openSUSE-SU-2026:21508-1: important: Security update for webkit2gtk3
openSUSE-SU-2026:21509-1: moderate: Security update for warewulf4
openSUSE-SU-2026:11419-1: moderate: python313-GitPython-3.1.56-1.1 on GA media
openSUSE-SU-2026:11422-1: moderate: python313-huggingface-hub-1.26.0-1.1 on GA media
openSUSE-SU-2026:11418-1: moderate: php8-8.5.9-1.1 on GA media
openSUSE-SU-2026:11420-1: moderate: python313-asteval-1.0.9-1.1 on GA media
openSUSE-SU-2026:11417-1: moderate: libntpc1-1.2.5-1.1 on GA media
openSUSE-SU-2026:11421-1: moderate: python313-certifi-2026.7.22-1.1 on GA media
openSUSE-SU-2026:11416-1: moderate: gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media
openSUSE-SU-2026:11415-1: moderate: gio-branding-upstream-2.88.3-1.1 on GA media
openSUSE-SU-2026:21508-1: important: Security update for webkit2gtk3
openSUSE security update: security update for webkit2gtk3
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21508-1
Rating: important
References:
* bsc#1271638
Cross-References:
* CVE-2024-4367
* CVE-2026-39872
* CVE-2026-43663
* CVE-2026-43676
* CVE-2026-43699
* CVE-2026-43701
* CVE-2026-43705
* CVE-2026-43707
* CVE-2026-43712
* CVE-2026-43713
* CVE-2026-43715
* CVE-2026-43716
* CVE-2026-43720
* CVE-2026-43721
* CVE-2026-43725
* CVE-2026-43726
* CVE-2026-43727
* CVE-2026-43731
* CVE-2026-43732
* CVE-2026-43734
* CVE-2026-43740
* CVE-2026-43742
* CVE-2026-43745
CVSS scores:
* CVE-2024-4367 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-39872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43699 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43701 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43705 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43707 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43712 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43713 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43715 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43716 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43720 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43721 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43725 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
* CVE-2026-43726 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43727 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43731 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-43732 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
* CVE-2026-43742 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-43745 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves 23 vulnerabilities and has one bug fix can now be installed.
Description:
This update for webkit2gtk3 fixes the following issues:
- CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution
(bsc#1271638).
- CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638).
- CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638).
- CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638).
- CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638).
- CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638).
- CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the
sandbox (bsc#1271638).
- CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
- CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638).
- CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information
(bsc#1271638).
- CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638).
- CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash
(bsc#1271638).
- CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash
(bsc#1271638).
Changes for webkit2gtk3:
- Update to version 2.52.5:
* Fire scrollend event for instant programmatic scrolls.
* Increase network idle connection timeout to 115 seconds.
* Add User-Agent quirk for HBO Max.
* Fix the build with system malloc.
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1420=1
Package List:
- openSUSE Leap 16.0:
WebKitGTK-4.0-lang-2.52.5-160000.1.1
WebKitGTK-4.1-lang-2.52.5-160000.1.1
WebKitGTK-6.0-lang-2.52.5-160000.1.1
libjavascriptcoregtk-4_0-18-2.52.5-160000.1.1
libjavascriptcoregtk-4_1-0-2.52.5-160000.1.1
libjavascriptcoregtk-6_0-1-2.52.5-160000.1.1
libwebkit2gtk-4_0-37-2.52.5-160000.1.1
libwebkit2gtk-4_1-0-2.52.5-160000.1.1
libwebkitgtk-6_0-4-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-4_0-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-4_1-2.52.5-160000.1.1
typelib-1_0-JavaScriptCore-6_0-2.52.5-160000.1.1
typelib-1_0-WebKit-6_0-2.52.5-160000.1.1
typelib-1_0-WebKit2-4_0-2.52.5-160000.1.1
typelib-1_0-WebKit2-4_1-2.52.5-160000.1.1
typelib-1_0-WebKit2WebExtension-4_0-2.52.5-160000.1.1
typelib-1_0-WebKit2WebExtension-4_1-2.52.5-160000.1.1
typelib-1_0-WebKitWebProcessExtension-6_0-2.52.5-160000.1.1
webkit-jsc-4-2.52.5-160000.1.1
webkit-jsc-4.1-2.52.5-160000.1.1
webkit-jsc-6.0-2.52.5-160000.1.1
webkit2gtk-4_0-injected-bundles-2.52.5-160000.1.1
webkit2gtk-4_1-injected-bundles-2.52.5-160000.1.1
webkit2gtk3-devel-2.52.5-160000.1.1
webkit2gtk3-minibrowser-2.52.5-160000.1.1
webkit2gtk3-soup2-devel-2.52.5-160000.1.1
webkit2gtk3-soup2-minibrowser-2.52.5-160000.1.1
webkit2gtk4-devel-2.52.5-160000.1.1
webkit2gtk4-minibrowser-2.52.5-160000.1.1
webkitgtk-6_0-injected-bundles-2.52.5-160000.1.1
References:
* https://www.suse.com/security/cve/CVE-2024-4367.html
* https://www.suse.com/security/cve/CVE-2026-39872.html
* https://www.suse.com/security/cve/CVE-2026-43663.html
* https://www.suse.com/security/cve/CVE-2026-43676.html
* https://www.suse.com/security/cve/CVE-2026-43699.html
* https://www.suse.com/security/cve/CVE-2026-43701.html
* https://www.suse.com/security/cve/CVE-2026-43705.html
* https://www.suse.com/security/cve/CVE-2026-43707.html
* https://www.suse.com/security/cve/CVE-2026-43712.html
* https://www.suse.com/security/cve/CVE-2026-43713.html
* https://www.suse.com/security/cve/CVE-2026-43715.html
* https://www.suse.com/security/cve/CVE-2026-43716.html
* https://www.suse.com/security/cve/CVE-2026-43720.html
* https://www.suse.com/security/cve/CVE-2026-43721.html
* https://www.suse.com/security/cve/CVE-2026-43725.html
* https://www.suse.com/security/cve/CVE-2026-43726.html
* https://www.suse.com/security/cve/CVE-2026-43727.html
* https://www.suse.com/security/cve/CVE-2026-43731.html
* https://www.suse.com/security/cve/CVE-2026-43732.html
* https://www.suse.com/security/cve/CVE-2026-43734.html
* https://www.suse.com/security/cve/CVE-2026-43740.html
* https://www.suse.com/security/cve/CVE-2026-43742.html
* https://www.suse.com/security/cve/CVE-2026-43745.html
openSUSE-SU-2026:21509-1: moderate: Security update for warewulf4
openSUSE security update: security update for warewulf4
-------------------------------------------------------------
Announcement ID: openSUSE-SU-2026:21509-1
Rating: moderate
References:
* bsc#1272014
Cross-References:
* CVE-2026-56852
CVSS scores:
* CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
openSUSE Leap 16.0
-------------------------------------------------------------
An update that solves one vulnerability and has one bug fix can now be installed.
Description:
This update for warewulf4 fixes the following issues:
Changes in warewulf4:
- updated golang.org/x/text to v0.40.0 to fix CVE-2026-56852 (bsc#1272014)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-packagehub-456=1
Package List:
- openSUSE Leap 16.0:
warewulf4-4.7.0-bp160.3.1
warewulf4-dracut-4.7.0-bp160.3.1
warewulf4-man-4.7.0-bp160.3.1
warewulf4-overlay-4.7.0-bp160.3.1
warewulf4-overlay-rke2-4.7.0-bp160.3.1
warewulf4-reference-doc-4.7.0-bp160.3.1
References:
* https://www.suse.com/security/cve/CVE-2026-56852.html
openSUSE-SU-2026:11419-1: moderate: python313-GitPython-3.1.56-1.1 on GA media
# python313-GitPython-3.1.56-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11419-1
Rating: moderate
Cross-References:
* CVE-2023-40267
* CVE-2023-40590
* CVE-2023-41040
CVSS scores:
* CVE-2023-40267 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-40590 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-41040 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products:
* openSUSE Tumbleweed
An update that solves 3 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the python313-GitPython-3.1.56-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-GitPython 3.1.56-1.1
* python314-GitPython 3.1.56-1.1
## References:
* https://www.suse.com/security/cve/CVE-2023-40267.html
* https://www.suse.com/security/cve/CVE-2023-40590.html
* https://www.suse.com/security/cve/CVE-2023-41040.html
openSUSE-SU-2026:11422-1: moderate: python313-huggingface-hub-1.26.0-1.1 on GA media
# python313-huggingface-hub-1.26.0-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11422-1
Rating: moderate
Cross-References:
* CVE-2026-15717
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the python313-huggingface-hub-1.26.0-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-huggingface-hub 1.26.0-1.1
* python314-huggingface-hub 1.26.0-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15717.html
openSUSE-SU-2026:11418-1: moderate: php8-8.5.9-1.1 on GA media
# php8-8.5.9-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11418-1
Rating: moderate
Cross-References:
* CVE-2026-17543
* CVE-2026-17544
* CVE-2026-7260
* CVE-2026-9672
CVSS scores:
* CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-17544 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-17544 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 4 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the php8-8.5.9-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* php8 8.5.9-1.1
* php8-bcmath 8.5.9-1.1
* php8-bz2 8.5.9-1.1
* php8-calendar 8.5.9-1.1
* php8-cli 8.5.9-1.1
* php8-ctype 8.5.9-1.1
* php8-curl 8.5.9-1.1
* php8-dba 8.5.9-1.1
* php8-devel 8.5.9-1.1
* php8-dom 8.5.9-1.1
* php8-enchant 8.5.9-1.1
* php8-exif 8.5.9-1.1
* php8-ffi 8.5.9-1.1
* php8-fileinfo 8.5.9-1.1
* php8-ftp 8.5.9-1.1
* php8-gd 8.5.9-1.1
* php8-gettext 8.5.9-1.1
* php8-gmp 8.5.9-1.1
* php8-iconv 8.5.9-1.1
* php8-intl 8.5.9-1.1
* php8-ldap 8.5.9-1.1
* php8-mbstring 8.5.9-1.1
* php8-mysql 8.5.9-1.1
* php8-odbc 8.5.9-1.1
* php8-openssl 8.5.9-1.1
* php8-pcntl 8.5.9-1.1
* php8-pdo 8.5.9-1.1
* php8-pgsql 8.5.9-1.1
* php8-phar 8.5.9-1.1
* php8-posix 8.5.9-1.1
* php8-readline 8.5.9-1.1
* php8-shmop 8.5.9-1.1
* php8-snmp 8.5.9-1.1
* php8-soap 8.5.9-1.1
* php8-sockets 8.5.9-1.1
* php8-sodium 8.5.9-1.1
* php8-sqlite 8.5.9-1.1
* php8-sysvmsg 8.5.9-1.1
* php8-sysvsem 8.5.9-1.1
* php8-sysvshm 8.5.9-1.1
* php8-tidy 8.5.9-1.1
* php8-tokenizer 8.5.9-1.1
* php8-xmlreader 8.5.9-1.1
* php8-xmlwriter 8.5.9-1.1
* php8-xsl 8.5.9-1.1
* php8-zip 8.5.9-1.1
* php8-zlib 8.5.9-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-17543.html
* https://www.suse.com/security/cve/CVE-2026-17544.html
* https://www.suse.com/security/cve/CVE-2026-7260.html
* https://www.suse.com/security/cve/CVE-2026-9672.html
openSUSE-SU-2026:11420-1: moderate: python313-asteval-1.0.9-1.1 on GA media
# python313-asteval-1.0.9-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11420-1
Rating: moderate
Cross-References:
* CVE-2026-55244
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the python313-asteval-1.0.9-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-asteval 1.0.9-1.1
* python314-asteval 1.0.9-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-55244.html
openSUSE-SU-2026:11417-1: moderate: libntpc1-1.2.5-1.1 on GA media
# libntpc1-1.2.5-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11417-1
Rating: moderate
Cross-References:
* CVE-2026-18321
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the libntpc1-1.2.5-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* libntpc1 1.2.5-1.1
* ntpsec 1.2.5-1.1
* ntpsec-devel 1.2.5-1.1
* ntpsec-doc 1.2.5-1.1
* ntpsec-utils 1.2.5-1.1
* python3-ntp 1.2.5-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-18321.html
openSUSE-SU-2026:11421-1: moderate: python313-certifi-2026.7.22-1.1 on GA media
# python313-certifi-2026.7.22-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11421-1
Rating: moderate
Cross-References:
* CVE-2022-23491
* CVE-2024-39689
CVSS scores:
* CVE-2022-23491 ( SUSE ): 6.6 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
* CVE-2024-39689 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products:
* openSUSE Tumbleweed
An update that solves 2 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the python313-certifi-2026.7.22-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* python313-certifi 2026.7.22-1.1
* python314-certifi 2026.7.22-1.1
## References:
* https://www.suse.com/security/cve/CVE-2022-23491.html
* https://www.suse.com/security/cve/CVE-2024-39689.html
openSUSE-SU-2026:11416-1: moderate: gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media
# gdk-pixbuf-loader-libheif-1.23.1-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11416-1
Rating: moderate
Cross-References:
* CVE-2026-62289
* CVE-2026-62291
* CVE-2026-62292
* CVE-2026-62377
Affected Products:
* openSUSE Tumbleweed
An update that solves 4 vulnerabilities can now be installed.
## Description:
These are all security issues fixed in the gdk-pixbuf-loader-libheif-1.23.1-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* gdk-pixbuf-loader-libheif 1.23.1-1.1
* libheif-aom 1.23.1-1.1
* libheif-dav1d 1.23.1-1.1
* libheif-devel 1.23.1-1.1
* libheif-ffmpeg 1.23.1-1.1
* libheif-jpeg 1.23.1-1.1
* libheif-openh264 1.23.1-1.1
* libheif-openjpeg 1.23.1-1.1
* libheif-rav1e 1.23.1-1.1
* libheif-svtenc 1.23.1-1.1
* libheif1 1.23.1-1.1
* libheif1-32bit 1.23.1-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-62289.html
* https://www.suse.com/security/cve/CVE-2026-62291.html
* https://www.suse.com/security/cve/CVE-2026-62292.html
* https://www.suse.com/security/cve/CVE-2026-62377.html
openSUSE-SU-2026:11415-1: moderate: gio-branding-upstream-2.88.3-1.1 on GA media
# gio-branding-upstream-2.88.3-1.1 on GA media
Announcement ID: openSUSE-SU-2026:11415-1
Rating: moderate
Cross-References:
* CVE-2026-15588
CVSS scores:
* CVE-2026-15588 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-15588 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected Products:
* openSUSE Tumbleweed
An update that solves one vulnerability can now be installed.
## Description:
These are all security issues fixed in the gio-branding-upstream-2.88.3-1.1 package on the GA media of openSUSE Tumbleweed.
## Package List:
* openSUSE Tumbleweed:
* gio-branding-upstream 2.88.3-1.1
* glib2-devel 2.88.3-1.1
* glib2-devel-32bit 2.88.3-1.1
* glib2-devel-static 2.88.3-1.1
* glib2-lang 2.88.3-1.1
* glib2-tests-devel 2.88.3-1.1
* glib2-tools 2.88.3-1.1
* glib2-tools-32bit 2.88.3-1.1
* libgio-2_0-0 2.88.3-1.1
* libgio-2_0-0-32bit 2.88.3-1.1
* libgirepository-2_0-0 2.88.3-1.1
* libglib-2_0-0 2.88.3-1.1
* libglib-2_0-0-32bit 2.88.3-1.1
* libgmodule-2_0-0 2.88.3-1.1
* libgmodule-2_0-0-32bit 2.88.3-1.1
* libgobject-2_0-0 2.88.3-1.1
* libgobject-2_0-0-32bit 2.88.3-1.1
* libgthread-2_0-0 2.88.3-1.1
* libgthread-2_0-0-32bit 2.88.3-1.1
* typelib-1_0-GIRepository-3_0 2.88.3-1.1
* typelib-1_0-GLib-2_0 2.88.3-1.1
* typelib-1_0-GLibUnix-2_0 2.88.3-1.1
* typelib-1_0-GModule-2_0 2.88.3-1.1
* typelib-1_0-GObject-2_0 2.88.3-1.1
* typelib-1_0-Gio-2_0 2.88.3-1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-15588.html