SUSE 5722 Published by

SUSE published a batch of security advisories in 2026 that address vulnerabilities across multiple Linux distributions and enterprise platforms. The updates include critical Live Patch releases for the Linux Kernel targeting SUSE Linux Enterprise versions 15 SP4 through SP7, alongside fixes for widely used software like samba, chromium, nginx, and java-21-openjdk. Several openSUSE community advisories also landed on general availability media, covering packages such as valkey, python313-CherryPy, libssh-config, and ignition.

openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media
openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media
openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media
openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media
SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3300-1: important: Security update for ignition
SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)
SUSE-SU-2026:3327-1: important: Security update for yq
SUSE-SU-2026:3329-1: important: Security update for nginx
SUSE-SU-2026:3330-1: moderate: Security update for libssh
SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk
SUSE-SU-2026:3335-1: important: Security update for ImageMagick
SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3
SUSE-SU-2026:3340-1: moderate: Security update for nmap
SUSE-SU-2026:3341-1: important: Security update for glib2
SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)
SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)
SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)
openSUSE-SU-2026:21453-1: important: Security update for chromium
openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui
SUSE-SU-2026:3362-1: important: Security update for samba
SUSE-SU-2026:3364-1: important: Security update for samba
SUSE-SU-2026:3365-1: important: Security update for samba
SUSE-SU-2026:3366-1: important: Security update for samba
SUSE-SU-2026:3368-1: moderate: Security update for sssd
SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)
SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)




openSUSE-SU-2026:11381-1: moderate: valkey-9.1.1-1.1 on GA media


# valkey-9.1.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11381-1
Rating: moderate

Cross-References:

* CVE-2026-56684
* CVE-2026-63639

CVSS scores:

* CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the valkey-9.1.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* valkey 9.1.1-1.1
* valkey-compat-redis 9.1.1-1.1
* valkey-devel 9.1.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56684.html
* https://www.suse.com/security/cve/CVE-2026-63639.html



openSUSE-SU-2026:11378-1: moderate: python313-CherryPy-18.10.0-4.1 on GA media


# python313-CherryPy-18.10.0-4.1 on GA media

Announcement ID: openSUSE-SU-2026:11378-1
Rating: moderate

Cross-References:

* CVE-2019-9740

CVSS scores:

* CVE-2019-9740 ( SUSE ): 5.4 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-CherryPy-18.10.0-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-CherryPy 18.10.0-4.1
* python314-CherryPy 18.10.0-4.1

## References:

* https://www.suse.com/security/cve/CVE-2019-9740.html



openSUSE-SU-2026:11377-1: moderate: libssh-config-0.11.5-1.1 on GA media


# libssh-config-0.11.5-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11377-1
Rating: moderate

Cross-References:

* CVE-2026-15370
* CVE-2026-59843
* CVE-2026-59844
* CVE-2026-59845
* CVE-2026-59846
* CVE-2026-59847
* CVE-2026-59848
* CVE-2026-59849
* CVE-2026-59850

CVSS scores:

* CVE-2026-15370 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-15370 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
* CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59849 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59849 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 9 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libssh-config-0.11.5-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libssh-config 0.11.5-1.1
* libssh-devel 0.11.5-1.1
* libssh4 0.11.5-1.1
* libssh4-32bit 0.11.5-1.2

## References:

* https://www.suse.com/security/cve/CVE-2026-15370.html
* https://www.suse.com/security/cve/CVE-2026-59843.html
* https://www.suse.com/security/cve/CVE-2026-59844.html
* https://www.suse.com/security/cve/CVE-2026-59845.html
* https://www.suse.com/security/cve/CVE-2026-59846.html
* https://www.suse.com/security/cve/CVE-2026-59847.html
* https://www.suse.com/security/cve/CVE-2026-59848.html
* https://www.suse.com/security/cve/CVE-2026-59849.html
* https://www.suse.com/security/cve/CVE-2026-59850.html



openSUSE-SU-2026:11376-1: moderate: ignition-2.26.0-5.1 on GA media


# ignition-2.26.0-5.1 on GA media

Announcement ID: openSUSE-SU-2026:11376-1
Rating: moderate

Cross-References:

* CVE-2026-34986
* CVE-2026-39821
* CVE-2026-56852

CVSS scores:

* CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the ignition-2.26.0-5.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* ignition 2.26.0-5.1

## References:

* https://www.suse.com/security/cve/CVE-2026-34986.html
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html



SUSE-SU-2026:3319-1: important: Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise 15 SP5)


# Security update for the Linux Kernel (Live Patch 35 for SUSE Linux Enterprise
15 SP5)

Announcement ID: SUSE-SU-2026:3319-1
Release Date: 2026-07-28T03:33:52Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves five vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.136 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3319=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3320=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3319=1 SUSE-2026-3320=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_35-debugsource-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-10-150500.2.1
* kernel-livepatch-5_14_21-150500_55_149-default-6-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_38-debugsource-6-150500.2.1
* kernel-livepatch-5_14_21-150500_55_136-default-10-150500.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3300-1: important: Security update for ignition


# Security update for ignition

Announcement ID: SUSE-SU-2026:3300-1
Release Date: 2026-07-27T17:00:29Z
Rating: important
References:

* bsc#1266606
* bsc#1272059

Cross-References:

* CVE-2026-39821
* CVE-2026-56852

CVSS scores:

* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* HPC Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7

An update that solves two vulnerabilities can now be installed.

## Description:

This update for ignition fixes the following issues

* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1266606).
* CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing
invalid UTF-8 bytes can lead to infinite loop (bsc#1272059).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3300=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3300=1

* HPC Module 15-SP7
zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3300=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1
* HPC Module 15-SP7 (aarch64 x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* ignition-debuginfo-2.14.0-150400.9.21.1
* ignition-dracut-grub2-2.14.0-150400.9.21.1
* ignition-2.14.0-150400.9.21.1

## References:

* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id66606
* https://bugzilla.suse.com/show_bug.cgi?id72059



SUSE-SU-2026:3316-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 15 SP7)


# Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux
Enterprise 15 SP7)

Announcement ID: SUSE-SU-2026:3316-1
Release Date: 2026-07-27T19:36:28Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271370
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves six vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.8 fixes various
security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3316=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3315=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3308=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-3307=1
SUSE-SLE-Module-Live-Patching-15-SP6-2026-3314=1 SUSE-SLE-Module-Live-
Patching-15-SP6-2026-3311=1

* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3303=1 SUSE-SLE-
Module-Live-Patching-15-SP7-2026-3304=1 SUSE-SLE-Module-Live-
Patching-15-SP7-2026-3309=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3312=1
SUSE-SLE-Module-Live-Patching-15-SP7-2026-3306=1 SUSE-SLE-Module-Live-
Patching-15-SP7-2026-3310=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-3305=1
SUSE-SLE-Module-Live-Patching-15-SP7-2026-3313=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3316=1 SUSE-2026-3315=1 SUSE-2026-3308=1
SUSE-2026-3307=1 SUSE-2026-3314=1 SUSE-2026-3311=1

## Package List:

* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP7_Update_5-debugsource-12-150700.2.1
* kernel-livepatch-6_4_0-150700_53_16-default-15-150700.2.1
* kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-12-150700.2.1
* kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-15-150700.2.1
* kernel-livepatch-6_4_0-150700_53_19-default-12-150700.2.1
* kernel-livepatch-SLE15-SP7_Update_4-debugsource-15-150700.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (x86_64)
* kernel-livepatch-6_4_0-150700_7_22-rt-11-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_2-debugsource-19-150700.2.1
* kernel-livepatch-6_4_0-150700_7_8-rt-debuginfo-19-150700.2.1
* kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-15-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-11-150700.2.1
* kernel-livepatch-6_4_0-150700_7_8-rt-19-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_13-rt-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_25-rt-10-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-10-150700.2.1
* kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-11-150700.2.1
* kernel-livepatch-6_4_0-150700_7_16-rt-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-12-150700.2.1
* kernel-livepatch-6_4_0-150700_7_19-rt-12-150700.2.1
* kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-10-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-15-150700.2.1
* kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-15-150700.2.1
* kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-12-150700.2.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_14-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_18-debugsource-10-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_13-debugsource-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_16-debugsource-12-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_15-debugsource-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-12-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_70-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_60-default-19-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-15-150600.2.1
* kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-10-150600.2.1
* kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-15-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_17-debugsource-10-150600.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3327-1: important: Security update for yq


# Security update for yq

Announcement ID: SUSE-SU-2026:3327-1
Release Date: 2026-07-28T09:18:18Z
Rating: important
References:

* bsc#1267199
* bsc#1271994

Cross-References:

* CVE-2026-39821
* CVE-2026-56852

CVSS scores:

* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves two vulnerabilities can now be installed.

## Description:

This update for yq fixes the following issues:

Update to v4.53.3.

* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1267199).
* CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input
containing invalid UTF-8 bytes can lead to infinite loop (bsc#1271994).

Changes for yq:

* v4.53.3:
* Add --ini-preserve-quotes flag for INI round-trip quote preservation.
* Fix: reset INI decoder state on init.
* Fix: decode properties array bracket paths.
* Fix: preserve floats with trailing zero when encoding YAML to JSON.
* Fix: JSON to TOML root scope and null handling.
* Fix: reset TOML decoder finished flag on Init for multi-doc evaluation.
* Fix: reset TOML decoder between files when evaluating all at once.
* Fix: preserve TOML inline table array scope.
* Fix: preserve empty TOML arrays in tables
* Fix: TOML encoder uses inline tables for YAML FlowStyle mappings.
* Fix nested inline YAML merge explode.
* Fix repeatString overflow test on 32-bit platforms.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3327=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3327=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* yq-debuginfo-4.53.3-150500.3.12.1
* yq-4.53.3-150500.3.12.1
* openSUSE Leap 15.5 (noarch)
* yq-bash-completion-4.53.3-150500.3.12.1
* yq-zsh-completion-4.53.3-150500.3.12.1
* yq-fish-completion-4.53.3-150500.3.12.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* yq-debuginfo-4.53.3-150500.3.12.1
* yq-4.53.3-150500.3.12.1

## References:

* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id67199
* https://bugzilla.suse.com/show_bug.cgi?id71994



SUSE-SU-2026:3329-1: important: Security update for nginx


# Security update for nginx

Announcement ID: SUSE-SU-2026:3329-1
Release Date: 2026-07-28T09:34:39Z
Rating: important
References:

* bsc#1267525
* bsc#1268492
* bsc#1268495

Cross-References:

* CVE-2026-42055
* CVE-2026-48142

CVSS scores:

* CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42055 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-48142 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products:

* openSUSE Leap 15.6
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves two vulnerabilities and has one security fix can now be
installed.

## Description:

This update for nginx fixes the following issues

* CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module`
and `ngx_http_grpc_module` modules (bsc#1268492).
* CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module`
module (bsc#1268495).
* Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3329=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3329=1

* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3329=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3329=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* openSUSE Leap 15.6 (noarch)
* nginx-source-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* nginx-source-1.21.5-150600.10.24.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* Server Applications Module 15-SP7 (noarch)
* nginx-source-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* nginx-debugsource-1.21.5-150600.10.24.1
* nginx-debuginfo-1.21.5-150600.10.24.1
* nginx-1.21.5-150600.10.24.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* nginx-source-1.21.5-150600.10.24.1

## References:

* https://www.suse.com/security/cve/CVE-2026-42055.html
* https://www.suse.com/security/cve/CVE-2026-48142.html
* https://bugzilla.suse.com/show_bug.cgi?id67525
* https://bugzilla.suse.com/show_bug.cgi?id68492
* https://bugzilla.suse.com/show_bug.cgi?id68495



SUSE-SU-2026:3330-1: moderate: Security update for libssh


# Security update for libssh

Announcement ID: SUSE-SU-2026:3330-1
Release Date: 2026-07-28T09:36:04Z
Rating: moderate
References:

* bsc#1272164
* bsc#1272165
* bsc#1272166
* bsc#1272167
* bsc#1272168
* bsc#1272169
* bsc#1272171

Cross-References:

* CVE-2026-59843
* CVE-2026-59844
* CVE-2026-59845
* CVE-2026-59846
* CVE-2026-59847
* CVE-2026-59848
* CVE-2026-59850

CVSS scores:

* CVE-2026-59843 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59845 ( SUSE ): 8.2
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H
* CVE-2026-59846 ( SUSE ): 2.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59847 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
* CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-59848 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for libssh fixes the following issues:

* CVE-2026-59843: denial of service via zero advertised channel packet size
(bsc#1272164).
* CVE-2026-59844: denial of service via oversized SFTP read length
(bsc#1272165).
* CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure
(bsc#1272166).
* CVE-2026-59846: information disclosure via ProxyCommand %r username
expansion (bsc#1272167).
* CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification
(bsc#1272168).
* CVE-2026-59848: denial of service via SFTP responses with unknown request
IDs (bsc#1272169).
* CVE-2026-59850: use-after-free via data callbacks on closed channels
(bsc#1272171).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3330=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3330=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3330=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3330=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libssh4-64bit-0.9.8-150600.11.15.1
* libssh4-64bit-debuginfo-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* Basesystem Module 15-SP7 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libssh4-32bit-0.9.8-150600.11.15.1
* libssh4-32bit-debuginfo-0.9.8-150600.11.15.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libssh4-debuginfo-0.9.8-150600.11.15.1
* libssh-config-0.9.8-150600.11.15.1
* libssh4-0.9.8-150600.11.15.1
* libssh-devel-0.9.8-150600.11.15.1
* libssh-debugsource-0.9.8-150600.11.15.1

## References:

* https://www.suse.com/security/cve/CVE-2026-59843.html
* https://www.suse.com/security/cve/CVE-2026-59844.html
* https://www.suse.com/security/cve/CVE-2026-59845.html
* https://www.suse.com/security/cve/CVE-2026-59846.html
* https://www.suse.com/security/cve/CVE-2026-59847.html
* https://www.suse.com/security/cve/CVE-2026-59848.html
* https://www.suse.com/security/cve/CVE-2026-59850.html
* https://bugzilla.suse.com/show_bug.cgi?id72164
* https://bugzilla.suse.com/show_bug.cgi?id72165
* https://bugzilla.suse.com/show_bug.cgi?id72166
* https://bugzilla.suse.com/show_bug.cgi?id72167
* https://bugzilla.suse.com/show_bug.cgi?id72168
* https://bugzilla.suse.com/show_bug.cgi?id72169
* https://bugzilla.suse.com/show_bug.cgi?id72171



SUSE-SU-2026:3332-1: important: Security update for java-21-openjdk


# Security update for java-21-openjdk

Announcement ID: SUSE-SU-2026:3332-1
Release Date: 2026-07-28T09:37:59Z
Rating: important
References:

* bsc#1264397
* bsc#1264994
* bsc#1267355
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237

Cross-References:

* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147

CVSS scores:

* CVE-2026-41254 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46968 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47010 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47021 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47063 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-60147 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves nine vulnerabilities and has two security fixes can now be
installed.

## Description:

This update for java-21-openjdk fixes the following issues:

Update to upstream tag jdk-21.0.12+8 (July 2026 CPU).

Security issues fixed:

* CVE-2026-41254: lcms: information disclosure and denial of service via
integer overflow in `CubeSize` (bsc#1264994).
* CVE-2026-46917: unauthenticated attacker with network access via TLS can
cause a partial denial of service (bsc#1272223).
* CVE-2026-46968: unauthenticated attacker with network access via TLS can
gain unauthorized creation, deletion or modification access to critical
data(bsc#1272224).
* CVE-2026-47010: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert or delete access to some data
(bsc#1272225).
* CVE-2026-47021: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272227).
* CVE-2026-47027: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272228).
* CVE-2026-47059: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272235).
* CVE-2026-47063: unauthenticated attacker with network access via multiple
protocols can gain unauthorized creation, deletion or modification access to
critical data (bsc#1272236).
* CVE-2026-60147: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert, delete and read access to
some(bsc#1272237).

Other updates and bugfixes:

* Errors from update-alternatives when installing java-25-openjdk
(bsc#1267355).
* Make post scripts less noisy (bsc#1267355).
* Use libalternatives instead of update-alternatives for distributions where
libalternatives is available.
* Update to upstream tag jdk-21.0.12+8 (July 2026 CPU):
* JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
* JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
* JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails
* JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
* JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F
* JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update
* JDK-8129418: JShell: better highlighting of errors in imports on demand
* JDK-8144124: [macosx] The tabs can't be aligned when we pressing the key of 'R','B','L','C' or 'T'.
* JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java
* JDK-8203004: UnixMultiResolutionSplashTest.java fails on Ubuntu16.04
* JDK-8212084: G1: Implement UseGCOverheadLimit
* JDK-8213530: Test java/awt/Modal/ToFront/ /DialogToFrontModeless1Test.java fails on Linux
* JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
* JDK-8225787: java/awt/Window/GetScreenLocation/ /GetScreenLocationTest.java fails on Ubuntu
* JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
* JDK-8274082: Wrong test name in jtreg run tag for java/awt/print/PrinterJob/SwingUIText.java
* JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
* JDK-8278102: containers/docker/TestJcmd.java failed with "RuntimeException: Could not find specified process"
* JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
* JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/nativeAndMH/ /Test.java fails with Out of space in CodeCache
* JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
* JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
* JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
* JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!"
* JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
* JDK-8310645: CancelledResponse.java does not use HTTP/2 when testing the HttpClient
* JDK-8311538: CDS InternSharedString test fails on huge pages host - cannot find shared string
* JDK-8315588: JShell does not accept underscore from JEP 443 even with --enable-preview
* JDK-8318365: Test runtime/cds/appcds/sharedStrings/ /InternSharedString.java fails after JDK-8311538
* JDK-8318662: Refactor some jdk/java/net/httpclient/http2 tests to JUnit
* JDK-8319326: GC: Make TestParallelRefProc use createTestJavaProcessBuilder
* JDK-8319540: GC: Make TestSelectDefaultGC use createTestJavaProcessBuilder
* JDK-8320677: Printer tests use invalid '@run main/manual=yesno
* JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux
* JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/ /TC03/tc03t002/TestDescription.java failed: JVMTI_ERROR_THREAD_NOT_ALIVE
* JDK-8322532: JShell : Unnamed variable issue
* JDK-8323089: networkaddress.cache.ttl is not a system property
* JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
* JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
* JDK-8323792: ThreadSnapshot::initialize can cause assert in Thread::check_for_dangling_thread_pointer (possibility of dangling Thread pointer)
* JDK-8326458: Menu mnemonics don't toggle in Windows LAF when F10 is pressed
* JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
* JDK-8329273: C2 SuperWord: Some basic MemorySegment IR tests
* JDK-8330704: Clean up non-standard use of /** comments in some langtools tests
* JDK-8330806: test/hotspot/jtreg/compiler/c1/ /TestLargeMonitorOffset.java fails on ARM32
* JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
* JDK-8333729: C2 SuperWord: remove some @requires usages in test/hotspot/jtreg/compiler/loopopts/superword
* JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use
* JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
* JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java
* JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
* JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
* JDK-8339638: Update vmTestbase/nsk/jvmti/_Field_ Watch tests to use virtual thread factory
* JDK-8339879: Open some dialog awt tests
* JDK-8339975: Open some dialog awt tests 2
* JDK-8340140: Open some dialog awt tests 3
* JDK-8340336: Open some checkbox awt tests
* JDK-8340494: Open some dialog awt tests 4
* JDK-8340818: Add a new jtreg test root to test the generated documentation
* JDK-8340851: Open some TextArea awt tests
* JDK-8340987: Open some TextArea awt tests 1
* JDK-8341055: Open some TextArea awt tests 2
* JDK-8341292: Open some TextArea awt tests 3
* JDK-8341376: Open some TextArea awt tests 4
* JDK-8341427: JFR: Adjust object sampler span handling
* JDK-8341436: containers/docker/TestJcmdWithSideCar.java takes needlessly long to run
* JDK-8341833: incomplete snippet from loaded files from command line is ignored
* JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
* JDK-8342836: Automatically determine that a test in the docs test root is requested
* JDK-8344128: Regression: make help broken after JDK-8340818
* JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete
* JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
* JDK-8346683: Problem list automated tests that fail on macOS15
* JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
* JDK-8349084: Update vectors used in several PQC benchmarks
* JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
* JDK-8349533: Refactor validator tests shell files to java
* JDK-8349699: XSL transform fails with certain UTF-8 characters on 1024 byte boundaries
* JDK-8349959: Test CR6740048.java passes unexpectedly missing CR6740048.xsd
* JDK-8350749: Upgrade JLine to 3.29.0
* JDK-8350808: Small typos in JShell method SnippetEvent .toString()
* JDK-8352020: [CompileFramework] enable compilation for VectorAPI
* JDK-8352147: G1: TestEagerReclaimHumongousRegionsClearMarkBits test takes very long
* JDK-8352149: Test java/awt/Frame/MultiScreenTest.java fails: Window list is empty
* JDK-8352431: java/net/httpclient/EmptyAuthenticate.java uses "localhost"
* JDK-8352685: Opensource JInternalFrame tests - series2
* JDK-8352733: Improve RotFontBoundsTest test
* JDK-8352877: Opensource Several Font related tests - Batch 1
* JDK-8353124: java/lang/Thread/virtual/stress/Skynet.java#Z times out on macosx-x64-debug
* JDK-8353488: Open some JComboBox bugs 3
* JDK-8353552: Opensource Several Font related tests - Batch 3
* JDK-8354163: Open source Swing tests Batch 1
* JDK-8354695: Open source several swing tests batch7
* JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
* JDK-8354910: Output by java.io.IO or System.console() corrupted for some non-ASCII characters
* JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
* JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run
* JDK-8355332: Fix failing semi-manual test EDT issue
* JDK-8355371: NegativeArraySizeException in print methods in IO or System.console() in JShell
* JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
* JDK-8356695: java/lang/StringBuilder/HugeCapacity.java failing with OOME
* JDK-8356868: Not all cgroup parameters are made available
* JDK-8357062: Update Public Suffix List to 823beb1
* JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
* JDK-8357086: os::xxx functions returning memory size should return size_t
* JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java
* JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
* JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
* JDK-8359364: java/net/URL/EarlyOrDelayedParsing test fails intermittently
* JDK-8359472: JVM crashes when attaching a dynamic agent before JVMTI_PHASE_LIVE
* JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
* JDK-8360160: ubuntu-22-04 machine is failing client tests
* JDK-8360395: sun/security/tools/keytool/i18n.java user country is current user location instead of the language
* JDK-8360562: sun/security/tools/keytool/i18n.java add an ability to add comment for failures
* JDK-8360702: runtime/Thread/AsyncExceptionTest.java timed out
* JDK-8360882: Tests throw SkippedException when they should fail
* JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
* JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
* JDK-8361894: sun/security/krb5/config/native/ /TestDynamicStore.java ensure that the test is run with sudo
* JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
* JDK-8363943: ARM32: Represent Registers as values
* JDK-8363949: Incorrect jtreg header in MonitorWithDeadObjectTest.java
* JDK-8364190: JFR: RemoteRecordingStream withers don't work
* JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles
* JDK-8364756: JFR: Improve slow tests
* JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
* JDK-8365379: SU3.applyInsets may produce wrong results
* JDK-8365398: TEST_BUG: java/rmi/transport/checkLeaseInfoLeak/ /CheckLeaseLeak.java failing intermittently
* JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26
* JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
* JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped without skip exception
* JDK-8365625: Can't change accelerator colors in Windows L&F
* JDK-8365776: Convert JShell tests to use JUnit instead of TestNG
* JDK-8365861: test/jdk/sun/security/pkcs11/Provider/ tests skipped without SkippedException
* JDK-8365863: /test/jdk/sun/security/pkcs11/Cipher tests skip without SkippedException
* JDK-8365893: test/jdk/java/lang/Thread/virtual/JfrEvents.java failing intermittently
* JDK-8366031: Mark com/sun/nio/sctp/SctpChannel/ /CloseDescriptors.java as intermittent
* JDK-8366182: Some PKCS11Tests are being skipped when they shouldn't
* JDK-8366369: Add @requires linux for GTK L&F tests
* JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing
* JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec, config, secmod and sslecc tests are skipping but showing as pass
* JDK-8367485: os::physical_memory is broken in 32-bit JVMs when running on 64-bit OSes
* JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner
* JDK-8368029: Several tests in httpserver/simpleserver should throw SkipException
* JDK-8368041: Enhance TLS certificate handling
* JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/ /ModalExcludedTest.java
* JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
* JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
* JDK-8368524: Tests are skipped and shown as passed in test/jdk/sun/security/pkcs11/Cipher/KeyWrap
* JDK-8368551: Core dump warning may be confusing
* JDK-8368625: com/sun/net/httpserver/ /ServerStopTerminationTest.java fails intermittently
* JDK-8368670: Deadlock in JFR on event register + class load
* JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
* JDK-8368866: compiler/codecache/stress/ /UnexpectedDeoptimizationTest.java intermittent timed out
* JDK-8368885: NMT CommandLine tests can check for error better
* JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
* JDK-8369251: Opensource few tests
* JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
* JDK-8369516: Delete duplicate imaging test
* JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual?000000)
* JDK-8369683: Exclude runtime/Monitor/ /MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on Alpine Linux debug
* JDK-8369851: Remove darcy author tags from langtools tests
* JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
* JDK-8370378: Some compiler tests inadvertently exclude particular platforms
* JDK-8370489: Some compiler tests miss the @key randomness
* JDK-8370492: [Linux] Update cpu shares to cpu.weight mapping function
* JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
* JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
* JDK-8370905: Update vm.defmeth tests to use virtual threads
* JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
* JDK-8371262: sun/security/pkcs11/Cipher/KeyWrap tests may silently skip
* JDK-8371349: Update NSS library to 3.117
* JDK-8371364: Refactor javax/swing/JFileChooser/ /FileSizeCheck.java to use Util.findComponent()
* JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
* JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout
* JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException
* JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
* JDK-8371895: Lower GCTimeLimit in TestUseGCOverheadLimit.java
* JDK-8371967: Add Visual Studio 2026 to build toolchain for Windows
* JDK-8372120: Add missing sound keyword to MIDI tests
* JDK-8372272: Hotspot shared lib loading - add load attempts to Events::log
* JDK-8372351: Add 2 WISeKey roots
* JDK-8372609: Bug4944439 does not enforce locale correctly
* JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
* JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
* JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
* JDK-8373275: Improve DTLS handshaking
* JDK-8373537: Migrate "test/jdk/com/sun/net/httpserver/" to null-safe "SimpleSSLContext" methods
* JDK-8373593: Support latest VS2026 MSC_VER in abstract_vm_version.cpp
* JDK-8373623: Refactor Serialization tests for Records to JUnit
* JDK-8373632: Some sound tests failing in CI due to lack of sound key
* JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected
* JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
* JDK-8373704: Improve "SocketException: Protocol family unavailable" message
* JDK-8373716: Refactor further java/util tests from TestNG to JUnit
* JDK-8373793: TestDynamicStore.java '/manual' disables use of '/timeout'
* JDK-8373796: Refactor java/net/httpclient/ /ThrowingPublishers*.java tests to use JUnit5
* JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost"
* JDK-8373832: Test java/lang/invoke/TestVHInvokerCaching.java tests nothing
* JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
* JDK-8373866: Refactor java/net/httpclient/ /ThrowingSubscribers*.java tests to use JUnit5
* JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5
* JDK-8373928: 4 Dangling pointer defect groups in java.c
* JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out
* JDK-8374058: Enhance JPEG handling
* JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
* JDK-8374322: TestMemoryWithSubgroups.java fails Permission denied
* JDK-8374434: Several JShell tests report JUnit discovery warnings
* JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
* JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name
* JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset _cont_fastpath if SP == _cont_fastpath
* JDK-8374888: Implement internal test cache to help UserIterCount test performance
* JDK-8374998: Failing os::write - remove bad file
* JDK-8375065: Update LCMS to 2.18
* JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
* JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
* JDK-8375232: Refactor util/StringJoiner tests to use JUnit
* JDK-8375233: Refactor util/Vector tests to use JUnit
* JDK-8375742: Test java/lang/invoke/MethodHandleProxies/ /Driver.java does not run Unnamed.java
* JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
* JDK-8376151: Test javax/swing/JFileChooser/4966171/ /bug4966171.java is failing with OOME
* JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
* JDK-8376233: Clean up code in Desktop native peer
* JDK-8376889: Enhance JfrRecorder::on_create_vm_3() assert output
* JDK-8377158: Enhance XBM image support
* JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
* JDK-8377347: jdk/jfr/event/gc/detailed/ /TestZAllocationStallEvent.java intermittent OOME
* JDK-8377498: Improve HttpServer handling
* JDK-8377602: Create automated test for PageRange
* JDK-8377727: Ghost caret and focus appear in non‑editable text fields
* JDK-8377833: Enhance Jar file processing
* JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java
* JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
* JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
* JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
* JDK-8378353: [PPC64] StringCoding.countPositives causes errors when the length is not a proper 32 bit int
* JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
* JDK-8378561: Mark gc/shenandoah/compiler/ /TestLinkToNativeRBP.java as /native
* JDK-8378687: Improve delegation of HttpURLConnection
* JDK-8378775: Bump update version for OpenJDK: jdk-21.0.12
* JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
* JDK-8378810: Enable missing FFM test via jtreg requires for RISC-V
* JDK-8378878: Refactor java/nio/channels/ /AsynchronousSocketChannel test to use JUnit
* JDK-8379464: Enable missing stack walking test via jtreg requires for RISC-V
* JDK-8380011: Path-to-gcroots search should not trigger stack overflows
* JDK-8380222: Refactor test/jdk/java/lang/Character TestNG tests to JUnit
* JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
* JDK-8380428: ProblemList containers/docker/ /TestJcmdWithSideCar.java on linux-all
* JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize after JDK-8323792
* JDK-8380565: PPC64: deoptimization stub should save vector registers
* JDK-8380672: Improve certification checking
* JDK-8380947: Add pull request template
* JDK-8381039: Enhance AWT ImagingLib
* JDK-8381049: Enhance Jar handling
* JDK-8381205: GHA: Upgrade Node.js 20 to 24
* JDK-8381315: compiler/vectorapi/TestVectorReallocation.java fails with -XX:UseAVX=1 after JDK-8380565
* JDK-8381519: Enhance Der Value Handling
* JDK-8381796: Enhance Certificate parsing
* JDK-8382018: test/jdk/java/nio/file/spi/ /SetDefaultProvider.java leaves a directory in /tmp
* JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
* JDK-8382419: Add missed @key randomness after JDK-8370489
* JDK-8383175: (tz) Update Timezone Data to 2026b
* JDK-8383185: [21u] Backport of JDK-8382925 causes test failure in SetDefaultProvider
* JDK-8383354: Update LCMS to 2.19.1
* JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
* JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
* JDK-8383630: Fix iteration in tests doing class redefinition
* JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
* JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
* JDK-8384495: Update Libpng to 1.6.58
* JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
* JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
* JDK-8384902: Update GIFlib to 6.1.3
* JDK-8385390: Update FreeType to 2.14.3
* JDK-8385490: Update HarfBuzz to 14.2.0
* JDK-8386551: Windows build broken because of MSys2/Make update

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3332=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3332=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3332=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3332=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* java-21-openjdk-jmods-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-src-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* openSUSE Leap 15.6 (noarch)
* java-21-openjdk-javadoc-21.0.12.0-150600.3.29.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* java-21-openjdk-debugsource-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-21.0.12.0-150600.3.29.1
* java-21-openjdk-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-21.0.12.0-150600.3.29.1
* java-21-openjdk-devel-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-headless-debuginfo-21.0.12.0-150600.3.29.1
* java-21-openjdk-demo-21.0.12.0-150600.3.29.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
* https://bugzilla.suse.com/show_bug.cgi?id64397
* https://bugzilla.suse.com/show_bug.cgi?id64994
* https://bugzilla.suse.com/show_bug.cgi?id67355
* https://bugzilla.suse.com/show_bug.cgi?id72223
* https://bugzilla.suse.com/show_bug.cgi?id72224
* https://bugzilla.suse.com/show_bug.cgi?id72225
* https://bugzilla.suse.com/show_bug.cgi?id72227
* https://bugzilla.suse.com/show_bug.cgi?id72228
* https://bugzilla.suse.com/show_bug.cgi?id72235
* https://bugzilla.suse.com/show_bug.cgi?id72236
* https://bugzilla.suse.com/show_bug.cgi?id72237



SUSE-SU-2026:3335-1: important: Security update for ImageMagick


# Security update for ImageMagick

Announcement ID: SUSE-SU-2026:3335-1
Release Date: 2026-07-28T09:43:52Z
Rating: important
References:

* bsc#1268878

Cross-References:

* CVE-2026-56379

CVSS scores:

* CVE-2026-56379 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Desktop Applications Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for ImageMagick fixes the following issue

* Extend CVE-2026-56379 patch by f63c78b (bsc#1268878).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3335=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3335=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3335=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3335=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3335=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3335=1

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3335=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3335=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3335=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3335=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3335=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3335=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-extra-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.104.1
* libMagick++-devel-64bit-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1
* ImageMagick-devel-64bit-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (x86_64)
* ImageMagick-devel-32bit-7.1.0.9-150400.6.104.1
* libMagick++-devel-32bit-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.104.1
* openSUSE Leap 15.4 (noarch)
* ImageMagick-doc-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-7.1.0.9-150400.6.104.1
* ImageMagick-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.104.1
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* libMagick++-devel-7.1.0.9-150400.6.104.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.104.1
* perl-PerlMagick-7.1.0.9-150400.6.104.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.104.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.104.1
* ImageMagick-debugsource-7.1.0.9-150400.6.104.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://bugzilla.suse.com/show_bug.cgi?id68878



SUSE-SU-2026:3338-1: important: Security update for webkit2gtk3


# Security update for webkit2gtk3

Announcement ID: SUSE-SU-2026:3338-1
Release Date: 2026-07-28T09:55:09Z
Rating: important
References:

* bsc#1271638

Cross-References:

* CVE-2024-4367
* CVE-2026-39872
* CVE-2026-43663
* CVE-2026-43676
* CVE-2026-43699
* CVE-2026-43701
* CVE-2026-43705
* CVE-2026-43707
* CVE-2026-43712
* CVE-2026-43713
* CVE-2026-43715
* CVE-2026-43716
* CVE-2026-43720
* CVE-2026-43721
* CVE-2026-43725
* CVE-2026-43726
* CVE-2026-43727
* CVE-2026-43731
* CVE-2026-43732
* CVE-2026-43734
* CVE-2026-43740
* CVE-2026-43742
* CVE-2026-43745

CVSS scores:

* CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-39872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43701 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43705 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43707 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43713 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43716 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43721 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43725 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43726 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43731 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43732 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43734 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43742 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves 23 vulnerabilities can now be installed.

## Description:

This update for webkit2gtk3 fixes the following issues:

* CVE-2024-4367: missing type check when handling fonts in PDF.js can allow
arbitrary JavaScript execution (bsc#1271638).
* CVE-2026-39872: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43663: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43676: out-of-bounds access when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43699: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43701: malicious website can process restricted web content outside
the sandbox (bsc#1271638).
* CVE-2026-43705: type confusion issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43707: memory corruption issue when processing web content can lead
to an unexpected process crash (bsc#1271638).
* CVE-2026-43712: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43713: visiting a website can leak sensitive data due to a
permissions issue (bsc#1271638).
* CVE-2026-43715: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43716: maliciously crafted web content can lead to an unexpected
Safari crash (bsc#1271638).
* CVE-2026-43720: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43721: malicious website can silently hijack clipboard data
(bsc#1271638).
* CVE-2026-43725: unvalidated input can allow a malicious website to process
restricted web content outside the sandbox (bsc#1271638).
* CVE-2026-43726: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43727: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43731: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43732: path handling issue when processing web content can disclose
sensitive user information (bsc#1271638).
* CVE-2026-43734: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43740: maliciously crafted web content can result in the disclosure
of process memory (bsc#1271638).
* CVE-2026-43742: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43745: out-of-bounds write issue when processing web content can
lead to an unexpected Safari crash (bsc#1271638).

Changes for webkit2gtk3:

* Update to version 2.52.5:

* Fire scrollend event for instant programmatic scrolls.

* Increase network idle connection timeout to 115 seconds.
* Add User-Agent quirk for HBO Max.
* Fix the build with system malloc.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3338=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3338=1

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3338=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3338=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3338=1

## Package List:

* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* webkit-jsc-6.0-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* webkit-jsc-4-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* webkit2gtk4-minibrowser-2.52.5-150600.12.71.1
* webkit-jsc-6.0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-minibrowser-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-minibrowser-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-minibrowser-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk4-minibrowser-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkit-jsc-4.1-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit-jsc-4.1-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-minibrowser-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* webkit-jsc-4-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-64bit-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-64bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-64bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-64bit-2.52.5-150600.12.71.1
* openSUSE Leap 15.6 (x86_64)
* libjavascriptcoregtk-4_0-18-32bit-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-32bit-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.5-150600.12.71.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* Basesystem Module 15-SP7 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* Desktop Applications Module 15-SP7 (noarch)
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_0-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-2.52.5-150600.12.71.1
* libwebkitgtk-6_0-4-2.52.5-150600.12.71.1
* webkit2gtk3-debugsource-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkit2gtk4-debugsource-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150600.12.71.1
* typelib-1_0-WebKit-6_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150600.12.71.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-devel-2.52.5-150600.12.71.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-devel-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1
* webkit2gtk3-soup2-debugsource-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-2.52.5-150600.12.71.1
* libwebkit2gtk-4_0-37-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150600.12.71.1
* libjavascriptcoregtk-4_0-18-2.52.5-150600.12.71.1
* libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150600.12.71.1
* WebKitGTK-4.1-lang-2.52.5-150600.12.71.1
* WebKitGTK-6.0-lang-2.52.5-150600.12.71.1

## References:

* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
* https://www.suse.com/security/cve/CVE-2026-43731.html
* https://www.suse.com/security/cve/CVE-2026-43732.html
* https://www.suse.com/security/cve/CVE-2026-43734.html
* https://www.suse.com/security/cve/CVE-2026-43740.html
* https://www.suse.com/security/cve/CVE-2026-43742.html
* https://www.suse.com/security/cve/CVE-2026-43745.html
* https://bugzilla.suse.com/show_bug.cgi?id71638



SUSE-SU-2026:3340-1: moderate: Security update for nmap


# Security update for nmap

Announcement ID: SUSE-SU-2026:3340-1
Release Date: 2026-07-28T10:04:18Z
Rating: moderate
References:

* bsc#1269570

Cross-References:

* CVE-2026-58058

CVSS scores:

* CVE-2026-58058 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58058 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for nmap fixes the following issue:

* CVE-2026-58058: crafted IPv6 response with a truncated extension header can
trigger out-of-bounds reads and a crash (bsc#1269570).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3340=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3340=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3340=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nping-7.92-150600.9.3.1
* nping-debuginfo-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* ncat-debuginfo-7.92-150600.9.3.1
* ncat-7.92-150600.9.3.1
* nmap-debugsource-7.92-150600.9.3.1
* nmap-7.92-150600.9.3.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nmap-debugsource-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* nmap-7.92-150600.9.3.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* nping-7.92-150600.9.3.1
* nmap-debugsource-7.92-150600.9.3.1
* nmap-debuginfo-7.92-150600.9.3.1
* nping-debuginfo-7.92-150600.9.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58058.html
* https://bugzilla.suse.com/show_bug.cgi?id69570



SUSE-SU-2026:3341-1: important: Security update for glib2


# Security update for glib2

Announcement ID: SUSE-SU-2026:3341-1
Release Date: 2026-07-28T10:09:32Z
Rating: important
References:

* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021

Cross-References:

* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016

CVSS scores:

* CVE-2026-58010 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58010 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-58011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58012 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58012 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-58014 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58016 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves six vulnerabilities can now be installed.

## Description:

This update for glib2 fixes the following issues:

* CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could
cause a 1-byte out-of-bounds read (bsc#1270009).
* CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a
2-byte out-of-bounds read (bsc#1270010).
* CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-
change replacements could cause an out-of- bounds read (bsc#1270016).
* CVE-2026-58013: multi-byte custom line terminator in
g_io_channel_read_line_backend could trigger an out-of-bounds read
(bsc#1270018).
* CVE-2026-58014: processing empty key file values in
g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access
(bsc#1270021).
* CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned
integer overflow (bsc#1270008).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3341=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3341=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3341=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3341=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libgio-2_0-0-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tests-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tests-devel-debuginfo-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* glib2-devel-2.78.6-150600.4.38.1
* glib2-doc-2.78.6-150600.4.38.1
* glib2-devel-static-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libgmodule-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-64bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-64bit-2.78.6-150600.4.38.1
* libgio-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-64bit-2.78.6-150600.4.38.1
* libgobject-2_0-0-64bit-2.78.6-150600.4.38.1
* glib2-tools-64bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-64bit-2.78.6-150600.4.38.1
* libgthread-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-64bit-2.78.6-150600.4.38.1
* glib2-tools-64bit-2.78.6-150600.4.38.1
* libgio-2_0-0-64bit-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-32bit-2.78.6-150600.4.38.1
* glib2-devel-32bit-debuginfo-2.78.6-150600.4.38.1
* libgthread-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* openSUSE Leap 15.6 (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* gio-branding-upstream-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* Basesystem Module 15-SP7 (noarch)
* glib2-lang-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* glib2-devel-2.78.6-150600.4.38.1
* libgthread-2_0-0-2.78.6-150600.4.38.1
* libgmodule-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-devel-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-2.78.6-150600.4.38.1
* glib2-tools-debuginfo-2.78.6-150600.4.38.1
* glib2-tools-2.78.6-150600.4.38.1
* libgobject-2_0-0-2.78.6-150600.4.38.1
* libgio-2_0-0-2.78.6-150600.4.38.1
* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1
* glib2-debugsource-2.78.6-150600.4.38.1
* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libgio-2_0-0-32bit-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-2.78.6-150600.4.38.1
* libgio-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-2.78.6-150600.4.38.1
* libgmodule-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libglib-2_0-0-32bit-debuginfo-2.78.6-150600.4.38.1
* libgobject-2_0-0-32bit-2.78.6-150600.4.38.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* glib2-lang-2.78.6-150600.4.38.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html
* https://bugzilla.suse.com/show_bug.cgi?id70008
* https://bugzilla.suse.com/show_bug.cgi?id70009
* https://bugzilla.suse.com/show_bug.cgi?id70010
* https://bugzilla.suse.com/show_bug.cgi?id70016
* https://bugzilla.suse.com/show_bug.cgi?id70018
* https://bugzilla.suse.com/show_bug.cgi?id70021



SUSE-SU-2026:3350-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5)


# Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise
15 SP5)

Announcement ID: SUSE-SU-2026:3350-1
Release Date: 2026-07-28T12:09:45Z
Rating: important
References:

* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-43038
* CVE-2026-53359

CVSS scores:

* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves two vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.172 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3350=1 SUSE-2026-3346=1

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3346=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3350=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3324=1

* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3324=1

## Package List:

* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_172-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_42-debugsource-3-150500.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_55-debugsource-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_56-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_225-default-3-150400.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3351-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5)


# Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise
15 SP5)

Announcement ID: SUSE-SU-2026:3351-1
Release Date: 2026-07-28T12:10:24Z
Rating: important
References:

* bsc#1266970
* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359

CVSS scores:

* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Live Patching 15-SP5
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Real Time 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves three vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3351=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3351=1

* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3328=1 SUSE-SLE-
Module-Live-Patching-15-SP5-2026-3349=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3349=1 SUSE-2026-3328=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150400_24_219-default-3-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_54-debugsource-3-150400.2.1
* kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-3-150400.2.1
* openSUSE Leap 15.5 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP5_Update_41-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_166-default-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-3-150500.2.1
* kernel-livepatch-SLE15-SP5_Update_40-debugsource-3-150500.2.1
* kernel-livepatch-5_14_21-150500_55_169-default-3-150500.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3344-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6)


# Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise
15 SP6)

Announcement ID: SUSE-SU-2026:3344-1
Release Date: 2026-07-28T12:06:44Z
Rating: important
References:

* bsc#1266970
* bsc#1270060
* bsc#1271370

Cross-References:

* CVE-2026-46113
* CVE-2026-53359
* CVE-2026-53366

CVSS scores:

* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves three vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3344=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3344=1

## Package List:

* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-4-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_26-debugsource-4-150600.2.1
* kernel-livepatch-6_4_0-150600_23_112-default-4-150600.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370



SUSE-SU-2026:3345-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4)


# Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise
15 SP4)

Announcement ID: SUSE-SU-2026:3345-1
Release Date: 2026-07-28T12:12:16Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves five vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.184 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3347=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3348=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3353=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3345=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3352=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3347=1 SUSE-2026-3348=1 SUSE-2026-3353=1
SUSE-2026-3345=1 SUSE-2026-3352=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_53-debugsource-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_50-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-4-150400.2.1
* kernel-livepatch-5_14_21-150400_24_200-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-4-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_49-debugsource-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-7-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_46-debugsource-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-11-150400.2.1
* kernel-livepatch-5_14_21-150400_24_197-default-7-150400.2.1
* kernel-livepatch-5_14_21-150400_24_209-default-5-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_52-debugsource-5-150400.2.1
* kernel-livepatch-5_14_21-150400_24_184-default-11-150400.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648



openSUSE-SU-2026:21453-1: important: Security update for chromium


openSUSE security update: security update for chromium
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21453-1
Rating: important
References:

* bsc#1272460

Cross-References:

* CVE-2026-16804
* CVE-2026-16805
* CVE-2026-16806
* CVE-2026-16807

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 4 vulnerabilities and has one bug fix can now be installed.

Description:

This update for chromium fixes the following issues:

Changes in chromium:

- Chromium 150.0.7871.186 (boo#1272460):
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260724162718479796.93181000773252=1

Package List:

- openSUSE Leap 16.0:

chromedriver-150.0.7871.186-bp160.1.1
chromium-150.0.7871.186-bp160.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-16804.html
* https://www.suse.com/security/cve/CVE-2026-16805.html
* https://www.suse.com/security/cve/CVE-2026-16806.html
* https://www.suse.com/security/cve/CVE-2026-16807.html



openSUSE-SU-2026:21448-1: important: Security update for agama-web-ui


openSUSE security update: security update for agama-web-ui
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21448-1
Rating: important
References:

* bsc#1246822
* bsc#1259169
* bsc#1268851
* bsc#1269359
* bsc#1269514
* bsc#1269595
* bsc#1269927
* bsc#1272310
* bsc#1272311
* bsc#1272312
* bsc#1272313
* bsc#1272317
* bsc#1272318
* bsc#1272319

Cross-References:

* CVE-2025-7783
* CVE-2026-12143
* CVE-2026-13149
* CVE-2026-13311
* CVE-2026-13676
* CVE-2026-27601
* CVE-2026-40181
* CVE-2026-49356
* CVE-2026-53550
* CVE-2026-53632
* CVE-2026-54466
* CVE-2026-54490
* CVE-2026-55602

CVSS scores:

* CVE-2025-7783 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-7783 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:N
* CVE-2026-12143 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13149 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13149 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13311 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13311 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13676 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-13676 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
* CVE-2026-27601 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-27601 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-40181 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-49356 ( SUSE ): 3.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
* CVE-2026-53550 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-53550 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-53632 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-54466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-54466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-54490 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-54490 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-55602 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 13 vulnerabilities and has 14 bug fixes can now be installed.

Description:

This update for agama-web-ui fixes the following issues:

- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart
form-encoded data (bsc#1246822).
- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).
- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing
non-expanding `{}` brace groups (bsc#1269927).
- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings
(bsc#1269359).
- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for
HTTP-family URLs (bsc#1269595).
- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual`
functions (bsc#1259169).
- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being
reinterpreted as protocol-relative URLs (bsc#1272311).
- CVE-2026-49356: @babel/core: arbitrary file read via `sourceMappingURL` comment (bsc#1272317).
- CVE-2026-53550: js-yaml: quadratic complexity in merge-key processing when processing a crafted YAML document
(bsc#1268851).
- CVE-2026-53632: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows (bsc#1272319).
- CVE-2026-54466: websocket-driver: message corruption via abuse of protocol length headers (bsc#1272312).
- CVE-2026-54490: websocket-driver: resource limit bypass via message compression (bsc#1272313).
- CVE-2026-55602: http-proxy-middleware: Host-header-driven backend routing bypass via `router` host+path substring
matching (bsc#1272318).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1354=1

Package List:

- openSUSE Leap 16.0:

agama-web-ui-17+673.b97ba64d6-160000.12.1

References:

* https://www.suse.com/security/cve/CVE-2025-7783.html
* https://www.suse.com/security/cve/CVE-2026-12143.html
* https://www.suse.com/security/cve/CVE-2026-13149.html
* https://www.suse.com/security/cve/CVE-2026-13311.html
* https://www.suse.com/security/cve/CVE-2026-13676.html
* https://www.suse.com/security/cve/CVE-2026-27601.html
* https://www.suse.com/security/cve/CVE-2026-40181.html
* https://www.suse.com/security/cve/CVE-2026-49356.html
* https://www.suse.com/security/cve/CVE-2026-53550.html
* https://www.suse.com/security/cve/CVE-2026-53632.html
* https://www.suse.com/security/cve/CVE-2026-54466.html
* https://www.suse.com/security/cve/CVE-2026-54490.html
* https://www.suse.com/security/cve/CVE-2026-55602.html



SUSE-SU-2026:3362-1: important: Security update for samba


# Security update for samba

Announcement ID: SUSE-SU-2026:3362-1
Release Date: 2026-07-28T12:18:51Z
Rating: important
References:

* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677

Cross-References:

* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949

CVSS scores:

* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Availability Extension 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for samba fixes the following issues

* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3362=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3362=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3362=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3362=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3362=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3362=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3362=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3362=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-test-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (x86_64)
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (aarch64 x86_64)
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* openSUSE Leap 15.4 (noarch)
* samba-doc-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64)
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64)
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64)
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le
s390x x86_64)
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* ctdb-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150400.3.52.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150400.3.52.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677



SUSE-SU-2026:3364-1: important: Security update for samba


# Security update for samba

Announcement ID: SUSE-SU-2026:3364-1
Release Date: 2026-07-28T12:19:49Z
Rating: important
References:

* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677

Cross-References:

* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949

CVSS scores:

* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise High Availability Extension 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for samba fixes the following issues

* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3364=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3364=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3364=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3364=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-pcp-pmda-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-test-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-test-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-pcp-pmda-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* samba-client-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-64bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-64bit-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (x86_64)
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (noarch)
* samba-doc-4.19.8+git.501.67274891bc-150600.3.29.1
* openSUSE Leap 15.6 (aarch64 x86_64)
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le
s390x x86_64)
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-4.19.8+git.501.67274891bc-150600.3.29.1
* ctdb-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* samba-ldb-ldap-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-tool-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-gpupdate-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-debugsource-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy-python3-devel-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ldb-ldap-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-dcerpc-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* libsamba-policy0-python3-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-python3-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-4.19.8+git.501.67274891bc-150600.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* samba-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-winbind-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-ceph-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1
* samba-client-libs-32bit-debuginfo-4.19.8+git.501.67274891bc-150600.3.29.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677



SUSE-SU-2026:3365-1: important: Security update for samba


# Security update for samba

Announcement ID: SUSE-SU-2026:3365-1
Release Date: 2026-07-28T12:20:57Z
Rating: important
References:

* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677

Cross-References:

* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949

CVSS scores:

* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Availability Extension 15 SP5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for samba fixes the following issues

* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP5
zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-3365=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3365=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3365=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3365=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3365=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3365=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3365=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-test-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-test-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-pcp-pmda-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-pcp-pmda-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (aarch64 x86_64)
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libsamba-policy0-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-64bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-64bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* openSUSE Leap 15.5 (noarch)
* samba-doc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64)
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-python3-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ldb-ldap-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-devel-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-ceph-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* libsamba-policy0-python3-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-dcerpc-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-tool-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-gpupdate-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* samba-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-winbind-libs-32bit-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-32bit-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le
s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* ctdb-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* samba-debugsource-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-client-libs-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1
* samba-debuginfo-4.17.12+git.581.f49579c6cd-150500.3.42.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677



SUSE-SU-2026:3366-1: important: Security update for samba


# Security update for samba

Announcement ID: SUSE-SU-2026:3366-1
Release Date: 2026-07-28T12:21:29Z
Rating: important
References:

* bsc#1271469
* bsc#1271672
* bsc#1271673
* bsc#1271674
* bsc#1271675
* bsc#1271676
* bsc#1271677

Cross-References:

* CVE-2026-15779
* CVE-2026-58216
* CVE-2026-58218
* CVE-2026-58221
* CVE-2026-58222
* CVE-2026-58224
* CVE-2026-6949

CVSS scores:

* CVE-2026-15779 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58216 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58218 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-58221 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58222 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58224 ( SUSE ): 7.1
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-6949 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.3
* SUSE Enterprise Storage 7.1
* SUSE Linux Enterprise Server 15 SP3

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for samba fixes the following issues

* CVE-2026-6949: TSIG packet with crafted name compression can crash internal
DNS server (bsc#1271672).
* CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of
critical system paths without validation (bsc#1271469).
* CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd`
service (bsc#1271674).
* CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in
a fixed FIFO before authentication completes (bsc#1271675).
* CVE-2026-58221: authenticated LDAP access to internal LDB special DNs
permits domain takeover (bsc#1271676).
* CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion
disclose protected attributes (bsc#1271677).
* CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB
(bsc#1271673).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3366=1

* SUSE Enterprise Storage 7.1
zypper in -t patch SUSE-Storage-7.1-2026-3366=1

## Package List:

* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* libsamba-policy0-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-dsdb-modules-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-dsdb-modules-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-pcp-pmda-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-tool-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ldb-ldap-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ldb-ldap-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-test-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-gpupdate-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-test-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-pcp-pmda-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy-python3-devel-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (x86_64)
* samba-ad-dc-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-32bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-32bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (aarch64_ilp32)
* libsamba-policy0-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* libsamba-policy0-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-devel-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ad-dc-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-libs-64bit-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-64bit-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (noarch)
* samba-doc-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* openSUSE Leap 15.3 (aarch64 x86_64)
* samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* SUSE Enterprise Storage 7.1 (aarch64 x86_64)
* samba-client-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debugsource-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-client-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* ctdb-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-python3-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-ceph-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-libs-4.15.13+git.808.eeca19f5e1-150300.3.106.1
* samba-winbind-debuginfo-4.15.13+git.808.eeca19f5e1-150300.3.106.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15779.html
* https://www.suse.com/security/cve/CVE-2026-58216.html
* https://www.suse.com/security/cve/CVE-2026-58218.html
* https://www.suse.com/security/cve/CVE-2026-58221.html
* https://www.suse.com/security/cve/CVE-2026-58222.html
* https://www.suse.com/security/cve/CVE-2026-58224.html
* https://www.suse.com/security/cve/CVE-2026-6949.html
* https://bugzilla.suse.com/show_bug.cgi?id71469
* https://bugzilla.suse.com/show_bug.cgi?id71672
* https://bugzilla.suse.com/show_bug.cgi?id71673
* https://bugzilla.suse.com/show_bug.cgi?id71674
* https://bugzilla.suse.com/show_bug.cgi?id71675
* https://bugzilla.suse.com/show_bug.cgi?id71676
* https://bugzilla.suse.com/show_bug.cgi?id71677



SUSE-SU-2026:3368-1: moderate: Security update for sssd


# Security update for sssd

Announcement ID: SUSE-SU-2026:3368-1
Release Date: 2026-07-28T12:23:46Z
Rating: moderate
References:

* bsc#1269807

Cross-References:

* CVE-2026-12610

CVSS scores:

* CVE-2026-12610 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4

An update that solves one vulnerability can now be installed.

## Description:

This update for sssd fixes the following issue:

* CVE-2026-12610: cancelled or completed PAM request while the asynchronous
child process is still running can lead to a use-after-free (bsc#1269807).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3368=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3368=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3368=1

## Package List:

* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python3-sssd-config-debuginfo-2.5.2-150400.4.48.1
* python3-ipa_hbac-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* sssd-winbind-idmap-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp-devel-2.5.2-150400.4.48.1
* sssd-krb5-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* libsss_idmap-devel-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap-devel-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp0-2.5.2-150400.4.48.1
* libipa_hbac-devel-2.5.2-150400.4.48.1
* python3-sssd-config-2.5.2-150400.4.48.1
* sssd-proxy-debuginfo-2.5.2-150400.4.48.1
* sssd-ipa-debuginfo-2.5.2-150400.4.48.1
* libipa_hbac0-debuginfo-2.5.2-150400.4.48.1
* python3-ipa_hbac-debuginfo-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-krb5-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-ad-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* python3-sss-murmur-debuginfo-2.5.2-150400.4.48.1
* python3-sss-murmur-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* libipa_hbac0-2.5.2-150400.4.48.1
* sssd-dbus-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.48.1
* sssd-kcm-debuginfo-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-tools-debuginfo-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* libsss_certmap0-2.5.2-150400.4.48.1
* sssd-tools-2.5.2-150400.4.48.1
* libnfsidmap-sss-debuginfo-2.5.2-150400.4.48.1
* libsss_simpleifp0-debuginfo-2.5.2-150400.4.48.1
* sssd-proxy-2.5.2-150400.4.48.1
* sssd-dbus-debuginfo-2.5.2-150400.4.48.1
* python3-sss_nss_idmap-2.5.2-150400.4.48.1
* sssd-ad-2.5.2-150400.4.48.1
* sssd-kcm-2.5.2-150400.4.48.1
* sssd-winbind-idmap-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap-devel-2.5.2-150400.4.48.1
* sssd-ipa-2.5.2-150400.4.48.1
* libnfsidmap-sss-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* sssd-common-64bit-debuginfo-2.5.2-150400.4.48.1
* sssd-common-64bit-2.5.2-150400.4.48.1
* openSUSE Leap 15.4 (x86_64)
* sssd-common-32bit-2.5.2-150400.4.48.1
* sssd-common-32bit-debuginfo-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libsss_certmap0-2.5.2-150400.4.48.1
* libsss_idmap0-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-2.5.2-150400.4.48.1
* libsss_idmap0-2.5.2-150400.4.48.1
* sssd-krb5-common-debuginfo-2.5.2-150400.4.48.1
* sssd-debugsource-2.5.2-150400.4.48.1
* sssd-ldap-debuginfo-2.5.2-150400.4.48.1
* sssd-common-2.5.2-150400.4.48.1
* sssd-ldap-2.5.2-150400.4.48.1
* libsss_certmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-common-debuginfo-2.5.2-150400.4.48.1
* libsss_nss_idmap0-debuginfo-2.5.2-150400.4.48.1
* sssd-2.5.2-150400.4.48.1
* sssd-krb5-common-2.5.2-150400.4.48.1

## References:

* https://www.suse.com/security/cve/CVE-2026-12610.html
* https://bugzilla.suse.com/show_bug.cgi?id69807



SUSE-SU-2026:3354-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4)


# Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise
15 SP4)

Announcement ID: SUSE-SU-2026:3354-1
Release Date: 2026-07-28T12:16:30Z
Rating: important
References:

* bsc#1262404
* bsc#1264060
* bsc#1266970
* bsc#1270060
* bsc#1271648

Cross-References:

* CVE-2026-23240
* CVE-2026-31738
* CVE-2026-43038
* CVE-2026-46113
* CVE-2026-53359

CVSS scores:

* CVE-2026-23240 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46113 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Live Patching 15-SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Real Time 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves five vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.167 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()
(bsc#1262404).
* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create
(bsc#1264060).
* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
(bsc#1271648).
* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected
GFN (bsc#1266970).
* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3354=1 SUSE-2026-3358=1 SUSE-2026-3359=1
SUSE-2026-3357=1 SUSE-2026-3360=1 SUSE-2026-3361=1 SUSE-2026-3355=1
SUSE-2026-3356=1

* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3354=1 SUSE-SLE-
Module-Live-Patching-15-SP4-2026-3358=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3359=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3357=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3360=1 SUSE-SLE-Module-Live-
Patching-15-SP4-2026-3361=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-3355=1
SUSE-SLE-Module-Live-Patching-15-SP4-2026-3356=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1
* openSUSE Leap 15.4 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP4_Update_47-debugsource-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_43-debugsource-18-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_42-debugsource-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_48-debugsource-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-11-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_45-debugsource-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-18-150400.2.1
* kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-15-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-9-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_44-debugsource-17-150400.2.1
* kernel-livepatch-5_14_21-150400_24_194-default-9-150400.2.1
* kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-6-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-22-150400.2.1
* kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-21-150400.2.1
* kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_41-debugsource-22-150400.2.1
* kernel-livepatch-SLE15-SP4_Update_51-debugsource-6-150400.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html
* https://www.suse.com/security/cve/CVE-2026-31738.html
* https://www.suse.com/security/cve/CVE-2026-43038.html
* https://www.suse.com/security/cve/CVE-2026-46113.html
* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://bugzilla.suse.com/show_bug.cgi?id62404
* https://bugzilla.suse.com/show_bug.cgi?id64060
* https://bugzilla.suse.com/show_bug.cgi?id66970
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71648



SUSE-SU-2026:3372-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7)


# Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise
15 SP7)

Announcement ID: SUSE-SU-2026:3372-1
Release Date: 2026-07-28T14:33:43Z
Rating: important
References:

* bsc#1270060
* bsc#1271370

Cross-References:

* CVE-2026-53359
* CVE-2026-53366

CVSS scores:

* CVE-2026-53359 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Live Patching 15-SP7
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves two vulnerabilities can now be installed.

## Description:

This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.60 fixes
various security issues:

The following security issues were fixed:

* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected
role (bsc#1270060).
* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path
(bsc#1271370).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3371=1 SUSE-SLE-
Module-Live-Patching-15-SP6-2026-3372=1

* SUSE Linux Enterprise Live Patching 15-SP7
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3373=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3372=1 SUSE-2026-3371=1

## Package List:

* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1
* SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150700_53_60-default-debuginfo-3-150700.2.1
* kernel-livepatch-6_4_0-150700_53_60-default-3-150700.2.1
* kernel-livepatch-SLE15-SP7_Update_16-debugsource-3-150700.2.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_115-default-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_27-debugsource-3-150600.2.1
* kernel-livepatch-SLE15-SP6_Update_28-debugsource-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-3-150600.2.1
* kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-3-150600.2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-53359.html
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://bugzilla.suse.com/show_bug.cgi?id70060
* https://bugzilla.suse.com/show_bug.cgi?id71370