SUSE 5718 Published by

SUSE distributed a fresh wave of security advisories addressing critical vulnerabilities across multiple openSUSE and standard enterprise packages. The release flags updates for perl, ImageMagick, gh, helm, glib2, and aws-nitro-enclaves-cli as important severity, while perl-XML-Bare and PackageKit receive moderate ratings. General availability media also received patches for kernel-devel 7.1.4, java-11-openjdk, java-26-openjdk, python313-pandas, and python314 alongside standard fixes for avahi, nmap, and SVT-AV1 libraries. Administrators should review the openSUSE-SU-2026 and SUSE-SU-2026 advisories to apply these corrections before threat actors exploit known flaws in the affected software stacks.

openSUSE-SU-2026:21435-1: moderate: Security update for perl-XML-Bare
openSUSE-SU-2026:21433-1: important: Security update for hauler
openSUSE-SU-2026:21432-1: important: Security update for gh
openSUSE-SU-2026:21426-1: important: Security update for ImageMagick
openSUSE-SU-2026:21429-1: low: Security update for net-tools
openSUSE-SU-2026:21427-1: moderate: Security update for perl-HTTP-Date
openSUSE-SU-2026:21423-1: important: Security update for jline3
openSUSE-SU-2026:21425-1: moderate: Security update for PackageKit
openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp
openSUSE-SU-2026:21422-1: important: Security update for helm
openSUSE-SU-2026:21417-1: moderate: Security update for avahi
openSUSE-SU-2026:21412-1: important: Security update for perl-DBI
openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c
openSUSE-SU-2026:21410-1: important: Security update for glib2
openSUSE-SU-2026:21411-1: important: Security update for perl
openSUSE-SU-2026:21408-1: important: Security update for joe
openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli
openSUSE-SU-2026:11341-1: moderate: python313-pandas-3.0.3-1.2 on GA media
openSUSE-SU-2026:11339-1: moderate: kernel-devel-7.1.4-1.1 on GA media
openSUSE-SU-2026:11342-1: moderate: python313-3.13.14-1.1 on GA media
openSUSE-SU-2026:11343-1: moderate: python314-3.14.6-2.1 on GA media
openSUSE-SU-2026:11340-1: moderate: prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media
openSUSE-SU-2026:11335-1: moderate: java-11-openjdk-11.0.32.0-1.1 on GA media
openSUSE-SU-2026:11334-1: moderate: helm3-3.21.3-3.1 on GA media
openSUSE-SU-2026:11337-1: moderate: java-26-openjdk-26.0.2.0-1.1 on GA media
openSUSE-SU-2026:0259-1: important: Security update for gh
SUSE-SU-2026:3217-1: moderate: Security update for avahi
SUSE-SU-2026:3219-1: important: Security update for ImageMagick
SUSE-SU-2026:3218-1: moderate: Security update for avahi
SUSE-SU-2026:3220-1: moderate: Security update for nmap
SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3




openSUSE-SU-2026:21435-1: moderate: Security update for perl-XML-Bare


openSUSE security update: security update for perl-xml-bare
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21435-1
Rating: moderate
References:

* bsc#1271637
* bsc#1271640

Cross-References:

* CVE-2026-13401
* CVE-2026-57074

CVSS scores:

* CVE-2026-13401 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-57074 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description:

This update for perl-XML-Bare fixes the following issues:

Changes in perl-XML-Bare:

- CVE-2026-13401: XML:Bare would hang when parsing malformed attributes (bsc#1271640)
- CVE-2026-57074: Fixed unbounded character lookahead (bsc#1271637)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-438=1

Package List:

- openSUSE Leap 16.0:

perl-XML-Bare-0.53-bp160.2.1

References:

* https://www.suse.com/security/cve/CVE-2026-13401.html
* https://www.suse.com/security/cve/CVE-2026-57074.html



openSUSE-SU-2026:21433-1: important: Security update for hauler


openSUSE security update: security update for hauler
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21433-1
Rating: important
References:

* bsc#1266602

Cross-References:

* CVE-2026-39821

CVSS scores:

* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for hauler fixes the following issues:

Changes in hauler:

- update embedded dependency x/net to 0.57 to fix CVE-2026-39821 (bsc#1266602)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-436=1

Package List:

- openSUSE Leap 16.0:

hauler-2.0.1-bp160.2.1

References:

* https://www.suse.com/security/cve/CVE-2026-39821.html



openSUSE-SU-2026:21432-1: important: Security update for gh


openSUSE security update: security update for gh
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21432-1
Rating: important
References:

* bsc#1266618

Cross-References:

* CVE-2026-39821

CVSS scores:

* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for gh fixes the following issues:

Changes in gh:

- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored
golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266618).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260723152513362606.93181000773252=1

Package List:

- openSUSE Leap 16.0:

gh-2.96.0-bp160.2.1
gh-bash-completion-2.96.0-bp160.2.1
gh-fish-completion-2.96.0-bp160.2.1
gh-zsh-completion-2.96.0-bp160.2.1

References:

* https://www.suse.com/security/cve/CVE-2026-39821.html



openSUSE-SU-2026:21426-1: important: Security update for ImageMagick


openSUSE security update: security update for imagemagick
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21426-1
Rating: important
References:

* bsc#1268878
* bsc#1271484
* bsc#1271485
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271494
* bsc#1271495
* bsc#1271496
* bsc#1271497

Cross-References:

* CVE-2026-56375
* CVE-2026-56379
* CVE-2026-61464
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61871
* CVE-2026-61872

CVSS scores:

* CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( SUSE ): 1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61871 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61871 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed.

Description:

This update for ImageMagick fixes the following issues

- CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).
- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).
- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).
- CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).
- CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).
- CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).
- CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).
- CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).
- CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).
- CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489).
- CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488).
- CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487).
- CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486).
- CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485).
- CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1337=1

Package List:

- openSUSE Leap 16.0:

ImageMagick-7.1.2.0-160000.13.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1
ImageMagick-devel-7.1.2.0-160000.13.1
ImageMagick-doc-7.1.2.0-160000.13.1
ImageMagick-extra-7.1.2.0-160000.13.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1
libMagick++-devel-7.1.2.0-160000.13.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1
perl-PerlMagick-7.1.2.0-160000.13.1

References:

* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
* https://www.suse.com/security/cve/CVE-2026-61860.html
* https://www.suse.com/security/cve/CVE-2026-61862.html
* https://www.suse.com/security/cve/CVE-2026-61863.html
* https://www.suse.com/security/cve/CVE-2026-61864.html
* https://www.suse.com/security/cve/CVE-2026-61865.html
* https://www.suse.com/security/cve/CVE-2026-61866.html
* https://www.suse.com/security/cve/CVE-2026-61867.html
* https://www.suse.com/security/cve/CVE-2026-61868.html
* https://www.suse.com/security/cve/CVE-2026-61869.html
* https://www.suse.com/security/cve/CVE-2026-61871.html
* https://www.suse.com/security/cve/CVE-2026-61872.html



openSUSE-SU-2026:21429-1: low: Security update for net-tools


openSUSE security update: security update for net-tools
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21429-1
Rating: low
References:

* bsc#1254323

Cross-References:

* CVE-2024-58251

CVSS scores:

* CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
* CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for net-tools fixes the following issue:

- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1340=1

Package List:

- openSUSE Leap 16.0:

net-tools-2.10-160000.4.1
net-tools-deprecated-2.10-160000.4.1
net-tools-lang-2.10-160000.4.1

References:

* https://www.suse.com/security/cve/CVE-2024-58251.html



openSUSE-SU-2026:21427-1: moderate: Security update for perl-HTTP-Date


openSUSE security update: security update for perl-http-date
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21427-1
Rating: moderate
References:

* bsc#1271705

Cross-References:

* CVE-2026-14741

CVSS scores:

* CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for perl-HTTP-Date fixes the following issue

- CVE-2026-14741: CPU exhaustion via polynomial regex backtracking in parse_date (bsc#1271705).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1338=1

Package List:

- openSUSE Leap 16.0:

perl-HTTP-Date-6.06-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-14741.html



openSUSE-SU-2026:21423-1: important: Security update for jline3


openSUSE security update: security update for jline3
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21423-1
Rating: important
References:

* bsc#1269021
* bsc#1270083

Cross-References:

* CVE-2026-56740
* CVE-2026-56741

CVSS scores:

* CVE-2026-56740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56741 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description:

This update for jline3 fixes the following issues:

- CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021).
- CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083).

Changes for jline3:

- Update to upstream version 3.30.15

+ fix: guard regex matching against catastrophic backtracking
(ReDoS) (#2018, backport of #2012):
* Adds SafeRegex utility with TimeoutCharSequence to enforce
wall-clock deadlines during regex matching
* Fixes 8 locations across terminal, reader, and builtins
where user-controlled input could trigger catastrophic
backtracking
* Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx,
GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3
+ fix: backport security hardening (#1986, #1995):
* Create persisted history file with owner-only permissions
* Use exclusive create for extracted native library temp files
+ fix: warn on insecure permissions when history file created
concurrently

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1334=1

Package List:

- openSUSE Leap 16.0:

jline3-3.30.15-160000.1.1
jline3-builtins-3.30.15-160000.1.1
jline3-console-3.30.15-160000.1.1
jline3-console-ui-3.30.15-160000.1.1
jline3-curses-3.30.15-160000.1.1
jline3-jansi-3.30.15-160000.1.1
jline3-jansi-core-3.30.15-160000.1.1
jline3-javadoc-3.30.15-160000.1.1
jline3-native-3.30.15-160000.1.1
jline3-reader-3.30.15-160000.1.1
jline3-remote-telnet-3.30.15-160000.1.1
jline3-style-3.30.15-160000.1.1
jline3-terminal-3.30.15-160000.1.1
jline3-terminal-jansi-3.30.15-160000.1.1
jline3-terminal-jna-3.30.15-160000.1.1
jline3-terminal-jni-3.30.15-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-56740.html
* https://www.suse.com/security/cve/CVE-2026-56741.html



openSUSE-SU-2026:21425-1: moderate: Security update for PackageKit


openSUSE security update: security update for packagekit
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21425-1
Rating: moderate
References:

* bsc#1263252
* bsc#1267250

Cross-References:

* CVE-2026-10294

CVSS scores:

* CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-10294 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has 2 bug fixes can now be installed.

Description:

This update for PackageKit fixes the following issues:

Security issue fixed:

- CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250).

Non security issue fixed:

- KDE Discover ignores package locks (bsc#1263252).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1336=1

Package List:

- openSUSE Leap 16.0:

PackageKit-1.2.8-160000.5.1
PackageKit-backend-dnf-1.2.8-160000.5.1
PackageKit-backend-zypp-1.2.8-160000.5.1
PackageKit-branding-upstream-1.2.8-160000.5.1
PackageKit-devel-1.2.8-160000.5.1
PackageKit-gstreamer-plugin-1.2.8-160000.5.1
PackageKit-gtk3-module-1.2.8-160000.5.1
PackageKit-lang-1.2.8-160000.5.1
libpackagekit-glib2-18-1.2.8-160000.5.1
libpackagekit-glib2-devel-1.2.8-160000.5.1
typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1

References:

* https://www.suse.com/security/cve/CVE-2026-10294.html



openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp


openSUSE security update: security update for shibboleth-sp
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21418-1
Rating: important
References:

* bsc#1249394

Cross-References:

* CVE-2025-9943

CVSS scores:

* CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for shibboleth-sp fixes the following issue

- CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth
Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1329=1

Package List:

- openSUSE Leap 16.0:

libshibsp-lite12-3.5.0-160000.3.1
libshibsp12-3.5.0-160000.3.1
shibboleth-sp-3.5.0-160000.3.1
shibboleth-sp-devel-3.5.0-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2025-9943.html



openSUSE-SU-2026:21422-1: important: Security update for helm


openSUSE security update: security update for helm
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21422-1
Rating: important
References:

* bsc#1266598
* bsc#1271997

Cross-References:

* CVE-2026-39821
* CVE-2026-56852

CVSS scores:

* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description:

This update for helm fixes the following issues

- Update to version 3.21.3
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1333=1

Package List:

- openSUSE Leap 16.0:

helm-3.21.3-160000.1.1
helm-bash-completion-3.21.3-160000.1.1
helm-fish-completion-3.21.3-160000.1.1
helm-zsh-completion-3.21.3-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:21417-1: moderate: Security update for avahi


openSUSE security update: security update for avahi
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21417-1
Rating: moderate
References:

* bsc#1255451

Cross-References:

* CVE-2025-59529

CVSS scores:

* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for avahi fixes the following issues:

- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).

Changes for avahi:

- Make /var/lib/avahi-autoipd a ghost dir instead of packaging it
since avahi-autoipd creates it on start (jsc#PED-14836).
- Use libalternative instead of update-alternatives in TW and SLFO
(jsc#PED-14835).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1328=1

Package List:

- openSUSE Leap 16.0:

avahi-0.8-160000.6.1
avahi-autoipd-0.8-160000.6.1
avahi-compat-howl-devel-0.8-160000.6.1
avahi-compat-mDNSResponder-devel-0.8-160000.6.1
avahi-lang-0.8-160000.6.1
avahi-utils-0.8-160000.6.1
avahi-utils-gtk-0.8-160000.6.1
libavahi-client3-0.8-160000.6.1
libavahi-common3-0.8-160000.6.1
libavahi-core7-0.8-160000.6.1
libavahi-devel-0.8-160000.6.1
libavahi-glib-devel-0.8-160000.6.1
libavahi-glib1-0.8-160000.6.1
libavahi-gobject-devel-0.8-160000.6.1
libavahi-gobject0-0.8-160000.6.1
libavahi-libevent1-0.8-160000.6.1
libavahi-qt6-1-0.8-160000.6.1
libavahi-qt6-devel-0.8-160000.6.1
libavahi-ui-gtk3-0-0.8-160000.6.1
libdns_sd-0.8-160000.6.1
libhowl0-0.8-160000.6.1
python3-avahi-gtk-0.8-160000.6.1
python313-avahi-0.8-160000.6.1
typelib-1_0-Avahi-0_6-0.8-160000.6.1

References:

* https://www.suse.com/security/cve/CVE-2025-59529.html



openSUSE-SU-2026:21412-1: important: Security update for perl-DBI


openSUSE security update: security update for perl-dbi
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21412-1
Rating: important
References:

* bsc#1271399
* bsc#1271458
* bsc#1271459
* bsc#1271629

Cross-References:

* CVE-2026-15043
* CVE-2026-15392
* CVE-2026-60081
* CVE-2026-60082

CVSS scores:

* CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-60082 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.

Description:

This update for perl-DBI fixes the following issues:

- CVE-2026-15392: failure to validate symbolic links during table path resolution could allow unauthorized file reads
and writes outside the configured data director (bsc#1271629).
- CVE-2026-15043: `DBI:SQL:Nano` has incorrect predicate evaluation, which allows for bypass of file-backed filters
(bsc#1271399).
- CVE-2026-60081: `DBI:ProfileData` does not limit the path index in profile parser, which enables small-file
memory-amplification DoS (bsc#1271458).
- CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row,
which allows for a process crash (bsc#1271459).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1322=1

Package List:

- openSUSE Leap 16.0:

perl-DBI-1.647.0-160000.5.1

References:

* https://www.suse.com/security/cve/CVE-2026-15043.html
* https://www.suse.com/security/cve/CVE-2026-15392.html
* https://www.suse.com/security/cve/CVE-2026-60081.html
* https://www.suse.com/security/cve/CVE-2026-60082.html



openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c


openSUSE security update: security update for mariadb-connector-c
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21409-1
Rating: important
References:

* bsc#1266438

Cross-References:

* CVE-2026-44172

CVSS scores:

* CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for mariadb-connector-c fixes the following issue:

- CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438).

Changes for mariadb-connector-c:

- Update to release 3.4.9.

- Update to release 3.4.8:

* Fix compilation with GCC 15
* CONC-762: always set is_null and length in the bind
structure to avoid msan errors
* CONC-763: add MySQL collation ID 309 (utf8mb4_0900_bin)
* CONC-764: fix build of ma_context.c on Android (X18 is a
platform-reserved register)
* CONC-766: disable clang -Wcast-function-type-strict for
makecontext

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1319=1

Package List:

- openSUSE Leap 16.0:

libmariadb-devel-3.4.9-160000.1.1
libmariadb3-3.4.9-160000.1.1
libmariadb_plugins-3.4.9-160000.1.1
libmariadbprivate-3.4.9-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-44172.html



openSUSE-SU-2026:21410-1: important: Security update for glib2


openSUSE security update: security update for glib2
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21410-1
Rating: important
References:

* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021

Cross-References:

* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016

CVSS scores:

* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.

Description:

This update for glib2 fixes the following issues:

- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
(bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1320=1

Package List:

- openSUSE Leap 16.0:

gio-branding-upstream-2.84.4-160000.4.1
glib2-devel-2.84.4-160000.4.1
glib2-devel-static-2.84.4-160000.4.1
glib2-doc-2.84.4-160000.4.1
glib2-lang-2.84.4-160000.4.1
glib2-tests-devel-2.84.4-160000.4.1
glib2-tools-2.84.4-160000.4.1
libgio-2_0-0-2.84.4-160000.4.1
libgirepository-2_0-0-2.84.4-160000.4.1
libglib-2_0-0-2.84.4-160000.4.1
libgmodule-2_0-0-2.84.4-160000.4.1
libgobject-2_0-0-2.84.4-160000.4.1
libgthread-2_0-0-2.84.4-160000.4.1
typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1
typelib-1_0-GLib-2_0-2.84.4-160000.4.1
typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1
typelib-1_0-GModule-2_0-2.84.4-160000.4.1
typelib-1_0-GObject-2_0-2.84.4-160000.4.1
typelib-1_0-Gio-2_0-2.84.4-160000.4.1

References:

* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html



openSUSE-SU-2026:21411-1: important: Security update for perl


openSUSE security update: security update for perl
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21411-1
Rating: important
References:

* bsc#1266304
* bsc#1266361
* bsc#1268349
* bsc#1271372
* bsc#1271386

Cross-References:

* CVE-2025-15649
* CVE-2026-12087
* CVE-2026-13221
* CVE-2026-57432
* CVE-2026-8376

CVSS scores:

* CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57432 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-8376 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

Description:

This update for perl fixes the following issues:

- CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date
(bsc#1266361).
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
- CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching
(bsc#1271386).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1321=1

Package List:

- openSUSE Leap 16.0:

perl-5.42.0-160000.3.1
perl-base-5.42.0-160000.3.1
perl-doc-5.42.0-160000.3.1

References:

* https://www.suse.com/security/cve/CVE-2025-15649.html
* https://www.suse.com/security/cve/CVE-2026-12087.html
* https://www.suse.com/security/cve/CVE-2026-13221.html
* https://www.suse.com/security/cve/CVE-2026-57432.html
* https://www.suse.com/security/cve/CVE-2026-8376.html



openSUSE-SU-2026:21408-1: important: Security update for joe


openSUSE security update: security update for joe
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21408-1
Rating: important
References:

* bsc#1269379

Cross-References:

* CVE-2026-13412

CVSS scores:

* CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for joe fixes the following issue

- CVE-2026-13412: improper validation in tag-file parser can lead to arbitrary command execution (bsc#1269379).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1318=1

Package List:

- openSUSE Leap 16.0:

joe-4.6-160000.4.1

References:

* https://www.suse.com/security/cve/CVE-2026-13412.html



openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli


openSUSE security update: security update for aws-nitro-enclaves-cli
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21406-1
Rating: important
References:

* bsc#1270492
* bsc#1270542
* bsc#1270705
* bsc#1270747
* bsc#1270839
* bsc#1270932
* bsc#1270952

Cross-References:

* CVE-2026-41677
* CVE-2026-41678
* CVE-2026-41681
* CVE-2026-41898
* CVE-2026-42327
* CVE-2026-44662
* CVE-2026-45784

CVSS scores:

* CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.

Description:

This update for aws-nitro-enclaves-cli fixes the following issues:

- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
openssl crate (bsc#1270542).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270705).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
(bsc#1270747).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
memory in rust-openssl crate (bsc#1270839).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
(bsc#1270492).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
(bsc#1270932).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
openssl crate (bsc#1270952).

Changes for aws-nitro-enclaves-cli:

- Update to version 1.4.5.

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1316=1

Package List:

- openSUSE Leap 16.0:

aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1
aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1
system-group-ne-1.4.5~git0.18a5f6f-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html



openSUSE-SU-2026:11341-1: moderate: python313-pandas-3.0.3-1.2 on GA media


# python313-pandas-3.0.3-1.2 on GA media

Announcement ID: openSUSE-SU-2026:11341-1
Rating: moderate

Cross-References:

* CVE-2023-47248

CVSS scores:

* CVE-2023-47248 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-pandas-3.0.3-1.2 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-pandas 3.0.3-1.2
* python313-pandas-all 3.0.3-1.2
* python313-pandas-clipboard 3.0.3-1.2
* python313-pandas-compression 3.0.3-1.2
* python313-pandas-computation 3.0.3-1.2
* python313-pandas-excel 3.0.3-1.2
* python313-pandas-feather 3.0.3-1.2
* python313-pandas-fss 3.0.3-1.2
* python313-pandas-hdf5 3.0.3-1.2
* python313-pandas-html 3.0.3-1.2
* python313-pandas-mysql 3.0.3-1.2
* python313-pandas-output_formatting 3.0.3-1.2
* python313-pandas-parquet 3.0.3-1.2
* python313-pandas-performance 3.0.3-1.2
* python313-pandas-plot 3.0.3-1.2
* python313-pandas-postgresql 3.0.3-1.2
* python313-pandas-pyarrow 3.0.3-1.2
* python313-pandas-spss 3.0.3-1.2
* python313-pandas-sql-other 3.0.3-1.2
* python313-pandas-test 3.0.3-1.2
* python313-pandas-xml 3.0.3-1.2
* python314-pandas 3.0.3-1.2
* python314-pandas-all 3.0.3-1.2
* python314-pandas-clipboard 3.0.3-1.2
* python314-pandas-compression 3.0.3-1.2
* python314-pandas-computation 3.0.3-1.2
* python314-pandas-excel 3.0.3-1.2
* python314-pandas-feather 3.0.3-1.2
* python314-pandas-fss 3.0.3-1.2
* python314-pandas-hdf5 3.0.3-1.2
* python314-pandas-html 3.0.3-1.2
* python314-pandas-mysql 3.0.3-1.2
* python314-pandas-output_formatting 3.0.3-1.2
* python314-pandas-parquet 3.0.3-1.2
* python314-pandas-performance 3.0.3-1.2
* python314-pandas-plot 3.0.3-1.2
* python314-pandas-postgresql 3.0.3-1.2
* python314-pandas-pyarrow 3.0.3-1.2
* python314-pandas-spss 3.0.3-1.2
* python314-pandas-sql-other 3.0.3-1.2
* python314-pandas-test 3.0.3-1.2
* python314-pandas-xml 3.0.3-1.2

## References:

* https://www.suse.com/security/cve/CVE-2023-47248.html



openSUSE-SU-2026:11339-1: moderate: kernel-devel-7.1.4-1.1 on GA media


# kernel-devel-7.1.4-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11339-1
Rating: moderate

Cross-References:

* CVE-2026-53366
* CVE-2026-53381
* CVE-2026-53382
* CVE-2026-53383
* CVE-2026-53384
* CVE-2026-53385
* CVE-2026-53386
* CVE-2026-53387
* CVE-2026-53388
* CVE-2026-53389
* CVE-2026-53390
* CVE-2026-53391
* CVE-2026-53392
* CVE-2026-53393
* CVE-2026-53394
* CVE-2026-53395
* CVE-2026-53396
* CVE-2026-53397
* CVE-2026-53398
* CVE-2026-53399
* CVE-2026-53400
* CVE-2026-53401
* CVE-2026-53402
* CVE-2026-53403
* CVE-2026-63793
* CVE-2026-63794
* CVE-2026-63795
* CVE-2026-63796
* CVE-2026-63797
* CVE-2026-63798
* CVE-2026-63799
* CVE-2026-63800
* CVE-2026-63801
* CVE-2026-63802
* CVE-2026-63803
* CVE-2026-63804
* CVE-2026-63805
* CVE-2026-63806
* CVE-2026-63807
* CVE-2026-63808
* CVE-2026-63809
* CVE-2026-63810
* CVE-2026-63811
* CVE-2026-63812
* CVE-2026-63813
* CVE-2026-63814
* CVE-2026-63815
* CVE-2026-63816
* CVE-2026-63817
* CVE-2026-63818
* CVE-2026-63819
* CVE-2026-63820
* CVE-2026-63821
* CVE-2026-63822
* CVE-2026-63823
* CVE-2026-63824
* CVE-2026-63825
* CVE-2026-63826
* CVE-2026-63827
* CVE-2026-63828
* CVE-2026-63829
* CVE-2026-63830
* CVE-2026-63831
* CVE-2026-63832
* CVE-2026-63833
* CVE-2026-63834
* CVE-2026-63835
* CVE-2026-63836

CVSS scores:

* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53382 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53383 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53384 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53384 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53385 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53385 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53387 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-53387 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53390 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53391 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53392 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-53392 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53393 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-53393 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53394 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53394 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53395 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53395 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53396 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53396 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53397 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53397 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53398 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-53398 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-53399 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53399 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53400 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53400 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53401 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53401 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53402 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53402 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63793 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63793 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63794 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63794 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63795 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63797 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63797 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63798 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63798 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63799 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-63799 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63800 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63800 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63802 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63802 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63803 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63803 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63804 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63804 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63805 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63805 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63806 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63806 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63807 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
* CVE-2026-63807 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63809 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63809 ( SUSE ): 8.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63811 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63811 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63812 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63812 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63813 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63813 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63814 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63814 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63815 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63815 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63816 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
* CVE-2026-63816 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63817 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63817 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63818 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63818 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63819 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63819 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63820 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63820 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63821 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63821 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63822 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63824 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63825 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63825 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63826 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63826 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-63829 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-63829 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63830 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63831 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63831 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63832 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63832 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63833 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-63833 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-63834 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63834 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63835 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63835 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63836 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63836 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 68 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the kernel-devel-7.1.4-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* kernel-devel 7.1.4-1.1
* kernel-macros 7.1.4-1.1
* kernel-source 7.1.4-1.1
* kernel-source-vanilla 7.1.4-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://www.suse.com/security/cve/CVE-2026-53381.html
* https://www.suse.com/security/cve/CVE-2026-53382.html
* https://www.suse.com/security/cve/CVE-2026-53383.html
* https://www.suse.com/security/cve/CVE-2026-53384.html
* https://www.suse.com/security/cve/CVE-2026-53385.html
* https://www.suse.com/security/cve/CVE-2026-53386.html
* https://www.suse.com/security/cve/CVE-2026-53387.html
* https://www.suse.com/security/cve/CVE-2026-53388.html
* https://www.suse.com/security/cve/CVE-2026-53389.html
* https://www.suse.com/security/cve/CVE-2026-53390.html
* https://www.suse.com/security/cve/CVE-2026-53391.html
* https://www.suse.com/security/cve/CVE-2026-53392.html
* https://www.suse.com/security/cve/CVE-2026-53393.html
* https://www.suse.com/security/cve/CVE-2026-53394.html
* https://www.suse.com/security/cve/CVE-2026-53395.html
* https://www.suse.com/security/cve/CVE-2026-53396.html
* https://www.suse.com/security/cve/CVE-2026-53397.html
* https://www.suse.com/security/cve/CVE-2026-53398.html
* https://www.suse.com/security/cve/CVE-2026-53399.html
* https://www.suse.com/security/cve/CVE-2026-53400.html
* https://www.suse.com/security/cve/CVE-2026-53401.html
* https://www.suse.com/security/cve/CVE-2026-53402.html
* https://www.suse.com/security/cve/CVE-2026-53403.html
* https://www.suse.com/security/cve/CVE-2026-63793.html
* https://www.suse.com/security/cve/CVE-2026-63794.html
* https://www.suse.com/security/cve/CVE-2026-63795.html
* https://www.suse.com/security/cve/CVE-2026-63796.html
* https://www.suse.com/security/cve/CVE-2026-63797.html
* https://www.suse.com/security/cve/CVE-2026-63798.html
* https://www.suse.com/security/cve/CVE-2026-63799.html
* https://www.suse.com/security/cve/CVE-2026-63800.html
* https://www.suse.com/security/cve/CVE-2026-63801.html
* https://www.suse.com/security/cve/CVE-2026-63802.html
* https://www.suse.com/security/cve/CVE-2026-63803.html
* https://www.suse.com/security/cve/CVE-2026-63804.html
* https://www.suse.com/security/cve/CVE-2026-63805.html
* https://www.suse.com/security/cve/CVE-2026-63806.html
* https://www.suse.com/security/cve/CVE-2026-63807.html
* https://www.suse.com/security/cve/CVE-2026-63808.html
* https://www.suse.com/security/cve/CVE-2026-63809.html
* https://www.suse.com/security/cve/CVE-2026-63810.html
* https://www.suse.com/security/cve/CVE-2026-63811.html
* https://www.suse.com/security/cve/CVE-2026-63812.html
* https://www.suse.com/security/cve/CVE-2026-63813.html
* https://www.suse.com/security/cve/CVE-2026-63814.html
* https://www.suse.com/security/cve/CVE-2026-63815.html
* https://www.suse.com/security/cve/CVE-2026-63816.html
* https://www.suse.com/security/cve/CVE-2026-63817.html
* https://www.suse.com/security/cve/CVE-2026-63818.html
* https://www.suse.com/security/cve/CVE-2026-63819.html
* https://www.suse.com/security/cve/CVE-2026-63820.html
* https://www.suse.com/security/cve/CVE-2026-63821.html
* https://www.suse.com/security/cve/CVE-2026-63822.html
* https://www.suse.com/security/cve/CVE-2026-63823.html
* https://www.suse.com/security/cve/CVE-2026-63824.html
* https://www.suse.com/security/cve/CVE-2026-63825.html
* https://www.suse.com/security/cve/CVE-2026-63826.html
* https://www.suse.com/security/cve/CVE-2026-63827.html
* https://www.suse.com/security/cve/CVE-2026-63828.html
* https://www.suse.com/security/cve/CVE-2026-63829.html
* https://www.suse.com/security/cve/CVE-2026-63830.html
* https://www.suse.com/security/cve/CVE-2026-63831.html
* https://www.suse.com/security/cve/CVE-2026-63832.html
* https://www.suse.com/security/cve/CVE-2026-63833.html
* https://www.suse.com/security/cve/CVE-2026-63834.html
* https://www.suse.com/security/cve/CVE-2026-63835.html
* https://www.suse.com/security/cve/CVE-2026-63836.html



openSUSE-SU-2026:11342-1: moderate: python313-3.13.14-1.1 on GA media


# python313-3.13.14-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11342-1
Rating: moderate

Cross-References:

* CVE-2021-4189
* CVE-2025-15366
* CVE-2025-15367
* CVE-2026-11940
* CVE-2026-7210
* CVE-2026-8328

CVSS scores:

* CVE-2021-4189 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
* CVE-2025-15366 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
* CVE-2025-15367 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-3.13.14-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313 3.13.14-1.1
* python313-32bit 3.13.14-1.1
* python313-curses 3.13.14-1.1
* python313-dbm 3.13.14-1.1
* python313-idle 3.13.14-1.1
* python313-tk 3.13.14-1.1
* python313-x86-64-v3 3.13.14-1.1

## References:

* https://www.suse.com/security/cve/CVE-2021-4189.html
* https://www.suse.com/security/cve/CVE-2025-15366.html
* https://www.suse.com/security/cve/CVE-2025-15367.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-8328.html



openSUSE-SU-2026:11343-1: moderate: python314-3.14.6-2.1 on GA media


# python314-3.14.6-2.1 on GA media

Announcement ID: openSUSE-SU-2026:11343-1
Rating: moderate

Cross-References:

* CVE-2026-11940

CVSS scores:

* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python314-3.14.6-2.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python314 3.14.6-2.1
* python314-32bit 3.14.6-2.1
* python314-curses 3.14.6-2.1
* python314-dbm 3.14.6-2.1
* python314-idle 3.14.6-2.1
* python314-tk 3.14.6-2.1
* python314-x86-64-v3 3.14.6-2.1

## References:

* https://www.suse.com/security/cve/CVE-2026-11940.html



openSUSE-SU-2026:11340-1: moderate: prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media


# prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11340-1
Rating: moderate

Cross-References:

* CVE-2026-39821

CVSS scores:

* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the prometheus-ha_cluster_exporter-1.4.2-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* prometheus-ha_cluster_exporter 1.4.2-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-39821.html



openSUSE-SU-2026:11335-1: moderate: java-11-openjdk-11.0.32.0-1.1 on GA media


# java-11-openjdk-11.0.32.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11335-1
Rating: moderate

Cross-References:

* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47057
* CVE-2026-47058
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147

CVSS scores:

* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 11 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-11-openjdk-11.0.32.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-11-openjdk 11.0.32.0-1.1
* java-11-openjdk-demo 11.0.32.0-1.1
* java-11-openjdk-devel 11.0.32.0-1.1
* java-11-openjdk-headless 11.0.32.0-1.1
* java-11-openjdk-javadoc 11.0.32.0-1.1
* java-11-openjdk-jmods 11.0.32.0-1.1
* java-11-openjdk-src 11.0.32.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47057.html
* https://www.suse.com/security/cve/CVE-2026-47058.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html



openSUSE-SU-2026:11334-1: moderate: helm3-3.21.3-3.1 on GA media


# helm3-3.21.3-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11334-1
Rating: moderate

Cross-References:

* CVE-2026-56852

CVSS scores:

* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the helm3-3.21.3-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* helm3 3.21.3-3.1
* helm3-bash-completion 3.21.3-3.1
* helm3-fish-completion 3.21.3-3.1
* helm3-zsh-completion 3.21.3-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:11337-1: moderate: java-26-openjdk-26.0.2.0-1.1 on GA media


# java-26-openjdk-26.0.2.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11337-1
Rating: moderate

Cross-References:

* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147

CVSS scores:

* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 8 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the java-26-openjdk-26.0.2.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* java-26-openjdk 26.0.2.0-1.1
* java-26-openjdk-demo 26.0.2.0-1.1
* java-26-openjdk-devel 26.0.2.0-1.1
* java-26-openjdk-headless 26.0.2.0-1.1
* java-26-openjdk-javadoc 26.0.2.0-1.1
* java-26-openjdk-jmods 26.0.2.0-1.1
* java-26-openjdk-src 26.0.2.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html



openSUSE-SU-2026:0259-1: important: Security update for gh


openSUSE Security Update: Security update for gh
_______________________________

Announcement ID: openSUSE-SU-2026:0259-1
Rating: important
References: #1266618
Cross-References: CVE-2026-39821
CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for gh fixes the following issues:

- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored
golang.org/x/net/idna package regardless of Go's unicode.Version
(boo#1266618).

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-259=1

Package List:

- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

gh-2.96.0-bp157.2.24.1

- openSUSE Backports SLE-15-SP7 (noarch):

gh-bash-completion-2.96.0-bp157.2.24.1
gh-fish-completion-2.96.0-bp157.2.24.1
gh-zsh-completion-2.96.0-bp157.2.24.1

References:

https://www.suse.com/security/cve/CVE-2026-39821.html
https://bugzilla.suse.com/1266618



SUSE-SU-2026:3217-1: moderate: Security update for avahi


# Security update for avahi

Announcement ID: SUSE-SU-2026:3217-1
Release Date: 2026-07-23T17:33:52Z
Rating: moderate
References:

* bsc#1255451

Cross-References:

* CVE-2025-59529

CVSS scores:

* CVE-2025-59529 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4

An update that solves one vulnerability can now be installed.

## Description:

This update for avahi fixes the following issue:

* CVE-2025-59529: local DoS due to simple protocol server ignoring client
limit CLIENTS_MAX (bsc#1255451).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3217=1

* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1

* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1

* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1

* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3217=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* avahi-autoipd-debuginfo-0.8-150400.7.34.1
* python3-avahi-0.8-150400.7.34.1
* libhowl0-debuginfo-0.8-150400.7.34.1
* avahi-utils-gtk-debuginfo-0.8-150400.7.34.1
* libavahi-gobject0-debuginfo-0.8-150400.7.34.1
* libavahi-qt5-1-0.8-150400.7.34.1
* avahi-autoipd-0.8-150400.7.34.1
* python3-avahi-gtk-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* libavahi-qt5-1-debuginfo-0.8-150400.7.34.1
* libavahi-glib-devel-0.8-150400.7.34.1
* libavahi-glib1-0.8-150400.7.34.1
* libdns_sd-0.8-150400.7.34.1
* avahi-compat-mDNSResponder-devel-0.8-150400.7.34.1
* libhowl0-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150400.7.34.1
* avahi-compat-howl-devel-0.8-150400.7.34.1
* avahi-qt5-debugsource-0.8-150400.7.34.1
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-debuginfo-0.8-150400.7.34.1
* libdns_sd-debuginfo-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* libavahi-libevent1-0.8-150400.7.34.1
* libavahi-devel-0.8-150400.7.34.1
* libavahi-ui-gtk3-0-0.8-150400.7.34.1
* avahi-utils-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* avahi-utils-0.8-150400.7.34.1
* libavahi-qt5-devel-0.8-150400.7.34.1
* typelib-1_0-Avahi-0_6-0.8-150400.7.34.1
* libavahi-libevent1-debuginfo-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* libavahi-gobject0-0.8-150400.7.34.1
* avahi-utils-gtk-0.8-150400.7.34.1
* libavahi-gobject-devel-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* avahi-glib2-debugsource-0.8-150400.7.34.1
* openSUSE Leap 15.4 (noarch)
* avahi-lang-0.8-150400.7.34.1
* openSUSE Leap 15.4 (x86_64)
* libavahi-client3-32bit-0.8-150400.7.34.1
* libavahi-client3-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-32bit-debuginfo-0.8-150400.7.34.1
* libdns_sd-32bit-0.8-150400.7.34.1
* libavahi-glib1-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-32bit-0.8-150400.7.34.1
* libdns_sd-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-32bit-0.8-150400.7.34.1
* avahi-32bit-debuginfo-0.8-150400.7.34.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libavahi-client3-64bit-0.8-150400.7.34.1
* libdns_sd-64bit-0.8-150400.7.34.1
* libavahi-client3-64bit-debuginfo-0.8-150400.7.34.1
* libdns_sd-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-64bit-debuginfo-0.8-150400.7.34.1
* avahi-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-64bit-0.8-150400.7.34.1
* libavahi-glib1-64bit-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1

## References:

* https://www.suse.com/security/cve/CVE-2025-59529.html
* https://bugzilla.suse.com/show_bug.cgi?id55451



SUSE-SU-2026:3219-1: important: Security update for ImageMagick


# Security update for ImageMagick

Announcement ID: SUSE-SU-2026:3219-1
Release Date: 2026-07-23T17:35:28Z
Rating: important
References:

* bsc#1268640
* bsc#1268878
* bsc#1270006
* bsc#1270081
* bsc#1271100
* bsc#1271293
* bsc#1271294
* bsc#1271311
* bsc#1271312
* bsc#1271313
* bsc#1271314
* bsc#1271315
* bsc#1271316
* bsc#1271484
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271494
* bsc#1271495
* bsc#1271496
* bsc#1271497

Cross-References:

* CVE-2026-55628
* CVE-2026-56362
* CVE-2026-56366
* CVE-2026-56372
* CVE-2026-56373
* CVE-2026-56375
* CVE-2026-56377
* CVE-2026-56379
* CVE-2026-61464
* CVE-2026-61465
* CVE-2026-61857
* CVE-2026-61858
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61861
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61870
* CVE-2026-61872

CVSS scores:

* CVE-2026-55628 ( SUSE ): 6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-56362 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56362 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56366 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56366 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-56372 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56372 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-56373 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56373 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56377 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56377 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56379 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-61464 ( SUSE ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( NVD ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-61857 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61857 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61858 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61858 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61859 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61859 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61860 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61860 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61862 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61862 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61863 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61863 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61867 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61867 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61870 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61870 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( NVD ): 2.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

Affected Products:

* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves 25 vulnerabilities and has one security fix can now be
installed.

## Description:

This update for ImageMagick fixes the following issues:

* CVE-2026-55628: policy bypass in concatenate operation due to missing checks
(bsc#1270081).
* CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to
metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).
* CVE-2026-56366: META reader memory leak in the APP1JPEG input path
(bsc#1271316).
* CVE-2026-56372: heap buffer overflow read in magnify operation via
unrecognized `magnify:method` value (bsc#1271314).
* CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640,
bsc#1271315).
* CVE-2026-56375: possible memory leak in ASHLAR coder when action fails
(bsc#1271495).
* CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).
* CVE-2026-61464: heap buffer overwrite in X11 import with crafted window
title (bsc#1271496).
* CVE-2026-61465: policy bypass possible with matrix-backed operations
(bsc#1271313).
* CVE-2026-61857: heap use-after-free via XMP profile could result in a crash
(bsc#1271312).
* CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing
check (bsc#1271311).
* CVE-2026-61859: policy bypass in script operation due to missing checks
(bsc#1271497).
* CVE-2026-61860: use-after-free when `freetype` initialization fails
(bsc#1271494).
* CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory
allocation fails (bsc#1271294).
* CVE-2026-61862: information disclosure when printing profiles with debug
enabled (bsc#1271493).
* CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not
be created (bsc#1271492).
* CVE-2026-61864: memory leak in color transformation to log colorspace when
operation fails (bsc#1271491).
* CVE-2026-61865: memory leak in hough lines operation when an operation fails
(bsc#1271490).
* CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened
(bsc#1271489).
* CVE-2026-61867: memory leak in TIFF encoder when an allocation fails
(bsc#1271488).
* CVE-2026-61868: memory leak in YUV decoder when opening of blob fails
(bsc#1271487).
* CVE-2026-61869: memory leak in MIFF encoder when allocation fails
(bsc#1271486).
* CVE-2026-61870: memory leak in VIFF encoder when allocation fails
(bsc#1271293).
* CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-
geometry` is specified (bsc#1271484).
* Extend CVE-2026-56379 patch by f63c78b (bsc#1268878).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3219=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3219=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3219=1

## Package List:

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libMagick++-devel-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2
* libMagick++-devel-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-extra-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-extra-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libMagick++-7_Q16HDRI5-64bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2
* libMagick++-devel-64bit-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-devel-64bit-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (x86_64)
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-devel-32bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2
* libMagick++-devel-32bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-32bit-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (noarch)
* ImageMagick-doc-7.1.1.21-150600.3.80.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* libMagick++-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2

## References:

* https://www.suse.com/security/cve/CVE-2026-55628.html
* https://www.suse.com/security/cve/CVE-2026-56362.html
* https://www.suse.com/security/cve/CVE-2026-56366.html
* https://www.suse.com/security/cve/CVE-2026-56372.html
* https://www.suse.com/security/cve/CVE-2026-56373.html
* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-56377.html
* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61465.html
* https://www.suse.com/security/cve/CVE-2026-61857.html
* https://www.suse.com/security/cve/CVE-2026-61858.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
* https://www.suse.com/security/cve/CVE-2026-61860.html
* https://www.suse.com/security/cve/CVE-2026-61861.html
* https://www.suse.com/security/cve/CVE-2026-61862.html
* https://www.suse.com/security/cve/CVE-2026-61863.html
* https://www.suse.com/security/cve/CVE-2026-61864.html
* https://www.suse.com/security/cve/CVE-2026-61865.html
* https://www.suse.com/security/cve/CVE-2026-61866.html
* https://www.suse.com/security/cve/CVE-2026-61867.html
* https://www.suse.com/security/cve/CVE-2026-61868.html
* https://www.suse.com/security/cve/CVE-2026-61869.html
* https://www.suse.com/security/cve/CVE-2026-61870.html
* https://www.suse.com/security/cve/CVE-2026-61872.html
* https://bugzilla.suse.com/show_bug.cgi?id68640
* https://bugzilla.suse.com/show_bug.cgi?id68878
* https://bugzilla.suse.com/show_bug.cgi?id70006
* https://bugzilla.suse.com/show_bug.cgi?id70081
* https://bugzilla.suse.com/show_bug.cgi?id71100
* https://bugzilla.suse.com/show_bug.cgi?id71293
* https://bugzilla.suse.com/show_bug.cgi?id71294
* https://bugzilla.suse.com/show_bug.cgi?id71311
* https://bugzilla.suse.com/show_bug.cgi?id71312
* https://bugzilla.suse.com/show_bug.cgi?id71313
* https://bugzilla.suse.com/show_bug.cgi?id71314
* https://bugzilla.suse.com/show_bug.cgi?id71315
* https://bugzilla.suse.com/show_bug.cgi?id71316
* https://bugzilla.suse.com/show_bug.cgi?id71484
* https://bugzilla.suse.com/show_bug.cgi?id71486
* https://bugzilla.suse.com/show_bug.cgi?id71487
* https://bugzilla.suse.com/show_bug.cgi?id71488
* https://bugzilla.suse.com/show_bug.cgi?id71489
* https://bugzilla.suse.com/show_bug.cgi?id71490
* https://bugzilla.suse.com/show_bug.cgi?id71491
* https://bugzilla.suse.com/show_bug.cgi?id71492
* https://bugzilla.suse.com/show_bug.cgi?id71493
* https://bugzilla.suse.com/show_bug.cgi?id71494
* https://bugzilla.suse.com/show_bug.cgi?id71495
* https://bugzilla.suse.com/show_bug.cgi?id71496
* https://bugzilla.suse.com/show_bug.cgi?id71497



SUSE-SU-2026:3218-1: moderate: Security update for avahi


# Security update for avahi

Announcement ID: SUSE-SU-2026:3218-1
Release Date: 2026-07-23T17:34:30Z
Rating: moderate
References:

* bsc#1255451

Cross-References:

* CVE-2025-59529

CVSS scores:

* CVE-2025-59529 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for avahi fixes the following issue:

* CVE-2025-59529: local DoS due to simple protocol server ignoring client
limit CLIENTS_MAX (bsc#1255451).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3218=1

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3218=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3218=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3218=1

## Package List:

* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libavahi-gobject0-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1
* avahi-utils-debuginfo-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* libdns_sd-debuginfo-0.8-150600.15.21.1
* libhowl0-debuginfo-0.8-150600.15.21.1
* typelib-1_0-Avahi-0_6-0.8-150600.15.21.1
* libavahi-client3-0.8-150600.15.21.1
* avahi-utils-0.8-150600.15.21.1
* libavahi-glib1-debuginfo-0.8-150600.15.21.1
* avahi-0.8-150600.15.21.1
* avahi-compat-howl-devel-0.8-150600.15.21.1
* libavahi-glib-devel-0.8-150600.15.21.1
* libhowl0-0.8-150600.15.21.1
* libdns_sd-0.8-150600.15.21.1
* libavahi-glib1-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-core7-0.8-150600.15.21.1
* libavahi-common3-debuginfo-0.8-150600.15.21.1
* libavahi-gobject0-0.8-150600.15.21.1
* libavahi-core7-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-0.8-150600.15.21.1
* libavahi-common3-0.8-150600.15.21.1
* libavahi-devel-0.8-150600.15.21.1
* libavahi-client3-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-debuginfo-0.8-150600.15.21.1
* Basesystem Module 15-SP7 (x86_64)
* libavahi-client3-32bit-0.8-150600.15.21.1
* libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1
* avahi-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-0.8-150600.15.21.1
* libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1
* Basesystem Module 15-SP7 (noarch)
* avahi-lang-0.8-150600.15.21.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python3-avahi-0.8-150600.15.21.1
* libavahi-gobject0-debuginfo-0.8-150600.15.21.1
* libavahi-qt5-1-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-0.8-150600.15.21.1
* avahi-utils-gtk-0.8-150600.15.21.1
* python3-avahi-gtk-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1
* avahi-utils-debuginfo-0.8-150600.15.21.1
* avahi-qt5-debugsource-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* libhowl0-debuginfo-0.8-150600.15.21.1
* libdns_sd-debuginfo-0.8-150600.15.21.1
* libavahi-qt5-1-0.8-150600.15.21.1
* libavahi-qt5-devel-0.8-150600.15.21.1
* typelib-1_0-Avahi-0_6-0.8-150600.15.21.1
* libavahi-client3-0.8-150600.15.21.1
* avahi-utils-0.8-150600.15.21.1
* libavahi-glib1-debuginfo-0.8-150600.15.21.1
* libavahi-gobject-devel-0.8-150600.15.21.1
* avahi-0.8-150600.15.21.1
* avahi-compat-howl-devel-0.8-150600.15.21.1
* libavahi-glib-devel-0.8-150600.15.21.1
* avahi-autoipd-debuginfo-0.8-150600.15.21.1
* libhowl0-0.8-150600.15.21.1
* libdns_sd-0.8-150600.15.21.1
* libavahi-glib1-0.8-150600.15.21.1
* avahi-autoipd-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-core7-0.8-150600.15.21.1
* libavahi-common3-debuginfo-0.8-150600.15.21.1
* libavahi-gobject0-0.8-150600.15.21.1
* libavahi-core7-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-0.8-150600.15.21.1
* libavahi-common3-0.8-150600.15.21.1
* libavahi-devel-0.8-150600.15.21.1
* libavahi-client3-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-debuginfo-0.8-150600.15.21.1
* avahi-utils-gtk-debuginfo-0.8-150600.15.21.1
* openSUSE Leap 15.6 (x86_64)
* libavahi-client3-32bit-0.8-150600.15.21.1
* libavahi-glib1-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1
* avahi-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-0.8-150600.15.21.1
* libdns_sd-32bit-0.8-150600.15.21.1
* libdns_sd-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-glib1-32bit-0.8-150600.15.21.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libdns_sd-64bit-0.8-150600.15.21.1
* libavahi-glib1-64bit-0.8-150600.15.21.1
* libdns_sd-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-64bit-0.8-150600.15.21.1
* avahi-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-glib1-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-64bit-0.8-150600.15.21.1
* libavahi-common3-64bit-debuginfo-0.8-150600.15.21.1
* openSUSE Leap 15.6 (noarch)
* avahi-lang-0.8-150600.15.21.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* avahi-autoipd-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-utils-gtk-0.8-150600.15.21.1
* avahi-autoipd-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-gobject-devel-0.8-150600.15.21.1
* avahi-utils-gtk-debuginfo-0.8-150600.15.21.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* python3-avahi-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1

## References:

* https://www.suse.com/security/cve/CVE-2025-59529.html
* https://bugzilla.suse.com/show_bug.cgi?id55451



SUSE-SU-2026:3220-1: moderate: Security update for nmap


# Security update for nmap

Announcement ID: SUSE-SU-2026:3220-1
Release Date: 2026-07-23T17:37:38Z
Rating: moderate
References:

* bsc#1269570

Cross-References:

* CVE-2026-58058

CVSS scores:

* CVE-2026-58058 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58058 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products:

* openSUSE Leap 15.4

An update that solves one vulnerability can now be installed.

## Description:

This update for nmap fixes the following issue:

* CVE-2026-58058: crafted IPv6 response with a truncated extension header can
trigger out-of-bounds reads and a crash (bsc#1269570).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3220=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ncat-debuginfo-7.92-150400.3.3.1
* ncat-7.92-150400.3.3.1
* nmap-debuginfo-7.92-150400.3.3.1
* nping-7.92-150400.3.3.1
* nmap-7.92-150400.3.3.1
* nping-debuginfo-7.92-150400.3.3.1
* nmap-debugsource-7.92-150400.3.3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58058.html
* https://bugzilla.suse.com/show_bug.cgi?id69570



SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3


# Security update for SVT-AV1, libyuv0, libaom3

Announcement ID: SUSE-SU-2026:3224-1
Release Date: 2026-07-23T18:34:25Z
Rating: important
References:

* bsc#1263678
* bsc#1268242
* bsc#1268650
* bsc#1268651
* bsc#1268653
* bsc#1268655

Cross-References:

* CVE-2026-56208
* CVE-2026-56209
* CVE-2026-56210
* CVE-2026-56211

CVSS scores:

* CVE-2026-56208 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
* CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-56209 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
* CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
* CVE-2026-56210 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56211 ( SUSE ): 7.5
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
* CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves four vulnerabilities and has two security fixes can now be
installed.

## Description:

This update for SVT-AV1, libyuv0, libaom3 fixes the following issues:

* CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-
based buffer overflow and a process crash (bsc#1268650).
* CVE-2026-56209: crafted video frames with specific Y-plane pixel values can
lead to an arbitrary memory write (bsc#1268651).
* CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-
of-bounds heap read (bsc#1268653).
* CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to
remote code execution (bsc#1268655).

Bug fixes:

* Add SVT-AV1, libyuv0, libaom3 to Basesystem, no source changes.
(bsc#1263678).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3224=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3224=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3224=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3224=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3224=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* aom-tools-3.7.1-150600.3.9.1
* libaom3-debuginfo-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* openSUSE Leap 15.6 (aarch64 x86_64)
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Dec0-1.8.0-150600.3.2.5
* SVT-AV1-devel-1.8.0-150600.3.2.5
* libSvtAv1Dec0-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-1.8.0-150600.3.2.5
* openSUSE Leap 15.6 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* openSUSE Leap 15.6 (x86_64)
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libaom3-64bit-3.7.1-150600.3.9.1
* libaom3-64bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-64bit-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-64bit-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libaom3-debuginfo-3.7.1-150600.3.9.1
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-3.7.1-150600.3.9.1
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libaom-debugsource-3.7.1-150600.3.9.1
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libaom3-debuginfo-3.7.1-150600.3.9.1
* Basesystem Module 15-SP7 (aarch64 x86_64)
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libaom3-debuginfo-3.7.1-150600.3.9.1
* Desktop Applications Module 15-SP7 (aarch64 x86_64)
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* Desktop Applications Module 15-SP7 (x86_64)
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* Desktop Applications Module 15-SP7 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libaom3-debuginfo-3.7.1-150600.3.9.1
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3

## References:

* https://www.suse.com/security/cve/CVE-2026-56208.html
* https://www.suse.com/security/cve/CVE-2026-56209.html
* https://www.suse.com/security/cve/CVE-2026-56210.html
* https://www.suse.com/security/cve/CVE-2026-56211.html
* https://bugzilla.suse.com/show_bug.cgi?id63678
* https://bugzilla.suse.com/show_bug.cgi?id68242
* https://bugzilla.suse.com/show_bug.cgi?id68650
* https://bugzilla.suse.com/show_bug.cgi?id68651
* https://bugzilla.suse.com/show_bug.cgi?id68653
* https://bugzilla.suse.com/show_bug.cgi?id68655