SUSE-SU-2026:3132-1: important: Security update for python311
SUSE-SU-2026:3133-1: important: Security update for gstreamer-plugins-bad
SUSE-SU-2026:3136-1: important: Security update for 389-ds
SUSE-SU-2026:3137-1: important: Security update for 389-ds
SUSE-SU-2026:3126-1: important: Security update for podman
openSUSE-SU-2026:11309-1: moderate: chromedriver-150.0.7871.128-1.1 on GA media
openSUSE-SU-2026:11308-1: moderate: libsuricata8_0_6-8.0.6-1.1 on GA media
SUSE-SU-2026:3125-1: important: Security update for gstreamer-plugins-bad
SUSE-SU-2026:3123-1: important: Security update for shibboleth-sp
SUSE-SU-2026:3132-1: important: Security update for python311
# Security update for python311
Announcement ID: SUSE-SU-2026:3132-1
Release Date: 2026-07-20T13:56:06Z
Rating: important
References:
* bsc#1261969
* bsc#1262098
* bsc#1262319
* bsc#1262654
Cross-References:
* CVE-2026-1502
* CVE-2026-4786
* CVE-2026-6019
* CVE-2026-6100
CVSS scores:
* CVE-2026-1502 ( SUSE ): 5.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-1502 ( NVD ): 5.7
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4786 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-4786 ( NVD ): 7.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-6019 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-6019 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2026-6100 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-6100 ( NVD ): 9.1
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves four vulnerabilities can now be installed.
## Description:
This update for python311 fixes the following issues
* CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers
or host (bsc#1261969).
* CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows
command injection via the `webbrowser.open()` API (bsc#1262319).
* CVE-2026-6019: HTML parser-sensitive sequence not neutralized by
`http.cookies.Morsel.js_output()` (bsc#1262654).
* CVE-2026-6100: use-after-free in decompression modules when a memory
allocation fails with a `MemoryError` and the decompression instance is re-
used (bsc#1262098).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3132=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3132=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3132=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3132=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3132=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3132=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3132=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3132=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3132=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3132=1
## Package List:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-testsuite-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-testsuite-debuginfo-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* python311-base-64bit-debuginfo-3.11.15-150400.9.91.1
* python311-64bit-3.11.15-150400.9.91.1
* python311-64bit-debuginfo-3.11.15-150400.9.91.1
* python311-base-64bit-3.11.15-150400.9.91.1
* libpython3_11-1_0-64bit-3.11.15-150400.9.91.1
* libpython3_11-1_0-64bit-debuginfo-3.11.15-150400.9.91.1
* openSUSE Leap 15.4 (x86_64)
* libpython3_11-1_0-32bit-3.11.15-150400.9.91.1
* libpython3_11-1_0-32bit-debuginfo-3.11.15-150400.9.91.1
* python311-base-32bit-3.11.15-150400.9.91.1
* python311-32bit-3.11.15-150400.9.91.1
* python311-base-32bit-debuginfo-3.11.15-150400.9.91.1
* python311-32bit-debuginfo-3.11.15-150400.9.91.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
* Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libpython3_11-1_0-3.11.15-150400.9.91.1
* python311-tools-3.11.15-150400.9.91.1
* python311-debuginfo-3.11.15-150400.9.91.1
* python311-tk-3.11.15-150400.9.91.1
* python311-doc-3.11.15-150400.9.91.1
* python311-idle-3.11.15-150400.9.91.1
* python311-doc-devhelp-3.11.15-150400.9.91.1
* python311-base-3.11.15-150400.9.91.1
* libpython3_11-1_0-debuginfo-3.11.15-150400.9.91.1
* python311-3.11.15-150400.9.91.1
* python311-debugsource-3.11.15-150400.9.91.1
* python311-dbm-debuginfo-3.11.15-150400.9.91.1
* python311-core-debugsource-3.11.15-150400.9.91.1
* python311-devel-3.11.15-150400.9.91.1
* python311-curses-3.11.15-150400.9.91.1
* python311-tk-debuginfo-3.11.15-150400.9.91.1
* python311-curses-debuginfo-3.11.15-150400.9.91.1
* python311-base-debuginfo-3.11.15-150400.9.91.1
* python311-dbm-3.11.15-150400.9.91.1
## References:
* https://www.suse.com/security/cve/CVE-2026-1502.html
* https://www.suse.com/security/cve/CVE-2026-4786.html
* https://www.suse.com/security/cve/CVE-2026-6019.html
* https://www.suse.com/security/cve/CVE-2026-6100.html
* https://bugzilla.suse.com/show_bug.cgi?id61969
* https://bugzilla.suse.com/show_bug.cgi?id62098
* https://bugzilla.suse.com/show_bug.cgi?id62319
* https://bugzilla.suse.com/show_bug.cgi?id62654
SUSE-SU-2026:3133-1: important: Security update for gstreamer-plugins-bad
# Security update for gstreamer-plugins-bad
Announcement ID: SUSE-SU-2026:3133-1
Release Date: 2026-07-20T13:58:55Z
Rating: important
References:
* bsc#1268168
* bsc#1268406
* bsc#1268408
* bsc#1268410
* bsc#1268971
* bsc#1271051
* bsc#1271168
Cross-References:
* CVE-2026-12892
* CVE-2026-14935
* CVE-2026-52720
* CVE-2026-52721
* CVE-2026-52722
* CVE-2026-53702
* CVE-2026-59692
CVSS scores:
* CVE-2026-12892 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-14935 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-59692 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for gstreamer-plugins-bad fixes the following issues
* CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice
parser (bsc#1268971).
* CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to
inverted presence check (bsc#1271051).
* CVE-2026-52720: invalid check of total area instead of individual dimensions
could trigger a heap out-of-bounds write (bsc#1268406).
* CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could
cause an out-of-bounds read (bsc#1268408).
* CVE-2026-52722: crafted VMnc stream with large cursor dimensions can
overflow signed integer (bsc#1268410).
* CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could
result in a stack buffer overflow (bsc#1268168).
* CVE-2026-59692: unvalidated peer certificate Subject DN printed during a
DTLS handshake could cause a stack buffer overflow (bsc#1271168).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3133=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3133=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3133=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3133=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3133=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* gstreamer-plugins-bad-1.20.1-150400.3.29.1
* libgstva-1_0-0-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-1.20.1-150400.3.29.1
* libgsttranscoder-1_0-0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1
* gstreamer-transcoder-debuginfo-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-1.20.1-150400.3.29.1
* gstreamer-transcoder-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-1.20.1-150400.3.29.1
* gstreamer-transcoder-devel-1.20.1-150400.3.29.1
* libgstplay-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-1.20.1-150400.3.29.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstVulkan-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstVulkanWayland-1_0-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstVulkanXCB-1_0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstTranscoder-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libgstcodecparsers-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstva-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstplay-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-64bit-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-64bit-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-64bit-debuginfo-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-64bit-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-64bit-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstplay-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstva-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-64bit-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-64bit-debuginfo-1.20.1-150400.3.29.1
* openSUSE Leap 15.4 (x86_64)
* libgstisoff-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstplay-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-32bit-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-32bit-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-32bit-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-32bit-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-32bit-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstva-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-32bit-debuginfo-1.20.1-150400.3.29.1
* libgstplay-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-32bit-1.20.1-150400.3.29.1
* libgstva-1_0-0-32bit-1.20.1-150400.3.29.1
* openSUSE Leap 15.4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* gstreamer-plugins-bad-1.20.1-150400.3.29.1
* libgstva-1_0-0-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-1.20.1-150400.3.29.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* gstreamer-plugins-bad-1.20.1-150400.3.29.1
* libgstva-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstplay-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-1.20.1-150400.3.29.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* gstreamer-plugins-bad-1.20.1-150400.3.29.1
* libgstva-1_0-0-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-1.20.1-150400.3.29.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* gstreamer-plugins-bad-1.20.1-150400.3.29.1
* libgstva-1_0-0-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.29.1
* typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.29.1
* typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstvulkan-1_0-0-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-1.20.1-150400.3.29.1
* libgstmpegts-1_0-0-1.20.1-150400.3.29.1
* libgstplay-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-1.20.1-150400.3.29.1
* libgstwayland-1_0-0-1.20.1-150400.3.29.1
* libgstva-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-1.20.1-150400.3.29.1
* libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.29.1
* libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstsctp-1_0-0-1.20.1-150400.3.29.1
* libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-1.20.1-150400.3.29.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.29.1
* libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstPlay-1_0-1.20.1-150400.3.29.1
* libgsturidownloader-1_0-0-1.20.1-150400.3.29.1
* libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-debugsource-1.20.1-150400.3.29.1
* gstreamer-plugins-bad-devel-1.20.1-150400.3.29.1
* libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.29.1
* typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.29.1
* libgstcodecs-1_0-0-1.20.1-150400.3.29.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* gstreamer-plugins-bad-lang-1.20.1-150400.3.29.1
## References:
* https://www.suse.com/security/cve/CVE-2026-12892.html
* https://www.suse.com/security/cve/CVE-2026-14935.html
* https://www.suse.com/security/cve/CVE-2026-52720.html
* https://www.suse.com/security/cve/CVE-2026-52721.html
* https://www.suse.com/security/cve/CVE-2026-52722.html
* https://www.suse.com/security/cve/CVE-2026-53702.html
* https://www.suse.com/security/cve/CVE-2026-59692.html
* https://bugzilla.suse.com/show_bug.cgi?id68168
* https://bugzilla.suse.com/show_bug.cgi?id68406
* https://bugzilla.suse.com/show_bug.cgi?id68408
* https://bugzilla.suse.com/show_bug.cgi?id68410
* https://bugzilla.suse.com/show_bug.cgi?id68971
* https://bugzilla.suse.com/show_bug.cgi?id71051
* https://bugzilla.suse.com/show_bug.cgi?id71168
SUSE-SU-2026:3136-1: important: Security update for 389-ds
# Security update for 389-ds
Announcement ID: SUSE-SU-2026:3136-1
Release Date: 2026-07-20T15:10:11Z
Rating: important
References:
* bsc#1267975
* bsc#1268041
* bsc#1268046
* bsc#1268047
* bsc#1268057
* bsc#1268058
* bsc#1268060
* bsc#1268062
* bsc#1268064
* bsc#1268065
* bsc#1268115
* bsc#1268298
* bsc#1268491
* bsc#1269120
* bsc#1270695
Cross-References:
* CVE-2026-11610
* CVE-2026-11611
* CVE-2026-11774
* CVE-2026-11785
* CVE-2026-11786
* CVE-2026-11787
* CVE-2026-11788
* CVE-2026-11789
* CVE-2026-11790
* CVE-2026-11791
* CVE-2026-11792
* CVE-2026-11793
* CVE-2026-11884
* CVE-2026-12528
CVSS scores:
* CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11611 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11774 ( SUSE ): 7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11785 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11787 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11788 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11791 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11792 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11793 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves 14 vulnerabilities and has one security fix can now be
installed.
## Description:
This update for 389-ds fixes the following issues:
Update to version 2.2.10~git255.752643c78.
Security issues fixed:
* CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap
buffer overflow when processing a specially crafted oversized LDAP UNBIND
packet (bsc#1270695).
* CVE-2026-11611: Content Synchronization persistent search plugin allows
unbounded memory growth when an authenticated client stops reading sync
responses(bsc#1267975).
* CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to
heap buffer overflow when processing a crafted SASL packet length prefix
(bsc#1268298).
* CVE-2026-11785: type confusion in the SSO token handler can cause partial
stack address information disclosure in LDA responses (bsc#1268065).
* CVE-2026-11786: out-of-bounds read in the LDIF parser when processing
attribute types with trailing semicolons during database import
(bsc#1268064).
* CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan
can lead to a heap buffer overread in string filter parsing(bsc#1268062).
* CVE-2026-11788: missing allocation check in the dereference control plugin
before using a BER structure can lead to LDAP server crash when the system
is under memory pressure (bsc#1268057).
* CVE-2026-11789: integer underflow in the SMD5 password storage plugin can
lead to a buffer overread when computing salt length from a crafted password
hash shorter than 16 bytes (bsc#1268058).
* CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password
storage plugin can lead to excessive resource consumption during
authentication and cause a DoS (bsc#1268060).
* CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a
`ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047).
* CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a
heap and log output corruption whe a short cleartext password is logged
(bsc#1268046).
* CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack
buffer overflow when processing an algorithm ID during parsing of
reversible-encrypted attribute values (bsc#1268041).
* CVE-2026-11884: improper string management can lead to heap buffer overflow
when serializing objectclass definitions (bsc#1268115).
* CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()`
function can lead to heap buffer overflow when processing a malformed ACI
string (bsc#1268491).
Other updates and bugfixes:
* Version 2.2.10~git255.752643c78.
* Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`
* Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password
Masking
* Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)
* Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch
(#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures
(#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI
(#7572)
* Issue 7593 - Reject invalid SASL packet length values in
`sasl_io_start_packet` (#7594)
* Issue 3555 - UI - Fix audit issue with `npm` \- `ws`, `js-yaml`, `js-yaml` ,
`postcss`, `uuid`
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema
reload
* Issue 7558 - During online import, the IDL should be created with in-depth
first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - `lib389` \- Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss
(#7540)
* Issue 7549 - Substring index should validate minimum
`nsSubStrBegin`/`nsSubStrEnd` values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-
default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441)
* Fix test389 imports on older branches
* Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - `AddressSanitizer`: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with `npm` \- `brace-expansion` (#7556)
* Issue 7554 - deref plugin null pointer dereference if `ber_init` fails
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - `dblayer_bulk_nextdata` should not return an error when
maxrecords is hit
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3136=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3136=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3136=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1
* lib389-2.2.10~git255.752643c78-150600.8.32.1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-snmp-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-snmp-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1
* lib389-2.2.10~git255.752643c78-150600.8.32.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* 389-ds-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150600.8.32.1
* lib389-2.2.10~git255.752643c78-150600.8.32.1
* libsvrcore0-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-devel-2.2.10~git255.752643c78-150600.8.32.1
* 389-ds-2.2.10~git255.752643c78-150600.8.32.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11610.html
* https://www.suse.com/security/cve/CVE-2026-11611.html
* https://www.suse.com/security/cve/CVE-2026-11774.html
* https://www.suse.com/security/cve/CVE-2026-11785.html
* https://www.suse.com/security/cve/CVE-2026-11786.html
* https://www.suse.com/security/cve/CVE-2026-11787.html
* https://www.suse.com/security/cve/CVE-2026-11788.html
* https://www.suse.com/security/cve/CVE-2026-11789.html
* https://www.suse.com/security/cve/CVE-2026-11790.html
* https://www.suse.com/security/cve/CVE-2026-11791.html
* https://www.suse.com/security/cve/CVE-2026-11792.html
* https://www.suse.com/security/cve/CVE-2026-11793.html
* https://www.suse.com/security/cve/CVE-2026-11884.html
* https://www.suse.com/security/cve/CVE-2026-12528.html
* https://bugzilla.suse.com/show_bug.cgi?id67975
* https://bugzilla.suse.com/show_bug.cgi?id68041
* https://bugzilla.suse.com/show_bug.cgi?id68046
* https://bugzilla.suse.com/show_bug.cgi?id68047
* https://bugzilla.suse.com/show_bug.cgi?id68057
* https://bugzilla.suse.com/show_bug.cgi?id68058
* https://bugzilla.suse.com/show_bug.cgi?id68060
* https://bugzilla.suse.com/show_bug.cgi?id68062
* https://bugzilla.suse.com/show_bug.cgi?id68064
* https://bugzilla.suse.com/show_bug.cgi?id68065
* https://bugzilla.suse.com/show_bug.cgi?id68115
* https://bugzilla.suse.com/show_bug.cgi?id68298
* https://bugzilla.suse.com/show_bug.cgi?id68491
* https://bugzilla.suse.com/show_bug.cgi?id69120
* https://bugzilla.suse.com/show_bug.cgi?id70695
SUSE-SU-2026:3137-1: important: Security update for 389-ds
# Security update for 389-ds
Announcement ID: SUSE-SU-2026:3137-1
Release Date: 2026-07-20T15:10:33Z
Rating: important
References:
* bsc#1267975
* bsc#1268041
* bsc#1268046
* bsc#1268047
* bsc#1268057
* bsc#1268058
* bsc#1268060
* bsc#1268062
* bsc#1268064
* bsc#1268065
* bsc#1268115
* bsc#1268298
* bsc#1268491
* bsc#1269120
* bsc#1270695
Cross-References:
* CVE-2026-11610
* CVE-2026-11611
* CVE-2026-11774
* CVE-2026-11785
* CVE-2026-11786
* CVE-2026-11787
* CVE-2026-11788
* CVE-2026-11789
* CVE-2026-11790
* CVE-2026-11791
* CVE-2026-11792
* CVE-2026-11793
* CVE-2026-11884
* CVE-2026-12528
CVSS scores:
* CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11611 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11774 ( SUSE ): 7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11785 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11787 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11788 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11791 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11792 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11793 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves 14 vulnerabilities and has one security fix can now be
installed.
## Description:
This update for 389-ds fixes the following issues:
Update to version 2.2.10~git255.752643c78.
Security issues fixed:
* CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap
buffer overflow when processing a specially crafted oversized LDAP UNBIND
packet (bsc#1270695).
* CVE-2026-11611: Content Synchronization persistent search plugin allows
unbounded memory growth when an authenticated client stops reading sync
responses(bsc#1267975).
* CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to
heap buffer overflow when processing a crafted SASL packet length prefix
(bsc#1268298).
* CVE-2026-11785: type confusion in the SSO token handler can cause partial
stack address information disclosure in LDA responses (bsc#1268065).
* CVE-2026-11786: out-of-bounds read in the LDIF parser when processing
attribute types with trailing semicolons during database import
(bsc#1268064).
* CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan
can lead to a heap buffer overread in string filter parsing(bsc#1268062).
* CVE-2026-11788: missing allocation check in the dereference control plugin
before using a BER structure can lead to LDAP server crash when the system
is under memory pressure (bsc#1268057).
* CVE-2026-11789: integer underflow in the SMD5 password storage plugin can
lead to a buffer overread when computing salt length from a crafted password
hash shorter than 16 bytes (bsc#1268058).
* CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password
storage plugin can lead to excessive resource consumption during
authentication and cause a DoS (bsc#1268060).
* CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a
`ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047).
* CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a
heap and log output corruption whe a short cleartext password is logged
(bsc#1268046).
* CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack
buffer overflow when processing an algorithm ID during parsing of
reversible-encrypted attribute values (bsc#1268041).
* CVE-2026-11884: improper string management can lead to heap buffer overflow
when serializing objectclass definitions (bsc#1268115).
* CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()`
function can lead to heap buffer overflow when processing a malformed ACI
string (bsc#1268491).
Other updates and bugfixes:
* Version 2.2.10~git255.752643c78.
* Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`
* Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password
Masking
* Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)
* Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch
(#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures
(#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI
(#7572)
* Issue 7593 - Reject invalid SASL packet length values in
`sasl_io_start_packet` (#7594)
* Issue 3555 - UI - Fix audit issue with `npm` \- `ws`, `js-yaml`, `js-yaml` ,
`postcss`, `uuid`
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema
reload
* Issue 7558 - During online import, the IDL should be created with in-depth
first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - `lib389` \- Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss
(#7540)
* Issue 7549 - Substring index should validate minimum
`nsSubStrBegin`/`nsSubStrEnd` values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-
default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441)
* Fix test389 imports on older branches
* Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - `AddressSanitizer`: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with `npm` \- `brace-expansion` (#7556)
* Issue 7554 - deref plugin null pointer dereference if `ber_init` fails
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - `dblayer_bulk_nextdata` should not return an error when
maxrecords is hit
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3137=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3137=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3137=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3137=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3137=1
## Package List:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* 389-ds-snmp-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-snmp-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11610.html
* https://www.suse.com/security/cve/CVE-2026-11611.html
* https://www.suse.com/security/cve/CVE-2026-11774.html
* https://www.suse.com/security/cve/CVE-2026-11785.html
* https://www.suse.com/security/cve/CVE-2026-11786.html
* https://www.suse.com/security/cve/CVE-2026-11787.html
* https://www.suse.com/security/cve/CVE-2026-11788.html
* https://www.suse.com/security/cve/CVE-2026-11789.html
* https://www.suse.com/security/cve/CVE-2026-11790.html
* https://www.suse.com/security/cve/CVE-2026-11791.html
* https://www.suse.com/security/cve/CVE-2026-11792.html
* https://www.suse.com/security/cve/CVE-2026-11793.html
* https://www.suse.com/security/cve/CVE-2026-11884.html
* https://www.suse.com/security/cve/CVE-2026-12528.html
* https://bugzilla.suse.com/show_bug.cgi?id67975
* https://bugzilla.suse.com/show_bug.cgi?id68041
* https://bugzilla.suse.com/show_bug.cgi?id68046
* https://bugzilla.suse.com/show_bug.cgi?id68047
* https://bugzilla.suse.com/show_bug.cgi?id68057
* https://bugzilla.suse.com/show_bug.cgi?id68058
* https://bugzilla.suse.com/show_bug.cgi?id68060
* https://bugzilla.suse.com/show_bug.cgi?id68062
* https://bugzilla.suse.com/show_bug.cgi?id68064
* https://bugzilla.suse.com/show_bug.cgi?id68065
* https://bugzilla.suse.com/show_bug.cgi?id68115
* https://bugzilla.suse.com/show_bug.cgi?id68298
* https://bugzilla.suse.com/show_bug.cgi?id68491
* https://bugzilla.suse.com/show_bug.cgi?id69120
* https://bugzilla.suse.com/show_bug.cgi?id70695
SUSE-SU-2026:3126-1: important: Security update for podman
# Security update for podman
Announcement ID: SUSE-SU-2026:3126-1
Release Date: 2026-07-20T08:27:54Z
Rating: important
References:
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
An update that can now be installed.
## Description:
This update for podman rebuilds it against the current go security release.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3126=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3126=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3126=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3126=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3126=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3126=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3126=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3126=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3126=1
## Package List:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* podman-docker-4.9.5-150400.4.76.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* podman-remote-4.9.5-150400.4.76.1
* podmansh-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* openSUSE Leap 15.4 (noarch)
* podman-docker-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* podman-docker-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* podman-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* podman-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* podman-docker-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* podman-remote-4.9.5-150400.4.76.1
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
* podman-remote-4.9.5-150400.4.76.1
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* podman-docker-4.9.5-150400.4.76.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
* podman-remote-debuginfo-4.9.5-150400.4.76.1
* podman-remote-4.9.5-150400.4.76.1
* podman-4.9.5-150400.4.76.1
* podman-debuginfo-4.9.5-150400.4.76.1
openSUSE-SU-2026:11309-1: moderate: chromedriver-150.0.7871.128-1.1 on GA media
# chromedriver-150.0.7871.128-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11309-1
Rating: moderate
Cross-References:
* CVE-2026-15899
* CVE-2026-15900
* CVE-2026-15901
* CVE-2026-15902
* CVE-2026-15903
* CVE-2026-15904
* CVE-2026-15905
Affected Products:
* openSUSE Tumbleweed
An update that solves 7 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the chromedriver-150.0.7871.128-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* chromedriver 150.0.7871.128-1.1
* chromium 150.0.7871.128-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15899.html
* https://www.suse.com/security/cve/CVE-2026-15900.html
* https://www.suse.com/security/cve/CVE-2026-15901.html
* https://www.suse.com/security/cve/CVE-2026-15902.html
* https://www.suse.com/security/cve/CVE-2026-15903.html
* https://www.suse.com/security/cve/CVE-2026-15904.html
* https://www.suse.com/security/cve/CVE-2026-15905.html
openSUSE-SU-2026:11308-1: moderate: libsuricata8_0_6-8.0.6-1.1 on GA media
# libsuricata8_0_6-8.0.6-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11308-1
Rating: moderate
Cross-References:
* CVE-2026-57222
* CVE-2026-57224
* CVE-2026-57227
* CVE-2026-57228
* CVE-2026-57229
Affected Products:
* openSUSE Tumbleweed
An update that solves 5 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the libsuricata8_0_6-8.0.6-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* libsuricata8_0_6 8.0.6-1.1
* suricata 8.0.6-1.1
* suricata-devel 8.0.6-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-57222.html
* https://www.suse.com/security/cve/CVE-2026-57224.html
* https://www.suse.com/security/cve/CVE-2026-57227.html
* https://www.suse.com/security/cve/CVE-2026-57228.html
* https://www.suse.com/security/cve/CVE-2026-57229.html
SUSE-SU-2026:3125-1: important: Security update for gstreamer-plugins-bad
# Security update for gstreamer-plugins-bad
Announcement ID: SUSE-SU-2026:3125-1
Release Date: 2026-07-20T07:01:47Z
Rating: important
References:
* bsc#1268168
* bsc#1268406
* bsc#1268408
* bsc#1268410
* bsc#1268971
* bsc#1271051
* bsc#1271168
Cross-References:
* CVE-2026-12892
* CVE-2026-14935
* CVE-2026-52720
* CVE-2026-52721
* CVE-2026-52722
* CVE-2026-53702
* CVE-2026-59692
CVSS scores:
* CVE-2026-12892 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-14935 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L
* CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-59692 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves seven vulnerabilities can now be installed.
## Description:
This update for gstreamer-plugins-bad fixes the following issues:
* CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice
parser (bsc#1268971).
* CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to
inverted presence check (bsc#1271051).
* CVE-2026-52720: invalid check of total area instead of individual dimensions
could trigger a heap out-of-bounds write (bsc#1268406).
* CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could
cause an out-of-bounds read (bsc#1268408).
* CVE-2026-52722: crafted VMnc stream with large cursor dimensions can
overflow signed integer (bsc#1268410).
* CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could
result in a stack buffer overflow (bsc#1268168).
* CVE-2026-59692: unvalidated peer certificate Subject DN printed during a
DTLS handshake could cause a stack buffer overflow (bsc#1271168).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3125=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3125=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3125=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3125=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3125=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1
* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1
* libgstva-1_0-0-1.22.0-150500.3.34.1
* libgstplay-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-1.22.0-150500.3.34.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1
* openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64)
* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-transcoder-devel-1.22.0-150500.3.34.1
* typelib-1_0-GstTranscoder-1_0-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-1.22.0-150500.3.34.1
* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-transcoder-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-transcoder-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstVulkanWayland-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstVulkanXCB-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstVulkan-1_0-1.22.0-150500.3.34.1
* openSUSE Leap 15.5 (aarch64_ilp32)
* gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstva-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-64bit-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstplay-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-64bit-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-64bit-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstva-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-64bit-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-64bit-debuginfo-1.22.0-150500.3.34.1
* openSUSE Leap 15.5 (x86_64)
* libgstcuda-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstva-1_0-0-32bit-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstva-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-32bit-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-32bit-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-32bit-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-32bit-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstplay-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-32bit-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-32bit-debuginfo-1.22.0-150500.3.34.1
* openSUSE Leap 15.5 (noarch)
* gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1
* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-1.22.0-150500.3.34.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-1.22.0-150500.3.34.1
* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-1.22.0-150500.3.34.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlay-1_0-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-1.22.0-150500.3.34.1
* libgstplay-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.34.1
* typelib-1_0-GstCuda-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debugsource-1.22.0-150500.3.34.1
* libgsttranscoder-1_0-0-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.34.1
* libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstvulkan-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstcuda-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstVa-1_0-1.22.0-150500.3.34.1
* typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.34.1
* libgstplay-1_0-0-1.22.0-150500.3.34.1
* libgstva-1_0-0-1.22.0-150500.3.34.1
* libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstadaptivedemux-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.34.1
* libgstbadaudio-1_0-0-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-devel-1.22.0-150500.3.34.1
* gstreamer-plugins-bad-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.34.1
* typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.34.1
* libgstinsertbin-1_0-0-1.22.0-150500.3.34.1
* typelib-1_0-CudaGst-1_0-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-1.22.0-150500.3.34.1
* libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.34.1
* libgstwebrtcnice-1_0-0-1.22.0-150500.3.34.1
* libgstplayer-1_0-0-1.22.0-150500.3.34.1
* libgsturidownloader-1_0-0-1.22.0-150500.3.34.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* gstreamer-plugins-bad-lang-1.22.0-150500.3.34.1
## References:
* https://www.suse.com/security/cve/CVE-2026-12892.html
* https://www.suse.com/security/cve/CVE-2026-14935.html
* https://www.suse.com/security/cve/CVE-2026-52720.html
* https://www.suse.com/security/cve/CVE-2026-52721.html
* https://www.suse.com/security/cve/CVE-2026-52722.html
* https://www.suse.com/security/cve/CVE-2026-53702.html
* https://www.suse.com/security/cve/CVE-2026-59692.html
* https://bugzilla.suse.com/show_bug.cgi?id68168
* https://bugzilla.suse.com/show_bug.cgi?id68406
* https://bugzilla.suse.com/show_bug.cgi?id68408
* https://bugzilla.suse.com/show_bug.cgi?id68410
* https://bugzilla.suse.com/show_bug.cgi?id68971
* https://bugzilla.suse.com/show_bug.cgi?id71051
* https://bugzilla.suse.com/show_bug.cgi?id71168
SUSE-SU-2026:3123-1: important: Security update for shibboleth-sp
# Security update for shibboleth-sp
Announcement ID: SUSE-SU-2026:3123-1
Release Date: 2026-07-20T07:01:17Z
Rating: important
References:
* bsc#1249394
Cross-References:
* CVE-2025-9943
CVSS scores:
* CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2025-9943 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products:
* openSUSE Leap 15.3
* Server Applications Module 15-SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for shibboleth-sp fixes the following issue:
* CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when
the replay cache of the Shibboleth Service Provider (SP) is configured to
use an SQL database as storage service (bsc#1249394).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3123=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3123=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3123=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3123=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3123=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3123=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3123=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3123=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3123=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3123=1
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-3123=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3123=1
## Package List:
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* libshibsp9-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-3.1.0-150300.3.6.1
* libshibsp-lite8-debuginfo-3.1.0-150300.3.6.1
* shibboleth-sp-debuginfo-3.1.0-150300.3.6.1
* libshibsp-lite8-3.1.0-150300.3.6.1
* shibboleth-sp-debugsource-3.1.0-150300.3.6.1
* libshibsp9-3.1.0-150300.3.6.1
* shibboleth-sp-devel-3.1.0-150300.3.6.1
## References:
* https://www.suse.com/security/cve/CVE-2025-9943.html
* https://bugzilla.suse.com/show_bug.cgi?id49394