SUSE-SU-2026:3483-1: important: Security update for valkey
SUSE-SU-2026:3485-1: important: Security update for spice-vdagent
SUSE-SU-2026:3486-1: moderate: Security update for openssl-3
SUSE-SU-2026:3488-1: important: Security update for openssl-1_1
SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools
SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant
SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt
SUSE-SU-2026:3492-1: moderate: Security update for alsa
SUSE-SU-2026:3493-1: important: Security update for libpng16
openSUSE-SU-2026:21518-1: important: Security update for python-ujson
openSUSE-SU-2026:21516-1: important: Security update for python-sh
openSUSE-SU-2026:21522-1: important: Security update for ffmpeg-4
openSUSE-SU-2026:11436-1: moderate: golang-github-prometheus-prometheus-3.13.2-1.1 on GA media
openSUSE-SU-2026:11438-1: moderate: alloy-1.18.0-1.1 on GA media
openSUSE-SU-2026:11437-1: moderate: podman-6.0.2-1.1 on GA media
openSUSE-SU-2026:11434-1: moderate: chromedriver-151.0.7922.71-1.1 on GA media
openSUSE-SU-2026:11440-1: moderate: nodejs26-26.5.1-1.1 on GA media
openSUSE-SU-2026:11439-1: moderate: corepack24-24.18.1-1.1 on GA media
openSUSE-SU-2026:11441-1: moderate: xen-4.22.0_02-1.1 on GA media
SUSE-SU-2026:3468-1: important: Security update for rrdtool
SUSE-SU-2026:3469-1: important: Security update for nginx
SUSE-SU-2026:3470-1: important: Security update for spice-vdagent
SUSE-SU-2026:3474-1: moderate: Security update for s390-tools
SUSE-SU-2026:3475-1: moderate: Security update for s390-tools
SUSE-SU-2026:3476-1: important: Security update for bind
SUSE-SU-2026:3477-1: important: Security update for bind
openSUSE-SU-2026:0275-1: important: Security update for thrift
openSUSE-SU-2026:0274-1: important: Security update for perl-HTTP-Tiny
openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck
SUSE-SU-2026:3483-1: important: Security update for valkey
# Security update for valkey
Announcement ID: SUSE-SU-2026:3483-1
Release Date: 2026-08-04T11:46:57Z
Rating: important
References:
* bsc#1272442
* bsc#1272443
Cross-References:
* CVE-2026-56684
* CVE-2026-63639
CVSS scores:
* CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves two vulnerabilities can now be installed.
## Description:
This update for valkey fixes the following issues
* CVE-2026-56684: use-after-free in TLS connection handling (bsc#1272443).
* CVE-2026-63639: RCE via corrupt stream RDB files containing a shared NACK
across consumers (bsc#1272442).
Changes for valkey:
* Update to 8.0.10.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3483=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3483=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3483=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* valkey-debugsource-8.0.10-150600.13.28.1
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* valkey-debugsource-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* valkey-debugsource-8.0.10-150600.13.28.1
* openSUSE Leap 15.6 (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56684.html
* https://www.suse.com/security/cve/CVE-2026-63639.html
* https://bugzilla.suse.com/show_bug.cgi?id72442
* https://bugzilla.suse.com/show_bug.cgi?id72443
SUSE-SU-2026:3485-1: important: Security update for spice-vdagent
# Security update for spice-vdagent
Announcement ID: SUSE-SU-2026:3485-1
Release Date: 2026-08-04T11:53:55Z
Rating: important
References:
* bsc#1269553
* bsc#1269554
Cross-References:
* CVE-2026-57965
* CVE-2026-57966
CVSS scores:
* CVE-2026-57965 ( SUSE ): 5.2
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-57966 ( SUSE ): 6.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for spice-vdagent fixes the following issues:
* CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer
overflow (bsc#1269553).
* CVE-2026-57966: improper sanitization allows a compromised SPICE host to
write arbitrary files to any location on the guest operating system
(bsc#1269554).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3485=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3485=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3485=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3485=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3485=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3485=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3485=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3485=1
## Package List:
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-57965.html
* https://www.suse.com/security/cve/CVE-2026-57966.html
* https://bugzilla.suse.com/show_bug.cgi?id69553
* https://bugzilla.suse.com/show_bug.cgi?id69554
SUSE-SU-2026:3486-1: moderate: Security update for openssl-3
# Security update for openssl-3
Announcement ID: SUSE-SU-2026:3486-1
Release Date: 2026-08-04T11:54:54Z
Rating: moderate
References:
* bsc#1271712
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that has one security fix can now be installed.
## Description:
This update for openssl-3 fixes the following issues:
* HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-
controlled memory allocations (bsc#1271712).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3486=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3486=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3486=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3486=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3486=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (noarch)
* openssl-3-doc-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libopenssl3-64bit-debuginfo-3.0.8-150400.4.93.1
* libopenssl3-64bit-3.0.8-150400.4.93.1
* libopenssl-3-devel-64bit-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (x86_64)
* libopenssl-3-devel-32bit-3.0.8-150400.4.93.1
* libopenssl3-32bit-3.0.8-150400.4.93.1
* libopenssl3-32bit-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id71712
SUSE-SU-2026:3488-1: important: Security update for openssl-1_1
# Security update for openssl-1_1
Announcement ID: SUSE-SU-2026:3488-1
Release Date: 2026-08-04T11:55:49Z
Rating: important
References:
* bsc#1271712
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that has one security fix can now be installed.
## Description:
This update for openssl-1_1 fixes the following issue
* HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-
controlled memory allocations (bsc#1271712).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3488=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3488=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3488=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3488=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3488=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3488=1
## Package List:
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libopenssl1_1-64bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-64bit-1.1.1l-150500.17.60.1
* libopenssl1_1-64bit-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-64bit-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (noarch)
* openssl-1_1-doc-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id71712
SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools
# Security update for multipath-tools
Announcement ID: SUSE-SU-2026:3489-1
Release Date: 2026-08-04T11:57:10Z
Rating: moderate
References:
* bsc#1268144
* bsc#1268145
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5
An update that has two security fixes can now be installed.
## Description:
This update for multipath-tools fixes the following issues:
Update to version 0.9.4+134+suse.c82f347.
* kpartx: integer overflow in the GPT partition table size calculation can
lead to heap OOB read via crafted USB device or disk image (bsc#1268145).
* kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write
via a crafted DASD disk with more than 256 consecutive format labels
(bsc#1268144).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3489=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3489=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp0_2_0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp0_2_0-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-devel-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp-devel-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-0.9.4+134+suse.c82f347-150500.3.12.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-0.9.4+134+suse.c82f347-150500.3.12.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id68144
* https://bugzilla.suse.com/show_bug.cgi?id68145
SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant
# Security update for wpa_supplicant
Announcement ID: SUSE-SU-2026:3490-1
Release Date: 2026-08-04T11:58:39Z
Rating: low
References:
* bsc#1239461
Cross-References:
* CVE-2025-24912
CVSS scores:
* CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5
An update that solves one vulnerability can now be installed.
## Description:
This update for wpa_supplicant fixes the following issues:
* CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user
in between the hostapd and the RADIUS server to inject crafted RADIUS
packets and force RADIUS authentications to fail (bsc#1239461).
* Missing network context validation for PMKSA caching
https://w1.fi/security/2026-2/
* Unexpected SAE commit message contents terminating `wpa_supplicant`
https://w1.fi/security/2026-3/
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3490=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3490=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* wpa_supplicant-debugsource-2.10-150500.3.6.1
* wpa_supplicant-gui-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-gui-2.10-150500.3.6.1
* wpa_supplicant-2.10-150500.3.6.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* wpa_supplicant-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-debugsource-2.10-150500.3.6.1
* wpa_supplicant-2.10-150500.3.6.1
## References:
* https://www.suse.com/security/cve/CVE-2025-24912.html
* https://bugzilla.suse.com/show_bug.cgi?id39461
SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt
# Security update for libgcrypt
Announcement ID: SUSE-SU-2026:3491-1
Release Date: 2026-08-04T11:58:46Z
Rating: moderate
References:
* bsc#1262684
Cross-References:
* CVE-2026-41989
CVSS scores:
* CVE-2026-41989 ( SUSE ): 5.8
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5
An update that solves one vulnerability can now be installed.
## Description:
This update for libgcrypt fixes the following issue
* CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH
ciphertext can lead to a denial of service (bsc#1262684).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3491=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3491=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* libgcrypt-debugsource-1.9.4-150500.12.6.1
* libgcrypt20-1.9.4-150500.12.6.1
* libgcrypt-cavs-1.9.4-150500.12.6.1
* libgcrypt-devel-1.9.4-150500.12.6.1
* libgcrypt20-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-devel-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-cavs-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-hmac-1.9.4-150500.12.6.1
* openSUSE Leap 15.5 (x86_64)
* libgcrypt20-32bit-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-32bit-1.9.4-150500.12.6.1
* libgcrypt-devel-32bit-1.9.4-150500.12.6.1
* libgcrypt20-hmac-32bit-1.9.4-150500.12.6.1
* libgcrypt-devel-32bit-debuginfo-1.9.4-150500.12.6.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libgcrypt20-hmac-64bit-1.9.4-150500.12.6.1
* libgcrypt20-64bit-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-devel-64bit-1.9.4-150500.12.6.1
* libgcrypt20-64bit-1.9.4-150500.12.6.1
* libgcrypt-devel-64bit-debuginfo-1.9.4-150500.12.6.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libgcrypt-debugsource-1.9.4-150500.12.6.1
* libgcrypt20-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-1.9.4-150500.12.6.1
* libgcrypt20-hmac-1.9.4-150500.12.6.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41989.html
* https://bugzilla.suse.com/show_bug.cgi?id62684
SUSE-SU-2026:3492-1: moderate: Security update for alsa
# Security update for alsa
Announcement ID: SUSE-SU-2026:3492-1
Release Date: 2026-08-04T11:58:57Z
Rating: moderate
References:
* bsc#1268853
Cross-References:
* CVE-2026-56109
CVSS scores:
* CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-56109 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5
An update that solves one vulnerability can now be installed.
## Description:
This update for alsa fixes the following issue
* CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that
can allow attackers to corrupt memory (bsc#1268853).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3492=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3492=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* alsa-debugsource-1.2.8-150500.3.3.1
* libasound2-1.2.8-150500.3.3.1
* libasound2-debuginfo-1.2.8-150500.3.3.1
* alsa-devel-1.2.8-150500.3.3.1
* alsa-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (x86_64)
* libatopology2-32bit-1.2.8-150500.3.3.1
* alsa-topology-devel-32bit-1.2.8-150500.3.3.1
* libasound2-32bit-1.2.8-150500.3.3.1
* libatopology2-32bit-debuginfo-1.2.8-150500.3.3.1
* libasound2-32bit-debuginfo-1.2.8-150500.3.3.1
* alsa-devel-32bit-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le x86_64)
* libatopology2-debuginfo-1.2.8-150500.3.3.1
* libatopology2-1.2.8-150500.3.3.1
* alsa-topology-devel-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libasound2-64bit-debuginfo-1.2.8-150500.3.3.1
* libasound2-64bit-1.2.8-150500.3.3.1
* libatopology2-64bit-1.2.8-150500.3.3.1
* alsa-topology-devel-64bit-1.2.8-150500.3.3.1
* alsa-devel-64bit-1.2.8-150500.3.3.1
* libatopology2-64bit-debuginfo-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (noarch)
* alsa-docs-1.2.8-150500.3.3.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libasound2-1.2.8-150500.3.3.1
* alsa-debugsource-1.2.8-150500.3.3.1
* libasound2-debuginfo-1.2.8-150500.3.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56109.html
* https://bugzilla.suse.com/show_bug.cgi?id68853
SUSE-SU-2026:3493-1: important: Security update for libpng16
# Security update for libpng16
Announcement ID: SUSE-SU-2026:3493-1
Release Date: 2026-08-04T12:11:14Z
Rating: important
References:
* jsc#PED-16190
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that contains one feature can now be installed.
## Description:
This update for libpng16 fixes the following issues:
Changes for libpng16:
* version update to 1.6.58 (jsc#PED-16190).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3493=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3493=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3493=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3493=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-compat-devel-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* libpng16-devel-32bit-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-tools-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-tools-debuginfo-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libpng16-devel-64bit-1.6.58-150600.3.23.1
* libpng16-16-64bit-debuginfo-1.6.58-150600.3.23.1
* libpng16-compat-devel-64bit-1.6.58-150600.3.23.1
* libpng16-16-64bit-1.6.58-150600.3.23.1
* Basesystem Module 15-SP7 (ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* Basesystem Module 15-SP7 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
## References:
* https://jira.suse.com/browse/PED-16190
openSUSE-SU-2026:21518-1: important: Security update for python-ujson
openSUSE security update: security update for python-ujson
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21518-1
Rating: important
References:
* bsc#1270301
Cross-References:
* CVE-2026-44660
CVSS scores:
* CVE-2026-44660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-44660 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for python-ujson fixes the following issue:
- CVE-2026-44660: failing to decrement a serialized JSON object during a write exception in ujson.dump() can lead to
memory leaks (bsc#1270301).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1423=1
Package List:
- openSUSE Leap 16.0:
python313-ujson-5.10.0-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2026-44660.html
openSUSE-SU-2026:21516-1: important: Security update for python-sh
openSUSE security update: security update for python-sh
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21516-1
Rating: important
References:
* bsc#1272424
Cross-References:
* CVE-2026-54552
CVSS scores:
* CVE-2026-54552 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for python-sh fixes the following issue
- CVE-2026-54552: `_uid` option performs an incomplete privilege drop on Linux/Unix-like systems and allows
for privilege escalation (bsc#1272424).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1421=1
Package List:
- openSUSE Leap 16.0:
python313-sh-2.2.2-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2026-54552.html
openSUSE-SU-2026:21522-1: important: Security update for ffmpeg-4
openSUSE security update: security update for ffmpeg-4
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21522-1
Rating: important
References:
* bsc#1272752
* bsc#1272754
* bsc#1272758
* bsc#1272765
* bsc#1272768
Cross-References:
* CVE-2026-64830
* CVE-2026-64832
* CVE-2026-64835
* CVE-2026-66038
* CVE-2026-66039
CVSS scores:
* CVE-2026-64830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64830 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64832 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64832 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64835 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64835 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-66038 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-66039 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-66039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.
Description:
This update for ffmpeg-4 fixes the following issues:
Changes in ffmpeg-4:
- CVE-2026-64835: Out-of-Bounds Memory Access in ADX Audio Decoder (bsc#1272758)
- CVE-2026-64832: Double-Free in NVDEC Hardware Decoder via nvdec.c (bsc#1272754)
- CVE-2026-64830: Heap Buffer Overflow via VobSub Subtitle Demuxer (bsc#1272752)
- CVE-2026-66038: LCL/ZLIB Video Decoder Information Disclosure via lcldec.c (bsc#1272768)
- CVE-2026-66039: MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File (bsc#1272765)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-464=1
Package List:
- openSUSE Leap 16.0:
ffmpeg-4-4.4.7-bp160.3.1
ffmpeg-4-libavcodec-devel-4.4.7-bp160.3.1
ffmpeg-4-libavdevice-devel-4.4.7-bp160.3.1
ffmpeg-4-libavfilter-devel-4.4.7-bp160.3.1
ffmpeg-4-libavformat-devel-4.4.7-bp160.3.1
ffmpeg-4-libavresample-devel-4.4.7-bp160.3.1
ffmpeg-4-libavutil-devel-4.4.7-bp160.3.1
ffmpeg-4-libpostproc-devel-4.4.7-bp160.3.1
ffmpeg-4-libswresample-devel-4.4.7-bp160.3.1
ffmpeg-4-libswscale-devel-4.4.7-bp160.3.1
ffmpeg-4-private-devel-4.4.7-bp160.3.1
libavcodec58_134-4.4.7-bp160.3.1
libavdevice58_13-4.4.7-bp160.3.1
libavfilter7_110-4.4.7-bp160.3.1
libavformat58_76-4.4.7-bp160.3.1
libavresample4_0-4.4.7-bp160.3.1
libavutil56_70-4.4.7-bp160.3.1
libpostproc55_9-4.4.7-bp160.3.1
libswresample3_9-4.4.7-bp160.3.1
libswscale5_9-4.4.7-bp160.3.1
References:
* https://www.suse.com/security/cve/CVE-2026-64830.html
* https://www.suse.com/security/cve/CVE-2026-64832.html
* https://www.suse.com/security/cve/CVE-2026-64835.html
* https://www.suse.com/security/cve/CVE-2026-66038.html
* https://www.suse.com/security/cve/CVE-2026-66039.html
openSUSE-SU-2026:11436-1: moderate: golang-github-prometheus-prometheus-3.13.2-1.1 on GA media
# golang-github-prometheus-prometheus-3.13.2-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11436-1
Rating: moderate
Cross-References:
* CVE-2023-45289
* CVE-2025-4673
* CVE-2026-44990
* CVE-2026-56852
CVSS scores:
* CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 4 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the golang-github-prometheus-prometheus-3.13.2-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* golang-github-prometheus-prometheus 3.13.2-1.1
## References:
* https://www.suse.com/security/cve/CVE-2023-45289.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2026-44990.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:11438-1: moderate: alloy-1.18.0-1.1 on GA media
# alloy-1.18.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11438-1
Rating: moderate
Cross-References:
* CVE-2026-1229
* CVE-2026-33814
* CVE-2026-41506
* CVE-2026-41606
* CVE-2026-41607
CVSS scores:
* CVE-2026-1229 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
* CVE-2026-1229 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 5 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the alloy-1.18.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* alloy 1.18.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-1229.html
* https://www.suse.com/security/cve/CVE-2026-33814.html
* https://www.suse.com/security/cve/CVE-2026-41506.html
* https://www.suse.com/security/cve/CVE-2026-41606.html
* https://www.suse.com/security/cve/CVE-2026-41607.html
openSUSE-SU-2026:11437-1: moderate: podman-6.0.2-1.1 on GA media
# podman-6.0.2-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11437-1
Rating: moderate
Cross-References:
* CVE-2026-57231
CVSS scores:
* CVE-2026-57231 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57231 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the podman-6.0.2-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* podman 6.0.2-1.1
* podman-docker 6.0.2-1.1
* podman-remote 6.0.2-1.1
* podmansh 6.0.2-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-57231.html
openSUSE-SU-2026:11434-1: moderate: chromedriver-151.0.7922.71-1.1 on GA media
# chromedriver-151.0.7922.71-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11434-1
Rating: moderate
Cross-References:
* CVE-2026-17650
* CVE-2026-17651
* CVE-2026-17652
* CVE-2026-17653
* CVE-2026-17654
* CVE-2026-17655
* CVE-2026-17656
* CVE-2026-17657
* CVE-2026-17658
* CVE-2026-17659
* CVE-2026-17660
* CVE-2026-17661
* CVE-2026-17662
* CVE-2026-17663
* CVE-2026-17664
* CVE-2026-17665
* CVE-2026-17666
* CVE-2026-17667
* CVE-2026-17668
* CVE-2026-17669
* CVE-2026-17670
* CVE-2026-17671
* CVE-2026-17672
* CVE-2026-17673
* CVE-2026-17674
* CVE-2026-17675
* CVE-2026-17676
* CVE-2026-17677
* CVE-2026-17678
* CVE-2026-17679
* CVE-2026-17680
* CVE-2026-17681
* CVE-2026-17682
* CVE-2026-17683
* CVE-2026-17684
* CVE-2026-17685
* CVE-2026-17686
* CVE-2026-17687
* CVE-2026-17688
* CVE-2026-17689
* CVE-2026-17690
* CVE-2026-17691
* CVE-2026-17692
* CVE-2026-17693
* CVE-2026-17694
* CVE-2026-17695
* CVE-2026-17696
* CVE-2026-17697
* CVE-2026-17698
* CVE-2026-17699
* CVE-2026-17700
* CVE-2026-17701
* CVE-2026-17702
* CVE-2026-17703
* CVE-2026-17704
* CVE-2026-17705
* CVE-2026-17706
* CVE-2026-17707
* CVE-2026-17708
* CVE-2026-17709
* CVE-2026-17710
* CVE-2026-17711
* CVE-2026-17712
* CVE-2026-17713
* CVE-2026-17714
* CVE-2026-17715
* CVE-2026-17716
* CVE-2026-17717
* CVE-2026-17718
* CVE-2026-17719
* CVE-2026-17720
* CVE-2026-17721
* CVE-2026-17722
* CVE-2026-17723
* CVE-2026-17724
* CVE-2026-17725
* CVE-2026-17726
* CVE-2026-17727
* CVE-2026-17728
* CVE-2026-17729
* CVE-2026-17730
* CVE-2026-17731
* CVE-2026-17732
* CVE-2026-17733
* CVE-2026-17734
* CVE-2026-17735
* CVE-2026-17736
* CVE-2026-17737
* CVE-2026-17738
* CVE-2026-17739
* CVE-2026-17740
* CVE-2026-17741
* CVE-2026-17742
* CVE-2026-17743
* CVE-2026-17744
* CVE-2026-17745
* CVE-2026-17746
* CVE-2026-17747
* CVE-2026-17748
* CVE-2026-17749
* CVE-2026-17750
* CVE-2026-17751
* CVE-2026-17752
* CVE-2026-17753
* CVE-2026-17754
* CVE-2026-17755
* CVE-2026-17756
* CVE-2026-17757
* CVE-2026-17758
* CVE-2026-17759
* CVE-2026-17760
* CVE-2026-17761
* CVE-2026-17762
* CVE-2026-17763
* CVE-2026-17764
* CVE-2026-17765
* CVE-2026-17766
* CVE-2026-17767
* CVE-2026-17768
* CVE-2026-17769
* CVE-2026-17770
* CVE-2026-17771
* CVE-2026-17772
* CVE-2026-17773
* CVE-2026-17774
* CVE-2026-17775
* CVE-2026-17776
* CVE-2026-17777
* CVE-2026-17778
* CVE-2026-17779
* CVE-2026-17780
* CVE-2026-17781
* CVE-2026-17782
* CVE-2026-17783
* CVE-2026-17784
* CVE-2026-17785
* CVE-2026-17786
* CVE-2026-17787
* CVE-2026-17788
* CVE-2026-17789
* CVE-2026-17790
* CVE-2026-17791
* CVE-2026-17792
* CVE-2026-17793
* CVE-2026-17794
* CVE-2026-17795
* CVE-2026-17796
* CVE-2026-17797
* CVE-2026-17798
* CVE-2026-17799
* CVE-2026-17800
* CVE-2026-17801
* CVE-2026-17802
* CVE-2026-17803
* CVE-2026-17804
* CVE-2026-17805
* CVE-2026-17806
* CVE-2026-17807
* CVE-2026-17808
* CVE-2026-17809
* CVE-2026-17810
* CVE-2026-17811
* CVE-2026-17812
* CVE-2026-17813
* CVE-2026-17814
* CVE-2026-17815
* CVE-2026-17816
* CVE-2026-17817
* CVE-2026-17818
* CVE-2026-17819
* CVE-2026-17820
* CVE-2026-17821
* CVE-2026-17822
* CVE-2026-17823
* CVE-2026-17824
* CVE-2026-17825
* CVE-2026-17826
* CVE-2026-17827
* CVE-2026-17828
* CVE-2026-17829
* CVE-2026-17830
* CVE-2026-17831
* CVE-2026-17832
* CVE-2026-17833
* CVE-2026-17834
* CVE-2026-17835
* CVE-2026-17836
* CVE-2026-17837
* CVE-2026-17838
* CVE-2026-17839
* CVE-2026-17840
* CVE-2026-17841
* CVE-2026-17842
* CVE-2026-17843
* CVE-2026-17844
* CVE-2026-17845
* CVE-2026-17846
* CVE-2026-17847
* CVE-2026-17848
* CVE-2026-17849
* CVE-2026-17850
* CVE-2026-17851
* CVE-2026-17852
* CVE-2026-17853
* CVE-2026-17854
* CVE-2026-17855
* CVE-2026-17856
* CVE-2026-17857
* CVE-2026-17858
* CVE-2026-17859
* CVE-2026-17860
* CVE-2026-17861
* CVE-2026-17862
* CVE-2026-17863
* CVE-2026-17864
* CVE-2026-17865
* CVE-2026-17866
* CVE-2026-17867
* CVE-2026-17868
* CVE-2026-17869
* CVE-2026-17870
* CVE-2026-17871
* CVE-2026-17872
* CVE-2026-17873
* CVE-2026-17874
* CVE-2026-17875
* CVE-2026-17876
* CVE-2026-17877
* CVE-2026-17878
* CVE-2026-17879
* CVE-2026-17880
* CVE-2026-17881
* CVE-2026-17882
* CVE-2026-17883
* CVE-2026-17884
* CVE-2026-17885
* CVE-2026-17886
* CVE-2026-17887
* CVE-2026-17888
* CVE-2026-17889
* CVE-2026-17890
* CVE-2026-17891
* CVE-2026-17892
* CVE-2026-17893
* CVE-2026-17894
* CVE-2026-17895
* CVE-2026-17896
* CVE-2026-17897
* CVE-2026-17898
* CVE-2026-17899
* CVE-2026-17900
* CVE-2026-17901
* CVE-2026-17902
* CVE-2026-17903
* CVE-2026-17904
* CVE-2026-17905
* CVE-2026-17906
* CVE-2026-17907
* CVE-2026-17908
* CVE-2026-17909
* CVE-2026-17910
* CVE-2026-17911
* CVE-2026-17912
* CVE-2026-17913
* CVE-2026-17914
* CVE-2026-17915
* CVE-2026-17916
* CVE-2026-17917
* CVE-2026-17918
* CVE-2026-17919
* CVE-2026-17920
* CVE-2026-17921
* CVE-2026-17922
* CVE-2026-17923
* CVE-2026-17924
* CVE-2026-17925
* CVE-2026-17926
* CVE-2026-17927
* CVE-2026-17928
* CVE-2026-17929
* CVE-2026-17930
* CVE-2026-17931
* CVE-2026-17932
* CVE-2026-17933
* CVE-2026-17934
* CVE-2026-17935
* CVE-2026-17936
* CVE-2026-17937
* CVE-2026-17938
* CVE-2026-17939
* CVE-2026-17940
* CVE-2026-17941
* CVE-2026-17942
* CVE-2026-17943
* CVE-2026-17944
* CVE-2026-17945
* CVE-2026-17946
* CVE-2026-17947
* CVE-2026-17948
* CVE-2026-17949
* CVE-2026-17950
* CVE-2026-17951
* CVE-2026-17952
* CVE-2026-17953
* CVE-2026-17954
* CVE-2026-17955
* CVE-2026-17956
* CVE-2026-17957
* CVE-2026-17958
* CVE-2026-17959
* CVE-2026-17960
* CVE-2026-17961
* CVE-2026-17962
* CVE-2026-17963
* CVE-2026-17964
* CVE-2026-17965
* CVE-2026-17966
* CVE-2026-17967
* CVE-2026-17968
* CVE-2026-17969
* CVE-2026-17970
* CVE-2026-17971
* CVE-2026-17972
* CVE-2026-17973
* CVE-2026-17974
* CVE-2026-17975
* CVE-2026-17976
* CVE-2026-17977
* CVE-2026-17978
* CVE-2026-17979
* CVE-2026-17980
* CVE-2026-17981
* CVE-2026-17982
* CVE-2026-17983
* CVE-2026-17984
* CVE-2026-17985
* CVE-2026-17986
* CVE-2026-17987
* CVE-2026-17988
* CVE-2026-17989
* CVE-2026-17990
* CVE-2026-17991
* CVE-2026-17992
* CVE-2026-17993
* CVE-2026-17994
* CVE-2026-17995
* CVE-2026-17996
* CVE-2026-17997
* CVE-2026-17998
* CVE-2026-17999
* CVE-2026-18000
* CVE-2026-18001
* CVE-2026-18002
* CVE-2026-18003
* CVE-2026-18004
* CVE-2026-18005
* CVE-2026-18006
* CVE-2026-18007
* CVE-2026-18008
* CVE-2026-18009
* CVE-2026-18010
* CVE-2026-18011
* CVE-2026-18012
* CVE-2026-18013
* CVE-2026-18014
* CVE-2026-18015
* CVE-2026-18016
* CVE-2026-18017
* CVE-2026-18018
* CVE-2026-18019
Affected Products:
* openSUSE Tumbleweed
An update that solves 370 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the chromedriver-151.0.7922.71-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* chromedriver 151.0.7922.71-1.1
* chromium 151.0.7922.71-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-17650.html
* https://www.suse.com/security/cve/CVE-2026-17651.html
* https://www.suse.com/security/cve/CVE-2026-17652.html
* https://www.suse.com/security/cve/CVE-2026-17653.html
* https://www.suse.com/security/cve/CVE-2026-17654.html
* https://www.suse.com/security/cve/CVE-2026-17655.html
* https://www.suse.com/security/cve/CVE-2026-17656.html
* https://www.suse.com/security/cve/CVE-2026-17657.html
* https://www.suse.com/security/cve/CVE-2026-17658.html
* https://www.suse.com/security/cve/CVE-2026-17659.html
* https://www.suse.com/security/cve/CVE-2026-17660.html
* https://www.suse.com/security/cve/CVE-2026-17661.html
* https://www.suse.com/security/cve/CVE-2026-17662.html
* https://www.suse.com/security/cve/CVE-2026-17663.html
* https://www.suse.com/security/cve/CVE-2026-17664.html
* https://www.suse.com/security/cve/CVE-2026-17665.html
* https://www.suse.com/security/cve/CVE-2026-17666.html
* https://www.suse.com/security/cve/CVE-2026-17667.html
* https://www.suse.com/security/cve/CVE-2026-17668.html
* https://www.suse.com/security/cve/CVE-2026-17669.html
* https://www.suse.com/security/cve/CVE-2026-17670.html
* https://www.suse.com/security/cve/CVE-2026-17671.html
* https://www.suse.com/security/cve/CVE-2026-17672.html
* https://www.suse.com/security/cve/CVE-2026-17673.html
* https://www.suse.com/security/cve/CVE-2026-17674.html
* https://www.suse.com/security/cve/CVE-2026-17675.html
* https://www.suse.com/security/cve/CVE-2026-17676.html
* https://www.suse.com/security/cve/CVE-2026-17677.html
* https://www.suse.com/security/cve/CVE-2026-17678.html
* https://www.suse.com/security/cve/CVE-2026-17679.html
* https://www.suse.com/security/cve/CVE-2026-17680.html
* https://www.suse.com/security/cve/CVE-2026-17681.html
* https://www.suse.com/security/cve/CVE-2026-17682.html
* https://www.suse.com/security/cve/CVE-2026-17683.html
* https://www.suse.com/security/cve/CVE-2026-17684.html
* https://www.suse.com/security/cve/CVE-2026-17685.html
* https://www.suse.com/security/cve/CVE-2026-17686.html
* https://www.suse.com/security/cve/CVE-2026-17687.html
* https://www.suse.com/security/cve/CVE-2026-17688.html
* https://www.suse.com/security/cve/CVE-2026-17689.html
* https://www.suse.com/security/cve/CVE-2026-17690.html
* https://www.suse.com/security/cve/CVE-2026-17691.html
* https://www.suse.com/security/cve/CVE-2026-17692.html
* https://www.suse.com/security/cve/CVE-2026-17693.html
* https://www.suse.com/security/cve/CVE-2026-17694.html
* https://www.suse.com/security/cve/CVE-2026-17695.html
* https://www.suse.com/security/cve/CVE-2026-17696.html
* https://www.suse.com/security/cve/CVE-2026-17697.html
* https://www.suse.com/security/cve/CVE-2026-17698.html
* https://www.suse.com/security/cve/CVE-2026-17699.html
* https://www.suse.com/security/cve/CVE-2026-17700.html
* https://www.suse.com/security/cve/CVE-2026-17701.html
* https://www.suse.com/security/cve/CVE-2026-17702.html
* https://www.suse.com/security/cve/CVE-2026-17703.html
* https://www.suse.com/security/cve/CVE-2026-17704.html
* https://www.suse.com/security/cve/CVE-2026-17705.html
* https://www.suse.com/security/cve/CVE-2026-17706.html
* https://www.suse.com/security/cve/CVE-2026-17707.html
* https://www.suse.com/security/cve/CVE-2026-17708.html
* https://www.suse.com/security/cve/CVE-2026-17709.html
* https://www.suse.com/security/cve/CVE-2026-17710.html
* https://www.suse.com/security/cve/CVE-2026-17711.html
* https://www.suse.com/security/cve/CVE-2026-17712.html
* https://www.suse.com/security/cve/CVE-2026-17713.html
* https://www.suse.com/security/cve/CVE-2026-17714.html
* https://www.suse.com/security/cve/CVE-2026-17715.html
* https://www.suse.com/security/cve/CVE-2026-17716.html
* https://www.suse.com/security/cve/CVE-2026-17717.html
* https://www.suse.com/security/cve/CVE-2026-17718.html
* https://www.suse.com/security/cve/CVE-2026-17719.html
* https://www.suse.com/security/cve/CVE-2026-17720.html
* https://www.suse.com/security/cve/CVE-2026-17721.html
* https://www.suse.com/security/cve/CVE-2026-17722.html
* https://www.suse.com/security/cve/CVE-2026-17723.html
* https://www.suse.com/security/cve/CVE-2026-17724.html
* https://www.suse.com/security/cve/CVE-2026-17725.html
* https://www.suse.com/security/cve/CVE-2026-17726.html
* https://www.suse.com/security/cve/CVE-2026-17727.html
* https://www.suse.com/security/cve/CVE-2026-17728.html
* https://www.suse.com/security/cve/CVE-2026-17729.html
* https://www.suse.com/security/cve/CVE-2026-17730.html
* https://www.suse.com/security/cve/CVE-2026-17731.html
* https://www.suse.com/security/cve/CVE-2026-17732.html
* https://www.suse.com/security/cve/CVE-2026-17733.html
* https://www.suse.com/security/cve/CVE-2026-17734.html
* https://www.suse.com/security/cve/CVE-2026-17735.html
* https://www.suse.com/security/cve/CVE-2026-17736.html
* https://www.suse.com/security/cve/CVE-2026-17737.html
* https://www.suse.com/security/cve/CVE-2026-17738.html
* https://www.suse.com/security/cve/CVE-2026-17739.html
* https://www.suse.com/security/cve/CVE-2026-17740.html
* https://www.suse.com/security/cve/CVE-2026-17741.html
* https://www.suse.com/security/cve/CVE-2026-17742.html
* https://www.suse.com/security/cve/CVE-2026-17743.html
* https://www.suse.com/security/cve/CVE-2026-17744.html
* https://www.suse.com/security/cve/CVE-2026-17745.html
* https://www.suse.com/security/cve/CVE-2026-17746.html
* https://www.suse.com/security/cve/CVE-2026-17747.html
* https://www.suse.com/security/cve/CVE-2026-17748.html
* https://www.suse.com/security/cve/CVE-2026-17749.html
* https://www.suse.com/security/cve/CVE-2026-17750.html
* https://www.suse.com/security/cve/CVE-2026-17751.html
* https://www.suse.com/security/cve/CVE-2026-17752.html
* https://www.suse.com/security/cve/CVE-2026-17753.html
* https://www.suse.com/security/cve/CVE-2026-17754.html
* https://www.suse.com/security/cve/CVE-2026-17755.html
* https://www.suse.com/security/cve/CVE-2026-17756.html
* https://www.suse.com/security/cve/CVE-2026-17757.html
* https://www.suse.com/security/cve/CVE-2026-17758.html
* https://www.suse.com/security/cve/CVE-2026-17759.html
* https://www.suse.com/security/cve/CVE-2026-17760.html
* https://www.suse.com/security/cve/CVE-2026-17761.html
* https://www.suse.com/security/cve/CVE-2026-17762.html
* https://www.suse.com/security/cve/CVE-2026-17763.html
* https://www.suse.com/security/cve/CVE-2026-17764.html
* https://www.suse.com/security/cve/CVE-2026-17765.html
* https://www.suse.com/security/cve/CVE-2026-17766.html
* https://www.suse.com/security/cve/CVE-2026-17767.html
* https://www.suse.com/security/cve/CVE-2026-17768.html
* https://www.suse.com/security/cve/CVE-2026-17769.html
* https://www.suse.com/security/cve/CVE-2026-17770.html
* https://www.suse.com/security/cve/CVE-2026-17771.html
* https://www.suse.com/security/cve/CVE-2026-17772.html
* https://www.suse.com/security/cve/CVE-2026-17773.html
* https://www.suse.com/security/cve/CVE-2026-17774.html
* https://www.suse.com/security/cve/CVE-2026-17775.html
* https://www.suse.com/security/cve/CVE-2026-17776.html
* https://www.suse.com/security/cve/CVE-2026-17777.html
* https://www.suse.com/security/cve/CVE-2026-17778.html
* https://www.suse.com/security/cve/CVE-2026-17779.html
* https://www.suse.com/security/cve/CVE-2026-17780.html
* https://www.suse.com/security/cve/CVE-2026-17781.html
* https://www.suse.com/security/cve/CVE-2026-17782.html
* https://www.suse.com/security/cve/CVE-2026-17783.html
* https://www.suse.com/security/cve/CVE-2026-17784.html
* https://www.suse.com/security/cve/CVE-2026-17785.html
* https://www.suse.com/security/cve/CVE-2026-17786.html
* https://www.suse.com/security/cve/CVE-2026-17787.html
* https://www.suse.com/security/cve/CVE-2026-17788.html
* https://www.suse.com/security/cve/CVE-2026-17789.html
* https://www.suse.com/security/cve/CVE-2026-17790.html
* https://www.suse.com/security/cve/CVE-2026-17791.html
* https://www.suse.com/security/cve/CVE-2026-17792.html
* https://www.suse.com/security/cve/CVE-2026-17793.html
* https://www.suse.com/security/cve/CVE-2026-17794.html
* https://www.suse.com/security/cve/CVE-2026-17795.html
* https://www.suse.com/security/cve/CVE-2026-17796.html
* https://www.suse.com/security/cve/CVE-2026-17797.html
* https://www.suse.com/security/cve/CVE-2026-17798.html
* https://www.suse.com/security/cve/CVE-2026-17799.html
* https://www.suse.com/security/cve/CVE-2026-17800.html
* https://www.suse.com/security/cve/CVE-2026-17801.html
* https://www.suse.com/security/cve/CVE-2026-17802.html
* https://www.suse.com/security/cve/CVE-2026-17803.html
* https://www.suse.com/security/cve/CVE-2026-17804.html
* https://www.suse.com/security/cve/CVE-2026-17805.html
* https://www.suse.com/security/cve/CVE-2026-17806.html
* https://www.suse.com/security/cve/CVE-2026-17807.html
* https://www.suse.com/security/cve/CVE-2026-17808.html
* https://www.suse.com/security/cve/CVE-2026-17809.html
* https://www.suse.com/security/cve/CVE-2026-17810.html
* https://www.suse.com/security/cve/CVE-2026-17811.html
* https://www.suse.com/security/cve/CVE-2026-17812.html
* https://www.suse.com/security/cve/CVE-2026-17813.html
* https://www.suse.com/security/cve/CVE-2026-17814.html
* https://www.suse.com/security/cve/CVE-2026-17815.html
* https://www.suse.com/security/cve/CVE-2026-17816.html
* https://www.suse.com/security/cve/CVE-2026-17817.html
* https://www.suse.com/security/cve/CVE-2026-17818.html
* https://www.suse.com/security/cve/CVE-2026-17819.html
* https://www.suse.com/security/cve/CVE-2026-17820.html
* https://www.suse.com/security/cve/CVE-2026-17821.html
* https://www.suse.com/security/cve/CVE-2026-17822.html
* https://www.suse.com/security/cve/CVE-2026-17823.html
* https://www.suse.com/security/cve/CVE-2026-17824.html
* https://www.suse.com/security/cve/CVE-2026-17825.html
* https://www.suse.com/security/cve/CVE-2026-17826.html
* https://www.suse.com/security/cve/CVE-2026-17827.html
* https://www.suse.com/security/cve/CVE-2026-17828.html
* https://www.suse.com/security/cve/CVE-2026-17829.html
* https://www.suse.com/security/cve/CVE-2026-17830.html
* https://www.suse.com/security/cve/CVE-2026-17831.html
* https://www.suse.com/security/cve/CVE-2026-17832.html
* https://www.suse.com/security/cve/CVE-2026-17833.html
* https://www.suse.com/security/cve/CVE-2026-17834.html
* https://www.suse.com/security/cve/CVE-2026-17835.html
* https://www.suse.com/security/cve/CVE-2026-17836.html
* https://www.suse.com/security/cve/CVE-2026-17837.html
* https://www.suse.com/security/cve/CVE-2026-17838.html
* https://www.suse.com/security/cve/CVE-2026-17839.html
* https://www.suse.com/security/cve/CVE-2026-17840.html
* https://www.suse.com/security/cve/CVE-2026-17841.html
* https://www.suse.com/security/cve/CVE-2026-17842.html
* https://www.suse.com/security/cve/CVE-2026-17843.html
* https://www.suse.com/security/cve/CVE-2026-17844.html
* https://www.suse.com/security/cve/CVE-2026-17845.html
* https://www.suse.com/security/cve/CVE-2026-17846.html
* https://www.suse.com/security/cve/CVE-2026-17847.html
* https://www.suse.com/security/cve/CVE-2026-17848.html
* https://www.suse.com/security/cve/CVE-2026-17849.html
* https://www.suse.com/security/cve/CVE-2026-17850.html
* https://www.suse.com/security/cve/CVE-2026-17851.html
* https://www.suse.com/security/cve/CVE-2026-17852.html
* https://www.suse.com/security/cve/CVE-2026-17853.html
* https://www.suse.com/security/cve/CVE-2026-17854.html
* https://www.suse.com/security/cve/CVE-2026-17855.html
* https://www.suse.com/security/cve/CVE-2026-17856.html
* https://www.suse.com/security/cve/CVE-2026-17857.html
* https://www.suse.com/security/cve/CVE-2026-17858.html
* https://www.suse.com/security/cve/CVE-2026-17859.html
* https://www.suse.com/security/cve/CVE-2026-17860.html
* https://www.suse.com/security/cve/CVE-2026-17861.html
* https://www.suse.com/security/cve/CVE-2026-17862.html
* https://www.suse.com/security/cve/CVE-2026-17863.html
* https://www.suse.com/security/cve/CVE-2026-17864.html
* https://www.suse.com/security/cve/CVE-2026-17865.html
* https://www.suse.com/security/cve/CVE-2026-17866.html
* https://www.suse.com/security/cve/CVE-2026-17867.html
* https://www.suse.com/security/cve/CVE-2026-17868.html
* https://www.suse.com/security/cve/CVE-2026-17869.html
* https://www.suse.com/security/cve/CVE-2026-17870.html
* https://www.suse.com/security/cve/CVE-2026-17871.html
* https://www.suse.com/security/cve/CVE-2026-17872.html
* https://www.suse.com/security/cve/CVE-2026-17873.html
* https://www.suse.com/security/cve/CVE-2026-17874.html
* https://www.suse.com/security/cve/CVE-2026-17875.html
* https://www.suse.com/security/cve/CVE-2026-17876.html
* https://www.suse.com/security/cve/CVE-2026-17877.html
* https://www.suse.com/security/cve/CVE-2026-17878.html
* https://www.suse.com/security/cve/CVE-2026-17879.html
* https://www.suse.com/security/cve/CVE-2026-17880.html
* https://www.suse.com/security/cve/CVE-2026-17881.html
* https://www.suse.com/security/cve/CVE-2026-17882.html
* https://www.suse.com/security/cve/CVE-2026-17883.html
* https://www.suse.com/security/cve/CVE-2026-17884.html
* https://www.suse.com/security/cve/CVE-2026-17885.html
* https://www.suse.com/security/cve/CVE-2026-17886.html
* https://www.suse.com/security/cve/CVE-2026-17887.html
* https://www.suse.com/security/cve/CVE-2026-17888.html
* https://www.suse.com/security/cve/CVE-2026-17889.html
* https://www.suse.com/security/cve/CVE-2026-17890.html
* https://www.suse.com/security/cve/CVE-2026-17891.html
* https://www.suse.com/security/cve/CVE-2026-17892.html
* https://www.suse.com/security/cve/CVE-2026-17893.html
* https://www.suse.com/security/cve/CVE-2026-17894.html
* https://www.suse.com/security/cve/CVE-2026-17895.html
* https://www.suse.com/security/cve/CVE-2026-17896.html
* https://www.suse.com/security/cve/CVE-2026-17897.html
* https://www.suse.com/security/cve/CVE-2026-17898.html
* https://www.suse.com/security/cve/CVE-2026-17899.html
* https://www.suse.com/security/cve/CVE-2026-17900.html
* https://www.suse.com/security/cve/CVE-2026-17901.html
* https://www.suse.com/security/cve/CVE-2026-17902.html
* https://www.suse.com/security/cve/CVE-2026-17903.html
* https://www.suse.com/security/cve/CVE-2026-17904.html
* https://www.suse.com/security/cve/CVE-2026-17905.html
* https://www.suse.com/security/cve/CVE-2026-17906.html
* https://www.suse.com/security/cve/CVE-2026-17907.html
* https://www.suse.com/security/cve/CVE-2026-17908.html
* https://www.suse.com/security/cve/CVE-2026-17909.html
* https://www.suse.com/security/cve/CVE-2026-17910.html
* https://www.suse.com/security/cve/CVE-2026-17911.html
* https://www.suse.com/security/cve/CVE-2026-17912.html
* https://www.suse.com/security/cve/CVE-2026-17913.html
* https://www.suse.com/security/cve/CVE-2026-17914.html
* https://www.suse.com/security/cve/CVE-2026-17915.html
* https://www.suse.com/security/cve/CVE-2026-17916.html
* https://www.suse.com/security/cve/CVE-2026-17917.html
* https://www.suse.com/security/cve/CVE-2026-17918.html
* https://www.suse.com/security/cve/CVE-2026-17919.html
* https://www.suse.com/security/cve/CVE-2026-17920.html
* https://www.suse.com/security/cve/CVE-2026-17921.html
* https://www.suse.com/security/cve/CVE-2026-17922.html
* https://www.suse.com/security/cve/CVE-2026-17923.html
* https://www.suse.com/security/cve/CVE-2026-17924.html
* https://www.suse.com/security/cve/CVE-2026-17925.html
* https://www.suse.com/security/cve/CVE-2026-17926.html
* https://www.suse.com/security/cve/CVE-2026-17927.html
* https://www.suse.com/security/cve/CVE-2026-17928.html
* https://www.suse.com/security/cve/CVE-2026-17929.html
* https://www.suse.com/security/cve/CVE-2026-17930.html
* https://www.suse.com/security/cve/CVE-2026-17931.html
* https://www.suse.com/security/cve/CVE-2026-17932.html
* https://www.suse.com/security/cve/CVE-2026-17933.html
* https://www.suse.com/security/cve/CVE-2026-17934.html
* https://www.suse.com/security/cve/CVE-2026-17935.html
* https://www.suse.com/security/cve/CVE-2026-17936.html
* https://www.suse.com/security/cve/CVE-2026-17937.html
* https://www.suse.com/security/cve/CVE-2026-17938.html
* https://www.suse.com/security/cve/CVE-2026-17939.html
* https://www.suse.com/security/cve/CVE-2026-17940.html
* https://www.suse.com/security/cve/CVE-2026-17941.html
* https://www.suse.com/security/cve/CVE-2026-17942.html
* https://www.suse.com/security/cve/CVE-2026-17943.html
* https://www.suse.com/security/cve/CVE-2026-17944.html
* https://www.suse.com/security/cve/CVE-2026-17945.html
* https://www.suse.com/security/cve/CVE-2026-17946.html
* https://www.suse.com/security/cve/CVE-2026-17947.html
* https://www.suse.com/security/cve/CVE-2026-17948.html
* https://www.suse.com/security/cve/CVE-2026-17949.html
* https://www.suse.com/security/cve/CVE-2026-17950.html
* https://www.suse.com/security/cve/CVE-2026-17951.html
* https://www.suse.com/security/cve/CVE-2026-17952.html
* https://www.suse.com/security/cve/CVE-2026-17953.html
* https://www.suse.com/security/cve/CVE-2026-17954.html
* https://www.suse.com/security/cve/CVE-2026-17955.html
* https://www.suse.com/security/cve/CVE-2026-17956.html
* https://www.suse.com/security/cve/CVE-2026-17957.html
* https://www.suse.com/security/cve/CVE-2026-17958.html
* https://www.suse.com/security/cve/CVE-2026-17959.html
* https://www.suse.com/security/cve/CVE-2026-17960.html
* https://www.suse.com/security/cve/CVE-2026-17961.html
* https://www.suse.com/security/cve/CVE-2026-17962.html
* https://www.suse.com/security/cve/CVE-2026-17963.html
* https://www.suse.com/security/cve/CVE-2026-17964.html
* https://www.suse.com/security/cve/CVE-2026-17965.html
* https://www.suse.com/security/cve/CVE-2026-17966.html
* https://www.suse.com/security/cve/CVE-2026-17967.html
* https://www.suse.com/security/cve/CVE-2026-17968.html
* https://www.suse.com/security/cve/CVE-2026-17969.html
* https://www.suse.com/security/cve/CVE-2026-17970.html
* https://www.suse.com/security/cve/CVE-2026-17971.html
* https://www.suse.com/security/cve/CVE-2026-17972.html
* https://www.suse.com/security/cve/CVE-2026-17973.html
* https://www.suse.com/security/cve/CVE-2026-17974.html
* https://www.suse.com/security/cve/CVE-2026-17975.html
* https://www.suse.com/security/cve/CVE-2026-17976.html
* https://www.suse.com/security/cve/CVE-2026-17977.html
* https://www.suse.com/security/cve/CVE-2026-17978.html
* https://www.suse.com/security/cve/CVE-2026-17979.html
* https://www.suse.com/security/cve/CVE-2026-17980.html
* https://www.suse.com/security/cve/CVE-2026-17981.html
* https://www.suse.com/security/cve/CVE-2026-17982.html
* https://www.suse.com/security/cve/CVE-2026-17983.html
* https://www.suse.com/security/cve/CVE-2026-17984.html
* https://www.suse.com/security/cve/CVE-2026-17985.html
* https://www.suse.com/security/cve/CVE-2026-17986.html
* https://www.suse.com/security/cve/CVE-2026-17987.html
* https://www.suse.com/security/cve/CVE-2026-17988.html
* https://www.suse.com/security/cve/CVE-2026-17989.html
* https://www.suse.com/security/cve/CVE-2026-17990.html
* https://www.suse.com/security/cve/CVE-2026-17991.html
* https://www.suse.com/security/cve/CVE-2026-17992.html
* https://www.suse.com/security/cve/CVE-2026-17993.html
* https://www.suse.com/security/cve/CVE-2026-17994.html
* https://www.suse.com/security/cve/CVE-2026-17995.html
* https://www.suse.com/security/cve/CVE-2026-17996.html
* https://www.suse.com/security/cve/CVE-2026-17997.html
* https://www.suse.com/security/cve/CVE-2026-17998.html
* https://www.suse.com/security/cve/CVE-2026-17999.html
* https://www.suse.com/security/cve/CVE-2026-18000.html
* https://www.suse.com/security/cve/CVE-2026-18001.html
* https://www.suse.com/security/cve/CVE-2026-18002.html
* https://www.suse.com/security/cve/CVE-2026-18003.html
* https://www.suse.com/security/cve/CVE-2026-18004.html
* https://www.suse.com/security/cve/CVE-2026-18005.html
* https://www.suse.com/security/cve/CVE-2026-18006.html
* https://www.suse.com/security/cve/CVE-2026-18007.html
* https://www.suse.com/security/cve/CVE-2026-18008.html
* https://www.suse.com/security/cve/CVE-2026-18009.html
* https://www.suse.com/security/cve/CVE-2026-18010.html
* https://www.suse.com/security/cve/CVE-2026-18011.html
* https://www.suse.com/security/cve/CVE-2026-18012.html
* https://www.suse.com/security/cve/CVE-2026-18013.html
* https://www.suse.com/security/cve/CVE-2026-18014.html
* https://www.suse.com/security/cve/CVE-2026-18015.html
* https://www.suse.com/security/cve/CVE-2026-18016.html
* https://www.suse.com/security/cve/CVE-2026-18017.html
* https://www.suse.com/security/cve/CVE-2026-18018.html
* https://www.suse.com/security/cve/CVE-2026-18019.html
openSUSE-SU-2026:11440-1: moderate: nodejs26-26.5.1-1.1 on GA media
# nodejs26-26.5.1-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11440-1
Rating: moderate
Cross-References:
* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58041
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045
CVSS scores:
* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 11 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the nodejs26-26.5.1-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* nodejs26 26.5.1-1.1
* nodejs26-devel 26.5.1-1.1
* nodejs26-docs 26.5.1-1.1
* npm26 26.5.1-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58041.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html
openSUSE-SU-2026:11439-1: moderate: corepack24-24.18.1-1.1 on GA media
# corepack24-24.18.1-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11439-1
Rating: moderate
Cross-References:
* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58041
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045
CVSS scores:
* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 11 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the corepack24-24.18.1-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* corepack24 24.18.1-1.1
* nodejs24 24.18.1-1.1
* nodejs24-devel 24.18.1-1.1
* nodejs24-docs 24.18.1-1.1
* npm24 24.18.1-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58041.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html
openSUSE-SU-2026:11441-1: moderate: xen-4.22.0_02-1.1 on GA media
# xen-4.22.0_02-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11441-1
Rating: moderate
Cross-References:
* CVE-2026-42492
* CVE-2026-42493
* CVE-2026-42494
* CVE-2026-62423
* CVE-2026-62426
* CVE-2026-62428
* CVE-2026-62429
* CVE-2026-62430
* CVE-2026-62431
* CVE-2026-62432
* CVE-2026-62433
* CVE-2026-62434
CVSS scores:
* CVE-2026-42492 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42492 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
Affected Products:
* openSUSE Tumbleweed
An update that solves 12 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the xen-4.22.0_02-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* xen 4.22.0_02-1.1
* xen-devel 4.22.0_02-1.1
* xen-doc-html 4.22.0_02-1.1
* xen-libs 4.22.0_02-1.1
* xen-tools 4.22.0_02-1.1
* xen-tools-domU 4.22.0_02-1.1
* xen-tools-xendomains-wait-disk 4.22.0_02-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-42492.html
* https://www.suse.com/security/cve/CVE-2026-42493.html
* https://www.suse.com/security/cve/CVE-2026-42494.html
* https://www.suse.com/security/cve/CVE-2026-62423.html
* https://www.suse.com/security/cve/CVE-2026-62426.html
* https://www.suse.com/security/cve/CVE-2026-62428.html
* https://www.suse.com/security/cve/CVE-2026-62429.html
* https://www.suse.com/security/cve/CVE-2026-62430.html
* https://www.suse.com/security/cve/CVE-2026-62431.html
* https://www.suse.com/security/cve/CVE-2026-62432.html
* https://www.suse.com/security/cve/CVE-2026-62433.html
* https://www.suse.com/security/cve/CVE-2026-62434.html
SUSE-SU-2026:3468-1: important: Security update for rrdtool
# Security update for rrdtool
Announcement ID: SUSE-SU-2026:3468-1
Release Date: 2026-08-03T16:34:53Z
Rating: important
References:
* bsc#1267243
Cross-References:
* CVE-2026-43958
CVSS scores:
* CVE-2026-43958 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43958 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43958 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for rrdtool fixes the following issue:
* CVE-2026-43958: stack buffer overflow in `rrdcached`
`handle_request_create()` can lead to local privilege escalation via
unbounded DS/RRA arguments (bsc#1267243).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3468=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3468=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3468=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3468=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* tcl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* tcl-rrdtool-1.8.0-150600.3.9.1
* lua-rrdtool-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* ruby-rrdtool-debuginfo-1.8.0-150600.3.9.1
* python3-rrdtool-1.8.0-150600.3.9.1
* python3-rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-cached-debuginfo-1.8.0-150600.3.9.1
* rrdtool-cached-1.8.0-150600.3.9.1
* ruby-rrdtool-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* rrdtool-doc-1.8.0-150600.3.9.1
* lua-rrdtool-debuginfo-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
## References:
* https://www.suse.com/security/cve/CVE-2026-43958.html
* https://bugzilla.suse.com/show_bug.cgi?id67243
SUSE-SU-2026:3469-1: important: Security update for nginx
# Security update for nginx
Announcement ID: SUSE-SU-2026:3469-1
Release Date: 2026-08-03T16:40:38Z
Rating: important
References:
* bsc#1271514
Cross-References:
* CVE-2026-42533
CVSS scores:
* CVE-2026-42533 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-42533 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42533 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42533 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for nginx fixes the following issue:
* CVE-2026-42533: referencing regex capture variables before map output
variables can trigger a heap buffer overflow (bsc#1271514).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3469=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3469=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3469=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3469=1
## Package List:
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* Server Applications Module 15-SP7 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* nginx-debuginfo-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* openSUSE Leap 15.6 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* nginx-source-1.21.5-150600.10.27.1
## References:
* https://www.suse.com/security/cve/CVE-2026-42533.html
* https://bugzilla.suse.com/show_bug.cgi?id71514
SUSE-SU-2026:3470-1: important: Security update for spice-vdagent
# Security update for spice-vdagent
Announcement ID: SUSE-SU-2026:3470-1
Release Date: 2026-08-03T16:42:20Z
Rating: important
References:
* bsc#1269553
* bsc#1269554
Cross-References:
* CVE-2026-57965
* CVE-2026-57966
CVSS scores:
* CVE-2026-57965 ( SUSE ): 5.2
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-57966 ( SUSE ): 6.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.3
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves two vulnerabilities can now be installed.
## Description:
This update for spice-vdagent fixes the following issues:
* CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer
overflow (bsc#1269553).
* CVE-2026-57966: improper sanitization allows a compromised SPICE host to
write arbitrary files to any location on the guest operating system
(bsc#1269554).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3470=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3470=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3470=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3470=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3470=1
## Package List:
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* spice-vdagent-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
## References:
* https://www.suse.com/security/cve/CVE-2026-57965.html
* https://www.suse.com/security/cve/CVE-2026-57966.html
* https://bugzilla.suse.com/show_bug.cgi?id69553
* https://bugzilla.suse.com/show_bug.cgi?id69554
SUSE-SU-2026:3474-1: moderate: Security update for s390-tools
# Security update for s390-tools
Announcement ID: SUSE-SU-2026:3474-1
Release Date: 2026-08-03T16:45:58Z
Rating: moderate
References:
* bsc#1270185
Cross-References:
* CVE-2026-41676
CVSS scores:
* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
An update that solves one vulnerability can now be installed.
## Description:
This update for s390-tools fixes the following issue
* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270185).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3474=1
## Package List:
* openSUSE Leap 15.4 (s390x)
* s390-tools-hmcdrvfs-debuginfo-2.31.0-150400.7.34.1
* s390-tools-zdsfs-debuginfo-2.31.0-150400.7.34.1
* libekmfweb1-devel-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-devel-2.31.0-150400.7.34.1
* s390-tools-chreipl-fcp-mpath-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* s390-tools-hmcdrvfs-2.31.0-150400.7.34.1
* osasnmpd-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* osasnmpd-debuginfo-2.31.0-150400.7.34.1
* s390-tools-zdsfs-2.31.0-150400.7.34.1
* openSUSE Leap 15.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* openSUSE Leap 15.4 (s390x x86_64)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://bugzilla.suse.com/show_bug.cgi?id70185
SUSE-SU-2026:3475-1: moderate: Security update for s390-tools
# Security update for s390-tools
Announcement ID: SUSE-SU-2026:3475-1
Release Date: 2026-08-03T16:46:06Z
Rating: moderate
References:
* bsc#1270185
Cross-References:
* CVE-2026-41676
CVSS scores:
* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5
An update that solves one vulnerability can now be installed.
## Description:
This update for s390-tools fixes the following issue
* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270185).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3475=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3475=1
## Package List:
* openSUSE Leap 15.5 (s390x)
* s390-tools-hmcdrvfs-debuginfo-2.31.0-150500.9.32.1
* libekmfweb1-debuginfo-2.31.0-150500.9.32.1
* osasnmpd-2.31.0-150500.9.32.1
* libkmipclient1-devel-2.31.0-150500.9.32.1
* s390-tools-hmcdrvfs-2.31.0-150500.9.32.1
* libkmipclient1-debuginfo-2.31.0-150500.9.32.1
* libekmfweb1-2.31.0-150500.9.32.1
* osasnmpd-debuginfo-2.31.0-150500.9.32.1
* s390-tools-chreipl-fcp-mpath-2.31.0-150500.9.32.1
* libekmfweb1-devel-2.31.0-150500.9.32.1
* libkmipclient1-2.31.0-150500.9.32.1
* s390-tools-zdsfs-debuginfo-2.31.0-150500.9.32.1
* s390-tools-zdsfs-2.31.0-150500.9.32.1
* openSUSE Leap 15.5 (s390x x86_64)
* s390-tools-debugsource-2.31.0-150500.9.32.1
* s390-tools-debuginfo-2.31.0-150500.9.32.1
* s390-tools-2.31.0-150500.9.32.1
* openSUSE Leap 15.5 (noarch)
* s390-tools-genprotimg-data-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (s390x x86_64)
* s390-tools-2.31.0-150500.9.32.1
* s390-tools-debuginfo-2.31.0-150500.9.32.1
* s390-tools-debugsource-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (s390x)
* libekmfweb1-2.31.0-150500.9.32.1
* libkmipclient1-2.31.0-150500.9.32.1
* libekmfweb1-debuginfo-2.31.0-150500.9.32.1
* libkmipclient1-debuginfo-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* s390-tools-genprotimg-data-2.31.0-150500.9.32.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://bugzilla.suse.com/show_bug.cgi?id70185
SUSE-SU-2026:3476-1: important: Security update for bind
# Security update for bind
Announcement ID: SUSE-SU-2026:3476-1
Release Date: 2026-08-03T16:58:19Z
Rating: important
References:
* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990
Cross-References:
* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321
CVSS scores:
* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves six vulnerabilities can now be installed.
## Description:
This update for bind fixes the following issues
* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3476=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3476=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3476=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3476=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3476=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* openSUSE Leap 15.4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990
SUSE-SU-2026:3477-1: important: Security update for bind
# Security update for bind
Announcement ID: SUSE-SU-2026:3477-1
Release Date: 2026-08-03T16:58:45Z
Rating: important
References:
* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990
Cross-References:
* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321
CVSS scores:
* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves six vulnerabilities can now be installed.
## Description:
This update for bind fixes the following issues
* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3477=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3477=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3477=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3477=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3477=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3477=1
## Package List:
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* openSUSE Leap 15.5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (x86_64)
* bind-debugsource-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990
openSUSE-SU-2026:0275-1: important: Security update for thrift
openSUSE Security Update: Security update for thrift
_______________________________
Announcement ID: openSUSE-SU-2026:0275-1
Rating: important
References: #1263321 #1263322 #1263365 #1263438 #1263492
#1263557 #1272609 #1272645 #1272647 #1272648
#1272649 #1272650 #1272651 #1272652 #1272653
#1272654 #1272655 #1272656 #1272657 #1272658
Cross-References: CVE-2026-41602 CVE-2026-41604 CVE-2026-41605
CVE-2026-41606 CVE-2026-41607 CVE-2026-41608
CVE-2026-41636 CVE-2026-43871 CVE-2026-45112
CVE-2026-48144 CVE-2026-48145 CVE-2026-48586
CVE-2026-49158 CVE-2026-55968 CVE-2026-55969
CVE-2026-55970 CVE-2026-55971 CVE-2026-58023
CVE-2026-58389 CVE-2026-58662
CVSS scores:
CVE-2026-41602 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-41604 (SUSE): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-41605 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVE-2026-41606 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-41607 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-41636 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes 20 vulnerabilities is now available.
Description:
This update for thrift fixes the following issues:
- update to 0.24.0 ( boo#1272609, CVE-2026-41608, boo#1272654,
CVE-2026-58023, boo#1272655, CVE-2026-55970, boo#1272656,
CVE-2026-49158, boo#1272657, CVE-2026-48586, boo#1272658,
CVE-2026-48145, boo#1272652, CVE-2026-58389, boo#1272653,
CVE-2026-55971, boo#1272645, CVE-2026-48144, boo#1272647,
CVE-2026-45112, boo#1272648, CVE-2026-43871, boo#1272649,
CVE-2026-55969, boo#1272650, CVE-2026-55968, boo#1272651,
CVE-2026-58662, boo#1272609, CVE-2026-41608):
* THRIFT-5930 - thrift_server_socket() copies Unix socket paths into
sockaddr_un.sun_path without bounds checking
* #3585 - limit recursion depth in c_glib thrift_protocol_skip
* #3507 - Add peer hostname validation to c_glib TLS client
* #3393 - Fix parent class resolution in c_glib generated dispatch_call
* THRIFT-3165 - Disable unsafe TLSv1.0 and TLSv1.1 by default
* THRIFT-6021 - When C++ client with HTTP transport calls a
oneway RPC method, it must not expect a response
* THRIFT-6060 - C++ THttpClient does not reopen socket after server
sends Connection: close
* THRIFT-6073 - Allow injecting external SSL_CTX into C++ SSLContext
* #3597 - link UnitTests against libthriftz to resolve THeaderTransport
vtable
* #3597 - fix off-by-ten header bounds check in readHeaderFormat
* #3569 - Add the cpp.ref (&) annotation to the recursive exception in
Recursive.thrift
* #3519 - Preserve private_optional field order
* #3498 - change sprintf to snprintf to eliminate security warnings on
OSX
* #3506 - Enforce RFC 6125 wildcard placement in TSSLSocket hostname
matching
* #3508 - Replace memory-safety asserts with unconditional throws in
TBufferTransports
* #3431 - Remove another boost header from the public API
* #3529 - nodejs+compiler: Add opt-in BigInt support for int64 via
js:bigint flag
* #3461 - Migration *.sln to *.slnx (except c++ libs)
* #2957 - Fix PHP cross-test server IPv4 binding
* #3372 - Fix JavaScript exception construction implementation (ES6)
* #3520 - added thrift-threat-model.md, SECURITY.md and security section
to AGENTS.md
* THRIFT-6030 - Harden Erlang protocol negative sizes
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* THRIFT-5214 - go: Implement connection check in TSocket
* THRIFT-5969 - Introduce gofmt for Go library
* THRIFT-5996 - go: connection check should work for TLS sockets
* THRIFT-6011 - Make compiled Go code formatting compatible with gofmt
* THRIFT-6012 - Fix inverted regexp.MatchString arguments and precompile
patterns in Go validator
* THRIFT-6044 - Limit struct read/write recursion depth in Go library
* THRIFT-6071 - Validate container size fits int32 range before
narrowing conversion in TSimpleJSONProtocol
* #3604 - Bound the container element count before the 64-bit size
precheck in the Go JSON protocol
* #3604 - widen container size precheck to 64-bit in go protocols
* #3599 - check wire-supplied size in simple json ReadMapBegin
* #3497 - Bump golang.org/x/sys to 0.0.0-20220412211240-33da011f77ad
* #3458 - Prevent concurrent calls to socketConn.Close() in Go
* #3428 - Fix range check on 32-bit architectures
* #3379 - Replace addr with factory in TServerSocket
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3381 - added int range checks
* #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
* #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
* #3605 - enforce stringLengthLimit in TCompactProtocol.readBinary
* #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
* #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in
/lib/kotlin
* #3452 - Add message byte tracking to consumeBuffer() in Java transports
* #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
* #3420 - Fix Java Spotless formatting
* #3415 - Connect skip() to TConfiguration recursion limit
* #3412 - Use bounded default for maxSkipDepth in TProtocolUtil
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3396 - Enable TLS hostname verification in TNonblockingSSLSocket
* #3390 - Enable TLS hostname verification in TSSLTransportFactory
* THRIFT-5915 - Python 3.12+ is not supported due to distutils
* THRIFT-5923 - UUID support for Python
* THRIFT-6024 - Python THeaderTransport and TZlibTransport default max
frame/decompressed size should be DEFAULT_MAX_FRAME_SIZE (16384000),
not HARD_MAX_FRAME_SIZE (0x3FFFFFFF)
* THRIFT-6043 - Harden Python binary protocol negative sizes
* THRIFT-6067 - Python: pip install fails on setuptools < 69 due to
sys.exit() in setup.py (PEP 517 build backend)
* THRIFT-6069 - suggestion for a few python perf improvements
* THRIFT-6070 - Publish Python wheel distributions to PyPI
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3413 - Use sslcompat hostname matcher in TSSLSocket
* #3411 - Add default recursion depth limit to TProtocol.skip()
* #3408 - Add decompressed payload size limit to Python THeaderTransport
* #3377 - Optimize Python C extension readStruct for nested structs
* #2957 - Fix PHP cross-test server IPv4 binding
- update to 0.23.0 (boo#1263557, CVE-2026-41602, boo#1263492,
CVE-2026-41604, boo#1263438, CVE-2026-41605, boo#1263365,
CVE-2026-41606, boo#1263321, CVE-2026-41607, boo#1263322,
CVE-2026-41636):
* THRIFT-5877 - Add cpp cross tests
* THRIFT-5866 - Dockerfile to support Ubuntu 24.04 LTS (Noble Numbat)
* THRIFT-5909 - add Ruby in GitHub workflow
* THRIFT-5649 - add go in GitHub workflow / action
* THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends
* THRIFT-5911 - Inconsistent UUID compilation for aliased types
* THRIFT-5912 - Assertion failed: `delta > 0`, file
ThreadManagerTests.h, line 162
* THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a
hostname of 127.0.0.1
* THRIFT-3268 - warning: token pasting of ',' and `__VA_ARGS__` is a GNU
extension
* THRIFT-5887 - build/cmake/ should be prepended (not appended) to
CMAKE_MODULE_PATH
* THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap
* THRIFT-5898 - Unable to build Thrift as a shared library on Windows
* THRIFT-5939 - Replace GUID generation with stable UUID algorithm
* THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support
* THRIFT-5896 - Race condition in TServerSocket.Addr() method
* THRIFT-5925 - UUID implementation in JAVA is not according to the
Thrift Specification
* THRIFT-5869 - Close the transport after TServerEventHandler
deleteContext
* THRIFT-5863 - Make TServerTransport able to customize the max message
size
* THRIFT-5774 - Add remote client's IP address to ServerContext in
TServerEventHandler
* THRIFT-4280 - Add async nonblocking ssl support in java client
* THRIFT-5879 - java and kotlin cross tests fail in the GitHub action
* THRIFT-5902 - Add net10 support
* THRIFT-5874 - Introduce new type `MESSAGE_SIZE_LIMIT` in
TTransportException
* THRIFT-5937 - nodejs episodic generation does not handle extending
services
* THRIFT-5924 - UUID support for nodejs and nodets
* THRIFT-4987 - TProtocolException: Bad version in readMessageBegin when
using XHR client with C++ server
* THRIFT-5924 - UUID support for nodejs and nodets
* THRIFT-5935 - Fix deprecated non-canonical casts for PHP 8.5
compatibility
* THRIFT-5921 - Ubuntu focal fail to run composer install
* THRIFT-5929 - Fix build failure on PHP 8.5 due to removed
zend_exception_get_default
* THRIFT-5927 - Cannot use reserved language keyword "None" with target
language Python
* THRIFT-5885 - TBinaryProtocolAccelerated incorrectly deserializes
IntEnum to None
* THRIFT-5923 - UUID support for Python
* THRIFT-5926 - TSaslClientTransport.open() crashes with DIGEST-MD5 due
to None initial response
* THRIFT-5915 - Python 3.12+ is not supported due to distutils
* THRIFT-5892 - PY_SSIZE_T_CLEAN error in some environments
* THRIFT-5873 - mTLS broken with python THttpClient
* THRIFT-792 - TSocket hides underlying exceptions when open() fails
* THRIFT-5888 - declare support for free-threaded CPython in extension
modules
* THRIFT-5900 - Thrift Cross Test broken in Github (Python 3.14)
* THRIFT-5308 - implement ruby seq replyÂ
* THRIFT-5910 - Add UUID support in Ruby
* THRIFT-5906 - Remove Fixnum references to support modern Ruby versions
* THRIFT-5905 - Add base64 and logger as explicit dependencies
* THRIFT-5903 - Fixnum is no longer supported since Ruby 3.2
* THRIFT-5687 - Ruby gems deprecation warning:
Gem::Specification#has_rdoc= is deprecated with no replacement
* THRIFT-4035 - Thrift ruby runtime does not send unique sequence IDs in
requests according to the unit tests
* THRIFT-1911 - IOError not being caught in socket.rb
* THRIFT-4526 - Implement rubocop for ruby in the sca build,
once clean into every make
* THRIFT-5273 - warning in ruby version >= 2.4
* THRIFT-5918 - Implement header protocol support for Ruby
* THRIFT-5559 - Processor can be implemented on handler trait itself
* THRIFT-5928 - skip() call on unknown binary field fails
deserialization instead of graceful skipping over field
* THRIFT-5739 - set_nodelay should be enabled for TTcpChannel
- Update to 0.22.0:
* ### Build Process
- THRIFT-5836 - 0.21.0 fails to build from sources at Arch Linux: No
rule to make target 'Thrift5272.thrift', needed by
'gen-cpp/Thrift5272_types.h'
- THRIFT-5860 - cmake 3.5 as a minimum version does not work with
cmake 4.0.0
* ### C glib
- THRIFT-5817 - [C++] Avoid copy of TUuid
* ### C++
- THRIFT-5637 - Thrift compiler should be able to output c++ Aggregate
types
- THRIFT-5667 - Make ThriftConfig.cmake relocatable
- THRIFT-5817 - [C++] Avoid copy of TUuid
- THRIFT-5821 - Cannot compile against aws-lc libcrypto (openssl
replacement from AWS)
- THRIFT-5841 - possible init/deinit conflict with manual
initialization flag
- THRIFT-5853 - Remove oldstyle casts from TBufferTransports and
TCompactProtocol
- THRIFT-5854 - TCompactProtocol readString checks maxMessageSize at
wrong position and off by one
- THRIFT-5868 - UUID Support for TCompactProtocol
- THRIFT-5865 - Fix TBinayProtocol with list
* ### Compiler (General)
- THRIFT-5823 - Fix illegal uses of exceptions as normal struct type
- THRIFT-5835 - Allow exceptions to be used as regular struct datatype
* # Delphi
- THRIFT-5822 - Remove deprecated AnsiString functions from the library
- THRIFT-5824 - Migrate, refactor and improve Delphi code generation
test script
- THRIFT-5825 - UUID constants lead to uncompileable Delphi code
- THRIFT-5826 - binary constants create uncompilable Delphi code
- THRIFT-5827 - enums in typedefs are not resolved in all cases
- THRIFT-5837 - Delphi implementation for THRIFT-5835
- THRIFT-5839 - incorrect cast under Win64
- THRIFT-5850 - Switch IThriftConfiguration interface from Cardinal to
Integer
- THRIFT-5851 - Promote known total stream sizes for seekable stream
transports properly
- THRIFT-5856 - Client should validate HTTP status
* ### Go
- THRIFT-5833 - go: Combine I/O and original error in compiler
generated Process functions
- THRIFT-5845 - The write error for union fields should be TException
- THRIFT-5859 - go: Generate a map for know values of an enum type
* ### Java
- THRIFT-5858 - Introduce new type MESSAGE_SIZE_LIMIT in
TTransportException
* ### netstd
- THRIFT-5832 - Drop net6 support and add net9 instead
- THRIFT-5838 - THttpTransport.FlushAsync does not include original
exception
- THRIFT-5852 - Promote known total stream sizes for seekable stream
transports
* ### Node.js
- THRIFT-5811 - Add ES module support to JS codegen
- THRIFT-5848 - Expose InputBufferUnderrunError in nodejs client
- THRIFT-5849 - Expose createClient in browser version of nodejs
package
* ### PHP
- THRIFT-1482 - Unix domain socket support under PHP
- THRIFT-5829 - PHP lib Use of "static" in callables is deprecated
notice
* ### Python
- THRIFT-5024 - tutorial\py.tornado\PythonServer.py failed under
Tornado6
- THRIFT-5847 - Python3.12 deprecation in THttpClient
- THRIFT-5857 - Remove deprecated Tornado io_loop usage
- THRIFT-5861 - Add isOpen method to TTornadoStreamTransport
* ### Swift
- THRIFT-4838 - add unix domain socket support to Swift
TSocketTransport implementation
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-275=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
libthrift-0_24_0-0.24.0-bp157.2.3.1
libthrift-devel-0.24.0-bp157.2.3.1
libthrift_c_glib0-0.24.0-bp157.2.3.1
libthriftnb-0_24_0-0.24.0-bp157.2.3.1
libthriftz-0_24_0-0.24.0-bp157.2.3.1
perl-thrift-0.24.0-bp157.2.3.1
python3-thrift-0.24.0-bp157.2.3.1
thrift-0.24.0-bp157.2.3.1
References:
https://www.suse.com/security/cve/CVE-2026-41602.html
https://www.suse.com/security/cve/CVE-2026-41604.html
https://www.suse.com/security/cve/CVE-2026-41605.html
https://www.suse.com/security/cve/CVE-2026-41606.html
https://www.suse.com/security/cve/CVE-2026-41607.html
https://www.suse.com/security/cve/CVE-2026-41608.html
https://www.suse.com/security/cve/CVE-2026-41636.html
https://www.suse.com/security/cve/CVE-2026-43871.html
https://www.suse.com/security/cve/CVE-2026-45112.html
https://www.suse.com/security/cve/CVE-2026-48144.html
https://www.suse.com/security/cve/CVE-2026-48145.html
https://www.suse.com/security/cve/CVE-2026-48586.html
https://www.suse.com/security/cve/CVE-2026-49158.html
https://www.suse.com/security/cve/CVE-2026-55968.html
https://www.suse.com/security/cve/CVE-2026-55969.html
https://www.suse.com/security/cve/CVE-2026-55970.html
https://www.suse.com/security/cve/CVE-2026-55971.html
https://www.suse.com/security/cve/CVE-2026-58023.html
https://www.suse.com/security/cve/CVE-2026-58389.html
https://www.suse.com/security/cve/CVE-2026-58662.html
https://bugzilla.suse.com/1263321
https://bugzilla.suse.com/1263322
https://bugzilla.suse.com/1263365
https://bugzilla.suse.com/1263438
https://bugzilla.suse.com/1263492
https://bugzilla.suse.com/1263557
https://bugzilla.suse.com/1272609
https://bugzilla.suse.com/1272645
https://bugzilla.suse.com/1272647
https://bugzilla.suse.com/1272648
https://bugzilla.suse.com/1272649
https://bugzilla.suse.com/1272650
https://bugzilla.suse.com/1272651
https://bugzilla.suse.com/1272652
https://bugzilla.suse.com/1272653
https://bugzilla.suse.com/1272654
https://bugzilla.suse.com/1272655
https://bugzilla.suse.com/1272656
https://bugzilla.suse.com/1272657
https://bugzilla.suse.com/1272658
openSUSE-SU-2026:0274-1: important: Security update for perl-HTTP-Tiny
openSUSE Security Update: Security update for perl-HTTP-Tiny
_______________________________
Announcement ID: openSUSE-SU-2026:0274-1
Rating: important
References: #1271020
Cross-References: CVE-2026-7017
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes one vulnerability is now available.
Description:
This update for perl-HTTP-Tiny fixes the following issues:
- updated to 0.096 see /usr/share/doc/packages/perl-HTTP-Tiny/Changes
0.096 2026-06-08 11:21:49+02:00 Europe/Brussels
- No changes from 0.095-TRIAL 0.095 2026-06-03 13:10:05+02:00
Europe/Brussels (TRIAL RELEASE) [!!! SECURITY !!!]
- CVE-2026-7017 boo#1271020
- Caller-supplied Authorization, Cookie, and Proxy-Authorization
headers are now stripped on cross-origin redirects by default. Use
allow_credentialed_redirects to opt out.
- Redirects are no longer automatically followed when going from
https to http. Use allow_downgrade to revert to the original behaviour.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-274=1
Package List:
- openSUSE Backports SLE-15-SP7 (noarch):
perl-HTTP-Tiny-0.096-bp157.2.6.1
References:
https://www.suse.com/security/cve/CVE-2026-7017.html
https://bugzilla.suse.com/1271020
openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck
openSUSE Security Update: Security update for perl-YAML-Syck
_______________________________
Announcement ID: openSUSE-SU-2026:0273-1
Rating: important
References: #1265155 #1271631 #1271632 #1271633 #1271634
Cross-References: CVE-2025-11683 CVE-2026-13713 CVE-2026-5089
CVE-2026-57075 CVE-2026-57076 CVE-2026-57077
CVSS scores:
CVE-2025-11683 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes 6 vulnerabilities is now available.
Description:
This update for perl-YAML-Syck fixes the following issues:
- updated to 1.470.0 (1.47) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026
[Security]
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags
(reported by Paul Johnson via CPANSec, PR #213):
- CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
boo#1271632
- CVE-2026-57076 (CWE-416): use-after-free of an anchor key string
shared between the node and the anchors table boo#1271633
- CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on to
CVE-2025-11683) boo#1271634
- CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of
an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte
input boo#1271631
- Harden syck_base64dec() to bounds-check each read so it cannot run
past a non-NUL-terminated input buffer (defense-in-depth for callers
passing raw buffers; PR #213) [Bug Fixes]
- Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from
deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now
default to 512, matching Dump (PR #204)
- Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf
values in Dump so they roundtrip with ImplicitTyping instead of
reloading as plain strings (PR #201) [Maintenance]
- CI: add an AddressSanitizer job that builds the XS with
-fsanitizeュdress and runs the suite plus the CVE trigger inputs to
catch libsyck memory-safety defects; de-pin the libasan version so it
tracks the runner's GCC (PR #213)
- updated to 1.460.0 (1.46) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug
Fixes]
- Fix: preserve string nature of numeric-looking values in Dump; pure
strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip
fidelity (GH #199, PR #200)
- Fix: accept trailing commas in flow sequences and mappings ([a, b,]
and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196)
[Maintenance]
- CI: upgrade install-with-cpm to v2 for compatibility with Perl
versions prior to 5.24 in perldocker containers (GH #197, PR #198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant
entries, exclude .claude/ from distribution
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-273=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
perl-YAML-Syck-1.470.0-bp157.2.6.1
References:
https://www.suse.com/security/cve/CVE-2025-11683.html
https://www.suse.com/security/cve/CVE-2026-13713.html
https://www.suse.com/security/cve/CVE-2026-5089.html
https://www.suse.com/security/cve/CVE-2026-57075.html
https://www.suse.com/security/cve/CVE-2026-57076.html
https://www.suse.com/security/cve/CVE-2026-57077.html
https://bugzilla.suse.com/1265155
https://bugzilla.suse.com/1271631
https://bugzilla.suse.com/1271632
https://bugzilla.suse.com/1271633
https://bugzilla.suse.com/1271634