SUSE 5729 Published by

SUSE released a batch of security advisories addressing vulnerabilities across more than thirty software packages distributed through their official repositories. The patches cover high-impact programs including OpenSSL versions one and three, nginx, bind, Python-ujson, ffmpeg, Node.js twenty-six, and several other critical system utilities. Severity ratings range from low to important, with the majority of updates flagged as either important or moderate due to potential privilege escalation, remote code execution risks, or data exposure flaws.

SUSE-SU-2026:3483-1: important: Security update for valkey
SUSE-SU-2026:3485-1: important: Security update for spice-vdagent
SUSE-SU-2026:3486-1: moderate: Security update for openssl-3
SUSE-SU-2026:3488-1: important: Security update for openssl-1_1
SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools
SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant
SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt
SUSE-SU-2026:3492-1: moderate: Security update for alsa
SUSE-SU-2026:3493-1: important: Security update for libpng16
openSUSE-SU-2026:21518-1: important: Security update for python-ujson
openSUSE-SU-2026:21516-1: important: Security update for python-sh
openSUSE-SU-2026:21522-1: important: Security update for ffmpeg-4
openSUSE-SU-2026:11436-1: moderate: golang-github-prometheus-prometheus-3.13.2-1.1 on GA media
openSUSE-SU-2026:11438-1: moderate: alloy-1.18.0-1.1 on GA media
openSUSE-SU-2026:11437-1: moderate: podman-6.0.2-1.1 on GA media
openSUSE-SU-2026:11434-1: moderate: chromedriver-151.0.7922.71-1.1 on GA media
openSUSE-SU-2026:11440-1: moderate: nodejs26-26.5.1-1.1 on GA media
openSUSE-SU-2026:11439-1: moderate: corepack24-24.18.1-1.1 on GA media
openSUSE-SU-2026:11441-1: moderate: xen-4.22.0_02-1.1 on GA media
SUSE-SU-2026:3468-1: important: Security update for rrdtool
SUSE-SU-2026:3469-1: important: Security update for nginx
SUSE-SU-2026:3470-1: important: Security update for spice-vdagent
SUSE-SU-2026:3474-1: moderate: Security update for s390-tools
SUSE-SU-2026:3475-1: moderate: Security update for s390-tools
SUSE-SU-2026:3476-1: important: Security update for bind
SUSE-SU-2026:3477-1: important: Security update for bind
openSUSE-SU-2026:0275-1: important: Security update for thrift
openSUSE-SU-2026:0274-1: important: Security update for perl-HTTP-Tiny
openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck




SUSE-SU-2026:3483-1: important: Security update for valkey


# Security update for valkey

Announcement ID: SUSE-SU-2026:3483-1
Release Date: 2026-08-04T11:46:57Z
Rating: important
References:

* bsc#1272442
* bsc#1272443

Cross-References:

* CVE-2026-56684
* CVE-2026-63639

CVSS scores:

* CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves two vulnerabilities can now be installed.

## Description:

This update for valkey fixes the following issues

* CVE-2026-56684: use-after-free in TLS connection handling (bsc#1272443).
* CVE-2026-63639: RCE via corrupt stream RDB files containing a shared NACK
across consumers (bsc#1272442).

Changes for valkey:

* Update to 8.0.10.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3483=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3483=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3483=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* valkey-debugsource-8.0.10-150600.13.28.1
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* valkey-debugsource-8.0.10-150600.13.28.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* valkey-devel-8.0.10-150600.13.28.1
* valkey-debuginfo-8.0.10-150600.13.28.1
* valkey-8.0.10-150600.13.28.1
* valkey-debugsource-8.0.10-150600.13.28.1
* openSUSE Leap 15.6 (noarch)
* valkey-compat-redis-8.0.10-150600.13.28.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56684.html
* https://www.suse.com/security/cve/CVE-2026-63639.html
* https://bugzilla.suse.com/show_bug.cgi?id72442
* https://bugzilla.suse.com/show_bug.cgi?id72443



SUSE-SU-2026:3485-1: important: Security update for spice-vdagent


# Security update for spice-vdagent

Announcement ID: SUSE-SU-2026:3485-1
Release Date: 2026-08-04T11:53:55Z
Rating: important
References:

* bsc#1269553
* bsc#1269554

Cross-References:

* CVE-2026-57965
* CVE-2026-57966

CVSS scores:

* CVE-2026-57965 ( SUSE ): 5.2
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-57966 ( SUSE ): 6.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* Desktop Applications Module 15-SP7
* openSUSE Leap 15.5
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves two vulnerabilities can now be installed.

## Description:

This update for spice-vdagent fixes the following issues:

* CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer
overflow (bsc#1269553).
* CVE-2026-57966: improper sanitization allows a compromised SPICE host to
write arbitrary files to any location on the guest operating system
(bsc#1269554).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3485=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3485=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3485=1

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3485=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3485=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3485=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3485=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3485=1

## Package List:

* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* spice-vdagent-debugsource-0.22.1-150500.4.3.1
* spice-vdagent-debuginfo-0.22.1-150500.4.3.1
* spice-vdagent-0.22.1-150500.4.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-57965.html
* https://www.suse.com/security/cve/CVE-2026-57966.html
* https://bugzilla.suse.com/show_bug.cgi?id69553
* https://bugzilla.suse.com/show_bug.cgi?id69554



SUSE-SU-2026:3486-1: moderate: Security update for openssl-3


# Security update for openssl-3

Announcement ID: SUSE-SU-2026:3486-1
Release Date: 2026-08-04T11:54:54Z
Rating: moderate
References:

* bsc#1271712

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that has one security fix can now be installed.

## Description:

This update for openssl-3 fixes the following issues:

* HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-
controlled memory allocations (bsc#1271712).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3486=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3486=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3486=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3486=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3486=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (noarch)
* openssl-3-doc-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libopenssl3-64bit-debuginfo-3.0.8-150400.4.93.1
* libopenssl3-64bit-3.0.8-150400.4.93.1
* libopenssl-3-devel-64bit-3.0.8-150400.4.93.1
* openSUSE Leap 15.4 (x86_64)
* libopenssl-3-devel-32bit-3.0.8-150400.4.93.1
* libopenssl3-32bit-3.0.8-150400.4.93.1
* libopenssl3-32bit-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libopenssl3-3.0.8-150400.4.93.1
* openssl-3-debugsource-3.0.8-150400.4.93.1
* openssl-3-3.0.8-150400.4.93.1
* openssl-3-debuginfo-3.0.8-150400.4.93.1
* libopenssl-3-devel-3.0.8-150400.4.93.1
* libopenssl3-debuginfo-3.0.8-150400.4.93.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id71712



SUSE-SU-2026:3488-1: important: Security update for openssl-1_1


# Security update for openssl-1_1

Announcement ID: SUSE-SU-2026:3488-1
Release Date: 2026-08-04T11:55:49Z
Rating: important
References:

* bsc#1271712

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that has one security fix can now be installed.

## Description:

This update for openssl-1_1 fixes the following issue

* HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-
controlled memory allocations (bsc#1271712).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3488=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3488=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3488=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3488=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3488=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3488=1

## Package List:

* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libopenssl1_1-64bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-64bit-1.1.1l-150500.17.60.1
* libopenssl1_1-64bit-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-64bit-1.1.1l-150500.17.60.1
* openSUSE Leap 15.5 (noarch)
* openssl-1_1-doc-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* openssl-1_1-debugsource-1.1.1l-150500.17.60.1
* openssl-1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1
* libopenssl-1_1-devel-1.1.1l-150500.17.60.1
* openssl-1_1-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-1.1.1l-150500.17.60.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* libopenssl1_1-32bit-1.1.1l-150500.17.60.1
* libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1
* libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id71712



SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools


# Security update for multipath-tools

Announcement ID: SUSE-SU-2026:3489-1
Release Date: 2026-08-04T11:57:10Z
Rating: moderate
References:

* bsc#1268144
* bsc#1268145

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5

An update that has two security fixes can now be installed.

## Description:

This update for multipath-tools fixes the following issues:

Update to version 0.9.4+134+suse.c82f347.

* kpartx: integer overflow in the GPT partition table size calculation can
lead to heap OOB read via crafted USB device or disk image (bsc#1268145).
* kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write
via a crafted DASD disk with more than 256 consecutive format labels
(bsc#1268144).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3489=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3489=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp0_2_0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp0_2_0-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-devel-0.9.4+134+suse.c82f347-150500.3.12.1
* libdmmp-devel-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-0.9.4+134+suse.c82f347-150500.3.12.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1
* multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1
* kpartx-0.9.4+134+suse.c82f347-150500.3.12.1

## References:

* https://bugzilla.suse.com/show_bug.cgi?id68144
* https://bugzilla.suse.com/show_bug.cgi?id68145



SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant


# Security update for wpa_supplicant

Announcement ID: SUSE-SU-2026:3490-1
Release Date: 2026-08-04T11:58:39Z
Rating: low
References:

* bsc#1239461

Cross-References:

* CVE-2025-24912

CVSS scores:

* CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability can now be installed.

## Description:

This update for wpa_supplicant fixes the following issues:

* CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user
in between the hostapd and the RADIUS server to inject crafted RADIUS
packets and force RADIUS authentications to fail (bsc#1239461).
* Missing network context validation for PMKSA caching
https://w1.fi/security/2026-2/
* Unexpected SAE commit message contents terminating `wpa_supplicant`
https://w1.fi/security/2026-3/

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3490=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3490=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* wpa_supplicant-debugsource-2.10-150500.3.6.1
* wpa_supplicant-gui-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-gui-2.10-150500.3.6.1
* wpa_supplicant-2.10-150500.3.6.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* wpa_supplicant-debuginfo-2.10-150500.3.6.1
* wpa_supplicant-debugsource-2.10-150500.3.6.1
* wpa_supplicant-2.10-150500.3.6.1

## References:

* https://www.suse.com/security/cve/CVE-2025-24912.html
* https://bugzilla.suse.com/show_bug.cgi?id39461



SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt


# Security update for libgcrypt

Announcement ID: SUSE-SU-2026:3491-1
Release Date: 2026-08-04T11:58:46Z
Rating: moderate
References:

* bsc#1262684

Cross-References:

* CVE-2026-41989

CVSS scores:

* CVE-2026-41989 ( SUSE ): 5.8
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability can now be installed.

## Description:

This update for libgcrypt fixes the following issue

* CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH
ciphertext can lead to a denial of service (bsc#1262684).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3491=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3491=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* libgcrypt-debugsource-1.9.4-150500.12.6.1
* libgcrypt20-1.9.4-150500.12.6.1
* libgcrypt-cavs-1.9.4-150500.12.6.1
* libgcrypt-devel-1.9.4-150500.12.6.1
* libgcrypt20-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-devel-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-cavs-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-hmac-1.9.4-150500.12.6.1
* openSUSE Leap 15.5 (x86_64)
* libgcrypt20-32bit-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-32bit-1.9.4-150500.12.6.1
* libgcrypt-devel-32bit-1.9.4-150500.12.6.1
* libgcrypt20-hmac-32bit-1.9.4-150500.12.6.1
* libgcrypt-devel-32bit-debuginfo-1.9.4-150500.12.6.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libgcrypt20-hmac-64bit-1.9.4-150500.12.6.1
* libgcrypt20-64bit-debuginfo-1.9.4-150500.12.6.1
* libgcrypt-devel-64bit-1.9.4-150500.12.6.1
* libgcrypt20-64bit-1.9.4-150500.12.6.1
* libgcrypt-devel-64bit-debuginfo-1.9.4-150500.12.6.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libgcrypt-debugsource-1.9.4-150500.12.6.1
* libgcrypt20-debuginfo-1.9.4-150500.12.6.1
* libgcrypt20-1.9.4-150500.12.6.1
* libgcrypt20-hmac-1.9.4-150500.12.6.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41989.html
* https://bugzilla.suse.com/show_bug.cgi?id62684



SUSE-SU-2026:3492-1: moderate: Security update for alsa


# Security update for alsa

Announcement ID: SUSE-SU-2026:3492-1
Release Date: 2026-08-04T11:58:57Z
Rating: moderate
References:

* bsc#1268853

Cross-References:

* CVE-2026-56109

CVSS scores:

* CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-56109 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability can now be installed.

## Description:

This update for alsa fixes the following issue

* CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that
can allow attackers to corrupt memory (bsc#1268853).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3492=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3492=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* alsa-debugsource-1.2.8-150500.3.3.1
* libasound2-1.2.8-150500.3.3.1
* libasound2-debuginfo-1.2.8-150500.3.3.1
* alsa-devel-1.2.8-150500.3.3.1
* alsa-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (x86_64)
* libatopology2-32bit-1.2.8-150500.3.3.1
* alsa-topology-devel-32bit-1.2.8-150500.3.3.1
* libasound2-32bit-1.2.8-150500.3.3.1
* libatopology2-32bit-debuginfo-1.2.8-150500.3.3.1
* libasound2-32bit-debuginfo-1.2.8-150500.3.3.1
* alsa-devel-32bit-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le x86_64)
* libatopology2-debuginfo-1.2.8-150500.3.3.1
* libatopology2-1.2.8-150500.3.3.1
* alsa-topology-devel-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* libasound2-64bit-debuginfo-1.2.8-150500.3.3.1
* libasound2-64bit-1.2.8-150500.3.3.1
* libatopology2-64bit-1.2.8-150500.3.3.1
* alsa-topology-devel-64bit-1.2.8-150500.3.3.1
* alsa-devel-64bit-1.2.8-150500.3.3.1
* libatopology2-64bit-debuginfo-1.2.8-150500.3.3.1
* openSUSE Leap 15.5 (noarch)
* alsa-docs-1.2.8-150500.3.3.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libasound2-1.2.8-150500.3.3.1
* alsa-debugsource-1.2.8-150500.3.3.1
* libasound2-debuginfo-1.2.8-150500.3.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56109.html
* https://bugzilla.suse.com/show_bug.cgi?id68853



SUSE-SU-2026:3493-1: important: Security update for libpng16


# Security update for libpng16

Announcement ID: SUSE-SU-2026:3493-1
Release Date: 2026-08-04T12:11:14Z
Rating: important
References:

* jsc#PED-16190

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that contains one feature can now be installed.

## Description:

This update for libpng16 fixes the following issues:

Changes for libpng16:

* version update to 1.6.58 (jsc#PED-16190).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3493=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3493=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3493=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3493=1

## Package List:

* SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-compat-devel-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1
* libpng16-devel-32bit-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-tools-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-tools-debuginfo-1.6.58-150600.3.23.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libpng16-devel-64bit-1.6.58-150600.3.23.1
* libpng16-16-64bit-debuginfo-1.6.58-150600.3.23.1
* libpng16-compat-devel-64bit-1.6.58-150600.3.23.1
* libpng16-16-64bit-1.6.58-150600.3.23.1
* Basesystem Module 15-SP7 (ppc64le s390x x86_64)
* libpng16-16-1.6.58-150600.3.23.1
* libpng16-16-debuginfo-1.6.58-150600.3.23.1
* libpng16-debugsource-1.6.58-150600.3.23.1
* libpng16-devel-1.6.58-150600.3.23.1
* libpng16-compat-devel-1.6.58-150600.3.23.1
* Basesystem Module 15-SP7 (x86_64)
* libpng16-16-32bit-1.6.58-150600.3.23.1
* libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1

## References:

* https://jira.suse.com/browse/PED-16190



openSUSE-SU-2026:21518-1: important: Security update for python-ujson


openSUSE security update: security update for python-ujson
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21518-1
Rating: important
References:

* bsc#1270301

Cross-References:

* CVE-2026-44660

CVSS scores:

* CVE-2026-44660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-44660 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for python-ujson fixes the following issue:

- CVE-2026-44660: failing to decrement a serialized JSON object during a write exception in ujson.dump() can lead to
memory leaks (bsc#1270301).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1423=1

Package List:

- openSUSE Leap 16.0:

python313-ujson-5.10.0-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-44660.html



openSUSE-SU-2026:21516-1: important: Security update for python-sh


openSUSE security update: security update for python-sh
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21516-1
Rating: important
References:

* bsc#1272424

Cross-References:

* CVE-2026-54552

CVSS scores:

* CVE-2026-54552 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for python-sh fixes the following issue

- CVE-2026-54552: `_uid` option performs an incomplete privilege drop on Linux/Unix-like systems and allows
for privilege escalation (bsc#1272424).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1421=1

Package List:

- openSUSE Leap 16.0:

python313-sh-2.2.2-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-54552.html



openSUSE-SU-2026:21522-1: important: Security update for ffmpeg-4


openSUSE security update: security update for ffmpeg-4
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21522-1
Rating: important
References:

* bsc#1272752
* bsc#1272754
* bsc#1272758
* bsc#1272765
* bsc#1272768

Cross-References:

* CVE-2026-64830
* CVE-2026-64832
* CVE-2026-64835
* CVE-2026-66038
* CVE-2026-66039

CVSS scores:

* CVE-2026-64830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64830 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64832 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64832 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64835 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64835 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-66038 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-66039 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-66039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

Description:

This update for ffmpeg-4 fixes the following issues:

Changes in ffmpeg-4:

- CVE-2026-64835: Out-of-Bounds Memory Access in ADX Audio Decoder (bsc#1272758)
- CVE-2026-64832: Double-Free in NVDEC Hardware Decoder via nvdec.c (bsc#1272754)
- CVE-2026-64830: Heap Buffer Overflow via VobSub Subtitle Demuxer (bsc#1272752)
- CVE-2026-66038: LCL/ZLIB Video Decoder Information Disclosure via lcldec.c (bsc#1272768)
- CVE-2026-66039: MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File (bsc#1272765)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-464=1

Package List:

- openSUSE Leap 16.0:

ffmpeg-4-4.4.7-bp160.3.1
ffmpeg-4-libavcodec-devel-4.4.7-bp160.3.1
ffmpeg-4-libavdevice-devel-4.4.7-bp160.3.1
ffmpeg-4-libavfilter-devel-4.4.7-bp160.3.1
ffmpeg-4-libavformat-devel-4.4.7-bp160.3.1
ffmpeg-4-libavresample-devel-4.4.7-bp160.3.1
ffmpeg-4-libavutil-devel-4.4.7-bp160.3.1
ffmpeg-4-libpostproc-devel-4.4.7-bp160.3.1
ffmpeg-4-libswresample-devel-4.4.7-bp160.3.1
ffmpeg-4-libswscale-devel-4.4.7-bp160.3.1
ffmpeg-4-private-devel-4.4.7-bp160.3.1
libavcodec58_134-4.4.7-bp160.3.1
libavdevice58_13-4.4.7-bp160.3.1
libavfilter7_110-4.4.7-bp160.3.1
libavformat58_76-4.4.7-bp160.3.1
libavresample4_0-4.4.7-bp160.3.1
libavutil56_70-4.4.7-bp160.3.1
libpostproc55_9-4.4.7-bp160.3.1
libswresample3_9-4.4.7-bp160.3.1
libswscale5_9-4.4.7-bp160.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-64830.html
* https://www.suse.com/security/cve/CVE-2026-64832.html
* https://www.suse.com/security/cve/CVE-2026-64835.html
* https://www.suse.com/security/cve/CVE-2026-66038.html
* https://www.suse.com/security/cve/CVE-2026-66039.html



openSUSE-SU-2026:11436-1: moderate: golang-github-prometheus-prometheus-3.13.2-1.1 on GA media


# golang-github-prometheus-prometheus-3.13.2-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11436-1
Rating: moderate

Cross-References:

* CVE-2023-45289
* CVE-2025-4673
* CVE-2026-44990
* CVE-2026-56852

CVSS scores:

* CVE-2023-45289 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2025-4673 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the golang-github-prometheus-prometheus-3.13.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* golang-github-prometheus-prometheus 3.13.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2023-45289.html
* https://www.suse.com/security/cve/CVE-2025-4673.html
* https://www.suse.com/security/cve/CVE-2026-44990.html
* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:11438-1: moderate: alloy-1.18.0-1.1 on GA media


# alloy-1.18.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11438-1
Rating: moderate

Cross-References:

* CVE-2026-1229
* CVE-2026-33814
* CVE-2026-41506
* CVE-2026-41606
* CVE-2026-41607

CVSS scores:

* CVE-2026-1229 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
* CVE-2026-1229 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 5 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the alloy-1.18.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* alloy 1.18.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-1229.html
* https://www.suse.com/security/cve/CVE-2026-33814.html
* https://www.suse.com/security/cve/CVE-2026-41506.html
* https://www.suse.com/security/cve/CVE-2026-41606.html
* https://www.suse.com/security/cve/CVE-2026-41607.html



openSUSE-SU-2026:11437-1: moderate: podman-6.0.2-1.1 on GA media


# podman-6.0.2-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11437-1
Rating: moderate

Cross-References:

* CVE-2026-57231

CVSS scores:

* CVE-2026-57231 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57231 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the podman-6.0.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* podman 6.0.2-1.1
* podman-docker 6.0.2-1.1
* podman-remote 6.0.2-1.1
* podmansh 6.0.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-57231.html



openSUSE-SU-2026:11434-1: moderate: chromedriver-151.0.7922.71-1.1 on GA media


# chromedriver-151.0.7922.71-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11434-1
Rating: moderate

Cross-References:

* CVE-2026-17650
* CVE-2026-17651
* CVE-2026-17652
* CVE-2026-17653
* CVE-2026-17654
* CVE-2026-17655
* CVE-2026-17656
* CVE-2026-17657
* CVE-2026-17658
* CVE-2026-17659
* CVE-2026-17660
* CVE-2026-17661
* CVE-2026-17662
* CVE-2026-17663
* CVE-2026-17664
* CVE-2026-17665
* CVE-2026-17666
* CVE-2026-17667
* CVE-2026-17668
* CVE-2026-17669
* CVE-2026-17670
* CVE-2026-17671
* CVE-2026-17672
* CVE-2026-17673
* CVE-2026-17674
* CVE-2026-17675
* CVE-2026-17676
* CVE-2026-17677
* CVE-2026-17678
* CVE-2026-17679
* CVE-2026-17680
* CVE-2026-17681
* CVE-2026-17682
* CVE-2026-17683
* CVE-2026-17684
* CVE-2026-17685
* CVE-2026-17686
* CVE-2026-17687
* CVE-2026-17688
* CVE-2026-17689
* CVE-2026-17690
* CVE-2026-17691
* CVE-2026-17692
* CVE-2026-17693
* CVE-2026-17694
* CVE-2026-17695
* CVE-2026-17696
* CVE-2026-17697
* CVE-2026-17698
* CVE-2026-17699
* CVE-2026-17700
* CVE-2026-17701
* CVE-2026-17702
* CVE-2026-17703
* CVE-2026-17704
* CVE-2026-17705
* CVE-2026-17706
* CVE-2026-17707
* CVE-2026-17708
* CVE-2026-17709
* CVE-2026-17710
* CVE-2026-17711
* CVE-2026-17712
* CVE-2026-17713
* CVE-2026-17714
* CVE-2026-17715
* CVE-2026-17716
* CVE-2026-17717
* CVE-2026-17718
* CVE-2026-17719
* CVE-2026-17720
* CVE-2026-17721
* CVE-2026-17722
* CVE-2026-17723
* CVE-2026-17724
* CVE-2026-17725
* CVE-2026-17726
* CVE-2026-17727
* CVE-2026-17728
* CVE-2026-17729
* CVE-2026-17730
* CVE-2026-17731
* CVE-2026-17732
* CVE-2026-17733
* CVE-2026-17734
* CVE-2026-17735
* CVE-2026-17736
* CVE-2026-17737
* CVE-2026-17738
* CVE-2026-17739
* CVE-2026-17740
* CVE-2026-17741
* CVE-2026-17742
* CVE-2026-17743
* CVE-2026-17744
* CVE-2026-17745
* CVE-2026-17746
* CVE-2026-17747
* CVE-2026-17748
* CVE-2026-17749
* CVE-2026-17750
* CVE-2026-17751
* CVE-2026-17752
* CVE-2026-17753
* CVE-2026-17754
* CVE-2026-17755
* CVE-2026-17756
* CVE-2026-17757
* CVE-2026-17758
* CVE-2026-17759
* CVE-2026-17760
* CVE-2026-17761
* CVE-2026-17762
* CVE-2026-17763
* CVE-2026-17764
* CVE-2026-17765
* CVE-2026-17766
* CVE-2026-17767
* CVE-2026-17768
* CVE-2026-17769
* CVE-2026-17770
* CVE-2026-17771
* CVE-2026-17772
* CVE-2026-17773
* CVE-2026-17774
* CVE-2026-17775
* CVE-2026-17776
* CVE-2026-17777
* CVE-2026-17778
* CVE-2026-17779
* CVE-2026-17780
* CVE-2026-17781
* CVE-2026-17782
* CVE-2026-17783
* CVE-2026-17784
* CVE-2026-17785
* CVE-2026-17786
* CVE-2026-17787
* CVE-2026-17788
* CVE-2026-17789
* CVE-2026-17790
* CVE-2026-17791
* CVE-2026-17792
* CVE-2026-17793
* CVE-2026-17794
* CVE-2026-17795
* CVE-2026-17796
* CVE-2026-17797
* CVE-2026-17798
* CVE-2026-17799
* CVE-2026-17800
* CVE-2026-17801
* CVE-2026-17802
* CVE-2026-17803
* CVE-2026-17804
* CVE-2026-17805
* CVE-2026-17806
* CVE-2026-17807
* CVE-2026-17808
* CVE-2026-17809
* CVE-2026-17810
* CVE-2026-17811
* CVE-2026-17812
* CVE-2026-17813
* CVE-2026-17814
* CVE-2026-17815
* CVE-2026-17816
* CVE-2026-17817
* CVE-2026-17818
* CVE-2026-17819
* CVE-2026-17820
* CVE-2026-17821
* CVE-2026-17822
* CVE-2026-17823
* CVE-2026-17824
* CVE-2026-17825
* CVE-2026-17826
* CVE-2026-17827
* CVE-2026-17828
* CVE-2026-17829
* CVE-2026-17830
* CVE-2026-17831
* CVE-2026-17832
* CVE-2026-17833
* CVE-2026-17834
* CVE-2026-17835
* CVE-2026-17836
* CVE-2026-17837
* CVE-2026-17838
* CVE-2026-17839
* CVE-2026-17840
* CVE-2026-17841
* CVE-2026-17842
* CVE-2026-17843
* CVE-2026-17844
* CVE-2026-17845
* CVE-2026-17846
* CVE-2026-17847
* CVE-2026-17848
* CVE-2026-17849
* CVE-2026-17850
* CVE-2026-17851
* CVE-2026-17852
* CVE-2026-17853
* CVE-2026-17854
* CVE-2026-17855
* CVE-2026-17856
* CVE-2026-17857
* CVE-2026-17858
* CVE-2026-17859
* CVE-2026-17860
* CVE-2026-17861
* CVE-2026-17862
* CVE-2026-17863
* CVE-2026-17864
* CVE-2026-17865
* CVE-2026-17866
* CVE-2026-17867
* CVE-2026-17868
* CVE-2026-17869
* CVE-2026-17870
* CVE-2026-17871
* CVE-2026-17872
* CVE-2026-17873
* CVE-2026-17874
* CVE-2026-17875
* CVE-2026-17876
* CVE-2026-17877
* CVE-2026-17878
* CVE-2026-17879
* CVE-2026-17880
* CVE-2026-17881
* CVE-2026-17882
* CVE-2026-17883
* CVE-2026-17884
* CVE-2026-17885
* CVE-2026-17886
* CVE-2026-17887
* CVE-2026-17888
* CVE-2026-17889
* CVE-2026-17890
* CVE-2026-17891
* CVE-2026-17892
* CVE-2026-17893
* CVE-2026-17894
* CVE-2026-17895
* CVE-2026-17896
* CVE-2026-17897
* CVE-2026-17898
* CVE-2026-17899
* CVE-2026-17900
* CVE-2026-17901
* CVE-2026-17902
* CVE-2026-17903
* CVE-2026-17904
* CVE-2026-17905
* CVE-2026-17906
* CVE-2026-17907
* CVE-2026-17908
* CVE-2026-17909
* CVE-2026-17910
* CVE-2026-17911
* CVE-2026-17912
* CVE-2026-17913
* CVE-2026-17914
* CVE-2026-17915
* CVE-2026-17916
* CVE-2026-17917
* CVE-2026-17918
* CVE-2026-17919
* CVE-2026-17920
* CVE-2026-17921
* CVE-2026-17922
* CVE-2026-17923
* CVE-2026-17924
* CVE-2026-17925
* CVE-2026-17926
* CVE-2026-17927
* CVE-2026-17928
* CVE-2026-17929
* CVE-2026-17930
* CVE-2026-17931
* CVE-2026-17932
* CVE-2026-17933
* CVE-2026-17934
* CVE-2026-17935
* CVE-2026-17936
* CVE-2026-17937
* CVE-2026-17938
* CVE-2026-17939
* CVE-2026-17940
* CVE-2026-17941
* CVE-2026-17942
* CVE-2026-17943
* CVE-2026-17944
* CVE-2026-17945
* CVE-2026-17946
* CVE-2026-17947
* CVE-2026-17948
* CVE-2026-17949
* CVE-2026-17950
* CVE-2026-17951
* CVE-2026-17952
* CVE-2026-17953
* CVE-2026-17954
* CVE-2026-17955
* CVE-2026-17956
* CVE-2026-17957
* CVE-2026-17958
* CVE-2026-17959
* CVE-2026-17960
* CVE-2026-17961
* CVE-2026-17962
* CVE-2026-17963
* CVE-2026-17964
* CVE-2026-17965
* CVE-2026-17966
* CVE-2026-17967
* CVE-2026-17968
* CVE-2026-17969
* CVE-2026-17970
* CVE-2026-17971
* CVE-2026-17972
* CVE-2026-17973
* CVE-2026-17974
* CVE-2026-17975
* CVE-2026-17976
* CVE-2026-17977
* CVE-2026-17978
* CVE-2026-17979
* CVE-2026-17980
* CVE-2026-17981
* CVE-2026-17982
* CVE-2026-17983
* CVE-2026-17984
* CVE-2026-17985
* CVE-2026-17986
* CVE-2026-17987
* CVE-2026-17988
* CVE-2026-17989
* CVE-2026-17990
* CVE-2026-17991
* CVE-2026-17992
* CVE-2026-17993
* CVE-2026-17994
* CVE-2026-17995
* CVE-2026-17996
* CVE-2026-17997
* CVE-2026-17998
* CVE-2026-17999
* CVE-2026-18000
* CVE-2026-18001
* CVE-2026-18002
* CVE-2026-18003
* CVE-2026-18004
* CVE-2026-18005
* CVE-2026-18006
* CVE-2026-18007
* CVE-2026-18008
* CVE-2026-18009
* CVE-2026-18010
* CVE-2026-18011
* CVE-2026-18012
* CVE-2026-18013
* CVE-2026-18014
* CVE-2026-18015
* CVE-2026-18016
* CVE-2026-18017
* CVE-2026-18018
* CVE-2026-18019

Affected Products:

* openSUSE Tumbleweed

An update that solves 370 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the chromedriver-151.0.7922.71-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* chromedriver 151.0.7922.71-1.1
* chromium 151.0.7922.71-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-17650.html
* https://www.suse.com/security/cve/CVE-2026-17651.html
* https://www.suse.com/security/cve/CVE-2026-17652.html
* https://www.suse.com/security/cve/CVE-2026-17653.html
* https://www.suse.com/security/cve/CVE-2026-17654.html
* https://www.suse.com/security/cve/CVE-2026-17655.html
* https://www.suse.com/security/cve/CVE-2026-17656.html
* https://www.suse.com/security/cve/CVE-2026-17657.html
* https://www.suse.com/security/cve/CVE-2026-17658.html
* https://www.suse.com/security/cve/CVE-2026-17659.html
* https://www.suse.com/security/cve/CVE-2026-17660.html
* https://www.suse.com/security/cve/CVE-2026-17661.html
* https://www.suse.com/security/cve/CVE-2026-17662.html
* https://www.suse.com/security/cve/CVE-2026-17663.html
* https://www.suse.com/security/cve/CVE-2026-17664.html
* https://www.suse.com/security/cve/CVE-2026-17665.html
* https://www.suse.com/security/cve/CVE-2026-17666.html
* https://www.suse.com/security/cve/CVE-2026-17667.html
* https://www.suse.com/security/cve/CVE-2026-17668.html
* https://www.suse.com/security/cve/CVE-2026-17669.html
* https://www.suse.com/security/cve/CVE-2026-17670.html
* https://www.suse.com/security/cve/CVE-2026-17671.html
* https://www.suse.com/security/cve/CVE-2026-17672.html
* https://www.suse.com/security/cve/CVE-2026-17673.html
* https://www.suse.com/security/cve/CVE-2026-17674.html
* https://www.suse.com/security/cve/CVE-2026-17675.html
* https://www.suse.com/security/cve/CVE-2026-17676.html
* https://www.suse.com/security/cve/CVE-2026-17677.html
* https://www.suse.com/security/cve/CVE-2026-17678.html
* https://www.suse.com/security/cve/CVE-2026-17679.html
* https://www.suse.com/security/cve/CVE-2026-17680.html
* https://www.suse.com/security/cve/CVE-2026-17681.html
* https://www.suse.com/security/cve/CVE-2026-17682.html
* https://www.suse.com/security/cve/CVE-2026-17683.html
* https://www.suse.com/security/cve/CVE-2026-17684.html
* https://www.suse.com/security/cve/CVE-2026-17685.html
* https://www.suse.com/security/cve/CVE-2026-17686.html
* https://www.suse.com/security/cve/CVE-2026-17687.html
* https://www.suse.com/security/cve/CVE-2026-17688.html
* https://www.suse.com/security/cve/CVE-2026-17689.html
* https://www.suse.com/security/cve/CVE-2026-17690.html
* https://www.suse.com/security/cve/CVE-2026-17691.html
* https://www.suse.com/security/cve/CVE-2026-17692.html
* https://www.suse.com/security/cve/CVE-2026-17693.html
* https://www.suse.com/security/cve/CVE-2026-17694.html
* https://www.suse.com/security/cve/CVE-2026-17695.html
* https://www.suse.com/security/cve/CVE-2026-17696.html
* https://www.suse.com/security/cve/CVE-2026-17697.html
* https://www.suse.com/security/cve/CVE-2026-17698.html
* https://www.suse.com/security/cve/CVE-2026-17699.html
* https://www.suse.com/security/cve/CVE-2026-17700.html
* https://www.suse.com/security/cve/CVE-2026-17701.html
* https://www.suse.com/security/cve/CVE-2026-17702.html
* https://www.suse.com/security/cve/CVE-2026-17703.html
* https://www.suse.com/security/cve/CVE-2026-17704.html
* https://www.suse.com/security/cve/CVE-2026-17705.html
* https://www.suse.com/security/cve/CVE-2026-17706.html
* https://www.suse.com/security/cve/CVE-2026-17707.html
* https://www.suse.com/security/cve/CVE-2026-17708.html
* https://www.suse.com/security/cve/CVE-2026-17709.html
* https://www.suse.com/security/cve/CVE-2026-17710.html
* https://www.suse.com/security/cve/CVE-2026-17711.html
* https://www.suse.com/security/cve/CVE-2026-17712.html
* https://www.suse.com/security/cve/CVE-2026-17713.html
* https://www.suse.com/security/cve/CVE-2026-17714.html
* https://www.suse.com/security/cve/CVE-2026-17715.html
* https://www.suse.com/security/cve/CVE-2026-17716.html
* https://www.suse.com/security/cve/CVE-2026-17717.html
* https://www.suse.com/security/cve/CVE-2026-17718.html
* https://www.suse.com/security/cve/CVE-2026-17719.html
* https://www.suse.com/security/cve/CVE-2026-17720.html
* https://www.suse.com/security/cve/CVE-2026-17721.html
* https://www.suse.com/security/cve/CVE-2026-17722.html
* https://www.suse.com/security/cve/CVE-2026-17723.html
* https://www.suse.com/security/cve/CVE-2026-17724.html
* https://www.suse.com/security/cve/CVE-2026-17725.html
* https://www.suse.com/security/cve/CVE-2026-17726.html
* https://www.suse.com/security/cve/CVE-2026-17727.html
* https://www.suse.com/security/cve/CVE-2026-17728.html
* https://www.suse.com/security/cve/CVE-2026-17729.html
* https://www.suse.com/security/cve/CVE-2026-17730.html
* https://www.suse.com/security/cve/CVE-2026-17731.html
* https://www.suse.com/security/cve/CVE-2026-17732.html
* https://www.suse.com/security/cve/CVE-2026-17733.html
* https://www.suse.com/security/cve/CVE-2026-17734.html
* https://www.suse.com/security/cve/CVE-2026-17735.html
* https://www.suse.com/security/cve/CVE-2026-17736.html
* https://www.suse.com/security/cve/CVE-2026-17737.html
* https://www.suse.com/security/cve/CVE-2026-17738.html
* https://www.suse.com/security/cve/CVE-2026-17739.html
* https://www.suse.com/security/cve/CVE-2026-17740.html
* https://www.suse.com/security/cve/CVE-2026-17741.html
* https://www.suse.com/security/cve/CVE-2026-17742.html
* https://www.suse.com/security/cve/CVE-2026-17743.html
* https://www.suse.com/security/cve/CVE-2026-17744.html
* https://www.suse.com/security/cve/CVE-2026-17745.html
* https://www.suse.com/security/cve/CVE-2026-17746.html
* https://www.suse.com/security/cve/CVE-2026-17747.html
* https://www.suse.com/security/cve/CVE-2026-17748.html
* https://www.suse.com/security/cve/CVE-2026-17749.html
* https://www.suse.com/security/cve/CVE-2026-17750.html
* https://www.suse.com/security/cve/CVE-2026-17751.html
* https://www.suse.com/security/cve/CVE-2026-17752.html
* https://www.suse.com/security/cve/CVE-2026-17753.html
* https://www.suse.com/security/cve/CVE-2026-17754.html
* https://www.suse.com/security/cve/CVE-2026-17755.html
* https://www.suse.com/security/cve/CVE-2026-17756.html
* https://www.suse.com/security/cve/CVE-2026-17757.html
* https://www.suse.com/security/cve/CVE-2026-17758.html
* https://www.suse.com/security/cve/CVE-2026-17759.html
* https://www.suse.com/security/cve/CVE-2026-17760.html
* https://www.suse.com/security/cve/CVE-2026-17761.html
* https://www.suse.com/security/cve/CVE-2026-17762.html
* https://www.suse.com/security/cve/CVE-2026-17763.html
* https://www.suse.com/security/cve/CVE-2026-17764.html
* https://www.suse.com/security/cve/CVE-2026-17765.html
* https://www.suse.com/security/cve/CVE-2026-17766.html
* https://www.suse.com/security/cve/CVE-2026-17767.html
* https://www.suse.com/security/cve/CVE-2026-17768.html
* https://www.suse.com/security/cve/CVE-2026-17769.html
* https://www.suse.com/security/cve/CVE-2026-17770.html
* https://www.suse.com/security/cve/CVE-2026-17771.html
* https://www.suse.com/security/cve/CVE-2026-17772.html
* https://www.suse.com/security/cve/CVE-2026-17773.html
* https://www.suse.com/security/cve/CVE-2026-17774.html
* https://www.suse.com/security/cve/CVE-2026-17775.html
* https://www.suse.com/security/cve/CVE-2026-17776.html
* https://www.suse.com/security/cve/CVE-2026-17777.html
* https://www.suse.com/security/cve/CVE-2026-17778.html
* https://www.suse.com/security/cve/CVE-2026-17779.html
* https://www.suse.com/security/cve/CVE-2026-17780.html
* https://www.suse.com/security/cve/CVE-2026-17781.html
* https://www.suse.com/security/cve/CVE-2026-17782.html
* https://www.suse.com/security/cve/CVE-2026-17783.html
* https://www.suse.com/security/cve/CVE-2026-17784.html
* https://www.suse.com/security/cve/CVE-2026-17785.html
* https://www.suse.com/security/cve/CVE-2026-17786.html
* https://www.suse.com/security/cve/CVE-2026-17787.html
* https://www.suse.com/security/cve/CVE-2026-17788.html
* https://www.suse.com/security/cve/CVE-2026-17789.html
* https://www.suse.com/security/cve/CVE-2026-17790.html
* https://www.suse.com/security/cve/CVE-2026-17791.html
* https://www.suse.com/security/cve/CVE-2026-17792.html
* https://www.suse.com/security/cve/CVE-2026-17793.html
* https://www.suse.com/security/cve/CVE-2026-17794.html
* https://www.suse.com/security/cve/CVE-2026-17795.html
* https://www.suse.com/security/cve/CVE-2026-17796.html
* https://www.suse.com/security/cve/CVE-2026-17797.html
* https://www.suse.com/security/cve/CVE-2026-17798.html
* https://www.suse.com/security/cve/CVE-2026-17799.html
* https://www.suse.com/security/cve/CVE-2026-17800.html
* https://www.suse.com/security/cve/CVE-2026-17801.html
* https://www.suse.com/security/cve/CVE-2026-17802.html
* https://www.suse.com/security/cve/CVE-2026-17803.html
* https://www.suse.com/security/cve/CVE-2026-17804.html
* https://www.suse.com/security/cve/CVE-2026-17805.html
* https://www.suse.com/security/cve/CVE-2026-17806.html
* https://www.suse.com/security/cve/CVE-2026-17807.html
* https://www.suse.com/security/cve/CVE-2026-17808.html
* https://www.suse.com/security/cve/CVE-2026-17809.html
* https://www.suse.com/security/cve/CVE-2026-17810.html
* https://www.suse.com/security/cve/CVE-2026-17811.html
* https://www.suse.com/security/cve/CVE-2026-17812.html
* https://www.suse.com/security/cve/CVE-2026-17813.html
* https://www.suse.com/security/cve/CVE-2026-17814.html
* https://www.suse.com/security/cve/CVE-2026-17815.html
* https://www.suse.com/security/cve/CVE-2026-17816.html
* https://www.suse.com/security/cve/CVE-2026-17817.html
* https://www.suse.com/security/cve/CVE-2026-17818.html
* https://www.suse.com/security/cve/CVE-2026-17819.html
* https://www.suse.com/security/cve/CVE-2026-17820.html
* https://www.suse.com/security/cve/CVE-2026-17821.html
* https://www.suse.com/security/cve/CVE-2026-17822.html
* https://www.suse.com/security/cve/CVE-2026-17823.html
* https://www.suse.com/security/cve/CVE-2026-17824.html
* https://www.suse.com/security/cve/CVE-2026-17825.html
* https://www.suse.com/security/cve/CVE-2026-17826.html
* https://www.suse.com/security/cve/CVE-2026-17827.html
* https://www.suse.com/security/cve/CVE-2026-17828.html
* https://www.suse.com/security/cve/CVE-2026-17829.html
* https://www.suse.com/security/cve/CVE-2026-17830.html
* https://www.suse.com/security/cve/CVE-2026-17831.html
* https://www.suse.com/security/cve/CVE-2026-17832.html
* https://www.suse.com/security/cve/CVE-2026-17833.html
* https://www.suse.com/security/cve/CVE-2026-17834.html
* https://www.suse.com/security/cve/CVE-2026-17835.html
* https://www.suse.com/security/cve/CVE-2026-17836.html
* https://www.suse.com/security/cve/CVE-2026-17837.html
* https://www.suse.com/security/cve/CVE-2026-17838.html
* https://www.suse.com/security/cve/CVE-2026-17839.html
* https://www.suse.com/security/cve/CVE-2026-17840.html
* https://www.suse.com/security/cve/CVE-2026-17841.html
* https://www.suse.com/security/cve/CVE-2026-17842.html
* https://www.suse.com/security/cve/CVE-2026-17843.html
* https://www.suse.com/security/cve/CVE-2026-17844.html
* https://www.suse.com/security/cve/CVE-2026-17845.html
* https://www.suse.com/security/cve/CVE-2026-17846.html
* https://www.suse.com/security/cve/CVE-2026-17847.html
* https://www.suse.com/security/cve/CVE-2026-17848.html
* https://www.suse.com/security/cve/CVE-2026-17849.html
* https://www.suse.com/security/cve/CVE-2026-17850.html
* https://www.suse.com/security/cve/CVE-2026-17851.html
* https://www.suse.com/security/cve/CVE-2026-17852.html
* https://www.suse.com/security/cve/CVE-2026-17853.html
* https://www.suse.com/security/cve/CVE-2026-17854.html
* https://www.suse.com/security/cve/CVE-2026-17855.html
* https://www.suse.com/security/cve/CVE-2026-17856.html
* https://www.suse.com/security/cve/CVE-2026-17857.html
* https://www.suse.com/security/cve/CVE-2026-17858.html
* https://www.suse.com/security/cve/CVE-2026-17859.html
* https://www.suse.com/security/cve/CVE-2026-17860.html
* https://www.suse.com/security/cve/CVE-2026-17861.html
* https://www.suse.com/security/cve/CVE-2026-17862.html
* https://www.suse.com/security/cve/CVE-2026-17863.html
* https://www.suse.com/security/cve/CVE-2026-17864.html
* https://www.suse.com/security/cve/CVE-2026-17865.html
* https://www.suse.com/security/cve/CVE-2026-17866.html
* https://www.suse.com/security/cve/CVE-2026-17867.html
* https://www.suse.com/security/cve/CVE-2026-17868.html
* https://www.suse.com/security/cve/CVE-2026-17869.html
* https://www.suse.com/security/cve/CVE-2026-17870.html
* https://www.suse.com/security/cve/CVE-2026-17871.html
* https://www.suse.com/security/cve/CVE-2026-17872.html
* https://www.suse.com/security/cve/CVE-2026-17873.html
* https://www.suse.com/security/cve/CVE-2026-17874.html
* https://www.suse.com/security/cve/CVE-2026-17875.html
* https://www.suse.com/security/cve/CVE-2026-17876.html
* https://www.suse.com/security/cve/CVE-2026-17877.html
* https://www.suse.com/security/cve/CVE-2026-17878.html
* https://www.suse.com/security/cve/CVE-2026-17879.html
* https://www.suse.com/security/cve/CVE-2026-17880.html
* https://www.suse.com/security/cve/CVE-2026-17881.html
* https://www.suse.com/security/cve/CVE-2026-17882.html
* https://www.suse.com/security/cve/CVE-2026-17883.html
* https://www.suse.com/security/cve/CVE-2026-17884.html
* https://www.suse.com/security/cve/CVE-2026-17885.html
* https://www.suse.com/security/cve/CVE-2026-17886.html
* https://www.suse.com/security/cve/CVE-2026-17887.html
* https://www.suse.com/security/cve/CVE-2026-17888.html
* https://www.suse.com/security/cve/CVE-2026-17889.html
* https://www.suse.com/security/cve/CVE-2026-17890.html
* https://www.suse.com/security/cve/CVE-2026-17891.html
* https://www.suse.com/security/cve/CVE-2026-17892.html
* https://www.suse.com/security/cve/CVE-2026-17893.html
* https://www.suse.com/security/cve/CVE-2026-17894.html
* https://www.suse.com/security/cve/CVE-2026-17895.html
* https://www.suse.com/security/cve/CVE-2026-17896.html
* https://www.suse.com/security/cve/CVE-2026-17897.html
* https://www.suse.com/security/cve/CVE-2026-17898.html
* https://www.suse.com/security/cve/CVE-2026-17899.html
* https://www.suse.com/security/cve/CVE-2026-17900.html
* https://www.suse.com/security/cve/CVE-2026-17901.html
* https://www.suse.com/security/cve/CVE-2026-17902.html
* https://www.suse.com/security/cve/CVE-2026-17903.html
* https://www.suse.com/security/cve/CVE-2026-17904.html
* https://www.suse.com/security/cve/CVE-2026-17905.html
* https://www.suse.com/security/cve/CVE-2026-17906.html
* https://www.suse.com/security/cve/CVE-2026-17907.html
* https://www.suse.com/security/cve/CVE-2026-17908.html
* https://www.suse.com/security/cve/CVE-2026-17909.html
* https://www.suse.com/security/cve/CVE-2026-17910.html
* https://www.suse.com/security/cve/CVE-2026-17911.html
* https://www.suse.com/security/cve/CVE-2026-17912.html
* https://www.suse.com/security/cve/CVE-2026-17913.html
* https://www.suse.com/security/cve/CVE-2026-17914.html
* https://www.suse.com/security/cve/CVE-2026-17915.html
* https://www.suse.com/security/cve/CVE-2026-17916.html
* https://www.suse.com/security/cve/CVE-2026-17917.html
* https://www.suse.com/security/cve/CVE-2026-17918.html
* https://www.suse.com/security/cve/CVE-2026-17919.html
* https://www.suse.com/security/cve/CVE-2026-17920.html
* https://www.suse.com/security/cve/CVE-2026-17921.html
* https://www.suse.com/security/cve/CVE-2026-17922.html
* https://www.suse.com/security/cve/CVE-2026-17923.html
* https://www.suse.com/security/cve/CVE-2026-17924.html
* https://www.suse.com/security/cve/CVE-2026-17925.html
* https://www.suse.com/security/cve/CVE-2026-17926.html
* https://www.suse.com/security/cve/CVE-2026-17927.html
* https://www.suse.com/security/cve/CVE-2026-17928.html
* https://www.suse.com/security/cve/CVE-2026-17929.html
* https://www.suse.com/security/cve/CVE-2026-17930.html
* https://www.suse.com/security/cve/CVE-2026-17931.html
* https://www.suse.com/security/cve/CVE-2026-17932.html
* https://www.suse.com/security/cve/CVE-2026-17933.html
* https://www.suse.com/security/cve/CVE-2026-17934.html
* https://www.suse.com/security/cve/CVE-2026-17935.html
* https://www.suse.com/security/cve/CVE-2026-17936.html
* https://www.suse.com/security/cve/CVE-2026-17937.html
* https://www.suse.com/security/cve/CVE-2026-17938.html
* https://www.suse.com/security/cve/CVE-2026-17939.html
* https://www.suse.com/security/cve/CVE-2026-17940.html
* https://www.suse.com/security/cve/CVE-2026-17941.html
* https://www.suse.com/security/cve/CVE-2026-17942.html
* https://www.suse.com/security/cve/CVE-2026-17943.html
* https://www.suse.com/security/cve/CVE-2026-17944.html
* https://www.suse.com/security/cve/CVE-2026-17945.html
* https://www.suse.com/security/cve/CVE-2026-17946.html
* https://www.suse.com/security/cve/CVE-2026-17947.html
* https://www.suse.com/security/cve/CVE-2026-17948.html
* https://www.suse.com/security/cve/CVE-2026-17949.html
* https://www.suse.com/security/cve/CVE-2026-17950.html
* https://www.suse.com/security/cve/CVE-2026-17951.html
* https://www.suse.com/security/cve/CVE-2026-17952.html
* https://www.suse.com/security/cve/CVE-2026-17953.html
* https://www.suse.com/security/cve/CVE-2026-17954.html
* https://www.suse.com/security/cve/CVE-2026-17955.html
* https://www.suse.com/security/cve/CVE-2026-17956.html
* https://www.suse.com/security/cve/CVE-2026-17957.html
* https://www.suse.com/security/cve/CVE-2026-17958.html
* https://www.suse.com/security/cve/CVE-2026-17959.html
* https://www.suse.com/security/cve/CVE-2026-17960.html
* https://www.suse.com/security/cve/CVE-2026-17961.html
* https://www.suse.com/security/cve/CVE-2026-17962.html
* https://www.suse.com/security/cve/CVE-2026-17963.html
* https://www.suse.com/security/cve/CVE-2026-17964.html
* https://www.suse.com/security/cve/CVE-2026-17965.html
* https://www.suse.com/security/cve/CVE-2026-17966.html
* https://www.suse.com/security/cve/CVE-2026-17967.html
* https://www.suse.com/security/cve/CVE-2026-17968.html
* https://www.suse.com/security/cve/CVE-2026-17969.html
* https://www.suse.com/security/cve/CVE-2026-17970.html
* https://www.suse.com/security/cve/CVE-2026-17971.html
* https://www.suse.com/security/cve/CVE-2026-17972.html
* https://www.suse.com/security/cve/CVE-2026-17973.html
* https://www.suse.com/security/cve/CVE-2026-17974.html
* https://www.suse.com/security/cve/CVE-2026-17975.html
* https://www.suse.com/security/cve/CVE-2026-17976.html
* https://www.suse.com/security/cve/CVE-2026-17977.html
* https://www.suse.com/security/cve/CVE-2026-17978.html
* https://www.suse.com/security/cve/CVE-2026-17979.html
* https://www.suse.com/security/cve/CVE-2026-17980.html
* https://www.suse.com/security/cve/CVE-2026-17981.html
* https://www.suse.com/security/cve/CVE-2026-17982.html
* https://www.suse.com/security/cve/CVE-2026-17983.html
* https://www.suse.com/security/cve/CVE-2026-17984.html
* https://www.suse.com/security/cve/CVE-2026-17985.html
* https://www.suse.com/security/cve/CVE-2026-17986.html
* https://www.suse.com/security/cve/CVE-2026-17987.html
* https://www.suse.com/security/cve/CVE-2026-17988.html
* https://www.suse.com/security/cve/CVE-2026-17989.html
* https://www.suse.com/security/cve/CVE-2026-17990.html
* https://www.suse.com/security/cve/CVE-2026-17991.html
* https://www.suse.com/security/cve/CVE-2026-17992.html
* https://www.suse.com/security/cve/CVE-2026-17993.html
* https://www.suse.com/security/cve/CVE-2026-17994.html
* https://www.suse.com/security/cve/CVE-2026-17995.html
* https://www.suse.com/security/cve/CVE-2026-17996.html
* https://www.suse.com/security/cve/CVE-2026-17997.html
* https://www.suse.com/security/cve/CVE-2026-17998.html
* https://www.suse.com/security/cve/CVE-2026-17999.html
* https://www.suse.com/security/cve/CVE-2026-18000.html
* https://www.suse.com/security/cve/CVE-2026-18001.html
* https://www.suse.com/security/cve/CVE-2026-18002.html
* https://www.suse.com/security/cve/CVE-2026-18003.html
* https://www.suse.com/security/cve/CVE-2026-18004.html
* https://www.suse.com/security/cve/CVE-2026-18005.html
* https://www.suse.com/security/cve/CVE-2026-18006.html
* https://www.suse.com/security/cve/CVE-2026-18007.html
* https://www.suse.com/security/cve/CVE-2026-18008.html
* https://www.suse.com/security/cve/CVE-2026-18009.html
* https://www.suse.com/security/cve/CVE-2026-18010.html
* https://www.suse.com/security/cve/CVE-2026-18011.html
* https://www.suse.com/security/cve/CVE-2026-18012.html
* https://www.suse.com/security/cve/CVE-2026-18013.html
* https://www.suse.com/security/cve/CVE-2026-18014.html
* https://www.suse.com/security/cve/CVE-2026-18015.html
* https://www.suse.com/security/cve/CVE-2026-18016.html
* https://www.suse.com/security/cve/CVE-2026-18017.html
* https://www.suse.com/security/cve/CVE-2026-18018.html
* https://www.suse.com/security/cve/CVE-2026-18019.html



openSUSE-SU-2026:11440-1: moderate: nodejs26-26.5.1-1.1 on GA media


# nodejs26-26.5.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11440-1
Rating: moderate

Cross-References:

* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58041
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045

CVSS scores:

* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 11 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the nodejs26-26.5.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* nodejs26 26.5.1-1.1
* nodejs26-devel 26.5.1-1.1
* nodejs26-docs 26.5.1-1.1
* npm26 26.5.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58041.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html



openSUSE-SU-2026:11439-1: moderate: corepack24-24.18.1-1.1 on GA media


# corepack24-24.18.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11439-1
Rating: moderate

Cross-References:

* CVE-2026-56846
* CVE-2026-56847
* CVE-2026-56848
* CVE-2026-56850
* CVE-2026-58039
* CVE-2026-58040
* CVE-2026-58041
* CVE-2026-58042
* CVE-2026-58043
* CVE-2026-58044
* CVE-2026-58045

CVSS scores:

* CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-58040 ( SUSE ): 7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
* CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 11 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the corepack24-24.18.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* corepack24 24.18.1-1.1
* nodejs24 24.18.1-1.1
* nodejs24-devel 24.18.1-1.1
* nodejs24-docs 24.18.1-1.1
* npm24 24.18.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56846.html
* https://www.suse.com/security/cve/CVE-2026-56847.html
* https://www.suse.com/security/cve/CVE-2026-56848.html
* https://www.suse.com/security/cve/CVE-2026-56850.html
* https://www.suse.com/security/cve/CVE-2026-58039.html
* https://www.suse.com/security/cve/CVE-2026-58040.html
* https://www.suse.com/security/cve/CVE-2026-58041.html
* https://www.suse.com/security/cve/CVE-2026-58042.html
* https://www.suse.com/security/cve/CVE-2026-58043.html
* https://www.suse.com/security/cve/CVE-2026-58044.html
* https://www.suse.com/security/cve/CVE-2026-58045.html



openSUSE-SU-2026:11441-1: moderate: xen-4.22.0_02-1.1 on GA media


# xen-4.22.0_02-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11441-1
Rating: moderate

Cross-References:

* CVE-2026-42492
* CVE-2026-42493
* CVE-2026-42494
* CVE-2026-62423
* CVE-2026-62426
* CVE-2026-62428
* CVE-2026-62429
* CVE-2026-62430
* CVE-2026-62431
* CVE-2026-62432
* CVE-2026-62433
* CVE-2026-62434

CVSS scores:

* CVE-2026-42492 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42492 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 12 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the xen-4.22.0_02-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* xen 4.22.0_02-1.1
* xen-devel 4.22.0_02-1.1
* xen-doc-html 4.22.0_02-1.1
* xen-libs 4.22.0_02-1.1
* xen-tools 4.22.0_02-1.1
* xen-tools-domU 4.22.0_02-1.1
* xen-tools-xendomains-wait-disk 4.22.0_02-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-42492.html
* https://www.suse.com/security/cve/CVE-2026-42493.html
* https://www.suse.com/security/cve/CVE-2026-42494.html
* https://www.suse.com/security/cve/CVE-2026-62423.html
* https://www.suse.com/security/cve/CVE-2026-62426.html
* https://www.suse.com/security/cve/CVE-2026-62428.html
* https://www.suse.com/security/cve/CVE-2026-62429.html
* https://www.suse.com/security/cve/CVE-2026-62430.html
* https://www.suse.com/security/cve/CVE-2026-62431.html
* https://www.suse.com/security/cve/CVE-2026-62432.html
* https://www.suse.com/security/cve/CVE-2026-62433.html
* https://www.suse.com/security/cve/CVE-2026-62434.html



SUSE-SU-2026:3468-1: important: Security update for rrdtool


# Security update for rrdtool

Announcement ID: SUSE-SU-2026:3468-1
Release Date: 2026-08-03T16:34:53Z
Rating: important
References:

* bsc#1267243

Cross-References:

* CVE-2026-43958

CVSS scores:

* CVE-2026-43958 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43958 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43958 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for rrdtool fixes the following issue:

* CVE-2026-43958: stack buffer overflow in `rrdcached`
`handle_request_create()` can lead to local privilege escalation via
unbounded DS/RRA arguments (bsc#1267243).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3468=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3468=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3468=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3468=1

## Package List:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* tcl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* tcl-rrdtool-1.8.0-150600.3.9.1
* lua-rrdtool-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* ruby-rrdtool-debuginfo-1.8.0-150600.3.9.1
* python3-rrdtool-1.8.0-150600.3.9.1
* python3-rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-cached-debuginfo-1.8.0-150600.3.9.1
* rrdtool-cached-1.8.0-150600.3.9.1
* ruby-rrdtool-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* rrdtool-doc-1.8.0-150600.3.9.1
* lua-rrdtool-debuginfo-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* perl-rrdtool-1.8.0-150600.3.9.1
* rrdtool-debugsource-1.8.0-150600.3.9.1
* rrdtool-1.8.0-150600.3.9.1
* librrd8-1.8.0-150600.3.9.1
* librrd8-debuginfo-1.8.0-150600.3.9.1
* rrdtool-debuginfo-1.8.0-150600.3.9.1
* rrdtool-devel-1.8.0-150600.3.9.1
* perl-rrdtool-debuginfo-1.8.0-150600.3.9.1

## References:

* https://www.suse.com/security/cve/CVE-2026-43958.html
* https://bugzilla.suse.com/show_bug.cgi?id67243



SUSE-SU-2026:3469-1: important: Security update for nginx


# Security update for nginx

Announcement ID: SUSE-SU-2026:3469-1
Release Date: 2026-08-03T16:40:38Z
Rating: important
References:

* bsc#1271514

Cross-References:

* CVE-2026-42533

CVSS scores:

* CVE-2026-42533 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-42533 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-42533 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-42533 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.6
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for nginx fixes the following issue:

* CVE-2026-42533: referencing regex capture variables before map output
variables can trigger a heap buffer overflow (bsc#1271514).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3469=1

* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3469=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3469=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3469=1

## Package List:

* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* Server Applications Module 15-SP7 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* nginx-debuginfo-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* openSUSE Leap 15.6 (noarch)
* nginx-source-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* nginx-debuginfo-1.21.5-150600.10.27.1
* nginx-debugsource-1.21.5-150600.10.27.1
* nginx-1.21.5-150600.10.27.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* nginx-source-1.21.5-150600.10.27.1

## References:

* https://www.suse.com/security/cve/CVE-2026-42533.html
* https://bugzilla.suse.com/show_bug.cgi?id71514



SUSE-SU-2026:3470-1: important: Security update for spice-vdagent


# Security update for spice-vdagent

Announcement ID: SUSE-SU-2026:3470-1
Release Date: 2026-08-03T16:42:20Z
Rating: important
References:

* bsc#1269553
* bsc#1269554

Cross-References:

* CVE-2026-57965
* CVE-2026-57966

CVSS scores:

* CVE-2026-57965 ( SUSE ): 5.2
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-57966 ( SUSE ): 6.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
* CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.3
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves two vulnerabilities can now be installed.

## Description:

This update for spice-vdagent fixes the following issues:

* CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer
overflow (bsc#1269553).
* CVE-2026-57966: improper sanitization allows a compromised SPICE host to
write arbitrary files to any location on the guest operating system
(bsc#1269554).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3470=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3470=1

* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3470=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3470=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3470=1

## Package List:

* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* spice-vdagent-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* spice-vdagent-debugsource-0.21.0-150300.3.6.1
* spice-vdagent-debuginfo-0.21.0-150300.3.6.1
* spice-vdagent-0.21.0-150300.3.6.1

## References:

* https://www.suse.com/security/cve/CVE-2026-57965.html
* https://www.suse.com/security/cve/CVE-2026-57966.html
* https://bugzilla.suse.com/show_bug.cgi?id69553
* https://bugzilla.suse.com/show_bug.cgi?id69554



SUSE-SU-2026:3474-1: moderate: Security update for s390-tools


# Security update for s390-tools

Announcement ID: SUSE-SU-2026:3474-1
Release Date: 2026-08-03T16:45:58Z
Rating: moderate
References:

* bsc#1270185

Cross-References:

* CVE-2026-41676

CVSS scores:

* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4

An update that solves one vulnerability can now be installed.

## Description:

This update for s390-tools fixes the following issue

* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270185).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3474=1

## Package List:

* openSUSE Leap 15.4 (s390x)
* s390-tools-hmcdrvfs-debuginfo-2.31.0-150400.7.34.1
* s390-tools-zdsfs-debuginfo-2.31.0-150400.7.34.1
* libekmfweb1-devel-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-devel-2.31.0-150400.7.34.1
* s390-tools-chreipl-fcp-mpath-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* s390-tools-hmcdrvfs-2.31.0-150400.7.34.1
* osasnmpd-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* osasnmpd-debuginfo-2.31.0-150400.7.34.1
* s390-tools-zdsfs-2.31.0-150400.7.34.1
* openSUSE Leap 15.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* openSUSE Leap 15.4 (s390x x86_64)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (s390x)
* s390-tools-debugsource-2.31.0-150400.7.34.1
* libkmipclient1-debuginfo-2.31.0-150400.7.34.1
* s390-tools-debuginfo-2.31.0-150400.7.34.1
* libkmipclient1-2.31.0-150400.7.34.1
* libekmfweb1-2.31.0-150400.7.34.1
* s390-tools-2.31.0-150400.7.34.1
* libekmfweb1-debuginfo-2.31.0-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (noarch)
* s390-tools-genprotimg-data-2.31.0-150400.7.34.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://bugzilla.suse.com/show_bug.cgi?id70185



SUSE-SU-2026:3475-1: moderate: Security update for s390-tools


# Security update for s390-tools

Announcement ID: SUSE-SU-2026:3475-1
Release Date: 2026-08-03T16:46:06Z
Rating: moderate
References:

* bsc#1270185

Cross-References:

* CVE-2026-41676

CVSS scores:

* CVE-2026-41676 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-41676 ( NVD ): 7.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise Micro 5.5

An update that solves one vulnerability can now be installed.

## Description:

This update for s390-tools fixes the following issue

* CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can
overflow short buffers on OpenSSL 1.1.1 (bsc#1270185).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3475=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3475=1

## Package List:

* openSUSE Leap 15.5 (s390x)
* s390-tools-hmcdrvfs-debuginfo-2.31.0-150500.9.32.1
* libekmfweb1-debuginfo-2.31.0-150500.9.32.1
* osasnmpd-2.31.0-150500.9.32.1
* libkmipclient1-devel-2.31.0-150500.9.32.1
* s390-tools-hmcdrvfs-2.31.0-150500.9.32.1
* libkmipclient1-debuginfo-2.31.0-150500.9.32.1
* libekmfweb1-2.31.0-150500.9.32.1
* osasnmpd-debuginfo-2.31.0-150500.9.32.1
* s390-tools-chreipl-fcp-mpath-2.31.0-150500.9.32.1
* libekmfweb1-devel-2.31.0-150500.9.32.1
* libkmipclient1-2.31.0-150500.9.32.1
* s390-tools-zdsfs-debuginfo-2.31.0-150500.9.32.1
* s390-tools-zdsfs-2.31.0-150500.9.32.1
* openSUSE Leap 15.5 (s390x x86_64)
* s390-tools-debugsource-2.31.0-150500.9.32.1
* s390-tools-debuginfo-2.31.0-150500.9.32.1
* s390-tools-2.31.0-150500.9.32.1
* openSUSE Leap 15.5 (noarch)
* s390-tools-genprotimg-data-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (s390x x86_64)
* s390-tools-2.31.0-150500.9.32.1
* s390-tools-debuginfo-2.31.0-150500.9.32.1
* s390-tools-debugsource-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (s390x)
* libekmfweb1-2.31.0-150500.9.32.1
* libkmipclient1-2.31.0-150500.9.32.1
* libekmfweb1-debuginfo-2.31.0-150500.9.32.1
* libkmipclient1-debuginfo-2.31.0-150500.9.32.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* s390-tools-genprotimg-data-2.31.0-150500.9.32.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41676.html
* https://bugzilla.suse.com/show_bug.cgi?id70185



SUSE-SU-2026:3476-1: important: Security update for bind


# Security update for bind

Announcement ID: SUSE-SU-2026:3476-1
Release Date: 2026-08-03T16:58:19Z
Rating: important
References:

* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990

Cross-References:

* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321

CVSS scores:

* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves six vulnerabilities can now be installed.

## Description:

This update for bind fixes the following issues

* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3476=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3476=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3476=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3476=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3476=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* openSUSE Leap 15.4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* bind-utils-debuginfo-9.16.50-150400.5.65.1
* bind-utils-9.16.50-150400.5.65.1
* bind-debuginfo-9.16.50-150400.5.65.1
* bind-debugsource-9.16.50-150400.5.65.1
* bind-9.16.50-150400.5.65.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* python3-bind-9.16.50-150400.5.65.1
* bind-doc-9.16.50-150400.5.65.1

## References:

* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990



SUSE-SU-2026:3477-1: important: Security update for bind


# Security update for bind

Announcement ID: SUSE-SU-2026:3477-1
Release Date: 2026-08-03T16:58:45Z
Rating: important
References:

* bsc#1271982
* bsc#1271984
* bsc#1271986
* bsc#1271987
* bsc#1271989
* bsc#1271990

Cross-References:

* CVE-2026-10723
* CVE-2026-11331
* CVE-2026-11622
* CVE-2026-11721
* CVE-2026-13204
* CVE-2026-13321

CVSS scores:

* CVE-2026-10723 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-11331 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11622 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11721 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13204 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13321 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
* CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
* CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected Products:

* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves six vulnerabilities can now be installed.

## Description:

This update for bind fixes the following issues

* CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
* CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
* CVE-2026-11622: potential memory usage beyond configured limits
(bsc#1271986).
* CVE-2026-11721: cache poisoning possible with label count discrepancy,
RRSIG, and wildcards (bsc#1271987).
* CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3
both present (bsc#1271989).
* CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field
(bsc#1271990).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3477=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3477=1

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3477=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3477=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3477=1

* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3477=1

## Package List:

* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* openSUSE Leap 15.5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* bind-debugsource-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* python3-bind-9.16.50-150500.8.41.1
* bind-doc-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* bind-utils-9.16.50-150500.8.41.1
* bind-utils-debuginfo-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* python3-bind-9.16.50-150500.8.41.1
* SUSE Linux Enterprise Micro 5.5 (x86_64)
* bind-debugsource-9.16.50-150500.8.41.1
* bind-debuginfo-9.16.50-150500.8.41.1

## References:

* https://www.suse.com/security/cve/CVE-2026-10723.html
* https://www.suse.com/security/cve/CVE-2026-11331.html
* https://www.suse.com/security/cve/CVE-2026-11622.html
* https://www.suse.com/security/cve/CVE-2026-11721.html
* https://www.suse.com/security/cve/CVE-2026-13204.html
* https://www.suse.com/security/cve/CVE-2026-13321.html
* https://bugzilla.suse.com/show_bug.cgi?id71982
* https://bugzilla.suse.com/show_bug.cgi?id71984
* https://bugzilla.suse.com/show_bug.cgi?id71986
* https://bugzilla.suse.com/show_bug.cgi?id71987
* https://bugzilla.suse.com/show_bug.cgi?id71989
* https://bugzilla.suse.com/show_bug.cgi?id71990



openSUSE-SU-2026:0275-1: important: Security update for thrift


openSUSE Security Update: Security update for thrift
_______________________________

Announcement ID: openSUSE-SU-2026:0275-1
Rating: important
References: #1263321 #1263322 #1263365 #1263438 #1263492
#1263557 #1272609 #1272645 #1272647 #1272648
#1272649 #1272650 #1272651 #1272652 #1272653
#1272654 #1272655 #1272656 #1272657 #1272658

Cross-References: CVE-2026-41602 CVE-2026-41604 CVE-2026-41605
CVE-2026-41606 CVE-2026-41607 CVE-2026-41608
CVE-2026-41636 CVE-2026-43871 CVE-2026-45112
CVE-2026-48144 CVE-2026-48145 CVE-2026-48586
CVE-2026-49158 CVE-2026-55968 CVE-2026-55969
CVE-2026-55970 CVE-2026-55971 CVE-2026-58023
CVE-2026-58389 CVE-2026-58662
CVSS scores:
CVE-2026-41602 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-41604 (SUSE): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
CVE-2026-41605 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVE-2026-41606 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-41607 (SUSE): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
CVE-2026-41636 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes 20 vulnerabilities is now available.

Description:

This update for thrift fixes the following issues:

- update to 0.24.0 ( boo#1272609, CVE-2026-41608, boo#1272654,
CVE-2026-58023, boo#1272655, CVE-2026-55970, boo#1272656,
CVE-2026-49158, boo#1272657, CVE-2026-48586, boo#1272658,
CVE-2026-48145, boo#1272652, CVE-2026-58389, boo#1272653,
CVE-2026-55971, boo#1272645, CVE-2026-48144, boo#1272647,
CVE-2026-45112, boo#1272648, CVE-2026-43871, boo#1272649,
CVE-2026-55969, boo#1272650, CVE-2026-55968, boo#1272651,
CVE-2026-58662, boo#1272609, CVE-2026-41608):
* THRIFT-5930 - thrift_server_socket() copies Unix socket paths into
sockaddr_un.sun_path without bounds checking
* #3585 - limit recursion depth in c_glib thrift_protocol_skip
* #3507 - Add peer hostname validation to c_glib TLS client
* #3393 - Fix parent class resolution in c_glib generated dispatch_call
* THRIFT-3165 - Disable unsafe TLSv1.0 and TLSv1.1 by default
* THRIFT-6021 - When C++ client with HTTP transport calls a
oneway RPC method, it must not expect a response
* THRIFT-6060 - C++ THttpClient does not reopen socket after server
sends Connection: close
* THRIFT-6073 - Allow injecting external SSL_CTX into C++ SSLContext
* #3597 - link UnitTests against libthriftz to resolve THeaderTransport
vtable
* #3597 - fix off-by-ten header bounds check in readHeaderFormat
* #3569 - Add the cpp.ref (&) annotation to the recursive exception in
Recursive.thrift
* #3519 - Preserve private_optional field order
* #3498 - change sprintf to snprintf to eliminate security warnings on
OSX
* #3506 - Enforce RFC 6125 wildcard placement in TSSLSocket hostname
matching
* #3508 - Replace memory-safety asserts with unconditional throws in
TBufferTransports
* #3431 - Remove another boost header from the public API
* #3529 - nodejs+compiler: Add opt-in BigInt support for int64 via
js:bigint flag
* #3461 - Migration *.sln to *.slnx (except c++ libs)
* #2957 - Fix PHP cross-test server IPv4 binding
* #3372 - Fix JavaScript exception construction implementation (ES6)
* #3520 - added thrift-threat-model.md, SECURITY.md and security section
to AGENTS.md
* THRIFT-6030 - Harden Erlang protocol negative sizes
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* THRIFT-5214 - go: Implement connection check in TSocket
* THRIFT-5969 - Introduce gofmt for Go library
* THRIFT-5996 - go: connection check should work for TLS sockets
* THRIFT-6011 - Make compiled Go code formatting compatible with gofmt
* THRIFT-6012 - Fix inverted regexp.MatchString arguments and precompile
patterns in Go validator
* THRIFT-6044 - Limit struct read/write recursion depth in Go library
* THRIFT-6071 - Validate container size fits int32 range before
narrowing conversion in TSimpleJSONProtocol
* #3604 - Bound the container element count before the 64-bit size
precheck in the Go JSON protocol
* #3604 - widen container size precheck to 64-bit in go protocols
* #3599 - check wire-supplied size in simple json ReadMapBegin
* #3497 - Bump golang.org/x/sys to 0.0.0-20220412211240-33da011f77ad
* #3458 - Prevent concurrent calls to socketConn.Close() in Go
* #3428 - Fix range check on 32-bit architectures
* #3379 - Replace addr with factory in TServerSocket
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3381 - added int range checks
* #3618 - Bump jvm from 2.3.21 to 2.4.0 in /lib/kotlin
* #3619 - Bump com.diffplug.spotless from 8.5.1 to 8.7.0 in /lib/kotlin
* #3605 - enforce stringLengthLimit in TCompactProtocol.readBinary
* #3574 - Bump com.diffplug.spotless from 8.4.0 to 8.5.1 in /lib/kotlin
* #3572 - Bump org.jetbrains.kotlinx:kotlinx-coroutines-jdk8 in
/lib/kotlin
* #3452 - Add message byte tracking to consumeBuffer() in Java transports
* #3434 - Bump jvm from 2.3.20 to 2.3.21 in /lib/kotlin
* #3420 - Fix Java Spotless formatting
* #3415 - Connect skip() to TConfiguration recursion limit
* #3412 - Use bounded default for maxSkipDepth in TProtocolUtil
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3396 - Enable TLS hostname verification in TNonblockingSSLSocket
* #3390 - Enable TLS hostname verification in TSSLTransportFactory
* THRIFT-5915 - Python 3.12+ is not supported due to distutils
* THRIFT-5923 - UUID support for Python
* THRIFT-6024 - Python THeaderTransport and TZlibTransport default max
frame/decompressed size should be DEFAULT_MAX_FRAME_SIZE (16384000),
not HARD_MAX_FRAME_SIZE (0x3FFFFFFF)
* THRIFT-6043 - Harden Python binary protocol negative sizes
* THRIFT-6067 - Python: pip install fails on setuptools < 69 due to
sys.exit() in setup.py (PEP 517 build backend)
* THRIFT-6069 - suggestion for a few python perf improvements
* THRIFT-6070 - Publish Python wheel distributions to PyPI
* #3410 - Add byte-count limit to TCompactProtocol varint reader
* #3413 - Use sslcompat hostname matcher in TSSLSocket
* #3411 - Add default recursion depth limit to TProtocol.skip()
* #3408 - Add decompressed payload size limit to Python THeaderTransport
* #3377 - Optimize Python C extension readStruct for nested structs
* #2957 - Fix PHP cross-test server IPv4 binding

- update to 0.23.0 (boo#1263557, CVE-2026-41602, boo#1263492,
CVE-2026-41604, boo#1263438, CVE-2026-41605, boo#1263365,
CVE-2026-41606, boo#1263321, CVE-2026-41607, boo#1263322,
CVE-2026-41636):
* THRIFT-5877 - Add cpp cross tests
* THRIFT-5866 - Dockerfile to support Ubuntu 24.04 LTS (Noble Numbat)
* THRIFT-5909 - add Ruby in GitHub workflow
* THRIFT-5649 - add go in GitHub workflow / action
* THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends
* THRIFT-5911 - Inconsistent UUID compilation for aliased types
* THRIFT-5912 - Assertion failed: `delta > 0`, file
ThreadManagerTests.h, line 162
* THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a
hostname of 127.0.0.1
* THRIFT-3268 - warning: token pasting of ',' and `__VA_ARGS__` is a GNU
extension
* THRIFT-5887 - build/cmake/ should be prepended (not appended) to
CMAKE_MODULE_PATH
* THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap
* THRIFT-5898 - Unable to build Thrift as a shared library on Windows
* THRIFT-5939 - Replace GUID generation with stable UUID algorithm
* THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support
* THRIFT-5896 - Race condition in TServerSocket.Addr() method
* THRIFT-5925 - UUID implementation in JAVA is not according to the
Thrift Specification
* THRIFT-5869 - Close the transport after TServerEventHandler
deleteContext
* THRIFT-5863 - Make TServerTransport able to customize the max message
size
* THRIFT-5774 - Add remote client's IP address to ServerContext in
TServerEventHandler
* THRIFT-4280 - Add async nonblocking ssl support in java client
* THRIFT-5879 - java and kotlin cross tests fail in the GitHub action
* THRIFT-5902 - Add net10 support
* THRIFT-5874 - Introduce new type `MESSAGE_SIZE_LIMIT` in
TTransportException
* THRIFT-5937 - nodejs episodic generation does not handle extending
services
* THRIFT-5924 - UUID support for nodejs and nodets
* THRIFT-4987 - TProtocolException: Bad version in readMessageBegin when
using XHR client with C++ server
* THRIFT-5924 - UUID support for nodejs and nodets
* THRIFT-5935 - Fix deprecated non-canonical casts for PHP 8.5
compatibility
* THRIFT-5921 - Ubuntu focal fail to run composer install
* THRIFT-5929 - Fix build failure on PHP 8.5 due to removed
zend_exception_get_default
* THRIFT-5927 - Cannot use reserved language keyword "None" with target
language Python
* THRIFT-5885 - TBinaryProtocolAccelerated incorrectly deserializes
IntEnum to None
* THRIFT-5923 - UUID support for Python
* THRIFT-5926 - TSaslClientTransport.open() crashes with DIGEST-MD5 due
to None initial response
* THRIFT-5915 - Python 3.12+ is not supported due to distutils
* THRIFT-5892 - PY_SSIZE_T_CLEAN error in some environments
* THRIFT-5873 - mTLS broken with python THttpClient
* THRIFT-792 - TSocket hides underlying exceptions when open() fails
* THRIFT-5888 - declare support for free-threaded CPython in extension
modules
* THRIFT-5900 - Thrift Cross Test broken in Github (Python 3.14)
* THRIFT-5308 - implement ruby seq replyÂ
* THRIFT-5910 - Add UUID support in Ruby
* THRIFT-5906 - Remove Fixnum references to support modern Ruby versions
* THRIFT-5905 - Add base64 and logger as explicit dependencies
* THRIFT-5903 - Fixnum is no longer supported since Ruby 3.2
* THRIFT-5687 - Ruby gems deprecation warning:
Gem::Specification#has_rdoc= is deprecated with no replacement
* THRIFT-4035 - Thrift ruby runtime does not send unique sequence IDs in
requests according to the unit tests
* THRIFT-1911 - IOError not being caught in socket.rb
* THRIFT-4526 - Implement rubocop for ruby in the sca build,
once clean into every make
* THRIFT-5273 - warning in ruby version >= 2.4
* THRIFT-5918 - Implement header protocol support for Ruby
* THRIFT-5559 - Processor can be implemented on handler trait itself
* THRIFT-5928 - skip() call on unknown binary field fails
deserialization instead of graceful skipping over field
* THRIFT-5739 - set_nodelay should be enabled for TTcpChannel

- Update to 0.22.0:
* ### Build Process
- THRIFT-5836 - 0.21.0 fails to build from sources at Arch Linux: No
rule to make target 'Thrift5272.thrift', needed by
'gen-cpp/Thrift5272_types.h'
- THRIFT-5860 - cmake 3.5 as a minimum version does not work with
cmake 4.0.0
* ### C glib
- THRIFT-5817 - [C++] Avoid copy of TUuid
* ### C++
- THRIFT-5637 - Thrift compiler should be able to output c++ Aggregate
types
- THRIFT-5667 - Make ThriftConfig.cmake relocatable
- THRIFT-5817 - [C++] Avoid copy of TUuid
- THRIFT-5821 - Cannot compile against aws-lc libcrypto (openssl
replacement from AWS)
- THRIFT-5841 - possible init/deinit conflict with manual
initialization flag
- THRIFT-5853 - Remove oldstyle casts from TBufferTransports and
TCompactProtocol
- THRIFT-5854 - TCompactProtocol readString checks maxMessageSize at
wrong position and off by one
- THRIFT-5868 - UUID Support for TCompactProtocol
- THRIFT-5865 - Fix TBinayProtocol with list
* ### Compiler (General)
- THRIFT-5823 - Fix illegal uses of exceptions as normal struct type
- THRIFT-5835 - Allow exceptions to be used as regular struct datatype
* # Delphi
- THRIFT-5822 - Remove deprecated AnsiString functions from the library
- THRIFT-5824 - Migrate, refactor and improve Delphi code generation
test script
- THRIFT-5825 - UUID constants lead to uncompileable Delphi code
- THRIFT-5826 - binary constants create uncompilable Delphi code
- THRIFT-5827 - enums in typedefs are not resolved in all cases
- THRIFT-5837 - Delphi implementation for THRIFT-5835
- THRIFT-5839 - incorrect cast under Win64
- THRIFT-5850 - Switch IThriftConfiguration interface from Cardinal to
Integer
- THRIFT-5851 - Promote known total stream sizes for seekable stream
transports properly
- THRIFT-5856 - Client should validate HTTP status
* ### Go
- THRIFT-5833 - go: Combine I/O and original error in compiler
generated Process functions
- THRIFT-5845 - The write error for union fields should be TException
- THRIFT-5859 - go: Generate a map for know values of an enum type
* ### Java
- THRIFT-5858 - Introduce new type MESSAGE_SIZE_LIMIT in
TTransportException
* ### netstd
- THRIFT-5832 - Drop net6 support and add net9 instead
- THRIFT-5838 - THttpTransport.FlushAsync does not include original
exception
- THRIFT-5852 - Promote known total stream sizes for seekable stream
transports
* ### Node.js
- THRIFT-5811 - Add ES module support to JS codegen
- THRIFT-5848 - Expose InputBufferUnderrunError in nodejs client
- THRIFT-5849 - Expose createClient in browser version of nodejs
package
* ### PHP
- THRIFT-1482 - Unix domain socket support under PHP
- THRIFT-5829 - PHP lib Use of "static" in callables is deprecated
notice
* ### Python
- THRIFT-5024 - tutorial\py.tornado\PythonServer.py failed under
Tornado6
- THRIFT-5847 - Python3.12 deprecation in THttpClient
- THRIFT-5857 - Remove deprecated Tornado io_loop usage
- THRIFT-5861 - Add isOpen method to TTornadoStreamTransport
* ### Swift
- THRIFT-4838 - add unix domain socket support to Swift
TSocketTransport implementation

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-275=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

libthrift-0_24_0-0.24.0-bp157.2.3.1
libthrift-devel-0.24.0-bp157.2.3.1
libthrift_c_glib0-0.24.0-bp157.2.3.1
libthriftnb-0_24_0-0.24.0-bp157.2.3.1
libthriftz-0_24_0-0.24.0-bp157.2.3.1
perl-thrift-0.24.0-bp157.2.3.1
python3-thrift-0.24.0-bp157.2.3.1
thrift-0.24.0-bp157.2.3.1

References:

https://www.suse.com/security/cve/CVE-2026-41602.html
https://www.suse.com/security/cve/CVE-2026-41604.html
https://www.suse.com/security/cve/CVE-2026-41605.html
https://www.suse.com/security/cve/CVE-2026-41606.html
https://www.suse.com/security/cve/CVE-2026-41607.html
https://www.suse.com/security/cve/CVE-2026-41608.html
https://www.suse.com/security/cve/CVE-2026-41636.html
https://www.suse.com/security/cve/CVE-2026-43871.html
https://www.suse.com/security/cve/CVE-2026-45112.html
https://www.suse.com/security/cve/CVE-2026-48144.html
https://www.suse.com/security/cve/CVE-2026-48145.html
https://www.suse.com/security/cve/CVE-2026-48586.html
https://www.suse.com/security/cve/CVE-2026-49158.html
https://www.suse.com/security/cve/CVE-2026-55968.html
https://www.suse.com/security/cve/CVE-2026-55969.html
https://www.suse.com/security/cve/CVE-2026-55970.html
https://www.suse.com/security/cve/CVE-2026-55971.html
https://www.suse.com/security/cve/CVE-2026-58023.html
https://www.suse.com/security/cve/CVE-2026-58389.html
https://www.suse.com/security/cve/CVE-2026-58662.html
https://bugzilla.suse.com/1263321
https://bugzilla.suse.com/1263322
https://bugzilla.suse.com/1263365
https://bugzilla.suse.com/1263438
https://bugzilla.suse.com/1263492
https://bugzilla.suse.com/1263557
https://bugzilla.suse.com/1272609
https://bugzilla.suse.com/1272645
https://bugzilla.suse.com/1272647
https://bugzilla.suse.com/1272648
https://bugzilla.suse.com/1272649
https://bugzilla.suse.com/1272650
https://bugzilla.suse.com/1272651
https://bugzilla.suse.com/1272652
https://bugzilla.suse.com/1272653
https://bugzilla.suse.com/1272654
https://bugzilla.suse.com/1272655
https://bugzilla.suse.com/1272656
https://bugzilla.suse.com/1272657
https://bugzilla.suse.com/1272658



openSUSE-SU-2026:0274-1: important: Security update for perl-HTTP-Tiny


openSUSE Security Update: Security update for perl-HTTP-Tiny
_______________________________

Announcement ID: openSUSE-SU-2026:0274-1
Rating: important
References: #1271020
Cross-References: CVE-2026-7017
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for perl-HTTP-Tiny fixes the following issues:

- updated to 0.096 see /usr/share/doc/packages/perl-HTTP-Tiny/Changes
0.096 2026-06-08 11:21:49+02:00 Europe/Brussels
- No changes from 0.095-TRIAL 0.095 2026-06-03 13:10:05+02:00
Europe/Brussels (TRIAL RELEASE) [!!! SECURITY !!!]
- CVE-2026-7017 boo#1271020
- Caller-supplied Authorization, Cookie, and Proxy-Authorization
headers are now stripped on cross-origin redirects by default. Use
allow_credentialed_redirects to opt out.
- Redirects are no longer automatically followed when going from
https to http. Use allow_downgrade to revert to the original behaviour.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-274=1

Package List:

- openSUSE Backports SLE-15-SP7 (noarch):

perl-HTTP-Tiny-0.096-bp157.2.6.1

References:

https://www.suse.com/security/cve/CVE-2026-7017.html
https://bugzilla.suse.com/1271020



openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck


openSUSE Security Update: Security update for perl-YAML-Syck
_______________________________

Announcement ID: openSUSE-SU-2026:0273-1
Rating: important
References: #1265155 #1271631 #1271632 #1271633 #1271634

Cross-References: CVE-2025-11683 CVE-2026-13713 CVE-2026-5089
CVE-2026-57075 CVE-2026-57076 CVE-2026-57077

CVSS scores:
CVE-2025-11683 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes 6 vulnerabilities is now available.

Description:

This update for perl-YAML-Syck fixes the following issues:

- updated to 1.470.0 (1.47) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026
[Security]
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags
(reported by Paul Johnson via CPANSec, PR #213):
- CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
boo#1271632
- CVE-2026-57076 (CWE-416): use-after-free of an anchor key string
shared between the node and the anchors table boo#1271633
- CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on to
CVE-2025-11683) boo#1271634
- CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of
an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte
input boo#1271631
- Harden syck_base64dec() to bounds-check each read so it cannot run
past a non-NUL-terminated input buffer (defense-in-depth for callers
passing raw buffers; PR #213) [Bug Fixes]
- Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from
deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now
default to 512, matching Dump (PR #204)
- Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf
values in Dump so they roundtrip with ImplicitTyping instead of
reloading as plain strings (PR #201) [Maintenance]
- CI: add an AddressSanitizer job that builds the XS with
-fsanitizeュdress and runs the suite plus the CVE trigger inputs to
catch libsyck memory-safety defects; de-pin the libasan version so it
tracks the runner's GCC (PR #213)

- updated to 1.460.0 (1.46) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug
Fixes]
- Fix: preserve string nature of numeric-looking values in Dump; pure
strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip
fidelity (GH #199, PR #200)
- Fix: accept trailing commas in flow sequences and mappings ([a, b,]
and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196)
[Maintenance]
- CI: upgrade install-with-cpm to v2 for compatibility with Perl
versions prior to 5.24 in perldocker containers (GH #197, PR #198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant
entries, exclude .claude/ from distribution

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-273=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

perl-YAML-Syck-1.470.0-bp157.2.6.1

References:

https://www.suse.com/security/cve/CVE-2025-11683.html
https://www.suse.com/security/cve/CVE-2026-13713.html
https://www.suse.com/security/cve/CVE-2026-5089.html
https://www.suse.com/security/cve/CVE-2026-57075.html
https://www.suse.com/security/cve/CVE-2026-57076.html
https://www.suse.com/security/cve/CVE-2026-57077.html
https://bugzilla.suse.com/1265155
https://bugzilla.suse.com/1271631
https://bugzilla.suse.com/1271632
https://bugzilla.suse.com/1271633
https://bugzilla.suse.com/1271634