SUSE 5727 Published by

SUSE Linux distributed a batch of system patches covering ten openSUSE-SU packages across its standard and GA media repositories. The most critical fix addresses a security flaw in WebKit2GTK3, while additional moderate updates target warewulf4, PHP 8.5, and several Python 3.13 libraries including GitPython and certifi. Administrators running these distributions should prioritize the WebKit patch to close known vulnerabilities before installing the remaining package upgrades. The updates ship through standard openSUSE update channels under their official SU reference numbers for easy tracking.

openSUSE-SU-2026:21508-1: important: Security update for webkit2gtk3
openSUSE-SU-2026:21509-1: moderate: Security update for warewulf4
openSUSE-SU-2026:11419-1: moderate: python313-GitPython-3.1.56-1.1 on GA media
openSUSE-SU-2026:11422-1: moderate: python313-huggingface-hub-1.26.0-1.1 on GA media
openSUSE-SU-2026:11418-1: moderate: php8-8.5.9-1.1 on GA media
openSUSE-SU-2026:11420-1: moderate: python313-asteval-1.0.9-1.1 on GA media
openSUSE-SU-2026:11417-1: moderate: libntpc1-1.2.5-1.1 on GA media
openSUSE-SU-2026:11421-1: moderate: python313-certifi-2026.7.22-1.1 on GA media
openSUSE-SU-2026:11416-1: moderate: gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media
openSUSE-SU-2026:11415-1: moderate: gio-branding-upstream-2.88.3-1.1 on GA media




openSUSE-SU-2026:21508-1: important: Security update for webkit2gtk3


openSUSE security update: security update for webkit2gtk3
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21508-1
Rating: important
References:

* bsc#1271638

Cross-References:

* CVE-2024-4367
* CVE-2026-39872
* CVE-2026-43663
* CVE-2026-43676
* CVE-2026-43699
* CVE-2026-43701
* CVE-2026-43705
* CVE-2026-43707
* CVE-2026-43712
* CVE-2026-43713
* CVE-2026-43715
* CVE-2026-43716
* CVE-2026-43720
* CVE-2026-43721
* CVE-2026-43725
* CVE-2026-43726
* CVE-2026-43727
* CVE-2026-43731
* CVE-2026-43732
* CVE-2026-43734
* CVE-2026-43740
* CVE-2026-43742
* CVE-2026-43745

CVSS scores:

* CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves 23 vulnerabilities and has one bug fix can now be installed.

Description:

This update for webkit2gtk3 fixes the following issues:

- CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution
(bsc#1271638).
- CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638).
- CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638).
- CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638).
- CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the
sandbox (bsc#1271638).
- CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information
(bsc#1271638).
- CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638).
- CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).

Changes for webkit2gtk3:

- Update to version 2.52.5:

* Fire scrollend event for instant programmatic scrolls.
* Increase network idle connection timeout to 115 seconds.
* Add User-Agent quirk for HBO Max.
* Fix the build with system malloc.

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1420=1

Package List:

- openSUSE Leap 16.0:

WebKitGTK-4.0-lang-2.52.5-160000.1.1
WebKitGTK-4.1-lang-2.52.5-160000.1.1
WebKitGTK-6.0-lang-2.52.5-160000.1.1
libjavascriptcoregtk-4_0-18-2.52.5-160000.1.1
libjavascriptcoregtk-4_1-0-2.52.5-160000.1.1
libjavascriptcoregtk-6_0-1-2.52.5-160000.1.1
libwebkit2gtk-4_0-37-2.52.5-160000.1.1
libwebkit2gtk-4_1-0-2.52.5-160000.1.1
libwebkitgtk-6_0-4-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-4_0-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-4_1-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-6_0-2.52.5-160000.1.1
typelib-1_0-WebKit-6_0-2.52.5-160000.1.1
typelib-1_0-WebKit2-4_0-2.52.5-160000.1.1
typelib-1_0-WebKit2-4_1-2.52.5-160000.1.1
typelib-1_0-WebKit2WebExtension-4_0-2.52.5-160000.1.1
typelib-1_0-WebKit2WebExtension-4_1-2.52.5-160000.1.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-160000.1.1
webkit-jsc-4-2.52.5-160000.1.1
webkit-jsc-4.1-2.52.5-160000.1.1
webkit-jsc-6.0-2.52.5-160000.1.1
webkit2gtk-4_0-injected-bundles-2.52.5-160000.1.1
webkit2gtk-4_1-injected-bundles-2.52.5-160000.1.1
webkit2gtk3-devel-2.52.5-160000.1.1
webkit2gtk3-minibrowser-2.52.5-160000.1.1
webkit2gtk3-soup2-devel-2.52.5-160000.1.1
webkit2gtk3-soup2-minibrowser-2.52.5-160000.1.1
webkit2gtk4-devel-2.52.5-160000.1.1
webkit2gtk4-minibrowser-2.52.5-160000.1.1
webkitgtk-6_0-injected-bundles-2.52.5-160000.1.1

References:

* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
* https://www.suse.com/security/cve/CVE-2026-43731.html
* https://www.suse.com/security/cve/CVE-2026-43732.html
* https://www.suse.com/security/cve/CVE-2026-43734.html
* https://www.suse.com/security/cve/CVE-2026-43740.html
* https://www.suse.com/security/cve/CVE-2026-43742.html
* https://www.suse.com/security/cve/CVE-2026-43745.html



openSUSE-SU-2026:21509-1: moderate: Security update for warewulf4


openSUSE security update: security update for warewulf4
-------------------------------------------------------------

Announcement ID: openSUSE-SU-2026:21509-1
Rating: moderate
References:

* bsc#1272014

Cross-References:

* CVE-2026-56852

CVSS scores:

* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

openSUSE Leap 16.0

-------------------------------------------------------------

An update that solves one vulnerability and has one bug fix can now be installed.

Description:

This update for warewulf4 fixes the following issues:

Changes in warewulf4:

- updated golang.org/x/text to v0.40.0 to fix CVE-2026-56852 (bsc#1272014)

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-packagehub-456=1

Package List:

- openSUSE Leap 16.0:

warewulf4-4.7.0-bp160.3.1
warewulf4-dracut-4.7.0-bp160.3.1
warewulf4-man-4.7.0-bp160.3.1
warewulf4-overlay-4.7.0-bp160.3.1
warewulf4-overlay-rke2-4.7.0-bp160.3.1
warewulf4-reference-doc-4.7.0-bp160.3.1

References:

* https://www.suse.com/security/cve/CVE-2026-56852.html



openSUSE-SU-2026:11419-1: moderate: python313-GitPython-3.1.56-1.1 on GA media


# python313-GitPython-3.1.56-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11419-1
Rating: moderate

Cross-References:

* CVE-2023-40267
* CVE-2023-40590
* CVE-2023-41040

CVSS scores:

* CVE-2023-40267 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-40590 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-41040 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-GitPython-3.1.56-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-GitPython 3.1.56-1.1
* python314-GitPython 3.1.56-1.1

## References:

* https://www.suse.com/security/cve/CVE-2023-40267.html
* https://www.suse.com/security/cve/CVE-2023-40590.html
* https://www.suse.com/security/cve/CVE-2023-41040.html



openSUSE-SU-2026:11422-1: moderate: python313-huggingface-hub-1.26.0-1.1 on GA media


# python313-huggingface-hub-1.26.0-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11422-1
Rating: moderate

Cross-References:

* CVE-2026-15717

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-huggingface-hub-1.26.0-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-huggingface-hub 1.26.0-1.1
* python314-huggingface-hub 1.26.0-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15717.html



openSUSE-SU-2026:11418-1: moderate: php8-8.5.9-1.1 on GA media


# php8-8.5.9-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11418-1
Rating: moderate

Cross-References:

* CVE-2026-17543
* CVE-2026-17544
* CVE-2026-7260
* CVE-2026-9672

CVSS scores:

* CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-17544 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-17544 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the php8-8.5.9-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* php8 8.5.9-1.1
* php8-bcmath 8.5.9-1.1
* php8-bz2 8.5.9-1.1
* php8-calendar 8.5.9-1.1
* php8-cli 8.5.9-1.1
* php8-ctype 8.5.9-1.1
* php8-curl 8.5.9-1.1
* php8-dba 8.5.9-1.1
* php8-devel 8.5.9-1.1
* php8-dom 8.5.9-1.1
* php8-enchant 8.5.9-1.1
* php8-exif 8.5.9-1.1
* php8-ffi 8.5.9-1.1
* php8-fileinfo 8.5.9-1.1
* php8-ftp 8.5.9-1.1
* php8-gd 8.5.9-1.1
* php8-gettext 8.5.9-1.1
* php8-gmp 8.5.9-1.1
* php8-iconv 8.5.9-1.1
* php8-intl 8.5.9-1.1
* php8-ldap 8.5.9-1.1
* php8-mbstring 8.5.9-1.1
* php8-mysql 8.5.9-1.1
* php8-odbc 8.5.9-1.1
* php8-openssl 8.5.9-1.1
* php8-pcntl 8.5.9-1.1
* php8-pdo 8.5.9-1.1
* php8-pgsql 8.5.9-1.1
* php8-phar 8.5.9-1.1
* php8-posix 8.5.9-1.1
* php8-readline 8.5.9-1.1
* php8-shmop 8.5.9-1.1
* php8-snmp 8.5.9-1.1
* php8-soap 8.5.9-1.1
* php8-sockets 8.5.9-1.1
* php8-sodium 8.5.9-1.1
* php8-sqlite 8.5.9-1.1
* php8-sysvmsg 8.5.9-1.1
* php8-sysvsem 8.5.9-1.1
* php8-sysvshm 8.5.9-1.1
* php8-tidy 8.5.9-1.1
* php8-tokenizer 8.5.9-1.1
* php8-xmlreader 8.5.9-1.1
* php8-xmlwriter 8.5.9-1.1
* php8-xsl 8.5.9-1.1
* php8-zip 8.5.9-1.1
* php8-zlib 8.5.9-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-17543.html
* https://www.suse.com/security/cve/CVE-2026-17544.html
* https://www.suse.com/security/cve/CVE-2026-7260.html
* https://www.suse.com/security/cve/CVE-2026-9672.html



openSUSE-SU-2026:11420-1: moderate: python313-asteval-1.0.9-1.1 on GA media


# python313-asteval-1.0.9-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11420-1
Rating: moderate

Cross-References:

* CVE-2026-55244

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the python313-asteval-1.0.9-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-asteval 1.0.9-1.1
* python314-asteval 1.0.9-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-55244.html



openSUSE-SU-2026:11417-1: moderate: libntpc1-1.2.5-1.1 on GA media


# libntpc1-1.2.5-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11417-1
Rating: moderate

Cross-References:

* CVE-2026-18321

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the libntpc1-1.2.5-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libntpc1 1.2.5-1.1
* ntpsec 1.2.5-1.1
* ntpsec-devel 1.2.5-1.1
* ntpsec-doc 1.2.5-1.1
* ntpsec-utils 1.2.5-1.1
* python3-ntp 1.2.5-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-18321.html



openSUSE-SU-2026:11421-1: moderate: python313-certifi-2026.7.22-1.1 on GA media


# python313-certifi-2026.7.22-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11421-1
Rating: moderate

Cross-References:

* CVE-2022-23491
* CVE-2024-39689

CVSS scores:

* CVE-2022-23491 ( SUSE ): 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2024-39689 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 2 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the python313-certifi-2026.7.22-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* python313-certifi 2026.7.22-1.1
* python314-certifi 2026.7.22-1.1

## References:

* https://www.suse.com/security/cve/CVE-2022-23491.html
* https://www.suse.com/security/cve/CVE-2024-39689.html



openSUSE-SU-2026:11416-1: moderate: gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media


# gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11416-1
Rating: moderate

Cross-References:

* CVE-2026-62289
* CVE-2026-62291
* CVE-2026-62292
* CVE-2026-62377

Affected Products:

* openSUSE Tumbleweed

An update that solves 4 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the gdk-pixbuf-loader-libheif-1.23.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* gdk-pixbuf-loader-libheif 1.23.1-1.1
* libheif-aom 1.23.1-1.1
* libheif-dav1d 1.23.1-1.1
* libheif-devel 1.23.1-1.1
* libheif-ffmpeg 1.23.1-1.1
* libheif-jpeg 1.23.1-1.1
* libheif-openh264 1.23.1-1.1
* libheif-openjpeg 1.23.1-1.1
* libheif-rav1e 1.23.1-1.1
* libheif-svtenc 1.23.1-1.1
* libheif1 1.23.1-1.1
* libheif1-32bit 1.23.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-62289.html
* https://www.suse.com/security/cve/CVE-2026-62291.html
* https://www.suse.com/security/cve/CVE-2026-62292.html
* https://www.suse.com/security/cve/CVE-2026-62377.html



openSUSE-SU-2026:11415-1: moderate: gio-branding-upstream-2.88.3-1.1 on GA media


# gio-branding-upstream-2.88.3-1.1 on GA media

Announcement ID: openSUSE-SU-2026:11415-1
Rating: moderate

Cross-References:

* CVE-2026-15588

CVSS scores:

* CVE-2026-15588 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-15588 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the gio-branding-upstream-2.88.3-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* gio-branding-upstream 2.88.3-1.1
* glib2-devel 2.88.3-1.1
* glib2-devel-32bit 2.88.3-1.1
* glib2-devel-static 2.88.3-1.1
* glib2-lang 2.88.3-1.1
* glib2-tests-devel 2.88.3-1.1
* glib2-tools 2.88.3-1.1
* glib2-tools-32bit 2.88.3-1.1
* libgio-2_0-0 2.88.3-1.1
* libgio-2_0-0-32bit 2.88.3-1.1
* libgirepository-2_0-0 2.88.3-1.1
* libglib-2_0-0 2.88.3-1.1
* libglib-2_0-0-32bit 2.88.3-1.1
* libgmodule-2_0-0 2.88.3-1.1
* libgmodule-2_0-0-32bit 2.88.3-1.1
* libgobject-2_0-0 2.88.3-1.1
* libgobject-2_0-0-32bit 2.88.3-1.1
* libgthread-2_0-0 2.88.3-1.1
* libgthread-2_0-0-32bit 2.88.3-1.1
* typelib-1_0-GIRepository-3_0 2.88.3-1.1
* typelib-1_0-GLib-2_0 2.88.3-1.1
* typelib-1_0-GLibUnix-2_0 2.88.3-1.1
* typelib-1_0-GModule-2_0 2.88.3-1.1
* typelib-1_0-GObject-2_0 2.88.3-1.1
* typelib-1_0-Gio-2_0 2.88.3-1.1

## References:

* https://www.suse.com/security/cve/CVE-2026-15588.html