SUSE 5642 Published by

Recent updates for openSUSE Tumbleweed address moderate security vulnerabilities across six different packages on the general availability media. These patches resolve multiple common vulnerability identifiers across libtree-sitter, copacetic, redis, libexif-devel, semaphore, and Django, with severity ratings that span from low to high impact. System administrators should apply these package upgrades as soon as possible to eliminate the identified attack vectors. Keeping your infrastructure current with these fixes will help maintain a secure baseline while avoiding unnecessary downtime during deployment.

openSUSE-SU-2026:10715-1: moderate: libtree-sitter0_26-0.26.8-2.1 on GA media
openSUSE-SU-2026:10716-1: moderate: copacetic-0.14.0-1.1 on GA media
openSUSE-SU-2026:10711-1: moderate: redis-8.6.3-1.1 on GA media
openSUSE-SU-2026:10717-1: moderate: libexif-devel-0.6.26-1.1 on GA media
openSUSE-SU-2026:10712-1: moderate: semaphore-2.18.1-1.1 on GA media
openSUSE-SU-2026:10708-1: moderate: python311-Django4-4.2.30-2.1 on GA media




openSUSE-SU-2026:10715-1: moderate: libtree-sitter0_26-0.26.8-2.1 on GA media


# libtree-sitter0_26-0.26.8-2.1 on GA media

Announcement ID: openSUSE-SU-2026:10715-1
Rating: moderate

Cross-References:

* CVE-2026-34941
* CVE-2026-34943
* CVE-2026-34988
* CVE-2026-35186

CVSS scores:

* CVE-2026-34941 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-34941 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-34943 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-34943 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-34988 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-34988 ( SUSE ): 7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-35186 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-35186 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libtree-sitter0_26-0.26.8-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libtree-sitter0_26 0.26.8-2.1
* libtree-sitter0_26-x86-64-v3 0.26.8-2.1
* tree-sitter 0.26.8-2.1
* tree-sitter-devel 0.26.8-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-34941.html
* https://www.suse.com/security/cve/CVE-2026-34943.html
* https://www.suse.com/security/cve/CVE-2026-34988.html
* https://www.suse.com/security/cve/CVE-2026-35186.html



openSUSE-SU-2026:10716-1: moderate: copacetic-0.14.0-1.1 on GA media


# copacetic-0.14.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:10716-1
Rating: moderate

Cross-References:

* CVE-2026-24051

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the copacetic-0.14.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* copacetic 0.14.0-1.1
* copacetic-bash-completion 0.14.0-1.1
* copacetic-fish-completion 0.14.0-1.1
* copacetic-zsh-completion 0.14.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-24051.html



openSUSE-SU-2026:10711-1: moderate: redis-8.6.3-1.1 on GA media


# redis-8.6.3-1.1 on GA media

Announcement ID: openSUSE-SU-2026:10711-1
Rating: moderate

Cross-References:

* CVE-2026-23479
* CVE-2026-23631
* CVE-2026-25243
* CVE-2026-25588
* CVE-2026-25589

CVSS scores:

* CVE-2026-23479 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23479 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-23631 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23631 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-25243 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25588 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-25588 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25589 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-25589 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the redis-8.6.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* redis 8.6.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23479.html
* https://www.suse.com/security/cve/CVE-2026-23631.html
* https://www.suse.com/security/cve/CVE-2026-25243.html
* https://www.suse.com/security/cve/CVE-2026-25588.html
* https://www.suse.com/security/cve/CVE-2026-25589.html



openSUSE-SU-2026:10717-1: moderate: libexif-devel-0.6.26-1.1 on GA media


# libexif-devel-0.6.26-1.1 on GA media

Announcement ID: openSUSE-SU-2026:10717-1
Rating: moderate

Cross-References:

* CVE-2026-32775
* CVE-2026-40385
* CVE-2026-40386

CVSS scores:

* CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
* CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libexif-devel-0.6.26-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libexif-devel 0.6.26-1.1
* libexif-devel-32bit 0.6.26-1.1
* libexif12 0.6.26-1.1
* libexif12-32bit 0.6.26-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-32775.html
* https://www.suse.com/security/cve/CVE-2026-40385.html
* https://www.suse.com/security/cve/CVE-2026-40386.html



openSUSE-SU-2026:10712-1: moderate: semaphore-2.18.1-1.1 on GA media


# semaphore-2.18.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:10712-1
Rating: moderate

Cross-References:

* CVE-2026-34986

CVSS scores:

* CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the semaphore-2.18.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* semaphore 2.18.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-34986.html



openSUSE-SU-2026:10708-1: moderate: python311-Django4-4.2.30-2.1 on GA media


# python311-Django4-4.2.30-2.1 on GA media

Announcement ID: openSUSE-SU-2026:10708-1
Rating: moderate

Cross-References:

* CVE-2026-35192
* CVE-2026-5766
* CVE-2026-6907

CVSS scores:

* CVE-2026-35192 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-35192 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-5766 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-5766 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-6907 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-6907 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python311-Django4-4.2.30-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-Django4 4.2.30-2.1
* python313-Django4 4.2.30-2.1
* python314-Django4 4.2.30-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-35192.html
* https://www.suse.com/security/cve/CVE-2026-5766.html
* https://www.suse.com/security/cve/CVE-2026-6907.html