SUSE 5681 Published by

SUSE recently published several security advisories that tackle known flaws across its enterprise Linux releases and openSUSE Tumbleweed. The highest priority patches address critical weaknesses in LibVNCServer and Wireshark, effectively blocking dangerous memory corruption issues and remote code execution vectors. System administrators should also roll out moderate updates for Grafana, Traefik2, Google ADK, and WebOb documentation to keep their infrastructure secure. Applying these fixes requires running standard zypper commands or launching the YaST online update utility on any impacted SUSE Linux Enterprise machine.

SUSE-SU-2026:2427-1: important: Security update for LibVNCServer
openSUSE-SU-2026:11045-1: moderate: traefik2-2.11.50-1.1 on GA media
openSUSE-SU-2026:11044-1: moderate: python311-google-adk-2.2.0-1.1 on GA media
openSUSE-SU-2026:11041-1: moderate: python-WebOb-doc-1.8.10-1.1 on GA media
openSUSE-SU-2026:11040-1: moderate: grafana-11.6.14+security04-4.1 on GA media
SUSE-SU-2026:2437-1: important: Security update for wireshark




SUSE-SU-2026:2427-1: important: Security update for LibVNCServer


# Security update for LibVNCServer

Announcement ID: SUSE-SU-2026:2427-1
Release Date: 2026-06-17T09:50:23Z
Rating: important
References:

* bsc#1266459

Cross-References:

* CVE-2026-44988

CVSS scores:

* CVE-2026-44988 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-44988 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-44988 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Linux Enterprise Workstation Extension 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for LibVNCServer fixes the following issues:

* CVE-2026-44988: Fixed missing validation of rectangle width in tight
gradient decoding can lead to server-triggered out-of-bounds write
(bsc#1266459).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-2427=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2427=1

* SUSE Linux Enterprise Workstation Extension 15 SP7
zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2427=1

## Package List:

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* LibVNCServer-devel-0.9.14-150600.3.9.1
* libvncserver1-debuginfo-0.9.14-150600.3.9.1
* libvncclient1-0.9.14-150600.3.9.1
* libvncserver1-0.9.14-150600.3.9.1
* libvncclient1-debuginfo-0.9.14-150600.3.9.1
* LibVNCServer-debugsource-0.9.14-150600.3.9.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x)
* LibVNCServer-devel-0.9.14-150600.3.9.1
* libvncserver1-debuginfo-0.9.14-150600.3.9.1
* libvncclient1-0.9.14-150600.3.9.1
* libvncserver1-0.9.14-150600.3.9.1
* libvncclient1-debuginfo-0.9.14-150600.3.9.1
* LibVNCServer-debugsource-0.9.14-150600.3.9.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64)
* libvncserver1-debuginfo-0.9.14-150600.3.9.1
* libvncclient1-0.9.14-150600.3.9.1
* libvncserver1-0.9.14-150600.3.9.1
* libvncclient1-debuginfo-0.9.14-150600.3.9.1
* LibVNCServer-debugsource-0.9.14-150600.3.9.1

## References:

* https://www.suse.com/security/cve/CVE-2026-44988.html
* https://bugzilla.suse.com/show_bug.cgi?id=1266459



openSUSE-SU-2026:11045-1: moderate: traefik2-2.11.50-1.1 on GA media


# traefik2-2.11.50-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11045-1
Rating: moderate

Cross-References:

* CVE-2026-48020

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the traefik2-2.11.50-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* traefik2 2.11.50-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-48020.html



openSUSE-SU-2026:11044-1: moderate: python311-google-adk-2.2.0-1.1 on GA media


# python311-google-adk-2.2.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11044-1
Rating: moderate

Cross-References:

* CVE-2026-48710

CVSS scores:

* CVE-2026-48710 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-48710 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python311-google-adk-2.2.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python311-google-adk 2.2.0-1.1
* python313-google-adk 2.2.0-1.1
* python314-google-adk 2.2.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-48710.html



openSUSE-SU-2026:11041-1: moderate: python-WebOb-doc-1.8.10-1.1 on GA media


# python-WebOb-doc-1.8.10-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11041-1
Rating: moderate

Cross-References:

* CVE-2026-44889

CVSS scores:

* CVE-2026-44889 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-44889 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python-WebOb-doc-1.8.10-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python-WebOb-doc 1.8.10-1.1
* python311-WebOb 1.8.10-1.1
* python313-WebOb 1.8.10-1.1
* python314-WebOb 1.8.10-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-44889.html



openSUSE-SU-2026:11040-1: moderate: grafana-11.6.14+security04-4.1 on GA media


# grafana-11.6.14+security04-4.1 on GA media

Announcement ID: openSUSE-SU-2026:11040-1
Rating: moderate

Cross-References:

* CVE-2026-41607

CVSS scores:

* CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the grafana-11.6.14+security04-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* grafana 11.6.14+security04-4.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41607.html



SUSE-SU-2026:2437-1: important: Security update for wireshark


# Security update for wireshark

Announcement ID: SUSE-SU-2026:2437-1
Release Date: 2026-06-17T14:44:46Z
Rating: important
References:

* bsc#1263767
* bsc#1263809

Cross-References:

* CVE-2026-5405
* CVE-2026-5656

CVSS scores:

* CVE-2026-5405 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-5405 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-5656 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-5656 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-5656 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves two vulnerabilities can now be installed.

## Description:

This update for wireshark fixes the following issues

* CVE-2026-5405: RDP dissector crash (bsc#1263767).
* CVE-2026-5656: Profile import crash and possible code execution
(bsc#1263809).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-2437=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2437=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2437=1

## Package List:

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* wireshark-ui-qt-4.2.14-150600.18.41.1
* libwsutil15-debuginfo-4.2.14-150600.18.41.1
* libwiretap14-4.2.14-150600.18.41.1
* wireshark-ui-qt-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-4.2.14-150600.18.41.1
* libwiretap14-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-debuginfo-4.2.14-150600.18.41.1
* wireshark-debugsource-4.2.14-150600.18.41.1
* wireshark-devel-4.2.14-150600.18.41.1
* wireshark-debuginfo-4.2.14-150600.18.41.1
* wireshark-4.2.14-150600.18.41.1
* libwsutil15-4.2.14-150600.18.41.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* wireshark-ui-qt-4.2.14-150600.18.41.1
* libwiretap14-4.2.14-150600.18.41.1
* libwsutil15-debuginfo-4.2.14-150600.18.41.1
* wireshark-ui-qt-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-4.2.14-150600.18.41.1
* libwiretap14-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-debuginfo-4.2.14-150600.18.41.1
* wireshark-debugsource-4.2.14-150600.18.41.1
* wireshark-devel-4.2.14-150600.18.41.1
* wireshark-debuginfo-4.2.14-150600.18.41.1
* wireshark-4.2.14-150600.18.41.1
* libwsutil15-4.2.14-150600.18.41.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* wireshark-ui-qt-4.2.14-150600.18.41.1
* libwiretap14-4.2.14-150600.18.41.1
* libwsutil15-debuginfo-4.2.14-150600.18.41.1
* wireshark-ui-qt-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-4.2.14-150600.18.41.1
* libwiretap14-debuginfo-4.2.14-150600.18.41.1
* libwireshark17-debuginfo-4.2.14-150600.18.41.1
* wireshark-debugsource-4.2.14-150600.18.41.1
* wireshark-devel-4.2.14-150600.18.41.1
* wireshark-debuginfo-4.2.14-150600.18.41.1
* wireshark-4.2.14-150600.18.41.1
* libwsutil15-4.2.14-150600.18.41.1

## References:

* https://www.suse.com/security/cve/CVE-2026-5405.html
* https://www.suse.com/security/cve/CVE-2026-5656.html
* https://bugzilla.suse.com/show_bug.cgi?id=1263767
* https://bugzilla.suse.com/show_bug.cgi?id=1263809