SUSE-SU-2026:3424-1: low: Security update for python3-pyOpenSSL
SUSE-SU-2026:3425-1: important: Security update for python-urwid
SUSE-SU-2026:3429-1: moderate: Security update for libarchive
SUSE-SU-2026:3430-1: important: Security update for tomcat11
openSUSE-SU-2026:21473-1: important: Security update for apptainer
openSUSE-SU-2026:21471-1: low: Security update for keybase-client
openSUSE-SU-2026:21474-1: moderate: Security update for s2n
openSUSE-SU-2026:21468-1: low: Security update for GraphicsMagick
openSUSE-SU-2026:21467-1: important: Security update for java-25-openjdk
openSUSE-SU-2026:21459-1: important: Security update for python313, python3
openSUSE-SU-2026:11393-1: moderate: logcli-3.7.4-1.1 on GA media
openSUSE-SU-2026:11392-1: moderate: kubevirt1.8-container-disk-1.8.4-3.1 on GA media
openSUSE-SU-2026:11384-1: moderate: ffmpeg-7-7.1.5-1.1 on GA media
openSUSE-SU-2026:11389-1: moderate: kubernetes1.34-apiserver-1.34.10-1.1 on GA media
openSUSE-SU-2026:11391-1: moderate: kubernetes1.36-apiserver-1.36.3-1.1 on GA media
openSUSE-SU-2026:11390-1: moderate: kubernetes1.35-apiserver-1.35.7-1.1 on GA media
openSUSE-SU-2026:11386-1: moderate: helm-4.2.3-4.1 on GA media
openSUSE-SU-2026:11385-1: moderate: freerdp-3.30.0-1.1 on GA media
SUSE-SU-2026:3413-1: moderate: Security update for ImageMagick
SUSE-SU-2026:3415-1: important: Security update for perl-DBI
SUSE-SU-2026:3417-1: important: Security update for apptainer
SUSE-SU-2026:3420-1: important: Security update for liboqs, oqs-provider
SUSE-SU-2026:3422-1: important: Security update for python-sh
SUSE-SU-2026:3423-1: important: Security update for xen
SUSE-SU-2026:3424-1: low: Security update for python3-pyOpenSSL
# Security update for python3-pyOpenSSL
Announcement ID: SUSE-SU-2026:3424-1
Release Date: 2026-07-30T11:07:53Z
Rating: low
References:
* bsc#1259804
Cross-References:
* CVE-2026-27448
CVSS scores:
* CVE-2026-27448 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-27448 ( NVD ): 1.7
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise Micro 5.4
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Micro for Rancher 5.3
* SUSE Linux Enterprise Micro for Rancher 5.4
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for python3-pyOpenSSL fixes the following issue:
* CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback`
callback can result in connection not being cancelled and allows for
possible security measure bypassing (bsc#1259804).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3424=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3424=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3424=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3424=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3424=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3424=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3424=1
## Package List:
* SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* SUSE Linux Enterprise Micro 5.3 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* openSUSE Leap 15.4 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* SUSE Linux Enterprise Micro 5.4 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* SUSE Linux Enterprise Micro 5.5 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
* Basesystem Module 15-SP7 (noarch)
* python3-pyOpenSSL-21.0.0-150400.22.1
## References:
* https://www.suse.com/security/cve/CVE-2026-27448.html
* https://bugzilla.suse.com/show_bug.cgi?id59804
SUSE-SU-2026:3425-1: important: Security update for python-urwid
# Security update for python-urwid
Announcement ID: SUSE-SU-2026:3425-1
Release Date: 2026-07-30T11:11:36Z
Rating: important
References:
* bsc#1271868
Cross-References:
* CVE-2026-9323
CVSS scores:
* CVE-2026-9323 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-9323 ( NVD ): 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-9323 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for python-urwid fixes the following issue
CVE-2026-9323: web session IDs generated by `Screen.start()` are not
cryptographically secure (bsc#1271868).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3425=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3425=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3425=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3425=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3425=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3425=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3425=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3425=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3425=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3425=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3425=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3425=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* python311-urwid-debuginfo-2.1.2-150400.11.6.1
* python311-urwid-2.1.2-150400.11.6.1
* python-urwid-debugsource-2.1.2-150400.11.6.1
## References:
* https://www.suse.com/security/cve/CVE-2026-9323.html
* https://bugzilla.suse.com/show_bug.cgi?id71868
SUSE-SU-2026:3429-1: moderate: Security update for libarchive
# Security update for libarchive
Announcement ID: SUSE-SU-2026:3429-1
Release Date: 2026-07-30T11:18:19Z
Rating: moderate
References:
* bsc#1254340
* bsc#1254341
* bsc#1260998
* bsc#1261002
* bsc#1261003
Affected Products:
* Basesystem Module 15-SP7
* Development Tools Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that has five security fixes can now be installed.
## Description:
This update for libarchive fixes the following issues:
* Creating temporary files in the current working directory instead of the
target directory can lead to file creation failures when the working
directory is not writable (bsc#1254340).
* File descriptor leak in the mtree parser cleanup path could lead to file
descriptor exhaustion and denial of service (bsc#1261003).
* NULL pointer dereference in archive_acl_from_text_w() could lead to a
segmentation fault (bsc#1260998).
* Reading from an invalid index when buffer size is smaller than
H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341).
* Incorrect pointer handling for RAR5 files declaring over 8192 filters can
lead to excessive resource usage and denial of service (bsc#1261002).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3429=1
* Development Tools Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3429=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3429=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* bsdtar-debuginfo-3.7.2-150600.3.23.1
* libarchive-devel-3.7.2-150600.3.23.1
* libarchive13-debuginfo-3.7.2-150600.3.23.1
* libarchive-debugsource-3.7.2-150600.3.23.1
* bsdtar-3.7.2-150600.3.23.1
* libarchive13-3.7.2-150600.3.23.1
* openSUSE Leap 15.6 (x86_64)
* libarchive13-32bit-3.7.2-150600.3.23.1
* libarchive13-32bit-debuginfo-3.7.2-150600.3.23.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libarchive13-64bit-3.7.2-150600.3.23.1
* libarchive13-64bit-debuginfo-3.7.2-150600.3.23.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libarchive13-debuginfo-3.7.2-150600.3.23.1
* libarchive-debugsource-3.7.2-150600.3.23.1
* libarchive-devel-3.7.2-150600.3.23.1
* libarchive13-3.7.2-150600.3.23.1
* Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libarchive-debugsource-3.7.2-150600.3.23.1
* bsdtar-debuginfo-3.7.2-150600.3.23.1
* bsdtar-3.7.2-150600.3.23.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id54340
* https://bugzilla.suse.com/show_bug.cgi?id54341
* https://bugzilla.suse.com/show_bug.cgi?id60998
* https://bugzilla.suse.com/show_bug.cgi?id61002
* https://bugzilla.suse.com/show_bug.cgi?id61003
SUSE-SU-2026:3430-1: important: Security update for tomcat11
# Security update for tomcat11
Announcement ID: SUSE-SU-2026:3430-1
Release Date: 2026-07-30T11:20:51Z
Rating: important
References:
* bsc#1271397
* bsc#1271398
Cross-References:
* CVE-2026-59083
* CVE-2026-59084
CVSS scores:
* CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
* CVE-2026-59083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-59084 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* Web and Scripting Module 15-SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for tomcat11 fixes the following issues:
Update to Tomcat 11.0.24.
Security issues fixed:
* CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security
control bypass (bsc#1271397).
* CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented
(bsc#1271398).
Other updates and bugfixes:
* Tomcat 11.0.24:
* Catalina
* Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt)
* Fix: Improve the performance of range validation for the default servlet. (markt)
* Fix: Avoid NPE in RewriteValve. (markt)
* Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm)
* Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm)
* Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt)
* Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt)
* Fix: Improve validation of configuration when DataSourceRealm starts. (remm)
* Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm)
* Fix: Various edge cases for SSI substitutions, quoting and escaping.
* Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt)
* Coyote
* Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt)
* Jasper
* Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt)
* Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt)
* WebSocket
* Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt)
* Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt)
* Other
* Update: to the Eclipse JDT compiler 4.40. (markt)
* Update: Byte Buddy to 1.18.9. (markt)
* Update: UnboundID to 7.0.5. (markt)
* Update: JaCoCo to 0.8.15. (markt)
* Update: BND to 7.3.0. (markt)
* Add: Improvements to French translations. (remm)
* Add: Improvements to Japanese translations provided by tak7iji. (markt)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3430=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3430=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3430=1
* Web and Scripting Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3430=1
## Package List:
* Web and Scripting Module 15-SP7 (noarch)
* tomcat11-11.0.24-150600.13.27.1
* tomcat11-el-6_0-api-11.0.24-150600.13.27.1
* tomcat11-webapps-11.0.24-150600.13.27.1
* tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1
* tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1
* tomcat11-admin-webapps-11.0.24-150600.13.27.1
* tomcat11-lib-11.0.24-150600.13.27.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* tomcat11-11.0.24-150600.13.27.1
* tomcat11-el-6_0-api-11.0.24-150600.13.27.1
* tomcat11-webapps-11.0.24-150600.13.27.1
* tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1
* tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1
* tomcat11-admin-webapps-11.0.24-150600.13.27.1
* tomcat11-lib-11.0.24-150600.13.27.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* tomcat11-11.0.24-150600.13.27.1
* tomcat11-el-6_0-api-11.0.24-150600.13.27.1
* tomcat11-webapps-11.0.24-150600.13.27.1
* tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1
* tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1
* tomcat11-admin-webapps-11.0.24-150600.13.27.1
* tomcat11-lib-11.0.24-150600.13.27.1
* openSUSE Leap 15.6 (noarch)
* tomcat11-11.0.24-150600.13.27.1
* tomcat11-embed-11.0.24-150600.13.27.1
* tomcat11-jsvc-11.0.24-150600.13.27.1
* tomcat11-el-6_0-api-11.0.24-150600.13.27.1
* tomcat11-docs-webapp-11.0.24-150600.13.27.1
* tomcat11-doc-11.0.24-150600.13.27.1
* tomcat11-webapps-11.0.24-150600.13.27.1
* tomcat11-jsp-4_0-api-11.0.24-150600.13.27.1
* tomcat11-servlet-6_1-api-11.0.24-150600.13.27.1
* tomcat11-admin-webapps-11.0.24-150600.13.27.1
* tomcat11-lib-11.0.24-150600.13.27.1
## References:
* https://www.suse.com/security/cve/CVE-2026-59083.html
* https://www.suse.com/security/cve/CVE-2026-59084.html
* https://bugzilla.suse.com/show_bug.cgi?id71397
* https://bugzilla.suse.com/show_bug.cgi?id71398
openSUSE-SU-2026:21473-1: important: Security update for apptainer
openSUSE security update: security update for apptainer
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21473-1
Rating: important
References:
* bsc#1266656
* bsc#1272115
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.
Description:
This update for apptainer fixes the following issues:
Changes in apptainer:
- Update to version 1.5.3:
* If the ptrace() system call does not work while building an image as
an unprivileged user, skip using PRoot to preserve file ownership and
print an INFO message.
* Bind getopt from the host when using fakeroot command mode, to make
the fakeroot command work with base containers which no longer contain
getopt by default.
* Update fixes CVE-2026-56852 (GO-2026-5970) (bsc#1272115)
golang.org/x/text/unicode/norm:
A norm.Iter can enter an infinite loop when handling input
containing invalid UTF-8 bytes.
- Update to version 1.5.2:
* Extended the mksquashfs segmentation fault workaround for cases
where mksquashfs uses many processor cores.
- Update the golang.org/x/net dependency to version v0.57.0
to fix CVE-2026-39821 for good (bsc#1266656).
The fix in v0.55.0 only applied to Unicode versions >.0.0
which aren't yet available on any Golang versions released.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260727081627270283.93181000773252=1
Package List:
- openSUSE Leap 16.0:
apptainer-1.5.3-bp160.1.1
apptainer-leap-1.5.3-bp160.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:21471-1: low: Security update for keybase-client
openSUSE security update: security update for keybase-client
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21471-1
Rating: low
Cross-References:
* CVE-2026-39824
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability can now be installed.
Description:
This update for keybase-client fixes the following issues:
Changes in keybase-client:
- CVE-2026-39824: failure to reject ASCII-only Punycode-encoded labels
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260723080014876564.93181000773252=1
Package List:
- openSUSE Leap 16.0:
kbfs-6.6.3-bp160.2.1
kbfs-git-6.6.3-bp160.2.1
kbfs-tool-6.6.3-bp160.2.1
keybase-client-6.6.3-bp160.2.1
References:
* https://www.suse.com/security/cve/CVE-2026-39824.html
openSUSE-SU-2026:21474-1: moderate: Security update for s2n
openSUSE security update: security update for s2n
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21474-1
Rating: moderate
References:
* bsc#1272352
Cross-References:
* CVE-2026-16317
* CVE-2026-16318
CVSS scores:
* CVE-2026-16317 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
* CVE-2026-16318 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 2 vulnerabilities and has one bug fix can now be installed.
Description:
This update for s2n fixes the following issues:
Changes in s2n:
- CVE-2026-16318: Denial of Service due to memory leak in QUIC
transport parameters handler (bsc#1272352)
- CVE-2026-16317: man-in-the-middle attack can silently discard
individual application data records
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-openSUSE_Backports_SLE-16.0__patchinfo.20260728100207342874.93181000773252=1
Package List:
- openSUSE Leap 16.0:
libs2n0unstable-1.5.1-bp160.2.1
s2n-devel-1.5.1-bp160.2.1
References:
* https://www.suse.com/security/cve/CVE-2026-16317.html
* https://www.suse.com/security/cve/CVE-2026-16318.html
openSUSE-SU-2026:21468-1: low: Security update for GraphicsMagick
openSUSE security update: security update for graphicsmagick
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21468-1
Rating: low
References:
* bsc#1271496
Cross-References:
* CVE-2026-61464
CVSS scores:
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( SUSE ): 1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for GraphicsMagick fixes the following issue
- CVE-2026-61464: Heap Buffer Over-Write in X11 import with crafted window title (bsc#1271496).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1383=1
Package List:
- openSUSE Leap 16.0:
GraphicsMagick-1.3.45-160000.11.1
GraphicsMagick-devel-1.3.45-160000.11.1
libGraphicsMagick++-Q16-12-1.3.45-160000.11.1
libGraphicsMagick++-devel-1.3.45-160000.11.1
libGraphicsMagick-Q16-3-1.3.45-160000.11.1
libGraphicsMagick3-config-1.3.45-160000.11.1
libGraphicsMagickWand-Q16-2-1.3.45-160000.11.1
perl-GraphicsMagick-1.3.45-160000.11.1
References:
* https://www.suse.com/security/cve/CVE-2026-61464.html
openSUSE-SU-2026:21467-1: important: Security update for java-25-openjdk
openSUSE security update: security update for java-25-openjdk
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21467-1
Rating: important
References:
* bsc#1264994
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237
Cross-References:
* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 9 vulnerabilities and has 9 bug fixes can now be installed.
Description:
This update for java-25-openjdk fixes the following issues:
- CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994).
- CVE-2026-46917: partial denial of service via TLS (bsc#1272223).
- CVE-2026-46968: unauthorized creation, deletion or modification access to critical data (bsc#1272224).
- CVE-2026-47010: unauthorized update, insert or delete access (bsc#1272225).
- CVE-2026-47021: partial denial of service via multiple network protocols (bsc#1272227).
- CVE-2026-47027: partial denial of service via multiple network protocols (bsc#1272228).
- CVE-2026-47059: partial denial of service via multiple network protocols (bsc#1272235).
- CVE-2026-47063: unauthorized creation, deletion or modification access to critical data (bsc#1272236).
- CVE-2026-60147: unauthorized update, insert or delete access (bsc#1272237).
Changes for java-25-openjdk:
- Update to upstream tag jdk-25.0.4+7 (July 2026 CPU):
+ JDK-7184899: Test sun/java2d/X11SurfaceData/
/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
+ JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes
fails
+ JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/
/bug4624207.java fails
+ JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/
/motif/InternalFrame/4150591/bug4150591.java fails with
GTKLookAndFeel
+ JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/
/Test4234761.java fails with GTKL&F
+ JDK-8144124: [macosx] The tabs can't be aligned when we
pressing the key of 'R','B','L','C' or 'T'.
+ JDK-8203004: UnixMultiResolutionSplashTest.java fails on
Ubuntu16.04
+ JDK-8213530: Test java/awt/Modal/ToFront/
/DialogToFrontModeless1Test.java fails on Linux
+ JDK-8221451: PIT: sun/java2d/X11SurfaceData/
/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
+ JDK-8225787: java/awt/Window/GetScreenLocation/
/GetScreenLocationTest.java fails on Ubuntu
+ JDK-8241066: Shenandoah: fix or cleanup SH::do_full_collection
+ JDK-8261743: Shenandoah: enable String deduplication with
compact heuristics
+ JDK-8264851: Shenandoah: Rework control loop mechanics to use
timed waits
+ JDK-8278102: containers/docker/TestJcmd.java failed with
"RuntimeException: Could not find specified process"
+ JDK-8279196: Test: jdk/jfr/event/gc/stacktrace/
/TestG1OldAllocationPendingStackTrace.java timed out
+ JDK-8297191: [macos] Printing a page range with starting
page > 1 results in missing pages
+ JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/
/DragWindowTest.java continues to fail with "No MouseReleased
event on label!"
+ JDK-8319326: GC: Make TestParallelRefProc use
createTestJavaProcessBuilder
+ JDK-8319540: GC: Make TestSelectDefaultGC use
+ JDK-8321303: Intermittent open/test/jdk/java/awt/
/KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/
/ConsumeNextMnemonicKeyTypedTest.java failure on Linux
+ JDK-8321687: Test vmTestbase/nsk/jvmti/scenarios/contention/
/TC03/tc03t002/TestDescription.java failed:
JVMTI_ERROR_THREAD_NOT_ALIVE
+ JDK-8323792: ThreadSnapshot::initialize can cause assert in
Thread::check_for_dangling_thread_pointer (possibility of
dangling Thread pointer)
+ JDK-8325482: Test that distinct seeds produce distinct traces
for compiler stress flags
+ JDK-8335355: Shenandoah: Fix race condition in gc/shenandoah/
/mxbeans/TestPauseNotifications.java
+ JDK-8339526: C2: store incorrectly removed for clone()
transformed to series of loads/stores
+ JDK-8340182: Java HttpClient does not follow default retry
limit of 3 retries
+ JDK-8341735: Rewrite the build/AbsPathsInImage.java test to
not load the entire file at once
+ JDK-8344345: test/hotspot/gtest/x86/x86-asmtest.py has
trailing whitespaces
+ JDK-8345631: TestRegionSamplingLogging.java
#generational-rotation intermittent fails
+ JDK-8347167: Reduce allocation in
com.sun.net.httpserver.Headers::normalize
+ JDK-8347938: Add Support for the Latest ML-KEM and ML-DSA
Private Key Encodings
+ JDK-8351010: Test java/io/File/GetXSpace.java failed: / usable
space 56380809216 > free space 14912244940
+ JDK-8352914: Shenandoah: Change definition of
ShenandoahSharedValue to int32_t to leverage platform atomics
+ JDK-8353115: GenShen: mixed evacuation candidate regions need
accurate live_data
+ JDK-8354650: [PPC64] Try to reduce register definitions
+ JDK-8355339: Test java/io/File/GetCanonicalPath.java failed:
The specified network name is no longer available
+ JDK-8357086: os::xxx functions returning memory size should
return size_t
+ JDK-8358600: Template-Framework Library: Template for
TestFramework test class
+ JDK-8358772: Template-Framework Library: Primitive Types
+ JDK-8359083: Test jdkCheckHtml.java should report
SkippedException rather than report fails when miss tidy
+ JDK-8359223: HttpClient: Remove leftovers from the
SecurityManager cleanup
+ JDK-8359412: Template-Framework Library: Operations and
Expressions
+ JDK-8359433: The final modifier on Windows L&F internal UI
classes prevents extending them in apps
+ JDK-8361339: Test gc/shenandoah/TestLargeObjectAlignment.java
#generational fails on macOS aarch64 with OOM: Java heap space
+ JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on
Windows: character typed with VK_A: a
+ JDK-8361699: C2: assert(can_reduce_phi(n->as_Phi())) failed:
Sanity: previous reducible Phi is no longer reducible before
SUT
+ JDK-8361726: Shenandoah: More detailed evacuation
instrumentation
+ JDK-8362428: Update IANA Language Subtag Registry to Version
2025-08-25
+ JDK-8363943: ARM32: Represent Registers as values
+ JDK-8363949: Incorrect jtreg header in
MonitorWithDeadObjectTest.java
+ JDK-8363986: Heap region in CDS archive is not at
deterministic address
+ JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/
/jaxp/functional/javax/xml/transform/xmlfiles
+ JDK-8364657: Crash for SecureRandom.generateSeed(0) on Windows
x86-64
+ JDK-8364927: Add @requires annotation to
TestReclaimStringsLeaksMemory.java
+ JDK-8365057: Add support for java.util.concurrent lock
information to Thread.dump_to_file
+ JDK-8365379: SU3.applyInsets may produce wrong results
+ JDK-8365423: [macos26] java/awt/MenuBar/8007006/
/bug8007006.java fails on macOS 26
+ JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails
on macOS 26
+ JDK-8365623: test/jdk/sun/security/pkcs11/tls/ tests skipped
without skip exception
+ JDK-8365625: Can't change accelerator colors in Windows L&F
+ JDK-8365792: GenShen: assertion "Generations aren't
reconciled"
+ JDK-8366692: Several gc/shenandoah tests timed out
+ JDK-8366695: Test sun/jvmstat/monitor/MonitoredVm/
/MonitorVmStartTerminate.java timed out
+ JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/
/ChoiceMouseWheelTest.java test is failing
+ JDK-8367096: jdk/open/test/jdk/sun/security/pkcs11/ rsa, ec,
config, secmod and sslecc tests are skipping but showing as
pass
+ JDK-8367450: Shenandoah: Log the composition of the collection
set
+ JDK-8367451: GenShen: Remove the option to compute age census
during evacuation
+ JDK-8367473: Shenandoah: Make the detailed evacuation metrics
a runtime diagnostic option
+ JDK-8367485: os::physical_memory is broken in 32-bit JVMs when
running on 64-bit OSes
+ JDK-8367531: Template Framework: use scopes and tokens instead
of misbehaving immediate-return-queries
+ JDK-8367646: [GenShen] Control thread may overwrite gc
cancellation cause set by mutator
+ JDK-8367708: GenShen: Reduce total evacuation burden
+ JDK-8367709: GenShen: Dirty cards for objects that get
promoted by safepoint that intervenes between allocation and
stores
+ JDK-8367722: [GenShen] ShenandoahEvacuationStats is always
empty
+ JDK-8367949: JFR: MethodTrace double-counts methods that catch
their own exceptions
+ JDK-8368001: java/text/Format/NumberFormat/
/NumberRoundTrip.java timed out
+ JDK-8368015: Shenandoah: fix error in computation of average
allocation rate
+ JDK-8368041: Enhance TLS certificate handling
+ JDK-8368159: Significant performance overhead when started
with jdwp agent and unattached debugger
+ JDK-8368181: ProblemList java/awt/Dialog/ModalExcludedTest/
/ModalExcludedTest.java
+ JDK-8368307: Shenandoah: get_next_bit_impl should special case
weak and strong mark bits
+ JDK-8368499: GenShen: Do not collect age census during evac
when adaptive tenuring is disabled
+ JDK-8368501: Shenandoah: GC progress evaluation does not use
generation
+ JDK-8368524: Tests are skipped and shown as passed in test/
/jdk/sun/security/pkcs11/Cipher/KeyWrap
+ JDK-8368681: Shenandoah: Add documentation comments for
ShenandoahAllocationRate
+ JDK-8369128: ProblemList jdk/jfr/event/profiling/
/TestCPUTimeSampleQueueAutoSizes.java in Xcomp configs
+ JDK-8369132: Disable vmTestbase/gc/vector/CircularListLow and
LinearListLow with SerialGC
+ JDK-8369133: Disable gc/g1/TestShrinkAuxiliaryDataRunner.java
with UseLargePages option
+ JDK-8369251: Opensource few tests
+ JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0:
Incorrect color for first pixel (actual?000000)
+ JDK-8369683: Exclude runtime/Monitor/
/MonitorWithDeadObjectTest.java#DumpThreadsBeforeDetach on
Alpine Linux debug
+ JDK-8369736: Add management interface for AOT cache creation
+ JDK-8369817: [TESTBUG] EmptyPath::toString is ignored
+ JDK-8369912: [TESTBUG] testlibrary_tests/template_framework/
/examples/TestExpressions.java fails with ArithmeticException:
/ by zero - forgot to respect Expression.info
+ JDK-8369950: TLS connection to IPv6 address fails with BCJSSE
due to IllegalArgumentException
+ JDK-8370370: Add still more cases to WorstCaseTests
+ JDK-8370489: Some compiler tests miss the @key randomness
+ JDK-8370502: C2: segfault while adding node to IGVN worklist
+ JDK-8370521: GenShen: Various code cleanup related to
promotion
+ JDK-8370939: C2: SIGSEGV in SafePointNode::verify_input when
processing MH call from
Compile::process_late_inline_calls_no_inline()
+ JDK-8371284: GenShen: Avoid unnecessary card marking
+ JDK-8371381: [Shenandoah] Setting ergo flags should use
FLAG_SET_ERGO
+ JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some
tests
+ JDK-8371792: Refactor barrier loop tests out of TestIfMinMax
+ JDK-8371893: [macOS] use dead_strip linker option to reduce
binary size
+ JDK-8372272: Hotspot shared lib loading - add load attempts to
Events::log
+ JDK-8372351: Add 2 WISeKey roots
+ JDK-8372380: Make hs_err reporting more robust for unattached
threads
+ JDK-8372513: Shenandoah: ShenandoahMaxRegionSize can produce
an unaligned heap alignment
+ JDK-8372851: Modify java/io/File/GetXSpace.java to print path
on failure of native call
+ JDK-8372861: Genshen: Override parallel_region_stride of
ShenandoahResetBitmapClosure to a reasonable value for better
parallelism
+ JDK-8373039: Remove Incorrect Asserts in
shenandoahScanRemembered
+ JDK-8373120: Virtual thread stuck in BLOCKED state
+ JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java
fails with incorrect selection of printed pages
+ JDK-8373275: Improve DTLS handshaking
+ JDK-8373515: Migrate "test/jdk/java/net/httpclient/" to
null-safe "SimpleSSLContext" methods
+ JDK-8373579: Problem list compiler/runtime/Test7196199.java
+ JDK-8373650: Test "javax/swing/JMenuItem/6458123/
/ManualBug6458123.java" fails because the check icons are not
aligned properly as expected
+ JDK-8373676: Test javax/net/ssl/HttpsURLConnection/
/SubjectAltNameIP.java fails on a machine without IPV6
+ JDK-8373690: Unexpected Keystore message using
jdk.crypto.disabledAlgorithms
+ JDK-8373714: Shenandoah: Register heuristic penalties
following a degenerated GC
+ JDK-8373718: jdk/internal/misc/VM/RuntimeArguments.java test
fails in Virtual threads mode
+ JDK-8373796: Refactor java/net/httpclient/
/ThrowingPublishers*.java tests to use JUnit5
+ JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/
/bug6197830.java failed because The test case automatically
fails when clicking any items in the "Nothing" menu in all
four windows (Left-to-right)-Menu Item Test and
(Right-to-left)-Menu Item Test
+ JDK-8373866: Refactor java/net/httpclient/
/ThrowingSubscribers*.java tests to use JUnit5
+ JDK-8373893: Refactor networking http server tests to use
JUnit
+ JDK-8373913: Refactor serialization tests to use JUnit
+ JDK-8373928: 4 Dangling pointer defect groups in java.c
+ JDK-8374001: sun/security/ skip without Exceptions
+ JDK-8374058: Enhance JPEG handling
+ JDK-8374168: Resolve disabled warnings in JDWP agent
+ JDK-8374304: MultiResolutionSplashTest.java fails in CI:
"Image with wrong resolution is used for splash screen!"
+ JDK-8374322: TestMemoryWithSubgroups.java fails Permission
denied
+ JDK-8374343: Fix SIGSEGV when lib/modules is unreadable
+ JDK-8374449: Shenandoah: Leaf locks used by Shenandoah need
lower ranks
+ JDK-8374506: Incorrect positioning of arrow icon in parent
JMenu in Windows L&F
+ JDK-8374712: AOTMappedHeapWriter::relocate_field_in_buffer
should use CompressedOops::narrow_oop_cast
+ JDK-8374727: Audio configuration Platform class - use nio for
getting endianness of the underlying platform
+ JDK-8374744: Enable dumping of APX EGPRs (R16--R31) in JVM
fatal error logs
+ JDK-8374769: PPC: MASM::pop_cont_fastpath() should reset
_cont_fastpath if SP == _cont_fastpath
+ JDK-8374888: Implement internal test cache to help
UserIterCount test performance
+ JDK-8374998: Failing os::write - remove bad file
+ JDK-8375065: Update LCMS to 2.18
+ JDK-8375177: Gtest
os_linux.decoder_get_source_info_valid_vm fails with
-ffunction-sections
+ JDK-8375294: (fs) Files.copy can fail with EOPNOTSUPP when
copy_file_range not supported
+ JDK-8376031: HttpsURLConnection.getServerCertificates() throws
"java.lang.IllegalStateException: connection not yet open" for
the HEAD method
+ JDK-8376104: C2 crashes in PhiNode::Ideal(PhaseGVN*, bool)
accessing NULL pointer
+ JDK-8376151: Test javax/swing/JFileChooser/4966171/
/bug4966171.java is failing with OOME
+ JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java
timed out then completed
+ JDK-8376185: NoSuchFieldError thrown after a record with type
annotation retransformed
+ JDK-8376233: Clean up code in Desktop native peer
+ JDK-8376287: Crashes when using -XX:ObjArrayMarkingStride=0
+ JDK-8376402: Dependencies::print_statistics() and
AbstractClassHierarchyWalker::print_statistics() are not
called from PRODUCT code
+ JDK-8376684: Compile OpenJDK in headless mode without required
X11 libraries
+ JDK-8376956: Add JVMTI phase entering/setting to hserr event
log
+ JDK-8376969: Shenandoah: GC state getters should be inlineable
+ JDK-8376970: Shenandoah: Verifier should do basic verification
before touching oops
+ JDK-8377158: Enhance XBM image support
+ JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when
x11 unavailable
+ JDK-8377498: Improve HttpServer handling
+ JDK-8377512: AOT cache creation fails with invalid native
pointer
+ JDK-8377602: Create automated test for PageRange
+ JDK-8377727: Ghost caret and focus appear in non-editable
text fields
+ JDK-8377833: Enhance Jar file processing
+ JDK-8377907: (process) Race in ProcessBuilder can cause JVM
hangs
+ JDK-8377910: Minor cleanup of java/io/FileDescriptor/
/Sharing.java
+ JDK-8377932: AOT cache is not rejected when JAR file has
changed
+ JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME:
Metaspace
+ JDK-8377949: TestZRelocationSetEvent.java intermittent fails
OOME
+ JDK-8378083: Mark shenandoah/generational/
/TestOldGrowthTriggers.java as flagless
+ JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers
of the unbound drawable
+ JDK-8378417: Printing All pages results in NPE for 1.1
PrintJob
+ JDK-8378561: Mark gc/shenandoah/compiler/
/TestLinkToNativeRBP.java as /native
+ JDK-8378687: Improve delegation of HttpURLConnection
+ JDK-8378727: [macOS] Missing dispatch_release for semaphores
in CDesktopPeer
+ JDK-8378746: ZGC: jdk/jfr/event/gc/detailed/
/TestZRelocationSetGroupEvent.java intermittent OOME
+ JDK-8378764: fileStream::fileSize() fails for >2GB files on
Windows
+ JDK-8378774: Bump update version for OpenJDK: jdk-25.0.4
+ JDK-8378810: Enable missing FFM test via jtreg requires for
RISC-V
+ JDK-8378836: Enable linktime-gc by default on Linux ppc64le
+ JDK-8378878: Refactor java/nio/channels/
/AsynchronousSocketChannel test to use JUnit
+ JDK-8378888: jdk/incubator/vector/
/Float16OperationsBenchmark.java uses wrong package name
+ JDK-8379021: Shenandoah: Speedup ShenandoahSimpleBitMapTest
+ JDK-8379202: Support linktime-gc on Linux with clang
+ JDK-8379416: AIX build fails if system (not GNU) date tool is
in PATH
+ JDK-8379425: Windows and macOS should not allow unsupported
headless-only build
+ JDK-8379457: Test EATests.java#id0 ERROR: monitor list errors:
error_cnt=1
+ JDK-8379464: Enable missing stack walking test via jtreg
requires for RISC-V
+ JDK-8379499: [AIX] headless-only build of libjawt.so fails
+ JDK-8379515: draft-ietf-lamps-kyber-certificates is now
RFC 9935
+ JDK-8380011: Path-to-gcroots search should not trigger stack
overflows
+ JDK-8380041: PPC: remove POWER6 remnants
+ JDK-8380222: Refactor test/jdk/java/lang/Character TestNG
tests to JUnit
+ JDK-8380316: Test runtime/os/AvailableProcessors.java fails
Invalid argument
+ JDK-8380409: JVM crashes when -XX:AOTMode=create uses
app.aotconf generated with JVMTI agent
+ JDK-8380428: ProblemList containers/docker/
/TestJcmdWithSideCar.java on linux-all
+ JDK-8380431: Shenandoah: Concurrent modification of
stack-chunk objects during evacuation
+ JDK-8380474: Crash SEGV in ThreadIdTable::lazy_initialize
after JDK-8323792
+ JDK-8380565: PPC64: deoptimization stub should save vector
registers
+ JDK-8380663: Update jcmd man page to include AOT.end_recording
diagnostic command
+ JDK-8380672: Improve certification checking
+ JDK-8380846: GenShen: Remove the experimental option to
disable adaptive tenuring
+ JDK-8380947: Add pull request template
+ JDK-8381039: Enhance AWT ImagingLib
+ JDK-8381049: Enhance Jar handling
+ JDK-8381205: GHA: Upgrade Node.js 20 to 24
+ JDK-8381315: compiler/vectorapi/TestVectorReallocation.java
fails with -XX:UseAVX=1 after JDK-8380565
+ JDK-8381382: Shenandoah: assert(capacity > 0) failed: free
regions must have allocation capacity
+ JDK-8381519: Enhance Der Value Handling
+ JDK-8381796: Enhance Certificate parsing
+ JDK-8381871: GenShen: ShenandoahGCHeuristics flag not reset
after ignoring non-adaptive value
+ JDK-8381935: Improve numChunks range in the PPC64 CallAranger
+ JDK-8381937: Make exceptions in
Java_sun_security_mscapi_CKeyPairGenerator generateCKeyPair
more specific
+ JDK-8382018: test/jdk/java/nio/file/spi/
/SetDefaultProvider.java leaves a directory in /tmp
+ JDK-8382020: Time Zone Abbreviation Not Localized for
Non-English Locales
+ JDK-8382035: [ubsan] Under UBSAN builds, disable tests that
rely on simulated JVM crashes
+ JDK-8382090: Remove .rej and .orig from .gitignore
+ JDK-8382242: JFR: Metadata reconstruction invalidates
ConstantMap for java.lang.String
+ JDK-8382295: Shenandoah: wrong denominator in full gc summary
+ JDK-8382395: Disable stringop-overflow in
shenandoahGenerationalHeap.cpp
+ JDK-8382419: Add missed @key randomness after JDK-8370489
+ JDK-8382522: Disable stringop-overflow in
safepointMechanism.cpp
+ JDK-8382740: JFR: Disable jdk.OldObjectSample event for
generational ZGC
+ JDK-8382878: RISC-V: Missing InlineSkippedInstructionsCounter
in ZGC barriers stubs
+ JDK-8382932: [25u] Test java/lang/instrument/
/RetransformRecordTypeAnn/TestRetransformRecord.java fails
with compilation error
+ JDK-8383161: [PPC64]
MachCallDynamicJavaNode::ret_addr_offset() needs adaptation
for COH
+ JDK-8383175: (tz) Update Timezone Data to 2026b
+ JDK-8383183: Shenandoah: Mangle trashed regions up to top
instead of end
+ JDK-8383354: Update LCMS to 2.19.1
+ JDK-8383473: Follow on from tzdata2026b time change to
include temporary hack BC time change
+ JDK-8383601: RISC-V:
ShenandoahBarrierSetAssembler::load_reference_barrier calls
"weak" on "phantom" path
+ JDK-8383630: Fix iteration in tests doing class redefinition
+ JDK-8384043: [REDO] Incorrect handling of Hawaii_Aleutian
metazone
+ JDK-8384158: GHA: Downgrade Windows GHA runners to
windows-2022 temporarily
+ JDK-8384163: (so) SocketChannel.connect and finishConnect()
exception messages could be improved
+ JDK-8384223: RISC-V: entry_barrier_offset should consider
UseZtso
+ JDK-8384486: NTLM tests fail on Windows 11 and Windows Server
2025
+ JDK-8384495: Update Libpng to 1.6.58
+ JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26
updates
+ JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after
expired test certificate
+ JDK-8384902: Update GIFlib to 6.1.3
+ JDK-8385390: Update FreeType to 2.14.3
+ JDK-8385490: Update HarfBuzz to 14.2.0
+ JDK-8386551: Windows build broken because of MSys2/Make update
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1382=1
Package List:
- openSUSE Leap 16.0:
java-25-openjdk-25.0.4.0-160000.1.1
java-25-openjdk-demo-25.0.4.0-160000.1.1
java-25-openjdk-devel-25.0.4.0-160000.1.1
java-25-openjdk-headless-25.0.4.0-160000.1.1
java-25-openjdk-javadoc-25.0.4.0-160000.1.1
java-25-openjdk-jmods-25.0.4.0-160000.1.1
java-25-openjdk-src-25.0.4.0-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
openSUSE-SU-2026:21459-1: important: Security update for python313, python3
openSUSE security update: security update for python313, python3
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21459-1
Rating: important
References:
* bsc#1211301
* bsc#1258364
* bsc#1261969
* bsc#1261970
* bsc#1262098
* bsc#1262319
* bsc#1262654
* bsc#1263787
Cross-References:
* CVE-2021-4189
* CVE-2026-1502
* CVE-2026-3446
* CVE-2026-4786
* CVE-2026-6019
* CVE-2026-6100
CVSS scores:
* CVE-2021-4189 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-3446 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
* CVE-2026-4786 ( SUSE ): 7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 6 vulnerabilities and has 8 bug fixes can now be installed.
Description:
This update for python313, python3 fixes the following issues:
Changes in python313:
Update to 3.13.14:
- Security
- gh-151159: Bumps the OpenSSL version to 3.0.21 on Android.
- gh-150599: Fix a possible stack buffer overflow in bz2 when
a bz2.BZ2Decompressor is reused after a decompression
error. The decompressor now becomes unusable after libbz2
reports an error.
- gh-149835: shutil.move() now resolves symlinks via
os.path.realpath() when checking whether the destination is
inside the source directory, preventing a symlink-based
bypass of that guard.
- gh-149698: Update bundled libexpat to version 2.8.1 for the
fix for CVE 2026-45186.
- gh-87451: The ftplib module’s undocumented ftpcp function
no longer trusts the IPv4 address value returned from the
source server in response to the PASV command by default,
completing the fix for CVE-2021-4189. As with ftplib.FTP,
the former behavior can be re-enabled by setting the
trust_server_pasv_ipv4_address attribute on the source
ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape
AI for the report.
- gh-149486: tarfile.data_filter() now validates link targets
using the same normalised value that is written to disk,
strips trailing separators from the member name when
resolving a symlink’s directory, and rejects link members
that would replace the destination directory itself. This
closes several path-traversal bypasses of the data
extraction filter.
- gh-149079: Fix a potential denial of service in
unicodedata.normalize(). The canonical ordering step of
Unicode normalization used a quadratic-time insertion sort
for reordering combining characters, which could be
exploited with crafted input containing many combining
characters in non-canonical order. Replaced with
a linear-time counting sort for long runs.
- gh-149018: Improved protection against XML hash-flooding
attacks in xml.parsers.expat and xml.etree.ElementTree when
Python is compiled with libExpat 2.8.0 or later.
- gh-149017: Update bundled libexpat to version 2.8.0.
- gh-90309: Base64-encode values when embedding cookies to
JavaScript using the http.cookies.BaseCookie.js_output()
method to avoid injection and escaping. (bsc#1262654,
CVE-2026-6019)
- gh-148808: Added buffer boundary check when using nbytes
parameter with
asyncio.AbstractEventLoop.sock_recvfrom_into(). Only
relevant for Windows and the asyncio.ProactorEventLoop.
- gh-148395: Fix a dangling input pointer in
lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal
zlib._ZlibDecompressor when memory allocation fails with
MemoryError, which could let a subsequent decompress() call
read or write through a stale pointer to the
already-released caller buffer. (bsc#1262098,
CVE-2026-6100, seems like it has been incompletely applied
gh#python/cpython#151605)
- gh-148169: A bypass in webbrowser allowed URLs prefixed
with %action to pass the dash-prefix safety check
(bsc#1262098, CVE-2026-6100).
- gh-146581: Fix vulnerability in shutil.unpack_archive() for
ZIP files on Windows which allowed to write files outside
of the destination tree if the patch in the archive
contains a Windows drive prefix. Now such invalid paths
will be skipped. Files containing “..” in the name (like
“foo..bar”) are no longer skipped.
- gh-146333: Fix quadratic backtracking in
configparser.RawConfigParser option parsing regexes (OPTCRE
and OPTCRE_NV). A crafted configuration line with many
whitespace characters could cause excessive CPU usage.
- gh-146211: Reject CR/LF characters in tunnel request
headers for the HTTPConnection.set_tunnel() method.
(bsc#1261969, CVE-2026-1502)
- Core and Builtins
- gh-151112: Fix a crash in the compiler that could occur
when running out of memory.
- gh-151126: Fix a crash, when there’s no memory left on
a device, which happened in:
- code compilation - _winapi.CreateProcess()
- Now these places raise proper MemoryError errors.
- gh-150633: Fix the frozen importer accepting module names
with embedded null bytes, which caused it to bypass the
sys.modules cache and create duplicate module objects.
- gh-149156: Fix an intermittent crash after os.fork() when
perf trampoline profiling is enabled and the child returns
through trampoline frames inherited from the parent
process.
- gh-149449: Fix a use-after-free crash when the unicodedata
module was removed from sys.modules and garbage-collected
between calls that decode \N{...} escapes or use the
namereplace codec error handler.
- gh-148450: Fix abc.register() so it invalidates type
version tags for registered classes.
- gh-150207: Fix a crash when a memory allocation fails
during tokenizer initialization. A proper MemoryError is
now raised instead.
- gh-150107: asyncio: sendfile() and sock_sendfile() event
loop methods now call file.seek(offset) if file has
a seek() method, even if offset is 0 (default value).
- gh-150146: Fix a crash on a complex type variable
substitution.
- from typing import TypeVar;
memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to
fail due to missing NULL check on _unpack_args C function
call.
- gh-149590: Fix crash when faulthandler is imported more
than once.
- gh-149738: sqlite3: Disallow removing row_factory and
text_factory attributes of a connection to prevent a crash
on a query.
- gh-139808: Add branch protections for AArch64 (BTI/PAC) in
assembly code used by -X perf_jit (Linux perf profiler
integration).
- gh-148820: Fix a race in _PyRawMutex on the free-threaded
build where a Py_PARK_INTR return from _PySemaphore_Wait
could let the waiter destroy its semaphore before the
unlocking thread’s _PySemaphore_Wakeup completed, causing
a fatal ReleaseSemaphore error.
- gh-148653: Forbid marshalling recursive code objects which
cannot be correctly unmarshalled.
- gh-148390: Fix an undefined behavior in memoryview when
using the native boolean format (?) in cast(). Previously,
on some common platforms, calling
memoryview(b).cast("?").tolist() incorrectly returned
[False] instead of [True] for any even byte b. Patch by
Bénédikt Tran.
- gh-148418: Fix a possible reference leak in a corrupted
TYPE_CODE marshal stream.
- gh-148222: Fix vectorcall support in types.GenericAlias
when the underlying type does not support the vectorcall
protocol. Fix possible leaks in types.GenericAlias and
types.UnionType in case of memory error.
- gh-145376: Fix reference leaks in various unusual error
scenarios.
- C API
- gh-150907: Fix dynamic_annotations.h header file when built
with C++ and Valgrind: add extern "C++" scope for the C++
template. Patch by Victor Stinner.
- Build
- gh-149351: Avoid possible broken macOS framework install
names when DESTDIR is specified during builds.
- gh-146475: Block Apple Clang from being used to build the
JIT as it ships without required LLVM tools.
- gh-148535: No longer use the gcc -fprofile-update=atomic
flag on i686. The flag has been added to fix a random GCC
internal error on PGO build (gh-145801) caused by
corruption of profile data (.gcda files). The problem is
that it makes the PGO build way slower (up to 47x slower)
on i686. Since the GCC internal error was not seen on i686
so far, don’t use -fprofile-update=atomic on i686 anymore.
Patch by Victor Stinner.
- Library
- gh-150913: Fix sqlite3.Blob slice assignment to raise
TypeError and IndexError for type and size mismatches
respectively, even when the target slice is empty.
- gh-143008: Fix race conditions when re-initializing
a io.TextIOWrapper object.
- gh-150685: Update bundled pip to 26.1.2
- gh-150406: Fix a possible crash occurring during socket
module initialization when the system is out of memory on
platforms without a reentrant gethostbyname.
- gh-150372: readline: Fix a potential crash during tab
completion caused by an out-of-memory error during module
initialization.
- gh-150175: Fix race condition in
unittest.mock.ThreadingMock where concurrent calls could
lose increments to call_count and other attributes due to
a missing lock in _increment_mock_call.
- gh-84353: Preserve non-UTF-8 encoded filenames when
appending to a zipfile.ZipFile. Previously, non-ASCII names
stored in a legacy encoding (without the UTF-8 flag bit
set) could be corrupted when the central directory was
rewritten: they were decoded as cp437 and then re-stored as
UTF-8.
- gh-149995: Update various docstrings in typing.
- gh-88726: The email package now uses standard MIME charset
names “gb2312” and “big5” instead of non-standard names
“eucgb2312_cn” and “big5_tw”.
- gh-149571: Fix the C implementation of
xml.etree.ElementTree.Element.itertext(): it no longer
emits text for comments and processing instructions.
- gh-149921: Fix reference leaks in error paths of the
_interpchannels and _interpqueues extension modules.
- gh-149801: Add IANA registered names and aliases with
leading zeros before number (like IBM00858, CP00858,
IBM01140, CP01140) for corresponding codecs.
- gh-149701: Fix bad return code from Lib/venv/bin/activate
if hashing is disabled
- gh-112821: In the REPL, autocompletion might run arbitrary
code in the getter of a descriptor. If that getter raised
an exception, autocompletion would fail to present any
options for the entire object. Autocompletion now works as
expected for these objects.
- gh-149388: Make asyncio.windows_utils.PipeHandle closing
idempotent.
- gh-149489: Fix ElementTree serialization to HTML. The
content of elements “xmp”, “iframe”, “noembed”, “noframes”,
and “plaintext” is no longer escaped. The “plaintext”
element no longer have the closing tag.
- gh-149377: Update bundled pip to 26.1.1
- gh-149231: In tomllib, the number of parts in TOML keys is
now limited.
- gh-149117: Fix runpy.run_module() and runpy.run_path() to
set the name attribute on the ImportError they raise.
- gh-149148: ensurepip: Upgrade bundled pip to 26.1. This
version fixes the CVE 2026-3219 vulnerability. Patch by
Victor Stinner.
- gh-148093: Fix an out-of-bounds read of one byte in
binascii.a2b_uu(). Raise binascii.Error, instead of reading
past the buffer end.
- gh-148914: Fix memoization of in-band PickleBuffer in the
Python implementation of pickle. Previously, identical
PickleBuffers did not preserve identity, and empty writable
PickleBuffer memoized an empty bytearray object in place of
b'', so the following references to b'' were unpickled as
an empty bytearray object.
- gh-138907: Support RFC 9309 in urllib.robotparser.
- gh-148954: Fix XML injection vulnerability in
xmlrpc.client.dumps() where the methodname was not being
escaped before interpolation into the XML body.
- gh-148801: xml.etree.ElementTree: Fix a crash in
Element.__deepcopy__ on deeply nested trees.
- gh-148735: xml.etree.ElementTree: Fix a use-after-free in
Element.findtext when the element tree is mutated
concurrently during the search.
- gh-146553: Fix infinite loop in typing.get_type_hints()
when __wrapped__ forms a cycle. Patch by Shamil Abdulaev.
- gh-148508: An intermittent timing error when running SSL
tests on iOS has been resolved.
- gh-148518: If an email containing an address header that
ended in an open double quote was parsed with
a non-compat32 policy, accessing the username attribute of
the mailbox accessed through that header object would
result in an IndexError. It now correctly returns an empty
string as the result.
- gh-148370: configparser: prevent quadratic behavior when
a ParsingError is raised after a parser fails to parse
multiple lines. Patch by Bénédikt Tran.
- gh-148254: Use singular “sec” instead of “secs” in timeit
verbose output for consistency with other time units.
- gh-148192: email.generator.Generator._make_boundary could
fail to detect a duplicate boundary string if linesep was
not n. It now correctly detects boundary strings when
linesep is rn as well.
- gh-146313: Fix a deadlock in multiprocessing’s resource
tracker where the parent process could hang indefinitely in
os.waitpid() during interpreter shutdown if a child created
via os.fork() still held the resource tracker’s pipe open.
- gh-145831: Fix email.quoprimime.decode() leaving a stray \r
when eol='\r\n' by stripping the full eol string instead of
one character.
- gh-145105: Fix crash in csv reader when iterating with
a re-entrant iterator that calls next() on the same reader
from within __next__.
- gh-130750: Restore quoting of choices in argparse error
messages for improved clarity and consistency with
documentation.
- gh-105936: Attempting to mutate non-field attributes of
dataclasses with both frozen and slots being True now
raises FrozenInstanceError instead of TypeError. Their
non-dataclass subclasses can now freely mutate non-field
attributes, and the original non-slotted class can be
garbage collected. The fix also handles the case of an
empty __class__ cell on a function found within the class
(gh-148947).
- gh-142516: ssl: fix reference leaks in ssl.SSLContext
objects. Patch by Bénédikt Tran.
- gh-142831: Fix a crash in the json module where
a use-after-free could occur if the object being encoded is
modified during serialization.
- gh-140287: The asyncio REPL now handles exceptions when
executing PYTHONSTARTUP scripts. Patch by Bartosz Sławecki.
- gh-90949: Add
SetBillionLaughsAttackProtectionActivationThreshold() and
SetBillionLaughsAttackProtectionMaximumAmplification() to
xmlparser objects to tune protections against billion
laughs attacks. Patch by Bénédikt Tran.
- gh-132631: Fix “I/O operation on closed file” when parsing
JSON Lines file with JSON CLI.
- gh-128110: Fix bug in the parsing of email address headers
that could result in extraneous spaces in the decoded text
when using a modern email policy. Space between pairs of
adjacent RFC 2047 encoded-words is now ignored, per section
6.2 (and consistent with existing parsing of unstructured
headers like Subject).
- gh-107398: Fix tarfile stream mode exception when process
the file with the gzip extra field.
- gh-123853: Update the table of Windows language code
identifiers (LCIDs) used by locale.getdefaultlocale() on
Windows to protocol version 16.0 (2024-04-23).
- gh-70039: Fixed bug where smtplib.SMTP.starttls() could
fail if smtplib.SMTP.connect() is called explicitly rather
than implicitly.
- gh-83281: email: improve handling trailing garbage in
address lists to avoid throwing AttributeError in certain
edge cases
- gh-91099: imaplib.IMAP4.login() now raises exceptions with
str instead of bytes. Patch by Florian Best.
- IDLE
- bpo-6699: Warn the user if a file will be overwritten when
saving.
- Documentation
- gh-150319: Generic builtin and standard library types now
document the meaning of their type parameters.
- gh-148663: Document that calendar.IllegalMonthError is
a subclass of both ValueError and IndexError since Python
3.12.
- gh-146646: Document that glob.glob(), glob.iglob(),
pathlib.Path.glob(), and pathlib.Path.rglob() silently
suppress OSError exceptions raised from scanning the
filesystem.
- gh-109503: Fix documentation for shutil.move() on usage of
os.rename() since nonatomic move might be used even if the
files are on the same filesystem. Patch by Fang Li
- Tests
- gh-151130: Add more tests for PyWeakref_* C API.
- gh-149776: Fix test_socket on Linux kernel 7.1 and newer:
skip UDP Lite tests if it’s not supported. Patch by Victor
Stinner.
- Keep unversioned Python 3 development entry points in
python3-devel: python313-devel no longer provides python3-devel
and no longer owns libpython3.so, python3-config, python3.pc,
or python3-embed.pc. Do not package versioned GIL pkg-config
files in nogil-devel. Also, fix regular expressions in
rpmlintrc.
- Improve testing for the support of IPPROTO_UDPLITE, which could be
not present although header files are. (bsc#1263787,
gh#python/cpython!149081)
- Add missing BR `crypto-policies-scripts` (need for the fix of
bsc#1211301).
- CVE-2026-6019: protect against HTML injection by
Base64-encoding cookie values embedded in JS (bsc#1262654,
gh#python/cpython#90309)
- CVE-2026-1502: reject CR/LF in HTTP tunnel request headers
(bsc#1261969, gh#python/cpython#146211)
- CVE-2026-4786: fix webbrowser %action substitution bypass of
dash-prefix check (bsc#1262319, gh#python/cpython#148169)
- CVE-2026-6100: prevent dangling pointer, which can end in the
use-after-free error (bsc#1262098, gh#python/cpython#148395)
Changes in python3:
- Provide explicitly also file dependencies /usr/bin/python3 and
/usr/bin/pydoc3.
break bootstrap build dependency cycle on primary python
Break the cyclic build dependency loop between `python3` and
`python313` during version upgrades (such as 3.13.13 to 3.13.14).
Previously, `python3.spec` required `BuildRequires:
%{primary_python}` (the versioned non-base interpreter package)
and queried its version via `rpm -q` during spec file parsing.
During upgrades, this blocked the build of `python3` because
`%{primary_python}` (non-base) depended on `python3-base`, which
demanded the new `python313-base` version.
Since the unversioned compatibility package `python3` only
creates unversioned symlinks (like `/usr/bin/python3`) and owns
generic RPM macros, it does not actually require the versioned
standard library modules (the non-base flavor) to build.
This change allows `python3` to build successfully against the
already built `python313-base` and `python313-devel` packages,
breaking the circular dependency and enabling a clean upgrade
path.
- Let python3-devel explicitly provide pkgconfig(python3) and
pkgconfig(python3-embed), matching its ownership of the unversioned
pkg-config files.
- Complete the transition of the unversioned python3 namespace
(jsc#PED-16123, bsc#1258364).
- Add missing Provides/Obsoletes for generic names.
- Add macros.python3 (moved from python313).
- Add BuildIgnore: gdb
BuildRequires: python313-devel → python313-devel owns
/usr/share/gdb/auto-load/...libpython3.13...-gdb.py → the
currently published version of that file has #!/usr/bin/python3
→ RPM auto-generated Requires: python3-base on gdb → OBS tries
to install gdb into the build root and fails because
python3-base is the package being built.
- Correct the logic in the %pre scripts.
- version of the package must be equal to the version of
%primary_python
- Initial packaging effort for the python3 superpackage.
python3 is shipped as new package.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1359=1
Package List:
- openSUSE Leap 16.0:
libpython3_13-1_0-3.13.14-160000.1.1
libpython3_13-1_0-x86-64-v3-3.13.14-160000.1.1
libpython3_13t1_0-3.13.14-160000.1.1
python3-3.13.14-160000.1.1
python3-base-3.13.14-160000.1.1
python3-curses-3.13.14-160000.1.1
python3-dbm-3.13.14-160000.1.1
python3-devel-3.13.14-160000.1.1
python3-doc-3.13.14-160000.1.1
python3-doc-devhelp-3.13.14-160000.1.1
python3-idle-3.13.14-160000.1.1
python3-testsuite-3.13.14-160000.1.1
python3-tk-3.13.14-160000.1.1
python3-tools-3.13.14-160000.1.1
python313-3.13.14-160000.1.1
python313-base-3.13.14-160000.1.1
python313-base-x86-64-v3-3.13.14-160000.1.1
python313-curses-3.13.14-160000.1.1
python313-dbm-3.13.14-160000.1.1
python313-devel-3.13.14-160000.1.1
python313-doc-3.13.14-160000.1.1
python313-doc-devhelp-3.13.14-160000.1.1
python313-idle-3.13.14-160000.1.1
python313-nogil-3.13.14-160000.1.1
python313-nogil-base-3.13.14-160000.1.1
python313-nogil-curses-3.13.14-160000.1.1
python313-nogil-dbm-3.13.14-160000.1.1
python313-nogil-devel-3.13.14-160000.1.1
python313-nogil-idle-3.13.14-160000.1.1
python313-nogil-testsuite-3.13.14-160000.1.1
python313-nogil-tk-3.13.14-160000.1.1
python313-nogil-tools-3.13.14-160000.1.1
python313-testsuite-3.13.14-160000.1.1
python313-tk-3.13.14-160000.1.1
python313-tools-3.13.14-160000.1.1
python313-x86-64-v3-3.13.14-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2021-4189.html
* https://www.suse.com/security/cve/CVE-2026-1502.html
* https://www.suse.com/security/cve/CVE-2026-3446.html
* https://www.suse.com/security/cve/CVE-2026-4786.html
* https://www.suse.com/security/cve/CVE-2026-6019.html
* https://www.suse.com/security/cve/CVE-2026-6100.html
openSUSE-SU-2026:11393-1: moderate: logcli-3.7.4-1.1 on GA media
# logcli-3.7.4-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11393-1
Rating: moderate
Cross-References:
* CVE-2026-39822
CVSS scores:
* CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the logcli-3.7.4-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* logcli 3.7.4-1.1
* loki 3.7.4-1.1
* lokitool 3.7.4-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-39822.html
openSUSE-SU-2026:11392-1: moderate: kubevirt1.8-container-disk-1.8.4-3.1 on GA media
# kubevirt1.8-container-disk-1.8.4-3.1 on GA media
Announcement ID: openSUSE-SU-2026:11392-1
Rating: moderate
Cross-References:
* CVE-2026-13201
* CVE-2026-46600
* CVE-2026-56852
CVSS scores:
* CVE-2026-13201 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-46600 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 3 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the kubevirt1.8-container-disk-1.8.4-3.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* kubevirt1.8-container-disk 1.8.4-3.1
* kubevirt1.8-libguestfs-tools 1.8.4-3.1
* kubevirt1.8-manifests 1.8.4-3.1
* kubevirt1.8-pr-helper-conf 1.8.4-3.1
* kubevirt1.8-sidecar-shim 1.8.4-3.1
* kubevirt1.8-tests 1.8.4-3.1
* kubevirt1.8-virt-api 1.8.4-3.1
* kubevirt1.8-virt-controller 1.8.4-3.1
* kubevirt1.8-virt-exportproxy 1.8.4-3.1
* kubevirt1.8-virt-exportserver 1.8.4-3.1
* kubevirt1.8-virt-handler 1.8.4-3.1
* kubevirt1.8-virt-launcher 1.8.4-3.1
* kubevirt1.8-virt-operator 1.8.4-3.1
* kubevirt1.8-virt-synchronization-controller 1.8.4-3.1
* kubevirt1.8-virtctl 1.8.4-3.1
* obs-service-kubevirt1.8_containers_meta 1.8.4-3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-13201.html
* https://www.suse.com/security/cve/CVE-2026-46600.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:11384-1: moderate: ffmpeg-7-7.1.5-1.1 on GA media
# ffmpeg-7-7.1.5-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11384-1
Rating: moderate
Cross-References:
* CVE-2026-8461
CVSS scores:
* CVE-2026-8461 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the ffmpeg-7-7.1.5-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* ffmpeg-7 7.1.5-1.1
* ffmpeg-7-libavcodec-devel 7.1.5-1.1
* ffmpeg-7-libavdevice-devel 7.1.5-1.1
* ffmpeg-7-libavfilter-devel 7.1.5-1.1
* ffmpeg-7-libavformat-devel 7.1.5-1.1
* ffmpeg-7-libavutil-devel 7.1.5-1.1
* ffmpeg-7-libpostproc-devel 7.1.5-1.1
* ffmpeg-7-libswresample-devel 7.1.5-1.1
* ffmpeg-7-libswscale-devel 7.1.5-1.1
* libavcodec61 7.1.5-1.1
* libavdevice61 7.1.5-1.1
* libavfilter10 7.1.5-1.1
* libavformat61 7.1.5-1.1
* libavutil59 7.1.5-1.1
* libpostproc58 7.1.5-1.1
* libswresample5 7.1.5-1.1
* libswscale8 7.1.5-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-8461.html
openSUSE-SU-2026:11389-1: moderate: kubernetes1.34-apiserver-1.34.10-1.1 on GA media
# kubernetes1.34-apiserver-1.34.10-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11389-1
Rating: moderate
Cross-References:
* CVE-2020-8561
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the kubernetes1.34-apiserver-1.34.10-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* kubernetes1.34-apiserver 1.34.10-1.1
* kubernetes1.34-client 1.34.10-1.1
* kubernetes1.34-client-bash-completion 1.34.10-1.1
* kubernetes1.34-client-common 1.34.10-1.1
* kubernetes1.34-client-fish-completion 1.34.10-1.1
* kubernetes1.34-controller-manager 1.34.10-1.1
* kubernetes1.34-kubeadm 1.34.10-1.1
* kubernetes1.34-kubelet 1.34.10-1.1
* kubernetes1.34-kubelet-common 1.34.10-1.1
* kubernetes1.34-proxy 1.34.10-1.1
* kubernetes1.34-scheduler 1.34.10-1.1
## References:
* https://www.suse.com/security/cve/CVE-2020-8561.html
openSUSE-SU-2026:11391-1: moderate: kubernetes1.36-apiserver-1.36.3-1.1 on GA media
# kubernetes1.36-apiserver-1.36.3-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11391-1
Rating: moderate
Cross-References:
* CVE-2020-8561
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the kubernetes1.36-apiserver-1.36.3-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* kubernetes1.36-apiserver 1.36.3-1.1
* kubernetes1.36-client 1.36.3-1.1
* kubernetes1.36-client-bash-completion 1.36.3-1.1
* kubernetes1.36-client-common 1.36.3-1.1
* kubernetes1.36-client-fish-completion 1.36.3-1.1
* kubernetes1.36-controller-manager 1.36.3-1.1
* kubernetes1.36-kubeadm 1.36.3-1.1
* kubernetes1.36-kubelet 1.36.3-1.1
* kubernetes1.36-kubelet-common 1.36.3-1.1
* kubernetes1.36-proxy 1.36.3-1.1
* kubernetes1.36-scheduler 1.36.3-1.1
## References:
* https://www.suse.com/security/cve/CVE-2020-8561.html
openSUSE-SU-2026:11390-1: moderate: kubernetes1.35-apiserver-1.35.7-1.1 on GA media
# kubernetes1.35-apiserver-1.35.7-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11390-1
Rating: moderate
Cross-References:
* CVE-2020-8561
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the kubernetes1.35-apiserver-1.35.7-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* kubernetes1.35-apiserver 1.35.7-1.1
* kubernetes1.35-client 1.35.7-1.1
* kubernetes1.35-client-bash-completion 1.35.7-1.1
* kubernetes1.35-client-common 1.35.7-1.1
* kubernetes1.35-client-fish-completion 1.35.7-1.1
* kubernetes1.35-controller-manager 1.35.7-1.1
* kubernetes1.35-kubeadm 1.35.7-1.1
* kubernetes1.35-kubelet 1.35.7-1.1
* kubernetes1.35-kubelet-common 1.35.7-1.1
* kubernetes1.35-proxy 1.35.7-1.1
* kubernetes1.35-scheduler 1.35.7-1.1
## References:
* https://www.suse.com/security/cve/CVE-2020-8561.html
openSUSE-SU-2026:11386-1: moderate: helm-4.2.3-4.1 on GA media
# helm-4.2.3-4.1 on GA media
Announcement ID: openSUSE-SU-2026:11386-1
Rating: moderate
Cross-References:
* CVE-2026-63308
CVSS scores:
* CVE-2026-63308 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the helm-4.2.3-4.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* helm 4.2.3-4.1
* helm-bash-completion 4.2.3-4.1
* helm-fish-completion 4.2.3-4.1
* helm-zsh-completion 4.2.3-4.1
## References:
* https://www.suse.com/security/cve/CVE-2026-63308.html
openSUSE-SU-2026:11385-1: moderate: freerdp-3.30.0-1.1 on GA media
# freerdp-3.30.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11385-1
Rating: moderate
Cross-References:
* CVE-2026-63117
* CVE-2026-63633
* CVE-2026-63652
Affected Products:
* openSUSE Tumbleweed
An update that solves 3 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the freerdp-3.30.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* freerdp 3.30.0-1.1
* freerdp-devel 3.30.0-1.1
* freerdp-proxy 3.30.0-1.1
* freerdp-proxy-plugins 3.30.0-1.1
* freerdp-sdl 3.30.0-1.1
* freerdp-server 3.30.0-1.1
* freerdp-wayland 3.30.0-1.1
* libfreerdp-server-proxy3-3 3.30.0-1.1
* libfreerdp3-3 3.30.0-1.1
* librdtk0-0 3.30.0-1.1
* libuwac0-0 3.30.0-1.1
* libwinpr3-3 3.30.0-1.1
* rdtk0-devel 3.30.0-1.1
* uwac0-devel 3.30.0-1.1
* winpr-devel 3.30.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-63117.html
* https://www.suse.com/security/cve/CVE-2026-63633.html
* https://www.suse.com/security/cve/CVE-2026-63652.html
SUSE-SU-2026:3413-1: moderate: Security update for ImageMagick
# Security update for ImageMagick
Announcement ID: SUSE-SU-2026:3413-1
Release Date: 2026-07-30T06:50:50Z
Rating: moderate
References:
* bsc#1272575
* bsc#1272579
* bsc#1272580
Cross-References:
* CVE-2026-25797
* CVE-2026-62343
* CVE-2026-62946
CVSS scores:
* CVE-2026-25797 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-25797 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
* CVE-2026-25797 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-62343 ( SUSE ): 5.6
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-62343 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62343 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62946 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-62946 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-62946 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves three vulnerabilities can now be installed.
## Description:
This update for ImageMagick fixes the following issues:
* CVE-2026-62343: heap buffer overwrite in morphology operation when an
invalid kernel is provided (bsc#1272575).
* CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer
overwrite when processing extremely large files on 32-bit builds
(bsc#1272580).
* code injection in HTML encoder due to incomplete fix of CVE-2026-25797
(bsc#1272579).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3413=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3413=1
## Package List:
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* ImageMagick-debugsource-7.1.0.9-150400.6.107.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.107.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.107.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.107.1
* libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.107.1
* perl-PerlMagick-7.1.0.9-150400.6.107.1
* ImageMagick-debuginfo-7.1.0.9-150400.6.107.1
* ImageMagick-config-7-upstream-7.1.0.9-150400.6.107.1
* ImageMagick-config-7-SUSE-7.1.0.9-150400.6.107.1
* libMagick++-devel-7.1.0.9-150400.6.107.1
* ImageMagick-7.1.0.9-150400.6.107.1
* ImageMagick-extra-7.1.0.9-150400.6.107.1
* ImageMagick-debugsource-7.1.0.9-150400.6.107.1
* ImageMagick-extra-debuginfo-7.1.0.9-150400.6.107.1
* perl-PerlMagick-debuginfo-7.1.0.9-150400.6.107.1
* libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.107.1
* ImageMagick-devel-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.107.1
* libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.107.1
* openSUSE Leap 15.4 (noarch)
* ImageMagick-doc-7.1.0.9-150400.6.107.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libMagick++-devel-64bit-7.1.0.9-150400.6.107.1
* libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.107.1
* libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.107.1
* libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.107.1
* libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.107.1
* ImageMagick-devel-64bit-7.1.0.9-150400.6.107.1
* openSUSE Leap 15.4 (x86_64)
* libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.107.1
* libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.107.1
* ImageMagick-devel-32bit-7.1.0.9-150400.6.107.1
* libMagick++-devel-32bit-7.1.0.9-150400.6.107.1
* libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.107.1
* libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.107.1
* libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.107.1
## References:
* https://www.suse.com/security/cve/CVE-2026-25797.html
* https://www.suse.com/security/cve/CVE-2026-62343.html
* https://www.suse.com/security/cve/CVE-2026-62946.html
* https://bugzilla.suse.com/show_bug.cgi?id72575
* https://bugzilla.suse.com/show_bug.cgi?id72579
* https://bugzilla.suse.com/show_bug.cgi?id72580
SUSE-SU-2026:3415-1: important: Security update for perl-DBI
# Security update for perl-DBI
Announcement ID: SUSE-SU-2026:3415-1
Release Date: 2026-07-30T06:54:43Z
Rating: important
References:
* bsc#1271017
* bsc#1271018
* bsc#1271399
* bsc#1271458
* bsc#1271459
* bsc#1271629
Cross-References:
* CVE-2026-14380
* CVE-2026-14740
* CVE-2026-15043
* CVE-2026-15392
* CVE-2026-60081
* CVE-2026-60082
CVSS scores:
* CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-15043 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities can now be installed.
## Description:
This update for perl-DBI fixes the following issues
* CVE-2026-14380: unvalidated string eval interpolation of the Profile package
name can lead to arbitrary Perl code execution (bsc#1271018).
* CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL
comment line can lead to a process crash (bsc#1271017).
* CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to
bypass of file-backed filters (bsc#1271399).
* CVE-2026-15392: missing checks to ensure the table file is not a symlink to
an untrusted location in `DBD::File` allows for arbitrary file reads and
writes (bsc#1271629).
* CVE-2026-60081: no limiting of the path index in profile parser of
`DBI:ProfileData` can enable small-file memory-amplification DoS
(bsc#1271458).
* CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle
has zero fields but a non-empty row can lead to a process crash
(bsc#1271459).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3415=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3415=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3415=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3415=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* perl-DBI-1.647.0-150600.12.18.1
* perl-DBI-debugsource-1.647.0-150600.12.18.1
* perl-DBI-debuginfo-1.647.0-150600.12.18.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* perl-DBI-1.647.0-150600.12.18.1
* perl-DBI-debugsource-1.647.0-150600.12.18.1
* perl-DBI-debuginfo-1.647.0-150600.12.18.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* perl-DBI-1.647.0-150600.12.18.1
* perl-DBI-debugsource-1.647.0-150600.12.18.1
* perl-DBI-debuginfo-1.647.0-150600.12.18.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* perl-DBI-1.647.0-150600.12.18.1
* perl-DBI-debugsource-1.647.0-150600.12.18.1
* perl-DBI-debuginfo-1.647.0-150600.12.18.1
## References:
* https://www.suse.com/security/cve/CVE-2026-14380.html
* https://www.suse.com/security/cve/CVE-2026-14740.html
* https://www.suse.com/security/cve/CVE-2026-15043.html
* https://www.suse.com/security/cve/CVE-2026-15392.html
* https://www.suse.com/security/cve/CVE-2026-60081.html
* https://www.suse.com/security/cve/CVE-2026-60082.html
* https://bugzilla.suse.com/show_bug.cgi?id71017
* https://bugzilla.suse.com/show_bug.cgi?id71018
* https://bugzilla.suse.com/show_bug.cgi?id71399
* https://bugzilla.suse.com/show_bug.cgi?id71458
* https://bugzilla.suse.com/show_bug.cgi?id71459
* https://bugzilla.suse.com/show_bug.cgi?id71629
SUSE-SU-2026:3417-1: important: Security update for apptainer
# Security update for apptainer
Announcement ID: SUSE-SU-2026:3417-1
Release Date: 2026-07-30T07:06:34Z
Rating: important
References:
* bsc#1266656
* bsc#1272115
Cross-References:
* CVE-2026-39821
* CVE-2026-56852
CVSS scores:
* CVE-2026-39821 ( SUSE ): 9.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-56852 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* HPC Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for apptainer fixes the following issues:
* CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only
Punycode-encoded labels allows for validation bypass and privilege
escalation (bsc#1266656).
* CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on
truncated/invalid UTF-8 input (bsc#1272115).
Changes for apptainer:
* Update apptainer to version 1.5.3:
* If the ptrace() system call does not work while building an image as an
unprivileged user, skip using PRoot to preserve file ownership and print an
INFO message.
* Bind getopt from the host when using fakeroot command mode, to make the
fakeroot command work with base containers which no longer contain getopt by
default.
* Extended the mksquashfs segmentation fault workaround for cases where
mksquashfs uses many processor cores.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3417=1
* HPC Module 15-SP7
zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3417=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3417=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3417=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* apptainer-sle15_6-1.5.3-150600.4.34.2
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64)
* apptainer-1.5.3-150600.4.34.2
* apptainer-debuginfo-1.5.3-150600.4.34.2
* openSUSE Leap 15.6 (noarch)
* apptainer-sle16-1.5.3-150600.4.34.2
* apptainer-leap-1.5.3-150600.4.34.2
* apptainer-sle15_7-1.5.3-150600.4.34.2
* apptainer-sle15_6-1.5.3-150600.4.34.2
* openSUSE Leap 15.6 (aarch64 x86_64)
* apptainer-1.5.3-150600.4.34.2
* apptainer-suid-1.5.3-150600.4.34.2
* apptainer-debuginfo-1.5.3-150600.4.34.2
* apptainer-suid-debuginfo-1.5.3-150600.4.34.2
* SUSE Package Hub 15 15-SP7 (aarch64 x86_64)
* apptainer-1.5.3-150600.4.34.2
* apptainer-suid-1.5.3-150600.4.34.2
* HPC Module 15-SP7 (noarch)
* apptainer-sle15_7-1.5.3-150600.4.34.2
* HPC Module 15-SP7 (aarch64 x86_64)
* apptainer-1.5.3-150600.4.34.2
* apptainer-debuginfo-1.5.3-150600.4.34.2
## References:
* https://www.suse.com/security/cve/CVE-2026-39821.html
* https://www.suse.com/security/cve/CVE-2026-56852.html
* https://bugzilla.suse.com/show_bug.cgi?id66656
* https://bugzilla.suse.com/show_bug.cgi?id72115
SUSE-SU-2026:3420-1: important: Security update for liboqs, oqs-provider
# Security update for liboqs, oqs-provider
Announcement ID: SUSE-SU-2026:3420-1
Release Date: 2026-07-30T07:28:37Z
Rating: important
References:
* bsc#1101107
* bsc#1242701
* bsc#1244617
* bsc#1245315
* bsc#1246301
* bsc#1249081
* bsc#1267001
* bsc#1267007
Cross-References:
* CVE-2025-52473
* CVE-2026-44518
* CVE-2026-46344
CVSS scores:
* CVE-2025-52473 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2025-52473 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-52473 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2025-52473 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-44518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-44518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46344 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46344 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves three vulnerabilities and has five security fixes can now
be installed.
## Description:
This update for liboqs, oqs-provider fixes the following issues:
* disable KEM_HQC and SIG_MQOM and KEM_NTRUPRIME on s390x for now, testsuite
shows them not working.
Updated to 0.16.0:
Deprecation notice:
* SPHINCS+ was removed in 0.16.0.
Security issues:
* Fixed uninitialized `encaps_derand` pointer dereference
* CVE-2026-46344, CVE-2026-44518: Fixed out-of-bounds read in XMSS/XMSS^MT
signature verification (bsc#1267007 bsc#1267001)
* Fixed Integer underflow in CROSS `crypto_sign_open()`
* Fixed incorrect array size when calling `secure_clean`
* Implemented optimization barrier `OQS_MEM_BLACK_BOX` and applied to
`ct_select` in FrodoKEM
Significant change:
FrodoKEM algorithm change:
* Existing FrodoKEM in 0.15.0 was renamed to ephemeral FrodoKEM
(`KEM_efrodokem_<640|976|1344>_<aes|shake>`), and the salted
variant of FrodoKEM was added under the prior names
(`KEM_frodokem_<640|976|1344>_<aes|shake>`). Ephemeral FrodoKEM
is recommended for applications where each keypair will encapsulate only a
small number of shared secrets and ciphertexts. Standard (salted) FrodoKEM
is recommended for applications where each keypair is expected to
encapsulate large number of ciphertexts. Please consult upstream for more
details.
* mldsa-native integration: mldsa-native is a secure, fast, and portable C90
implementation of the ML-DSA post-quantum signature standard. It also
includes optimized builds for x86_64 and aarch64. It is now the default
implementation behind `SIG_ml_dsa_<44|65|87>`.
* Updated HQC implementation: The HQC implementations in liboqs were updated
to 20250822 spec. Its upstream switched from PQClean to the official repo.
`KEM_hqc_<1|3|5>` is now enabled by default.
* MQOM integration and memory-optimized build flag: MQOM is a third-round
candidate in NIST's Additional Digital Signatures for the PQC
Standardization Process. Portable, x86_64-optimized, and memory-optimized
implementations were integrate into liboqs under `OQS_ENABLE_SIG_MQOM`.
* OpenSSH implementation of NTRU Prime: A public-domain OpenSSH implementation
of NTRUPrime761 replaced the PQClean implementation as the default backend
for `KEM_ntruprime_sntrup761`.
Bug fixes:
* Fixed incremental absorption bug in AVX512VL SHA3-512 #2442
* Implemented fallback for when `EVP_DigestSqueeze` is unavailable #2433
* Added API for detecting stateful signature support at runtime #2434
* Fixed missing initialization and indexing bug in LMS #2416
* Fixed erroneous MAYO_OK despite failed sample_solution() attempts in MAYO
#2403
* Limited pytest parallelism to prevent memory exhaustion in constrained
environment #2397
* Fixed cuPQC ML-KEM derand symbol names and `#if/#elif` chains #2396
* Tightened Windows compiler detection #2394
* Fixed mismatched macros in LMS #2379
* Made fuzzers tolerant to disabled algorithms #2359
* Removed inlined exponentiation in CROSS-RSDPG-1 #2357
* Fixed incorrect arg register update in AVX512 Keccak #2330
Update to 0.15.0:
* Significant changes:
* Integrated SLH-DSA implementation from pq-code-package/slhdsa-c
* SLH-DSA ACVP tests (#2237)
* Integrate SLH-DSA-C Library (#2175)
* Added NTRU back (#2176)
* Removed all Dilithium implementations (#2275)
* Replaced SPHINCS+ with SLH-DSA for CMake build option OQS_ALGS_ENABLED=STD (#2290)
* Updated CROSS to version 2.2 (#2247)
* Included DeriveEncapsulation functionality (#2221)
* Integrated ML-KEM implementation from ICICLE-PQC (#2216)
* Bug fixes:
* Fixed erroneously disabled LMS variants with build flag OQS_ENABLE_SIG_STFL_LMS (#2310)
* Fixed incorrect import in OV-III-pkc_skc (#2299)
* Fixed incorrect actual signature length in signature full-cycle speed test (#2293)
* Fixed ICICLE ML-KEM integration (#2288)
* Disabled strict aliasing on SPHINCS+-SHAKE (#2264)
* Fixed uninitialized length_encaps_seed for NTRU implementations (#2266)
* Changed 64 bit add to 32 bit add to wrap on 32 bit counter for AES-CTR AES-NI implementation (#2252)
* Improved random number generator security (#2225)
* Added Classic McEliece sanitization patch (#2218)
* Miscellaneous:
* Deprecated noregress scripts (#2295)
* Updated no-pass explanation for constant-time testing (#2294)
* Re-enabled all ACVP tests (#2283)
* Updated license info for ML-KEM (#2250)
* Added Poutine SASL (#2213)
* Updated ACVP to 1.1.0.40 (#2172)
* Switched to dev mode for 0.14.1 (#2199)
* Deprecation notice: liboqs 0.15.0 is the last version to officially support
SPHINCS+. SPHINCS+ will be removed in the 0.16.0 release and replaced by
SLH-DSA. liboqs 0.15.0 also removes support for Dilithium.
Updated to 0.14.0:
* Key encapsulation mechanisms:
* HQC: Disabled compiler optimizations to avoid secret-dependent branching in certain configurations. HQC remains disabled by default.
* ML-KEM: Updated the default ML-KEM implementation to PQCP's mlkem-native v1.0.0.
* Digital signature schemes:
* New API: added an API function to check if a signature scheme supports signing with a context string.
* SNOVA: added SNOVA from NIST Additional Signature Schemes Round 2.
* Other changes:
* Added an AVX512VL-optimized backend for SHA3.
* Improved memory management throughout the codebase.
* CVE-2025-52473: Disabled compiler optimizations for HQC to avoid secret-
dependent branches. Thank you to Zhenzhi Lai and Zhiyuan Zhang from from the
University of Melbourne and the Max Planck Institute for Security and
Privacy for identifying the issue. (bsc#1246301)
* new major library version liboqs.so.8
* add -DOQS_ENABLE_KEM_HQC=ON even due to security issues, as otherwise we
dropped binary compatibility with postquantumcryptoengine (bsc#1242701)
* Do not embed the buildhost's kernel version to help reproducibility
(bsc#1101107)
Updated to 0.13.0:
* Key encapsulation mechanisms
* New API: Added a deterministic key generation and API for KEMs (only ML-KEM supported at the moment).
* ML-KEM: Changed the default ML-KEM implementation to PQCP's mlkem-native. There are three variants: Portable C, AVX2, and AArch64. Large +parts of these implementations are formally verified: all of the C code is verified for memory and type safety using CBMC and the functional correctness +of the core AArch64 assembly routines is verified using HOL-Light.
* ML-KEM: Added support for the ML-KEM implementation from Nvidia cuPQC, a GPU accelerated cryptography library.
* ML-KEM: Implementation from mlkem-native upstream updated to add Pair-wise Consistency Test (PCT) and Intel CET support.
* ML-KEM: Improved testing of ML-KEM keys.
* HQC: Disabled HQC by default until a new security flaw is fixed.
* Digital signature schemes
* ML-DSA: Improved testing for ML-DSA.
* CROSS: Updated to NIST Additional Signatures Round 2 version.
* MAYO: Updated to NIST Additional Signatures Round 2 version.
* UOV: Added support for UOV algorithm from NIST Additional Signatures Round 2.
Update to 0.11.0:
* Hide all symbols except for OSSL_provider_init entrypoint
* corrects fixed test cert validity
* Update CROSS to version 2.2
* update contributing guide to point to more resilient script
* follow upstream and fixup Composites removal
* Add Brainpool hybrid KEM support
* Fix 'enable_tls' SIG algorithm mismatch
Updated to 0.10.0:
* Add SNOVA signatures
* Remove Composite Signature logic, templating, and documentation
* disable openssl.cnf which blocks some of our tests (bsc#1249081)
updated to 0.9.0:
* Adds support for UOV (NIST Additional Signatures Round 2)
* Adds support for Mayo (NIST Additional Signatures Round 2)
* Adds support for CROSS (NIST Additional Signatures Round 2)
* Disables HQC KEM by default, following liboqs v0.13.0, until a security flaw
is fixed.
* Disables default support for Kyber (Round 3 version).
* Disables default support for Dilithium (Round 3 version).
* Restricts non-standard TLS group code points to IANA private use range.
* Updates TLS group code point and name for ML-KEM 1024 hybrid
SecP384r1MLKEM1024.
* Disables ML-KEM (along with certain hybrid variants) and ML-DSA (along with
all composite/hybrid variants) when oqs-provider is loaded with OpenSSL
(version >= 3.5.0) which offers native support for some of these algorithms.
Please see README.md for detailed information.
* fixes build with openssl 3.5 (bsc#1244617)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3420=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3420=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3420=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3420=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* oqs-provider-debuginfo-0.11.0.32-150600.3.9.1
* liboqs9-debuginfo-0.16.0-150600.3.6.1
* oqs-provider-0.11.0.32-150600.3.9.1
* liboqs-devel-0.16.0-150600.3.6.1
* liboqs9-0.16.0-150600.3.6.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* oqs-provider-debuginfo-0.11.0.32-150600.3.9.1
* liboqs9-debuginfo-0.16.0-150600.3.6.1
* oqs-provider-0.11.0.32-150600.3.9.1
* liboqs-devel-0.16.0-150600.3.6.1
* liboqs9-0.16.0-150600.3.6.1
* openSUSE Leap 15.6 (x86_64)
* liboqs-devel-32bit-0.16.0-150600.3.6.1
* liboqs9-32bit-0.16.0-150600.3.6.1
* liboqs9-32bit-debuginfo-0.16.0-150600.3.6.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* liboqs9-64bit-debuginfo-0.16.0-150600.3.6.1
* liboqs-devel-64bit-0.16.0-150600.3.6.1
* liboqs9-64bit-0.16.0-150600.3.6.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* oqs-provider-debuginfo-0.11.0.32-150600.3.9.1
* liboqs9-debuginfo-0.16.0-150600.3.6.1
* oqs-provider-0.11.0.32-150600.3.9.1
* liboqs-devel-0.16.0-150600.3.6.1
* liboqs9-0.16.0-150600.3.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* oqs-provider-debuginfo-0.11.0.32-150600.3.9.1
* liboqs9-debuginfo-0.16.0-150600.3.6.1
* oqs-provider-0.11.0.32-150600.3.9.1
* liboqs-devel-0.16.0-150600.3.6.1
* liboqs9-0.16.0-150600.3.6.1
## References:
* https://www.suse.com/security/cve/CVE-2025-52473.html
* https://www.suse.com/security/cve/CVE-2026-44518.html
* https://www.suse.com/security/cve/CVE-2026-46344.html
* https://bugzilla.suse.com/show_bug.cgi?id01107
* https://bugzilla.suse.com/show_bug.cgi?id42701
* https://bugzilla.suse.com/show_bug.cgi?id44617
* https://bugzilla.suse.com/show_bug.cgi?id45315
* https://bugzilla.suse.com/show_bug.cgi?id46301
* https://bugzilla.suse.com/show_bug.cgi?id49081
* https://bugzilla.suse.com/show_bug.cgi?id67001
* https://bugzilla.suse.com/show_bug.cgi?id67007
SUSE-SU-2026:3422-1: important: Security update for python-sh
# Security update for python-sh
Announcement ID: SUSE-SU-2026:3422-1
Release Date: 2026-07-30T07:42:14Z
Rating: important
References:
* bsc#1272424
Cross-References:
* CVE-2026-54552
CVSS scores:
* CVE-2026-54552 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected Products:
* openSUSE Leap 15.4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for python-sh fixes the following issues:
* CVE-2026-54552: incomplete privilege drop in the _uid option can allow a
subprocess to retain parent supplementary groups (bsc#1272424).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3422=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3422=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3422=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3422=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3422=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3422=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3422=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3422=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3422=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3422=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3422=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3422=1
## Package List:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* python311-sh-2.0.4-150400.9.6.1
* openSUSE Leap 15.4 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* python311-sh-2.0.4-150400.9.6.1
* Python 3 Module 15-SP7 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* python311-sh-2.0.4-150400.9.6.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* python311-sh-2.0.4-150400.9.6.1
## References:
* https://www.suse.com/security/cve/CVE-2026-54552.html
* https://bugzilla.suse.com/show_bug.cgi?id72424
SUSE-SU-2026:3423-1: important: Security update for xen
# Security update for xen
Announcement ID: SUSE-SU-2026:3423-1
Release Date: 2026-07-30T07:50:01Z
Rating: important
References:
* bsc#1271528
* bsc#1271530
* bsc#1271531
* bsc#1271532
* bsc#1271533
* bsc#1271534
* bsc#1271535
* bsc#1271536
* bsc#1271537
* bsc#1271538
* bsc#1271539
* bsc#1271947
Cross-References:
* CVE-2026-42493
* CVE-2026-42494
* CVE-2026-42495
* CVE-2026-62423
* CVE-2026-62424
* CVE-2026-62425
* CVE-2026-62426
* CVE-2026-62427
* CVE-2026-62428
* CVE-2026-62429
* CVE-2026-62430
* CVE-2026-62431
* CVE-2026-62432
* CVE-2026-62433
* CVE-2026-62434
CVSS scores:
* CVE-2026-42493 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-42494 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-42495 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62423 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62424 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62425 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62426 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-62427 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-62428 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62429 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-62430 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-62431 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-62432 ( SUSE ): 8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-62433 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-62434 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Micro 5.5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves 15 vulnerabilities can now be installed.
## Description:
This update for xen fixes the following issues
* CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
* CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425:
buffer overruns in libfsimage iso9660 handling (bsc#1271530).
* CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse
(bsc#1271531).
* CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
* CVE-2026-62429: vNUMA domain cleanup may race other operations
(bsc#1271534).
* CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
* CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
* CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
* CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
* CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
* pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3423=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3423=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3423=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3423=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3423=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3423=1
## Package List:
* openSUSE Leap 15.5 (x86_64)
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-libs-32bit-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-doc-html-4.17.6_14-150500.3.76.3
* xen-libs-32bit-4.17.6_14-150500.3.76.3
* openSUSE Leap 15.5 (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* openSUSE Leap 15.5 (i586 x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* xen-tools-xendomains-wait-disk-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64)
* xen-tools-domU-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-tools-4.17.6_14-150500.3.76.3
* xen-4.17.6_14-150500.3.76.3
* xen-tools-domU-debuginfo-4.17.6_14-150500.3.76.3
* xen-tools-debuginfo-4.17.6_14-150500.3.76.3
* xen-libs-4.17.6_14-150500.3.76.3
* xen-devel-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
* SUSE Linux Enterprise Micro 5.5 (x86_64)
* xen-libs-4.17.6_14-150500.3.76.3
* xen-debugsource-4.17.6_14-150500.3.76.3
* xen-libs-debuginfo-4.17.6_14-150500.3.76.3
## References:
* https://www.suse.com/security/cve/CVE-2026-42493.html
* https://www.suse.com/security/cve/CVE-2026-42494.html
* https://www.suse.com/security/cve/CVE-2026-42495.html
* https://www.suse.com/security/cve/CVE-2026-62423.html
* https://www.suse.com/security/cve/CVE-2026-62424.html
* https://www.suse.com/security/cve/CVE-2026-62425.html
* https://www.suse.com/security/cve/CVE-2026-62426.html
* https://www.suse.com/security/cve/CVE-2026-62427.html
* https://www.suse.com/security/cve/CVE-2026-62428.html
* https://www.suse.com/security/cve/CVE-2026-62429.html
* https://www.suse.com/security/cve/CVE-2026-62430.html
* https://www.suse.com/security/cve/CVE-2026-62431.html
* https://www.suse.com/security/cve/CVE-2026-62432.html
* https://www.suse.com/security/cve/CVE-2026-62433.html
* https://www.suse.com/security/cve/CVE-2026-62434.html
* https://bugzilla.suse.com/show_bug.cgi?id71528
* https://bugzilla.suse.com/show_bug.cgi?id71530
* https://bugzilla.suse.com/show_bug.cgi?id71531
* https://bugzilla.suse.com/show_bug.cgi?id71532
* https://bugzilla.suse.com/show_bug.cgi?id71533
* https://bugzilla.suse.com/show_bug.cgi?id71534
* https://bugzilla.suse.com/show_bug.cgi?id71535
* https://bugzilla.suse.com/show_bug.cgi?id71536
* https://bugzilla.suse.com/show_bug.cgi?id71537
* https://bugzilla.suse.com/show_bug.cgi?id71538
* https://bugzilla.suse.com/show_bug.cgi?id71539
* https://bugzilla.suse.com/show_bug.cgi?id71947