1
* tar-doc 1.35-8.1
* tar-lang 1.35-8.1
* tar-rmt 1.35-8.1
* tar-tests 1.35-8.1

## References:

* https://www.suse.com/security/cve/CVE-2026-5704.html



openSUSE-SU-2026:11124-1: moderate: python311-pdm-2.28.0-1.1 on GA media


# python311-pdm-2.28.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11124-1
Rating: moderate

Cross-References:

* CVE-2026-47763
* CVE-2026-47764
* CVE-2026-47781

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python311-pdm-2.28.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-pdm 2.28.0-1.1
* python313-pdm 2.28.0-1.1
* python314-pdm 2.28.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-47763.html
* https://www.suse.com/security/cve/CVE-2026-47764.html
* https://www.suse.com/security/cve/CVE-2026-47781.html



openSUSE-SU-2026:11127-1: moderate: ImageMagick-7.1.2.25-3.1 on GA media


# ImageMagick-7.1.2.25-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11127-1
Rating: moderate

Cross-References:

* CVE-2026-56367
* CVE-2026-56368
* CVE-2026-56370
* CVE-2026-56371
* CVE-2026-56376
* CVE-2026-56379

CVSS scores:

* CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ImageMagick-7.1.2.25-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ImageMagick 7.1.2.25-3.1
* ImageMagick-config-7-SUSE 7.1.2.25-3.1
* ImageMagick-devel 7.1.2.25-3.1
* ImageMagick-devel-32bit 7.1.2.25-3.1
* ImageMagick-doc 7.1.2.25-3.1
* ImageMagick-extra 7.1.2.25-3.1
* libMagick++-7_Q16HDRI5 7.1.2.25-3.1
* libMagick++-7_Q16HDRI5-32bit 7.1.2.25-3.1
* libMagick++-devel 7.1.2.25-3.1
* libMagick++-devel-32bit 7.1.2.25-3.1
* libMagickCore-7_Q16HDRI10 7.1.2.25-3.1
* libMagickCore-7_Q16HDRI10-32bit 7.1.2.25-3.1
* libMagickWand-7_Q16HDRI10 7.1.2.25-3.1
* libMagickWand-7_Q16HDRI10-32bit 7.1.2.25-3.1
* perl-PerlMagick 7.1.2.25-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56367.html
* https://www.suse.com/security/cve/CVE-2026-56368.html
* https://www.suse.com/security/cve/CVE-2026-56370.html
* https://www.suse.com/security/cve/CVE-2026-56371.html
* https://www.suse.com/security/cve/CVE-2026-56376.html
* https://www.suse.com/security/cve/CVE-2026-56379.html



openSUSE-SU-2026:11122-1: moderate: glances-common-4.5.5-1.1 on GA media


# glances-common-4.5.5-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11122-1
Rating: moderate

Cross-References:

* CVE-2026-46606
* CVE-2026-46607
* CVE-2026-46608
* CVE-2026-46611
* CVE-2026-53925

CVSS scores:

* CVE-2026-46606 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46606 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46607 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46607 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46608 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
* CVE-2026-46608 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-46611 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-46611 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the glances-common-4.5.5-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* glances-common 4.5.5-1.1
* python311-Glances 4.5.5-1.1
* python313-Glances 4.5.5-1.1
* python314-Glances 4.5.5-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-46606.html
* https://www.suse.com/security/cve/CVE-2026-46607.html
* https://www.suse.com/security/cve/CVE-2026-46608.html
* https://www.suse.com/security/cve/CVE-2026-46611.html
* https://www.suse.com/security/cve/CVE-2026-53925.html



openSUSE-SU-2026:0221-1: moderate: Security update for xtrabackup


openSUSE Security Update: Security update for xtrabackup
_______________________________

Announcement ID: openSUSE-SU-2026:0221-1
Rating: moderate
References: #1244285
Cross-References: CVE-2025-5918
CVSS scores:
CVE-2025-5918 (SUSE): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for xtrabackup fixes the following issues:

- CVE-2025-5918: embedded libarchive: Reading past EOF may be triggered
for piped file streams (boo#1244285)

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-221=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

xtrabackup-2.4.26-bp157.2.6.1
xtrabackup-test-2.4.26-bp157.2.6.1

References:

https://www.suse.com/security/cve/CVE-2025-5918.html
https://bugzilla.suse.com/1244285