openSUSE-SU-2026:21435-1: moderate: Security update for perl-XML-Bare
openSUSE-SU-2026:21433-1: important: Security update for hauler
openSUSE-SU-2026:21432-1: important: Security update for gh
openSUSE-SU-2026:21426-1: important: Security update for ImageMagick
openSUSE-SU-2026:21429-1: low: Security update for net-tools
openSUSE-SU-2026:21427-1: moderate: Security update for perl-HTTP-Date
openSUSE-SU-2026:21423-1: important: Security update for jline3
openSUSE-SU-2026:21425-1: moderate: Security update for PackageKit
openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp
openSUSE-SU-2026:21422-1: important: Security update for helm
openSUSE-SU-2026:21417-1: moderate: Security update for avahi
openSUSE-SU-2026:21412-1: important: Security update for perl-DBI
openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c
openSUSE-SU-2026:21410-1: important: Security update for glib2
openSUSE-SU-2026:21411-1: important: Security update for perl
openSUSE-SU-2026:21408-1: important: Security update for joe
openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli
openSUSE-SU-2026:11341-1: moderate: python313-pandas-3.0.3-1.2 on GA media
openSUSE-SU-2026:11339-1: moderate: kernel-devel-7.1.4-1.1 on GA media
openSUSE-SU-2026:11342-1: moderate: python313-3.13.14-1.1 on GA media
openSUSE-SU-2026:11343-1: moderate: python314-3.14.6-2.1 on GA media
openSUSE-SU-2026:11340-1: moderate: prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media
openSUSE-SU-2026:11335-1: moderate: java-11-openjdk-11.0.32.0-1.1 on GA media
openSUSE-SU-2026:11334-1: moderate: helm3-3.21.3-3.1 on GA media
openSUSE-SU-2026:11337-1: moderate: java-26-openjdk-26.0.2.0-1.1 on GA media
openSUSE-SU-2026:0259-1: important: Security update for gh
SUSE-SU-2026:3217-1: moderate: Security update for avahi
SUSE-SU-2026:3219-1: important: Security update for ImageMagick
SUSE-SU-2026:3218-1: moderate: Security update for avahi
SUSE-SU-2026:3220-1: moderate: Security update for nmap
SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3
openSUSE-SU-2026:21435-1: moderate: Security update for perl-XML-Bare
openSUSE security update: security update for perl-xml-bare
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21435-1
Rating: moderate
References:
* bsc#1271637
* bsc#1271640
Cross-References:
* CVE-2026-13401
* CVE-2026-57074
CVSS scores:
* CVE-2026-13401 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-57074 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for perl-XML-Bare fixes the following issues:
Changes in perl-XML-Bare:
- CVE-2026-13401: XML:Bare would hang when parsing malformed attributes (bsc#1271640)
- CVE-2026-57074: Fixed unbounded character lookahead (bsc#1271637)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-438=1
Package List:
- openSUSE Leap 16.0:
perl-XML-Bare-0.53-bp160.2.1
References:
* https://www.suse.com/security/cve/CVE-2026-13401.html
* https://www.suse.com/security/cve/CVE-2026-57074.html
openSUSE-SU-2026:21433-1: important: Security update for hauler
openSUSE security update: security update for hauler
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21433-1
Rating: important
References:
* bsc#1266602
Cross-References:
* CVE-2026-39821
CVSS scores:
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for hauler fixes the following issues:
Changes in hauler:
- update embedded dependency x/net to 0.57 to fix CVE-2026-39821 (bsc#1266602)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-436=1
Package List:
- openSUSE Leap 16.0:
hauler-2.0.1-bp160.2.1
References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
openSUSE-SU-2026:21432-1: important: Security update for gh
openSUSE security update: security update for gh
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21432-1
Rating: important
References:
* bsc#1266618
Cross-References:
* CVE-2026-39821
CVSS scores:
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for gh fixes the following issues:
Changes in gh:
- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored
golang.org/x/net/idna package regardless of Go's unicode.Version (boo#1266618).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260723152513362606.93181000773252=1
Package List:
- openSUSE Leap 16.0:
gh-2.96.0-bp160.2.1
gh-bash-completion-2.96.0-bp160.2.1
gh-fish-completion-2.96.0-bp160.2.1
gh-zsh-completion-2.96.0-bp160.2.1
References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
openSUSE-SU-2026:21426-1: important: Security update for ImageMagick
openSUSE security update: security update for imagemagick
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21426-1
Rating: important
References:
* bsc#1268878
* bsc#1271484
* bsc#1271485
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271494
* bsc#1271495
* bsc#1271496
* bsc#1271497
Cross-References:
* CVE-2026-56375
* CVE-2026-56379
* CVE-2026-61464
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61871
* CVE-2026-61872
CVSS scores:
* CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( SUSE ): 1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61859 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61860 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61862 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61863 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61867 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61871 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61871 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 15 vulnerabilities and has 15 bug fixes can now be installed.
Description:
This update for ImageMagick fixes the following issues
- CVE-2026-56375: Possible memory leak in ASHLAR coder when action fails (bsc#1271495).
- CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878).
- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).
- CVE-2026-61859: Policy Bypass in script operation due to missing checks (bsc#1271497).
- CVE-2026-61860: Use-After-Free when freetype initialization fails (bsc#1271494).
- CVE-2026-61862: Information Disclosure when printing profiles with debug enabled (bsc#1271493).
- CVE-2026-61863: Memory Leak in TIFF encoder when a temporary file could not be created (bsc#1271492).
- CVE-2026-61864: Memory Leak in color transformation to log colorspace when operation fails (bsc#1271491).
- CVE-2026-61865: Memory Leak in hough lines operation when an operation fails (bsc#1271490).
- CVE-2026-61866: Memory Leak in JNG encoder when a blob could not be opened (bsc#1271489).
- CVE-2026-61867: Memory Leak in TIFF encoder when an allocation fails (bsc#1271488).
- CVE-2026-61868: Memory Leak in YUV decoder when opening of blob fails (bsc#1271487).
- CVE-2026-61869: Memory Leak in MIFF encoder when allocation fails (bsc#1271486).
- CVE-2026-61871: Memory Leak in ICON decoder when allocation fails (bsc#1271485).
- CVE-2026-61872: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified (bsc#1271484).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1337=1
Package List:
- openSUSE Leap 16.0:
ImageMagick-7.1.2.0-160000.13.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.13.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.13.1
ImageMagick-devel-7.1.2.0-160000.13.1
ImageMagick-doc-7.1.2.0-160000.13.1
ImageMagick-extra-7.1.2.0-160000.13.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.13.1
libMagick++-devel-7.1.2.0-160000.13.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.13.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.13.1
perl-PerlMagick-7.1.2.0-160000.13.1
References:
* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
* https://www.suse.com/security/cve/CVE-2026-61860.html
* https://www.suse.com/security/cve/CVE-2026-61862.html
* https://www.suse.com/security/cve/CVE-2026-61863.html
* https://www.suse.com/security/cve/CVE-2026-61864.html
* https://www.suse.com/security/cve/CVE-2026-61865.html
* https://www.suse.com/security/cve/CVE-2026-61866.html
* https://www.suse.com/security/cve/CVE-2026-61867.html
* https://www.suse.com/security/cve/CVE-2026-61868.html
* https://www.suse.com/security/cve/CVE-2026-61869.html
* https://www.suse.com/security/cve/CVE-2026-61871.html
* https://www.suse.com/security/cve/CVE-2026-61872.html
openSUSE-SU-2026:21429-1: low: Security update for net-tools
openSUSE security update: security update for net-tools
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21429-1
Rating: low
References:
* bsc#1254323
Cross-References:
* CVE-2024-58251
CVSS scores:
* CVE-2024-58251 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
* CVE-2024-58251 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for net-tools fixes the following issue:
- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1340=1
Package List:
- openSUSE Leap 16.0:
net-tools-2.10-160000.4.1
net-tools-deprecated-2.10-160000.4.1
net-tools-lang-2.10-160000.4.1
References:
* https://www.suse.com/security/cve/CVE-2024-58251.html
openSUSE-SU-2026:21427-1: moderate: Security update for perl-HTTP-Date
openSUSE security update: security update for perl-http-date
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21427-1
Rating: moderate
References:
* bsc#1271705
Cross-References:
* CVE-2026-14741
CVSS scores:
* CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for perl-HTTP-Date fixes the following issue
- CVE-2026-14741: CPU exhaustion via polynomial regex backtracking in parse_date (bsc#1271705).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1338=1
Package List:
- openSUSE Leap 16.0:
perl-HTTP-Date-6.06-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2026-14741.html
openSUSE-SU-2026:21423-1: important: Security update for jline3
openSUSE security update: security update for jline3
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21423-1
Rating: important
References:
* bsc#1269021
* bsc#1270083
Cross-References:
* CVE-2026-56740
* CVE-2026-56741
CVSS scores:
* CVE-2026-56740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56741 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for jline3 fixes the following issues:
- CVE-2026-56740: unauthenticated remote memory exhaustion via unbounded Telnet `NEW-ENVIRON` variables (bsc#1269021).
- CVE-2026-56741: unauthenticated remote DoS via Unbounded Telnet NAWS Terminal Geometry (bsc#1270083).
Changes for jline3:
- Update to upstream version 3.30.15
+ fix: guard regex matching against catastrophic backtracking
(ReDoS) (#2018, backport of #2012):
* Adds SafeRegex utility with TimeoutCharSequence to enforce
wall-clock deadlines during regex matching
* Fixes 8 locations across terminal, reader, and builtins
where user-controlled input could trigger catastrophic
backtracking
* Addresses GHSA-r2xf-8xr9-62gw, GHSA-2v9w-34q6-wpqx,
GHSA-ph9c-7hw9-vhhw, GHSA-5q95-hrpc-m3w3
+ fix: backport security hardening (#1986, #1995):
* Create persisted history file with owner-only permissions
* Use exclusive create for extracted native library temp files
+ fix: warn on insecure permissions when history file created
concurrently
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1334=1
Package List:
- openSUSE Leap 16.0:
jline3-3.30.15-160000.1.1
jline3-builtins-3.30.15-160000.1.1
jline3-console-3.30.15-160000.1.1
jline3-console-ui-3.30.15-160000.1.1
jline3-curses-3.30.15-160000.1.1
jline3-jansi-3.30.15-160000.1.1
jline3-jansi-core-3.30.15-160000.1.1
jline3-javadoc-3.30.15-160000.1.1
jline3-native-3.30.15-160000.1.1
jline3-reader-3.30.15-160000.1.1
jline3-remote-telnet-3.30.15-160000.1.1
jline3-style-3.30.15-160000.1.1
jline3-terminal-3.30.15-160000.1.1
jline3-terminal-jansi-3.30.15-160000.1.1
jline3-terminal-jna-3.30.15-160000.1.1
jline3-terminal-jni-3.30.15-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-56740.html
* https://www.suse.com/security/cve/CVE-2026-56741.html
openSUSE-SU-2026:21425-1: moderate: Security update for PackageKit
openSUSE security update: security update for packagekit
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21425-1
Rating: moderate
References:
* bsc#1263252
* bsc#1267250
Cross-References:
* CVE-2026-10294
CVSS scores:
* CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-10294 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has 2 bug fixes can now be installed.
Description:
This update for PackageKit fixes the following issues:
Security issue fixed:
- CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250).
Non security issue fixed:
- KDE Discover ignores package locks (bsc#1263252).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1336=1
Package List:
- openSUSE Leap 16.0:
PackageKit-1.2.8-160000.5.1
PackageKit-backend-dnf-1.2.8-160000.5.1
PackageKit-backend-zypp-1.2.8-160000.5.1
PackageKit-branding-upstream-1.2.8-160000.5.1
PackageKit-devel-1.2.8-160000.5.1
PackageKit-gstreamer-plugin-1.2.8-160000.5.1
PackageKit-gtk3-module-1.2.8-160000.5.1
PackageKit-lang-1.2.8-160000.5.1
libpackagekit-glib2-18-1.2.8-160000.5.1
libpackagekit-glib2-devel-1.2.8-160000.5.1
typelib-1_0-PackageKitGlib-1_0-1.2.8-160000.5.1
References:
* https://www.suse.com/security/cve/CVE-2026-10294.html
openSUSE-SU-2026:21418-1: important: Security update for shibboleth-sp
openSUSE security update: security update for shibboleth-sp
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21418-1
Rating: important
References:
* bsc#1249394
Cross-References:
* CVE-2025-9943
CVSS scores:
* CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for shibboleth-sp fixes the following issue
- CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth
Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1329=1
Package List:
- openSUSE Leap 16.0:
libshibsp-lite12-3.5.0-160000.3.1
libshibsp12-3.5.0-160000.3.1
shibboleth-sp-3.5.0-160000.3.1
shibboleth-sp-devel-3.5.0-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2025-9943.html
openSUSE-SU-2026:21422-1: important: Security update for helm
openSUSE security update: security update for helm
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21422-1
Rating: important
References:
* bsc#1266598
* bsc#1271997
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for helm fixes the following issues
- Update to version 3.21.3
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1271997).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1333=1
Package List:
- openSUSE Leap 16.0:
helm-3.21.3-160000.1.1
helm-bash-completion-3.21.3-160000.1.1
helm-fish-completion-3.21.3-160000.1.1
helm-zsh-completion-3.21.3-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:21417-1: moderate: Security update for avahi
openSUSE security update: security update for avahi
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21417-1
Rating: moderate
References:
* bsc#1255451
Cross-References:
* CVE-2025-59529
CVSS scores:
* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for avahi fixes the following issues:
- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).
Changes for avahi:
- Make /var/lib/avahi-autoipd a ghost dir instead of packaging it
since avahi-autoipd creates it on start (jsc#PED-14836).
- Use libalternative instead of update-alternatives in TW and SLFO
(jsc#PED-14835).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1328=1
Package List:
- openSUSE Leap 16.0:
avahi-0.8-160000.6.1
avahi-autoipd-0.8-160000.6.1
avahi-compat-howl-devel-0.8-160000.6.1
avahi-compat-mDNSResponder-devel-0.8-160000.6.1
avahi-lang-0.8-160000.6.1
avahi-utils-0.8-160000.6.1
avahi-utils-gtk-0.8-160000.6.1
libavahi-client3-0.8-160000.6.1
libavahi-common3-0.8-160000.6.1
libavahi-core7-0.8-160000.6.1
libavahi-devel-0.8-160000.6.1
libavahi-glib-devel-0.8-160000.6.1
libavahi-glib1-0.8-160000.6.1
libavahi-gobject-devel-0.8-160000.6.1
libavahi-gobject0-0.8-160000.6.1
libavahi-libevent1-0.8-160000.6.1
libavahi-qt6-1-0.8-160000.6.1
libavahi-qt6-devel-0.8-160000.6.1
libavahi-ui-gtk3-0-0.8-160000.6.1
libdns_sd-0.8-160000.6.1
libhowl0-0.8-160000.6.1
python3-avahi-gtk-0.8-160000.6.1
python313-avahi-0.8-160000.6.1
typelib-1_0-Avahi-0_6-0.8-160000.6.1
References:
* https://www.suse.com/security/cve/CVE-2025-59529.html
openSUSE-SU-2026:21412-1: important: Security update for perl-DBI
openSUSE security update: security update for perl-dbi
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21412-1
Rating: important
References:
* bsc#1271399
* bsc#1271458
* bsc#1271459
* bsc#1271629
Cross-References:
* CVE-2026-15043
* CVE-2026-15392
* CVE-2026-60081
* CVE-2026-60082
CVSS scores:
* CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-60082 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.
Description:
This update for perl-DBI fixes the following issues:
- CVE-2026-15392: failure to validate symbolic links during table path resolution could allow unauthorized file reads
and writes outside the configured data director (bsc#1271629).
- CVE-2026-15043: `DBI:SQL:Nano` has incorrect predicate evaluation, which allows for bypass of file-backed filters
(bsc#1271399).
- CVE-2026-60081: `DBI:ProfileData` does not limit the path index in profile parser, which enables small-file
memory-amplification DoS (bsc#1271458).
- CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row,
which allows for a process crash (bsc#1271459).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1322=1
Package List:
- openSUSE Leap 16.0:
perl-DBI-1.647.0-160000.5.1
References:
* https://www.suse.com/security/cve/CVE-2026-15043.html
* https://www.suse.com/security/cve/CVE-2026-15392.html
* https://www.suse.com/security/cve/CVE-2026-60081.html
* https://www.suse.com/security/cve/CVE-2026-60082.html
openSUSE-SU-2026:21409-1: important: Security update for mariadb-connector-c
openSUSE security update: security update for mariadb-connector-c
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21409-1
Rating: important
References:
* bsc#1266438
Cross-References:
* CVE-2026-44172
CVSS scores:
* CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for mariadb-connector-c fixes the following issue:
- CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438).
Changes for mariadb-connector-c:
- Update to release 3.4.9.
- Update to release 3.4.8:
* Fix compilation with GCC 15
* CONC-762: always set is_null and length in the bind
structure to avoid msan errors
* CONC-763: add MySQL collation ID 309 (utf8mb4_0900_bin)
* CONC-764: fix build of ma_context.c on Android (X18 is a
platform-reserved register)
* CONC-766: disable clang -Wcast-function-type-strict for
makecontext
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1319=1
Package List:
- openSUSE Leap 16.0:
libmariadb-devel-3.4.9-160000.1.1
libmariadb3-3.4.9-160000.1.1
libmariadb_plugins-3.4.9-160000.1.1
libmariadbprivate-3.4.9-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-44172.html
openSUSE-SU-2026:21410-1: important: Security update for glib2
openSUSE security update: security update for glib2
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21410-1
Rating: important
References:
* bsc#1270008
* bsc#1270009
* bsc#1270010
* bsc#1270016
* bsc#1270018
* bsc#1270021
Cross-References:
* CVE-2026-58010
* CVE-2026-58011
* CVE-2026-58012
* CVE-2026-58013
* CVE-2026-58014
* CVE-2026-58016
CVSS scores:
* CVE-2026-58010 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58010 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58011 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-58012 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58012 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58013 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58014 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-58016 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.
Description:
This update for glib2 fixes the following issues:
- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
(bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1320=1
Package List:
- openSUSE Leap 16.0:
gio-branding-upstream-2.84.4-160000.4.1
glib2-devel-2.84.4-160000.4.1
glib2-devel-static-2.84.4-160000.4.1
glib2-doc-2.84.4-160000.4.1
glib2-lang-2.84.4-160000.4.1
glib2-tests-devel-2.84.4-160000.4.1
glib2-tools-2.84.4-160000.4.1
libgio-2_0-0-2.84.4-160000.4.1
libgirepository-2_0-0-2.84.4-160000.4.1
libglib-2_0-0-2.84.4-160000.4.1
libgmodule-2_0-0-2.84.4-160000.4.1
libgobject-2_0-0-2.84.4-160000.4.1
libgthread-2_0-0-2.84.4-160000.4.1
typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1
typelib-1_0-GLib-2_0-2.84.4-160000.4.1
typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1
typelib-1_0-GModule-2_0-2.84.4-160000.4.1
typelib-1_0-GObject-2_0-2.84.4-160000.4.1
typelib-1_0-Gio-2_0-2.84.4-160000.4.1
References:
* https://www.suse.com/security/cve/CVE-2026-58010.html
* https://www.suse.com/security/cve/CVE-2026-58011.html
* https://www.suse.com/security/cve/CVE-2026-58012.html
* https://www.suse.com/security/cve/CVE-2026-58013.html
* https://www.suse.com/security/cve/CVE-2026-58014.html
* https://www.suse.com/security/cve/CVE-2026-58016.html
openSUSE-SU-2026:21411-1: important: Security update for perl
openSUSE security update: security update for perl
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21411-1
Rating: important
References:
* bsc#1266304
* bsc#1266361
* bsc#1268349
* bsc#1271372
* bsc#1271386
Cross-References:
* CVE-2025-15649
* CVE-2026-12087
* CVE-2026-13221
* CVE-2026-57432
* CVE-2026-8376
CVSS scores:
* CVE-2025-15649 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-12087 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-13221 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-13221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-57432 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-57432 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8376 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-8376 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.
Description:
This update for perl fixes the following issues:
- CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date
(bsc#1266361).
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
- CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching
(bsc#1271386).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1321=1
Package List:
- openSUSE Leap 16.0:
perl-5.42.0-160000.3.1
perl-base-5.42.0-160000.3.1
perl-doc-5.42.0-160000.3.1
References:
* https://www.suse.com/security/cve/CVE-2025-15649.html
* https://www.suse.com/security/cve/CVE-2026-12087.html
* https://www.suse.com/security/cve/CVE-2026-13221.html
* https://www.suse.com/security/cve/CVE-2026-57432.html
* https://www.suse.com/security/cve/CVE-2026-8376.html
openSUSE-SU-2026:21408-1: important: Security update for joe
openSUSE security update: security update for joe
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21408-1
Rating: important
References:
* bsc#1269379
Cross-References:
* CVE-2026-13412
CVSS scores:
* CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for joe fixes the following issue
- CVE-2026-13412: improper validation in tag-file parser can lead to arbitrary command execution (bsc#1269379).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1318=1
Package List:
- openSUSE Leap 16.0:
joe-4.6-160000.4.1
References:
* https://www.suse.com/security/cve/CVE-2026-13412.html
openSUSE-SU-2026:21406-1: important: Security update for aws-nitro-enclaves-cli
openSUSE security update: security update for aws-nitro-enclaves-cli
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21406-1
Rating: important
References:
* bsc#1270492
* bsc#1270542
* bsc#1270705
* bsc#1270747
* bsc#1270839
* bsc#1270932
* bsc#1270952
Cross-References:
* CVE-2026-41677
* CVE-2026-41678
* CVE-2026-41681
* CVE-2026-41898
* CVE-2026-42327
* CVE-2026-44662
* CVE-2026-45784
CVSS scores:
* CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U
* CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
* CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 7 vulnerabilities and has 7 bug fixes can now be installed.
Description:
This update for aws-nitro-enclaves-cli fixes the following issues:
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
openssl crate (bsc#1270542).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270705).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
(bsc#1270747).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
memory in rust-openssl crate (bsc#1270839).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
(bsc#1270492).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
(bsc#1270932).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
openssl crate (bsc#1270952).
Changes for aws-nitro-enclaves-cli:
- Update to version 1.4.5.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1316=1
Package List:
- openSUSE Leap 16.0:
aws-nitro-enclaves-binaryblobs-upstream-1.4.5~git0.18a5f6f-160000.1.1
aws-nitro-enclaves-cli-1.4.5~git0.18a5f6f-160000.1.1
system-group-ne-1.4.5~git0.18a5f6f-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-41677.html
* https://www.suse.com/security/cve/CVE-2026-41678.html
* https://www.suse.com/security/cve/CVE-2026-41681.html
* https://www.suse.com/security/cve/CVE-2026-41898.html
* https://www.suse.com/security/cve/CVE-2026-42327.html
* https://www.suse.com/security/cve/CVE-2026-44662.html
* https://www.suse.com/security/cve/CVE-2026-45784.html
openSUSE-SU-2026:11341-1: moderate: python313-pandas-3.0.3-1.2 on GA media
# python313-pandas-3.0.3-1.2 on GA media
Announcement ID: openSUSE-SU-2026:11341-1
Rating: moderate
Cross-References:
* CVE-2023-47248
CVSS scores:
* CVE-2023-47248 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the python313-pandas-3.0.3-1.2 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-pandas 3.0.3-1.2
* python313-pandas-all 3.0.3-1.2
* python313-pandas-clipboard 3.0.3-1.2
* python313-pandas-compression 3.0.3-1.2
* python313-pandas-computation 3.0.3-1.2
* python313-pandas-excel 3.0.3-1.2
* python313-pandas-feather 3.0.3-1.2
* python313-pandas-fss 3.0.3-1.2
* python313-pandas-hdf5 3.0.3-1.2
* python313-pandas-html 3.0.3-1.2
* python313-pandas-mysql 3.0.3-1.2
* python313-pandas-output_formatting 3.0.3-1.2
* python313-pandas-parquet 3.0.3-1.2
* python313-pandas-performance 3.0.3-1.2
* python313-pandas-plot 3.0.3-1.2
* python313-pandas-postgresql 3.0.3-1.2
* python313-pandas-pyarrow 3.0.3-1.2
* python313-pandas-spss 3.0.3-1.2
* python313-pandas-sql-other 3.0.3-1.2
* python313-pandas-test 3.0.3-1.2
* python313-pandas-xml 3.0.3-1.2
* python314-pandas 3.0.3-1.2
* python314-pandas-all 3.0.3-1.2
* python314-pandas-clipboard 3.0.3-1.2
* python314-pandas-compression 3.0.3-1.2
* python314-pandas-computation 3.0.3-1.2
* python314-pandas-excel 3.0.3-1.2
* python314-pandas-feather 3.0.3-1.2
* python314-pandas-fss 3.0.3-1.2
* python314-pandas-hdf5 3.0.3-1.2
* python314-pandas-html 3.0.3-1.2
* python314-pandas-mysql 3.0.3-1.2
* python314-pandas-output_formatting 3.0.3-1.2
* python314-pandas-parquet 3.0.3-1.2
* python314-pandas-performance 3.0.3-1.2
* python314-pandas-plot 3.0.3-1.2
* python314-pandas-postgresql 3.0.3-1.2
* python314-pandas-pyarrow 3.0.3-1.2
* python314-pandas-spss 3.0.3-1.2
* python314-pandas-sql-other 3.0.3-1.2
* python314-pandas-test 3.0.3-1.2
* python314-pandas-xml 3.0.3-1.2
## References:
* https://www.suse.com/security/cve/CVE-2023-47248.html
openSUSE-SU-2026:11339-1: moderate: kernel-devel-7.1.4-1.1 on GA media
# kernel-devel-7.1.4-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11339-1
Rating: moderate
Cross-References:
* CVE-2026-53366
* CVE-2026-53381
* CVE-2026-53382
* CVE-2026-53383
* CVE-2026-53384
* CVE-2026-53385
* CVE-2026-53386
* CVE-2026-53387
* CVE-2026-53388
* CVE-2026-53389
* CVE-2026-53390
* CVE-2026-53391
* CVE-2026-53392
* CVE-2026-53393
* CVE-2026-53394
* CVE-2026-53395
* CVE-2026-53396
* CVE-2026-53397
* CVE-2026-53398
* CVE-2026-53399
* CVE-2026-53400
* CVE-2026-53401
* CVE-2026-53402
* CVE-2026-53403
* CVE-2026-63793
* CVE-2026-63794
* CVE-2026-63795
* CVE-2026-63796
* CVE-2026-63797
* CVE-2026-63798
* CVE-2026-63799
* CVE-2026-63800
* CVE-2026-63801
* CVE-2026-63802
* CVE-2026-63803
* CVE-2026-63804
* CVE-2026-63805
* CVE-2026-63806
* CVE-2026-63807
* CVE-2026-63808
* CVE-2026-63809
* CVE-2026-63810
* CVE-2026-63811
* CVE-2026-63812
* CVE-2026-63813
* CVE-2026-63814
* CVE-2026-63815
* CVE-2026-63816
* CVE-2026-63817
* CVE-2026-63818
* CVE-2026-63819
* CVE-2026-63820
* CVE-2026-63821
* CVE-2026-63822
* CVE-2026-63823
* CVE-2026-63824
* CVE-2026-63825
* CVE-2026-63826
* CVE-2026-63827
* CVE-2026-63828
* CVE-2026-63829
* CVE-2026-63830
* CVE-2026-63831
* CVE-2026-63832
* CVE-2026-63833
* CVE-2026-63834
* CVE-2026-63835
* CVE-2026-63836
CVSS scores:
* CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53366 ( SUSE ): 9 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53382 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53383 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53384 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53384 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53385 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53385 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53387 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-53387 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53390 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53391 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53392 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-53392 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53393 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-53393 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-53394 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53394 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53395 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53395 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53396 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53396 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53397 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53397 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53398 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-53398 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-53399 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53399 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53400 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53400 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53401 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53401 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53402 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53402 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63793 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63793 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63794 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63794 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63795 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63797 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63797 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63798 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63798 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63799 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-63799 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63800 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63800 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63802 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63802 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63803 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63803 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63804 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63804 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63805 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63805 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63806 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63806 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63807 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
* CVE-2026-63807 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63809 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63809 ( SUSE ): 8.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63811 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63811 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63812 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63812 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63813 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63813 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63814 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63814 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63815 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63815 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63816 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
* CVE-2026-63816 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63817 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63817 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63818 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-63818 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63819 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63819 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63820 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63820 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63821 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63821 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63822 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63824 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63825 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63825 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63826 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63826 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-63829 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-63829 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63830 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63831 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63831 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63832 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63832 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63833 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-63833 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-63834 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63834 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63835 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63835 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63836 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63836 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 68 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the kernel-devel-7.1.4-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* kernel-devel 7.1.4-1.1
* kernel-macros 7.1.4-1.1
* kernel-source 7.1.4-1.1
* kernel-source-vanilla 7.1.4-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-53366.html
* https://www.suse.com/security/cve/CVE-2026-53381.html
* https://www.suse.com/security/cve/CVE-2026-53382.html
* https://www.suse.com/security/cve/CVE-2026-53383.html
* https://www.suse.com/security/cve/CVE-2026-53384.html
* https://www.suse.com/security/cve/CVE-2026-53385.html
* https://www.suse.com/security/cve/CVE-2026-53386.html
* https://www.suse.com/security/cve/CVE-2026-53387.html
* https://www.suse.com/security/cve/CVE-2026-53388.html
* https://www.suse.com/security/cve/CVE-2026-53389.html
* https://www.suse.com/security/cve/CVE-2026-53390.html
* https://www.suse.com/security/cve/CVE-2026-53391.html
* https://www.suse.com/security/cve/CVE-2026-53392.html
* https://www.suse.com/security/cve/CVE-2026-53393.html
* https://www.suse.com/security/cve/CVE-2026-53394.html
* https://www.suse.com/security/cve/CVE-2026-53395.html
* https://www.suse.com/security/cve/CVE-2026-53396.html
* https://www.suse.com/security/cve/CVE-2026-53397.html
* https://www.suse.com/security/cve/CVE-2026-53398.html
* https://www.suse.com/security/cve/CVE-2026-53399.html
* https://www.suse.com/security/cve/CVE-2026-53400.html
* https://www.suse.com/security/cve/CVE-2026-53401.html
* https://www.suse.com/security/cve/CVE-2026-53402.html
* https://www.suse.com/security/cve/CVE-2026-53403.html
* https://www.suse.com/security/cve/CVE-2026-63793.html
* https://www.suse.com/security/cve/CVE-2026-63794.html
* https://www.suse.com/security/cve/CVE-2026-63795.html
* https://www.suse.com/security/cve/CVE-2026-63796.html
* https://www.suse.com/security/cve/CVE-2026-63797.html
* https://www.suse.com/security/cve/CVE-2026-63798.html
* https://www.suse.com/security/cve/CVE-2026-63799.html
* https://www.suse.com/security/cve/CVE-2026-63800.html
* https://www.suse.com/security/cve/CVE-2026-63801.html
* https://www.suse.com/security/cve/CVE-2026-63802.html
* https://www.suse.com/security/cve/CVE-2026-63803.html
* https://www.suse.com/security/cve/CVE-2026-63804.html
* https://www.suse.com/security/cve/CVE-2026-63805.html
* https://www.suse.com/security/cve/CVE-2026-63806.html
* https://www.suse.com/security/cve/CVE-2026-63807.html
* https://www.suse.com/security/cve/CVE-2026-63808.html
* https://www.suse.com/security/cve/CVE-2026-63809.html
* https://www.suse.com/security/cve/CVE-2026-63810.html
* https://www.suse.com/security/cve/CVE-2026-63811.html
* https://www.suse.com/security/cve/CVE-2026-63812.html
* https://www.suse.com/security/cve/CVE-2026-63813.html
* https://www.suse.com/security/cve/CVE-2026-63814.html
* https://www.suse.com/security/cve/CVE-2026-63815.html
* https://www.suse.com/security/cve/CVE-2026-63816.html
* https://www.suse.com/security/cve/CVE-2026-63817.html
* https://www.suse.com/security/cve/CVE-2026-63818.html
* https://www.suse.com/security/cve/CVE-2026-63819.html
* https://www.suse.com/security/cve/CVE-2026-63820.html
* https://www.suse.com/security/cve/CVE-2026-63821.html
* https://www.suse.com/security/cve/CVE-2026-63822.html
* https://www.suse.com/security/cve/CVE-2026-63823.html
* https://www.suse.com/security/cve/CVE-2026-63824.html
* https://www.suse.com/security/cve/CVE-2026-63825.html
* https://www.suse.com/security/cve/CVE-2026-63826.html
* https://www.suse.com/security/cve/CVE-2026-63827.html
* https://www.suse.com/security/cve/CVE-2026-63828.html
* https://www.suse.com/security/cve/CVE-2026-63829.html
* https://www.suse.com/security/cve/CVE-2026-63830.html
* https://www.suse.com/security/cve/CVE-2026-63831.html
* https://www.suse.com/security/cve/CVE-2026-63832.html
* https://www.suse.com/security/cve/CVE-2026-63833.html
* https://www.suse.com/security/cve/CVE-2026-63834.html
* https://www.suse.com/security/cve/CVE-2026-63835.html
* https://www.suse.com/security/cve/CVE-2026-63836.html
openSUSE-SU-2026:11342-1: moderate: python313-3.13.14-1.1 on GA media
# python313-3.13.14-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11342-1
Rating: moderate
Cross-References:
* CVE-2021-4189
* CVE-2025-15366
* CVE-2025-15367
* CVE-2026-11940
* CVE-2026-7210
* CVE-2026-8328
CVSS scores:
* CVE-2021-4189 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
* CVE-2025-15366 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
* CVE-2025-15367 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 6 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the python313-3.13.14-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313 3.13.14-1.1
* python313-32bit 3.13.14-1.1
* python313-curses 3.13.14-1.1
* python313-dbm 3.13.14-1.1
* python313-idle 3.13.14-1.1
* python313-tk 3.13.14-1.1
* python313-x86-64-v3 3.13.14-1.1
## References:
* https://www.suse.com/security/cve/CVE-2021-4189.html
* https://www.suse.com/security/cve/CVE-2025-15366.html
* https://www.suse.com/security/cve/CVE-2025-15367.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
openSUSE-SU-2026:11343-1: moderate: python314-3.14.6-2.1 on GA media
# python314-3.14.6-2.1 on GA media
Announcement ID: openSUSE-SU-2026:11343-1
Rating: moderate
Cross-References:
* CVE-2026-11940
CVSS scores:
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the python314-3.14.6-2.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python314 3.14.6-2.1
* python314-32bit 3.14.6-2.1
* python314-curses 3.14.6-2.1
* python314-dbm 3.14.6-2.1
* python314-idle 3.14.6-2.1
* python314-tk 3.14.6-2.1
* python314-x86-64-v3 3.14.6-2.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11940.html
openSUSE-SU-2026:11340-1: moderate: prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media
# prometheus-ha_cluster_exporter-1.4.2-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11340-1
Rating: moderate
Cross-References:
* CVE-2026-39821
CVSS scores:
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the prometheus-ha_cluster_exporter-1.4.2-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* prometheus-ha_cluster_exporter 1.4.2-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
openSUSE-SU-2026:11335-1: moderate: java-11-openjdk-11.0.32.0-1.1 on GA media
# java-11-openjdk-11.0.32.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11335-1
Rating: moderate
Cross-References:
* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47057
* CVE-2026-47058
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 11 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-11-openjdk-11.0.32.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-11-openjdk 11.0.32.0-1.1
* java-11-openjdk-demo 11.0.32.0-1.1
* java-11-openjdk-devel 11.0.32.0-1.1
* java-11-openjdk-headless 11.0.32.0-1.1
* java-11-openjdk-javadoc 11.0.32.0-1.1
* java-11-openjdk-jmods 11.0.32.0-1.1
* java-11-openjdk-src 11.0.32.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47057.html
* https://www.suse.com/security/cve/CVE-2026-47058.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
openSUSE-SU-2026:11334-1: moderate: helm3-3.21.3-3.1 on GA media
# helm3-3.21.3-3.1 on GA media
Announcement ID: openSUSE-SU-2026:11334-1
Rating: moderate
Cross-References:
* CVE-2026-56852
CVSS scores:
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the helm3-3.21.3-3.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* helm3 3.21.3-3.1
* helm3-bash-completion 3.21.3-3.1
* helm3-fish-completion 3.21.3-3.1
* helm3-zsh-completion 3.21.3-3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:11337-1: moderate: java-26-openjdk-26.0.2.0-1.1 on GA media
# java-26-openjdk-26.0.2.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11337-1
Rating: moderate
Cross-References:
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 8 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the java-26-openjdk-26.0.2.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* java-26-openjdk 26.0.2.0-1.1
* java-26-openjdk-demo 26.0.2.0-1.1
* java-26-openjdk-devel 26.0.2.0-1.1
* java-26-openjdk-headless 26.0.2.0-1.1
* java-26-openjdk-javadoc 26.0.2.0-1.1
* java-26-openjdk-jmods 26.0.2.0-1.1
* java-26-openjdk-src 26.0.2.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
openSUSE-SU-2026:0259-1: important: Security update for gh
openSUSE Security Update: Security update for gh
_______________________________
Announcement ID: openSUSE-SU-2026:0259-1
Rating: important
References: #1266618
Cross-References: CVE-2026-39821
CVSS scores:
CVE-2026-39821 (SUSE): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes one vulnerability is now available.
Description:
This update for gh fixes the following issues:
- CVE-2026-39821: reject all-ASCII xn-- Punycode labels in the vendored
golang.org/x/net/idna package regardless of Go's unicode.Version
(boo#1266618).
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-259=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
gh-2.96.0-bp157.2.24.1
- openSUSE Backports SLE-15-SP7 (noarch):
gh-bash-completion-2.96.0-bp157.2.24.1
gh-fish-completion-2.96.0-bp157.2.24.1
gh-zsh-completion-2.96.0-bp157.2.24.1
References:
https://www.suse.com/security/cve/CVE-2026-39821.html
https://bugzilla.suse.com/1266618
SUSE-SU-2026:3217-1: moderate: Security update for avahi
# Security update for avahi
Announcement ID: SUSE-SU-2026:3217-1
Release Date: 2026-07-23T17:33:52Z
Rating: moderate
References:
* bsc#1255451
Cross-References:
* CVE-2025-59529
CVSS scores:
* CVE-2025-59529 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
An update that solves one vulnerability can now be installed.
## Description:
This update for avahi fixes the following issue:
* CVE-2025-59529: local DoS due to simple protocol server ignoring client
limit CLIENTS_MAX (bsc#1255451).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3217=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3217=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3217=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3217=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* avahi-autoipd-debuginfo-0.8-150400.7.34.1
* python3-avahi-0.8-150400.7.34.1
* libhowl0-debuginfo-0.8-150400.7.34.1
* avahi-utils-gtk-debuginfo-0.8-150400.7.34.1
* libavahi-gobject0-debuginfo-0.8-150400.7.34.1
* libavahi-qt5-1-0.8-150400.7.34.1
* avahi-autoipd-0.8-150400.7.34.1
* python3-avahi-gtk-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* libavahi-qt5-1-debuginfo-0.8-150400.7.34.1
* libavahi-glib-devel-0.8-150400.7.34.1
* libavahi-glib1-0.8-150400.7.34.1
* libdns_sd-0.8-150400.7.34.1
* avahi-compat-mDNSResponder-devel-0.8-150400.7.34.1
* libhowl0-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150400.7.34.1
* avahi-compat-howl-devel-0.8-150400.7.34.1
* avahi-qt5-debugsource-0.8-150400.7.34.1
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-debuginfo-0.8-150400.7.34.1
* libdns_sd-debuginfo-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* libavahi-libevent1-0.8-150400.7.34.1
* libavahi-devel-0.8-150400.7.34.1
* libavahi-ui-gtk3-0-0.8-150400.7.34.1
* avahi-utils-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* avahi-utils-0.8-150400.7.34.1
* libavahi-qt5-devel-0.8-150400.7.34.1
* typelib-1_0-Avahi-0_6-0.8-150400.7.34.1
* libavahi-libevent1-debuginfo-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* libavahi-gobject0-0.8-150400.7.34.1
* avahi-utils-gtk-0.8-150400.7.34.1
* libavahi-gobject-devel-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* avahi-glib2-debugsource-0.8-150400.7.34.1
* openSUSE Leap 15.4 (noarch)
* avahi-lang-0.8-150400.7.34.1
* openSUSE Leap 15.4 (x86_64)
* libavahi-client3-32bit-0.8-150400.7.34.1
* libavahi-client3-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-32bit-debuginfo-0.8-150400.7.34.1
* libdns_sd-32bit-0.8-150400.7.34.1
* libavahi-glib1-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-32bit-0.8-150400.7.34.1
* libdns_sd-32bit-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-32bit-0.8-150400.7.34.1
* avahi-32bit-debuginfo-0.8-150400.7.34.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libavahi-client3-64bit-0.8-150400.7.34.1
* libdns_sd-64bit-0.8-150400.7.34.1
* libavahi-client3-64bit-debuginfo-0.8-150400.7.34.1
* libdns_sd-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-glib1-64bit-debuginfo-0.8-150400.7.34.1
* avahi-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-64bit-debuginfo-0.8-150400.7.34.1
* libavahi-common3-64bit-0.8-150400.7.34.1
* libavahi-glib1-64bit-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* libavahi-common3-debuginfo-0.8-150400.7.34.1
* libavahi-core7-0.8-150400.7.34.1
* avahi-debugsource-0.8-150400.7.34.1
* avahi-0.8-150400.7.34.1
* avahi-debuginfo-0.8-150400.7.34.1
* libavahi-common3-0.8-150400.7.34.1
* libavahi-core7-debuginfo-0.8-150400.7.34.1
* libavahi-client3-debuginfo-0.8-150400.7.34.1
* libavahi-client3-0.8-150400.7.34.1
## References:
* https://www.suse.com/security/cve/CVE-2025-59529.html
* https://bugzilla.suse.com/show_bug.cgi?id55451
SUSE-SU-2026:3219-1: important: Security update for ImageMagick
# Security update for ImageMagick
Announcement ID: SUSE-SU-2026:3219-1
Release Date: 2026-07-23T17:35:28Z
Rating: important
References:
* bsc#1268640
* bsc#1268878
* bsc#1270006
* bsc#1270081
* bsc#1271100
* bsc#1271293
* bsc#1271294
* bsc#1271311
* bsc#1271312
* bsc#1271313
* bsc#1271314
* bsc#1271315
* bsc#1271316
* bsc#1271484
* bsc#1271486
* bsc#1271487
* bsc#1271488
* bsc#1271489
* bsc#1271490
* bsc#1271491
* bsc#1271492
* bsc#1271493
* bsc#1271494
* bsc#1271495
* bsc#1271496
* bsc#1271497
Cross-References:
* CVE-2026-55628
* CVE-2026-56362
* CVE-2026-56366
* CVE-2026-56372
* CVE-2026-56373
* CVE-2026-56375
* CVE-2026-56377
* CVE-2026-56379
* CVE-2026-61464
* CVE-2026-61465
* CVE-2026-61857
* CVE-2026-61858
* CVE-2026-61859
* CVE-2026-61860
* CVE-2026-61861
* CVE-2026-61862
* CVE-2026-61863
* CVE-2026-61864
* CVE-2026-61865
* CVE-2026-61866
* CVE-2026-61867
* CVE-2026-61868
* CVE-2026-61869
* CVE-2026-61870
* CVE-2026-61872
CVSS scores:
* CVE-2026-55628 ( SUSE ): 6.7
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-55628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-56362 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56362 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56362 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56362 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-56366 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56366 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56366 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56366 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-56372 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56372 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56372 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56372 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-56373 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56373 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56373 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56373 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56375 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56375 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56375 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-56377 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56377 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56377 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-56379 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-56379 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
* CVE-2026-61464 ( SUSE ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( NVD ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61465 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61465 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-61857 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61857 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61857 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61858 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61858 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61858 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61858 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-61859 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61859 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61859 ( NVD ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61859 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61860 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61860 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61860 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61861 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61862 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-61862 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61862 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61862 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-61863 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61863 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61863 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61863 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61863 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61864 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61864 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61864 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61865 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61865 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61865 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61866 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61866 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61866 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61867 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61867 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61867 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61867 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61868 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61868 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61868 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61869 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61869 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61869 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61870 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61870 ( NVD ): 2.1
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61870 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-61870 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61872 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61872 ( NVD ): 2.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61872 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves 25 vulnerabilities and has one security fix can now be
installed.
## Description:
This update for ImageMagick fixes the following issues:
* CVE-2026-55628: policy bypass in concatenate operation due to missing checks
(bsc#1270081).
* CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to
metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100).
* CVE-2026-56366: META reader memory leak in the APP1JPEG input path
(bsc#1271316).
* CVE-2026-56372: heap buffer overflow read in magnify operation via
unrecognized `magnify:method` value (bsc#1271314).
* CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640,
bsc#1271315).
* CVE-2026-56375: possible memory leak in ASHLAR coder when action fails
(bsc#1271495).
* CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006).
* CVE-2026-61464: heap buffer overwrite in X11 import with crafted window
title (bsc#1271496).
* CVE-2026-61465: policy bypass possible with matrix-backed operations
(bsc#1271313).
* CVE-2026-61857: heap use-after-free via XMP profile could result in a crash
(bsc#1271312).
* CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing
check (bsc#1271311).
* CVE-2026-61859: policy bypass in script operation due to missing checks
(bsc#1271497).
* CVE-2026-61860: use-after-free when `freetype` initialization fails
(bsc#1271494).
* CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory
allocation fails (bsc#1271294).
* CVE-2026-61862: information disclosure when printing profiles with debug
enabled (bsc#1271493).
* CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not
be created (bsc#1271492).
* CVE-2026-61864: memory leak in color transformation to log colorspace when
operation fails (bsc#1271491).
* CVE-2026-61865: memory leak in hough lines operation when an operation fails
(bsc#1271490).
* CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened
(bsc#1271489).
* CVE-2026-61867: memory leak in TIFF encoder when an allocation fails
(bsc#1271488).
* CVE-2026-61868: memory leak in YUV decoder when opening of blob fails
(bsc#1271487).
* CVE-2026-61869: memory leak in MIFF encoder when allocation fails
(bsc#1271486).
* CVE-2026-61870: memory leak in VIFF encoder when allocation fails
(bsc#1271293).
* CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-
geometry` is specified (bsc#1271484).
* Extend CVE-2026-56379 patch by f63c78b (bsc#1268878).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3219=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3219=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3219=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libMagick++-devel-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2
* libMagick++-devel-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-extra-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-extra-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libMagick++-7_Q16HDRI5-64bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2
* libMagick++-devel-64bit-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-64bit-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-devel-64bit-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (x86_64)
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-devel-32bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2
* libMagick++-devel-32bit-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-32bit-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-32bit-7.1.1.21-150600.3.80.2
* openSUSE Leap 15.6 (noarch)
* ImageMagick-doc-7.1.1.21-150600.3.80.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.80.2
* perl-PerlMagick-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.80.2
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* libMagick++-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.80.2
* ImageMagick-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.80.2
* ImageMagick-debuginfo-7.1.1.21-150600.3.80.2
* libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.80.2
* ImageMagick-debugsource-7.1.1.21-150600.3.80.2
* ImageMagick-devel-7.1.1.21-150600.3.80.2
* libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.80.2
* perl-PerlMagick-debuginfo-7.1.1.21-150600.3.80.2
* ImageMagick-config-7-SUSE-7.1.1.21-150600.3.80.2
## References:
* https://www.suse.com/security/cve/CVE-2026-55628.html
* https://www.suse.com/security/cve/CVE-2026-56362.html
* https://www.suse.com/security/cve/CVE-2026-56366.html
* https://www.suse.com/security/cve/CVE-2026-56372.html
* https://www.suse.com/security/cve/CVE-2026-56373.html
* https://www.suse.com/security/cve/CVE-2026-56375.html
* https://www.suse.com/security/cve/CVE-2026-56377.html
* https://www.suse.com/security/cve/CVE-2026-56379.html
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://www.suse.com/security/cve/CVE-2026-61465.html
* https://www.suse.com/security/cve/CVE-2026-61857.html
* https://www.suse.com/security/cve/CVE-2026-61858.html
* https://www.suse.com/security/cve/CVE-2026-61859.html
* https://www.suse.com/security/cve/CVE-2026-61860.html
* https://www.suse.com/security/cve/CVE-2026-61861.html
* https://www.suse.com/security/cve/CVE-2026-61862.html
* https://www.suse.com/security/cve/CVE-2026-61863.html
* https://www.suse.com/security/cve/CVE-2026-61864.html
* https://www.suse.com/security/cve/CVE-2026-61865.html
* https://www.suse.com/security/cve/CVE-2026-61866.html
* https://www.suse.com/security/cve/CVE-2026-61867.html
* https://www.suse.com/security/cve/CVE-2026-61868.html
* https://www.suse.com/security/cve/CVE-2026-61869.html
* https://www.suse.com/security/cve/CVE-2026-61870.html
* https://www.suse.com/security/cve/CVE-2026-61872.html
* https://bugzilla.suse.com/show_bug.cgi?id68640
* https://bugzilla.suse.com/show_bug.cgi?id68878
* https://bugzilla.suse.com/show_bug.cgi?id70006
* https://bugzilla.suse.com/show_bug.cgi?id70081
* https://bugzilla.suse.com/show_bug.cgi?id71100
* https://bugzilla.suse.com/show_bug.cgi?id71293
* https://bugzilla.suse.com/show_bug.cgi?id71294
* https://bugzilla.suse.com/show_bug.cgi?id71311
* https://bugzilla.suse.com/show_bug.cgi?id71312
* https://bugzilla.suse.com/show_bug.cgi?id71313
* https://bugzilla.suse.com/show_bug.cgi?id71314
* https://bugzilla.suse.com/show_bug.cgi?id71315
* https://bugzilla.suse.com/show_bug.cgi?id71316
* https://bugzilla.suse.com/show_bug.cgi?id71484
* https://bugzilla.suse.com/show_bug.cgi?id71486
* https://bugzilla.suse.com/show_bug.cgi?id71487
* https://bugzilla.suse.com/show_bug.cgi?id71488
* https://bugzilla.suse.com/show_bug.cgi?id71489
* https://bugzilla.suse.com/show_bug.cgi?id71490
* https://bugzilla.suse.com/show_bug.cgi?id71491
* https://bugzilla.suse.com/show_bug.cgi?id71492
* https://bugzilla.suse.com/show_bug.cgi?id71493
* https://bugzilla.suse.com/show_bug.cgi?id71494
* https://bugzilla.suse.com/show_bug.cgi?id71495
* https://bugzilla.suse.com/show_bug.cgi?id71496
* https://bugzilla.suse.com/show_bug.cgi?id71497
SUSE-SU-2026:3218-1: moderate: Security update for avahi
# Security update for avahi
Announcement ID: SUSE-SU-2026:3218-1
Release Date: 2026-07-23T17:34:30Z
Rating: moderate
References:
* bsc#1255451
Cross-References:
* CVE-2025-59529
CVSS scores:
* CVE-2025-59529 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-59529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-59529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for avahi fixes the following issue:
* CVE-2025-59529: local DoS due to simple protocol server ignoring client
limit CLIENTS_MAX (bsc#1255451).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3218=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3218=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3218=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3218=1
## Package List:
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libavahi-gobject0-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1
* avahi-utils-debuginfo-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* libdns_sd-debuginfo-0.8-150600.15.21.1
* libhowl0-debuginfo-0.8-150600.15.21.1
* typelib-1_0-Avahi-0_6-0.8-150600.15.21.1
* libavahi-client3-0.8-150600.15.21.1
* avahi-utils-0.8-150600.15.21.1
* libavahi-glib1-debuginfo-0.8-150600.15.21.1
* avahi-0.8-150600.15.21.1
* avahi-compat-howl-devel-0.8-150600.15.21.1
* libavahi-glib-devel-0.8-150600.15.21.1
* libhowl0-0.8-150600.15.21.1
* libdns_sd-0.8-150600.15.21.1
* libavahi-glib1-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-core7-0.8-150600.15.21.1
* libavahi-common3-debuginfo-0.8-150600.15.21.1
* libavahi-gobject0-0.8-150600.15.21.1
* libavahi-core7-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-0.8-150600.15.21.1
* libavahi-common3-0.8-150600.15.21.1
* libavahi-devel-0.8-150600.15.21.1
* libavahi-client3-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-debuginfo-0.8-150600.15.21.1
* Basesystem Module 15-SP7 (x86_64)
* libavahi-client3-32bit-0.8-150600.15.21.1
* libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1
* avahi-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-0.8-150600.15.21.1
* libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1
* Basesystem Module 15-SP7 (noarch)
* avahi-lang-0.8-150600.15.21.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python3-avahi-0.8-150600.15.21.1
* libavahi-gobject0-debuginfo-0.8-150600.15.21.1
* libavahi-qt5-1-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-compat-mDNSResponder-devel-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-0.8-150600.15.21.1
* avahi-utils-gtk-0.8-150600.15.21.1
* python3-avahi-gtk-0.8-150600.15.21.1
* libavahi-ui-gtk3-0-debuginfo-0.8-150600.15.21.1
* avahi-utils-debuginfo-0.8-150600.15.21.1
* avahi-qt5-debugsource-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* libhowl0-debuginfo-0.8-150600.15.21.1
* libdns_sd-debuginfo-0.8-150600.15.21.1
* libavahi-qt5-1-0.8-150600.15.21.1
* libavahi-qt5-devel-0.8-150600.15.21.1
* typelib-1_0-Avahi-0_6-0.8-150600.15.21.1
* libavahi-client3-0.8-150600.15.21.1
* avahi-utils-0.8-150600.15.21.1
* libavahi-glib1-debuginfo-0.8-150600.15.21.1
* libavahi-gobject-devel-0.8-150600.15.21.1
* avahi-0.8-150600.15.21.1
* avahi-compat-howl-devel-0.8-150600.15.21.1
* libavahi-glib-devel-0.8-150600.15.21.1
* avahi-autoipd-debuginfo-0.8-150600.15.21.1
* libhowl0-0.8-150600.15.21.1
* libdns_sd-0.8-150600.15.21.1
* libavahi-glib1-0.8-150600.15.21.1
* avahi-autoipd-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-core7-0.8-150600.15.21.1
* libavahi-common3-debuginfo-0.8-150600.15.21.1
* libavahi-gobject0-0.8-150600.15.21.1
* libavahi-core7-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-0.8-150600.15.21.1
* libavahi-common3-0.8-150600.15.21.1
* libavahi-devel-0.8-150600.15.21.1
* libavahi-client3-debuginfo-0.8-150600.15.21.1
* libavahi-libevent1-debuginfo-0.8-150600.15.21.1
* avahi-utils-gtk-debuginfo-0.8-150600.15.21.1
* openSUSE Leap 15.6 (x86_64)
* libavahi-client3-32bit-0.8-150600.15.21.1
* libavahi-glib1-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-32bit-debuginfo-0.8-150600.15.21.1
* avahi-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-32bit-0.8-150600.15.21.1
* libdns_sd-32bit-0.8-150600.15.21.1
* libdns_sd-32bit-debuginfo-0.8-150600.15.21.1
* libavahi-glib1-32bit-0.8-150600.15.21.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libdns_sd-64bit-0.8-150600.15.21.1
* libavahi-glib1-64bit-0.8-150600.15.21.1
* libdns_sd-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-64bit-0.8-150600.15.21.1
* avahi-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-client3-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-glib1-64bit-debuginfo-0.8-150600.15.21.1
* libavahi-common3-64bit-0.8-150600.15.21.1
* libavahi-common3-64bit-debuginfo-0.8-150600.15.21.1
* openSUSE Leap 15.6 (noarch)
* avahi-lang-0.8-150600.15.21.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* avahi-autoipd-debuginfo-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-utils-gtk-0.8-150600.15.21.1
* avahi-autoipd-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
* avahi-glib2-debugsource-0.8-150600.15.21.1
* libavahi-gobject-devel-0.8-150600.15.21.1
* avahi-utils-gtk-debuginfo-0.8-150600.15.21.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* python3-avahi-0.8-150600.15.21.1
* avahi-debugsource-0.8-150600.15.21.1
* avahi-debuginfo-0.8-150600.15.21.1
## References:
* https://www.suse.com/security/cve/CVE-2025-59529.html
* https://bugzilla.suse.com/show_bug.cgi?id55451
SUSE-SU-2026:3220-1: moderate: Security update for nmap
# Security update for nmap
Announcement ID: SUSE-SU-2026:3220-1
Release Date: 2026-07-23T17:37:38Z
Rating: moderate
References:
* bsc#1269570
Cross-References:
* CVE-2026-58058
CVSS scores:
* CVE-2026-58058 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-58058 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-58058 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-58058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected Products:
* openSUSE Leap 15.4
An update that solves one vulnerability can now be installed.
## Description:
This update for nmap fixes the following issue:
* CVE-2026-58058: crafted IPv6 response with a truncated extension header can
trigger out-of-bounds reads and a crash (bsc#1269570).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3220=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* ncat-debuginfo-7.92-150400.3.3.1
* ncat-7.92-150400.3.3.1
* nmap-debuginfo-7.92-150400.3.3.1
* nping-7.92-150400.3.3.1
* nmap-7.92-150400.3.3.1
* nping-debuginfo-7.92-150400.3.3.1
* nmap-debugsource-7.92-150400.3.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-58058.html
* https://bugzilla.suse.com/show_bug.cgi?id69570
SUSE-SU-2026:3224-1: important: Security update for SVT-AV1, libyuv0, libaom3
# Security update for SVT-AV1, libyuv0, libaom3
Announcement ID: SUSE-SU-2026:3224-1
Release Date: 2026-07-23T18:34:25Z
Rating: important
References:
* bsc#1263678
* bsc#1268242
* bsc#1268650
* bsc#1268651
* bsc#1268653
* bsc#1268655
Cross-References:
* CVE-2026-56208
* CVE-2026-56209
* CVE-2026-56210
* CVE-2026-56211
CVSS scores:
* CVE-2026-56208 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
* CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-56209 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
* CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
* CVE-2026-56210 ( SUSE ): 7.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-56211 ( SUSE ): 7.5
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
* CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H
Affected Products:
* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves four vulnerabilities and has two security fixes can now be
installed.
## Description:
This update for SVT-AV1, libyuv0, libaom3 fixes the following issues:
* CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-
based buffer overflow and a process crash (bsc#1268650).
* CVE-2026-56209: crafted video frames with specific Y-plane pixel values can
lead to an arbitrary memory write (bsc#1268651).
* CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-
of-bounds heap read (bsc#1268653).
* CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to
remote code execution (bsc#1268655).
Bug fixes:
* Add SVT-AV1, libyuv0, libaom3 to Basesystem, no source changes.
(bsc#1263678).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3224=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3224=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3224=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3224=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3224=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* aom-tools-3.7.1-150600.3.9.1
* libaom3-debuginfo-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* openSUSE Leap 15.6 (aarch64 x86_64)
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Dec0-1.8.0-150600.3.2.5
* SVT-AV1-devel-1.8.0-150600.3.2.5
* libSvtAv1Dec0-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-1.8.0-150600.3.2.5
* openSUSE Leap 15.6 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* openSUSE Leap 15.6 (x86_64)
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* openSUSE Leap 15.6 (aarch64_ilp32)
* libaom3-64bit-3.7.1-150600.3.9.1
* libaom3-64bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-64bit-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-64bit-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libaom3-debuginfo-3.7.1-150600.3.9.1
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-3.7.1-150600.3.9.1
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libaom-debugsource-3.7.1-150600.3.9.1
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libaom3-debuginfo-3.7.1-150600.3.9.1
* Basesystem Module 15-SP7 (aarch64 x86_64)
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libaom3-debuginfo-3.7.1-150600.3.9.1
* Desktop Applications Module 15-SP7 (aarch64 x86_64)
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* Desktop Applications Module 15-SP7 (x86_64)
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* Desktop Applications Module 15-SP7 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* SVT-AV1-debugsource-1.8.0-150600.3.2.5
* SVT-AV1-debuginfo-1.8.0-150600.3.2.5
* libSvtAv1Enc1-1.8.0-150600.3.2.5
* libyuv0-32bit-debuginfo-20230517+a377993-150600.3.4.2
* libSvtAv1Enc1-debuginfo-1.8.0-150600.3.2.5
* libaom3-32bit-3.7.1-150600.3.9.1
* libyuv0-32bit-20230517+a377993-150600.3.4.2
* libaom3-32bit-debuginfo-3.7.1-150600.3.9.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libaom3-debuginfo-3.7.1-150600.3.9.1
* aom-tools-debuginfo-3.7.1-150600.3.9.1
* libaom-debugsource-3.7.1-150600.3.9.1
* libaom-devel-3.7.1-150600.3.9.1
* aom-tools-3.7.1-150600.3.9.1
* libyuv-tools-20230517+a377993-150600.3.4.2
* libyuv0-20230517+a377993-150600.3.4.2
* libyuv-tools-debuginfo-20230517+a377993-150600.3.4.2
* libaom3-3.7.1-150600.3.9.1
* libyuv0-debuginfo-20230517+a377993-150600.3.4.2
* libyuv-debugsource-20230517+a377993-150600.3.4.2
* libyuv-devel-20230517+a377993-150600.3.4.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* libaom-devel-doc-3.7.1-150600.3.9.3
## References:
* https://www.suse.com/security/cve/CVE-2026-56208.html
* https://www.suse.com/security/cve/CVE-2026-56209.html
* https://www.suse.com/security/cve/CVE-2026-56210.html
* https://www.suse.com/security/cve/CVE-2026-56211.html
* https://bugzilla.suse.com/show_bug.cgi?id63678
* https://bugzilla.suse.com/show_bug.cgi?id68242
* https://bugzilla.suse.com/show_bug.cgi?id68650
* https://bugzilla.suse.com/show_bug.cgi?id68651
* https://bugzilla.suse.com/show_bug.cgi?id68653
* https://bugzilla.suse.com/show_bug.cgi?id68655