SUSE-SU-2026:3398-1: important: Security update for rsyslog
SUSE-SU-2026:3399-1: important: Security update for gimp
openSUSE-SU-2026:0265-1: important: Security update for nsd
SUSE-SU-2026:3395-1: low: Security update for GraphicsMagick
SUSE-SU-2026:3396-1: important: Security update for webkit2gtk3
SUSE-SU-2026:3397-1: moderate: Security update for python-urllib3
SUSE-SU-2026:3402-1: important: Security update for python-ujson
SUSE-SU-2026:3404-1: moderate: Security update for PackageKit
SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk
SUSE-SU-2026:3407-1: important: Security update for openvpn
SUSE-SU-2026:3409-1: important: Security update for xen
SUSE-SU-2026:3398-1: important: Security update for rsyslog
# Security update for rsyslog
Announcement ID: SUSE-SU-2026:3398-1
Release Date: 2026-07-29T07:44:27Z
Rating: important
References:
* bsc#1271910
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that has one security fix can now be installed.
## Description:
This update for rsyslog fixes the following issue
* input sequence during oversize-frame recovery in imptcp can cause denial of
service (bsc#1271910).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3398=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3398=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3398=1
## Package List:
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* rsyslog-module-ossl-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-relp-8.2406.0-150600.12.13.1
* rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-debugsource-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-8.2406.0-150600.12.13.1
* rsyslog-debuginfo-8.2406.0-150600.12.13.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* rsyslog-module-ossl-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-relp-8.2406.0-150600.12.13.1
* rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-debugsource-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-8.2406.0-150600.12.13.1
* rsyslog-debuginfo-8.2406.0-150600.12.13.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* rsyslog-module-ossl-8.2406.0-150600.12.13.1
* rsyslog-module-elasticsearch-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-diag-tools-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-elasticsearch-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-diag-tools-8.2406.0-150600.12.13.1
* rsyslog-module-relp-8.2406.0-150600.12.13.1
* rsyslog-module-relp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-doc-8.2406.0-150600.12.13.1
* rsyslog-debugsource-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mmnormalize-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-mysql-8.2406.0-150600.12.13.1
* rsyslog-module-gcrypt-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-omhttpfs-8.2406.0-150600.12.13.1
* rsyslog-module-kafka-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-kafka-8.2406.0-150600.12.13.1
* rsyslog-module-gcrypt-8.2406.0-150600.12.13.1
* rsyslog-module-omhttpfs-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-dbi-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-omamqp1-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-8.2406.0-150600.12.13.1
* rsyslog-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-omtcl-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-8.2406.0-150600.12.13.1
* rsyslog-module-omtcl-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-gtls-8.2406.0-150600.12.13.1
* rsyslog-module-udpspoof-8.2406.0-150600.12.13.1
* rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-module-dbi-8.2406.0-150600.12.13.1
* rsyslog-module-snmp-8.2406.0-150600.12.13.1
* rsyslog-module-omamqp1-debuginfo-8.2406.0-150600.12.13.1
* rsyslog-debuginfo-8.2406.0-150600.12.13.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id71910
SUSE-SU-2026:3399-1: important: Security update for gimp
# Security update for gimp
Announcement ID: SUSE-SU-2026:3399-1
Release Date: 2026-07-29T07:44:50Z
Rating: important
References:
* bsc#1270239
* bsc#1270299
* bsc#1270444
Cross-References:
* CVE-2026-58379
* CVE-2026-58380
* CVE-2026-58381
CVSS scores:
* CVE-2026-58379 ( SUSE ): 8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58379 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-58379 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-58380 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58380 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-58380 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-58380 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-58381 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-58381 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
* CVE-2026-58381 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Linux Enterprise Workstation Extension 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves three vulnerabilities can now be installed.
## Description:
This update for gimp fixes the following issues
* CVE-2026-58379: Heap buffer overflow in read_channel_data() (bsc#1270299).
* CVE-2026-58380: Stack buffer overflow in pnmscanner_gettoken()
(bsc#1270444).
* CVE-2026-58381: double-free in read_layer_block() (bsc#1270239).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Workstation Extension 15 SP7
zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3399=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3399=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3399=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* gimp-devel-2.10.30-150400.3.58.1
* gimp-devel-debuginfo-2.10.30-150400.3.58.1
* libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-debugsource-2.10.30-150400.3.58.1
* libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-2.10.30-150400.3.58.1
* gimp-plugin-aa-2.10.30-150400.3.58.1
* gimp-debuginfo-2.10.30-150400.3.58.1
* gimp-plugin-aa-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-2.10.30-150400.3.58.1
* libgimp-2_0-0-2.10.30-150400.3.58.1
* openSUSE Leap 15.4 (x86_64)
* libgimp-2_0-0-32bit-2.10.30-150400.3.58.1
* libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-32bit-2.10.30-150400.3.58.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-64bit-2.10.30-150400.3.58.1
* libgimp-2_0-0-64bit-2.10.30-150400.3.58.1
* libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.58.1
* openSUSE Leap 15.4 (noarch)
* gimp-lang-2.10.30-150400.3.58.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64)
* gimp-devel-2.10.30-150400.3.58.1
* gimp-devel-debuginfo-2.10.30-150400.3.58.1
* libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-debugsource-2.10.30-150400.3.58.1
* libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-2.10.30-150400.3.58.1
* gimp-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-2.10.30-150400.3.58.1
* libgimp-2_0-0-2.10.30-150400.3.58.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch)
* gimp-lang-2.10.30-150400.3.58.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x)
* libgimp-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-debugsource-2.10.30-150400.3.58.1
* libgimpui-2_0-0-debuginfo-2.10.30-150400.3.58.1
* gimp-debuginfo-2.10.30-150400.3.58.1
* libgimpui-2_0-0-2.10.30-150400.3.58.1
* libgimp-2_0-0-2.10.30-150400.3.58.1
* SUSE Package Hub 15 15-SP7 (aarch64)
* gimp-devel-debuginfo-2.10.30-150400.3.58.1
* gimp-devel-2.10.30-150400.3.58.1
* gimp-2.10.30-150400.3.58.1
* gimp-plugin-aa-2.10.30-150400.3.58.1
* gimp-plugin-aa-debuginfo-2.10.30-150400.3.58.1
* SUSE Package Hub 15 15-SP7 (noarch)
* gimp-lang-2.10.30-150400.3.58.1
## References:
* https://www.suse.com/security/cve/CVE-2026-58379.html
* https://www.suse.com/security/cve/CVE-2026-58380.html
* https://www.suse.com/security/cve/CVE-2026-58381.html
* https://bugzilla.suse.com/show_bug.cgi?id70239
* https://bugzilla.suse.com/show_bug.cgi?id70299
* https://bugzilla.suse.com/show_bug.cgi?id70444
openSUSE-SU-2026:0265-1: important: Security update for nsd
openSUSE Security Update: Security update for nsd
_______________________________
Announcement ID: openSUSE-SU-2026:0265-1
Rating: important
References: #1269563 #1269564 #1269565 #1269566
Cross-References: CVE-2026-12244 CVE-2026-12245 CVE-2026-12246
CVE-2026-12490
Affected Products:
openSUSE Backports SLE-15-SP7
_______________________________
An update that fixes four vulnerabilities is now available.
Description:
This update for nsd fixes the following issues:
- Update nsd.keyring
- update to 4.14.3:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_3_REL/doc/ChangeLog
* CVE-2026-12490: Bypass of client certificate verification with
transfer over TLS (boo#1269563)
* CVE-2026-12246: Out of bounds stack write with crafted APL RR
(boo#1269564)
* CVE-2026-12245: Denial of DNS over TLS service by any DoT client
(boo#1269565)
* CVE-2026-12244: Heap overflow and crash with crafted SVCB RR
(boo#1269566)
- update to 4.14.2:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_2_REL/doc/ChangeLog
- update to 4.14.1:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_1_REL/doc/ChangeLog
- update to 4.14.0:
https://github.com/NLnetLabs/nsd/blob/NSD_4_14_0_REL/doc/ChangeLog
- update to 4.13.0:
https://github.com/NLnetLabs/nsd/blob/NSD_4_13_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_12_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_12_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_11_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_11_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_10_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_10_0_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_9_1_REL/doc/ChangeLog
https://github.com/NLnetLabs/nsd/blob/NSD_4_9_0_REL/doc/ChangeLog
- enable systemd notify support.
- enable dnstap support.
- enable tcp fast open support
- enable support for >= 2038
- As far as it is known the kernel has a working recvmmsg pass
--enable-recvmmsg to configure.
- Don't --enable-mmap. Replacing malloc may sound attractive but all
safety checks to prevent corruption included in libc are lost.
- Provide user/group symbol for user created during pre.
- update to 4.8.0:
* Fix unit test kill_from_pidfile function for nonexistent files because
the argument is evaluated before the test expression.
* Fix rr-test to also convert the contents of the just written
output file.
* Fix test set to remove -f nsd.db and rm nsd.db commands.
* Fix test set to remove difffile option.
* Fix #14: Set timeout to 3s when servicing remaining TCP connections.
* Fix: Always instate write handler after reading queries from TCP.
* Answer first query on connections accepted just before reload.
* Merge #305: faster stats. Statistics can be gathered while a reload is
in progress.
* Remove on-disk database.
* Fix processing of consolidated IXFRs.
* Fix for interprocess communication to set quit sync command from main
process explicitly.
* Merge #281: Proxy protocol. An implementation of PROXYv2 for NSD.
* It can be configured with proxy-protocol-port: portnum with the port
number of the interface on which proxy traffic is handled.
* The interface can support proxy traffic for UDP, TCP and TLS.
* Fix autoconf 2.69 warnings in configure.
* Merge #287: Update nsd.conf.5.in.
* Fix unused variable warning in unit test of udb.
* Fix #284: dnstap_collector.c: SOCK_NONBLOCK is not available
on Mac/Darwin.
* Fix unused but set variable warning. bind8-stats and --without-ssl are
specified.
* Add missing items to doc/RELNOTES.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-265=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
nsd-4.14.3-bp157.2.3.1
References:
https://www.suse.com/security/cve/CVE-2026-12244.html
https://www.suse.com/security/cve/CVE-2026-12245.html
https://www.suse.com/security/cve/CVE-2026-12246.html
https://www.suse.com/security/cve/CVE-2026-12490.html
https://bugzilla.suse.com/1269563
https://bugzilla.suse.com/1269564
https://bugzilla.suse.com/1269565
https://bugzilla.suse.com/1269566
SUSE-SU-2026:3395-1: low: Security update for GraphicsMagick
# Security update for GraphicsMagick
Announcement ID: SUSE-SU-2026:3395-1
Release Date: 2026-07-28T18:28:19Z
Rating: low
References:
* bsc#1271496
Cross-References:
* CVE-2026-61464
CVSS scores:
* CVE-2026-61464 ( SUSE ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-61464 ( SUSE ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
* CVE-2026-61464 ( NVD ): 1.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-61464 ( NVD ): 1.8 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Package Hub 15 15-SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for GraphicsMagick fixes the following issue:
* CVE-2026-61464: heap buffer overwrite when running an X11 import with a
crafted window title (bsc#1271496).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3395=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3395=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libGraphicsMagick++-devel-1.3.42-150600.3.39.1
* libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagickWand-Q16-2-1.3.42-150600.3.39.1
* perl-GraphicsMagick-1.3.42-150600.3.39.1
* libGraphicsMagick++-Q16-12-1.3.42-150600.3.39.1
* libGraphicsMagick-Q16-3-1.3.42-150600.3.39.1
* GraphicsMagick-devel-1.3.42-150600.3.39.1
* GraphicsMagick-debugsource-1.3.42-150600.3.39.1
* GraphicsMagick-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick3-config-1.3.42-150600.3.39.1
* GraphicsMagick-1.3.42-150600.3.39.1
* perl-GraphicsMagick-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.39.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* libGraphicsMagick++-devel-1.3.42-150600.3.39.1
* libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagickWand-Q16-2-1.3.42-150600.3.39.1
* perl-GraphicsMagick-1.3.42-150600.3.39.1
* libGraphicsMagick++-Q16-12-1.3.42-150600.3.39.1
* libGraphicsMagick-Q16-3-1.3.42-150600.3.39.1
* GraphicsMagick-devel-1.3.42-150600.3.39.1
* GraphicsMagick-debugsource-1.3.42-150600.3.39.1
* GraphicsMagick-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick3-config-1.3.42-150600.3.39.1
* GraphicsMagick-1.3.42-150600.3.39.1
* perl-GraphicsMagick-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.39.1
* libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.39.1
## References:
* https://www.suse.com/security/cve/CVE-2026-61464.html
* https://bugzilla.suse.com/show_bug.cgi?id71496
SUSE-SU-2026:3396-1: important: Security update for webkit2gtk3
# Security update for webkit2gtk3
Announcement ID: SUSE-SU-2026:3396-1
Release Date: 2026-07-28T18:31:07Z
Rating: important
References:
* bsc#1271638
Cross-References:
* CVE-2024-4367
* CVE-2026-39872
* CVE-2026-43663
* CVE-2026-43676
* CVE-2026-43699
* CVE-2026-43701
* CVE-2026-43705
* CVE-2026-43707
* CVE-2026-43712
* CVE-2026-43713
* CVE-2026-43715
* CVE-2026-43716
* CVE-2026-43720
* CVE-2026-43721
* CVE-2026-43725
* CVE-2026-43726
* CVE-2026-43727
* CVE-2026-43731
* CVE-2026-43732
* CVE-2026-43734
* CVE-2026-43740
* CVE-2026-43742
* CVE-2026-43745
CVSS scores:
* CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2024-4367 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-39872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43701 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43705 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43707 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43713 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43715 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43716 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43721 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43725 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43726 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43731 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43732 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43734 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43742 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves 23 vulnerabilities can now be installed.
## Description:
This update for webkit2gtk3 fixes the following issues:
* CVE-2024-4367: missing type check when handling fonts in PDF.js can allow
arbitrary JavaScript execution (bsc#1271638).
* CVE-2026-39872: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43663: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43676: out-of-bounds access when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43699: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43701: malicious website can process restricted web content outside
the sandbox (bsc#1271638).
* CVE-2026-43705: type confusion issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43707: memory corruption issue when processing web content can lead
to an unexpected process crash (bsc#1271638).
* CVE-2026-43712: maliciously crafted web content can lead to an unexpected
process crash (bsc#1271638).
* CVE-2026-43713: visiting a website can leak sensitive data due to a
permissions issue (bsc#1271638).
* CVE-2026-43715: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43716: maliciously crafted web content can lead to an unexpected
Safari crash (bsc#1271638).
* CVE-2026-43720: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43721: malicious website can silently hijack clipboard data
(bsc#1271638).
* CVE-2026-43725: unvalidated input can allow a malicious website to process
restricted web content outside the sandbox (bsc#1271638).
* CVE-2026-43726: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43727: use-after-free issue when processing web content can lead to
an unexpected Safari crash (bsc#1271638).
* CVE-2026-43731: use-after-free issue when processing web content can lead to
memory corruption (bsc#1271638).
* CVE-2026-43732: path handling issue when processing web content can disclose
sensitive user information (bsc#1271638).
* CVE-2026-43734: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43740: maliciously crafted web content can result in the disclosure
of process memory (bsc#1271638).
* CVE-2026-43742: use-after-free issue when processing web content can lead to
an unexpected process crash (bsc#1271638).
* CVE-2026-43745: out-of-bounds write issue when processing web content can
lead to an unexpected Safari crash (bsc#1271638).
Changes for webkit2gtk3:
* Update to version 2.52.5:
* Fire scrollend event for instant programmatic scrolls.
* Increase network idle connection timeout to 115 seconds.
* Add User-Agent quirk for HBO Max.
* Fix the build with system malloc.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3396=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3396=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3396=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3396=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3396=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3396=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3396=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3396=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3396=1
## Package List:
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* webkit-jsc-4.1-debuginfo-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* webkit2gtk4-devel-2.52.5-150400.4.146.1
* webkit2gtk4-minibrowser-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* webkit-jsc-4-debuginfo-2.52.5-150400.4.146.1
* webkit-jsc-6.0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-6_0-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit-6_0-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk4-minibrowser-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-minibrowser-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit-jsc-4-2.52.5-150400.4.146.1
* webkit-jsc-6.0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-minibrowser-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-minibrowser-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* webkit-jsc-4.1-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-minibrowser-2.52.5-150400.4.146.1
* openSUSE Leap 15.4 (aarch64_ilp32)
* libwebkit2gtk-4_1-0-64bit-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-64bit-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-64bit-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-64bit-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.5-150400.4.146.1
* openSUSE Leap 15.4 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* openSUSE Leap 15.4 (x86_64)
* libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-32bit-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-32bit-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-32bit-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-32bit-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* webkit2gtk4-debugsource-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_0-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_0-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_1-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-2.52.5-150400.4.146.1
* typelib-1_0-JavaScriptCore-4_1-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-2.52.5-150400.4.146.1
* webkitgtk-6_0-injected-bundles-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libwebkitgtk-6_0-4-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-2.52.5-150400.4.146.1
* webkit2gtk-4_0-injected-bundles-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_1-0-2.52.5-150400.4.146.1
* libwebkit2gtk-4_1-0-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-devel-2.52.5-150400.4.146.1
* webkit2gtk3-soup2-debugsource-2.52.5-150400.4.146.1
* libjavascriptcoregtk-4_0-18-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk-4_1-injected-bundles-debuginfo-2.52.5-150400.4.146.1
* libjavascriptcoregtk-6_0-1-debuginfo-2.52.5-150400.4.146.1
* webkit2gtk3-devel-2.52.5-150400.4.146.1
* typelib-1_0-WebKit2-4_0-2.52.5-150400.4.146.1
* webkit2gtk3-debugsource-2.52.5-150400.4.146.1
* libwebkit2gtk-4_0-37-debuginfo-2.52.5-150400.4.146.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
* WebKitGTK-4.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-6.0-lang-2.52.5-150400.4.146.1
* WebKitGTK-4.1-lang-2.52.5-150400.4.146.1
## References:
* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
* https://www.suse.com/security/cve/CVE-2026-43731.html
* https://www.suse.com/security/cve/CVE-2026-43732.html
* https://www.suse.com/security/cve/CVE-2026-43734.html
* https://www.suse.com/security/cve/CVE-2026-43740.html
* https://www.suse.com/security/cve/CVE-2026-43742.html
* https://www.suse.com/security/cve/CVE-2026-43745.html
* https://bugzilla.suse.com/show_bug.cgi?id71638
SUSE-SU-2026:3397-1: moderate: Security update for python-urllib3
# Security update for python-urllib3
Announcement ID: SUSE-SU-2026:3397-1
Release Date: 2026-07-28T18:31:35Z
Rating: moderate
References:
* bsc#1268683
Cross-References:
* CVE-2026-9375
CVSS scores:
* CVE-2026-9375 ( SUSE ): 8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-9375 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-9375 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.4
* Public Cloud Module 15-SP4
* Python 3 Module 15-SP7
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Manager Proxy 4.3
* SUSE Manager Retail Branch Server 4.3
* SUSE Manager Server 4.3
An update that solves one vulnerability can now be installed.
## Description:
This update for python-urllib3 fixes the following issue
* CVE-2026-9375: decompression bomb bypass in the streaming API when using
Brotli support can lead to a denial of service (bsc#1268683).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3397=1
* Public Cloud Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3397=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3397=1
## Package List:
* Python 3 Module 15-SP7 (noarch)
* python311-urllib3-2.0.7-150400.7.33.1
* Public Cloud Module 15-SP4 (noarch)
* python311-urllib3-2.0.7-150400.7.33.1
* openSUSE Leap 15.4 (noarch)
* python311-urllib3-2.0.7-150400.7.33.1
## References:
* https://www.suse.com/security/cve/CVE-2026-9375.html
* https://bugzilla.suse.com/show_bug.cgi?id68683
SUSE-SU-2026:3402-1: important: Security update for python-ujson
# Security update for python-ujson
Announcement ID: SUSE-SU-2026:3402-1
Release Date: 2026-07-29T10:46:13Z
Rating: important
References:
* bsc#1270301
Cross-References:
* CVE-2026-44660
CVSS scores:
* CVE-2026-44660 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44660 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-44660 ( NVD ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-44660 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* openSUSE Leap 15.6
An update that solves one vulnerability can now be installed.
## Description:
This update for python-ujson fixes the following issue:
* CVE-2026-44660: failing to decrement a serialized JSON object during a write
exception in ujson.dump() can lead to memory leaks (bsc#1270301).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3402=1
## Package List:
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* python311-ujson-5.9.0-150600.3.3.1
## References:
* https://www.suse.com/security/cve/CVE-2026-44660.html
* https://bugzilla.suse.com/show_bug.cgi?id70301
SUSE-SU-2026:3404-1: moderate: Security update for PackageKit
# Security update for PackageKit
Announcement ID: SUSE-SU-2026:3404-1
Release Date: 2026-07-29T10:59:45Z
Rating: moderate
References:
* bsc#1267250
Cross-References:
* CVE-2026-10294
CVSS scores:
* CVE-2026-10294 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-10294 ( NVD ): 2.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-10294 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products:
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
* SUSE Linux Enterprise Workstation Extension 15 SP7
An update that solves one vulnerability can now be installed.
## Description:
This update for PackageKit fixes the following issues:
* CVE-2026-10294: manipulation of the argument frontend-socket can lead to
improper authorization (bsc#1267250).
## Special Instructions and Notes:
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3404=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3404=1
* SUSE Linux Enterprise Workstation Extension 15 SP7
zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3404=1
## Package List:
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libpackagekit-glib2-devel-1.2.8-150600.4.17.1
* PackageKit-backend-zypp-1.2.8-150600.4.17.1
* PackageKit-1.2.8-150600.4.17.1
* PackageKit-debuginfo-1.2.8-150600.4.17.1
* PackageKit-devel-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-1.2.8-150600.4.17.1
* PackageKit-backend-zypp-debuginfo-1.2.8-150600.4.17.1
* typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-debuginfo-1.2.8-150600.4.17.1
* PackageKit-debugsource-1.2.8-150600.4.17.1
* PackageKit-devel-debuginfo-1.2.8-150600.4.17.1
* Desktop Applications Module 15-SP7 (noarch)
* PackageKit-lang-1.2.8-150600.4.17.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* libpackagekit-glib2-devel-1.2.8-150600.4.17.1
* PackageKit-backend-dnf-debuginfo-1.2.8-150600.4.17.1
* PackageKit-1.2.8-150600.4.17.1
* PackageKit-debuginfo-1.2.8-150600.4.17.1
* PackageKit-backend-zypp-1.2.8-150600.4.17.1
* PackageKit-devel-1.2.8-150600.4.17.1
* PackageKit-debugsource-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-1.2.8-150600.4.17.1
* PackageKit-backend-zypp-debuginfo-1.2.8-150600.4.17.1
* PackageKit-gtk3-module-1.2.8-150600.4.17.1
* typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.17.1
* PackageKit-gstreamer-plugin-1.2.8-150600.4.17.1
* PackageKit-backend-dnf-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-debuginfo-1.2.8-150600.4.17.1
* PackageKit-gtk3-module-debuginfo-1.2.8-150600.4.17.1
* PackageKit-gstreamer-plugin-debuginfo-1.2.8-150600.4.17.1
* PackageKit-devel-debuginfo-1.2.8-150600.4.17.1
* openSUSE Leap 15.6 (x86_64)
* libpackagekit-glib2-devel-32bit-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-32bit-debuginfo-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-32bit-1.2.8-150600.4.17.1
* openSUSE Leap 15.6 (noarch)
* PackageKit-branding-upstream-1.2.8-150600.4.17.1
* PackageKit-lang-1.2.8-150600.4.17.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libpackagekit-glib2-devel-64bit-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-64bit-1.2.8-150600.4.17.1
* libpackagekit-glib2-18-64bit-debuginfo-1.2.8-150600.4.17.1
* SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64)
* PackageKit-debuginfo-1.2.8-150600.4.17.1
* PackageKit-gtk3-module-1.2.8-150600.4.17.1
* PackageKit-gstreamer-plugin-1.2.8-150600.4.17.1
* PackageKit-gstreamer-plugin-debuginfo-1.2.8-150600.4.17.1
* PackageKit-debugsource-1.2.8-150600.4.17.1
* PackageKit-gtk3-module-debuginfo-1.2.8-150600.4.17.1
## References:
* https://www.suse.com/security/cve/CVE-2026-10294.html
* https://bugzilla.suse.com/show_bug.cgi?id67250
SUSE-SU-2026:3406-1: important: Security update for java-17-openjdk
# Security update for java-17-openjdk
Announcement ID: SUSE-SU-2026:3406-1
Release Date: 2026-07-29T11:10:17Z
Rating: important
References:
* bsc#1264396
* bsc#1264994
* bsc#1267355
* bsc#1272223
* bsc#1272224
* bsc#1272225
* bsc#1272227
* bsc#1272228
* bsc#1272235
* bsc#1272236
* bsc#1272237
Cross-References:
* CVE-2026-41254
* CVE-2026-46917
* CVE-2026-46968
* CVE-2026-47010
* CVE-2026-47021
* CVE-2026-47027
* CVE-2026-47059
* CVE-2026-47063
* CVE-2026-60147
CVSS scores:
* CVE-2026-41254 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
* CVE-2026-46917 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46968 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47010 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2026-47021 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-47063 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-60147 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products:
* Legacy Module 15-SP7
* openSUSE Leap 15.4
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves nine vulnerabilities and has two security fixes can now be
installed.
## Description:
This update for java-17-openjdk fixes the following issues:
Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU).
Security issues fixed:
* CVE-2026-41254: lcms: information disclosure and denial of service via
integer overflow in `CubeSize` (bsc#1264994).
* CVE-2026-46917: unauthenticated attacker with network access via TLS can
cause a partial denial of service (bsc#1272223).
* CVE-2026-46968: unauthenticated attacker with network access via TLS can
gain unauthorized creation, deletion or modification access to critical data
(bsc#1272224).
* CVE-2026-47010: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert or delete access to some data
(bsc#1272225).
* CVE-2026-47021: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272227).
* CVE-2026-47027: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272228).
* CVE-2026-47059: unauthenticated attacker with network access via multiple
protocols can cause a partial denial of service (bsc#1272235).
* CVE-2026-47063: unauthenticated attacker with network access via multiple
protocols can gain unauthorized creation, deletion or modification access to
critical data (bsc#1272236).
* CVE-2026-60147: unauthenticated attacker with network access via multiple
protocols can gain unauthorized update, insert, delete and read access to
some data (bsc#1272237).
Other updates and bugfixes:
* Make post scripts less noisy (bsc#1267355).
* Use `libalternatives` instead of `update-alternatives` for distributions
where `libalternatives` is available.
* Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU):
* JDK-7184899: Test sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
* JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
* JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/ /bug4624207.java fails
* JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/ /motif/InternalFrame/4150591/bug4150591.java fails with GTKLookAndFeel
* JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/ /Test4234761.java fails with GTKL&F
* JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/ /PrintDialogsTest.java instruction need to update
* JDK-8183336: Better cleanup for jdk/test/java/lang/module/ /customfs/ModulesInCustomFileSystem.java
* JDK-8221451: PIT: sun/java2d/X11SurfaceData/ /SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
* JDK-8240908: RetransformClass does not know about MethodParameters attribute
* JDK-8255463: java/nio/channels/spi/SelectorProvider/ /inheritedChannel/InheritedChannelTest.java failed with ThreadTimeoutException
* JDK-8272477: Additional cleanup of test/jdk/java/nio/file/spi/ /SetDefaultProvider.java
* JDK-8274082: Wrong test name in jtreg run tag for java/awt/ /print/PrinterJob/SwingUIText.java
* JDK-8277444: Data race between JvmtiClassFileReconstituter::copy_bytecodes and class linking
* JDK-8281243: Test java/lang/instrument/ /RetransformWithMethodParametersTest.java is failing
* JDK-8282044: [JVMCI] Export _sha3_implCompress, _md5_implCompress and aarch64::_has_negatives stubs to JVMCI compiler.
* JDK-8284993: Replace System.exit call in swing tests with RuntimeException
* JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads the spinner value wrong and sometime partially
* JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/ /nativeAndMH/Test.java fails with Out of space in CodeCache
* JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed due to different timeout message
* JDK-8290504: Close streams returned by ModuleReader::list
* JDK-8293484: AArch64: TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU with SHA512 feature support
* JDK-8297191: [macos] Printing a page range with starting page > 1 results in missing pages
* JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed with "RuntimeException: MyObject is not found in test output"
* JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/ /DragWindowTest.java continues to fail with "No MouseReleased event on label!"
* JDK-8299304: Test "java/awt/print/PrinterJob/ /PageDialogTest.java" fails on macOS 13 x64 because the Page Dialog blocks the Toolkit
* JDK-8304065: HttpServer.stop should terminate immediately if no exchanges are in progress
* JDK-8309142: Refactor test/langtools/tools/javac/versions/ /Versions.java
* JDK-8316274: javax/swing/ButtonGroup/ /TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with Motif LAF
* JDK-8317801: java/net/Socket/asyncClose/Race.java fails intermittently (aix)
* JDK-8320677: Printer tests use invalid '@run main/manual=yesno
* JDK-8321182: SourceExample.SOURCE_14 comment should refer to 'switch expressions' instead of 'text blocks'
* JDK-8321303: Intermittent open/test/jdk/java/awt/ /KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/ /ConsumeNextMnemonicKeyTypedTest.java failure on Linux
* JDK-8323089: networkaddress.cache.ttl is not a system property
* JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java fails with "exit code: 133"
* JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX
* JDK-8324345: Stack overflow during C2 compilation when splitting memory phi
* JDK-8324641: [IR Framework] Add Setup method to provide custom arguments and set fields
* JDK-8328300: Convert PrintDialogsTest.java from Applet to main program
* JDK-8332495: java/util/logging/LoggingDeadlock2.java fails with AssertionError: Some tests failed
* JDK-8334928: Test sun/security/ssl/SSLSocketImpl/ /ReuseAddr.java failed: java.net.BindException: Address already in use
* JDK-8337876: [IR Framework] Add support for IR tests with @Stable
* JDK-8338103: Stabilize and open source a Swing OGL ButtonResizeTest
* JDK-8338112: Test testlibrary_tests/ir_framework/tests/ /TestPrivilegedMode.java fails with release build
* JDK-8338344: Test TestPrivilegedMode.java intermittent fails java.lang.NoClassDefFoundError: jdk/test/lib/Platform
* JDK-8338554: Fix inconsistencies in javadoc/doclet/ /testLinkOption/TestRedirectLinks.java
* JDK-8338883: Show warning when CreateCoredumpOnCrash set, but core dump will not happen
* JDK-8339233: Test javax/swing/JButton/ /SwingButtonResizeTestWithOpenGL.java#id failed: Button renderings are different after window resize
* JDK-8339238: Update to use jtreg 7.5.1
* JDK-8339879: Open some dialog awt tests
* JDK-8339975: Open some dialog awt tests 2
* JDK-8340140: Open some dialog awt tests 3
* JDK-8340336: Open some checkbox awt tests
* JDK-8340494: Open some dialog awt tests 4
* JDK-8340851: Open some TextArea awt tests
* JDK-8340987: Open some TextArea awt tests 1
* JDK-8341055: Open some TextArea awt tests 2
* JDK-8341292: Open some TextArea awt tests 3
* JDK-8341376: Open some TextArea awt tests 4
* JDK-8341427: JFR: Adjust object sampler span handling
* JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/ /JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on SBR Hosts
* JDK-8345618: javax/swing/text/Caret/8163124/ /CaretFloatingPointAPITest.java leaves Caret is not complete
* JDK-8346154: [XWayland] Some tests fail intermittently in the CI, but not locally
* JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers
* JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
* JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails: ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime - waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
* JDK-8349533: Refactor validator tests shell files to java
* JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups
* JDK-8350749: Upgrade JLine to 3.29.0
* JDK-8352685: Opensource JInternalFrame tests - series2
* JDK-8352733: Improve RotFontBoundsTest test
* JDK-8352877: Opensource Several Font related tests - Batch 1
* JDK-8353488: Open some JComboBox bugs 3
* JDK-8353552: Opensource Several Font related tests - Batch 3
* JDK-8354163: Open source Swing tests Batch 1
* JDK-8354469: Keytool exposes the password in plain text when command is piped using | grep
* JDK-8354695: Open source several swing tests batch7
* JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300
* JDK-8354900: javax/swing/AbstractButton/bug4133768.java failing on macosx-aarch64
* JDK-8355048: ProblemList TestGlyphVectorLayout.java on all platforms
* JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/ /bug4865918.java headful and macos run
* JDK-8355332: Fix failing semi-manual test EDT issue
* JDK-8355443: [java.io] Use @requires tag instead of exiting based on File.separatorChar value
* JDK-8355445: [java.nio] Use @requires tag instead of exiting based on "os.name" property value
* JDK-8356107: [java.lang] Use @requires tag instead of exiting based on os.name or separatorChar property
* JDK-8357062: Update Public Suffix List to 823beb1
* JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
* JDK-8357141: Update to use jtreg 7.5.2
* JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/ /LimitDirectMemory[NegativeTest].java
* JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/ /ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts used by Oracle's internal CI system
* JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails intermittently
* JDK-8358751: C2: Recursive inlining check for compiled lambda forms is broken
* JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java failed again with java.net.SocketException: An established connection was aborted by the software in your host machine
* JDK-8360160: ubuntu-22-04 machine is failing client tests
* JDK-8360882: Tests throw SkippedException when they should fail
* JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails with java.nio.file.FileSystemException
* JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on Windows: character typed with VK_A: a
* JDK-8362428: Update IANA Language Subtag Registry to Version 2025-08-25
* JDK-8364190: JFR: RemoteRecordingStream withers don't work
* JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/ /jaxp/functional/javax/xml/transform/xmlfiles
* JDK-8364927: Add @requires annotation to TestReclaimStringsLeaksMemory.java
* JDK-8365379: SU3.applyInsets may produce wrong results
* JDK-8365423: [macos26] java/awt/MenuBar/8007006/ /bug8007006.java fails on macOS 26
* JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails on macOS 26
* JDK-8365526: Crash with null Symbol passed to SystemDictionary::resolve_or_null
* JDK-8365625: Can't change accelerator colors in Windows L&F
* JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile uses wrong file
* JDK-8366261: Provide utility methods for sun.security.util.Password
* JDK-8366369: Add @requires linux for GTK L&F tests
* JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/ /ChoiceMouseWheelTest.java test is failing
* JDK-8367583: sun/security/util/AlgorithmConstraints/ /InvalidCryptoDisabledAlgos.java fails after JDK-8244336
* JDK-8367772: Refactor createUI in PassFailJFrame
* JDK-8367784: java/awt/Focus/InitialFocusTest/ /InitialFocusTest1.java failed with Wrong focus owner
* JDK-8368041: Enhance TLS certificate handling
* JDK-8368335: Refactor the rest of Locale TestNG based tests to JUnit
* JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
* JDK-8368551: Core dump warning may be confusing
* JDK-8368670: Deadlock in JFR on event register + class load
* JDK-8368683: [process] Increase jtreg debug output maxOutputSize for TreeTest
* JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is too strict
* JDK-8368885: NMT CommandLine tests can check for error better
* JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
* JDK-8369251: Opensource few tests
* JDK-8369319: java/net/httpclient/CancelRequestTest.java fails intermittently
* JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows after JDK-8358058
* JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0: Incorrect color for first pixel (actual?000000)
* JDK-8369851: Remove darcy author tags from langtools tests
* JDK-8369858: Remove darcy author tags from jdk tests
* JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java #CubicDoDash, #Cubic and #Poly fail intermittent
* JDK-8369950: TLS connection to IPv6 address fails with BCJSSE due to IllegalArgumentException
* JDK-8370325: G1: Disallow GC for TLAB allocation
* JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does not release previously pressed keys
* JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking gc for nsk/jvmti tests
* JDK-8370942: test/jdk/java/security/Provider/NewInstance.java and /test/jdk/java/security/cert/CertStore/NoLDAP.java may skip without notifying
* JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java to use Util.findComponent()
* JDK-8371366: java/net/httpclient/whitebox/ /RawChannelTestDriver.java fails intermittently in jtreg timeout
* JDK-8371383: Test sun/security/tools/jarsigner/ /DefaultOptions.java failed due to CertificateNotYetValidException
* JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some tests
* JDK-8372120: Add missing sound keyword to MIDI tests
* JDK-8372351: Add 2 WISeKey roots
* JDK-8372609: Bug4944439 does not enforce locale correctly
* JDK-8372661: Add a null-safe static factory method to "jdk.test.lib.net.SimpleSSLContext"
* JDK-8372988: Test runtime/Nestmates/membership/ /TestNestHostErrorWithMultiThread.java failed: Unexpected interrupt
* JDK-8373101: JdkClient and JdkServer test classes ignore namedGroups field
* JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java fails with incorrect selection of printed pages
* JDK-8373275: Improve DTLS handshaking
* JDK-8373623: Refactor Serialization tests for Records to JUnit
* JDK-8373650: Test "javax/swing/JMenuItem/6458123/ /ManualBug6458123.java" fails because the check icons are not aligned properly as expected
* JDK-8373690: Unexpected Keystore message using jdk.crypto.disabledAlgorithms
* JDK-8373716: Refactor further java/util tests from TestNG to JUnit
* JDK-8373807: test/jdk/java/net/httpclient/websocket/ /DummyWebSocketServer.java getURI() uses "localhost"
* JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/ /bug6197830.java failed because The test case automatically fails when clicking any items in the “Nothing” menu in all four windows (Left-to-right)-Menu Item Test and (Right-to-left)-Menu Item Test
* JDK-8373869: Refactor java/net/httpclient/ /ThrowingPushPromises*.java tests to use JUnit5
* JDK-8373928: 4 Dangling pointer defect groups in java.c
* JDK-8373931: Test javax/sound/sampled/Clip/ /AutoCloseTimeCheck.java timed out
* JDK-8374058: Enhance JPEG handling
* JDK-8374178: Missing include in systemDictionary.cpp after JDK-8365526
* JDK-8374304: MultiResolutionSplashTest.java fails in CI: "Image with wrong resolution is used for splash screen!"
* JDK-8374433: java/util/Locale/PreserveTagCase.java does not run any tests
* JDK-8374506: Incorrect positioning of arrow icon in parent JMenu in Windows L&F
* JDK-8374548: Process httpserver cancelled keys more quickly
* JDK-8374555: No need for visible input warning in s.s.u.Password when not reading from System.in
* JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/ /TestOptionsWithRanges fails without printing the option name
* JDK-8374888: Implement internal test cache to help UserIterCount test performance
* JDK-8374998: Failing os::write - remove bad file
* JDK-8375065: Update LCMS to 2.18
* JDK-8375080: The tools/jpackage/windows/Win8365790Test.java may fail with ClassNotFoundException: jtreg.SkippedException
* JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
* JDK-8375232: Refactor util/StringJoiner tests to use JUnit
* JDK-8375233: Refactor util/Vector tests to use JUnit
* JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails sporadically on Windows
* JDK-8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method
* JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java timed out then completed
* JDK-8376233: Clean up code in Desktop native peer
* JDK-8377158: Enhance XBM image support
* JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable
* JDK-8377498: Improve HttpServer handling
* JDK-8377602: Create automated test for PageRange
* JDK-8377678: G1: Heap Dumping crashes with -UseClassUnloading
* JDK-8377727: Ghost caret and focus appear in non‑editable text fields
* JDK-8377833: Enhance Jar file processing
* JDK-8377910: Minor cleanup of java/io/FileDescriptor/ /Sharing.java
* JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME: Metaspace
* JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the ProblemList.txt file
* JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers of the unbound drawable
* JDK-8378417: Printing All pages results in NPE for 1.1 PrintJob
* JDK-8378687: Improve delegation of HttpURLConnection
* JDK-8378777: Bump update version for OpenJDK: jdk-17.0.20
* JDK-8378802: [21u] backport changes to TKit.java by JDK-8352419
* JDK-8380316: Test runtime/os/AvailableProcessors.java fails Invalid argument
* JDK-8380565: PPC64: deoptimization stub should save vector registers
* JDK-8380672: Improve certification checking
* JDK-8380947: Add pull request template
* JDK-8381039: Enhance AWT ImagingLib
* JDK-8381049: Enhance Jar handling
* JDK-8381205: GHA: Upgrade Node.js 20 to 24
* JDK-8381519: Enhance Der Value Handling
* JDK-8381796: Enhance Certificate parsing
* JDK-8382242: JFR: Metadata reconstruction invalidates ConstantMap for java.lang.String
* JDK-8383175: (tz) Update Timezone Data to 2026b
* JDK-8383354: Update LCMS to 2.19.1
* JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change
* JDK-8383601: RISC-V: ShenandoahBarrierSetAssembler::load_reference_barrier calls "weak" on "phantom" path
* JDK-8383630: Fix iteration in tests doing class redefinition
* JDK-8383659: [17u] JVM crashes during stub routines generation on Windows and rare combination of CPU features
* JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily
* JDK-8384486: NTLM tests fail on Windows 11 and Windows Server 2025
* JDK-8384495: Update Libpng to 1.6.58
* JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26 updates
* JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after expired test certificate
* JDK-8384902: Update GIFlib to 6.1.3
* JDK-8385390: Update FreeType to 2.14.3
* JDK-8385490: Update HarfBuzz to 14.2.0
* JDK-8386343: [17u] Fix NTLMHeadTest after backport of 8384486
* JDK-8386551: Windows build broken because of MSys2/Make update
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3406=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3406=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3406=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3406=1
* Legacy Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3406=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3406=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3406=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3406=1
## Package List:
* Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-jmods-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-src-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* openSUSE Leap 15.4 (noarch)
* java-17-openjdk-javadoc-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* java-17-openjdk-demo-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-17.0.20.0-150400.3.69.1
* java-17-openjdk-headless-17.0.20.0-150400.3.69.1
* java-17-openjdk-devel-17.0.20.0-150400.3.69.1
* java-17-openjdk-debuginfo-17.0.20.0-150400.3.69.1
* java-17-openjdk-debugsource-17.0.20.0-150400.3.69.1
## References:
* https://www.suse.com/security/cve/CVE-2026-41254.html
* https://www.suse.com/security/cve/CVE-2026-46917.html
* https://www.suse.com/security/cve/CVE-2026-46968.html
* https://www.suse.com/security/cve/CVE-2026-47010.html
* https://www.suse.com/security/cve/CVE-2026-47021.html
* https://www.suse.com/security/cve/CVE-2026-47027.html
* https://www.suse.com/security/cve/CVE-2026-47059.html
* https://www.suse.com/security/cve/CVE-2026-47063.html
* https://www.suse.com/security/cve/CVE-2026-60147.html
* https://bugzilla.suse.com/show_bug.cgi?id64396
* https://bugzilla.suse.com/show_bug.cgi?id64994
* https://bugzilla.suse.com/show_bug.cgi?id67355
* https://bugzilla.suse.com/show_bug.cgi?id72223
* https://bugzilla.suse.com/show_bug.cgi?id72224
* https://bugzilla.suse.com/show_bug.cgi?id72225
* https://bugzilla.suse.com/show_bug.cgi?id72227
* https://bugzilla.suse.com/show_bug.cgi?id72228
* https://bugzilla.suse.com/show_bug.cgi?id72235
* https://bugzilla.suse.com/show_bug.cgi?id72236
* https://bugzilla.suse.com/show_bug.cgi?id72237
SUSE-SU-2026:3407-1: important: Security update for openvpn
# Security update for openvpn
Announcement ID: SUSE-SU-2026:3407-1
Release Date: 2026-07-29T11:10:53Z
Rating: important
References:
* bsc#1270413
* bsc#1270414
Cross-References:
* CVE-2026-13122
* CVE-2026-13698
CVSS scores:
* CVE-2026-13122 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13122 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13122 ( NVD ): 5.9
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13122 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13698 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-13698 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-13698 ( NVD ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-13698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves two vulnerabilities can now be installed.
## Description:
This update for openvpn fixes the following issues:
* CVE-2026-13122: denial of service via a malformed authentication token that
triggers a reachable assertion when external-auth is enabled (bsc#1270413).
* CVE-2026-13698: denial of service via memory leak triggered by remote
attackers with a valid tls-crypt-v2 client key (bsc#1270414).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3407=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3407=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3407=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3407=1
## Package List:
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* openvpn-dco-debuginfo-2.6.10-150600.3.23.1
* openvpn-debugsource-2.6.10-150600.3.23.1
* openvpn-dco-2.6.10-150600.3.23.1
* openvpn-dco-devel-2.6.10-150600.3.23.1
* openvpn-dco-debugsource-2.6.10-150600.3.23.1
* openvpn-debuginfo-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1
* openvpn-devel-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.23.1
* openvpn-2.6.10-150600.3.23.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* openvpn-dco-debuginfo-2.6.10-150600.3.23.1
* openvpn-debugsource-2.6.10-150600.3.23.1
* openvpn-dco-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.23.1
* openvpn-dco-devel-2.6.10-150600.3.23.1
* openvpn-dco-debugsource-2.6.10-150600.3.23.1
* openvpn-debuginfo-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1
* openvpn-devel-2.6.10-150600.3.23.1
* openvpn-down-root-plugin-2.6.10-150600.3.23.1
* openvpn-down-root-plugin-debuginfo-2.6.10-150600.3.23.1
* openvpn-2.6.10-150600.3.23.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* openvpn-dco-debuginfo-2.6.10-150600.3.23.1
* openvpn-debugsource-2.6.10-150600.3.23.1
* openvpn-dco-2.6.10-150600.3.23.1
* openvpn-dco-devel-2.6.10-150600.3.23.1
* openvpn-dco-debugsource-2.6.10-150600.3.23.1
* openvpn-debuginfo-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1
* openvpn-devel-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.23.1
* openvpn-2.6.10-150600.3.23.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* openvpn-dco-debuginfo-2.6.10-150600.3.23.1
* openvpn-debugsource-2.6.10-150600.3.23.1
* openvpn-dco-2.6.10-150600.3.23.1
* openvpn-dco-devel-2.6.10-150600.3.23.1
* openvpn-dco-debugsource-2.6.10-150600.3.23.1
* openvpn-debuginfo-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.23.1
* openvpn-devel-2.6.10-150600.3.23.1
* openvpn-auth-pam-plugin-2.6.10-150600.3.23.1
* openvpn-2.6.10-150600.3.23.1
## References:
* https://www.suse.com/security/cve/CVE-2026-13122.html
* https://www.suse.com/security/cve/CVE-2026-13698.html
* https://bugzilla.suse.com/show_bug.cgi?id70413
* https://bugzilla.suse.com/show_bug.cgi?id70414
SUSE-SU-2026:3409-1: important: Security update for xen
# Security update for xen
Announcement ID: SUSE-SU-2026:3409-1
Release Date: 2026-07-29T11:18:18Z
Rating: important
References:
* bsc#1271528
* bsc#1271530
* bsc#1271531
* bsc#1271532
* bsc#1271533
* bsc#1271534
* bsc#1271535
* bsc#1271536
* bsc#1271537
* bsc#1271538
* bsc#1271539
* bsc#1271947
Cross-References:
* CVE-2026-42493
* CVE-2026-42494
* CVE-2026-42495
* CVE-2026-62423
* CVE-2026-62424
* CVE-2026-62425
* CVE-2026-62426
* CVE-2026-62427
* CVE-2026-62428
* CVE-2026-62429
* CVE-2026-62430
* CVE-2026-62431
* CVE-2026-62432
* CVE-2026-62433
* CVE-2026-62434
CVSS scores:
* CVE-2026-42493 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-42494 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
* CVE-2026-42495 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62423 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62424 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62425 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-62426 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-62427 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-62428 ( SUSE ): 8.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-62429 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-62430 ( SUSE ): 2.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-62431 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
* CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-62432 ( SUSE ): 8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-62433 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
* CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
* CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-62434 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H
* CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
* CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves 15 vulnerabilities can now be installed.
## Description:
This update for xen fixes the following issues:
* CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
* CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425:
buffer overruns in libfsimage iso9660 handling (bsc#1271530).
* CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse
(bsc#1271531).
* CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
* CVE-2026-62429: vNUMA domain cleanup may race other operations
(bsc#1271534).
* CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
* CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
* CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
* CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
* CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
* pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3409=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3409=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3409=1
## Package List:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* xen-tools-domU-4.18.5_20-150600.3.53.3
* xen-tools-debuginfo-4.18.5_20-150600.3.53.3
* xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3
* xen-debugsource-4.18.5_20-150600.3.53.3
* xen-4.18.5_20-150600.3.53.3
* xen-libs-4.18.5_20-150600.3.53.3
* xen-tools-4.18.5_20-150600.3.53.3
* xen-libs-debuginfo-4.18.5_20-150600.3.53.3
* xen-devel-4.18.5_20-150600.3.53.3
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3
* openSUSE Leap 15.6 (x86_64)
* xen-libs-32bit-debuginfo-4.18.5_20-150600.3.53.3
* xen-doc-html-4.18.5_20-150600.3.53.3
* xen-libs-32bit-4.18.5_20-150600.3.53.3
* xen-tools-debuginfo-4.18.5_20-150600.3.53.3
* xen-4.18.5_20-150600.3.53.3
* xen-tools-4.18.5_20-150600.3.53.3
* openSUSE Leap 15.6 (i586 x86_64)
* xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3
* xen-debugsource-4.18.5_20-150600.3.53.3
* xen-libs-debuginfo-4.18.5_20-150600.3.53.3
* xen-libs-4.18.5_20-150600.3.53.3
* xen-devel-4.18.5_20-150600.3.53.3
* xen-tools-domU-4.18.5_20-150600.3.53.3
* openSUSE Leap 15.6 (noarch)
* xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* xen-tools-domU-4.18.5_20-150600.3.53.3
* xen-tools-debuginfo-4.18.5_20-150600.3.53.3
* xen-tools-domU-debuginfo-4.18.5_20-150600.3.53.3
* xen-debugsource-4.18.5_20-150600.3.53.3
* xen-4.18.5_20-150600.3.53.3
* xen-libs-debuginfo-4.18.5_20-150600.3.53.3
* xen-tools-4.18.5_20-150600.3.53.3
* xen-libs-4.18.5_20-150600.3.53.3
* xen-devel-4.18.5_20-150600.3.53.3
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* xen-tools-xendomains-wait-disk-4.18.5_20-150600.3.53.3
## References:
* https://www.suse.com/security/cve/CVE-2026-42493.html
* https://www.suse.com/security/cve/CVE-2026-42494.html
* https://www.suse.com/security/cve/CVE-2026-42495.html
* https://www.suse.com/security/cve/CVE-2026-62423.html
* https://www.suse.com/security/cve/CVE-2026-62424.html
* https://www.suse.com/security/cve/CVE-2026-62425.html
* https://www.suse.com/security/cve/CVE-2026-62426.html
* https://www.suse.com/security/cve/CVE-2026-62427.html
* https://www.suse.com/security/cve/CVE-2026-62428.html
* https://www.suse.com/security/cve/CVE-2026-62429.html
* https://www.suse.com/security/cve/CVE-2026-62430.html
* https://www.suse.com/security/cve/CVE-2026-62431.html
* https://www.suse.com/security/cve/CVE-2026-62432.html
* https://www.suse.com/security/cve/CVE-2026-62433.html
* https://www.suse.com/security/cve/CVE-2026-62434.html
* https://bugzilla.suse.com/show_bug.cgi?id71528
* https://bugzilla.suse.com/show_bug.cgi?id71530
* https://bugzilla.suse.com/show_bug.cgi?id71531
* https://bugzilla.suse.com/show_bug.cgi?id71532
* https://bugzilla.suse.com/show_bug.cgi?id71533
* https://bugzilla.suse.com/show_bug.cgi?id71534
* https://bugzilla.suse.com/show_bug.cgi?id71535
* https://bugzilla.suse.com/show_bug.cgi?id71536
* https://bugzilla.suse.com/show_bug.cgi?id71537
* https://bugzilla.suse.com/show_bug.cgi?id71538
* https://bugzilla.suse.com/show_bug.cgi?id71539
* https://bugzilla.suse.com/show_bug.cgi?id71947