openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media
openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media
openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media
openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media
SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3300-1: important: Security update for ignition
SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3327-1: important: Security update for yq
SUSE-SU-2026:3329-1: important: Security update for nginx
SUSE-SU-2026:3330-1: moderate: Security update for libssh
SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk
SUSE-SU-2026:3335-1: important: Security update for ImageMagick
SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3
SUSE-SU-2026:3340-1: moderate: Security update for nmap
SUSE-SU-2026:3341-1: important: Security update for glib2
SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)
openSUSE-SU-2026:21453-1: important: Security update for chromium
openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui
SUSE-SU-2026:3362-1: important: Security update for samba
SUSE-SU-2026:3364-1: important: Security update for samba
SUSE-SU-2026:3365-1: important: Security update for samba
SUSE-SU-2026:3366-1: important: Security update for samba
SUSE-SU-2026:3368-1: moderate: Security update for sssd
SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)
openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media
# valkey-9.1.1-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11381-1
Rating: moderate
Cross-References:
* CVE-2026-56684
* CVE-2026-63639
CVSS scores:
* CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Tumbleweed
An update that solves 2 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the valkey-9.1.1-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* valkey 9.1.1-1.1
* valkey-compat-redis 9.1.1-1.1
* valkey-devel 9.1.1-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56684.html
* https://www.suse.com/security/cve/CVE-2026-63639.html
openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media
# python313-CherryPy-18.10.0-4.1 on GA media
Announcement ID: openSUSE-SU-2026:11378-1
Rating: moderate
Cross-References:
* CVE-2019-9740
CVSS scores:
* CVE-2019-9740 ( SUSE ): 5.4 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the python313-CherryPy-18.10.0-4.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-CherryPy 18.10.0-4.1
* python314-CherryPy 18.10.0-4.1
## References:
* https://www.suse.com/security/cve/CVE-2019-9740.html
openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media
# libssh-config-0.11.5-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11377-1
Rating: moderate
Cross-References:
* CVE-2026-15370
* CVE-2026-59843
* CVE-2026-59844
* CVE-2026-59845
* CVE-2026-59846
* CVE-2026-59847
* CVE-2026-59848
* CVE-2026-59849
* CVE-2026-59850
CVSS scores:
* CVE-2026-15370 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-15370 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
* CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59849 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59849 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 9 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the libssh-config-0.11.5-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* libssh-config 0.11.5-1.1
* libssh-devel 0.11.5-1.1
* libssh4 0.11.5-1.1
* libssh4-32bit 0.11.5-1.2
## References:
* https://www.suse.com/security/cve/CVE-2026-15370.html
* https://www.suse.com/security/cve/CVE-2026-59843.html
* https://www.suse.com/security/cve/CVE-2026-59844.html
* https://www.suse.com/security/cve/CVE-2026-59845.html
* https://www.suse.com/security/cve/CVE-2026-59846.html
* https://www.suse.com/security/cve/CVE-2026-59847.html
* https://www.suse.com/security/cve/CVE-2026-59848.html
* https://www.suse.com/security/cve/CVE-2026-59849.html
* https://www.suse.com/security/cve/CVE-2026-59850.html
openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media
# ignition-2.26.0-5.1 on GA media
Announcement ID: openSUSE-SU-2026:11376-1
Rating: moderate
Cross-References:
* CVE-2026-34986
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 3 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the ignition-2.26.0-5.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* ignition 2.26.0-5.1
## References:
* https://www.suse.com/security/cve/CVE-2026-34986.html
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)
# Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise
15 SP5)
Announcement ID: SUSE-SU-2026:3319-1
Release Date: 2026-07-28T03:33:52Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves five vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.136 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3319=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3320=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3319=1 SUSE-2026-3320=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3300-1: important: Security update for ignition
# Security update for ignition
Announcement ID: SUSE-SU-2026:3300-1
Release Date: 2026-07-27T17:00:29Z
Rating: important
References:
* bsc#1266606
* bsc#1272059
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* HPC Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for ignition fixes the following issues
* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1266606).
* CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing
invalid UTF-8 bytes can lead to infinite loop (bsc#1272059).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3300=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3300=1
* HPC Module 15-SP7
zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3300=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1
* HPC Module 15-SP7 (aarch64 x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1
## References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id66606
* https://bugzilla.suse.com/show_bug.cgi?id72059
SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
# Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux
Enterprise 15 SP7)
Announcement ID: SUSE-SU-2026:3316-1
Release Date: 2026-07-27T19:36:28Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.8 fixes various
security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3316=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3315=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3308=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3307=1
SUSE-SLE-Module-Live-Patching-15-SP6-2026-3314=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3311=1
* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3303=1 SUSE-SLE-
Module-Live-Patching-15-SP7-2026-3304=1 SUSE-SLE-Module-Live-
Patching-15-SP7-2026-3309=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3312=1
SUSE-SLE-Module-Live-Patching-15-SP7-2026-3306=1 SUSE-SLE-Module-Live-
Patching-15-SP7-2026-3310=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3305=1
SUSE-SLE-Module-Live-Patching-15-SP7-2026-3313=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3316=1 SUSE-2026-3315=1 SUSE-2026-3308=1
SUSE-2026-3307=1 SUSE-2026-3314=1 SUSE-2026-3311=1
## Package List:
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP7_Update_5-debugsource-12-150700.2.1
* kernel-livepatch-6_4_0-150700_53_16-default-15-150700.2.1
* kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-12-150700.2.1
* kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-15-150700.2.1
* kernel-livepatch-6_4_0-150700_53_19-default-12-150700.2.1
* kernel-livepatch-SLE15-SP7_Update_4-debugsource-15-150700.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (x86_64)
* kernel-livepatch-6_4_0-150700_7_22-rt-11-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_2-debugsource-19-150700.2.1
* kernel-livepatch-6_4_0-150700_7_8-rt-debuginfo-19-150700.2.1
* kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-15-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-11-150700.2.1
* kernel-livepatch-6_4_0-150700_7_8-rt-19-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_13-rt-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_25-rt-10-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-10-150700.2.1
* kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-11-150700.2.1
* kernel-livepatch-6_4_0-150700_7_16-rt-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-12-150700.2.1
* kernel-livepatch-6_4_0-150700_7_19-rt-12-150700.2.1
* kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-10-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-15-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-12-150700.2.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3327-1: important: Security update for yq
# Security update for yq
Announcement ID: SUSE-SU-2026:3327-1
Release Date: 2026-07-28T09:18:18Z
Rating: important
References:
* bsc#1267199
* bsc#1271994
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for yq fixes the following issues:
Update to v4.53.3.
* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1267199).
* CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input
containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994).
Changes for yq:
* v4.53.3:
* Add --ini-preserve-quotes flag for INI round-trip quote preservation.
* Fix: reset INI decoder state on init.
* Fix: decode properties array bracket paths.
* Fix: preserve floats with trailing zero when encoding YAML to JSON.
* Fix: JSON to TOML root scope and null handling.
* Fix: reset TOML decoder finished flag on Init for multi-doc evaluation.
* Fix: reset TOML decoder between files when evaluating all at once.
* Fix: preserve TOML inline table array scope.
* Fix: preserve empty TOML arrays in tables
* Fix: TOML encoder uses inline tables for YAML FlowStyle mappings.
* Fix nested inline YAML merge explode.
* Fix repeatString overflow test on 32-bit platforms.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3327=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3327=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* yq-debuginfo-4.53.3-150500.3.12.1
* yq-4.53.3-150500.3.12.1
* openSUSE Leap 15.5 (noarch)
* yq-bash-completion-4.53.3-150500.3.12.1
* yq-zsh-completion-4.53.3-150500.3.12.1
* yq-fish-completion-4.53.3-150500.3.12.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* yq-debuginfo-4.53.3-150500.3.12.1
* yq-4.53.3-150500.3.12.1
## References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id67199
* https://bugzilla.suse.com/show_bug.cgi?id71994
SUSE-SU-2026:3329-1: important: Security update for nginx
# Security update for nginx
Announcement ID: SUSE-SU-2026:3329-1
Release Date: 2026-07-28T09:34:39Z
Rating: important
References:
* bsc#1267525
* bsc#1268492
* bsc#1268495
Cross-References:
* CVE-2026-42055
* CVE-2026-48142
CVSS scores:
* CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42055 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-48142 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected Products:
* openSUSE Leap 15.6
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves two vulnerabilities and has one security fix can now be
installed.
## Description:
This update for nginx fixes the following issues
* CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module`
and `ngx_http_grpc_module` modules (bsc#1268492).
* CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module`
module (bsc#1268495).
* Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3329=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3329=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3329=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3329=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* openSUSE Leap 15.6 (noarch)
* nginx-source-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* nginx-source-1.21.5-150600.10.24.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* Server Applications Module 15-SP7 (noarch)
* nginx-source-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* nginx-source-1.21.5-150600.10.24.1
## References:
* https://www.suse.com/security/cve/CVE-2026-42055.html
* https://www.suse.com/security/cve/CVE-2026-48142.html
* https://bugzilla.suse.com/show_bug.cgi?id67525
* https://bugzilla.suse.com/show_bug.cgi?id68492
* https://bugzilla.suse.com/show_bug.cgi?id68495
SUSE-SU-2026:3330-1: moderate: Security update for libssh
# Security update for libssh
Announcement ID: SUSE-SU-2026:3330-1
Release Date: 2026-07-28T09:36:04Z
Rating: moderate
References:
* bsc#1272164
* bsc#1272165
* bsc#1272166
* bsc#1272167
* bsc#1272168
* bsc#1272169
* bsc#1272171
Cross-References:
* CVE-2026-59843
* CVE-2026-59844
* CVE-2026-59845
* CVE-2026-59846
* CVE-2026-59847
* CVE-2026-59848
* CVE-2026-59850
CVSS scores:
* CVE-2026-59843 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59845 ( SUSE ): 8.2
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
* CVE-2026-59846 ( SUSE ): 2.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59847 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
* CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-59848 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for libssh fixes the following issues:
* CVE-2026-59843: denial of service via zero advertised channel packet size
(bsc#1272164).
* CVE-2026-59844: denial of service via oversized SFTP read length
(bsc#1272165).
* CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure
(bsc#1272166).
* CVE-2026-59846: information disclosure via ProxyCommand %r username
expansion (bsc#1272167).
* CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification
(bsc#1272168).
* CVE-2026-59848: denial of service via SFTP responses with unknown request
IDs (bsc#1272169).
* CVE-2026-59850: use-after-free via data callbacks on closed channels
(bsc#1272171).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3330=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3330=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3330=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3330=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libssh4-64bit-0.9.8-150600.11.15.1
* libssh4-64bit-debuginfo-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
## References:
* https://www.suse.com/security/cve/CVE-2026-59843.html
* https://www.suse.com/security/cve/CVE-2026-59844.html
* https://www.suse.com/security/cve/CVE-2026-59845.html
* https://www.suse.com/security/cve/CVE-2026-59846.html
* https://www.suse.com/security/cve/CVE-2026-59847.html
* https://www.suse.com/security/cve/CVE-2026-59848.html
* https://www.suse.com/security/cve/CVE-2026-59850.html
* https://bugzilla.suse.com/show_bug.cgi?id72164
* https://bugzilla.suse.com/show_bug.cgi?id72165
* https://bugzilla.suse.com/show_bug.cgi?id72166
* https://bugzilla.suse.com/show_bug.cgi?id72167
* https://bugzilla.suse.com/show_bug.cgi?id72168
* https://bugzilla.suse.com/show_bug.cgi?id72169
* https://bugzilla.suse.com/show_bug.cgi?id72171
SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk
# Security update for java-21-openjdk
Announcement ID: SUSE-SU-2026:3332-1
Release Date: 2026-07-28T09:37:59Z
Rating: important
References:
* bsc#1264397
* bsc#1264994
* bsc#1267355
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237
Cross-References:
* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-41254 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46968 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47010 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47021 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47063 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-60147 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves nine vulnerabilities and has two security fixes can now be
installed.
## Description:
This update for java-21-openjdk fixes the following issues:
Update to upstream tag jdk-21.0.12+8 (July 2026 CPU).
Security issues fixed:
* CVE-2026-41254: lcms: information disclosure and denial of service via
integer overflow in `CubeSize` (bsc#1264994).
* CVE-2026-46917: unauthenticated attacker with network access via TLS can
cause a partial denial of service (bsc#1272223).
* CVE-2026-46968: unauthenticated attacker with network access via TLS can
gain unauthorized creation, deletion or modification access to critical
data(bsc#1272224).
* CVE-2026-47010: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert or delete access to some data
(bsc#1272225).
* CVE-2026-47021: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272227).
* CVE-2026-47027: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272228).
* CVE-2026-47059: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272235).
* CVE-2026-47063: unauthenticated attacker with network access via multiple
protocols can gain unauthorized creation, deletion or modification access to
critical data (bsc#1272236).
* CVE-2026-60147: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert, delete and read access to
some(bsc#1272237).
Other updates and bugfixes:
* Errors from update-alternatives when installing java-25-openjdk
(bsc#1267355).
* Make post scripts less noisy (bsc#1267355).
* Use libalternatives instead of update-alternatives for distributions where
libalternatives is available.
* Update to upstream tag jdk-21.0.12+8 (July 2026 CPU):
* JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
* JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
* JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails
* JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
* JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F
* JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update
* JDK-8129418: JShell: better highlighting of errors in imports on demand
* JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'.
* JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java
* JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04
* JDK-8212084: G1: Implement UseGCOverheadLimit
* JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux
* JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
* JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu
* JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
* JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java
* JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
* JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process"
* JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
* JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/ /Test.java fails with Out of space in CodeCache
* JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
* JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
* JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
* JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!"
* JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
* JDK-8310645: CancelledResponse.java does not use HTTP/2 when testing the HttpClient
* JDK-8311538: CDS InternSharedString test fails on huge pages host - cannot find shared string
* JDK-8315588: JShell does not accept underscore from JEP 443 even with --enable-preview
* JDK-8318365: Test runtime/cds/appcds/sharedStrings/ /InternSharedString.java fails after JDK-8311538
* JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit
* JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder
* JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder
* JDK-8320677: Printer tests use invalid '@run main/manual=yesno
* JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux
* JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE
* JDK-8322532: JShell : Unnamed variable issue
* JDK-8323089: networkaddress.cache.ttl is not a system property
* JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
* JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
* JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer)
* JDK-8326458: Menu mnemonics don't toggle in Windows LAF when F10 is pressed
* JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
* JDK-8329273: C2 SuperWord: Some basic MemorySegment IR tests
* JDK-8330704: Clean up non-standard use of /** comments in some langtools tests
* JDK-8330806: test/hotspot/jtreg/compiler/c1/ /TestLargeMonitorOffset.java fails on ARM32
* JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
* JDK-8333729: C2 SuperWord: remove some @requires usages in test/hotspot/jtreg/compiler/loopopts/superword
* JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use
* JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
* JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java
* JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
* JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
* JDK-8339638: Update vmTestbase/nsk/jvmti/_Field_ Watch tests to use virtual thread factory
* JDK-8339879: Open some dialog awt tests
* JDK-8339975: Open some dialog awt tests 2
* JDK-8340140: Open some dialog awt tests 3
* JDK-8340336: Open some checkbox awt tests
* JDK-8340494: Open some dialog awt tests 4
* JDK-8340818: Add a new jtreg test root to test the generated documentation
* JDK-8340851: Open some TextArea awt tests
* JDK-8340987: Open some TextArea awt tests 1
* JDK-8341055: Open some TextArea awt tests 2
* JDK-8341292: Open some TextArea awt tests 3
* JDK-8341376: Open some TextArea awt tests 4
* JDK-8341427: JFR: Adjust object sampler span handling
* JDK-8341436: containers/docker/TestJcmdWithSideCar.java takes needlessly long to run
* JDK-8341833: incomplete snippet from loaded files from command line is ignored
* JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
* JDK-8342836: Automatically determine that a test in the docs test root is requested
* JDK-8344128: Regression: make help broken after JDK-8340818
* JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete
* JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
* JDK-8346683: Problem list automated tests that fail on macOS15
* JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
* JDK-8349084: Update vectors used in several PQC benchmarks
* JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
* JDK-8349533: Refactor validator tests shell files to java
* JDK-8349699: XSL transform fails with certain UTF-8 characters on 1024 byte boundaries
* JDK-8349959: Test CR6740048.java passes unexpectedly missing CR6740048.xsd
* JDK-8350749: Upgrade JLine to 3.29.0
* JDK-8350808: Small typos in JShell method SnippetEvent .toString()
* JDK-8352020: [CompileFramework] enable compilation for VectorAPI
* JDK-8352147: G1: TestEagerReclaimHumongousRegionsClearMarkBits test takes very long
* JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty
* JDK-8352431: java/net/httpclient/EmptyAuthenticate.java uses "localhost"
* JDK-8352685: Opensource JInternalFrame tests - series2
* JDK-8352733: Improve RotFontBoundsTest test
* JDK-8352877: Opensource Several Font related tests - Batch 1
* JDK-8353124: java/lang/Thread/virtual/stress/Skynet.java#Z times out on macosx-x64-debug
* JDK-8353488: Open some JComboBox bugs 3
* JDK-8353552: Opensource Several Font related tests - Batch 3
* JDK-8354163: Open source Swing tests Batch 1
* JDK-8354695: Open source several swing tests batch7
* JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
* JDK-8354910: Output by java.io.IO or System.console() corrupted for some non-ASCII characters
* JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
* JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run
* JDK-8355332: Fix failing semi-manual test EDT issue
* JDK-8355371: NegativeArraySizeException in print methods in IO or System.console() in JShell
* JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
* JDK-8356695: java/lang/StringBuilder/HugeCapacity.java failing with OOME
* JDK-8356868: Not all cgroup parameters are made available
* JDK-8357062: Update Public Suffix List to 823beb1
* JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
* JDK-8357086: os::xxx functions returning memory size should return size_t
* JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java
* JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
* JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
* JDK-8359364: java/net/URL/EarlyOrDelayedParsing test fails intermittently
* JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE
* JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
* JDK-8360160: ubuntu-22-04 machine is failing client tests
* JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language
* JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures
* JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out
* JDK-8360882: Tests throw SkippedException when they should fail
* JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
* JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
* JDK-8361894: sun/security/krb5/config/native/ /TestDynamicStore.java ensure that the test is run with sudo
* JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
* JDK-8363943: ARM32: Represent Registers as values
* JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java
* JDK-8364190: JFR: RemoteRecordingStream withers don't work
* JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles
* JDK-8364756: JFR: Improve slow tests
* JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
* JDK-8365379: SU3.applyInsets may produce wrong results
* JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/ /CheckLeaseLeak.java failing intermittently
* JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26
* JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
* JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception
* JDK-8365625: Can't change accelerator colors in Windows L&F
* JDK-8365776: Convert JShell tests to use JUnit instead of TestNG
* JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException
* JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException
* JDK-8365893: test/jdk/java/lang/Thread/virtual/JfrEvents.java failing intermittently
* JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/ /CloseDescriptors.java as intermittent
* JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't
* JDK-8366369: Add @requires linux for GTK L&F tests
* JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing
* JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass
* JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes
* JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner
* JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException
* JDK-8368041: Enhance TLS certificate handling
* JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ /ModalExcludedTest.java
* JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
* JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
* JDK-8368524: Tests are skipped and shown as passed in test/jdk/sun/security/pkcs11/Cipher/KeyWrap
* JDK-8368551: Core dump warning may be confusing
* JDK-8368625: com/sun/net/httpserver/ /ServerStopTerminationTest.java fails intermittently
* JDK-8368670: Deadlock in JFR on event register + class load
* JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
* JDK-8368866: compiler/codecache/stress/ /UnexpectedDeoptimizationTest.java intermittent timed out
* JDK-8368885: NMT CommandLine tests can check for error better
* JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
* JDK-8369251: Opensource few tests
* JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
* JDK-8369516: Delete duplicate imaging test
* JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual?000000)
* JDK-8369683: Exclude runtime/Monitor/ /MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug
* JDK-8369851: Remove darcy author tags from langtools tests
* JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
* JDK-8370378: Some compiler tests inadvertently exclude particular platforms
* JDK-8370489: Some compiler tests miss the @key randomness
* JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function
* JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
* JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
* JDK-8370905: Update vm.defmeth tests to use virtual threads
* JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
* JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip
* JDK-8371349: Update NSS library to 3.117
* JDK-8371364: Refactor javax/swing/JFileChooser/ /FileSizeCheck.java to use Util.findComponent()
* JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
* JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout
* JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException
* JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
* JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java
* JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows
* JDK-8372120: Add missing sound keyword to MIDI tests
* JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log
* JDK-8372351: Add 2 WISeKey roots
* JDK-8372609: Bug4944439 does not enforce locale correctly
* JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
* JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
* JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
* JDK-8373275: Improve DTLS handshaking
* JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods
* JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp
* JDK-8373623: Refactor Serialization tests for Records to JUnit
* JDK-8373632: Some sound tests failing in CI due to lack of sound key
* JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected
* JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
* JDK-8373704: Improve "SocketException: Protocol family unavailable" message
* JDK-8373716: Refactor further java/util tests from TestNG to JUnit
* JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout'
* JDK-8373796: Refactor java/net/httpclient/ /ThrowingPublishers*.java tests to use JUnit5
* JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost"
* JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing
* JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
* JDK-8373866: Refactor java/net/httpclient/ /ThrowingSubscribers*.java tests to use JUnit5
* JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5
* JDK-8373928: 4 Dangling pointer defect groups in java.c
* JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out
* JDK-8374058: Enhance JPEG handling
* JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
* JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied
* JDK-8374434: Several JShell tests report JUnit discovery warnings
* JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
* JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name
* JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath
* JDK-8374888: Implement internal test cache to help UserIterCount test performance
* JDK-8374998: Failing os::write - remove bad file
* JDK-8375065: Update LCMS to 2.18
* JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
* JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
* JDK-8375232: Refactor util/StringJoiner tests to use JUnit
* JDK-8375233: Refactor util/Vector tests to use JUnit
* JDK-8375742: Test java/lang/invoke/MethodHandleProxies/ /Driver.java does not run Unnamed.java
* JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
* JDK-8376151: Test javax/swing/JFileChooser/4966171/ /bug4966171.java is failing with OOME
* JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
* JDK-8376233: Clean up code in Desktop native peer
* JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output
* JDK-8377158: Enhance XBM image support
* JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
* JDK-8377347: jdk/jfr/event/gc/detailed/ /TestZAllocationStallEvent.java intermittent OOME
* JDK-8377498: Improve HttpServer handling
* JDK-8377602: Create automated test for PageRange
* JDK-8377727: Ghost caret and focus appear in non‑editable text fields
* JDK-8377833: Enhance Jar file processing
* JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java
* JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
* JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
* JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
* JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int
* JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
* JDK-8378561: Mark gc/shenandoah/compiler/ /TestLinkToNativeRBP.java as /native
* JDK-8378687: Improve delegation of HttpURLConnection
* JDK-8378775: Bump update version for OpenJDK: jdk-21.0.12
* JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
* JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V
* JDK-8378878: Refactor java/nio/channels/ /AsynchronousSocketChannel test to use JUnit
* JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V
* JDK-8380011: Path-to-gcroots search should not trigger stack overflows
* JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit
* JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
* JDK-8380428: ProblemList containers/docker/ /TestJcmdWithSideCar.java on linux-all
* JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792
* JDK-8380565: PPC64: deoptimization stub should save vector registers
* JDK-8380672: Improve certification checking
* JDK-8380947: Add pull request template
* JDK-8381039: Enhance AWT ImagingLib
* JDK-8381049: Enhance Jar handling
* JDK-8381205: GHA: Upgrade Node.js 20 to 24
* JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565
* JDK-8381519: Enhance Der Value Handling
* JDK-8381796: Enhance Certificate parsing
* JDK-8382018: test/jdk/java/nio/file/spi/ /SetDefaultProvider.java leaves a directory in /tmp
* JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
* JDK-8382419: Add missed @key randomness after JDK-8370489
* JDK-8383175: (tz) Update Timezone Data to 2026b
* JDK-8383185: [21u] Backport of JDK-8382925 causes test failure in SetDefaultProvider
* JDK-8383354: Update LCMS to 2.19.1
* JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
* JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
* JDK-8383630: Fix iteration in tests doing class redefinition
* JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
* JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
* JDK-8384495: Update Libpng to 1.6.58
* JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
* JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
* JDK-8384902: Update GIFlib to 6.1.3
* JDK-8385390: Update FreeType to 2.14.3
* JDK-8385490: Update HarfBuzz to 14.2.0
* JDK-8386551: Windows build broken because of MSys2/Make update
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3332=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3332=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3332=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3332=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* java-21-openjdk-jmods-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-src-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* openSUSE Leap 15.6 (noarch)
* java-21-openjdk-javadoc-21.0.12.0-150600.3.29.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
* https://bugzilla.suse.com/show_bug.cgi?id64397
* https://bugzilla.suse.com/show_bug.cgi?id64994
* https://bugzilla.suse.com/show_bug.cgi?id67355
* https://bugzilla.suse.com/show_bug.cgi?id72223
* https://bugzilla.suse.com/show_bug.cgi?id72224
* https://bugzilla.suse.com/show_bug.cgi?id72225
* https://bugzilla.suse.com/show_bug.cgi?id72227
* https://bugzilla.suse.com/show_bug.cgi?id72228
* https://bugzilla.suse.com/show_bug.cgi?id72235
* https://bugzilla.suse.com/show_bug.cgi?id72236
* https://bugzilla.suse.com/show_bug.cgi?id72237
SUSE-SU-2026:3335-1: important: Security update for ImageMagick
# Security update for ImageMagick
Announcement ID: SUSE-SU-2026:3335-1
Release Date: 2026-07-28T09:43:52Z
Rating: important
References:
* bsc#1268878
Cross-References:
* CVE-2026-56379
CVSS scores:
* CVE-2026-56379 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for ImageMagick fixes the following issue
* Extend CVE-2026-56379 patch by f63c78b (bsc#1268878).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3335=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3335=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3335=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3335=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3335=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3335=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3335=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3335=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3335=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3335=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3335=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3335=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-extra-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.104.1
* libMagick++-devel-64bit-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1
* ImageMagick-devel-64bit-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (x86_64)
* ImageMagick-devel-32bit-7.1.0.9-150400.6.104.1
* libMagick++-devel-32bit-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (noarch)
* ImageMagick-doc-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://bugzilla.suse.com/show_bug.cgi?id68878
SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3
# Security update for webkit2gtk3
Announcement ID: SUSE-SU-2026:3338-1
Release Date: 2026-07-28T09:55:09Z
Rating: important
References:
* bsc#1271638
Cross-References:
* CVE-2024-4367
* CVE-2026-39872
* CVE-2026-43663
* CVE-2026-43676
* CVE-2026-43699
* CVE-2026-43701
* CVE-2026-43705
* CVE-2026-43707
* CVE-2026-43712
* CVE-2026-43713
* CVE-2026-43715
* CVE-2026-43716
* CVE-2026-43720
* CVE-2026-43721
* CVE-2026-43725
* CVE-2026-43726
* CVE-2026-43727
* CVE-2026-43731
* CVE-2026-43732
* CVE-2026-43734
* CVE-2026-43740
* CVE-2026-43742
* CVE-2026-43745
CVSS scores:
* CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-39872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43701 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43705 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43707 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43713 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43716 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43721 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43725 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43726 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43731 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43732 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43734 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43742 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves 23 vulnerabilities can now be installed.
## Description:
This update for webkit2gtk3 fixes the following issues:
* CVE-2024-4367: missing type check when handling fonts in PDF.js can allow
arbitrary JavaScript execution (bsc#1271638).
* CVE-2026-39872: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43663: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43676: out-of-bounds access when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43699: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43701: malicious website can process restricted web content outside
the sandbox (bsc#1271638).
* CVE-2026-43705: type confusion issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43707: memory corruption issue when processing web content can lead
to an unexpected process crash (bsc#1271638).
* CVE-2026-43712: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43713: visiting a website can leak sensitive data due to a
permissions issue (bsc#1271638).
* CVE-2026-43715: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43716: maliciously crafted web content can lead to an unexpected
Safari crash (bsc#1271638).
* CVE-2026-43720: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43721: malicious website can silently hijack clipboard data
(bsc#1271638).
* CVE-2026-43725: unvalidated input can allow a malicious website to process
restricted web content outside the sandbox (bsc#1271638).
* CVE-2026-43726: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43727: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43731: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43732: path handling issue when processing web content can disclose
sensitive user information (bsc#1271638).
* CVE-2026-43734: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43740: maliciously crafted web content can result in the disclosure
of process memory (bsc#1271638).
* CVE-2026-43742: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43745: out-of-bounds write issue when processing web content can
lead to an unexpected Safari crash (bsc#1271638).
Changes for webkit2gtk3:
* Update to version 2.52.5:
* Fire scrollend event for instant programmatic scrolls.
* Increase network idle connection timeout to 115 seconds.
* Add User-Agent quirk for HBO Max.
* Fix the build with system malloc.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3338=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3338=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3338=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3338=1
## Package List:
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* webkit-jsc-6.0-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* webkit-jsc-4-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-minibrowser-2.52.5-150600.12.71.1
* webkit-jsc-6.0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-minibrowser-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-minibrowser-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-minibrowser-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk4-minibrowser-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkit-jsc-4.1-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit-jsc-4.1-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-minibrowser-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* webkit-jsc-4-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-64bit-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-64bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-64bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-64bit-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (x86_64)
* libjavascriptcoregtk-4_0-18-32bit-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.5-150600.12.71.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* Basesystem Module 15-SP7 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* Desktop Applications Module 15-SP7 (noarch)
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
## References:
* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
* https://www.suse.com/security/cve/CVE-2026-43731.html
* https://www.suse.com/security/cve/CVE-2026-43732.html
* https://www.suse.com/security/cve/CVE-2026-43734.html
* https://www.suse.com/security/cve/CVE-2026-43740.html
* https://www.suse.com/security/cve/CVE-2026-43742.html
* https://www.suse.com/security/cve/CVE-2026-43745.html
* https://bugzilla.suse.com/show_bug.cgi?id71638
SUSE-SU-2026:3340-1: moderate: Security update for nmap
# Security update for nmap
Announcement ID: SUSE-SU-2026:3340-1
Release Date: 2026-07-28T10:04:18Z
Rating: moderate
References:
* bsc#1269570
Cross-References:
* CVE-2026-58058
CVSS scores:
* CVE-2026-58058 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58058 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for nmap fixes the following issue:
* CVE-2026-58058: crafted IPv6 response with a truncated extension header can
trigger out-of-bounds reads and a crash (bsc#1269570).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3340=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3340=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3340=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nping-7.92-150600.9.3.1
* nping-debuginfo-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* ncat-debuginfo-7.92-150600.9.3.1
* ncat-7.92-150600.9.3.1
* nmap-debugsource-7.92-150600.9.3.1
* nmap-7.92-150600.9.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nmap-debugsource-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* nmap-7.92-150600.9.3.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* nping-7.92-150600.9.3.1
* nmap-debugsource-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* nping-debuginfo-7.92-150600.9.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-58058.html
* https://bugzilla.suse.com/show_bug.cgi?id69570
SUSE-SU-2026:3341-1: important: Security update for glib2
# Security update for glib2
Announcement ID: SUSE-SU-2026:3341-1
Release Date: 2026-07-28T10:09:32Z
Rating: important
References:
* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021
Cross-References:
* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016
CVSS scores:
* CVE-2026-58010 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58012 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities can now be installed.
## Description:
This update for glib2 fixes the following issues:
* CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could
cause a 1-byte out-of-bounds read (bsc#1270009).
* CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a
2-byte out-of-bounds read (bsc#1270010).
* CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-
change replacements could cause an out-of- bounds read (bsc#1270016).
* CVE-2026-58013: multi-byte custom line terminator in
g_io_channel_read_line_backend could trigger an out-of-bounds read
(bsc#1270018).
* CVE-2026-58014: processing empty key file values in
g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access
(bsc#1270021).
* CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned
integer overflow (bsc#1270008).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3341=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3341=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3341=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3341=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libgio-2_0-0-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tests-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tests-devel-debuginfo-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* glib2-devel-2.78.6-150600.4.38.1
* glib2-doc-2.78.6-150600.4.38.1
* glib2-devel-static-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libgmodule-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-64bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-64bit-2.78.6-150600.4.38.1
* libgio-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-64bit-2.78.6-150600.4.38.1
* libgobject-2_0-0-64bit-2.78.6-150600.4.38.1
* glib2-tools-64bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-64bit-2.78.6-150600.4.38.1
* libgthread-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-64bit-2.78.6-150600.4.38.1
* glib2-tools-64bit-2.78.6-150600.4.38.1
* libgio-2_0-0-64bit-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-32bit-2.78.6-150600.4.38.1
* glib2-devel-32bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* gio-branding-upstream-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* glib2-lang-2.78.6-150600.4.38.1
## References:
* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html
* https://bugzilla.suse.com/show_bug.cgi?id70008
* https://bugzilla.suse.com/show_bug.cgi?id70009
* https://bugzilla.suse.com/show_bug.cgi?id70010
* https://bugzilla.suse.com/show_bug.cgi?id70016
* https://bugzilla.suse.com/show_bug.cgi?id70018
* https://bugzilla.suse.com/show_bug.cgi?id70021
SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)
# Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise
15 SP5)
Announcement ID: SUSE-SU-2026:3350-1
Release Date: 2026-07-28T12:09:45Z
Rating: important
References:
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-43038
* CVE-2026-53359
CVSS scores:
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves two vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.172 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3350=1 SUSE-2026-3346=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3346=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3350=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3324=1
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3324=1
## Package List:
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
# Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise
15 SP5)
Announcement ID: SUSE-SU-2026:3351-1
Release Date: 2026-07-28T12:10:24Z
Rating: important
References:
* bsc#1266970
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
CVSS scores:
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves three vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3351=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3351=1
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3328=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3349=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3349=1 SUSE-2026-3328=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
# Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise
15 SP6)
Announcement ID: SUSE-SU-2026:3344-1
Release Date: 2026-07-28T12:06:44Z
Rating: important
References:
* bsc#1266970
* bsc#1270060
* bsc#1271370
Cross-References:
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366
CVSS scores:
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves three vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3344=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3344=1
## Package List:
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)
# Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise
15 SP4)
Announcement ID: SUSE-SU-2026:3345-1
Release Date: 2026-07-28T12:12:16Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves five vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.184 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3347=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3348=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3353=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3345=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3352=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3347=1 SUSE-2026-3348=1 SUSE-2026-3353=1
SUSE-2026-3345=1 SUSE-2026-3352=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648
openSUSE-SU-2026:21453-1: important: Security update for chromium
openSUSE security update: security update for chromium
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21453-1
Rating: important
References:
* bsc#1272460
Cross-References:
* CVE-2026-16804
* CVE-2026-16805
* CVE-2026-16806
* CVE-2026-16807
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 4 vulnerabilities and has one bug fix can now be installed.
Description:
This update for chromium fixes the following issues:
Changes in chromium:
- Chromium 150.0.7871.186 (boo#1272460):
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260724162718479796.93181000773252=1
Package List:
- openSUSE Leap 16.0:
chromedriver-150.0.7871.186-bp160.1.1
chromium-150.0.7871.186-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-16804.html
* https://www.suse.com/security/cve/CVE-2026-16805.html
* https://www.suse.com/security/cve/CVE-2026-16806.html
* https://www.suse.com/security/cve/CVE-2026-16807.html
openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui
openSUSE security update: security update for agama-web-ui
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21448-1
Rating: important
References:
* bsc#1246822
* bsc#1259169
* bsc#1268851
* bsc#1269359
* bsc#1269514
* bsc#1269595
* bsc#1269927
* bsc#1272310
* bsc#1272311
* bsc#1272312
* bsc#1272313
* bsc#1272317
* bsc#1272318
* bsc#1272319
Cross-References:
* CVE-2025-7783
* CVE-2026-12143
* CVE-2026-13149
* CVE-2026-13311
* CVE-2026-13676
* CVE-2026-27601
* CVE-2026-40181
* CVE-2026-49356
* CVE-2026-53550
* CVE-2026-53632
* CVE-2026-54466
* CVE-2026-54490
* CVE-2026-55602
CVSS scores:
* CVE-2025-7783 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-7783 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:N
* CVE-2026-12143 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13149 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13149 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13311 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13311 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13676 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-13676 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2026-27601 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-27601 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-40181 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-49356 ( SUSE ): 3.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
* CVE-2026-53550 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-53550 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-53632 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-54466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-54466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-54490 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54490 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-55602 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 13 vulnerabilities and has 14 bug fixes can now be installed.
Description:
This update for agama-web-ui fixes the following issues:
- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart
form-encoded data (bsc#1246822).
- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).
- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing
non-expanding `{}` brace groups (bsc#1269927).
- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings
(bsc#1269359).
- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for
HTTP-family URLs (bsc#1269595).
- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual`
functions (bsc#1259169).
- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being
reinterpreted as protocol-relative URLs (bsc#1272311).
- CVE-2026-49356: @babel/core: arbitrary file read via `sourceMappingURL` comment (bsc#1272317).
- CVE-2026-53550: js-yaml: quadratic complexity in merge-key processing when processing a crafted YAML document
(bsc#1268851).
- CVE-2026-53632: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows (bsc#1272319).
- CVE-2026-54466: websocket-driver: message corruption via abuse of protocol length headers (bsc#1272312).
- CVE-2026-54490: websocket-driver: resource limit bypass via message compression (bsc#1272313).
- CVE-2026-55602: http-proxy-middleware: Host-header-driven backend routing bypass via `router` host+path substring
matching (bsc#1272318).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1354=1
Package List:
- openSUSE Leap 16.0:
agama-web-ui-17+673.b97ba64d6-160000.12.1
References:
* https://www.suse.com/security/cve/CVE-2025-7783.html
* https://www.suse.com/security/cve/CVE-2026-12143.html
* https://www.suse.com/security/cve/CVE-2026-13149.html
* https://www.suse.com/security/cve/CVE-2026-13311.html
* https://www.suse.com/security/cve/CVE-2026-13676.html
* https://www.suse.com/security/cve/CVE-2026-27601.html
* https://www.suse.com/security/cve/CVE-2026-40181.html
* https://www.suse.com/security/cve/CVE-2026-49356.html
* https://www.suse.com/security/cve/CVE-2026-53550.html
* https://www.suse.com/security/cve/CVE-2026-53632.html
* https://www.suse.com/security/cve/CVE-2026-54466.html
* https://www.suse.com/security/cve/CVE-2026-54490.html
* https://www.suse.com/security/cve/CVE-2026-55602.html
SUSE-SU-2026:3362-1: important: Security update for samba
# Security update for samba
Announcement ID: SUSE-SU-2026:3362-1
Release Date: 2026-07-28T12:18:51Z
Rating: important
References:
* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677
Cross-References:
* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949
CVSS scores:
* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Availability Extension 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for samba fixes the following issues
* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3362=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3362=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3362=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3362=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3362=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3362=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-test-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (x86_64)
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (aarch64 x86_64)
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (noarch)
* samba-doc-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64)
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le
s390x x86_64)
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677
SUSE-SU-2026:3364-1: important: Security update for samba
# Security update for samba
Announcement ID: SUSE-SU-2026:3364-1
Release Date: 2026-07-28T12:19:49Z
Rating: important
References:
* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677
Cross-References:
* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949
CVSS scores:
* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise High Availability Extension 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for samba fixes the following issues
* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3364=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3364=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3364=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3364=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-pcp-pmda-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-test-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-test-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-pcp-pmda-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* samba-client-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (x86_64)
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (noarch)
* samba-doc-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (aarch64 x86_64)
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le
s390x x86_64)
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677
SUSE-SU-2026:3365-1: important: Security update for samba
# Security update for samba
Announcement ID: SUSE-SU-2026:3365-1
Release Date: 2026-07-28T12:20:57Z
Rating: important
References:
* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677
Cross-References:
* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949
CVSS scores:
* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Availability Extension 15 SP5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for samba fixes the following issues
* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Availability Extension 15 SP5
zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-3365=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3365=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3365=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3365=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3365=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3365=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3365=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-test-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-test-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-pcp-pmda-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-pcp-pmda-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (aarch64 x86_64)
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libsamba-policy0-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (noarch)
* samba-doc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64)
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le
s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677
SUSE-SU-2026:3366-1: important: Security update for samba
# Security update for samba
Announcement ID: SUSE-SU-2026:3366-1
Release Date: 2026-07-28T12:21:29Z
Rating: important
References:
* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677
Cross-References:
* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949
CVSS scores:
* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.3
* SUSE Enterprise Storage 7.1
* SUSE Linux Enterprise Server 15 SP3
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for samba fixes the following issues
* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3366=1
* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2026-3366=1
## Package List:
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-test-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (x86_64)
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (aarch64_ilp32)
* libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (noarch)
* samba-doc-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (aarch64 x86_64)
* samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* SUSE Enterprise Storage 7.1 (aarch64 x86_64)
* samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677
SUSE-SU-2026:3368-1: moderate: Security update for sssd
# Security update for sssd
Announcement ID: SUSE-SU-2026:3368-1
Release Date: 2026-07-28T12:23:46Z
Rating: moderate
References:
* bsc#1269807
Cross-References:
* CVE-2026-12610
CVSS scores:
* CVE-2026-12610 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
An update that solves one vulnerability can now be installed.
## Description:
This update for sssd fixes the following issue:
* CVE-2026-12610: cancelled or completed PAM request while the asynchronous
child process is still running can lead to a use-after-free (bsc#1269807).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3368=1
## Package List:
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python3-sssd-config-debuginfo-2.5.2-150400.4.48.1
* python3-ipa_hbac-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp-devel-2.5.2-150400.4.48.1
* sssd-krb5-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* libsss_idmap-devel-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap-devel-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp0-2.5.2-150400.4.48.1
* libipa_hbac-devel-2.5.2-150400.4.48.1
* python3-sssd-config-2.5.2-150400.4.48.1
* sssd-proxy-debuginfo-2.5.2-150400.4.48.1
* sssd-ipa-debuginfo-2.5.2-150400.4.48.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.48.1
* python3-ipa_hbac-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-krb5-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-ad-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* python3-sss-murmur-debuginfo-2.5.2-150400.4.48.1
* python3-sss-murmur-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* libipa_hbac0-2.5.2-150400.4.48.1
* sssd-dbus-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.48.1
* sssd-kcm-debuginfo-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-tools-debuginfo-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* libsss_certmap0-2.5.2-150400.4.48.1
* sssd-tools-2.5.2-150400.4.48.1
* libnfsidmap-sss-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.48.1
* sssd-proxy-2.5.2-150400.4.48.1
* sssd-dbus-debuginfo-2.5.2-150400.4.48.1
* python3-sss_nss_idmap-2.5.2-150400.4.48.1
* sssd-ad-2.5.2-150400.4.48.1
* sssd-kcm-2.5.2-150400.4.48.1
* sssd-winbind-idmap-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap-devel-2.5.2-150400.4.48.1
* sssd-ipa-2.5.2-150400.4.48.1
* libnfsidmap-sss-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* sssd-common-64bit-debuginfo-2.5.2-150400.4.48.1
* sssd-common-64bit-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (x86_64)
* sssd-common-32bit-2.5.2-150400.4.48.1
* sssd-common-32bit-debuginfo-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
## References:
* https://www.suse.com/security/cve/CVE-2026-12610.html
* https://bugzilla.suse.com/show_bug.cgi?id69807
SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)
# Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise
15 SP4)
Announcement ID: SUSE-SU-2026:3354-1
Release Date: 2026-07-28T12:16:30Z
Rating: important
References:
* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648
Cross-References:
* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
CVSS scores:
* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves five vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.167 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3354=1 SUSE-2026-3358=1 SUSE-2026-3359=1
SUSE-2026-3357=1 SUSE-2026-3360=1 SUSE-2026-3361=1 SUSE-2026-3355=1
SUSE-2026-3356=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3354=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3358=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3359=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3357=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3360=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3361=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3355=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3356=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648
SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)
# Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise
15 SP7)
Announcement ID: SUSE-SU-2026:3372-1
Release Date: 2026-07-28T14:33:43Z
Rating: important
References:
* bsc#1270060
* bsc#1271370
Cross-References:
* CVE-2026-53359
* CVE-2026-53366
CVSS scores:
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.60 fixes
various security issues:
The following security issues were fixed:
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3371=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3372=1
* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3373=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3372=1 SUSE-2026-3371=1
## Package List:
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150700_53_60-default-debuginfo-3-150700.2.1
* kernel-livepatch-6_4_0-150700_53_60-default-3-150700.2.1
* kernel-livepatch-SLE15-SP7_Update_16-debugsource-3-150700.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370