SUSE 5732 Published by

SUSE issued a batch of security advisories addressing vulnerabilities across major software packages used in production environments. The patches update critical components including Python 3.10, FFmpeg 4, libssh2, Wireshark libraries, gstreamer-plugins-bad, azure-storage-azcopy, and Perl modules. Several advisories carry important ratings due to high-impact flaws like memory corruption in FFmpeg decoders, path traversal risks in the tarfile module, and privilege escalation in IDNA validation.

openSUSE-SU-2026:0278-1: moderate: Security update for perl-Mojolicious
openSUSE-SU-2026:11460-1: moderate: libwireshark19-4.6.7-3.1 on GA media
openSUSE-SU-2026:11461-1: moderate: fuse-overlayfs-1.17-1.1 on GA media
openSUSE-SU-2026:11454-1: moderate: libssh2-1-1.11.1-4.1 on GA media
SUSE-SU-2026:3527-1: moderate: Security update for gstreamer-plugins-bad
SUSE-SU-2026:3528-1: important: Security update for azure-storage-azcopy
SUSE-SU-2026:3529-1: important: Security update for ffmpeg-4
SUSE-SU-2026:3530-1: important: Security update for python310
openSUSE-SU-2026:0279-1: moderate: Security update for perl-Mojo-JWT




openSUSE-SU-2026:0278-1: moderate: Security update for perl-Mojolicious


openSUSE Security Update: Security update for perl-Mojolicious
_______________________________

Announcement ID: openSUSE-SU-2026:0278-1
Rating: moderate
References: #1271431
Cross-References: CVE-2026-15747
CVSS scores:
CVE-2026-15747 (SUSE): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for perl-Mojolicious fixes the following issues:

- updated to 9.480.0 (9.48) see
/usr/share/doc/packages/perl-Mojolicious/Changes 9.48 2026-07-14
- Fixed a security issue where CSRF tokens were vulnerable to BREACH
attacks. Tokens are now masked with a fresh random value on every
request, instead of being reused for the whole lifetime of a
session. CVE-2026-15747 boo#1271431

- updated to 9.470.0 (9.47) see
/usr/share/doc/packages/perl-Mojolicious/Changes 9.47 2026-07-05
- Added support for the QUERY HTTP request method from RFC 10008.
- Added query and query_p methods to Mojo::UserAgent.
- Added query method to Mojolicious::Routes::Route.
- Added query method to Mojolicious::Lite.
- Added query_ok method to Test::Mojo.
- Fixed a security issue where the pure-Perl implementation of
Mojo::JSON could exhaust all available memory when decoding deeply
nested data. Decoding is now limited to 512 levels of nesting, to
match the default of Cpanel::JSON::XS.
- Fixed a memory leak in Morbo. (heikojansen)
- Fixed Mojo::File::list_tree to no longer follow symbolic links to
directories.

- updated to 9.460.0 (9.46) see
/usr/share/doc/packages/perl-Mojolicious/Changes 9.46 2026-06-04
- Added random_bytes function to Mojo::Util. (leont)
- Improved randomness for CSRF token generation. (leont)
- Fixed tls_options handling in Mojo::IOLoop::TLS. (krauro)
- Fixed spec compliance issue with attribute selectors in
Mojo::DOM::CSS.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-278=1

Package List:

- openSUSE Backports SLE-15-SP7 (noarch):

perl-Mojolicious-9.480.0-bp157.5.1

References:

https://www.suse.com/security/cve/CVE-2026-15747.html
https://bugzilla.suse.com/1271431



openSUSE-SU-2026:11460-1: moderate: libwireshark19-4.6.7-3.1 on GA media


# libwireshark19-4.6.7-3.1 on GA media

Announcement ID: openSUSE-SU-2026:11460-1
Rating: moderate

Cross-References:

* CVE-2026-15163
* CVE-2026-15164
* CVE-2026-15165
* CVE-2026-15166
* CVE-2026-15167
* CVE-2026-15168
* CVE-2026-15169
* CVE-2026-15170
* CVE-2026-15171
* CVE-2026-15172
* CVE-2026-15173
* CVE-2026-15174
* CVE-2026-9759

CVSS scores:

* CVE-2026-15163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15165 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15167 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15168 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
* CVE-2026-15169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15170 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15173 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-15174 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-9759 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Tumbleweed

An update that solves 13 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libwireshark19-4.6.7-3.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libwireshark19 4.6.7-3.1
* libwiretap16 4.6.7-3.1
* libwsutil17 4.6.7-3.1
* wireshark 4.6.7-3.1
* wireshark-devel 4.6.7-3.1
* wireshark-ui-qt 4.6.7-3.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15163.html
* https://www.suse.com/security/cve/CVE-2026-15164.html
* https://www.suse.com/security/cve/CVE-2026-15165.html
* https://www.suse.com/security/cve/CVE-2026-15166.html
* https://www.suse.com/security/cve/CVE-2026-15167.html
* https://www.suse.com/security/cve/CVE-2026-15168.html
* https://www.suse.com/security/cve/CVE-2026-15169.html
* https://www.suse.com/security/cve/CVE-2026-15170.html
* https://www.suse.com/security/cve/CVE-2026-15171.html
* https://www.suse.com/security/cve/CVE-2026-15172.html
* https://www.suse.com/security/cve/CVE-2026-15173.html
* https://www.suse.com/security/cve/CVE-2026-15174.html
* https://www.suse.com/security/cve/CVE-2026-9759.html



openSUSE-SU-2026:11461-1: moderate: fuse-overlayfs-1.17-1.1 on GA media


# fuse-overlayfs-1.17-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11461-1
Rating: moderate

Cross-References:

* CVE-2026-52791

CVSS scores:

* CVE-2026-52791 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-52791 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the fuse-overlayfs-1.17-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* fuse-overlayfs 1.17-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-52791.html



openSUSE-SU-2026:11454-1: moderate: libssh2-1-1.11.1-4.1 on GA media


# libssh2-1-1.11.1-4.1 on GA media

Announcement ID: openSUSE-SU-2026:11454-1
Rating: moderate

Cross-References:

* CVE-2026-58050
* CVE-2026-58051
* CVE-2026-66032
* CVE-2026-66033
* CVE-2026-66034
* CVE-2026-66035

CVSS scores:

* CVE-2026-58050 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-58050 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58051 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-58051 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66032 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-66032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66033 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-66033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66034 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-66034 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66035 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-66035 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 6 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libssh2-1-1.11.1-4.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libssh2-1 1.11.1-4.1
* libssh2-1-32bit 1.11.1-4.1
* libssh2-devel 1.11.1-4.1

## References:

* https://www.suse.com/security/cve/CVE-2026-58050.html
* https://www.suse.com/security/cve/CVE-2026-58051.html
* https://www.suse.com/security/cve/CVE-2026-66032.html
* https://www.suse.com/security/cve/CVE-2026-66033.html
* https://www.suse.com/security/cve/CVE-2026-66034.html
* https://www.suse.com/security/cve/CVE-2026-66035.html



SUSE-SU-2026:3527-1: moderate: Security update for gstreamer-plugins-bad


# Security update for gstreamer-plugins-bad

Announcement ID: SUSE-SU-2026:3527-1
Release Date: 2026-08-07T14:17:46Z
Rating: moderate
References:

* bsc#1268394

Cross-References:

* CVE-2026-52718

CVSS scores:

* CVE-2026-52718 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for gstreamer-plugins-bad fixes the following issue:

* CVE-2026-52718: byte count instead of a bit count in
gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and
an application crash (bsc#1268394).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3527=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3527=1

* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3527=1

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3527=1

## Package List:

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* typelib-1_0-GstPlay-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.12.1
* libgstplay-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstVa-1_0-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-1.24.0-150600.4.12.1
* libgstva-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-devel-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstDxva-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstMse-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-1.24.0-150600.4.12.1
* libgstmse-1_0-0-1.24.0-150600.4.12.1
* libgstmse-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstva-1_0-0-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-CudaGst-1_0-1.24.0-150600.4.12.1
* libgstplay-1_0-0-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-1.24.0-150600.4.12.1
* gstreamer-transcoder-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-transcoder-debuginfo-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstCuda-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.12.1
* gstreamer-transcoder-devel-1.24.0-150600.4.12.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstva-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-64bit-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstmse-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-64bit-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstplay-1_0-0-64bit-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-64bit-1.24.0-150600.4.12.1
* openSUSE Leap 15.6 (x86_64)
* libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstva-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstplay-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-32bit-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-32bit-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-32bit-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.12.1
* libgstmse-1_0-0-32bit-1.24.0-150600.4.12.1
* openSUSE Leap 15.6 (noarch)
* gstreamer-plugins-bad-lang-1.24.0-150600.4.12.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* typelib-1_0-GstPlay-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstVa-1_0-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1
* libgstva-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-devel-1.24.0-150600.4.12.1
* libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-1.24.0-150600.4.12.1
* libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-1.24.0-150600.4.12.1
* libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstDxva-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstMse-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstmse-1_0-0-1.24.0-150600.4.12.1
* libgstisoff-1_0-0-1.24.0-150600.4.12.1
* libgstva-1_0-0-1.24.0-150600.4.12.1
* libgstmse-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-CudaGst-1_0-1.24.0-150600.4.12.1
* libgstvulkan-1_0-0-1.24.0-150600.4.12.1
* libgsturidownloader-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.12.1
* libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstcodecs-1_0-0-1.24.0-150600.4.12.1
* libgstinsertbin-1_0-0-1.24.0-150600.4.12.1
* typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-1.24.0-150600.4.12.1
* libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.12.1
* libgstwayland-1_0-0-1.24.0-150600.4.12.1
* libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstbadaudio-1_0-0-1.24.0-150600.4.12.1
* libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.12.1
* typelib-1_0-GstCuda-1_0-1.24.0-150600.4.12.1
* typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.12.1
* Desktop Applications Module 15-SP7 (noarch)
* gstreamer-plugins-bad-lang-1.24.0-150600.4.12.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libgstplay-1_0-0-debuginfo-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1
* gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstphotography-1_0-0-1.24.0-150600.4.12.1
* libgstplay-1_0-0-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-1.24.0-150600.4.12.1
* libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1
* libgstplayer-1_0-0-1.24.0-150600.4.12.1

## References:

* https://www.suse.com/security/cve/CVE-2026-52718.html
* https://bugzilla.suse.com/show_bug.cgi?id68394



SUSE-SU-2026:3528-1: important: Security update for azure-storage-azcopy


# Security update for azure-storage-azcopy

Announcement ID: SUSE-SU-2026:3528-1
Release Date: 2026-08-07T14:20:23Z
Rating: important
References:

* bsc#1266657
* bsc#1272123

Cross-References:

* CVE-2026-39821
* CVE-2026-56852

CVSS scores:

* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Public Cloud Module 15-SP5
* Public Cloud Module 15-SP6
* Public Cloud Module 15-SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3

An update that solves two vulnerabilities can now be installed.

## Description:

This update for azure-storage-azcopy fixes the following issues:

Update to 10.32.6.

Security issues fixed:

* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1266657).
* CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of
truncated/invalid UTF-8 input can lead to infinite loop (bsc#1272123).

Other updates and bugfixes:

* Version 10.32.6:
* Run `go mod tidy`
* Merge tag `v10.32.4` into release/fips
* Merge `remote-tracking` branch `origin/wendi/10.32.5` into `release/fips`
* Merge branch `main` into `wendi/10.32.5`
* TASK 38260338: Updated the release pipeline to produce Linux builds capable
of complying with the FIPS 140-3 standard. (#3488)
* Bump Go toolchain and security-relevant dependencies (#3486)
* stylistic changes from copilot :)
* Update `golang.org/x/text` to v0.40.0
* Update `golang.org/x/net` to v0.57.0
* Version 10.32.5:
* Create new patch release
* Merge branch `main` into `seanmcc/bump-deps-2026-06`
* Ensure get/set ACLs are on URLs with paths (#3453)
* Print out help command on just `azcopy` (#3485)
* Bump Go toolchain and security-relevant dependencies
* Centralize HTTP client into a shared global instance (#3436)
* Remove 0-padding in mode with SetUID (#3467)
* Updated `trivy` dependency to known safe version (#3421)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* Public Cloud Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3528=1

* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3528=1

* Public Cloud Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3528=1

* Public Cloud Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3528=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3528=1

## Package List:

* Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2
* Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64)
* azure-storage-azcopy-10.32.6-150400.9.16.2

## References:

* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id66657
* https://bugzilla.suse.com/show_bug.cgi?id72123



SUSE-SU-2026:3529-1: important: Security update for ffmpeg-4


# Security update for ffmpeg-4

Announcement ID: SUSE-SU-2026:3529-1
Release Date: 2026-08-07T14:23:26Z
Rating: important
References:

* bsc#1268595
* bsc#1269490
* bsc#1272752
* bsc#1272754
* bsc#1272758
* bsc#1272765
* bsc#1272768

Cross-References:

* CVE-2026-12706
* CVE-2026-64830
* CVE-2026-64832
* CVE-2026-64835
* CVE-2026-66038
* CVE-2026-66039
* CVE-2026-8461

CVSS scores:

* CVE-2026-12706 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-12706 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-64830 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64830 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-64830 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64832 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64832 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64832 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-64832 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64835 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64835 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-64835 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-64835 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-66038 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-66038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-66038 ( NVD ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-66038 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-66038 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-66039 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-66039 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
* CVE-2026-66039 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-66039 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-66039 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-8461 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-8461 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-8461 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves seven vulnerabilities can now be installed.

## Description:

This update for ffmpeg-4 fixes the following issues:

Update to release 4.4.8.

* CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to
denial of service or remote code execution (bsc#1269490).
* CVE-2026-12706: heap use-after-free read in the RASC video decoder can lead
to denial of service (bsc#1268595).
* CVE-2026-64830: heap buffer overflow in the VobSub subtitle demuxer can lead
to arbitrary code execution (bsc#1272752).
* CVE-2026-64832: double-free in the NVIDIA NVDEC hardware decoder can lead to
can lead to memory corruption (bsc#1272754).
* CVE-2026-64835: out-of-bounds memory access in the ADX audio decoder can
lead to information disclosure and memory corruption (bsc#1272758).
* CVE-2026-66038: exposure of uninitialized heap memory by the LCL/ZLIB video
decoder can lead to sensitive information disclosure (bsc#1272768).
* CVE-2026-66039: signed integer overflow in the MACE6 audio decoder can lead
to heap corruption and arbitrary code execution (bsc#1272765).

Other updates and bugfixes:

* Release 4.4.8
* Various bug fixes to codecs
* avcodec/magicyuv: Fix 1 line MEDIAN slices
* avcodec/magicyuv: Expand the `s->interlaced` slice-height sanity check
* avcodec/magicyuv: reject `slice_height` misaligned with chroma vshift
* Address build failure on s390x.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3529=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3529=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3529=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3529=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3529=1

## Package List:

* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libswscale5_9-debuginfo-4.4.8-150400.3.72.1
* libswresample3_9-4.4.8-150400.3.72.1
* ffmpeg-4-libavutil-devel-4.4.8-150400.3.72.1
* ffmpeg-4-4.4.8-150400.3.72.1
* libpostproc55_9-4.4.8-150400.3.72.1
* ffmpeg-4-libavdevice-devel-4.4.8-150400.3.72.1
* ffmpeg-4-libavfilter-devel-4.4.8-150400.3.72.1
* libavdevice58_13-4.4.8-150400.3.72.1
* libavfilter7_110-4.4.8-150400.3.72.1
* ffmpeg-4-debuginfo-4.4.8-150400.3.72.1
* ffmpeg-4-libswresample-devel-4.4.8-150400.3.72.1
* libavformat58_76-debuginfo-4.4.8-150400.3.72.1
* ffmpeg-4-libavcodec-devel-4.4.8-150400.3.72.1
* libavfilter7_110-debuginfo-4.4.8-150400.3.72.1
* ffmpeg-4-debugsource-4.4.8-150400.3.72.1
* ffmpeg-4-libavresample-devel-4.4.8-150400.3.72.1
* ffmpeg-4-libavformat-devel-4.4.8-150400.3.72.1
* ffmpeg-4-libpostproc-devel-4.4.8-150400.3.72.1
* libavcodec58_134-4.4.8-150400.3.72.1
* libavcodec58_134-debuginfo-4.4.8-150400.3.72.1
* libavresample4_0-4.4.8-150400.3.72.1
* libavresample4_0-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-debuginfo-4.4.8-150400.3.72.1
* libpostproc55_9-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-4.4.8-150400.3.72.1
* ffmpeg-4-private-devel-4.4.8-150400.3.72.1
* ffmpeg-4-libswscale-devel-4.4.8-150400.3.72.1
* libavdevice58_13-debuginfo-4.4.8-150400.3.72.1
* libswresample3_9-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-4.4.8-150400.3.72.1
* libavutil56_70-4.4.8-150400.3.72.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libavresample4_0-64bit-4.4.8-150400.3.72.1
* libswresample3_9-64bit-debuginfo-4.4.8-150400.3.72.1
* libavdevice58_13-64bit-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-64bit-4.4.8-150400.3.72.1
* libavcodec58_134-64bit-4.4.8-150400.3.72.1
* libavformat58_76-64bit-debuginfo-4.4.8-150400.3.72.1
* libavfilter7_110-64bit-debuginfo-4.4.8-150400.3.72.1
* libswresample3_9-64bit-4.4.8-150400.3.72.1
* libavutil56_70-64bit-4.4.8-150400.3.72.1
* libpostproc55_9-64bit-4.4.8-150400.3.72.1
* libpostproc55_9-64bit-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-64bit-debuginfo-4.4.8-150400.3.72.1
* libavfilter7_110-64bit-4.4.8-150400.3.72.1
* libavdevice58_13-64bit-4.4.8-150400.3.72.1
* libswscale5_9-64bit-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-64bit-4.4.8-150400.3.72.1
* libavcodec58_134-64bit-debuginfo-4.4.8-150400.3.72.1
* libavresample4_0-64bit-debuginfo-4.4.8-150400.3.72.1
* openSUSE Leap 15.4 (x86_64)
* libavcodec58_134-32bit-4.4.8-150400.3.72.1
* libswresample3_9-32bit-4.4.8-150400.3.72.1
* libswscale5_9-32bit-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-32bit-4.4.8-150400.3.72.1
* libavformat58_76-32bit-4.4.8-150400.3.72.1
* libavresample4_0-32bit-4.4.8-150400.3.72.1
* libavresample4_0-32bit-debuginfo-4.4.8-150400.3.72.1
* libswresample3_9-32bit-debuginfo-4.4.8-150400.3.72.1
* libavdevice58_13-32bit-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-32bit-debuginfo-4.4.8-150400.3.72.1
* libavfilter7_110-32bit-4.4.8-150400.3.72.1
* libpostproc55_9-32bit-4.4.8-150400.3.72.1
* libavfilter7_110-32bit-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-32bit-4.4.8-150400.3.72.1
* libavdevice58_13-32bit-4.4.8-150400.3.72.1
* libpostproc55_9-32bit-debuginfo-4.4.8-150400.3.72.1
* libavcodec58_134-32bit-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-32bit-debuginfo-4.4.8-150400.3.72.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libswresample3_9-4.4.8-150400.3.72.1
* libavformat58_76-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-4.4.8-150400.3.72.1
* libpostproc55_9-debuginfo-4.4.8-150400.3.72.1
* ffmpeg-4-debugsource-4.4.8-150400.3.72.1
* libswresample3_9-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-4.4.8-150400.3.72.1
* libpostproc55_9-4.4.8-150400.3.72.1
* libavcodec58_134-4.4.8-150400.3.72.1
* ffmpeg-4-debuginfo-4.4.8-150400.3.72.1
* libavcodec58_134-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-4.4.8-150400.3.72.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libswresample3_9-4.4.8-150400.3.72.1
* libavformat58_76-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-debuginfo-4.4.8-150400.3.72.1
* libpostproc55_9-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-4.4.8-150400.3.72.1
* ffmpeg-4-debugsource-4.4.8-150400.3.72.1
* libswresample3_9-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-4.4.8-150400.3.72.1
* libpostproc55_9-4.4.8-150400.3.72.1
* libavcodec58_134-4.4.8-150400.3.72.1
* ffmpeg-4-debuginfo-4.4.8-150400.3.72.1
* libavcodec58_134-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-4.4.8-150400.3.72.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libswresample3_9-4.4.8-150400.3.72.1
* libavformat58_76-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-debuginfo-4.4.8-150400.3.72.1
* libpostproc55_9-debuginfo-4.4.8-150400.3.72.1
* libavformat58_76-4.4.8-150400.3.72.1
* ffmpeg-4-debugsource-4.4.8-150400.3.72.1
* libswresample3_9-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-4.4.8-150400.3.72.1
* libpostproc55_9-4.4.8-150400.3.72.1
* libavcodec58_134-4.4.8-150400.3.72.1
* ffmpeg-4-debuginfo-4.4.8-150400.3.72.1
* libavcodec58_134-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-4.4.8-150400.3.72.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libswresample3_9-4.4.8-150400.3.72.1
* libavformat58_76-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-debuginfo-4.4.8-150400.3.72.1
* libpostproc55_9-debuginfo-4.4.8-150400.3.72.1
* ffmpeg-4-debugsource-4.4.8-150400.3.72.1
* libswresample3_9-debuginfo-4.4.8-150400.3.72.1
* libavutil56_70-4.4.8-150400.3.72.1
* libpostproc55_9-4.4.8-150400.3.72.1
* ffmpeg-4-debuginfo-4.4.8-150400.3.72.1
* libavcodec58_134-4.4.8-150400.3.72.1
* libavformat58_76-4.4.8-150400.3.72.1
* libavcodec58_134-debuginfo-4.4.8-150400.3.72.1
* libswscale5_9-4.4.8-150400.3.72.1

## References:

* https://www.suse.com/security/cve/CVE-2026-12706.html
* https://www.suse.com/security/cve/CVE-2026-64830.html
* https://www.suse.com/security/cve/CVE-2026-64832.html
* https://www.suse.com/security/cve/CVE-2026-64835.html
* https://www.suse.com/security/cve/CVE-2026-66038.html
* https://www.suse.com/security/cve/CVE-2026-66039.html
* https://www.suse.com/security/cve/CVE-2026-8461.html
* https://bugzilla.suse.com/show_bug.cgi?id68595
* https://bugzilla.suse.com/show_bug.cgi?id69490
* https://bugzilla.suse.com/show_bug.cgi?id72752
* https://bugzilla.suse.com/show_bug.cgi?id72754
* https://bugzilla.suse.com/show_bug.cgi?id72758
* https://bugzilla.suse.com/show_bug.cgi?id72765
* https://bugzilla.suse.com/show_bug.cgi?id72768



SUSE-SU-2026:3530-1: important: Security update for python310


# Security update for python310

Announcement ID: SUSE-SU-2026:3530-1
Release Date: 2026-08-07T14:30:12Z
Rating: important
References:

* bsc#1211301
* bsc#1264962
* bsc#1265268
* bsc#1267581
* bsc#1267821
* bsc#1268375
* bsc#1268977
* bsc#1269066
* bsc#1269788
* bsc#1269959
* bsc#1271192

Cross-References:

* CVE-2026-0864
* CVE-2026-11940
* CVE-2026-11972
* CVE-2026-15308
* CVE-2026-3276
* CVE-2026-4360
* CVE-2026-7210
* CVE-2026-7774
* CVE-2026-8328

CVSS scores:

* CVE-2026-0864 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-0864 ( NVD ): 4.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11940 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-11940 ( NVD ): 7.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-11972 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11972 ( NVD ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-15308 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-3276 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-4360 ( NVD ): 2.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-7210 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7210 ( NVD ): 6.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-7774 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-7774 ( NVD ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-8328 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-8328 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves nine vulnerabilities and has two security fixes can now be
installed.

## Description:

This update for python310 fixes the following issues:

Security issues fixed:

* CVE-2026-0864: improper handling of line-ending characters can lead to
configuration file injection when the `configparser` module is used
(bsc#1269066).
* CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to
DoS when processing specially crafted Unicode input (bsc#1267581).
* CVE-2026-4360: in the `Tarfile.extract()` function, the filter parameter is
not passed properly when extracting hardlinks (bsc#1269959).
* CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use
insufficient entropy for Expat hash-flooding protection (bsc#1264962).
* CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing
outside the extraction directory (bsc#1267821).
* CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-
supplied PASV host address (bsc#1265268).
* CVE-2026-11940: tarfile extraction filter bypass via a crafted archive
allows escaping the destination directory and enables arbitrary file reads
and writes (bsc#1268977).
* CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile
module streaming mode can lead to DoS (bsc#1269788).
* CVE-2026-15308: incremental `HTMLParser` allows CPU-exhaustion DoS via
repeated unterminated markup declarations (bsc#1271192).

Non security issues fixed:

* Improve testing for the support of `IPPROTO_UDPLITE`, which could be not
present although header files are (bsc#1268375).
* Use the system-wide crypto-policies (bsc#1211301).
* Support changes required for Sphinx 9.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3530=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3530=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3530=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3530=1

* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3530=1

## Package List:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2
* python310-base-3.10.20-150400.4.115.2
* python310-debuginfo-3.10.20-150400.4.115.1
* python310-core-debugsource-3.10.20-150400.4.115.2
* python310-3.10.20-150400.4.115.1
* python310-curses-debuginfo-3.10.20-150400.4.115.1
* python310-tools-3.10.20-150400.4.115.2
* libpython3_10-1_0-3.10.20-150400.4.115.2
* python310-tk-debuginfo-3.10.20-150400.4.115.1
* python310-idle-3.10.20-150400.4.115.1
* python310-debugsource-3.10.20-150400.4.115.1
* python310-curses-3.10.20-150400.4.115.1
* python310-tk-3.10.20-150400.4.115.1
* python310-dbm-3.10.20-150400.4.115.1
* python310-dbm-debuginfo-3.10.20-150400.4.115.1
* python310-base-debuginfo-3.10.20-150400.4.115.2
* python310-devel-3.10.20-150400.4.115.2
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python310-doc-3.10.20-150400.4.115.1
* python310-testsuite-debuginfo-3.10.20-150400.4.115.2
* python310-debuginfo-3.10.20-150400.4.115.1
* python310-tools-3.10.20-150400.4.115.2
* python310-dbm-debuginfo-3.10.20-150400.4.115.1
* python310-devel-3.10.20-150400.4.115.2
* python310-base-debuginfo-3.10.20-150400.4.115.2
* python310-curses-debuginfo-3.10.20-150400.4.115.1
* python310-debugsource-3.10.20-150400.4.115.1
* libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2
* python310-3.10.20-150400.4.115.1
* python310-tk-3.10.20-150400.4.115.1
* libpython3_10-1_0-3.10.20-150400.4.115.2
* python310-base-3.10.20-150400.4.115.2
* python310-core-debugsource-3.10.20-150400.4.115.2
* python310-tk-debuginfo-3.10.20-150400.4.115.1
* python310-idle-3.10.20-150400.4.115.1
* python310-curses-3.10.20-150400.4.115.1
* python310-dbm-3.10.20-150400.4.115.1
* python310-doc-devhelp-3.10.20-150400.4.115.1
* python310-testsuite-3.10.20-150400.4.115.2
* openSUSE Leap 15.4 (x86_64)
* python310-base-32bit-debuginfo-3.10.20-150400.4.115.2
* libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.115.2
* libpython3_10-1_0-32bit-3.10.20-150400.4.115.2
* python310-base-32bit-3.10.20-150400.4.115.2
* python310-32bit-debuginfo-3.10.20-150400.4.115.1
* python310-32bit-3.10.20-150400.4.115.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.115.2
* python310-base-64bit-debuginfo-3.10.20-150400.4.115.2
* python310-64bit-3.10.20-150400.4.115.1
* libpython3_10-1_0-64bit-3.10.20-150400.4.115.2
* python310-base-64bit-3.10.20-150400.4.115.2
* python310-64bit-debuginfo-3.10.20-150400.4.115.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2
* python310-base-3.10.20-150400.4.115.2
* python310-curses-debuginfo-3.10.20-150400.4.115.1
* python310-core-debugsource-3.10.20-150400.4.115.2
* python310-3.10.20-150400.4.115.1
* python310-debuginfo-3.10.20-150400.4.115.1
* python310-base-debuginfo-3.10.20-150400.4.115.2
* python310-tools-3.10.20-150400.4.115.2
* python310-tk-debuginfo-3.10.20-150400.4.115.1
* python310-idle-3.10.20-150400.4.115.1
* python310-debugsource-3.10.20-150400.4.115.1
* python310-curses-3.10.20-150400.4.115.1
* python310-tk-3.10.20-150400.4.115.1
* python310-dbm-3.10.20-150400.4.115.1
* python310-dbm-debuginfo-3.10.20-150400.4.115.1
* python310-devel-3.10.20-150400.4.115.2
* libpython3_10-1_0-3.10.20-150400.4.115.2
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2
* python310-base-3.10.20-150400.4.115.2
* python310-3.10.20-150400.4.115.1
* python310-debuginfo-3.10.20-150400.4.115.1
* python310-core-debugsource-3.10.20-150400.4.115.2
* python310-curses-debuginfo-3.10.20-150400.4.115.1
* python310-tools-3.10.20-150400.4.115.2
* python310-tk-debuginfo-3.10.20-150400.4.115.1
* python310-idle-3.10.20-150400.4.115.1
* python310-devel-3.10.20-150400.4.115.2
* python310-debugsource-3.10.20-150400.4.115.1
* python310-curses-3.10.20-150400.4.115.1
* python310-tk-3.10.20-150400.4.115.1
* python310-dbm-3.10.20-150400.4.115.1
* python310-dbm-debuginfo-3.10.20-150400.4.115.1
* python310-base-debuginfo-3.10.20-150400.4.115.2
* libpython3_10-1_0-3.10.20-150400.4.115.2
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* python310-3.10.20-150400.4.115.1
* python310-debuginfo-3.10.20-150400.4.115.1
* python310-base-3.10.20-150400.4.115.2
* python310-core-debugsource-3.10.20-150400.4.115.2
* python310-base-debuginfo-3.10.20-150400.4.115.2
* python310-curses-debuginfo-3.10.20-150400.4.115.1
* libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2
* python310-tools-3.10.20-150400.4.115.2
* python310-tk-debuginfo-3.10.20-150400.4.115.1
* python310-idle-3.10.20-150400.4.115.1
* python310-debugsource-3.10.20-150400.4.115.1
* python310-curses-3.10.20-150400.4.115.1
* python310-tk-3.10.20-150400.4.115.1
* python310-dbm-3.10.20-150400.4.115.1
* python310-dbm-debuginfo-3.10.20-150400.4.115.1
* python310-devel-3.10.20-150400.4.115.2
* libpython3_10-1_0-3.10.20-150400.4.115.2

## References:

* https://www.suse.com/security/cve/CVE-2026-0864.html
* https://www.suse.com/security/cve/CVE-2026-11940.html
* https://www.suse.com/security/cve/CVE-2026-11972.html
* https://www.suse.com/security/cve/CVE-2026-15308.html
* https://www.suse.com/security/cve/CVE-2026-3276.html
* https://www.suse.com/security/cve/CVE-2026-4360.html
* https://www.suse.com/security/cve/CVE-2026-7210.html
* https://www.suse.com/security/cve/CVE-2026-7774.html
* https://www.suse.com/security/cve/CVE-2026-8328.html
* https://bugzilla.suse.com/show_bug.cgi?id11301
* https://bugzilla.suse.com/show_bug.cgi?id64962
* https://bugzilla.suse.com/show_bug.cgi?id65268
* https://bugzilla.suse.com/show_bug.cgi?id67581
* https://bugzilla.suse.com/show_bug.cgi?id67821
* https://bugzilla.suse.com/show_bug.cgi?id68375
* https://bugzilla.suse.com/show_bug.cgi?id68977
* https://bugzilla.suse.com/show_bug.cgi?id69066
* https://bugzilla.suse.com/show_bug.cgi?id69788
* https://bugzilla.suse.com/show_bug.cgi?id69959
* https://bugzilla.suse.com/show_bug.cgi?id71192



openSUSE-SU-2026:0279-1: moderate: Security update for perl-Mojo-JWT


openSUSE Security Update: Security update for perl-Mojo-JWT
_______________________________

Announcement ID: openSUSE-SU-2026:0279-1
Rating: moderate
References: #1271935
Cross-References: CVE-2026-9537
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________

An update that fixes one vulnerability is now available.

Description:

This update for perl-Mojo-JWT fixes the following issues:

- CVE-2026-9537: verification of HMAC signatures with a non-constant-time
string comparison (boo#1271935)

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-279=1

Package List:

- openSUSE Backports SLE-15-SP7 (noarch):

perl-Mojo-JWT-0.09-bp157.2.3.1

References:

https://www.suse.com/security/cve/CVE-2026-9537.html
https://bugzilla.suse.com/1271935